Subscribe to The Register feed
Articles from www.theregister.com
Updated: 2 months 2 weeks ago

.NET's long-term support is not long-term enough, dev complains

Mon, 06/29/2026 - 12:15
Microsoft's support policy for its .NET runtime and development platform is too short for enterprises, according to a developer who has revived a long-standing complaint in a new GitHub issue. The current release lifecycle for modern .NET, formerly known as .NET Core, is an annual major release, with even-numbered versions being long-term support (LTS) for three years, and odd-numbered versions maintained for two years. The legacy and Windows-only .NET Framework, which is in maintenance, is defined as a component of Windows and therefore supported for much longer. Breaking changes are rare, but it is old and many libraries and application frameworks do not support it, including Microsoft's ASP.NET Core. Earlier this month, a developer opened an issue in the official .NET repository arguing that the LTS support window is "too short for upgrade and adoption cycles." The problem with the current three-year cycle is that by the time the next LTS release appears, two of those years have already elapsed, leaving just one year to upgrade. Even when they can get the upgrade done in time, potential customers "are hesitant to adopt software which is soon to run out of the defined EOL [end of life] window." Another developer commented: "I've got telemetry showing about 50 percent of the deployed versions of my software are running EOL versions." They also complained about the one-year upgrade window, saying: "I try to use netfx [.NET Framework] as much as I can because of the ten-year support tied to OS life but that's getting harder and harder as the ecosystem drops FX support." The problem is not new, but is becoming more pressing as .NET Framework ages. A similar complaint in 2023 drew comment from program manager Richard Lander, who said: "We chose the support time frames to enable a balance between stable deployment time for users and enabling the team to spend most of their time innovating." He said that Microsoft had discussed longer support time frames and extended paid support offerings but has "opted to continue with only the free support plan." Microsoft's free support period is shorter than that offered for some other platforms including Java (five years plus extended support for LTS versions) and Python (five years security fixes for all releases). Upgrading from one .NET version to another can sometimes be done easily, but complications include breaking changes, third-party dependencies that may also need updating, the usual testing and deployment cycle, and in some cases paying external developers for the upgrade. "The .NET Framework only incurs costs for functional modifications and bug fixes, but .NET tries to add to that the non-negligible cost of version upgrades at relatively short intervals," said a comment to the 2023 issue. In March, Microsoft principal software engineer Shay Rojansky requested feedback on dropping .NET Framework support in the Microsoft.Data.Sqlite library, drawing the comment that "right now .NET Standard 2.0 and framework 4.8 are the only .NET targets with reasonable support timelines available for enterprise." The .NET Standard 2.0 specifies a common set of APIs implemented by .NET Framework and modern .NET releases, including .NET 10. Rojansky said the comment was off-topic, yet it is a factor in the enduring use of .NET Framework, which in turn may explain why the proposal was closed as "not planned." ®

How the AI bubble could pop and take down the global economy, according to the BIS

Mon, 06/29/2026 - 10:55
The central bank for central banks is concerned about the eye-watering sums being invested into AI, and it's raising the specter of a global recession should the bubble burst. In its annual report for 2026, the Bank for International Settlements compared the current craze to historical events, including canal and British railway mania in the 1800s, electrification exuberance of the 1920s, and the dotcom boom of the 1990s. The report states: “all shared one common trait: a genuine technological breakthrough that attracted capital in excess of what commercial returns could ultimately justify. “These episodes ended with an eventual reversal in investment, inducing economy-wide recessions. The scale and pace of the current AI investment boom accompanied by expectations of large productivity payoffs bear resemblance to these precedents, highlighting potential downside risks in the near term.” The Register has already reported that Amazon forecasts capital expenditures of $200 billion for 2026, Microsoft is projecting $190 billion, Google some $180 billon and Meta up to $140 billion. Oracle is also betting big on AI. BIS estimates the five largest hyperscalers are set to spend more than a trillion dollars on AI-related capex in 2026 – and given the inflationary conditions regarding memory and that each rival is trying to outdo each other, that seems plausible. “These commitments are outpacing earnings and the free cash flow of these firms, leading some to issue debt to raise additional financing. This investment race may be partly driven by the perception that only a small number of players with superior technology will ultimately dominate the market shares." Intense competition is leading to the risk of the tech giants overcommitting resources to “investment projects with still uncertain returns, leaving all firms vulnerable to disappointments in AI payoffs.” This is because as competitive pressure drives spending ever higher, the net economic surplus for the tech industry declines and “could turn negative in adverse scenarios.” “Disappointment in returns could trigger a sudden pullback in financing and turn the capex boom into a protracted investment bust with potential knock-on effects on the financial conditions,” the annual report continues. The report also cited concerns about a looming "supply side roadblock" around issues like electricity availability, chip shortages and grid connection bottlenecks. AI datacenters are already putting pressure on energy prices and input costs with “potential spillovers to inflation.” “Looking ahead, these temporary shortages may also amplify over-investment, as firms attempt to lock in future capacity through long-dated contracts that further expose them to any disappointments in demand.” Should inflation spike or AI-led investment collapse, the macroeconomic consequences could be amplified by “existing financial vulnerabilities.” Policy rates being tightened to get a hold on inflation may precipitate a “sharp pullback in asset prices after a prolonged period of exuberant risk-taking, triggering disruptive macro-financial feedback loops.” Given AI companies' “rising leverage” and a “growing footprint in credit markets”, a major change in optimistic sentiments towards these businesses could have serious financial knock-on effects. ”Vulnerabilities extend to their supplier ecosystem, including engineering, procurement and construction contractors whose balance sheets are comparatively weak, leaving them exposed to any Capex pullback by hyperscalers.” The “opacity” of AI-sector financing is compounding vulnerabilities as corporations create a web of private arrangements – circular financing – and the terms of datacenter facility leases are often not fully disclosed, BIS adds. The backdrop to all of this is that, while enterprises running pilots report some efficiency gains at a employee level, few report discernible productivity gains from AI projects that went into production environments at scale. The Register has long discussed concerns about the dynamics of the AI industry, as outlined in the many links in this article above. It now seems that suits in the finance industry are waking up to the potential pitfalls too. ®

Mageia 10 keeps the 32-bit Linux flame alive

Mon, 06/29/2026 - 10:32
Mageia 10 marks 15 years since the distribution's first release in June 2011. The project began the previous year as a fork of Mandriva, itself formerly known as Mandrake Linux. We last looked at Mageia alongside the other Mandrake descendants in 2022. What sets Mageia apart from OpenMandriva Lx, PCLinuxOS, and Russia's ROSA Linux is its continued support for 32-bit x86 PCs. Its GNOME and KDE Plasma live images are available only for x86-64, while the Xfce edition comes in both x86-64 and x86-32 versions. There is also a "Classic Installer" ISO, which lets you choose your own desktop from nine different desktop environments, plus another 16 window managers, as detailed in the release notes. Both the standard GNOME session and GNOME Classic are available, while Liquidshell provides a lightweight alternative to KDE Plasma. Mandrake Linux started out in 1998 as an easier version of Red Hat Linux using the new KDE desktop, which, at that time, Red Hat refused to incorporate due to concerns over the licence of KDE's Qt toolkit. Nearly three decades later, Mageia remains an RPM-based distro. Version 10 offers two RPM package-management tools: Mageia's urpmi command and DNF. urpmi also has its own graphical wrapper called Rpmdrake, but Fedora's dnfdragora is an optional install. Since RHEL and the RHELatives, Fedora, SUSE and openSUSE all use RPM as well, packages of big-name apps such as Google Chrome are available – but Mageia is a different distro, whose common ancestry dates back more than 25 years, and packages for Fedora or openSUSE may not install or work correctly. It comes with Flatpak preinstalled, although no Flatpak applications are installed by default. As with other niche distros, Flatpak may help when you can't find a native package of something. For those with the 32-bit edition, though, we suspect that few Flatpaks support that architecture. Mageia 10 is a polished, friendly graphical Linux, built from recent components such as kernel 6.18. True, it does feel a little old-fashioned in some ways: for instance, it uses separate root and user accounts – although sudo is installed, it's not configured for use. However, it's a solid choice if you want to get away from the Debian/Fedora mainstream – and if you have a capable 32-bit machine, like a Windows 10 32-bit box, or some other need to run a 32-bit OS such as specific hardware support, then this is one of the best choices around today. The Welcome screen is rich and very helpful, offering the ability to install extra apps, switch repositories, and more. Alongside it is the Mageia Control Center, which can manage most aspects of the OS without going near a command line. The distro is also well documented, with a substantial Mageia wiki. It does use systemd, but, even so, it's relatively lightweight. In our testing on a 32-bit VirtualBox VM, the Xfce edition used just 633 MB of RAM at idle, which is low by modern standards, and 7.8 GB of disk space. If you choose the KDE Plasma desktop, you get Plasma 6.5.5 with a choice of X11 or Wayland. The installation occupies about the same amount of disk space, although the RAM usage rises sharply: about 1.7 GB at idle. Xfce has an unusual GNOME 2-style two-panel setup, while the Plasma layout is clean and simple. We installed the Liquidshell desktop to have a look, but it's very basic and rather clunky. Mageia forked from Mandriva in 2011, before the company closed down, while OpenMandriva did so afterwards. They are still quite similar distributions, though, and we really wish that the two teams could settle their differences and merge the distros. Either way, Mageia's 32-bit edition is an increasingly rare offering in an increasingly 64-bit world, which might win it some new admirers. ®

Rocket Lab buys its way into the satellite big league with $8B Iridium deal

Mon, 06/29/2026 - 09:08
Rocket Lab has agreed to acquire Iridium Communications in an $8 billion cash-and-stock deal, potentially creating another challenger to SpaceX and Amazon for vertically integrated satellite broadband. Both Rocket Lab and Iridium's boards unanimously agreed to the deal, which was jointly announced on Monday and is expected to close by the middle of next year. Rocket Lab separately described the move in an investor slide deck [PDF] as positioning it as a "fully integrated, self-launching, tier-1 space power" alongside the forces of Amazon/Globalstar and SpaceX/EchoStar. Amazon agreed to acquire Globalstar earlier this year to help serve its nascent Leo satellite operation, while SpaceX agreed to buy spectrum licences from EchoStar in a transaction partly funded with SpaceX shares. Iridium currently operates a constellation of 80 satellites, 66 of which are active and the rest are on-orbit spares. The satellites use L-band frequencies for user communications and Ka-band frequencies for links between satellites and ground gateways. L-band offers lower data rates but is more resistant to weather interference. Iridium offers service around the world, including in the polar regions (as does Starlink), and claims to have more than 2.55 million global subscribers. The soon-to-be-absorbed satellite operator already has a wide customer base across several sectors, serving the US government and military, as well as customers in the maritime, aviation, and telecommunications sectors. One major question is how Rocket Lab would accommodate an influx of customers given the relatively small size of Iridium's constellation (Starlink has close to 10,000 satellites in orbit). Rocket Lab said it plans to expand Iridium's direct-to-device cellular offering to compete with Starlink and Amazon Leo when the latter opens to customers. "This is our entrance into recurring applications revenue from space, but it's not the finish line," Rocket Lab said in its investor deck. "Rather than simply continuing Iridium's network, we will build upon it to scale into untapped markets and pioneer new space-based services." Rocket Lab is likely to increase launch activity as it expands the Iridium constellation and seeks more customers. The proposed deal would make Rocket Lab a more direct competitor to SpaceX in vertically integrated launch and satellite communications, with Amazon playing a distant third as it has yet to realize its Leo ambition. To add to the risk for SpaceX, Rocket Lab recently achieved a record speed launch for the Space Force, putting its Pioneer space vehicle in orbit just 17 hours after receiving orders for a rapid launch tactical space mission. SpaceX, meanwhile, has pursued heavy-lift capability with Starship but has been repeatedly grounded for failing to meet launch objectives safely. Rocket Lab does not yet operate a rocket with payload capacity comparable to SpaceX's Falcon 9, and development of its planned competitor, Neutron, hasn't been without setbacks. Rocket Lab is still unlikely to displace SpaceX, whose operations have become so closely entwined with the US government that officials have reportedly deemed them difficult to disentangle. SpaceX also has roughly a year to extend its lead while the Iridium deal undergoes shareholder and regulatory review. ®

Microsoft to assist European Commission in defense of EU-US data-sharing agreement

Mon, 06/29/2026 - 07:29
Microsoft says it is trying to help the European Commission see off a legal threat to the EU-US Data Privacy Framework agreement - relied on by organizations to legally move data between the bloc and the US. In a weekend blog post, the software biz confirmed the Court of Justice of the European Union had granted its application to formally intervene in a case challenging the framework, which has supported data between the two economic super-powers since 2023. Microsoft thinks the case before the court will determine whether its enterprise customers — of which there are many — can continue under the existing pact. “Companies across the globe rely on data flows to manage their people, produce their goods and services, and distribute products to their customers. We understand that data flows trigger questions about differences in legal traditions.” In Redmond's blog post, Jon Palmer, Microsoft corporate veep and chief legal officer, and Cari Benn, chief privacy officer, say the Court found Microsoft has a direct and existing interest in the result, allowing it to intervene in the case. “As an intervener, we can now file legal briefs in support of the European Commission, participate in oral hearings, and share our perspective on the importance of upholding a framework that directly benefits the European economy,” the pair write. The case before the court is an appeal against an earlier ruling which struck down a challenge to the EU-US Data Privacy Framework. In September last year, the EU General Court’s judgment confirmed the data sharing agreements' validity, ruling against the challenge from French parliamentarian Philippe Latombe. He brought the case by arguing the Data Protection Review Court (DPRC) — the US body set up to hear issues related to the Framework — lacked independence. A presidential executive order could disregard the DPRC, he argued. But the General Court disagreed. "It is apparent from the file that the appointment of judges to the DPRC and the DPRC's functioning are accompanied by several safeguards and conditions to ensure the independence of its members," the Court said at the time. Max Schrems, the lawyer and campaigner behind two successful challenges to EU data sharing rules, Safe Harbor (2015) and Privacy Shield (2020), pointed out that Latombe had chosen a targeted and narrow challenge to the current deal. Another challenge based on a broader set of arguments might prove successful, he said. “This was a rather narrow challenge. We are convinced that a broader review of US law – especially the use of Executive Orders by the Trump administration – should yield a different result. We are reviewing our options to bring such a challenge. While the Commission may have gained another year, we still lack any legal certainty for users and businesses,” Schrems said in a blog post. Latombe announced plans to appeal in October last year, although the basis for the appeal is still to be made public. According to law firm WilmerHale, the ECJ has historically been more skeptical than the General Court in assessing US surveillance practices and the adequacy of redress mechanisms. Its prior decisions in the so-called Schrems I and II rulings invalidated frameworks that had also been endorsed by the European Commission, and Latombe’s appeal puts another framework before the European Court of Justice for consideration. Clearly, Microsoft feels the appeal’s chances of success are sufficient for it to step in. ®

AI may be good at finding security vulnerabilities, but it can't beat human stupidity

Mon, 06/29/2026 - 06:45
KETTLE AI commands all the headlines nowadays, but the biggest security story of the week is all about human laziness and poor password habits – just like the good old days. This week on the Kettle, host Brandon Vigliarolo is joined by US editor Avram Piltch and security editor Jessica Lyons to talk about the Klue breach, which was blamed on a "compromised legacy credential" that ought to have been deleted a while ago. The hole allowed cybercriminals to access the SalesForce environments of hundreds of companies, say researchers. The incident has caused trouble for security firm Huntress, which admitted to the breach early on, and the situation over there wasn't caused by AI either. That said, AI is playing a role in what's being described as "the summer from hell" by one security professional, but while top-tier AI models are spotting troublesome vulnerabilities, the amount of damage they've managed to cause pales in comparison to what one lazy sysadmin can cause by poorly managing passwords. You can listen to the latest episode of The Kettle by clicking on the player above, as well as on Spotify, Apple Music, or YouTube, or read the transcript of the latest episode below. It's been lightly edited for clarity. Brandon (00:01) Welcome to the latest episode of The Register's Kettle Podcast. I'm your host, Brandon Vigliarolo, and this week we have some rather interesting security stories to talk about concerning yet another Salesforce data breach affecting a whole bunch of companies, the new extortion gang behind them, and the trouble the whole thing has spelled for one of the first companies to point the whole thing out. This week I'm joined by US editor Avram Pilch and security editor Jessica Lyons to talk about this whole mess and more. Welcome to you both. Jessica Lyons (00:29) Good to be here. Avram Piltch (00:30) Hey. Brandon (00:30) Jess, let's start with that Salesforce supply chain attack that you wrote about this week. I understand there was a market intelligence connector of some sort that was behind the incident, right? Jessica Lyons (00:41) Right. So there's this company named Klue, and they provide market intelligence to more than 250,000 users worldwide. And they integrate with Salesforce. And so apparently what happened, on around June 11th, somebody used compromised legacy credentials linked to the Salesforce integration, and then by that they were able to obtain OAuth tokens and then were able to access customers' Salesforce data, Klue customers' Salesforce data from that. Brandon (01:21) Okay, was it data that Klue had on their customers in their Salesforce environment, or they pivoted to the customers' environments as well? Jessica Lyons (01:29) It was through the integration with the Salesforce databases. Brandon (01:34) That's not great. A lot of companies were exposed, and a lot of them in your article you mentioned were security companies. Is that right? Jessica Lyons (01:42) There were a ton of security ones, and then LastPass, this huge password manager. We don't know how many; Klue didn't say. Huntress, which is one of the security companies who was involved in this and who came out on the forefront and said, "Yeah, we were one of the compromised organizations," said it was hundreds. And out of 250,000 users, it could be pretty comprehensive. Avram Piltch (02:12) Do you think this makes Huntress look good? Jessica Lyons (02:17) I think it was admirable that they came out, especially as a security company, and said "we were one of the companies who were victimized." I think that's how any company should respond if they're among the companies affected. Especially if you're a security firm, you have an obligation to be transparent and tell your customers what happened. Brandon (02:43) Legally, in the United States at least, if you've got a breach, you've got to report these things to the government. There's all kinds of cybersecurity reporting standards in place. They are contradictory and overlapping sometimes, but they're there. What kind of data was exposed, Jess? Jessica Lyons (02:57) It was basically CRM data. It wasn't any of the companies' internal IP or anything like that. It was CRM data for pretty much every single company involved across the board. The cybercrime group behind this hack did leak the Huntress data a few days later. And we've heard that they're actually deleting the stolen data from LastPass. That's what LastPass is saying. We don't know if this data is actually not going to exist anymore or if they're just handing it off for other attacks or to other organizations. But it involves CRM data. Brandon (03:49) CRM data then, customer data, from the affected companies too. I'm assuming no financial information was exposed? Jessica Lyons (03:52) No, no financial information. Avram Piltch (04:02) So relatively not that bad for Huntress's reputation when you think about it. Jessica Lyons (04:08) They specifically said it's our business contacts, price quotes, and other sales related data and messaging. They said no threat data, passwords, payment card information, or engineering data related to Huntress Agent or telemetry are affected. That's pretty standard across the board. The companies who did get more specific in their disclosures about what was taken basically lost business data, leads, and contacts. Brandon (04:46) For LastPass, was it just CRM records or were consumers of their password managers affected too? Jessica Lyons (04:55) LastPass customers' data was affected. It was some sale-related data, but also the intruders took customers' names, phone numbers, email addresses, and physical addresses, plus some case support data and then also sales-related data. Brandon (05:13) Right. If you're a LastPass customer, you might want to go in and reset that Master Vault password now. Jessica Lyons (05:18) Big yes, yes, definitely. Brandon (05:22) This didn't involve Shiny Hunters, who've been the de facto kings of Salesforce attacks recently. They weren't involved, right? Jessica Lyons (05:29) Right. No, they weren't involved in that. I think it was what everybody assumed is that you've got Salesforce and you've got OAuth tokens and that just screams Shiny Hunters. They weren't involved. It was a new group called Icarus. They're a new data theft and extortion crew, and they're modeled in the same mold here as Shiny Hunters and Scattered Spider. I was wondering though, is this just a front? According to Shiny Hunters, no, they were not involved. They told me that they were kind of bummed (laughs) that this other group was able to do this. And if it had been them, they would have definitely publicized the fact that it was Shiny Hunters who did this. Brandon (06:15) Yeah, they're not exactly publicity shy. So … I I love the fact that we've got an inside line to them too, that you can be like, "Hey, was this you guys in any way?" And they're like, "No, no, we wish it was." Jessica Lyons (06:26) I think the actual response was, "We wish." Brandon (06:29) Not much is known about Icarus. I think you mentioned a couple of different countries that their IPs might have been linked to, but those very well could have been Tor or VPN exit nodes. We don't even know where they're located. Jessica Lyons (06:43) No, we don't know much about them. Their leak site has been active since late April. We've seen different IP addresses in Europe, but we don't know much about this group at all. Brandon (06:53) These groups change and move so rapidly. Who knows who they are? Are they ransoming this data? Do we know? Jessica Lyons (07:08) Yes, they were ransoming and then leaking some of the data outright. Brandon (07:20) Okay, that's standard MO for a lot of these groups. Speaking of Huntress's early identification of this, that opened up a bit of a Pandora's box for them. Because they had a jilted ex-employee who wasn't thrilled with the response, which you also wrote about. What happened there? Jessica Lyons (07:22) Right. So after Huntress came out and and they said Huntress believes in radical transparency about security incidents, including when it affects our company. That was about the Klue breach. They said that in their blog. A former security operations analyst posted their response on his LinkedIn page along with a Pinocchio GIF. And that just kind of started this whole mess. He says that he was threatened by the company with legal action. He made it very clear this has nothing to do with the Klue incident. He says this stems from an earlier incident that he found out about in December, and because of that incident, he resigned from the company. What he's alleging, and again this is all allegations at this point, is that another Huntress employee who still works for the company passed communications from US law enforcement to a cyber criminal. Now this alleged cyber criminal, according to the ex-employee, is actively targeting his family and him. He says that he can no longer work at Huntress because of this. He says in the next few weeks he's going to provide more proof, including communications and phone calls about what happened here. He says also that this alleged insider was caught by the FBI. I don't know if that means arrested, I don't know if that means questioned, but still continues to work at Huntress. Brandon (09:30) I'm assuming there's no DoJ notice of anything that ties to an arrest of someone who could be involved. Jessica Lyons (09:37) Not at Huntress. No. Not at Huntress. Brandon (09:40) What has Huntress had to say about this whole thing? Jessica Lyons (09:42) The CEO responded to me and also responded on a Reddit post. He acknowledges the concerns raised by this former employee. He said that because of our work as researchers, sometimes we need to communicate with possible cyber criminals to gather intel that supports our partners and customers. He says that he appreciates the former employee's concerns and will continue to investigate the instance. He said a little bit more directly on Reddit that he doesn't understand and he firmly disagrees with these accusations and the insider narrative. Another thing that the former employee also brought up that Huntress is prioritizing an IPO over the safety of its partners, customers, and team members. He said that "sure AF" isn't the case. He's made it very clear that the company disagrees with all of these accusations and they're continuing to work with law enforcement. He said some of this involves legal proceedings, so they can't be completely public about everything. It sounds like a continuing story that we're going to learn more about in the weeks ahead. Brandon (11:15) If this ex-employee has documents to prove his allegations, that's pretty serious. Obviously, yes, you do have to interact with some of the people that you're defending against at a security firm, but passing law enforcement communications to them – I don't see a very good reason for that. Jessica Lyons (11:22) Right. Avram Piltch (11:36) Could this be a misunderstanding about what the employee was doing? Jessica Lyons (11:44) It potentially could, but if he has these communications between law enforcement and the Huntress employee, I don't know how that could be a misunderstanding. It's one thing to talk with cyber criminals, but it's another thing to be passing them information about legal proceedings.... Brandon (12:09) Yeah, or potential operations. We'll see what comes of that. It's going to be interesting to follow that thread. These two stories aside, it seems like we've got a really busy cybersecurity summer so far, even though it is usually a lull. Jess, you were talking about that with one of your sources, right? Jessica Lyons (12:13) Right. Normally everything slows down in the summer, and I was talking to a source and they said they're already calling it the "summer of hell." For the security folks out there, that's pretty accurate. I think a lot of that has to do with AI, to be perfectly honest. Brandon (12:48) Right. Squidbleed, which you wrote about recently, was a Mythos-discovered vulnerability discovered that was old and potentially serious. Jessica Lyons (12:51) Definitely. It's been around since 1997. It was discovered by Mythos, but it was also discovered even before then by IL Security, a European startup. They have their own model that they said found this before Mythos did. You've got this 29-year-old vulnerability, it's existed since 1997. It's in Squid, which is an open source web proxy server. It's a parsing bug and it essentially allows users to access the proxy's active memory. There are a couple key points: it's only unencrypted traffic, so it's cleartext HTTP, and it also requires that Squid has the file transfer protocol, FTP server gateway features turned on. So you have to be using this older vintage technology and protocols. FTP is pretty outdated at this point. Brandon (14:07) It's a vulnerability, but maybe not a serious one. Jessica Lyons (14:11) It's serious if these two conditions are met, because then it's going to expose your password, session tokens, and API keys. Brandon (14:15) Hopefully there are not too many environments where this is the case, but we know from writing about stories like this that every time you say this is a very rare case on old software, you can easily find examples. Avram Piltch (14:33) If you're still using FTP and HTTP on your servers, then you're letting yourself in for a big security problem. That probably isn't your only problem. Brandon (14:39) Yeah, you don't want to say asking for it, but yeah. AI might be discovering these and other problems. We've seen multiple open source projects shut down bug reports because they're getting flooded with AI-discovered issues, some of which are completely legitimate. It feels like this is the summer of AI and cybersecurity convergence. The Trump administration is now haranguing OpenAI, just as much as they've been putting pressure on Anthropic not to go public with models that could be a threat. It feels like a big moment for cybersecurity, and a lot of it's being driven by AI. What do you guys think about the current moment of this pairing? Jessica Lyons (15:23) It's a perfect storm because you have these models that are really good at finding vulnerabilities and developing exploits. That's leading to a bunch of internally, with security companies finding their own bugs and pushing out patches, so then all the sysadmins need to work extra hard. Plus open source, which is a huge issue here, you have all of these bug hunters looking for and finding all kinds of vulnerabilities on open source projects. They push those to maintainers who a lot of times are volunteers themselves and they're not getting paid. There's maybe one of them for this huge project. They have this huge backlog of AI-enabled threat reports that they need to deal with. It's just coming at people from all ends here and yeah, a lot of that's because of the AI models. Brandon (16:35) Is NIST still backed up with the national vulnerability database? Last I heard they were some months behind. Not only that, but we've got a lot of big threats out there that might not be being made public because they're buried too. It's quite the mess. So before we wrap up, I did wanna touch on, like you mentioned, Jess, and and we've seen this in a number of stories that Avram's written recently for the Pwned column. AI is creating a headache for a lot of people, but there's still a group of people that are stuck dealing with this and it's sysadmins, right? It's the security professional, it's the sysadmins, NShuman human problems can still be kind of the root of this. Avram, you wrote a number of stories in your Pwn column that it was it was like all these problems, these security problems come back to bad password hygiene, administrator laziness. I mean, what are some of the things you've kind of seen? Avram Piltch (17:35) Hubris. There was a CEO that wanted to make sure that he could get in and change anybody in the company's email. We could talk about whether that's a good policy in the first place, but his method of doing it was to have an Excel file on his desktop with all of the usernames and passwords of all the employees so that if he sent out an email he shouldn't have, he could go into their inboxes and delete it. But conversely that was a wonderful target for people outside the company to find all the names and passwords they needed, even though there's software out there that will allow an admin to go into an inbox anyway. This was completely unnecessary, but things like that are constantly happening. We had another incident where somebody hadn't deleted a former employee's username and password, perhaps their password was in a breach somewhere or somebody guessed it. But Greg from auditing hadn't worked there in like ten years, but somebody used his credentials to break into a city's water system and start trying to interfere with things having to do with the water supply. The best AI in the world isn't needed to find these problems and couldn't be used to prevent them. The human element is still the biggest problem in security. Maybe when I have my agent talk to your agent, they will be much better behaved than when people get involved. But coming up in a future Pwned column, I talked to a red teamer who said he's basically able to break into almost any facility by acting like he belongs there. Brandon (19:51) That's a classic trick. It's the same thing I've said for a long time about security: you've got new tricks that come up, you've got new things like AI, but there's nothing new under the sun at the end of the day. The best way to gain access to a system isn't to swordfish your way in a la Huge Jackman, it's a con. It's lying, putting on a reflective vest, and having a clipboard. It's relying on password breaches and people being bad about their password hygiene. That's what happened with the Clue issue: an old password that was in a breach somewhere that someone used to get into the system. Nothing new under the sun. Jessica Lyons (20:26) Yeah, we see that all the time. Brandon (20:34) And it's probably going to keep being that way, and I bet we are probably going to be talking about it on the Kettle for months and years to come. Invariably, until AI fully takes over the computer world and we're all just sitting in our WALL-E couches being perpetually entertained by all these sentient machines. But until then, we will be here to talk about these things. Thanks for joining me, guys, and we will see you all again soon. ®

Microsoft keeps Windows Server 2022 hotpatching alive into 2027

Mon, 06/29/2026 - 06:00
Microsoft has extended Windows Server 2022 hotpatching into 2027, beyond the end of mainstream support for the operating system, as confirmed on its Windows Release Health dashboard. Mainstream support for Windows Server 2022 ends on October 13, 2026, with extended support running to October 14, 2031. Hotpatching generally ends with mainstream support, but Microsoft will keep updates flowing into next year for Windows Server 2022 Datacenter: Azure Edition - likely mindful of users who depend on the technology. Hotpatching is a boon for Windows Server administrators, allowing security updates to be applied without scheduled server downtime. There's still a cumulative update once a quarter that requires a reboot, but otherwise the relentless monthly reboots required by Microsoft's updates are avoided. According to Microsoft, the technology works by patching the in-memory code of a running process. This means no restart is needed. Linux administrators might point to tools like Ksplice, which can apply patches to a running kernel without requiring a reboot, but anything that reduces the time between the discovery of a vulnerability and patching is a good idea. Microsoft would prefer administrators move to Windows Server 2025, the latest Long Term Servicing Channel (LTSC) release, but the extension gives Azure Edition users a reprieve from monthly reboots until 2027. The hotpatching extension only applies to Windows Server 2022 Datacenter: Azure Edition. On-premises Windows Server 2022 users remain out of luck, though Microsoft has never been shy about nudging users toward Azure. Hotpatch updates were also introduced for Windows 11 24H2 Enterprise clients in public preview in 2024 and are now the default for Windows Autopatch.®

Blue Origin insists New Glenn will rise from the ashes this year after explosion deleted launchpad

Mon, 06/29/2026 - 05:30
Blue Origin's boss has reiterated that the Jeff Bezos-owned space biz will return to flight this year after an explosion destroyed a New Glenn rocket and severely damaged its launchpad. CEO Dave Limp last week used X to praise workers who have been clearing the wreckage from Launch Complex 36. "We have started reconstruction and still plan to fly again this year," he said. Over the weekend, Limp posted a video showing the assembly of a crane beside the launchpad's tower, which is being dismantled for repairs. Time is of the essence. At the end of May, a New Glenn rocket exploded during a static fire test at Cape Canaveral Space Force Station's Launch Complex 36 in Florida. In addition to destroying the rocket, the site – Blue Origin's only New Glenn launch complex – was severely damaged. The scale of the damage makes resuming launches in 2026 seem optimistic. The explosion of a SpaceX Falcon 9 at Space Launch Complex 40 in 2016 left the facility out of use for more than a year before launches resumed. However, Limp's posts indicate Blue Origin is still aiming to return to flight before 2027. Blue Origin's New Glenn is required to loft the company's lunar lander for an in-orbit demonstration during Artemis III, which NASA has tabled for 2027. The mission aims to rendezvous with lunar landing tech supplied by SpaceX and Blue Origin. For SpaceX, this is currently a Starship with a docking adapter on its nose, although Starship has yet to reach orbit. Blue Origin plans to provide a more functionally complete lander that astronauts can enter during the demonstration. That depends on Blue Origin being able to launch it. The size and propulsion requirements mean it is not simply a matter of sticking it on another rocket. If Limp's estimates are correct, there would be little point in other companies making the necessary adaptations. Blue Origin is not the only company affected by the New Glenn explosion. The cause remains unclear, but until the rocket's BE-4 engines are cleared for flight, a question mark likely hangs over the United Launch Alliance (ULA) Vulcan Centaur, which also uses them. That said, ULA has its own problems. The Vulcan Centaur has experienced several solid rocket booster nozzle "anomalies" during its life, the most recent of which occurred in February. However, it did not prevent the payload from being delivered as planned. The US Space Force later decided to pause national security launches on the rocket until the issue was resolved. ®

BT and Verizon spin off international networking arms into $4B joint venture

Mon, 06/29/2026 - 04:45
BT and Verizon are putting their international enterprise networking businesses into a 50:50 joint venture, creating a company with roughly $4 billion in annual revenue as both telcos re-focus on the markets that actually make them money. The proposed venture, announced on Monday, will combine BT International with Verizon's international enterprise wireline business. Once regulators sign off, the new company will serve more than 3,000 multinational customers across 180 countries, while its two parents return their attention to the markets that actually move the needle: Britain for BT and the US for Verizon. Verizon will pay BT $625 million to balance the relative value of the assets each side is contributing. The transaction is expected to close in 2027. For BT, the move removes a business that has long looked like the awkward relative in the family photo. BT's guidance for the year ending March 2027 forecasts £1.82 billion in international revenue but just £108 million in adjusted EBITDA, making it one of the group's weakest performers. Tom Oughton, analyst at Megabuyte, described the deal as strategically sensible for both companies, noting that BT International has been "a consistent underperformer" while Verizon has repeatedly characterized its own international revenues as insignificant relative to its domestic business. “BT International has always been a drag on BT Group. It is far less profitable (BT reports a 47 percent UK EBTDA margin vs 5.9 percent for International) and has failed to grow, and we suspect a somewhat similar story for Verizon given it is immaterial relative to its US operations,” Oughton said. Of course, the official line isn't about squeezing costs. BT and Verizon say the real prize is helping multinational customers navigate cloud infrastructure and the growing tangle of data residency rules. That also explains why nearly every paragraph of the announcement manages to mention AI. BT chief executive Allison Kirkby said the combination would create "a stronger, scaled connectivity partner" offering secure and resilient connectivity platforms "designed for the age of AI." Verizon chief exec Dan Schulman similarly described the venture as a "cutting-edge, AI-ready and secure platform." Strip away the AI messaging and the strategy is pretty straightforward. Combining two middling international operations creates more scale, reduces duplicated infrastructure and operations, and gives both companies a chance to concentrate investment where they still dominate. The joint venture will be incorporated in Jersey, although it will be headquartered and tax resident in the UK. Former EXA Infrastructure chief executive Martijn Blanken has been named CEO-designate, subject to the deal completing, while BT International chief executive Clive Selley will remain in place until then. BT also updated its financial guidance to reflect the carve-out. Excluding the international business and other disposals, it stuck with its target of doubling free cash flow to £3 billion by the end of the decade. For customers, not much will change immediately. BT International and Verizon's international operations will continue to run independently until regulators approve the deal and the joint venture officially opens its doors. ®

Nissan says Oracle PeopleSoft break-in may have spilled payroll records, SSNs

Mon, 06/29/2026 - 04:14
Nissan has joined the growing list of Oracle customers cleaning up after a cyberattack, warning employees that payroll records, bank details, Social Security numbers, and other personal data may have been stolen. In a filing submitted to the California Attorney General on Friday, Nissan Americas said Oracle had informed it of "a cyber event" involving the personnel records of "hundreds of companies." The automaker said it later learned Nissan had been "specifically targeted" in the attack. A notification sent to current and former employees, seen by The Register, says the company believes attackers accessed a haul of sensitive info, including contact and banking information; Social Security, Social Insurance, or other national identification numbers; financial and tax records; and dependent and beneficiary details. Current and former employees in the US, Canada, Mexico, and Brazil may have been affected, although Nissan said it is still working to determine exactly whose information was exposed. Nissan said it kicked off its incident response plan after learning of the intrusion, brought in outside security specialists, and has been working with Oracle while keeping law enforcement informed. It plans to offer affected individuals credit or dark web monitoring where available. The company has also put a few extra locks on the payroll office. Employees can now access pay slips or update direct deposit details only from a corporate network or through a secure VPN, while Nissan adds extra identity checks before processing payroll requests. The accompanying employee FAQ pins the incident on "an unknown vulnerability in Oracle's PeopleSoft software" and says the campaign is affecting "hundreds of companies and institutions." The document offers no clue as to what the vulnerability is, whether Oracle has patched it, or whether the compromised PeopleSoft environment was hosted by Oracle or by Nissan itself. The disclosure lands just weeks after researchers linked the ShinyHunters extortion crew to a wave of attacks exploiting a PeopleSoft zero-day. More than 100 organizations and roughly 300 PeopleSoft instances were reportedly compromised before Oracle issued mitigation measures, with the gang claiming to have made off with HR, payroll, and other enterprise data. Oracle has said little publicly about the reported attacks and didn't respond to The Register's questions, even as organizations have continued to disclose being caught in the fallout. Nissan has not confirmed that the incidents are connected, though its California filing lists the breach period as May 27 through June 9, broadly aligning with the previously reported timeline. The carmaker didn't respond to questions about how many current and former employees are affected, when Oracle first notified it of the breach, and whether the compromise was limited to Oracle-managed systems. ®

Zuck saves Meta bucks by reusing memory from old servers with a custom CXL ASIC

Mon, 06/29/2026 - 03:43
Meta is recovering DDR4 memory from old servers, installing it in new machines, and using a custom Compute Express Link (CXL) ASIC to share the memory across applications – without encountering latency problems. The social networking giant calls its tech "Vistara" and will present it at ISCA 2026 on Monday, but The Register found the company's paper ahead of the talk. The document opens with the admission that Meta can't increase the amount of memory in around 40 percent of its vast server fleet, meaning millions of servers can't handle some of its workloads. That's unfortunate because the expected service life of its servers is three to five years, but memory is useful for seven to ten years. Meta's response is to rip DDR4 DIMMs from old servers, put them into new machines that rely on DDR5, and turn it all into a pool of capacity – which in theory makes it possible to compose virtual servers that share resources across multiple physical hosts. The paper points out that CXL is hard to put into production because sharing memory across hosts can mean low bandwidth, high latency, and extra computing overheads to manage additional memory layers. Those problems can arise in systems that combine different memory technologies. Meta wanted to blend memory types in a single machine but found off-the-shelf CXL kit can't do the job. "Most CXL solutions bundle DRAM with the controller – preventing DIMM reuse – and often omit DDR4 support, which is a requirement for repurposing older memory," the paper states. "Additionally, their high power consumption and high cost further limit their appeal." To make CXL sing, Meta created a custom ASIC called "Vistara." "At its core, the Vistara ASIC is designed to bridge DDR4 memory to host processors via a CXL 2.0/1.1-compliant PCIe Gen5 x16 interface," the paper explains. "Each Vistara ASIC integrates two independent 72-bit DDR4 memory channels, supporting speeds up to 3,200 MT/s and up to 256 GB per chip with 64 GB DIMMs." A pair of custom RISC-V processors drive the ASICs. Vistara hardware lives in devices Meta calls a "MemServer" powered by an AMD Turin processor packing 158 cores and running 316 threads. Each MemServer combines 768 GB of DDR5 memory alongside 256 GB of DDR4 connected through Vistara ASICs. "The Vistara CXL cards are installed in dedicated rear-accessible slots within each MemServer chassis," the paper reveals. "To manage the increased thermal load from high-density memory and CXL devices, the chassis employs directed airflow with high-capacity fans that channel cool air directly across the Vistara modules, for stable operation under heavy workloads." The software side of Vistara sees the DDR4 presented to the OS "as a distinct, CPU-less NUMA node, separate from the local DRAM nodes directly attached to the processor." Meta's platforms first use all available local DDR4, then employ the CXL-enabled memory when needed. Zuck's house of hyperscale hypnotism makes this happen with custom tweaks to the Linux CXL driver. "All Linux kernel CXL driver code in use for Vistara is either present in the upstream kernel, or is on its way to being included in the upstream kernel," the paper states. The paper says Meta has put this CXL stuff to work "in hyperscale infrastructure with millions of servers, across a variety of production workloads, including disaggregated ML inference (embedding tables in recommendation systems), big data processing, databases, distributed caches, and CI/CD build systems." Some workloads, including big data tools such as Spark and Hive, use terabyte and petabyte-scale datasets, and need hundreds of gigabytes of memory per job. The paper says that if those workloads experience out-of-memory events, it can "disrupt critical business analytics and ML pipelines." "The expanded memory headroom provided by CXL enhances system reliability," the paper explains. "By mitigating the risk of out-of-memory (OOM) events, CXL reduces the frequency of job failures and the associated overhead of job restarts and resource fragmentation by 33 percent." Meta says the system also cuts infrastructure costs. "These deployments have demonstrated large benefits, such as reducing the server count by up to 25 percent for disaggregated inference," the paper states. And of course Meta is avoiding the sky-high memory prices caused by the RAMpocalypse. ®

ZTE released all-in-one FTTR-B solution for SME AI and connectivity at MWC Shanghai 2026

Mon, 06/29/2026 - 03:10
ZTE recently unveiled its AI-Powered Enterprise-Grade FTTR-B Gateway and unified all-in-one enterprise solution at MWC Shanghai 2026. The new product ushers in a new era of integrated enterprise networking and intelligent digital management, delivering streamlined, secure and high-efficiency digital infrastructure tailored for global small and medium-sized enterprises (SMEs). As businesses face escalating operational complexities, the need for a seamless, all-in-one infrastructure has never been more critical. At the same time, while rapid advances in AI open unprecedented opportunities, turning it into a practical business tool remains far from simple. Engineered precisely to bridge this gap, this new release sets a bold benchmark for enterprise networking. By seamlessly integrating secure, localized AI with all-optical, high-performance networking and smart security care into a unified system, it redefines operational efficiency from day one. Through plug-and-play deployment and centralized management, the solution dissolves the friction of isolated systems, delivering the ultimate simplicity and agility modern businesses demand. At first glance, the system redefines operational efficiency from the ground up by seamlessly integrating localized AI, high-speed networking, and smart security care. This robust foundation is driven by a 2000 M dedicated cloud access, Wi-Fi 7, and intelligent slicing, optimizing the solution for high-density office environments to ensure smooth, reliable performance for both mission-critical operations and AI workloads. Capitalizing on this network, the system's high-performance computing engine supports the real-time analysis of over 50 simultaneous high-definition video streams, powered by more than 20 industry-leading AI recognition algorithms. Together, these intelligent predictive capabilities empower enterprises to elevate their security operations, risk prevention, and overall management efficiency. Beyond simplicity, the true strength of the system lies in its ability to power local AI large models directly on enterprise devices rather than relying on the cloud. By integrating this on-premise AI into core business operations, from automated customer service to intelligent financial operations, businesses can seamlessly scale a highly efficient digital workforce. Such a localized approach not only cuts the massive cost of third-party cloud APIs but also keeps sensitive corporate data completely secure. In doing so, by dissolving the traditional friction between disconnected systems, centralized control eliminates the headache of IT management, giving modern enterprises a faster, simpler way to scale. Ultimately, to sustain this highly automated digital workforce, the entire infrastructure is safeguarded by an uncompromising layer of defense. Recognizing that intelligence and connectivity require absolute protection, Co-Claw's robust security hardening and access control mechanisms ensure that every layer of the AI and networking ecosystem is thoroughly safeguarded. This trusted foundation mitigates vulnerabilities proactively, allowing enterprises to scale their digital operations with total peace of mind. With this launch, the ZTE AI-Powered Enterprise-Grade FTTR-B Gateway not only addresses the immediate pain points of deployment and overhead but also empowers organizations to build a resilient, future-ready foundation that safely scales alongside their ambitions. Moving forward, ZTE remains dedicated to serving global customers and delivering continuous innovation tailored for small and medium-sized enterprises (SMEs), fueling their digital transformation every step of the way. Contributed by ZTE.

ZTE released AI FTTR solution, empowering home network security

Mon, 06/29/2026 - 03:04
ZTE recently showcased its innovative AI-powered Fiber-to-the-Home (FTTR) Solution at MWC Shanghai 2026, bringing intelligent, secure and all-scenario home network upgrades to global users and marking a major breakthrough in smart home network security and intelligent iteration. More than just a Wi-Fi gateway, this sleek, multifunctional device integrates a 10.95 inch magnetic detachable display, HD camera, smart speaker, and 8K media decoder, offering seamless adaptability across work, study, entertainment, and home care scenarios. Its portable, rotatable design ensures convenience, while high-performance hardware — including a 6 TOPS NPU and distributed NAS storage — empowers local AI computing and large-capacity data processing, making it the ultimate hub for AI-powered home experiences. At the heart of this device is OpenClaw full-stack AI ecosystem, enabling on-device AI agents that provide autonomous decision-making and proactive services. With capabilities such as persistent memory, scheduled tasks, visual behavior recognition, and multi-device collaborative reasoning, the system intelligently manages daily life — from monitoring children's sitting posture and reminding users of appointments to planning health routines and conducting autonomous home security patrols. Security is redefined through AI-powered DDoS/CC attack protection, using lightweight Temporal Convolutional Networks (TCN) to analyze traffic patterns in real time. By learning normal network behavior over seven days, the system builds device-specific fingerprints and detects anomalies — such as unusual traffic bursts or unknown IP communications — with an ultra-low false alarm rate of lower than 0.1%. It also features AI-based IoT security hardening, including device fingerprinting, vulnerability detection, and behavioral monitoring, effectively preventing hijacking of smart devices. Unique to this solution is its camera-free presence sensing, which delivers whole-home awareness for elderly care and child safety without compromising privacy. All AI processing happens locally, ensuring sensitive data never leaves the home. For service providers, AI FTTR unlocks new revenue streams by seamlessly integrating with value-added services like cloud storage, smart surveillance, Wi-Fi security, and whole-home automation. By merging ultra-fast FTTR networks, edge AI computing, and intelligent perception, ZTE's AI FTTR isn't just advancing home networking — it's redefining what a smart and secure home can be. Contributed by ZTE.

End of era as the BBC switches off Radio 4 Long Wave service

Mon, 06/29/2026 - 03:00
The BBC called time on Radio 4 Long Wave broadcasts and, unlike the waves of hot weather sweeping across Europe, the service is unlikely to make a comeback any time soon. This is the UK's last long wave radio station in the UK, and the station permanently terminated broadcasts on the service at 0100 BST on June 27. The Long Wave platform is set to close on June 30. It has been a while coming – the BBC first announced it expected Long Wave to close in 2022, and in March 2024, the corporation called a halt to separate scheduling on Radio 4 Long Wave. Radio 4 itself will, of course, continue broadcasting on other infrastructure, as it has over the years. Imagine the outcry if the long-running drama The Archers was to come to an abrupt end. According to the Beeb, "The Long Wave infrastructure is owned and operated by a third party who have advised us the platform is now coming to the end of its life as a technology. "Continuing would require significant investment to replace ageing equipment and sustain a platform now used by a very small proportion of listeners." Since Long Wave is not considered Critical National Infrastructure, keeping the service going is not a requirement, and so the ax has fallen. FM, DAB, and internet services might reach the vast majority of the UK's population, yet Long Wave has endured for remote or rural communities, or the maritime world. For the latter, the BBC stated: "The Shipping Forecast does not constitute part of the UK's mandatory Maritime Safety Information (MSI) service; it has always been a UK-specific, complementary broadcast. MSI is considered of vital concern to all vessels, and the Maritime and Coastguard Agency encourage all seafarers to make every effort to receive it." As for the former, "We also work closely with organizations that support vulnerable audiences around platform closures, to ensure listeners are helped in a timely and sensitive way. "FM remains the main fallback option and is available to 99.5 percent of UK households." The Long Wave service is historically associated with a set of masts at Droitwich transmitting station in the Worcestershire countryside. A pair of additional stations were constructed in Scotland, in Westerglen and Burghead. All three are more than 90 years old, and transmission from Droitwich began in 1934. A campaign has begun to list the structures in historic preservation on the recognized heritage register. This process would recognize the Droitwich masts as having historic interest and therefore make altering or demolishing them considerably more difficult. This hack well remembers being huddled under the blankets with a wireless set, listening to crackly Long Wave transmissions. Long Wave also played an important role in the Second World War, and, more recently, the 198kHz signal was used to control off-peak energy meters. However, considering the age of the infrastructure and the expense of keeping it going in the face of alternatives, the end was inevitable. The Shipping Forecast, which is deeply ingrained in the psyche of Brits of a certain age, will continue on other platforms, and mariners can access information by satellite. ®

UK firm bombarded debt-ridden people with 5.5M texts

Mon, 06/29/2026 - 02:15
"Am I confident on the data set? As long as I'm doing the cases, I don't really give a f*** if it's old as long as it's making money." According to the UK's Information Commissioner's Office (ICO), this was part of a message sent by the director of a company fined for targeting financially vulnerable people with unlawful texts, including fake bailiff messages. The message, sent by KRA Consultancy Ltd (KRA) director Khuram Rezvan Ahmad, appeared in the watchdog's monetary penalty notice, which said the firm did not check "the loan decline data was accurate" or whether the recipients had consented to receive marketing messages. The regulator fined KRA £300,000 last week, saying it had targeted people who were already in financial difficulty and had been turned down for loans. The watchdog described the operation as a "calculated, unlawful scheme," saying the fake bailiff messages had left recipients fearing that bailiffs were coming to their homes to remove their family's belongings. The ICO said KRA sent fabricated bailiff threats in the hope of scaring recipients so much that they would then engage with the company's debt services. The fake messages were sent using the sender ID "DEMAND." It read: "We have attempted on numerous occasions to contact you without any success. This matter has escalated further and an Enforcement agent will attend ****** within 48 hours to remove your goods as per Court Order. If you are on any legal/debt plan you will need proof readily available." The ICO also claimed the company deliberately tried to evade detection. It alleged that Ahmad had contacted a telecoms provider based in China and sought assurances from the telco that the mass text messages would be "completely untraceable." KRA promoted debt "solutions" to people, sending 5,575,715 unsolicited direct marketing texts between April 2022 and May 2025, the watchdog said. The campaign generated more than 60,000 complaints to the ICO and Mobile UK's 7726 spam-reporting service. The company was not registered with the Financial Conduct Authority, despite directing people towards debt solutions, the ICO added. In internal WhatsApp messages uncovered during its investigation, the ICO said Ahmad used the term "coaching" as a euphemism for the threats. "Get through as much as and pitch whatever. Don’t worry about forcing anything back because the coaching will take care of that tomorrow morning." During the ICO's investigation, search warrants were executed at KRA's offices and Ahmad’s home. The watchdog said KRA resumed its unlawful marketing activity following the searches, leading to 161 new complaints. Andy Curry, head of investigations at the ICO, said: "People in financial difficulty deserve support, not exploitation. KRA deliberately sought these people out – knowing they might be especially susceptible to this kind of high-pressure marketing – and bombarded them with illegal texts. When that wasn't enough, it sent fake threats telling people bailiffs were coming to their homes to remove their belongings. This was a calculated, unlawful scheme, and it caused real fear and distress to people who were already struggling with debt. "KRA showed complete disregard for the law throughout our investigation and this £300,000 fine – one of the largest for nuisance marketing in recent years – reflects that. It should leave no doubt that we will pursue any company that thinks it can evade the law and prey on the public." Alongside the Monetary Penalty, the ICO also issued KRA with an Enforcement Notice, ordering the company to stop sending marketing messages without consent within 30 days. ®

Telling internet platforms where to stick public service media will serve nobody. Turn it on its head

Mon, 06/29/2026 - 01:28
OPINION Microsoft is making massive progress in quantum computing, says Microsoft. Oh no they're not, say researchers. Anthropic's frontier models are too powerful for general use, says the US government. No, it's just Anthropic being punished for not doing what the US government tells them, say critics. Humans-in-the-loop are a pain-in-the-neck, says Amazon exec. Go do one, says this human. Three tech news stories from last week, six interpretations. You can probably decide between Microsoft PR and a peer-reviewed paper in Nature. Likewise, whether vindictiveness or virtue is at work with Anthropic. Amazon or a Reg hack? Harder to call. In all these cases, as in all cases, prior knowledge is the best context in which to judge media reports. Most citizens don't know much about most news, an eternal truth that is causing the UK government to fret about the future of public service broadcasting – or as it has become, public service media (PSM). With fewer people, especially that dread tribe, Young People, watching the wholesome fare of highly regulated broadcasters but feeding instead on firehoses of algo-spew, public service media risks suffocating on insignificance. That's a reasonable fear, if you feel that public service media deserves to be heard. It is a complicated argument where great forces have clashed since the birth of broadcasting, but if you know that the rhetoric of "fake news" has an antecedent in the German slur "Lügenpresse," you'll know the answer is yes, and yes, with a side order of yes. Vivat Reith. Having identified the problem, the brains of Britgov propose exactly the wrong solution. Get the algorithms that drive content consumption on social media to rank the quality PSM product higher. All those lost eyeballs will be brought back into the fold. This won't work for reasons both obvious and subtle. Forcing a quota of state-mandated media into the stream, even with the best of intentions, is a hostage to fortune. It's probably unenforceable, will be deeply unpopular with users and companies alike, and will poison PSM across the board. It also amplifies two falsehoods about PSM: that it's about news, and that it's about numbers. Both are important, but neither is anywhere near enough to argue for PSM's right to life. One of PSM's primary roles is to provide content that isn't commercially viable or is otherwise invisible. That reflects culture, art, science, all the human stuff that enriches life. It's where new ideas and new people come from, and some of those will become box-office hits. Putting numbers first, as parts of the BBC are moving toward, kills diversity and gives the commercial sector the killer argument that PSM is just unfair competition. PSM has always had the tension between being popular enough to matter to lots of people and broad enough to do the things that only it can do, but it does need both. That has been very expensive, but arguably worth it. High-quality news is one pillar of that, but only one. The one thing that keeps PSM alive is the editorial process, the decision-making that understands the purpose, constituent parts, and audiences, and applies that equation to the resources available. Those resources have changed, but they haven't gone away. What's needed now isn't a public service tweak to secret commercial algorithms, but a public service algorithm with humans in the loop, amplifying the good stuff on the platforms by driving traffic through exposure. How to design channels that do that and are compatible with the platforms themselves is an interesting challenge begging to be explored. However realized, it would be entirely compatible with providing natively sourced news, entertainment, sport, and everything else that keeps a brand current. It adapts seamlessly to multiple platforms, all of which have PSM-worthy content in quantity, if you filter out the toxins. It's a model that scales up and down, provided only that there are sufficient motivated and trained editorial staff who know who they're serving and why. There have to be ethical standards, transparency, training and support, and just the right level of management. That would turn the threat of the new media environment into a huge promise, all the techniques of distributed, diverse digital content from adversary to amplification. Public service broadcasting, at least in the UK, has been moving in this direction for decades, in the name of efficiency, outsourcing more and more programming to independent production companies – usually staffed by ex-BBC employees. You can't move very far in TV, radio, film, or digital media in the UK without tripping over ex-BBC bodies. That's another role of PSM, creating a huge pool of talent that irrigates an entire economic sector. A PSM strategy that encourages content creators to align with production and editorial standards would have invigorating effects in the new landscape. Public service media deserves to survive and thrive in an attention economy driven by so many forces designed to exploit rather than enlighten the public. Done well, it gives voice to the voiceless, describes a nation to itself, and sets standards that inspire trust and quench cynicism. All of this is there to be had, even today, even in the future. We just need to keep the right humans in the loop. Sorry, Amazon. ®

Sysadmin broke hardware worth more than he made in a month – and lied his way out of the mess

Sun, 06/28/2026 - 23:28
WHO, ME? The world of work is basically broken, which is why The Register uses Monday mornings to remind readers of that foul fact in a new instalment of “Who, Me?” – the reader-contributed column that shares your mistakes and reveals how you recovered from them. This week, meet a reader we’ll Regomize as “Hank” who told us his career started in the 1990s with a gig as sysadmin for a small town poultry factory that was an outpost for a larger company. “I was brimming with excitement to work on the latest tech, Novell NetWare 4.1!” he told The Register. One of the first things Hank was asked to do was a storage upgrade for a pair of servers. “We bought a pair of very expensive 750MB disks and since I was the sole IT person at the plant, head office sent me the drives and put me in charge of the upgrade.” Hank was excited when the drives arrived, so he unboxed them and spent a little time fondling what was then just about the most capacious and expensive storage device money could buy. “Who would not want to touch 750MB SCSI drives with blazing fast reads courtesy of 10,000 RPM spindles?” he asked. “It was cutting edge!” It was also rather slippery, because after removing one of the drives from its anti-static bag, Hank dropped it. “Panic set it shortly after,” he admitted. “This drive was worth more than I made in a month. I was still new and on probation. Visions of unemployment and having to move back in with my parents danced through my head.” Hank’s solution was to tell a big fat lie. “I called my boss told them I thought one of the drives was making a strange sound and might have an issue.” Then Hank played his trump card, offering the wise-beyond-his-years suggestion that it would be a waste of time to do the upgrade with a bad drive. His boss agreed and told Hank how to contact the vendor to have a new drive delivered overnight. “The new drive arrived the next day and the upgrade went off without a hitch,” Hank said. “And I learned to sit down when handling expensive hardware.” Have you broken hardware and blamed it on something else? If so, break your mouse by clicking here to send email to Who, Me? We’d love the chance to share your story! ®

Malaysia ponders regulating management of IP addresses

Sun, 06/28/2026 - 20:51
Wants to revive the lost art of the National Internet Registry, which APNIC has deprecated and isn’t keen to bring back The government of Malaysia has commenced a consultation on whether it should regulate management of IP addresses and autonomous systems numbers, over objections from regional internet registry the Asian Pacific Network Information Center (APNIC). Malaysia announced its consultation in June, when the nation’s Communications and Multimedia Commission (MCMC) posted a paper [PDF] in which it explains that a lot has happened since passage of the 1998 Act that governs its activities – so it probably needs an update. One of the proposed changes would see Malaysia create a statutory authority with the power to manage electronic addressing “including the management of IP addresses, AS numbers and associated fees.” “This is to support the development of a National Internet Registry model and to ensure a transparent and sustainable administration of electronic addressing resources in Malaysia which will be overseen by the Commission,” the consultation paper states. “This will contribute to a more robust and well-governed digital infrastructure environment in Malaysia.” APNIC says its talks with the MCMC saw the Malaysian entity express a desire for “full operational and technical autonomy over resource assignments” – powers that existing NIRs don’t have. National Internet Registries (NIRs) are a relic of the time before regional internet registries came into being. Only APNIC and LACNIC, the Latin American and Caribbean Internet Addresses Registry, allowed NIRs – and only nine exist, covering China, India, Indonesia, Japan, Korea, Taiwan, Vietnam, Mexico, and Brazil. APNIC stopped accepting applications for new NIRs in 2012, and in 2024 made the moratorium on new applications permanent. In 2024, APNIC’s executive chair Kenny Huang explained: “NIRs are a historical feature of the APNIC membership structure, recognizing that some IP address registries were already operating at a national or economy level when APNIC started, and some were in formation.” “In the past, particularly while IPv4 address space was being rapidly allocated and needed careful management, NIRs provided important support to a fast-growing Internet with high demand for number resources and registry services.” The internet governance community long ago decided that internet resource distribution and management works best when handled by sizable organizations which operate at regional scale, and that if every country had an NIR it would create unhelpful risks and overlapping authorities. If Malaysia presses ahead with its desire to create its own National Internet Registry (NIR) and have it assume some of APNIC’s functions, it will therefore challenge the status quo. If it actually gets an NIR into operation, that would likely revive debate about whether national governments should have a role in allocating internet resources given the potential for such power to be used for political purposes such as denying resources to groups that a government opposes. The United Nations last year had its say on that idea by re-affirming its support for multi-stakeholder governance under which governments are one of many voices that participate in debate about the future of the internet. Kenny Huang has written [PDF] to the Communications and Multimedia Commission (MCMC), pointing out that it’s currently not possible to create a new NIR and that APNIC won’t revisit its policy on the matter – but he also notes that it’s always possible to commence a consultation and policy process that would see APNIC debate a new position. But that process could only start after the conclusion of work on ICP-2, the major revision of the rules that govern the operation of RIRs. The current ICP-2 timeline calls for a revised document to be in place by the end of 2026. If MCMC decides to pursue creation of an NIR, it will be in conflict on a collision course with APNIC. In the past, most collisions in the world of internet governance occurred at low speed and involved mostly civil debate that plays out over years. ®

Australia investigating five social media giants for not enforcing ban on kids

Sun, 06/28/2026 - 18:22
Australia’s government has decided to double the fines it can levy companies that don’t take appropriate steps to enforce the country’s ban on children under 16 accessing social media – and said Facebook, Instagram, Snapchat, TikTok and YouTube are under investigation for possible non-compliance. The decision to increase fines came after publication of a study that found around 80 percent of kids in Australia continue to use social media despite the ban, mostly because age verification tech hasn’t blocked their accounts. Prime Minister Anthony Albanese on Sunday announced the increased fines, saying that while social media companies have deactivated or restricted access to five million accounts since the ban came into force last December. The PM thinks that’s a decent start but feels Australia’s cyber-regulator, eSafety, “needs more tools in their belt to take on these billion-dollar social media companies and hold them to account.” Those tools include the ability to demand information about a platform’s attempts to enforce the ban, including third-party information from age assurance or app-store providers. “Social media companies have a social responsibility, and they must uphold their legal responsibility in Australia to keep under 16s off social media,” Albanese said. The new fines can reach AU$99 million ($68.25 million) for systemic failures – back of the sofa money for the social media giants. Qualcomm builds throttled-for-China datacenter chips Qualcomm last week launched a new range of datacenter chips, and CEO Cristiano Amon later told Japanese outlet Nikkei the company has already created versions of them compliant with US export rules. “There are very clear guidelines about how you can ship products to China, and we have versions of all of our products that comply with those guidelines, " he said. "We are engaged in conversations and are positively optimistic about the reaction we're getting." Rumors suggest Chinese social media giant ByteDance might be one source of those positive reactions. Chinese chip champ delivers another modest machine Chinese chip designer Loongson has delivered another server CPU that won’t scare AMD or Intel. The 16-core Loongson 3C3000 hums along at 1.5 to 1.8GHz while consuming 40 watts. It uses Loongson’s proprietary instruction set architecture that draws on MIPS and RISC technology. Chinese media report that each core packs 64KB of private L1 instruction cache and 64KB of private L1 data cache, and that the chip shares 16MB of L2 cache among all cores. The memory controller is 2×72-bit DDR4-2400, supporting ECC verification. The company says it’s a low-cost CPU suited to everyday workloads such as file servers, database servers or web servers. Intel and AMD continue to make 16-core server CPUs, but with faster clock speeds and superior specs compared to the latest Loongson offering. The one thing those American CPUs lack is Beijing’s blessing: China’s government encourages local organizations to buy Chinese hardware whenever possible. Japan extends Air Force’s mission into space Japan’s government last week ordered a name change and re-org for its Air Self-Defense Force, which as of next year will be renamed the "Aerospace Self-Defense Force." Defense Minister Shinjiro Koizumi said the changes are needed because reliance on space-based services like GPS navigation mean Japan needs to defend its orbital interests. The re-org means Japan’s government will upgrade its Space Operations Squadron into a full Space Operations Command, staffed by 880 personnel. Japan is one of just ten nations – plus the European Union – that has the capability to launch payloads into orbit. Iran’s internet ends in tiers Internet Governance Researcher Imad Payande has published updated research on the state of Iran’s internet, which he says now offers tiers of access to different users. “In the first one to two weeks of the conflict, relatively unrestricted connectivity appeared limited to specific groups – primarily journalists and individuals with institutional affiliations. For the broader population, access to the global Internet was largely unavailable,” he wrote. In the second week of the war he saw “configurations” go on sale – “custom connection profiles enabling access to the open Internet.” Payande said those connections “relied on alternative protocols and tools rather than standard VPNs, suggesting a different underlying infrastructure and possibly a limited number of controlled gateways.” “Alongside these informal markets, more institutionalized models of access emerged. Telecom operators introduced restricted SIM cards under frameworks often described as ‘Pro Internet.’ These were made available to selected users – such as companies and researchers – through screening processes. However, access remained limited to a narrow set of services, prioritizing stability over openness.” He thinks Iran’s government now regulates internet access at the infrastructure level, with access allowed for some and not for others. And those who can get online pay for the privilege. Another week, another WiseTech mess Already beset by allegations of CEO sleaze, odd share trades, and human trafficking, Australian SaaSy logistics outfit WiseTech now has major software flaws to address. Infosec outfit Searchlight Cyber last week published research after finding hard-coded master keys in the company’s products that made it possible for an attacker to log in without a password and impersonate real customers and partners – and then enjoy access to data such as financial documents and contact details for users’ staff. Searchlight Cyber says its researchers informed WiseTech of the vulnerabilities prior to publication, and that the Australian company made a round of fixes but is “still working on further mitigations.” ®

Boffins build a better pixel capable of emitting and receiving light

Sun, 06/28/2026 - 09:00
Researchers affiliated with ETH Zurich have devised a multifunction picture element, or pixel, that can both emit and measure light. Traditional pixels generally do one or the other – illuminating a display screen or capturing light in a camera sensor. A team led by David Norris, professor at ETH Zurich's Optical Materials Engineering Laboratory, has found a way to combine the two functions. The research raises the possibility of two-way screens that take and present pictures, holographic displays, optical communication systems, and quantum information processing. As described in the Nature article "Fourier pixels for bidirectional light control," the ETH Zurich boffins developed a technique that involves measuring light wave interference patterns over a metallic surface. By doing so, they're able to generate "Fourier pixels" that can create and detect the amplitude, phase and polarization of optical fields. The Fourier transform is a mathematical technique that takes a function like a sound wave and returns a function representing the specific frequencies present in that sound. A Fourier pixel represents the spatial frequency of light rather than the specific brightness at a given point in an image. "Thanks to the fact that the relevant surface profiles of the pixels can be determined using Fourier analysis, we can combine the control and analysis of amplitude, phase and polarisation on a single pixel," said post-doc Sander Vonk in an ETH Zurich press release. In the near term, Norris expects to put Fourier pixels into a matrix that can be used to construct more sophisticated camera displays. The other authors included Yannik M. Glauser, David B. Seda, Hannah Niese, Boris de Jong, Matthieu F. Bidaut, Daniel Petter, Erwan Bossavit, Gabriel Nagamine, and Nolan Lassaline. ®

Pages