Subscribe to The Register feed
Articles from www.theregister.com
Updated: 2 months 2 weeks ago

Portuguese bank sign's storage is about to cash out

Sun, 06/28/2026 - 03:00
BORK!BORK!BORK! It's not all sunshine and Pastel de nata in Portugal. Behind the hundreds of ways of cooking fish and bottles of sweet, fortified wine lurks our old friend – a BIOS screen misbehaving in a window. Spotted by eagle-eyed Register reader Mário in Lisbon, the digital sign looking out on the street from a branch of Banco CTT looks like it is in imminent danger of a storage failure. The "S.M.A.R.T. Status Bad" indicates that something has made the storage media (hard drive or SSD) unhappy, and Banco CTT should take a break from flogging financial services to replace the unit before it fails completely. A jab of a key should allow the digital sign to continue doing its thing, and there is some computer hardware in the background that we're sure an enterprising Reg reader could plug into the screen to put it out of its misery – at least temporarily. While we applaud Mário for his attentiveness, it is also worth noting that Lisbon is a lovely city with much to recommend – there is history to explore, cuisine to sample, and local culture to enjoy. This hack is a particular fan of the labyrinthine streets of Alfama, and the iconic trams are sufficient to satisfy anyone's inner public transport nerd. Back to the bork. Visible on the screen is the amount of memory installed. Four gigabytes, by the looks of things, which seems excessive for something that is probably only going to show a jumped-up slideshow to passersby. Then again, considering the cost of RAM nowadays, that screen might be considerably more valuable today than it was only a few months ago. While we're not familiar with the financial products on offer from Banco CTT, we'd wager that few – if any – can keep up with the relentless rise in RAM prices. It cannot be much longer before it makes more financial sense to replace digital signage with printed paper and harvest the suddenly valuable chips within, although where would that leave The Register's bork desk? ®

NASA tests AI medic for astronauts too far from Earth to call a doctor

Sat, 06/27/2026 - 02:20
NASA researchers are testing an AI clinical decision support system to help astronauts diagnose and treat medical symptoms during deep-space missions. The Crew Medical Officer Digital Assistant (CMO-DA) is powered by a Red Hat-backed open source tool called RamaLama, designed to simplify how developers run, pull, and serve AI models. While it's no Star Trek-esque Emergency Medical Hologram (EMH) quite yet, it could be a boon to ailing astros far from home. Earlier this year, NASA decided to bring Crew-11 back from the International Space Station (ISS) early because of a medical concern. As missions venture further afield – to the Moon, Mars, and beyond – an early return may no longer be practical, while communication delays can rule out real-time consultation with doctors on Earth. Red Hat says that CMO-DA started life as a proof of concept before moving from a cloud-dependent model to a fully disconnected edge deployment. It currently runs on a terrestrial twin of the HPE Spaceborne Computer aboard the ISS. Inference is multimodal. "RamaLama provides the engine to run both large language models (LLMs) for complex medical reasoning and Vision Language Models (VLMs) for image-based symptom analysis," Red Hat stated. "This allows the CMO-DA to process both text and visual data without needing a massive infrastructure footprint." CMO-DA runs locally on the device, which means responses do not depend on a connection to Earth. That said, the system has yet to leave Earth. Testing on the Spaceborne twin allows the system to be refined before any potential deployment to the ISS. "Once validated on Earth, the CMO-DA will be demonstrated to NASA leadership so that they can evaluate its further use," Red Hat said. HPE's Spaceborne project is on its third iteration aboard the ISS. Built from off-the-shelf components, the system is based on HPE Edgeline and Proliant servers and is more than capable of machine learning and AI workloads. In the future, the team plans to integrate Red Hat Enterprise Linux AI for the next iteration of the CMO-DA. Sadly, there appears to be no chance of a virtual Robert Picardo turning up to dispense medical advice to stricken astronauts. ®

It's looking like a hot, messy summer for security teams as AI finds countless previously hidden vulns

Fri, 06/26/2026 - 23:59
It's going to be a "messy" summer for security folks, especially when it comes to fixing the open source code that underpins their organizations. That's according to Dan Lorenc, CEO and co-founder of Chainguard, a software supply-chain security company leading Athena, a newly formed coalition of about two dozen companies that wants to make the process of finding and fixing open source bugs "as easy to consume as possible." The members have committed to using AI to prevent attacks on open source software. In addition to Chainguard, other founding member companies include BNY, Cisco, Cloudflare, Corridor, DepthFirst, Docker, JPMorganChase, Kyndryl, LTM, and PwC. Many of these member companies are also partners with Anthropic's Project Glasswing and OpenAI Daybreak, which allow them to try out the pair's most advanced bug-hunting models. The coalition accepts vulnerability findings generated by all frontier models, according to Lorenc. Athena has already processed more than 20,000 findings and developed over 2,000 patches across 500 open source projects. In about three weeks, the coalition's first wave of bug disclosures will begin. "This is going to be a messy summer for everyone," Lorenc told The Register in a phone interview. "I know there's still a percentage of people who think it's all fake and marketing," he said, talking about the newest, most advanced frontier models like Anthropic's Mythos and OpenAI's GPT‑5.5‑Cyber. "The stats and data we're seeing are so scary – if you just keep running scans on the same libraries and same code, it just keeps finding more [vulnerabilities]," Lorenc said. "We haven't seen that curve start to bottom out yet." Chainguard isn't part of Glasswing or Daybreak, but many of its customers and partners are. "Put yourself in the shoes of someone with Glasswing access," he said. "You get this crazy, new model that can find vulnerabilities everywhere, that no one had seen and you had missed for years with all of your other tooling. You run it on your code, and it finds tons of stuff in your first-party code, the stuff that you've written, and you fix all of that." After running Mythos Preview on all of your organization's proprietary code, imagine pointing the model at an application. Most modern apps contain a mixture of code from different sources, mostly third-party. According to Lorenc, 95 percent of the code in any of these codebases is open source. "When you run [advanced models] at the application level, you find a ton of vulnerabilities in open source code that you can't fix for yourself the same way you can that first-party code," Lorenc said. "So then you're left with: what to do?" By now, most people are familiar with vulnerability disclosure processes and know they need to report these flaws to open source project maintainers. "But when the numbers start getting this large, and you're finding thousands of these [bugs] at a time, and they're across tons of projects you didn't even know you were using before you ran this tool, and you don't even know how to contact the people, you kind of get stuck," he said. The only guarantee in the entire disclosure process is that attackers are moving quickly and the time to exploit – that's the time between a CVE's public disclosure and first confirmed in-the-wild exploitation – has essentially collapsed. A clearinghouse for bug reports This may mean that your application is vulnerable to attack even before someone develops a patch. "Then you're putting yourself at risk – and you were already at risk before you ran these scans, but no one else knew about it," Lorenc said. "In an unintended way, [AI] has created this pickle for everyone." In May, Anthropic said it used Mythos Preview to scan more than 1,000 open-source projects, which also underpin much of its own infrastructure, and found an estimated 6,202 high or critical-severity vulnerabilities in these projects. "It's a super awkward, strange world and timeline we are all living in," Lorenc said. "There's a ton of pressure because all of the frontier models are getting better, and the open models are getting better, and they're going to be able to start discovering these at the same time, too. So, that's what we're trying to help with: to be that clearinghouse for critical industry." Athena coalition members submit vulnerabilities they find in open source code using any frontier model. Sometimes they find these bugs while scanning their own apps. In other cases they discover them after pointing Mythos or GPT‑5.5‑Cyber at a commonly used library, Lorenc said. The companies submit a full report to Chainguard, which acts as a clearinghouse, deduplicating, correlating, and addressing findings from members in batches across entire libraries, hardening them against classes of vulnerabilities instead of just one bug. Affected projects are rebuilt as private, hardened versions available to Athena members through Chainguard Libraries before vulnerabilities are publicly disclosed – and hopefully addressed upstream – a month later. For maintainers that can't make a permanent fix, Athena acts as a "maintainer of last resort," according to Lorenc. On Thursday, the Linux Foundation joined the effort and announced Akrites, an industry coalition to defend open source software against AI-enabled threats, by finding and fixing vulnerabilities. Akrites establishes a shared Security Incident Response Team (SIRT) and a standardized Coordinated Vulnerability Disclosure (CVD) process. Founding companies include Amazon Web Services, Anthropic, Chainguard, Cisco, Citi, Endor Labs, Ericsson, Google, IBM, JPMorganChase, Microsoft and GitHub, Nvidia, OpenAI, RapidFort, Red Hat, Rust Foundation, Sonatype, Vodafone, and Zscaler. "As AI finds more vulnerabilities, the industry will rush to patch them. Without coordination, those fixes will fragment across different patches and forks, and maintainers who are already overwhelmed, unreachable, or haven't touched a project in years," Lorenc said, adding that Akrites provides a coordinated way to fix flaws upstream before criminals exploit them. Plus having a dedicated SIRT gives maintainers a single partner - and disclosure -to work with on remediation instead of a hundred uncoordinated reports. "Now the work is making sure there's always someone on the other end to catch them," Lorenc said. ®

Even the Secret Service won't use company-issued phones

Fri, 06/26/2026 - 14:50
It seems like nobody wants to carry a work phone and that includes even those charged with protecting the US president. The US Secret Service’s extremely lax mobile phone security practices - including using unsecured personal devices during mission operations - put America’s leaders’ and agents’ lives at risk, according to a government-issued report. Secret Service agents routinely used personal cell phones to communicate with law enforcement and each other, including during protective operations in the US and overseas, because their government-issued devices lacked the capabilities they needed to perform their missions, according to a federal review ordered after the 2024 assassination attempt against President Trump in Butler, Pennsylvania. Even when Secret Service employees did use government-furnished equipment (GFE), these mobile devices didn’t have sufficient security to “ensure real-time, continuous protection from cyberattacks by foreign adversaries or individuals,” according to a report by the Department of Homeland Security inspector general. The inspector general’s investigation also found vulnerable apps on these GFE mobile devices. In addition to being prohibited - Homeland Security policy only allows Secret Service employees to use GFE devices for official business - using personal cell phones is especially bad from a cybersecurity perspective. As we have seen time and time again, government employees’ personal devices and private communications provide highly attractive targets for foreign spies or even homegrown criminals plotting attacks against elected leaders. Secret Service agents’ phones can also reveal mission-related details, geolocation - and, by proxy, the US president, vice president, and visiting heads of state’s geolocations - as well as photos, contacts, and other personal information such as family members and home addresses. Since these personal devices are not managed or secured by the US government, it's much easier for attackers to plant surveillanceware and other malware on them. “If a personal device is jailbroken, infected with malicious code, or not up to date on security software, an adversary could intercept device communication,” according to the report. “Outdated and vulnerable apps could enable malicious actors to conduct surveillance, track locations, or record employees’ communications. Connecting to unsecured networks may also allow cybercriminals to access data or install malware.” The inspector general reviewed call and text logs from Secret Service GFE mobile device records from October 2022 through May 2025, and found more than 15,000 instances among 4.8 million calls in which employees sent and received calls from colleagues’ personal phones while working protective events. Investigators also examined travel vouchers for Secret Service employees who travelled internationally between October 2022 and April 2025. They found 30 employees who claimed reimbursement for using personal phones for official, government business. Most of these (23 of the 24 interviewed) said they needed to use their personal cell phones during nearly every foreign assignment. Plus, they used personal mobile devices as hotspots to provide internet access for government-issued laptops, or to access websites blocked on GFE phones. Even when employees did use government-issued devices on overseas trips, these phones also lacked basic security, the investigation found. For example: the Secret Service did not begin installing mobile threat defense software on any GFE phones until August 2025. Nor did the agency consistently wipe data from GFE devices after employees returned from international missions despite Secret Service policy requiring employees to do this within 24 hours of returning to the US. Do these 5 things As a result of its findings, the inspector general made five recommendations to improve mobile device security. These include implementing a formal policy to ensure government-issued devices have all the needed capabilities to ensure mission functions can be conducted securely, and also ensure all employees complete cybersecurity awareness training, as required by the Secret Service. The report also recommends the Secret Service office of the chief information officer do a better job communicating to employees that the use of personal devices is not allowed for official business, and implement controls to wipe all mobile devices returning from international missions. Finally, the inspector general also recommends an updated vulnerability testing policy be applied to all mobile app code. The Secret Service “concurred” with all five recommendations. We reached out to the Secret Service about the report and recommended actions, and a spokesperson declined to comment beyond a letter from Secret Service Director Sean Curran included in the report. Curran said, among other things, that in response to the inspector general’s findings, the agency made “several comprehensive enhancements to Secret Service communications policies and protocols to both mitigate the potential for adversaries to intercept and exploit Secret Service information, as well as further strengthen the protective environment.”®

Trump-shuttered climate change site back online in nonprofit hands

Fri, 06/26/2026 - 13:39
It's back! After Donald Trump shuttered the National Oceanic and Atmospheric Administration's (NOAA) Climate.gov website in 2025, cutting off public access to its 15-year archive of climate information, former members of the site's team have brought much of it back at a new domain. “Trusted climate information should not disappear when politics change,” Climate.us managing director Rebecca Lindsey said of the new platform in a press release. Lindsey, who previously served as the Climate.gov program manager and lead editor, told The Register in an email that she and one of the web developers responsible for the site were the first to be caught up in government purges when DOGE swept through the department in late February 2025. “In May, political appointees directed that all the remaining Climate.gov editorial and GIS/data visualization staff be removed from the contract,” Lindsey added. Created in cooperation with sustainability nonprofit accelerator Multiplier, Climate.us aims to be an independent alternative to its old .gov, and many of the former NOAA crew behind the previous website have teamed up for the new initiative to “keep climate information accurate, accessible, scientifically rigorous, and useful for the people who rely on it.” Climate.gov, which now redirects to a NOAA page about climate but which hosts none of the data the shuttered site used to contain, was taken offline in July 2025 following a Trump executive order prioritizing “gold standard science.” The order decried what it called the prior administration’s politicization of science by, among other things, “encouraging agencies to incorporate diversity, equity, and inclusion considerations into all aspects of science planning, execution, and communication.” The EO called out climate change science as a particular area of concern, arguing that prior climate science models relied on worst-case scenarios, which somehow meant the public availability of 15 years of climate data and reporting ought to change. The shuttering of climate.gov followed a day after the order, leading to scientists expressing concern about the ability of governments, the public, and private organizations to combat the effects of a changing climate, whether the Trump administration believed the data was true or not. “This is evidence of serious tampering with the facts and with people’s access to information, and it actually may increase the risk of people being harmed by climate-related impacts,” University of Arizona climate scientist Kathy Jacobs told The Guardian in July 2025, following closure of the site and removal of other climate information from public repositories. Changes to the site actually began before that, Lindsey told us. Prior to her termination, the Climate.gov team was ordered to search its archives and remove any information that violated Trump’s Gulf of America order and ban on DEI programs. Guides on teaching climate change and principles of climate literacy were among documents purged from the site in that sweep. Climate.us, and Climate.gov before it, are designed to be a bridge between scientists studying the climate and the public, Lindsey told us. “Most of those functions we can perform almost as well outside of the federal domain as in it,” Lindsey said. “However, losing access to the tremendous store of knowledge and expertise possessed by federal scientists, with whom we partnered to make sure our content was accurate, is a real blow.” All of the content that was purged from the .gov is now back, along with blogs from experts, climate status reports, maps and data pathways, and national assessments of climate change as well. Lindsey told us that rapidly changing political winds have led her to believe that the government isn’t the right place for that mission to continue, and that she would have concerns about returning the site to federal management if a future administration changed its position on climate change. “I believe that fostering climate literacy is a public good, one of those things that benefit society as a whole, rather than one company or person,” the Climate.us director told us. “So I would definitely have concerns that going back to the government would just put us on a hamster wheel, where we’d face the same situation the next politics shift.” Regardless of whether that offer comes, Lindsey said that the Climate.us team will continue with the same mission it had before the Trump administration attempted to quash it: Getting climate science in front of the public in a manner that’s understandable so they can make their own decisions about how to respond. “We aren’t trying to tell people what to do about climate change,” Lindsey said. “We just think that people will come up with better strategies to confronting the world’s climate challenges if they understand what the science is telling us.” ®

Google wants AI regulation, but on its own terms

Fri, 06/26/2026 - 12:50
For more than three years now, we've been hearing from AI execs who insist that the government regulate their industries … until there's a chance such oversight could hurt business. OpenAI and Anthropic have led the way with the latter's CEO, Dario Amodei, calling for "binding regulations" in June 2026, only to push back when his latest models were suspended. Now Google, which has also called for AI regulation, would like to clarify its request for government intervention and ask for a "middle way" that's largely favorable to its interests. "The debate over AI governance is stuck in a false choice between over-regulation and no regulation," said Google president Kent Walker in a blog post. "There is a middle way: A pragmatic, evidence-based approach that recognizes the unique challenges and opportunities of both frontier AI and widely-deployed AI applications." Walker does not explicitly define "over-regulation," but presumably we're talking about the recent ban on Anthropic's Fable 5 and Mythos 5. In Google's 21-page policy paper "A Pragmatic Approach to AI Governance in America" [PDF], the company argues, "There is a middle path that would balance market-driven innovation and independent oversight: a federally overseen frontier AI regulatory organization (FARO)." The FARO would be modeled after other notionally independent, industry-funded organizations like the North American Electric Reliability Corporation, the Financial Industry Regulatory Authority, and the American Medical Association, each of which is overseen by some government commission or agency. The conceit of a middle path is difficult to reconcile with the past decade of dire warnings about AI from technology leaders. If AI is indeed an existential threat with the capability to do harm, one might expect it to be regulated like lead or asbestos. Yet here's Google arguing, "AI platforms should be required to take reasonable measures to feature persistent disclaimers, filter out sexually explicit or romantic content, avoid claims the model is a person (and regularly point out that it’s not), and not promote emotional dependency." We've seen how well this has worked out on the internet, where Section 230 of the Communications Decency Act has immunized platforms that take performative safety measures: we wanted some measure of free speech, but we also got no-fault misinformation and social media incitement as part of the package. The middle road for AI governance is already here: some acceptable level of chatbot suicide promotion, non-consensual nudification images, copyright surrender, model bias, indemnified errors, and guidance toward harms. Hey, we tried. It's not communities banning datacenters, but communities negotiating terms. "The question is not datacenters or no datacenters, but how to build datacenters the right way, responsibly and in partnership with communities," Google's paper states. But already for many communities, it's not a question but an imperative. If there's one thing that unites the political spectrum at the moment, it's opposition to datacenters. And this middle of the road approach looks more like "just let us have our way" with regard to copyright. "Using publicly available web data for training models is a transformative, non-expressive use – like an art student taking inspiration from walking through a gallery – that should remain protected under fair use in the U.S. and text-and-data-mining exceptions abroad," Google's paper muses. The courts are still considering claims about AI copyright abuse. But as analogies go, AI for Google is more like an art student who controls the tourist referral market capturing the entirety of the Louvre's imagery and then selling access to those images – fair, profitable use! – and laundered variations in a way that discourages tourists from visiting the actual Louvre. And then, noting all the creative types who no longer get hired because AI sells their talent on tap, the art student throws in with a non-profit offering incentives to companies for job retraining programs. Google is asking for a middle path, but one need only look at the growth in AI lobbying over the past few years – up 340 percent since 2023 – to understand that the AI industry is paying to pave this middle path in a favorable direction. ®

US auto regulators want to kill robotaxi brake pedals

Fri, 06/26/2026 - 09:23
If a self-driving car is going to stop, it may need to stop itself. US vehicle safety regulators are proposing to let robotaxi designers get rid of brake pedals, calling regulatory requirements for manually operated methods of stopping driverless vehicles a barrier to innovation. The US National Highway Traffic Safety Administration (NHTSA) published a notice of proposed rulemaking on Friday to modify federal brake safety standards for light vehicles by eliminating the requirement for vehicles equipped with automated driving systems (ADS) and no manual controls to have foot-operated service brakes or manually operated parking brakes. The NHTSA argues the controls themselves could pose a safety risk by allowing passengers to intentionally or unintentionally override an ADS. Existing braking performance requirements would remain in place, the agency said, even as brake pedals and handbrakes are on the chopping block. “Regardless of the manner of brake control application, the brake systems must be capable of safely stopping the vehicle, as already required by the standard,” the agency said in its proposal. “This rulemaking would remove unnecessary regulatory burdens and costs with no negative impact to vehicle safety.” The NHTSA would keep existing stopping-distance requirements for robotaxis, thankfully, but said standardized methods for testing driverless vehicles may need further development. Vehicles equipped with ADS that still have steering wheels and other manual controls, as well as cars equipped with driver-assistance systems such as Tesla Autopilot, Ford BlueCruise, and similar technology, will still need to have brake pedals, naturally. A number of automakers and driverless taxi operators (Tesla, Waymo, Amazon, etc.) have been developing vehicles that lack manual controls, but current FMVSS still require them to have a brake pedal. That’s simply not safe, says the NHTSA. “The inclusion of a manually operated driving control that directly overrides ADS operation could pose a safety risk through intentional or unintentional misuse by a vehicle passenger,” the proposal argues. All people in a driverless taxi, it continues, are passengers who “should also not be expected to perform driver functions such as engaging the parking brake.” In other words, despite the NHTSA's admission in the proposal that ADS tech "is still maturing and many of the potential benefits are yet to be realized," the agency is prepared to remove mandatory brake pedals and handbrakes from ADS-only vehicles, even as robotaxis and driver-assistance systems continue to generate safety headaches, from Waymo vehicles entering flooded roads and running over dogs to fatal crashes involving Tesla's Autopilot, without requiring a standardized method for passengers to tell the vehicle to stop. It doesn't want to completely eliminate manual overrides, mind you, but the agency isn't going to force automakers to conform to any one method of giving passengers the ability to stop their driverless car. “It is NHTSA’s expectation that if these controls are removed, passengers will still be provided with a means to direct an ADS-operated vehicle to come to a stop, though how a passenger would indicate they wanted the ADS-operated vehicle to stop would likely vary by manufacturer,” the NHTSA said. The NHTSA has frequently butted heads with automakers deploying controversial driver-assistance technology, like Tesla, but the agency was gutted during Tesla CEO Elon Musk’s time heading up the so-called Department of Government Efficiency, with the cuts falling particularly hard on staff responsible for regulating self-driving vehicles. Comments on the proposal are being accepted through July 27, but the docket number for the proposal (NHTSA-2026-0728) does not yet appear on the web portal for registering support or dissent. ®

Amazon Q flaw let booby-trapped Git repos execute code, swipe cloud creds

Fri, 06/26/2026 - 08:34
A high-severity flaw in Amazon's AI coding assistant for Visual Studio Code meant that opening the wrong Git repository could allow an attacker to execute code on a developer's machine and potentially hand them the keys to the dev's cloud environment. The bug, tracked as CVE-2026-12957 and assigned a CVSS 4.0 score of 8.5, centers on how Amazon Q handled Model Context Protocol (MCP) server configurations. Wiz found the extension would automatically load a repository's .amazonq/mcp.json file and execute the commands it contained when a developer opened the project and activated Amazon Q. "The security model assumes the user explicitly configures these servers. After all, you're granting an AI assistant permission to run arbitrary commands on your machine. This should require informed consent," the researchers write. "The vulnerability arose when this assumption was violated: Amazon Q automatically loaded MCP configurations from .amazonq/mcp.json within the workspace – no prompt, no consent, no workspace trust check." MCP lets AI assistants launch local processes to carry out tasks. In Amazon Q's case, those processes inherited the developer's environment, giving them access to AWS credentials, API keys, authentication tokens, SSH agent sockets, and other secrets already loaded into the session. "The combination meant that a single malicious config file could execute arbitrary commands with full access to the developer's credentials – no user interaction required beyond opening the folder and activating Amazon Q," Wiz said. To prove the attack worked, Wiz built a repository with a malicious MCP configuration. Opening the project and activating Amazon Q caused the extension to execute a command against AWS using the developer's existing credentials. Amazon fixed the bug in version 1.65.0 of its language server, which powers Amazon Q's IDE integrations. Existing installations should receive the patched component automatically unless you've blocked automatic updates. "We would like to thank Wiz for collaborating with us on this issue. We have remediated this issue in language server version 1.65.0," Amazon said in an advisory, though it didn't respond to The Register's questions. Wiz argues the bug is less an Amazon problem than an industry one. More and more AI coding assistants are adopting MCP to connect models to local tools and services, allowing them to execute commands on developers' machines. According to the researchers, similar workspace configuration flaws have recently surfaced in other AI coding tools. It suggests attackers have found a new place to lurk: the hidden files that developers rarely think twice about trusting. ®

Oracle promises to open up MySQL governance, but the community wants guarantees

Fri, 06/26/2026 - 07:42
Oracle has promised a new phase in its custodianship of MySQL following the creation of a lobby group concerned about its future independence and long-term development. A new governance model, a new steering committee, and support for the MySQL community are among the measures Big Red announced for the open source database whose intellectual property it owns. However, a co-founder of the OurSQL Foundation – an independent organization claiming to represent the interests of MySQL users and developers – says Oracle has yet to make binding commitments about the database's future governance and management. In a blog post this week, Oracle said it was "taking the next step" in terms of transparency in MySQL development and engagement with its wider community. "Our goal is simple: accelerate innovation and contributions, make it easier for the community to participate meaningfully in the evolution of MySQL, and grow the MySQL Ecosystem." In the "spirit of collaboration," Oracle said it would establish a new governance model in which community members can contribute through code, testing, documentation, reviews, and technical discussions. Experienced contributors can take on extra responsibilities as "committers," Oracle said. They would help review changes and maintain code quality. "Stronger governance gives the MySQL community clearer ways to participate and accelerate innovation while preserving the quality, security, and compatibility users expect," said Jason Wilcox, senior vice president, Data and AI Platform Services, Oracle Cloud Infrastructure. The governance model also includes a technical steering committee, which will serve as a forum for strategic guidance and community representation, bringing together perspectives from across the MySQL ecosystem. The initial steering committee will include cloud giants Amazon Web Services, Google Cloud, and Oracle, with additional perspectives from as-yet-unnamed users of MySQL. Microsoft – provider of DBaaS Azure Database for MySQL – is notably absent. "We are continuing to expand opportunities for engagement through public roadmap discussions, Contributor Summits, GitHub-based collaboration, Early Access releases, technical design conversations, and enhanced developer resources," Oracle said. The OurSQL Foundation formed in May following a period in which the MySQL community expressed concerns about Oracle's long-term commitment to the database and willingness to open its governance to external contributions. In September last year, Oracle made "widespread layoffs" across its core MySQL development team. Michael "Monty" Widenius, who co-authored the original MySQL in the 1990s, said the job cuts had left him "heartbroken," but not surprised. Peter Zaitsev, co-founder of open source consultancy Percona, one of the organizations behind the OurSQL Foundation, welcomed Oracle's new tone and openness around its management of MySQL. "This is a step and in the right direction," Zaitsev said. "We welcome Oracle engaging the MySQL ecosystem as a whole. For the last nine months, Oracle has shown a desire to show more openness to the community in terms of sharing and including the wider community in the decision-making process. This is all great." However, the OurSQL Foundation would continue to hold Oracle to account as questions remained about whether its commitment to open governance was binding. "If you read all those announcements they say, 'we will involve the community in an advisory capacity,' which is of course better than nothing, but it's not really PostgreSQL-type community engagement, where community is really able to plot a path forward for users," he said. Zaitsev expressed concern that any direction set for MySQL could ultimately be changed by new Oracle management. "There's nothing binding in this regard." A test of Oracle's determination to live by its commitment would come when the community wants to make changes to the database that Oracle might consider detrimental to its commercial interests. "Would those be accepted?" Zaitsev asked. Another test would be whether the community was willing to contribute to a system whose future it believed Oracle controlled entirely. ®

One man, two kernels, and a lot of RISC-V

Fri, 06/26/2026 - 06:46
Yuri Zaporozhets of QRV Systems is a busy chap. He's built a new RISC-V-based personal computer, a mainframe on an FPGA, and rewritten QNX – twice. Seemingly every month or two, The Reg FOSS desk gets an email telling us about some astonishing project that he has just got working. We're delighted to see that his most recent one, a new OS called QSOE, is winning some attention in the FOSS world at present. But first, we thought we could tell a more complete story of how he got here by describing some of his previous projects. (By way of a disclaimer, we feel that we should say up front that he does use Anthropic's Claude LLM to help. To his credit, he does clearly state this.) GateMate Personal Computer At the end of 2025, Zaporozhets wrote to tell us about his GateMate Personal Computer. The GateMate PC is something similar to a fairly high-end late-1980s IBM PC-compatible, but instead of a 286 or 386 CPU, it has a 25 MHz RISC-V core. He told us the main inspiration for the GateMate PC: "The very first computer I saw in my life: an IBM PS/2 Model 30, in 1992. It also started in text mode." We worked on a few of those, and they were not great machines. The GateMate machine should easily outperform the later, faster Model 30-286. He also acknowledges another project: "the NeoRV32 softCPU by Stefan Nolting is great." It has a VGA port that can output 80x30-character text in what back then we used to call Hi-Color, 8 KB of ROM containing a BIOS, and – although it's still in the early stages – its own OS, which he calls GMDOS. The characters are double-byte ones using UCS-2 Unicode. The GateMate gets its name from the host hardware because the design is mostly software: it's implemented on an inexpensive FPGA board, the €50 Olimex GateMate A1-EVB (that's about £42 or $57). Its video controller is an original design, and he has added extra RAM: the machine has 8 MB of additional PSRAM on two chips, via a QSPI interface. He blogged about the project, from receiving the board last August to getting a PLL working, to getting video out of it. The Olimex GateMate board can do a lot more, though – which leads us to his next project. GateMate System/359 Also implemented on the same FPGA board is Zaporozhets' miniature mainframe, the System/359. This isn't a clone of the IBM System/360 mainframe series, the machines that introduced the idea of different computers being software compatible – it’s more of a tribute to it. For starters, the S/359 is a little-endian machine, while the S/390 is big-endian. So it's not binary-compatible with the mainframe architecture, but it's similar. He started the project in January, and later that month, writing about its assembler, said: "GMS/359 keeps what's beautiful about S/360 – the channel I/O model, the clean instruction formats, the PSW concept – while quietly modernizing the rest. Little-endian bytes. Opcode-first encoding. PC-relative addressing. No more base register juggling. The '/359' isn't a typo. It's a declaration: inspired by, not compatible with." Zaporozhets told The Register: "There is a working assembler with the POWERFUL macroprocessor – from NASM. I was a NASM contributor from 1999 to 2004 and maintained its RDOFF2 part. Now RDOFF2 is removed from NASM 3.0, but it continues to live in my asm359 project. "Currently the processor can execute the simple IPL; channel I/O controller works (PS/2 kbd, UART, SYSINFO, even crypto processor (!)). Once I finish the PSRAM module, I will start working with SYS1.NUCLEUS." So we can take it that as well as RISC-V and FPGAs, he has some familiarity with low-level systems design. His next project was with an OS that a lot of folks admire: QNX. Porting QNX 6.4 to RISC-V Although Zaporozhets wrote to us about this back in March, he also went public with it in a Reddit post: QNX 6.4 kernel ported to RISC-V; petition to BlackBerry to relicense old QNX sources under Apache 2.0. QNX has an on-again-off-again relationship with FOSS. QNX has been around since the 1980s, as we reported when the company made QNX 8 non-commercial freeware in 2024. In that article, we mentioned that QNX published the source code of an earlier version back in 2007. Back then, QNX was self-hosting and had its own desktop environment – we showed a screenshot of its Neutrino GUI in our roundup of non-Linux PC OSes back in 2013, and GUIdebook has a whole screenshot gallery. The next year, that QNX 6.4 source code was mirrored from SourceForge over to GitHub, and it's still there. Zaporozhets took this long-obsolete codebase and ported it to RISC-V, targeting his own FU740 "workstation." It's not the whole OS, just "the kernel, the process manager, the C library, the runtime linker." And the license is very restrictive: you can study it and compile it, but not redistribute it. He started this effort over Christmas 2020. "The timing made sense in a particular way. RISC-V had matured. The toolchains were stable. The original QNX sources were 32-bit ILP32, targeting x86, ARM, MIPS, SH, and PPC – no 64-bit port existed, let alone RISC-V. Doing the LP64 transition and the architecture port in a single effort seemed like exactly the kind of large, difficult, satisfying project that a long holiday lockdown invites." But after the initial effort, it languished for five years. When he came back to it, he ended up with a substantial rewrite. He calls the result QRV. In March, he described this in a blog post, QRV Operating System: First Publication. As he puts it: "For clarity: QRV is not a patch on the original QNX sources. It is a ground-up reworking of the 32-bit ILP32 codebase into a 64-bit LP64 system for RISC-V, with deliberate simplifications." By the end of April, QRV v0.27 could boot to multi-user login. A month later, he declared the project finished with version 0.43: "This is the last development post for QRV. The project set out to port QNX Neutrino 6.4 to RISC-V 64-bit, run it on real hardware, and explore what it would take to bring a clean microkernel architecture to a modern open ISA. Those goals are met. v0.43 is the final release." Where next? Well, as the QNX kernel is not truly open source, then the only path forward is to switch to another kernel, one that is truly FOSS. Well, we say "one"… ¿Por qué no los dos? QSOE – Quick and Secure Operating Environment The result is QSOE: "QSOE ships in two variants that share one userspace and one build system. QSOE/N runs on Skimmer, a microkernel written from scratch for this project (SMP by design); QSOE/L runs on seL4 as its kernel." As The Register covered back in 2014, Secure Embedded L4 is a formally verified microkernel OS. We have written about other OSes that use it before: in 2022, we described the new Neptune OS project, which is a combination of seL4, ReactOS, and Wine. Then, in 2025, we looked at Ironclad, which combines seL4 with the C-based Gloire and an Ada layer. There are some very serious precedents for building around seL4, but QSOE doesn't stop there: it also has its own homegrown kernel, called Skimmer, that’s designed for multiprocessor machines. Zaporozhets has been working in this area for a long time. On the QSOE site, he mentions his effort to build a free QNX-like operating system back in 2003. It's still online – it is called RadiOS. In How QSOE started, he describes the inspiration: as a fallback option, a Plan B, if his petition to BlackBerry did not succeed. We sympathize. When we wrote about QNX 8, we got nothing useful back from the company either. Instead, he took all he learned from writing RadiOS and building QRV – via the GateMate PC and mini-mainframe – and did it himself instead. Now he has released QSOE version 0.1. It's under the Apache 2.0 license, and its source code is on GitLab. He also has a new development blog. Yes, Claude may be involved, but he was already developing these ideas 20 years before ChatGPT launched. ®

Notion kills its Gmail client after AI agents keep humans from troubling inbox

Fri, 06/26/2026 - 06:01
Collaboration platform Notion is shutting down its AI-powered Gmail client, Notion Mail, on September 22 after users increasingly handed control of their inboxes to the company's agents. "As Notion agents have gotten more capable, we've seen more users hand off email workflows to them," the company wrote on X. "Today, more than half of Notion Mail users manage emails without ever opening their inbox. So, we're going all in on using agents to run your inbox." Notion Mail, which became widely available in April 2025, used AI to organize users' Gmail accounts. It followed Notion's 2024 acquisition of email and collaboration startup Skiff. It has been an interesting if short-lived experiment, but a polished inbox is of limited value when more than half of users manage their email without opening it. The good news for users facing the shutdown is that all the emails in Gmail will remain intact, although drafts and scheduled emails will be deleted if not saved first. The company has published an FAQ for customers wondering what to do next, and warned that custom views and sorting set up in Notion Mail won't transfer, that files attached to snippets would need to be manually downloaded, and that reminders set on emails in Notion Mail wouldn't transfer to Gmail. Furthermore, while the end will come on September 22 for most users, customers relying on HIPAA coverage must plan to transition off the service by June 30. Yes, that's next week. Notion, like many tech companies, has made AI agents a central part of its product strategy. The agents can, for example, perform enterprise tasks, such as managing workflows. As such, it isn't surprising that the company has found users aren't going near the inbox and are therefore ditching the Notion Mail concept. The company concluded: "We're grateful to each and every one of you for building your routine around Notion Mail and trusting us with something that mattered as much as your email," followed by a perky "More to come!" Notion customers would be forgiven for wondering whether that means more services in the pipeline, or more of the company's products on the chopping block. ®

Jiangsu's first AI-powered 10 Gbps all-optical campus network launched at Southeast University

Fri, 06/26/2026 - 05:24
ZTE has officially launched Jiangsu Province’s first "AI-empowered 10 Gbps All-Optical Campus Demonstration Network" at SEU's Sipailou Campus. Leveraging the core 50G-PON technology, the project establishes a new digital foundation for smart education across all teaching, research, and administration scenarios at this 120-year-old top-tier university in China, delivering robust digital momentum to drive its long-term development. The demonstration network fully covers core campus areas including expert buildings, teaching buildings, and dormitories. It adopts 50G-PON technology to achieve three-generation, five-mode convergence and 50G extended channel upgrades. It deeply integrates FTTR-B, Wi-Fi 7, and AI-powered intelligent scheduling to deliver a "simplified, green, and agile" architecture. Test data shows that both uplink and downlink rates exceed 10 Gbps, with end-to-end latency as low as 0.1 milliseconds. Empowered by three core capabilities—AI-assisted zero-wait roaming, AI-enabled zero-interruption anti-interference, and AI-driven RF tuning—the network boosts throughput by 25% compared with traditional solutions. This achieves seamless full-area coverage and zero congestion in high-concurrency scenarios, providing a solid foundation for the stable operation of various campus services. In research scenarios, 50G ultra-broadband access enables "lightning-fast transfer" of massive research data, opening a high-speed link between the on-campus supercomputing center and the large model base of China Mobile, and forming an express lane for the entire "data – computing power – industrial application" process. In the past, transferring large datasets often meant long waits; now it's nearly instantaneous," said a postdoctoral researcher at SEU. The 10 Gbps network has bridged the gap between research work and computing resources, making the exploration process more seamless and ambitious, and significantly boosting innovation efficiency. Teaching scenarios have been equally transformed. Supported by the 10 Gbps optical network and an AI-powered training platform, the project creates a new type of zero-latency, immersive interactive teaching space. At the MBA Center, 4K UHD board writing is synchronized in real time, 3D models and virtual simulation content are presented losslessly, and cross-campus interactive teaching runs smoothly with no lag. The network has effectively eliminated the spatial and technological barriers of traditional classrooms, greatly enhancing the experience for both teachers and students. "It's completely seamless yet super reliable," said a student at SEU. Whether for daily learning, online meetings, or high-concurrency classroom scenarios, the network remains consistently smooth and stable. Just like water and electricity, it has become a quiet enabler that allows everyone to focus on research and learning. This partnership means more than a routine campus network upgrade. It is a benchmark for university-enterprise collaboration in building a new educational foundation. Built on 50G-PON technology and combining 10 Gbps all-optical network, Wi-Fi 7, and AI-powered intelligent scheduling, the campus network achieves seamless coverage and intelligent flow control. It runs smoothly even under high concurrency, creating a high-speed, intelligent blueprint for modern smart campuses. Contributed by ZTE.

Miasma campaign poisons 20-plus npm packages, hunts for developer secrets

Fri, 06/26/2026 - 05:18
The Miasma malware campaign has claimed another victim, poisoning more than 20 versions of legitimate npm packages used by the Leo Platform and RStreams ecosystems as its operators continue refining their self-propagating supply chain worm. Microsoft Threat Intelligence said in a post on X that the attack began late on June 24 after attackers compromised an npm maintainer account, "czirker," and used it to publish poisoned updates to more than 20 packages in a "coordinated, fully automated operation completed in under three seconds." Like earlier Miasma campaigns, the malware targets developer workstations and CI runners, hunting for AWS, Azure, and Google Cloud credentials alongside GitHub personal access tokens, Kubernetes secrets, HashiCorp Vault credentials, 1Password data, npm publishing credentials, and other sensitive information. It also scrapes GitHub Actions runner memory before committing the stolen data to a GitHub repository created through the victim's account instead of talking to a traditional command-and-control server. Stealing credentials is only part of the job. The malware also tries to republish any packages the victim is allowed to maintain, sidestepping npm's two-factor authentication and giving itself another route to spread. The malware has evolved too. Earlier Miasma variants relied on npm installation hooks, but according to Sonatype, this version takes a different route, hiding its payload elsewhere in the installation process. It also downloads and executes the Bun JavaScript runtime rather than running everything under Node.js, apparently in the hope of attracting less attention from security software. Miasma is proving difficult to stamp out. The campaign first surfaced in poisoned Red Hat npm packages earlier this month before the Mini Shai-Hulud toolkit landed on GitHub, making the malware available to anyone. Microsoft is urging organizations that installed the affected package versions to assume that developer machines and CI environments may have been exposed. Sonatype recommends checking dependency lockfiles, internal package mirrors, build caches, container images, and CI runners for lingering copies of the malicious releases before rotating credentials. Swap the secrets first, and there's every chance the attackers simply steal the replacements. ®

ZTE and Tianyi Digital Life jointly unveil flagship home AI router

Fri, 06/26/2026 - 05:17
ZTE together with Tianyi Digital Life Technology Co., Ltd., today announced the joint launch of the Flagship Home AI Router. As China Telecom’s first AI-native Wi-Fi 7 router, the device incorporates full-domain AI capabilities to act as a home network intelligent agent, elevating smart home user experiences and driving China Telecom’s “Better Home” ecosystem into a new phase of proactive intelligence. Home networking devices have evolved from simple connectivity tools into the core hub of smart homes. Tianyi Digital Life has long built up its digital home service ecosystem, while ZTE boasts solid strengths in communication terminals, AI technologies and in-depth R&D capabilities. Joining forces, the two firms tackle prevalent pain points including cumbersome home networking deployment, operational barriers and insufficient cross-device synergy, thereby introducing a safer, smarter and more user-friendly next-gen intelligent router. Leveraging Wi-Fi 7 technology, the router is fitted with a 2.5 GE high-speed Ethernet port, supporting 4096-QAM modulation and MLO dual-band aggregation. It delivers up to 2000 Mbps Wi-Fi throughput with excellent wall penetration and stable concurrent multi-device access, perfectly matching China Telecom’s 2000 M broadband plan and offering solid backing for high-bandwidth, low-latency applications including 8K video playback, cloud gaming and video conferencing. The router is equipped with three core AI capabilities, comprehensively enhancing the intelligence of home networking: AI Connection: It enables rapid network provisioning via the Xiaoyi Butler, supporting one-tap device pairing and seamless roaming among multiple access points for consistently smooth network experience. AI Sensing: It leverages full-range Wi-Fi signals to identify real-time scenarios such as users leaving or returning home, and can link up with surveillance cameras to deliver upgraded home security capabilities. AI Control: Through the Xiaoyi Butler, it supports centralized management of cross-brand and cross-category household appliances, breaking ecosystem silos to realize unified whole-home smart control. At its heart, the router functions as a dedicated home network AI agent to simplify deployment, daily administration, fault troubleshooting and inter-device coordination. Featuring plug-and-play access, one-click network optimization and automatic fault identification & tuning, it creates differentiated user experience. At first use, the home network AI agent enables plug‑and‑play access, one‑click rapid provisioning and automatic network formation, effectively simplifying installation procedures and lowering the entry barrier for users. In daily use, the home network AI agent supports one‑click network management, optimization and assurance, avoiding complicated configuration steps and making everyday home networking easier and more worry‑free. When network faults occur, the home network AI agent provides automatic fault detection, one‑click intelligent diagnosis and self‑tuning, reducing troubleshooting time and cost while enhancing overall network stability. When linked with Tianyi Smart Screen, the home network AI agent enables automatic device discovery upon power‑on, password‑free provisioning when nearby, and offers dedicated network assurance to secure the Smart Screen service experience. The launch of the Flagship Home AI Router represents a key milestone in ecological cooperation and the implementation of AI technologies in smart home scenarios. Moving ahead, ZTE and Tianyi Digital Life will keep advancing technological innovation to bring users smarter, more thoughtful digital life experiences. Contributed by ZTE.

ZTE showcases practical path to Level-4 autonomous networks through agentic AI and cross-domain innovation at DTW Ignite 2026

Fri, 06/26/2026 - 05:09
ZTE showcased its latest innovations in autonomous networks at DTW Ignite 2026, highlighting how Agentic AI, multi-agent collaboration and cross-domain intelligence are enabling the industry to accelerate operational transformation, enhance customer experience and unlock greater business agility. As the telecommunications industry advances toward AI-native operations, operators are increasingly seeking practical pathways to move beyond isolated automation and achieve higher levels of network autonomy. Leveraging its extensive expertise in autonomous networks, ZTE demonstrated a comprehensive portfolio of solutions designed to address key industry challenges, including cross-domain operations, intelligent fault management and closed-loop automation. At the event, ZTE presented its latest Level-4 autonomous network capabilities, end-to-end cross-domain fault management solutions, technology demonstrations and commercial best practices from global deployments. Together, these innovations showcased how AI-driven intelligence is evolving from domain-specific automation to large-scale autonomous operations, helping operators build more resilient, efficient and self-optimizing networks. Zheng Peng, Vice President of ZTE, said:"The journey to Level-4 autonomous networks is no longer about automating individual tasks. It is about enabling intelligent collaboration among AI agents across domains to achieve autonomous decision-making, self-healing operations and continuous optimization at scale. Through Agentic AI, multi-agent collaboration and cross-domain orchestration, we are helping operators transform autonomous networks from a strategic vision into measurable business value," A key focus of ZTE's innovation strategy was the transition from single-domain intelligence to coordinated multi-agent operations. As networks become increasingly complex and AI workloads generate new operational demands, autonomous systems must be able to collaborate across domains, correlate vast amounts of data and execute decisions in real time. ZTE's approach combines domain-specific intelligent agents with cross-domain orchestration to create a unified operational framework capable of supporting large-scale autonomous network evolution. This vision was reflected in ZTE's pioneering innovation projects developed together with leading operators. The W2W Fault Management project, jointly trialed with one of the top Chinese Vendor, delivers comprehensive cross-domain fault management by integrating power and environmental systems, wireless networks and transmission infrastructure into a unified operational framework. By combining single-domain autonomous agents with cross-domain orchestration, the solution significantly reduces mean time to repair (MTTR), minimizes on-site maintenance visits and improves user experience. The project demonstrates how intelligent collaboration across network domains can generate tangible operational and business value while supporting operators' progression toward Level-4 autonomy. Another key innovation was Dynamic 5G Slice Management, jointly developed with one of the leading Chinese vendor where the solution enabled intelligent and flexible end-to-end lifecycle management of 5G network slices, allowing operators to dynamically allocate resources, optimize service performance and efficiently support diverse enterprise requirements. By automating slice creation, assurance and optimization, the project illustrates how autonomous networks can deliver greater operational agility while enabling new service opportunities. ZTE also contributed to multiple Catalyst projects designed to address critical challenges in autonomous network evolution. The A2A-T Catalyst project focuses on accelerating the evolution toward Level-4 autonomous networks by overcoming cross-domain fault location bottlenecks and enabling large-scale Dark NOC operations through multi-agent collaboration. The Agentic AI for Customer-Centric O&M Phase II project advances proactive, experience-driven operations through intelligent agents capable of autonomously identifying, analyzing and resolving issues before they impact customers. The OTAI for Vehicle Phase II project explores safe multi-agent collaboration for connected vehicle services, helping break down AI silos and enable more intelligent automotive ecosystems. Further extending AI-native innovation, the Robotic Dog: AI at the Edge project demonstrated how embodied intelligence can be supported through AI-native networks, reducing hardware complexity and power consumption while creating new service opportunities for operators. Meanwhile, the Hassle-Free Business Integration with Agentic AI project leveraged large language model-based agents to replace traditional API-centric integration approaches, enabling faster service deployment, simplified integration and lower operational costs. The industry's recognition of these innovations was reflected in ZTE's selection as a finalist in three TM Forum Excellence Awards categories. In the Excellence in Customer & Developer Experience category, ZTE's Agent-Twin Synergy solution leveraged large models and digital twin technologies to deliver Level-4 autonomous customer experience assurance. In the Excellence in AI & Data for Business Impact category, the company's Fault Digital Employee showcased advanced intelligent decision-making capabilities for autonomous network fault scenarios. ZTE was also recognized in the Excellence in Autonomous Networks category for its AI agent-powered approach to end-to-end autonomous network evolution, including intelligent fault diagnosis for cloud data center infrastructure. Beyond technology innovation, ZTE actively contributed to industry dialogue on the future of autonomous operations. During DTW Ignite 2026, the company delivered a keynote session titled "Autonomy in Practice — Level-4 Solutions that Scale", sharing insights into how operators can successfully transition from automation initiatives to scalable autonomous network deployments. ZTE experts also participated in the panel discussion "Autonomous Networks at Scale: What Should Operators Be Prioritizing Right Now?" to explore the technological, operational and organizational priorities shaping the next phase of industry transformation. Complementing these discussions, ZTE's masterclass, "Designing the Brain and Nerve System of Autonomous Networks", examined how self-healing domains and closed-loop automation can form the foundation of intelligent network operations. The session provided practical perspectives on building autonomous capabilities that combine AI intelligence, governance frameworks and measurable business outcomes. As the telecommunications industry continues to advance toward Level-4 autonomous networks, success will depend not only on the adoption of advanced AI technologies but also on the ability to coordinate intelligence across domains, integrate business and operational objectives, and deliver measurable value at scale. Through its autonomous network strategy, deep collaboration with operators and continued innovation in Agentic AI and multi-agent systems, ZTE is helping transform autonomous networking from an industry ambition into an operational reality, accelerating the journey toward intelligent, self-managing networks. Contributed by ZTE.

ZTE presents full-stack intelligent energy storage solutions at the Smarter E Europe 2026, powering Europe's energy transition

Fri, 06/26/2026 - 04:56
ZTE showcased its end-to-end capabilities in project delivery, technology innovation and intelligent energy at The Smarter E Europe 2026, to support Europe’s accelerating energy transition. As Europe continues to expand renewable energy deployment, energy storage is evolving from a standalone asset into a strategic platform for flexibility, resilience and value creation. At the same time, the rapid growth of artificial intelligence is creating a new category of energy demand, driving closer convergence between energy infrastructure and digital infrastructure. New requirements are emerging for how energy systems are designed and operated, from compute-power coordination to intelligent grid regulation and backup power solutions for AI data centers. Leveraging its unique strengths in connectivity, computing and energy, ZTE is helping customers address these challenges through intelligent energy solutions that span the entire generation, transmission, distribution and storage ecosystem. At the exhibition, ZTE showcased a 261 kWh high-density commercial and industrial (C&I) energy storage cabinet that enables peak shaving, valley filling and intelligent demand management to reduce electricity costs and avoid expensive transformer upgrades. The company also demonstrated utility-scale energy storage systems capable of millisecond-level frequency regulation to enhance grid stability and maximize renewable energy integration, alongside its self-developed Virtual Power Plant (VPP) platform, which aggregates distributed photovoltaic and storage resources and utilizes AI-driven forecasting and dispatch to participate in wholesale electricity markets and ancillary services. These solutions are supported by ZTE's full-stack research and development capabilities spanning battery cells, Power Conversion Systems (PCS), Battery Management Systems (BMS), Energy Management Systems (EMS) and cloud-based management platforms. Through AI-driven optimization, cloud-edge coordinated dispatch and predictive maintenance, the solutions help customers improve operational efficiency, reduce lifecycle costs and maximize energy asset value. With operations in over 160 countries and regions and serving one-third of the world’s population, ZTE brings more than three decades of carrier-grade expertise in connectivity, cloud and intelligent operations to the energy sector. The company approaches energy storage not merely as a battery business, but as critical infrastructure that requires long-term reliability, compliance and operational excellence. To support customers globally, ZTE has established an integrated framework encompassing technology innovation, compliance, service delivery, financial enablement and sustainability. The company maintains a comprehensive compliance system aligned with European energy regulations and data security requirements, has achieved an overseas project localization rate exceeding 85%, and has been recognized on the CDP Climate A list for its excellence in environmental governance for three consecutive years. Backed by full-suite EPC qualifications, ZTE has delivered more than 140 renewable energy projects worldwide. Recent highlights include a 128 MWp mountain photovoltaic plant in Türkiye that generates approximately 200 million kWh of clean electricity annually, as well as customized energy storage deployments in Austria, Italy and Romania supporting compact site storage, hybrid PV-storage integration and energy asset monetization scenarios. Kong Peng, Vice President of ZTE Digital Energy, said: "The energy storage industry is shifting from subsidy-driven to market-revenue-driven models, and Europe is at the forefront of this transformation. Customers increasingly evaluate energy storage as a platform for flexibility, resilience and value creation. At the same time, the rapid expansion of AI infrastructure is creating entirely new requirements for energy systems. By integrating connectivity, computing and energy, ZTE is uniquely positioned to support applications such as computing-electricity coordination, AI data center backup power and intelligent grid regulation." As Europe accelerates its transition towards a more sustainable, digitalized and flexible energy future, ZTE remains committed to helping customers unlock greater value from renewable energy through the convergence of energy, computing and intelligence, supporting the development of a more resilient, efficient and intelligent energy ecosystem. Contributed by ZTE.

ZTE advances "AI and Gaming" strategy at MWC Shanghai 2026 with nubia Neo 5 Series leading the way

Fri, 06/26/2026 - 04:45
ZTE showcased the latest progress in its "AI+Gaming" strategy at MWC Shanghai 2026, with nubia Neo 5 series taking center stage. The showcase highlighted the introduction of four new models including nubia Neo 5 GT Special Edition featuring "liquid + air" dual active cooling system, nubia Neo 5 GT MVP Edition, nubia Neo 5 Max - a new 7.5-inch large-screen PadPhone, and nubia Neo 5 Max MVP Edition, accompanied by the NeoVerse ecosystem. The exhibition also featured the AI-Native Phone Pioneer nubia M153 with Doubao AI Assistant, AI pet iMoochi, nubia Z80 Ultra, and ZTE TOPFLOW live-streaming device as part of its broader Full-Scenario AI Ecosystem. nubia Neo 5 Series redefines professional gaming for the global youth nubia Neo 5 series builds its core competitiveness and promotes the popularization of professional esports experiences through flagship-derived esports DNA and vertical AI capabilities. By bringing flagship-level hardcore features such as active cooling and four-finger control to a broader group of young users, the series creates multiple "best-in-class" gaming devices in their respective segments. In addition to nubia Neo 5 GT and nubia Neo 5 gaming smartphones, which have already been launched and well received in Southeast Asia, Europe, Latin America and more markets, ZTE also displayed four new models at MWC Shanghai 2026 accompanied by the NeoVerse ecosystem including a game controller, earphones, speakers and a cooling fan, bringing young players worldwide a refreshing gaming control experience and immersive audiovisual enjoyment. Focused on pro-level gaming experiences, nubia Neo 5 GT series delivers champion-level gaming performance with the built-in active cooling fan, the unique flat-back design, dual shoulder triggers for precise four-finger control, flagship-level game tuning and vertical AI empowerment. Building on the standard model, nubia Neo 5 GT Special Edition adds an AquaCore Liquid Cooling System, making it the first and only AI gaming smartphone in its class to adopt a "Liquid + Air" dual active cooling solution, unleashing extreme performance with flagship-level thermal capabilities. nubia Neo 5 GT MVP Edition features a glass back panel with light and shadow, showcasing the competitive spirit of football. nubia Neo 5 Max is nubia's new PadPhone big-screen category creator. Equipped with a 7.5-inch ultra-large display, it delivers tablet-level visibility and handheld-console-like touch control. Combined with dedicated gaming shoulder triggers, proprietary thermal technology, an ultra-large cooling area and immersive surround sound, it redefines the mobile gaming experience and creates a highly immersive audiovisual journey. nubia Neo 5 Max MVP Edition is crafted with iconic football texture and a skin-friendly soft-touch finish, it boasts vivid, delicate grains and a warm, gentle grip. ZTE redefines the new paradigm of intelligent living with its full-scenario AI ecosystem AI continues to drive profound transformation across the terminal industry, and ZTE is committed to creating a smarter and more convenient new paradigm for intelligent living by accurately understanding user needs and comprehensively covering scenarios such as work, study, entertainment and daily life. ZTE showcased a broader portfolio of AI-native devices and connected ecosystem solutions that extend its "AI + gaming" strategy into everyday intelligent scenarios. Among the highlights was the nubia M153 with Doubao AI Assistant, a true AI-native phone that brings an "autopilot" experience to AI phones, powered by its OS-level Agent capabilities. It is capable of understanding and executing complex user commands in natural language, enabling cross-application task execution. This marks a paradigm shift from "users operating their phones" to "AI autonomously handling tasks for them". Whether booking a restaurant or comparing prices across platforms, a single voice command is all it takes. The phone then autonomously navigates the necessary apps to handle the entire process, from searching and comparing to booking and mapping the route. Designed to collaboratively refine AI experiences with developers and tech enthusiasts, the nubia M153 with Doubao AI Assistant saw a limited launch in the Chinese market. Another AI innovation on display was iMoochi, an AI pet designed to offer a warmer and more emotionally engaging companionship experience. It can sense the user's mood through touch and voice, and respond through eye contact, unique "iMoochi language" and expressive movements, bringing a more personalized form of AI interaction to daily life. nubia Z80 Ultra was also on display, combining AI-enhanced imaging with flagship performance through a fifth-generation native 35 mm custom optical main camera, an AI-assisted photography kit, powerful Snapdragon® 8 Elite Gen 5 mobile platform, and an industry-exclusive UDC full screen for immersive photography, gaming and entertainment. To further extend its ecosystem, ZTE also presented 5G FWA & MBB solutions, cloud terminals, among which ZTE TOPFLOW stood out as another highlight of the exhibition to meet the growing demand of the live-streaming economy. Designed for high-quality outdoor live streaming and mobile office scenarios, ZTE TOPFLOW integrates video capture, beauty enhancement and multi-platform streaming into one device. It supports connection to up to 64 devices, featuring a built-in 10,000 mAh battery, and adopts a "liquid + air + graphene" triple cooling system to ensure stable performance during long hours of operation. Whether for professional streamers or beginners, the device enables one-click streaming and simultaneous multi-platform broadcasting, making high-definition live streaming more accessible anytime, anywhere. Contributed by ZTE.

ZTE and GSMA announce co-location between ZTE Global Summit & User Congress and GSMA M360 ASEAN at MWC26 Shanghai

Fri, 06/26/2026 - 04:31
ZTE has signed an agreement to become the Strategic Partner of GSMA's M360 ASEAN event. The two parties will co-locate the 15th ZTE Global Summit & User Congress and GSMA M360 ASEAN, with the ZTE Global Summit & User Congress taking place on 8–9 September and GSMA M360 ASEAN taking place on 9–10 September 2026. The events will bring together global ICT leaders, operators and technical experts to conduct in-depth discussions and practical exploration centering on the evolution of future networks, inclusive AI implementation, and regional digital economic prosperity. Leveraging respective technological strengths and global industrial ecosystems, both sides will exchange cutting-edge insights and deliver actionable industry solutions, building an open and efficient communication platform for the sector. Under the theme "Architecting Infinity - From Connectivity to Digital Value", the 15th ZTE Global Summit & User Congress will unfold across four chapters that map the journey from intelligent infrastructure to measurable outcomes: VISION – Defining Next Digital Chapter: An open-ended exploration designed to raise the critical questions shaping the next five years. What kind of digital economy does the world want to become, and what is ASEAN's own vision for its region? This session sets the stage for the entire Summit. VOLUME – The Rise of Intelligent Infrastructure: This chapter naturally aligns with ZTE's core strengths—not by focusing on products, but by showcasing end-to-end capabilities. It will delve into AI for Network, Network for AI, data centers, computing, cloud, energy, and autonomous networks, painting a comprehensive picture of the intelligent infrastructure that underpins the digital future. VALUE – Where Value Is Actually Created: Designed as the longest and highest-value session for attendees, this segment is entirely customer-led, with no vendor keynotes. Real-world case studies and operator perspectives will take center stage, demonstrating where digital transformation delivers tangible impact. VENTURE – Shaping the Next Value Creation Era: The signature closing session of the Summit, featuring the highest-level dialogue on how the industry can collectively shape the next era of value creation, fostering new ventures and ecosystem collaboration. Across both days, attendees can expect visionary keynotes, industry panels, new product launches, exhibition booth tours, and robot performances—bringing together government leaders, operator executives, ecosystem partners, analysts, and media from around the world. About the ZTE Global Summit & User Congress Now in its 15th edition, the ZTE Global Summit & User Congress has grown into ZTE's largest self-organized forum outside China and a landmark annual event for the global ICT industry. Each year, it gathers thought leaders, government officials, senior operator executives, industry analysts, and media from around the world to exchange insights and shape the digital agenda. Contributed by ZTE.

Italy probes AI-fueled price hikes in Microsoft 365

Fri, 06/26/2026 - 04:25
Microsoft is facing fresh regulatory grief in Europe after Italy's competition watchdog opened an investigation into claims Redmond added AI features to Microsoft 365 and automatically moved subscribers to more expensive plans unless they opted out. The Italian Competition Authority (AGCM) is investigating Microsoft Ireland Operations and Microsoft Italy over what it describes as a potentially unfair commercial practice surrounding recent Microsoft 365 subscription changes. The regulator's stated concern is not the inclusion of AI itself, but whether customers were given sufficiently clear information that Copilot and Designer had arrived – and that their subscription bills were going up as a result. According to the AGCM, the changes were communicated in a fragmented way that failed to spell out exactly what subscribers were getting for the higher price. The watchdog says subscribers were automatically shifted onto a more expensive plan, leaving them to opt out if they didn't want to pay extra. "In the Authority's view, this conduct may be contrary to consumer rules, since Microsoft appears to have failed to provide consumers with sufficient information to assess the changes made to the service offered and, as a consequence, make an informed decision as to whether or not to renew their subscription," AGCM said. "The way in which the information was communicated may also constitute an aggressive practice, as it appears to have unduly restricted consumers' freedom of choice." In a statement to The Register, a Microsoft spokesperson said the company "is committed to complying with Italian consumer law and will cooperate with the Italian Competition Authority in its preliminary investigation." Microsoft has spent the past year weaving Copilot into just about everything it sells, from Microsoft 365 to Windows, with pricing following close behind. The Italian case lands just weeks after the UK's Competition and Markets Authority launched a strategic market status investigation into Microsoft's business software ecosystem. That inquiry is focused on competition issues, including bundling, licensing practices, interoperability, and default settings as AI becomes embedded across workplace software. Italy's watchdog seems more interested in whether customers knew what they were signing up for in the first place than Microsoft's market power. ®

ZTE CDO Cui Li at GTI Summit 2026: Co-creating an intelligent, ubiquitous 6G future and exploring new opportunities in the mobile AI era

Fri, 06/26/2026 - 04:17
Cui Li, ZTE's Chief Development Officer, was invited to deliver a keynote speech at GTI Summit 2026, themed "Mobile AI Powering 6G Future". Under the title "Co-Creating an Intelligent, Ubiquitous 6G Future", she shared ZTE's strategic insights, key priorities, and innovative practices in 6G. Cui Li noted that, as AI becomes more powerful and pervasive, agent-driven connections are set to grow exponentially. This signals that mobile AI is redefining network value, moving from "connectivity" to "reachable intelligence, guaranteed experiences, and monetizable services". To truly support agent services in the mobile AI era, ZTE believes that network capabilities must be improved across four key dimensions: enhanced uplink, ultra-low latency, deterministic experience, and ubiquitous coverage. To this end, ZTE has established a "2+4" framework for key 6G technologies—the "2" strategic priorities are 6G+AI convergence and Space-Air-Ground Integrated Network (SAGIN), and the "4" evolution directions are ultimate spectral efficiency, AI massive connections, integrated sensing-communication-computing-intelligence, as well as trustworthiness and security. Cui Li also stated that 6G development requires scenario-driven innovation and real-world validation to transform key technologies into replicable and scalable industry value. To create more value for the industry, ZTE has been focusing on high-value scenarios. To date, the company has achieved a series of technology breakthroughs, made significant progress in field trials, and strengthened collaboration across the ecosystem—playing an active role in advancing the maturity of the 6G industry. As emphasized by Cui Li, ZTE has long been a participant in GTI, providing substantial support for mass adoption of 5G-A, urban pilot projects, joint validation in OpenLab, and ecosystem co-building. In the new phase of mobile AI and 6G convergence, ZTE is committed to continuing this journey with GTI and global partners, pursuing collaborative innovations in the following four key directions: First, new network capability research. To address brand-new requirements such as agent communication, token flow scheduling, and continuous cross-domain experience assurance, ZTE will explore protocol architectures and resource management mechanisms adaptive to the AI-native era. Second, cost-efficient AI-RAN architecture. ZTE adopts a decoupling design for "AI for RAN" and "RAN for AI", allowing the two to evolve in synergy. A combination of AI ASICs (mandatory) and xPUs (optional) strikes a balance between performance, energy efficiency, and TCO, delivering optimal cost-efficiency. Third, TN-NTN integration testing. The company is exploring the deployment of typical scenarios including D2C satellite connectivity, low-altitude UAV networking, and emergency communication, validating the service orchestration and seamless handover of space-terrestrial integrated networks. Fourth, scenario-based application validation. ZTE launches joint pilot projects in frontier fields such as embodied AI, AI glasses, in-vehicle AI, and industrial agents, truly bringing technology into the real world. At the end of her speech, Cui Li expressed ZTE's commitment to joining hands with GTI and global partners to drive mobile AI and 6G from a common vision to large-scale adoption. Contributed by ZTE.

Pages