Subscribe to The Register feed
Articles from www.theregister.com
Updated: 2 months 2 weeks ago

O2 joins UK 2G switch-off with summer 2029 start date

Tue, 06/23/2026 - 08:56
Virgin Media O2 (VMO2) will switch off its 2G network starting in summer 2029, meaning that anyone still operating devices that use the technology must start planning an upgrade. The UK network operator says it will start to switch off its 2G signal in 2029 as part of an ongoing mobile transformation plan. This will see it expand and upgrade its 4G and 5G support, leading to reduced energy consumption and a faster and more reliable service for customers. 2G cell networks first started operating in Britain back in 1992, meaning the technology will have been around for nearly four decades by the time it is phased out. O2 can trace its roots to Cellnet, which launched as a joint venture between British Telecom and Securicor in January 1985. Cellnet introduced its digital GSM network in December 1993, before BT bought out Securicor, renamed the business BT Cellnet, and later spun it off as O2. All of this stems from plans announced back in 2021 by the previous UK government for all 2G and 3G mobile networks to be phased out of use by 2033. All of the major networks had managed to phase out 3G services by the end of 2025, but 2G is proving more problematic. This is because many devices have come to rely on the 2G service as a a low-power, cost-effective conduit for small volumes of data. In the UK, this includes such hardware as smart meters installed by utilities, telecare alarms and other medical devices, and many Internet of Things (IoT) devices. The topic was covered by The Register a couple of years ago, when a Parliamentary committee questioned what was going to happen when millions of smart meters lost their connection back to the mothership. The big three network operators – VMO2, BT/EE, and VodafoneThree – signed a government 2G switch-off charter earlier this year, undertaking to ensure that the switch-off takes place safely and effectively for all users of 2G services, including for vulnerable users, life-critical systems, and critical national infrastructure (CNI). The operators also agreed to publicly announce the end date of their 2G services a minimum of three years before it happens. BT/EE will begin closing its network from May 2029, and Vodafone will switch off in spring 2030, well ahead of the government deadline. Another undertaking is that the telcos will verify that "reliable 4G and/or 5G coverage" is present for their network before switching off the old service. From Reg reader comments on earlier articles, we understand that many locations in the country still lack a 4G signal, so this will be interesting to follow. But don't worry – they also agreed to encourage suppliers and customers to "upgrade and/or mitigate 2G devices" well ahead of the doomsday date. VMO2 says its 2G service currently carries less than 0.5 percent of all data traffic across its mobile network and is already closed for international roaming. By reallocating the spectrum to more efficient 4G and 5G services and replacing old network equipment, it claims the switch-off will allow it to provide customers with faster and more reliable connectivity. PP Foresight founder and analyst Paolo Pescatore told us that O2's 2029 date is an important marker that the switch-off is now moving from theory to reality. "But this is not just about old phones. There are still many devices and services that need to be supported through the transition, from smart meters and telecare alarms to payment terminals, security systems and enterprise IoT estates," he said. Not all smart meters will need to be replaced. In many cases, the communications hub can be upgraded, Pescatore added. "But a clear program is needed to identify which devices can be migrated, which need a new 4G communications hub, and which require a full meter replacement." "The clock is now ticking for utilities, local authorities, healthcare providers, alarm companies and businesses to map their 2G estates and act early. Arguably, now is the time to fully migrate to 4G communications hubs to ensure a smoother transition and make these services more future-proof." ®

Valve opens Steam Machine pre-orders with queue lottery and hefty prices amid AI squeeze

Tue, 06/23/2026 - 07:46
Valve has opened pre-orders for its forthcoming Steam Machine – but it is going to cost you quite a lot, thanks to the AI-induced storage shortage. However, the company is expecting such high demand that it is setting up an automated lottery system, so that the lucky people whose orders go through will get random places on the waiting list. The machine will come with an AMD Zen 4 hexacore CPU, as we covered back in November when the company's three new hardware models were announced. The desktop model will be offered in two configurations, with either a 512 GB or 2 TB SSD. You can order just the base unit, or if you want, get it bundled with Valve's new Steam Controller. The announcement lays out the pricing: Both models come with 16 GB of DDR5 RAM (plus 8 GB of GDDR6 VRAM), and if you're feeling rich, you can upgrade the main memory yourself. There's a microSD slot for more storage. You can pre-order the machine on its Steam Store page, although this vulture isn't eligible – in our 15 years on Steam, we've never bought a game. If you do want to get in line, you have until Thursday, June 25, to do so. There's also a Steam Hardware News Hub for news and updates. The company is randomizing the placement of orders, and there are separate queues for North America, Europe (including the UK), and Australia. Or you can do-it-yourself with SteamOS 3.8 The reason that the largely non-video-game-playing Reg FOSS desk is looking at the news is that the machine will run SteamOS 3, which, as we have covered before, is a relatively radical Arch-based Linux distribution. It has dual immutable Btrfs root partitions, which update one another ChromeOS-style, with automatic rollback and recovery in the event of failed updates. SteamOS 3.8 was released just last week. It now uses KDE Plasma 6.4.3 and defaults to a Wayland session, although you can still choose X11 from the Steam developer settings or via the steamosctl command. Perhaps the most interesting thing about this version is that the company now permits you to install SteamOS on your own hardware – so long as it uses an AMD GPU. (Nvidia support is planned: the company says "we're working on expanding support for the future.") The latest version of the SteamOS Installation and Repair page includes downloads and instructions. We lack suitable hardware for testing, but it looks like you need an 8 GB USB key for installation, the machine needs to have UEFI firmware, and you need to disable Secure Boot – all of which are very reasonable. However, the fancy partitioning scheme means that it doesn't dual-boot – so any existing OS will be erased. If you have anything on your machine you want to keep, we suggest buying a second-hand SSD, and disconnecting any other drives just in case. ® Bootnote Despite the continued non-appearance of Half-Life 3 – which has been awaited for so long that even this geriatric vulture played the original game 28 years ago – Valve seems to be doing well. It is privately held company, so it doesn't release public finances, but industry analysts peg the company's annual operating profit at around $2 billion to $3 billion – most of that coming from Steam. According to Robb Report, which seems to be a website for very rich people to learn about other very rich people's new toys, Valve boss Gabe Newell has just ordered another new €700 million yacht for his collection, part of a fleet which to his credit is also used for marine research. Perhaps he will keep it with his other six.

21,000 Oracle jobs vanish amid Big Red's big bets on AI

Tue, 06/23/2026 - 07:12
Oracle's workforce shrank by 21,000 over the last year, according to the company's annual report. In June 2025 [PDF], Big Red reported that it employed "approximately 162,000" employees. By June 2026 [PDF], that figure had fallen to 141,000. US headcount fell by 9,000, while the international workforce declined by 12,000. "Our periodic workforce restructurings and reorganizations can be disruptive," Oracle stated. "Deployment of AI technologies across our operations have resulted, and may continue to result, in reductions to our workforce." "We may initiate new restructuring plans in the future," it added, ominously. Reports of layoffs at Oracle have circulated in recent months as the company seeks to finance its AI datacenter build-out. Estimates have ranged from 20,000 to 30,000, while the annual report shows that its workforce shrank by approximately 21,000 over the last year. Oracle spelled out the effect on the company and remaining staff, saying: "These types of restructurings have resulted, and may in the future result, in increased restructuring costs and reduced productivity. These types of restructurings may also lead to shortages of sufficiently skilled employees in certain roles, loss of valuable institutional knowledge and damage to employee morale and retention." The company is legally obliged to highlight the risks in these reports, but it's a point worth making. "As our cloud and AI businesses grow, we will continually balance our resources and restructure our development group to help ensure we have the right people delivering the best cloud and AI products to our customers around the world," the company said in response to The Register's request for comment. Big Red is hardly alone in laying off staff as companies roll out AI technologies, spend billions on infrastructure for the tech, and seek to improve the bottom line by cutting payroll. Microsoft has laid off thousands of workers in the last year, something CEO Satya Nadella said was "weighing heavily on me." Nonetheless, in April, the company offered a voluntary departure program to some US employees. Microsoft has not confirmed how many staffers have taken the option to depart, but one commented: "Seeing a lot of 'I'm accepting the retirement' posts this week," to which another responded: "Folks leaving behind some big shoes to fill." All of which highlights one cost of layoffs for companies. For affected staff, the experience can be traumatic, even when departure is voluntary, but the loss of institutional knowledge can be difficult to quantify. ®

Bold move, Cotton: Trump administration tells US techies it expects American quantum computer by 2028

Tue, 06/23/2026 - 06:18
President Trump has ordered the development of a quantum computer to ensure that the US maintains a strategic technical advantage, along with a nationwide migration to post-quantum cryptography to protect sensitive data against just such a computer. In an executive order signed Monday, Trump directed various federal agencies to establish a national program to deliver a quantum computer, aimed at driving scientific discoveries and keeping the US at the forefront of technology. To be precise, it calls for “the first ever quantum computer powerful enough to initiate the era of quantum-enabled scientific discovery and accelerate quantum capabilities for commercial applications.” Trump’s order directs the Assistant to the President for Science and Technology (APST), Michael Kratsios, to coordinate the effort across the Departments of Energy, Defense, Commerce, and the Intelligence Community, as well as with the broader industry and research communities. The program is to be given the somewhat clumsy moniker of Quantum Computer for Application Development and Discovery Science (QC-ADDS), and the intent is to deliver at least one such computer to a Department of Energy (DoE) facility and make it available to the scientific community. Kratsios told reporters that the administration believes that this goal can be achieved by 2028, so that at least one full-blown quantum system will be operating by the time Trump leaves office. This is a bold claim, as quantum computers are one of those technologies where a big breakthrough has been promised to be just around the corner for decades, yet never seems to arrive. Quantum computing still has a number of challenges to solve, primarily the error correction problem, as quantum bits (qubits) are extremely sensitive to noise and will easily lose their quantum properties, like superposition and entanglement, through interference from the environment. Current quantum systems also lack the scale to do useful work; the first systems to feature more than 1,000 qubits were unveiled a couple of years ago, and an Intel-backed startup called QuantWare claims it has the technology to deliver hardware with up to 10,000 qubits by 2028. Systems to do useful work are expected to require hundreds of thousands or even millions of qubits. The executive order makes no mention of a budget or how much the Trump administration believes development of its quantum Holy Grail will cost. However, our colleagues over at The Next Platform reported last month that it intends to dole out more than $2 billion to various companies for quantum research, plus $1.375 billion to GlobalFoundries and IBM to develop quantum foundries. In anticipation that truly useful quantum kit could soon become reality, Trump also orders federal agencies to lead a nationwide migration to post-quantum cryptography (PQC). The agencies in question are chiefly the National Security Agency and the Department of Homeland Security, which are to deliver guidance to other agencies on making the move to quantum-resistant encryption. Trump's government expects “high value assets for certain uses” to be in place by 2030 or 2031, depending on the use case, with a pilot program to showcase a successful migration expected next year. Post-quantum cryptography involves development of new encryption methods to resist attacks from quantum computers, which may be able to break existing encryption algorithms that are used to protect sensitive data and communications. Under the order, the administration will help critical infrastructure owners adopt the same protections to keep power grids, water systems, and transportation networks safe, while the Federal Acquisition Regulatory Council, which coordinates government procurement policy, will require contractors to meet specified Federal cybersecurity standards by the end of 2030. ®

Microsoft Access finally breaks free of its 22-inch form limit

Tue, 06/23/2026 - 05:36
Microsoft has demonstrated that there is life in the old dog yet with an update to the Access relational database management system that addresses a limitation stemming from the days of cathode-ray tube monitors. The fix, currently in beta and set to roll out in the Current Channel preview by July 21, 2026, removes a 22-inch form-size limitation dating back to the era of cathode-ray tube (CRT) monitors. It's a weirdly restrictive limitation, considering that widescreen monitors have been around for years, and one that has resulted in some crowded interfaces as designers tried to meet business requirements while bumping up against Microsoft's decree that 22 inches should be enough for anyone. The restriction also harks back to a different time, when developers had to ensure their forms would work at lower resolutions. The 640 x 480 pixels of the Video Graphics Array (VGA) standard might be scoffed at by modern engineers, but represented a real challenge in the early days of Windows. Microsoft Access dates back more than 30 years to 1992, so it's somewhat comforting to know that the limitations of decades past still haunt today's products. While Microsoft Access has been eclipsed in terms of databases, it is often found gluing corporate systems together or lurking behind the scenes in small businesses. The form-size limitation has become increasingly frustrating as screens have grown, while the area for data entry and display has felt more and more cramped. "Larger form designs allow more flexibility in presenting information, increasing spacing between controls, displaying larger text, and reducing visual clutter," Microsoft said. More likely, it will simply encourage users to cram more into the available space – assuming anyone is willing to tinker with Access forms in the first place. Enterprise users tend to take a firmly conservative "if it ain't broke, don't fix it" approach. According to Microsoft, the removal of the forms limit is "one of the most highly requested enhancements from the Access community and a top-voted request on the Access feedback forum." Other popular requests include a Mac-native version – almost certainly a nonstarter – and modern controls. Still, it's good to see the old warhorse getting some attention. After Publisher was dropped from the Office suite (support for the perpetual version ends October 1, 2026), thoughts will inevitably turn to the fate of Access, which has so far escaped the Copilot treatment inflicted on so many of Microsoft's other products. ®

AWS debuts Lambda MicroVMs with up to 8 hours runtime

Tue, 06/23/2026 - 04:37
AWS has introduced Lambda MicroVMs, built on its Firecracker virtual machine monitor, which can run isolated Linux containers with runtimes of up to eight hours, in contrast to the 15-minute limit on containers in Lambda functions. MicroVMs form a new core feature of Lambda, the AWS serverless platform. Developers provide a Dockerfile defining a container along with application artifacts, and upload it to Amazon S3. Lambda builds this into a Firecracker snapshot, which can then be run with multiple instances if needed. AWS presents the primary purpose of MicroVMs as providing an isolated environment for running code, such as inspecting potentially malicious packages, scanning for vulnerabilities, or running AI-generated code while guarding against prompt injection and insecure output. They are also suitable for running code as part of a CI/CD process. Developers have noted that the new feature has plenty of uses beyond code isolation. "This lets you run anything you like and for up to 8 hours all while giving you full shell access to the VM and unopinionated HTTP ingress. All while still getting the benefits of SnapStart and true consumption-based pricing as opposed to wall-time pricing. It's a complement to functions," said one. Another obvious use case is for AI agents, though the company already offers AgentCore Runtime, which looks a lot like MicroVMs. Both have a maximum lifetime of eight hours, for example. MicroVMs are more generalized, though, and unlike the AgentCore Runtime, a MicroVM can be suspended and resumed. AWS does provide a skill for its Agent Toolkit that uses MicroVMs, making this a simpler alternative to the AgentCore runtime. AWS also provides a guide to using MicroVMs for AI agents managed by Anthropic Claude. A MicroVM has several possible states, including running, suspended, and terminated. It can automatically scale up to four times the base specification, and automatically suspend when there is no traffic. When it resumes, for example in response to a new network request, its state is preserved. MicroVM pricing is based on per-second usage of vCPU, RAM (provisioned in a 2:1 GB ratio to vCPU), snapshot storage, and data transfer. When a MicroVM is suspended, the compute charges cease. At the time of writing, it appears that MicroVMs are only available in US East, US West, Tokyo, and Ireland regions, and only Arm-based AWS Graviton instances are supported. Although a MicroVM is an isolated VM, this is only one element of using AI securely, since it may need network access to other resources. The ability to run a container on Lambda for more than 15 minutes has been a common request that MicroVMs now address. The feature provides a serverless, ephemeral environment that is nevertheless suitable for relatively long-running tasks or a full day of coding, with its relatively high compute price mitigated by scaling down to just snapshot storage costs when not in use. ®

Blast from the past as GIMP 0.54 is revived in Flatpak form

Tue, 06/23/2026 - 03:45
Development of GIMP has picked up speed in recent years, but now its first public release is back as a Flatpak, allowing the 1996 version to run on modern x86-64 Linux distros, even under Wayland, without the nightmare of finding and installing its 30-year-old dependencies. If you are just looking for a quick and lightweight image editor – especially if you want modern features such as edge detection or generative fill – this is not the package for you. It's mainly for the software archaeologists. For example, 0.54 did have basic "deep etching" capabilities, where you can isolate an element from its background, but you'd have to use destructive techniques – i.e. there were no fripperies like layers or layer masks, where you could preserve the badness in case you made a mistake. But at the time of release, it made a pretty good stab at replicating a lot of the features you'd have in the 1996-era Photoshop. GIMP 0.54 did include a clone stamp, though which at the time was the height of sophistication in photo retouching. Active development of what we've seen called the "GNU IMP" has resumed in recent years. In 2024, we reported that after 21 years, version 3 was close and then, in May last year, that GIMP 3.0 was out. The team has not slackened since. GIMP 3.2 came out in March 2026, and as we write, the most recent version is GIMP 3.2.4 from mid-April. What is interesting about the new Flatpak, though, is that this isn't the modern GIMP: this is the original public release of GIMP, brought back to life. The GIMP homepage has a section called A Brief (and Ancient) History of GIMP. This describes how this original version used the Motif toolkit: "It had a dependency on Motif for its GUI toolkit, which made efficient distribution to a lot of users impossible. This restriction also alienated a lot of would-be plug-in development." Back then, Motif was the default graphical programming toolkit for developing GUI apps on X11. One of the problems, though, was that Motif was not FOSS. It was not released under a recognized FOSS license until 2012, shortly after the Common Desktop Environment was open-sourced, as this vulture reported at the time, back when he still had a lot more hair on his cranium. The next GIMP release was version 0.60, and that had a very significant change: "Peter [Mattis, co-creator] got really fed up with Motif. So he decided to write his own. He called them gtk and gdk, for the Gimp Tool Kit, and the Gimp Drawing Kit. Peter tells us now that they never intended for it to become a general-purpose toolkit – they just wanted something to use with GIMP, and it 'seemed like a good idea at the time.'" The Motif-based GIMP looks a little strange and clunky by modern standards. It reminds us slightly of WordPerfect 8 for Linux, which we wrote about in 2022 – 24 years after a very young Register told readers it was coming. Even though Motif is FOSS now, we don't expect anyone will start using it again for new projects. However, running GIMP 0.54 today gives an interesting glimpse into an alternate Unix universe. Because Motif wasn't FOSS, the year after GIMP appeared, the founders of the GNOME desktop chose GTK instead, noting the issues with KDE's Qt: "The KDE project – in its current form – has about 89,000 lines of code, on the other hand, the source code for the Qt library has about 91,000 lines. Qt also forces the programmer to write his code in C++ or Python. GTK can be used in C, Scheme, Python, C++, Objective-C and Perl." GTK has been developed alongside GNOME ever since. It's now up to GTK 4, which GNOME would prefer you not to theme, although the Linux Mint project is trying to support that anyway. Others are expressing discontent with its limitations in other ways: we recently covered the announcement of a new fork of GTK 2. There are other alternatives. GTK 1 is still around. Robin Rowe, the developer of the TrapC type-safe dialect of C, also maintains CinePaint, and to do so, he also maintains a fork of GTK 1, which you can find on GitLab. Other old GUI toolkits are also adapting to the new world of HiDPI and Wayland. In 2024, we reported on Tcl/Tk 9, 12 years after the last point release, and the following month, on a new release of FLTK after 13 years. ®

Brits still reckon Big Tech isn't paying enough tax

Tue, 06/23/2026 - 03:00
The majority of Britons still believe Big Tech should be contributing more to the public purse, new research suggests. Polling by the Fair Tax Foundation, shared with The Register, finds that 67 percent of respondents believe the UK should ensure large technology companies such as Meta, Google, Apple, and Amazon pay more in Digital Services Tax (DST) to increase their overall tax contribution. The same proportion of Brits said the government should aim to become a world leader in regulating cryptocurrencies and other digital assets to help prevent tax avoidance and evasion. The findings arrive as the future of the UK's Digital Services Tax continues to attract scrutiny on both sides of the Atlantic. Introduced in 2020, the levy was designed to extract more money from online giants that generate substantial revenues from UK users while often reporting profits elsewhere. Last year alone, the tax raised around £800 million for the Treasury. Not everyone has been thrilled by the arrangement. President Donald Trump threatened in April to impose a "big tariff" on British imports if the government refused to drop the Digital Services Tax, arguing it unfairly targets US tech giants. The British public, however, appear less concerned, and the polling suggests support extends well beyond the digital tax itself. Three-quarters of respondents said they would prefer to work for a company that can demonstrate it pays its fair share of tax, while 74 percent said they would rather spend money with such a business. More than seven in ten backed requiring fair tax practices from companies bidding for public sector contracts, while 82 percent supported similar requirements for firms receiving government bailout funds. The research forms part of the Fair Tax Foundation's annual survey of public attitudes toward corporate tax conduct, released during Fair Tax Week. Paul Monaghan, chief executive of the organization, said the findings showed that tax fairness remains one of the public's biggest concerns regarding corporate behavior and argued that politicians have a clear mandate to push for greater transparency. "The UK public care about many issues, but 'tax justice' is consistently at the top of their concerns when it comes to corporate conduct," he said. "The days of large multinationals such as Amazon refusing to disclose what their income, profit, and corporate taxes are in the UK need to end. As does the almost complete absence of tax transparency we see from the vast majority of micro-enterprises – which is helping to fuel fraud across the country." That may prove easier said than done. Governments have spent years trying to agree on an international framework for taxing multinational corporations, with varying degrees of success and enthusiasm. Until then, the UK's stopgap solution appears to retain something increasingly rare in modern politics: broad public support. For all the complaints from Big Tech and the US government, most Britons seem perfectly content for HMRC to keep rattling the collection tin outside Silicon Valley's front door. ®

Datacenters dip a toe back into waterborne computing despite obvious challenges

Tue, 06/23/2026 - 02:15
Siting datacenters either on the water or underwater is an idea that just won't sink, and there is increasing interest in it, despite the obvious fact that water and IT equipment are a potentially disastrous combination. The attraction of having a data facility in or on the water is that it offers virtually limitless natural cooling, which is an increasingly vital consideration for operators deploying hot-running systems filled with GPUs for AI processing. But set against that are potential issues with access for maintenance, in the case of underwater facilities, and gaining access to enough power to keep all that IT infrastructure chugging along. The most recent announcement is that an underwater facility off the coast of China has now commenced operations, powered by a nearby offshore wind farm. First disclosed last October, this project by Beijing-based Highlander Digital Technology has a capacity of 24 megawatts, about half the average size of a US datacenter, but is designed to run on more than 95 percent green electricity. It is expected to serve clients such as China Telecom and a state-owned AI computing company, and is said to be part of a push by the Chinese government for operators to lower their carbon footprint. But long before China got in on the act, there was Microsoft and its Project Natick. This involved a prototype lowered into the water off the coast of California in August 2015 to test out the concept, before Phase II of the trial saw a larger unit tested out near Scotland in 2018. When this latter unit, fitted with 12 racks containing 864 servers, was hauled up from the seabed in 2020, Microsoft reported that the systems in it had experienced a failure rate one-eighth that of a land-based control cluster. Yet despite declaring the experiment a success, Microsoft chose not to proceed any further with submerged server farms, and the company never fully explained why. It seems likely that the issues around accessing the IT kit for maintenance or upgrades, not to mention supplying power to an underwater enclosure, all add up to make land-based facilities just more convenient. Despite this, some companies, such as Subsea Cloud, have persevered with the idea. However, another approach that seems to be gaining more traction is the floating datacenter, typically on a barge tethered close to shore or even on board a ship. Google toyed with the concept back in 2013 after patenting a design for a floating facility back in 2008, but changed its mind, reportedly after finding the time and cost of meeting federal maritime safety regulations too burdensome. Another US company, Nautilus Data Technologies, made bit barges a reality with one facility in Marseille, France, and another in Stockton, California, before shifting to focus on the EcoCore line of AI infrastructure. However, the Stockton facility is still operational, according to Nautilus, offering 6.5 MW of IT load capacity. In Japan, shipping biz Mitsui OSK Lines (MOL) started exploring the possibility of fitting out a ship as a floating data hall last year. This year, the company signed a memorandum of understanding (MoU) with Hitachi for the development of such a facility from a second-hand vessel, with a view to commence operations in 2027. When first floated, MOL said it expected to use a 120-meter ship to support an IT capacity of 20 to 73 MW, but the plans with Hitachi could involve a larger vessel. The ship's onboard systems, including air conditioning, water intake, and power generation, would be used to service the IT infrastructure. Korean behemoth Samsung is also looking to get in on this action, signing an MoU with Greece-based shipowner Capital Clean Energy Carriers and Lloyd's Register earlier this month to build floating server farms from scratch using existing shipbuilding methods. Samsung said that such facilities can have advantages over existing datacenters because they can address land scarcity, lower cooling costs, and reduce carbon emissions. But perhaps the wildest floating bit barn concept comes from Panthalassa, a startup based in Portland, Oregon, which is developing wave-powered floating structures designed to operate in the deep ocean. The firm, backed by venture capitalist Peter Thiel, has designed the units to operate autonomously, connected to the outside world via SpaceX's Starlink satellite network, according to reports. But as New Scientist magazine points out, saltwater and wave action are very effective at causing trouble for machinery, and Panthalassa didn't respond to its questions about what happens when something goes wrong in the middle of the ocean, or about relying on a satellite link to get data in and out. Other floating datacenter projects aim to sidestep the permitting hurdles and power constraints faced by land-based facilities, but it seems that scale is likely to be the enemy of such waterborne projects. The hyperscaler mob is looking to build massive multi-gigawatt facilities such as Meta's planned Hyperion facility, and stuffing servers onto barges or ships is unlikely to match facilities of this size or their economies of scale. Where they will find a home is in places such as Singapore, which is severely land-constrained. Earlier this year, two firms even proposed floating hydrogen power plants to serve shore-based datacenters. ®

Digital indigestion: Fizzy Coca-Cola display chokes on full storage

Tue, 06/23/2026 - 01:27
BORK!BORK!BORK! Are you a glass-half-full or glass-half-empty person? Some distressed digital signage on the island of São Miguel in Portugal's Azores is running on empty, judging by today's entry into the files of signage silage. Spotted by an eagle-eyed Register reader, a Coca-Cola display has clearly had too much of the carbonated beverage and urgently needs to free up some space, a feeling many an over-caffeinated techie will be familiar with after chugging one Diet Coke too many. It's tricky to work out what operating system is running behind the scenes. Running Windows with 200 MB or so of disk space is only for the brave (or foolhardy), but we suspect this might be Ubuntu Unity warning onlookers that the volume is fit to burst. While there is an option to ignore the message (assuming the viewer can find somewhere to plug in a mouse or keyboard), doing so might be the computing equivalent of dropping some Mentos into a bottle of Coke and standing well back. While a good old-fashioned poster would never show an error message, thus obscuring whatever message Coca-Cola is trying to convey via the medium of a bottle top, Ubuntu isn't a bad choice for digital signage. Assuming it is indeed the operating system running behind the scenes, security maintenance could continue well past the display's lifetime, and there are plenty of tools to deploy, provision, and manage the hardware. All of which makes the pop-up a little incongruous. Somewhere, a distant dashboard is flashing red to indicate the signage storage is not what it might be. But on a well-managed system, surely the customer would never be aware of any issues. Kiosks and digital signs are about keeping their internals well tucked away from prying eyes after all. Except here. A volume is getting dangerously full. The same effect can be created by pouring a sachet of Pop Rocks/Space Dust* into one's mouth and chugging a glass of Coke. The result could be your very own storage error. Possibly through your nostrils. ® *Also known as popping candy.

Five Eyes spooks warn AI means infosec incidents can become ‘major operational and financial crises’

Mon, 06/22/2026 - 22:29
The leaders of intelligence agencies from the Five Eyes nations – Australia, Canada, New Zealand, the USA and the UK – have together issued strongly worded advice calling for leaders to nail cybersecurity basics or fall victim to ruinous AI-powered attacks. “The rapid pace of frontier AI development means cyber risk assumptions can become outdated in months, not years,” the advice warns, and calls for organizations to take rapid action to ensure their defenses remain potent. “While AI will help us improve cyber defence over time, it also accelerates the speed, scale, and sophistication of cyber threats,” the advice adds. “Frontier AI models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities. The timeline is not years, it is months.” After all that scary stuff, the spook bosses offer some antidote: “Cyber resilience is integral to advancing business continuity, market confidence, and long-term value.” And how might one achieve that resilience? The Five Eyes have four suggestions: Understand and assess risk, readiness and accountability Prioritize foundational cyber security practices and controls Empower cyber leaders with authority and resources Stay actively engaged as threats and guidance evolve “Cyber risk can no longer be treated as a purely technical issue,” the advice points out. “This is a core business risk and leadership responsibility,” because breaches are inevitable and “Breaches will occur. Preparedness helps you contain them quickly and prevent escalation into major operational and financial crises.” The intelligence chiefs therefore want organizations to test their cyber resilience rigs. “It is not enough to have controls,” they write. “Leaders must be confident those controls will perform during a real incident. This requires reassessing long-standing trade-offs and using AI deliberately to strengthen defence – not just improve efficiency.” That last sentence is a rare moment of optimism in the advice and precedes a section in which the intelligence bosses observe “Organizations that integrate AI tools into their security operations can detect vulnerabilities earlier, improve software quality, monitor unusual behaviour, and respond faster to incidents – reducing both the cost and impact of incidents.” Readers of The Register might find this advice a little quaint given that infosec vendors have for years blathered on about the need for boards and bosses to take cyber seriously. It’s also been a couple of years since it became apparent that generative and agentic AI can fuel new and unusually potent cyber-attacks. Interest in that idea spiked in the eleven weeks since Anthropic revealed the existence of its powerful flaw-finding Mythos model and hid it behind a regwall lest criminals use it to swiftly slice holes in important software. The Five Eyes bosses address their advice to “leaders” – presumably bosses of substantial organizations – who may not have watched the Mythos mess unfurl while they worried about a global energy crisis kicking holes in their supply chains. The good news is that the spy bosses don’t think leaders need to learn a lot to cope with the advent of AI, as their advice suggests five practical actions they rate as “not new,” but “now urgent to reduce not only technical risk, but also operational, financial and reputational exposure.” For the record, those actions are: 1. Reduce your attack surface: Limit unnecessary system access and external connectivity. Challenge whether systems need to be exposed at all and isolate those that do not. 2. Accelerate patching processes: AI is shortening the time between vulnerability discovery and exploitation. Delays in patching increase risk, especially for operational systems with long update cycles. Prioritize security updates accordingly to manage risks. 3. Address legacy systems: Unsupported systems are easy targets. They are not just technical debt, they are strategic liabilities. 4. Review and strengthen identity and access controls: Limit who can access critical systems. Enforce strong authentication and regularly review permissions. 5. Prepare for incidents before they happen: Test response plans, train and prepare teams, and assume breaches will occur. Focus on fast containment and recovery. Take us, and this, to your leaders, dear readers. ®

India and China are home to 2.9 billion people – and together they bought just 13 million PCs in Q1

Mon, 06/22/2026 - 21:06
Buyers in the world’s two most populous nations, India and China, bought just 13.1 million PCs in the first quarter of 2026, according to analyst firm Omdia. The firm’s analysts last week declared that Indian buyers acquired 4.4 million PCs – 3.5 million of them laptops – during Q1. That figure represented 32 percent year-over-year growth. “Brands and channels front-loaded their inventory, to secure pricing ahead of anticipated increases,” the firm wrote. “This triggered a 43 percent surge in the consumer market as buyers moved to purchase high-performance PCs at older price points, a trend amplified by intense online retail promotions.” On Monday, Omdia published Q1 PC sales data for China and found total shipments of 8.9 million – a two-percent year-over-year decline. Senior analyst Emma Xu blamed the slump on the end of government subsidies that Beijing used to keep consumer spending buoyant. Whatever the reason for the drop in shipments, it meant that the two nations – combined population 2.9 billion, or 36 percent of global population – bought 13.1 million PCs in the quarter, or 20 percent of the 68.44 million PCs Omdia says shipped worldwide in Q1. Omdia forecasts China will experience a 14 percent PC shipment slump in 2026, while Indian shipments will dip by 5.3 percent across the year. The firm believes rising component costs will push PC prices beyond the reach of local purchasers. Samsung signs up for OpenAI everywhere Samsung has gone all-in on OpenAI, adopting the upstart’s ChatGPT Enterprise and Codex tools for all employees in its Korean home and all Device eXperience (DX) employees worldwide. “Samsung Electronics plans to use ChatGPT and Codex for technical and non-technical work, across a broad range of functions, including software development, marketing, product development, and manufacturing, to enhance employee productivity and problem-solving capabilities,” according to a Monday announcement from OpenAI, which describes the deal as “one of our largest to date.” Samsung Electronics employs over 100,000 people in South Korea. OpenAI’s announcement points out that the company already collaborates with Samsung on memory chips. “With Samsung Electronics’ adoption of ChatGPT Enterprise, the relationship between the two companies is expanding beyond AI infrastructure to encompass workforce transformation and company-wide AI adoption,” the upstart enthused. Jio heading for spaaaaace, and an IPO Indian mega-telco Jio is contemplating its own constellation of broadband satellites. “Jio is evaluating the development of a sovereign Low Earth Orbit satellite constellation for India,” chairman and managing director Mukesh D. Ambani wrote in a statement [PDF] made at its annual general meeting. “We are also partnering with the leading global constellation providers by leasing satellite capacity, so that we can accelerate service availability while building our own long-term sovereign capability,” he said. “To anchor this ambition, Jio is also building its own ground station infrastructure in India. These ground stations will support our partner constellations, as well as our own future satellites, creating an end-to-end satellite broadband ecosystem from space to ground.” The telco, which in a decade has become India’s largest by winning over half a billion subscribers, also revealed its intention to conduct an initial public offering. Locally developed AI is also on the company’s agenda. “Unlike global AI platforms that build in English and translate later, Jio is building AI natively in Indian languages,” Ambani said. “Be it a Marathi farmer or a Tamil student, both will get an AI that thinks and replies in their language.” Vietnam decides to create ten of its own Big Tech companies The government of Vietnam last week announced its intention to foster development of ten tech companies, each with revenue of $1 billion, by the year 2030. Vietnam knows exactly what it wants these so-called “large-scale domestic strategic tech enterprises” to do, including deploying half a dozen new high-speed international submarine fiber-optic cables and rolling out 5G networks to 99 percent of the country's population. Others get to “develop and improve digital platforms and shared databases that meet the needs of ministries, agencies, and localities to provide nationwide services, serving as a critical digital infrastructure for socio-economic development.” All that work will require “at least five large-scale data centers that meet international and green standards, contributing to positioning Vietnam as a regional data hub.” China’s digital currency finds 26 friends Chinese authorities last week announced that 26 financial institutions have signed up to transact in the Digital Yuan, the Middle Kingdom’s central bank digital currency. Per a state media report, “Standard Chartered China, as well as multiple Chinese-funded banks' branches in Thailand, Singapore, Laos and Qatar” have agreed to use the digital currency for cross-border transactions. As the report points out, existing cross-border payment schemes can involve several intermediaries and take days. The institutions that signed up to use the Digital Yuan will apparently need only hours to settle things up. China promotes its digital currency as a more efficient way to handle international payments than US-dollar-centric schemes like SWIFT. Signing 26 institutions therefore signals China continues to seek its own place in the international payments system. More scandal at Australia's WiseTech Things just keep getting weirder at Australian logistics tech company WiseTech Global, which saw its CEO Richard White depart amid claims of improper behavior and later investigated share trading that White conducted during a blackout period. This week’s escalation saw Australian media allege that White had become the subject of a human trafficking investigation related to a former employee who needed a visa to remain in Australia. That allegation saw WiseTech issue a stock exchange filing [PDF] in which White unequivocally denied any involvement with human trafficking and WiseTech point out this is a matter for White to deal with in his capacity as a private citizen. ®

Sniff out stale AI override advice with this open source CLI

Mon, 06/22/2026 - 17:17
The JavaScript development ecosystem may be a security nightmare, but it's also ripe for improvement. One such tool is the CVE Lite CLI, a free open source dependency scanner that helps reduce the risk of software supply chain attacks. It runs locally and provides actionable vulnerability fixes, if any are available. The tool, endorsed by OWASP, has recently been updated to include override auditing, which has the potential to avert transitive dependency vulnerabilities such as the March 2022 node-ipc package incident. The Shai-hulud software supply chain attacks that have been vexing security professionals for the past few months underscore how common it has become for threat actors to target the developer ecosystem, including CI/CD, package registries, and developer tooling. Software developers can reduce their risk by making sure the dependencies in their apps are up to date and free of known vulnerabilities, but that's more difficult than it should be. It's generally apparent when a particular library or module relies on a vulnerable dependency. But there isn't necessarily an available fix or clear remediation path. Modern JavaScript applications, like many other programming languages, allow developers to incorporate pre-existing solutions to particular problems in the form of packages – modular code that can be imported to implement particular functionality. These packages commonly depend on other packages, which is why they're known as dependencies. And these dependencies in turn may also depend on still more packages, referred to as transitive or indirect dependencies. A common security scenario goes something like this: A developer creates an app using some application framework. The app includes a dependency on "Package A", which itself relies on "Package B" – the transitive or indirect dependency in this situation. If the maintainers of "Package B" have deployed a patch addressing a reported CVE, but the maintainers of "Package A" haven't gotten around to incorporating that change into their code, apps incorporating "Package A" may be vulnerable to attack. Among other possible responses, affected developers may choose to create an override to replace the outdated, vulnerable version of "Package B," a configuration entry that can be removed once "Package A" gets repaired. But Sonu Kapoor, creator of CVE Lite CLI, explained to The Register that overrides represent a legitimate security tool but have limitations. "When a transitive dependency has a CVE and the upstream maintainer hasn't shipped a fix yet, you pin it via npm overrides, pnpm overrides, or Yarn resolutions," Kapoor explained in an email. "Once the vulnerability is addressed and CI passes, you move on. The problem is what happens after that." Kapoor recently added an override auditing tool to the CLI. When he scanned four popular JavaScript open source projects, he found that three of the four had broken overrides. "Cal.com has 90 override entries and 11 that are silently doing nothing," he said. "Jest has an override for its own package name pointing at nothing in the resolved tree. NoCoDB has entries using wildcard patterns that never matched any path in the graph. Next.js was the only clean one with zero findings, which tells me the tool is finding a real pattern, not noise." This can be dangerous, he said, when a project migrates between package managers (e.g. npm to pnpm) that looks for overrides in a different location. "npm reads from overrides, pnpm from pnpm.overrides, Yarn from resolutions," he explained. "When a team migrates package managers and forgets to move their security pins, the package manager silently ignores them. No error, no warning, the vulnerable package ships unconstrained." Kapoor said that AI coding assistants commonly advise developers to add override entries when asked to fix a transitive dependency vulnerability. "That advice is correct at the moment," he said. "None of them ever tell the developer to come back and verify the entry still works." CVE Lite CLI, Kapoor said, does not recommend overrides as the way to properly address a vulnerable dependency. "Overrides look like a security fix in package.json, but routinely outlive their purpose – they can point at packages no longer in the dependency tree, apply to the wrong package manager entirely, or shift to an unintended version on every install," he said. "The override hygiene feature exists precisely because of this failure mode: teams add an override to address a CVE, move on, and years later, the override does nothing while they still believe they're protected." ®

OpenAI: Yoo-hoo, look over here, we do that security stuff too!

Mon, 06/22/2026 - 16:34
OpenAI announced a flurry of cybersecurity-related AI news on Monday, releasing an improved version of GPT‑5.5‑Cyber, its most advanced vulnerability-finding model, along with an expanded partner program for cybersecurity vendors, an update to its Codex Security scanner⁠, and an initiative to “Patch the Planet” – or at least 30 high-profile open source projects. The announcements come as Anthropic’s Mythos mess keeps getting more complicated, with national security concerns clouding defenders’ abilities to use that AI company’s most advanced models to find and fix vulnerabilities – or perhaps it’s just politics as usual. They also coincide with a general feeling of FUD around AI cyberattacks and the impending vulnpocalype. The Reg’s vultures will keep out collective eyes on all of this. First off: GPT‑5.5‑Cyber. After releasing a preview version of the model to a select group of “trusted defenders,” OpenAI on Monday released an update that it says makes the model even better at finding – and also fixing – bugs in code. “It is our strongest model yet for finding and helping patch software vulnerabilities, while retaining GPT‑5.5’s general-purpose intelligence and ability to work across long, complex tasks,” the AI shop said. “The model can sustain deeper analysis across large codebases: identifying security-relevant components, tracing whether vulnerable code is reachable, validating likely issues in controlled environments, developing and testing patches, and preparing evidence for human review.” OpenAI said it evaluated the update and 5.5 preview using a few different benchmarks: CyberGym, which test how well AI systems can reproduce known vulnerabilities; ExploitGym, which determines how well models can turn known vulnerabilities into working exploits that achieve unauthorized code execution; and SEC-bench Pro, which measures AI systems’ long-horizon vulnerability discovery and proof-of-concept generation capabilities. The updated version 5.5 outperformed the preview model in all three tests, we’re told. On CyberGym, the updated GPT‑5.5‑Cyber reached 85.6 percent success, compared with 81.8 percent for GPT‑5.5. On ExploitGym, it outperformed the earlier model 39.5 percent versus 25.95 percent. And on SEC-bench Pro, GPT‑5.5‑Cyber hit 69.8 percent, compared with 63.1 percent for GPT‑5.5. Plus, OpenAI assures everyone that it’s had “ongoing dialogue” with the US government, including about its latest model plus upcoming releases, so hopefully that insulates the company against any surprise export controls. OpenAI also expanded its partner program. The OpenAI Daybreak Cyber Partner Program currently has about 30 security-vendor and service-provider partners, and only these select firms get to use the updated GPT‑5.5‑Cyber model. OpenAI says it plans to add more organizations to the elite group “in the coming months.” FOSS flaw-finding Also on Monday, OpenAI announced Patch the Planet, an initiative to help open source project maintainers find and patch vulnerabilities. This initiative, co-founded with Trail of Bits and launched in collaboration with HackerOne and AI-powered bug hunting outfit Calif, provides participating open source projects with ChatGPT Pro, conditional access to its Codex Security scanner, and API credits for core development, maintainer automation, and release workflows. “Maintainers define their priorities, preferences, and established disclosure processes,” according to OpenAI. “Patch the Planet security researchers then manage the work end to end - validating and deduplicating both vulnerabilities and patches before they reach maintainers, significantly reducing the burden on maintainers and speeding up remediation.” Trail of Bits reports that in the first week alone, Patch the Planet uncovered hundreds of bugs, and generated 64 pull requests with 51 issues filed across 19 projects. The 19 projects Patch the Planet assists includes cURL, NATS, pyca, Sigstore, aiohttp, the Go project, freenginx, Python and python.org, urllib3, PyPI, SimpleX, Valkey, and RustCrypto. More than 30 projects have joined so far, and project maintainers can apply to join the initiative. Some of the initiative’s highlights from the week include using GPT-5.5-Cyber to build a full-scale fuzzing lab in under a day – an effort we’re told would have take human fuzzing experts two or three weeks to do manually. Patch the Planet also used Codex to build a CVE variant analysis pipeline. This also took less than a day to complete. Speaking of Codex: OpenAI on Monday released a Codex Security plugin⁠ that the company says “enables out-of-the-box defensive security workflows,” allowing developers to integrate Codex into their workflows and CI/CD pipelines. The scanner, which was released as a research preview in March, has so far scanned more than 30 million commits across more than 30,000 codebases, according to OpenAI. Of these, human reviewers have manually marked about 70,000 findings as fixed, and AIs have auto-determined that more than 500,000 findings are fixed. In addition to performing automated scans and reviewing code changes, the new plugin can “triage and validate existing findings from scanners, advisories, bug-bounty reports, or ticketing systems, then automate patch generation at scale to quickly close a backlog of vulnerabilities,” OpenAI said. After it completes a scan, the AI coding agent can export reports to existing vulnerability management systems or integrate into tools with SARIF files and CodeQL queries. “The plugin makes these capabilities much more accessible to support automated pipelines with Codex CLI or integrate into developer workflows in the Codex app,” according to OpenAI. ®

Texas lassoes massive Microsoft datacenter - and 20 years of gas turbine emissions

Mon, 06/22/2026 - 13:31
Never mind the fact that datacenter environmental concerns have come under growing scrutiny across the United States. Microsoft has just inked a deal with fossil fuel giant Chevron to supply one of the largest single-capacity additions to its datacenter fleet with 2.67 gigawatts of natural gas power for a full two decades. Chevron said today that it signed a two-decade power purchase agreement with Microsoft through its subsidiary Energy Forge One to supply 2.67 GW of power for a new datacenter project in West Texas dubbed Project Kilby. The natural gas turbines to be constructed on the datacenter’s site will sit behind-the-meter (Microsoft gets access to the power without it flowing through the grid first) and will be “among the largest co-located natural gas power and data center developments in the U.S.,” according to Chevron. Microsoft’s own press release on the matter, which doesn’t mention Chevron or Energy Forge One by name but does admit the new facility “will operate with a co-located natural gas power facility,” identified Pecos as the West Texas location where the bit barn will be built. The self-proclaimed birthplace of the rodeo is also a West Texas hub for agriculture and ranching, among other Texas-sized industries. Microsoft confirmed to The Register that, despite it not mentioning Chevron in the announcement, the power purchase agreement does concern the Pecos facility. The facility will be “one of the largest single-capacity additions” to Microsoft’s datacenter fleet “in our history,” according to Redmond’s release, and the company is trying hard to lean into its desire to be a good neighbor to the people of Pecos as it spends the next few years building the massive facility. Shouldn’t good neighbors care about air and water quality? “We know that being a good neighbor isn’t something you say,” Microsoft wrote in an open letter to the people of Pecos alongside its announcement of the new datacenter. “It’s something you prove over time.” That letter and the announcement take pains to point out all the good things Microsoft has done for the communities where it plunked down massive datacenters, and it wants the locals to know that the Pecos facility will be no different. Why, the very fact it’s building multiple gigawatts of natural gas power for itself proves just that! Building its own energy infrastructure, says Microsoft, will prevent locals from having to pay more for power. Additionally, the company anticipates eventually connecting its turbines to the grid and serving as a broader energy source, too. According to Chevron, the turbines being deployed for the Pecos datacenter include noise and light impact mitigations as well as “selective catalytic reduction” systems that reduce nitrogen oxide emissions. Not eliminate, mind you - just reduce. To get an idea of the scale of what Microsoft is planning to deploy with Chevron in Pecos, let’s consider the gas turbine generators that xAI’s Colossus AI datacenter installed in Memphis, Tennessee. That facility saw the installation of just 150 megawatts of gas turbines - roughly one eighteenth the size of Microsoft’s planned Pecos gas plant. Even at that small a scale, the xAI datacenter has still become the subject of a lawsuit [PDF] alleging that the facility is belching way too much smog into local communities for the air to be healthy and calling for it to be shut down. Emissions mitigations or not, one can't imagine the prairie sky around the Pecos datacenter will be as clear and high as it once was after the facility is completed. It’s worth pointing out that some of the turbines being deployed to Pecos will be manufactured by the deceptively named Solar Turbines, which actually builds gas power systems. According to reports and photographs out of the xAI Memphis facility, Solar Turbines also supplied gas turbines for Colossus. Then there’s the water concerns: Microsoft and Chevron both called attention to their plans to minimize water usage in Pecos, which lies in a part of Texas prone to drought and with limited access to fresh, potable water. “We are also designing our operations to minimize reliance on freshwater sources by utilizing nonpotable water where possible,” Microsoft noted. The company will rely on closed-loop cooling systems that will “significantly reduce water requirements.” As for the gas plant planned for the site, Chevron said that its facility will use “non-potable, brackish groundwater sources for power plant operations” instead of freshwater, but that doesn’t tell the whole story. Brackish groundwater, located in massive, salty, underground aquifers, is a major source of water for dry, dusty West Texas, and has been for some time. Desalination of brackish groundwater has been suggested [PDF] as a source of drinking water for the town and the surrounding region, raising questions about whether datacenters and gas power plants sucking it up to cool their jets are sustainable. Microsoft didn’t want to answer any of the questions we put to it aside from confirming Chevron’s press release related to the Pecos datacenter; Chevron didn’t respond. ®

Cloudflare teams up with big browsers to help websites tell welcome from unwelcome visitors

Mon, 06/22/2026 - 13:02
Cloudflare on Monday said that it has joined with the three leading commercial browser makers to create a privacy-preserving protocol that websites can use to separate desirable web traffic from undesirable network requests. Cloudflare, along with Google Chrome, Microsoft Edge, and Mozilla Firefox, have committed to develop Private Access Control Tokens (PACTs), a way for websites to generate a digital token that asserts a given browsing session is being run by a human or bot with legitimate intent, as opposed to network requests from people or software deemed abusive or improper. PACTs will let websites "with strong knowledge of 'personhood'" issue anonymous tokens that browser users and designated bots can present at other websites, so that fewer identity checks are necessary. Think of PACTs as a shareable, privacy-preserving CAPTCHA test result, where the desirability of the web traffic is being tested rather than whether the visitor is a human or bot – an increasingly difficult distinction. While the technical details are still being hammered out and harmonized between related proposals, it isn't immediately clear what constitutes "strong knowledge of 'personhood'" in this context, particularly since "personhood" appears to extend to software that has been authorized to act on behalf of a legitimate person for an authorized purpose. It may be that the test criteria puts certain browsers, behaviors, or network signals at greater risk of being denied the dispensation of a PACT, though past technical discussion by developers from Google and Mozilla suggests that excluding certain hardware, platforms, or user-agents is not a goal. Dane Knecht, CTO of Cloudflare, argues that the way people interact with the web is changing and increasingly may involve autonomous agents. "As AI-powered traffic becomes widespread, existing tools to support its use are too generic and coarse," said Knecht in a statement. "Now this collaboration lets us eliminate the friction caused by security protocols for every visitor – whether they are human or agent – without sacrificing privacy." The claim "without sacrificing privacy" is a bit of an overstatement. PACT tokens, it appears, will not contain personal details. But they won't do anything to repair all the other ways browsers can facilitate digital fingerprinting and tracking. And if implemented poorly, they may introduce novel risks. Fundamentally, they divide the internet traffic into welcome and unwelcome traffic – something already widely done through firewalls and other technical measures but not easily reconciled with the notionally open web. "Mozilla is committed to defending openness and user privacy on the web," said Bobby Holley, CTO for Firefox at Mozilla, in a statement. "An avalanche of automated traffic is pushing sites to adopt blunt defenses – paywalls, identity checks, CAPTCHAs, and invasive tracking – simply to tell whether a request comes from a human." While Cloudflare touts the privacy benefits of PACTs, it's clear from the company's announcement that the technology is designed to "empower businesses to identify genuine visitors, ensuring they can focus their resources on the traffic that matters to them." Essentially, this is an anti-fraud initiative. Many website operators have complained about the burden of handling unwanted network traffic from disrespectful crawlers. PACTs may be the answer to their prayers. At the same time, they may also become an access barrier that demands negotiation with site publishers to have one's site visits or software deemed worthy of "personhood." ®

Security shops among the 'hundreds' of Klue hack victims

Mon, 06/22/2026 - 12:50
The list of Klue customers whose Salesforce data was stolen in the latest supply-chain heist keeps growing, with an increasing number of cybersecurity companies disclosing that they are among the victims of a new data-theft and extortion crew called Icarus. Klue, which provides market intelligence to more than 250,000 companies worldwide, hasn’t said how many of its customers were caught up in the breach and didn’t immediately respond to The Register’s inquiries. Huntress was one of the first cybersecurity vendors to sound the alarm, and, in an email to The Register, said that it was among the “hundreds of Klue customers” affected. However, it said that the breach did not affect its tools or highly secure information such as passwords. “Huntress believes in radical transparency about security incidents, including when it affects our company,” the security shop wrote on Thursday. “The data that was copied from our Salesforce account includes business contacts, price quotes, and other sales-related data and messaging. No threat data, passwords, payment card information, or engineering data relating to the Huntress agent or telemetry we collect was affected.” Huntress, along with the other victim companies, said that there is no indication that any of its products or infrastructure were compromised, and that this security incident was specific to CRM data. Since then, several other security and software vendors including Recorded Future, Tanium, Jamf, Gong, HackerOne, Kudelski Security, Snyk, Insurity, and Sprout Social have revealed that the data thieves also accessed their CRM data via the Klue integration with Salesforce. Here’s what we do know about what happened and who is behind this latest extortion campaign. The breach occurred on June 11, and Klue spotted the intrusion a day later. This unauthorized activity affected “a portion” of its integration infrastructure, according to the software provider. Klue has since disconnected all of its integrations with Salesforce, Gong, HubSpot, SharePoint, and Google Drive. It also hired CrowdStrike to assist in the investigation and security response. “Our investigation determined that an attacker gained access through a compromised legacy credential associated with an integration service,” Klue CEO Jason Smith said in a Friday blog post. “The attacker used that access to obtain OAuth tokens used to connect Klue with certain third-party platforms, including Salesforce, and subsequently accessed data within a number of connected customer environments.” Mandiant CTO Charles Carmakal urged organizations using Klue integrations to “immediately audit their systems and monitor application logs for evidence of compromise over the past few weeks. Rotate credentials as appropriate based on the scope of compromise.” While the attack “resembles the 2025 and 2026 third-party OAuth abuse campaigns against Salesforce,” as ReliaQuest noted, a group called Icarus began posting victims on its data-leak site. It soon became apparent that this new extortion crew - not ShinyHunters, which has frequently targeted Salesforce and stolen data from hundreds of the CRM giant's customers in attacks over the past few years - was behind this latest supply-chain incident. Icarus, according to the group’s leak site, has been active since April 28. After compromising Klue, the criminals began emailing affected customers. Huntress shared its extortion message, with the subject line “top secret email” purportedly sent from “mr bean,” with The Reg, and we are leaving the misspellings, and poor grammar, as is. “This email is being written to you because your data as exfiltrated due to a breach happening to your partner, Klue.com (as them),” it reads. “Your Salesforce data has been downloaded. We advice you to write us on Session @” with a Session address, the email continues, and threatens to make the data public within 48 hours unless Huntress initiates communication with the criminals. “Do the right decision,” it says, “xoxo.” There’s a subsequent email that simply says “wrong session lol” and then lists the correct Session ID. Researchers don’t know too much about Icarus - yet - but this type of large-scale supply-chain attack typically paints an equally large target on the intruders’ collective backs. So we expect to hear more from law enforcement and third-party security sleuths in the upcoming days. “There is very little publicly known about [Icarus],” Huntress' Lindsey O'Donnell-Welch told us. “IP addresses from which they are known to have accessed sensitive information include the Netherlands, France, and Ukraine. But we cannot draw any conclusions based on that information alone as these may have been VPN concentrators or Tor exit nodes.” And while this intrusion “bears some surface-level similarities with prior Salesforce-focused extortion activity, we have not seen any evidence at this point linking Icarus to ShinyHunters,” O'Donnell-Welch added. ® Correction: An earlier version of this story stated ReliaQuest was a victim. That company has since clarified it was not.

Nvidia gets all agentic about supercomputing for scientific research

Mon, 06/22/2026 - 11:15
Nvidia is pushing agentic AI for scientific computing, and says that this requires a new scientific computing stack, which the GPU giant is ready to deliver, of course. At the ISC High Performance 2026 event in Hamburg, Germany, Nvidia is lauding its own achievements in supercomputing, highlighting just how many of the world’s top compute clusters use its hardware these days. But just as agentic AI has become this year’s buzzword in the machine intelligence industry, so the GPU slinger is pushing it as the next big thing for supercomputers and their research programs, driven by its next-gen Vera Rubin platform and new software tools. “We are currently witnessing a massive inflection point with agentic AI. AI is shifting from a tool that simply answers questions to an autonomous system that executes complex tasks,” Nvidia’s senior director of HPC and AI Factory Solutions Dion Harris told the media in a briefing. The Mission and Vision systems at the Los Alamos National Laboratory (LANL) in the US will be the world's first agentic AI supercomputers when they come online, he says. A new scientific computing stack connects agents, simulation, and AI together to accelerate the next generation of scientific discovery, Harris claims. “Scientists leverage agentic AI co-scientists that call simulators and surrogate models alongside tools and applications, to do everything from planned experiments to write code to run the simulations to simulations and AI and data analytics converging into one single workflow,” he explained. This requires an incredible amount of compute, memory, and networking, which, in Nvidia’s eyes, means supercomputers built on its Vera Rubin and Grace Blackwell platforms, plus Quantum InfiniBand networking, and new software for accelerating discovery. The latter comprises ALCHEMI, DAQIRI, and cuPhoton. The first is described by Nvidia as a domain-specific toolkit for chemical and material discoveries, using the BGR microservice for simulating millions of molecules and structures. DAQIRI is designed for the next-generation scientific instruments, connecting sensors directly to real-time AI inference points, Harris says. “At CERN's ATLAS experiment, less than 2 percent of collision data can typically be stored. DAQIRI introduces a GPU accelerated AI trigger pipeline allowing FPGAs to handle low latency routing while GPUs run deep learning models to ensure we learn from significantly more data,” he explained. Finally, cuPhoton is built to process petabytes of camera and telescope data to help scientists analyze massive cosmic data sets in minutes rather than months. “In testing with 32 Grace Blackwell superchips simulating data from the Rubin Observatory, cuPhoton loaded and read images 15,000 times faster and accelerated signal processing and analysis by up to 8,000 times,” Harris claimed. But Nvidia is pitching its next-gen silicon as the platform for agentic supercomputing. Due to be available in Q4 this year, the Vera Rubin NVL rack will cram in up to 144 GPUs per rack, and deliver 5 petaFLOPS of FP64 floating-point performance. Because many high-performance computing workloads are often bound by memory performance, Vera Rubin increases memory bandwidth by 2.8 times compared to Blackwell, Harris says, using 41 TB of HBM4 memory per rack to achieve three petabytes per second of bandwidth. Systems that are getting Vera Rubin include the Mission and Vision systems at LANL. These stack up to 2,160 Rubin GPUs plus 1,080 Vera CPUs, in the case of Mission, while Vision has a more modest 1,298 Rubins and 648 Veras. “Then there's Veritas, which is being announced at ISC, which deploys 576 Rubin GPUs, along with 288 Vera CPUs,” Harris says. We asked Nvidia what the purpose is of embedding agentic AI into scientific computing, much of which is about research driven by human curiosity. “Agentic AI, or in fact any AI, is not required to do science,” Harris told The Register. “But Nvidia believe agentic AI is already emerging as a powerful tool to do science at a scale that isn’t possible when human scientists alone drive the process. Agents don’t need to sleep, or eat, or take breaks. They can consume thousands or millions of technical papers and remember the details, and in some cases, they benefit from PhD-level understanding across diverse fields from astrophysics to zoology,” he said. Nvidia’s vision is that human scientists will have a team of agents running around the clock, able to do investigations they couldn’t themselves perform. “But agents require foundation models, LLMs, and connections to data and tools to perform science. They run on CPUs, but access tools, many of which need GPUs to run at maximum performance and efficiency,” Harris added. Nvidia claims that Europe is now a hotspot for HPC, with 35 new supercomputers brought online in the past year, all using Nvidia tech. These include Jupiter, Europe’s exascale system, MareNostrum 5 at the Barcelona supercomputing center, Bavaria AI's Blue Swan, HammerHAI at the University of Stuttgart, and Italy’s CINECA. ®

The database that refused to die: How Postgres survived its own creators

Mon, 06/22/2026 - 10:43
FEATURE Today Postgres is one of the most widely used database systems, but its launch and subsequent development were inauspicious to say the least. If it weren’t for a league of exceptionally devoted open source contributors, it probably would be another forgotten also-ran just like Ingres, the database system on which it was based (“Postgres” was shorthand for “Post-Ingres”). The creator of both systems, Michael Stonebraker, is perhaps the preeminent database pioneer in the field. Earlier this month, he spoke at PGDay, a conference in Boston hosted by the U.S. PostgreSQL Association, where he detailed the complicated history of the open source database system, which actually existed long before the term "open source" was even uttered. In a sense, “Postgres is the epitome of open source software, because it doesn't belong to anybody. It was picked up by this team of programmers without any specific affiliation,” Stonebraker said. Stonebraker essentially abandoned Postgres in the mid-1990s. But instead of fading into obscurity, the codebase was salvaged by a fiercely-dedicated volunteer community that bolted on standard SQL while preserving Stonebraker’s revolutionary extensible architecture. Three decades later, this stubbornly-independent database has become the bedrock of modern cloud infrastructure. Data should be relational When it comes to relational database systems, British computer scientist and then-IBM employee Ted Codd got the ball rolling in 1970. A database is where you store your data so it can be queried in a predictable way. A database system is the software that manages the database (don’t confuse the two). That year, Codd decreed that all data should be stored in tables and accessed using a high-level query language. IBM implemented Codd’s idea in System R, and created SQL as the query language. The results were eventually rolled into IBM's DB2. Stonebraker, then an assistant professor at UC Berkeley, also implemented Codd’s ideas. Stonebraker and his team of grad students created not only a working prototype, but a full-scale implementation – he later cofounded a startup, Relational Technology, to sell Ingres commercially. Ingres did not use SQL, but instead employed another query language, QUEL (Query Language), although the fundamentals were similar. A relatively primitive version of Ingres was even released gratis for academic research. But by the early 1980s, Stonebraker had “pushed the code off a cliff” and started building something new. Thus, Postgres was born. Beyond Ingres: Postgres At the time, Stonebraker explained, the business world was pushing for databases to hold additional data types beyond the integers, floats, and character strings required for basic business accounting. There was complicated CAD data and GIS data, with multiple data points that needed to be stored and reasoned against. It was clear to Stonebraker and his colleagues that the ideal database system needed to be extended with more data types, user-defined data types, user-defined operators, and user-defined functions. Adding more data types and such might seem simple enough, but the “devil is in the details,” he noted. “You need to be able to teach the query optimizer about new types, and that's not exactly easy.” Commutative rules had to be worked out, and they had to be optimized. This led to what was probably Postgres’ most successful feature: support for abstract data types (ADTs). Stonebraker had other ambitions for Postgres as well. He also wanted to incorporate new work from Chris Date on referential integrity, which brought “semantic consistency between foreign keys and primary keys” to the relational model. He wanted to add in a rules engine, which would continually monitor for changes and make decisions based on those changes. Also, he wanted crash recovery. The crash recovery and the rules engine never quite worked out, but the ADTs took root, and now most database systems support this extensibility, pretty much exactly like they were devised by Stonebraker and Co. in 1983. “We pretty much got it right,” he said. In fact, he reckons that his work on ADTs was probably the major reason he landed the Association for Computing Machinery’s 2014 A.M. Turing Award. Stonebraker and his mates were eager to make money from their creation. So they rolled Postgres into a start-up, Illustra, which was eventually purchased by Informix, which promptly digested the technology into its own database server. But they also maintained an open source version…barely. It wasn’t even called open source (which wasn’t a formal term until 1998). It was considered freely available academic software, something for fellow researchers to tinker with. And it was based on the very-permissive BSD license. The architecture that refused to die In 1995, two Berkeley graduate students, Andrew Yu and Jolly Chen, resurrected Postgres from the last 4.2 academic release. They jettisoned the poorly-running rules engine and disaster recovery features, and, most importantly, swapped out QUEL for the then industry standard of SQL, releasing the software as Postgre95 (and later PostgreSQL). “I didn't know any of these people,” Stonebraker said of this all-volunteer development crew. They were “a collection of super programmers who picked up this open source project and started shepherding it forward, and they've been shepherding it for the last 30 years.” This sovereignty made Postgres safe for anyone to use and modify. Postgres’ wire interface has been widely used as the base for building other database systems, including CockroachDB, YugoByteDB, and TimeScale. Amazon Web Services, Microsoft Azure, and Google Cloud each have their own database-as-a-service built on Postgres. Chief selling point? Each is fully Postgres compatible. “The elephants have basically bet the ranch on Postgres,” he said. Even AWS’ graph database service is built on Postgres (“the relational implementation of [a graph database] is almost always faster, usually substantially faster, than doing it natively,” Stonebraker quipped.) Top of the heap These days, Postgres sits near the top of the DB-Engines ranking of the world’s most popular database systems, just below Oracle, MySQL and Microsoft SQL Server. Unlike those rivals however, Postgres continues to steadfastly gain market share. Tom Kincaid helped organize the PGDay meetup – and is a vice president of EDB, a Postgres service company. He offered several reasons why Postgres made such a big impact, despite its initial lack of support from any of the IT giants (unlike the fellow open source MySQL, now managed by Oracle, which many open sourcerers distrust for that reason alone). Extensibility was a major help in adoption, especially as the role of databases expanded beyond basic business accounting. ADTs gave the database system an easy entry into an expanding geospatial market, and later, document databases. “Postgres was quickly able to provide developers exactly what they needed for storing, retrieving and searching JSON documents,” Kincaid told The Register. “The fact that you could combine SQL with many different data types allowed it to thrive with every new trend in application development.” Also helping was the quality of the codebase (“It is held to the highest standard of review,” Kincaid said) which attracted top developers, as did the quality of the optimizer. The permissive licensing also helped, allowing start-ups and project leaders to build derivative products without fear of legal repercussions. Why Postgres still doesn’t have file-level encryption Despite all the love from the open source community, Postgres is still missing features that it might need to maintain parity with commercial database systems. This was the focus of another illuminating PGDay talk by long-time Postgres contributor (and always dapper) Bruce Momjian. He ran down a long list of missing features, most of which the development team are currently grappling with. The database system could use 64-bit transaction IDs to accommodate very large databases. It could also use support for columnar storage, which is all the rage for large-scale data analysis. Global indexing, server-threading, internal connection pooling and sharding are also features in various stages of assembly. The major feature Postgres currently lacks, however, is file-level encryption, or “transparent data encryption,” as it is called in the industry. TDE is supported by all commercial database vendors, and it is required by the latest Payment Card Industry (PCI DSS) specifications for storing financial transaction data. Currently, Postgres lets the operating system handle the encryption. Current development on Postgres file-level encryption is stalled “in many ways,” Momjian said. “The code changes became too heavy for the value of the feature,” he said. Not only would the functions touching the data files themselves need modification, but all the other functions scattered through the system that write temporary files must be altered as well. This would be a “monstrous” job, he said. Still, missing features allow commercial entities to fill in the gaps. Percona, for instance, offers the feature as part of its own Postgres commercial distribution. Commercial database companies are very sensitive to customer requirements, whether those requirements are truly necessary in a practical or technical sense, or if they are merely external or regulatory in nature. It’s the latter set of requirements that don’t make it to the top of the Postgres to-do list as quickly, Momjian said. “We don't want to add a feature unless it really has technical value,” he said. Momjian pointed out that the PCI mandate itself also has questionable value purely from a technical view. Once the contents are copied into the server’s memory, the encryption protection vanishes. If an attacker can bypass a system’s file system permissions, they can probably read the raw working memory and get the encryption key. “If we're trying to lock down the file system, we'd also have to lock down memory. We don't know how to do that,” he said. But the missing TDE may not even be a bug at all, but an actual feature of Postgres's fundamental philosophy. “While proprietary databases target the workloads of their largest customers, Postgres targets the workloads of general users,” he said. And that may be the best kind of success for an open source project. ®

Ukraine puts its Russian war trophies online for allies to pick apart

Mon, 06/22/2026 - 10:19
Russia’s equipment losses in Ukraine are about to become the world’s gain, as Kyiv has decided to hand out its intel on seized Russian battlefield assets to its international partners. And it has launched a new site to do so. Announced on Friday by Ukraine’s Ministry of Defense, the TrophyLab is being billed as a place for Ukraine and its allies to analyze Russian military technology for the benefit of both Kyiv’s government in its current fight against Moscow, and for anyone else that might face off against Russian gear in the near future. “From now on, the entire democratic world will have access to the secrets of Russian weapons and equipment,” the Defense Ministry said in a press release. International partners also have the opportunity to obtain samples of war trophies for their own research efforts via the program. As for how much equipment is in the database so far, the Defense Ministry said that TrophyLab currently contains samples from more than 115 war trophies divided into 79 categories, including bombs and missiles, aircraft, drones, electronic warfare equipment, tanks, and even small arms. More than 225 prior studies of the seized equipment are also included in the TrophyLab dataset, and that’s just the beginning, with Ukrainian defense forces, the Main Intelligence Directorate, and the country’s Security Service all continually providing data for the program. The included total so far is likely just a fraction of the data Ukraine could share with its international partners, as Russia’s losses since its 2022 invasion of its southwestern neighbor have been extensive. One estimate last year by the US Center for Strategic and International Studies suggests that Russia lost more than a thousand armored fighting vehicles, at least 3,000 infantry fighting vehicles, 300 self-propelled artillery units, and nearly 2,000 tanks. That only includes losses sustained between January 2024 and June 2025 when the report was published, mind you, meaning the actual total may be far greater. Russia’s gains in Ukraine have been largely erased outside of the Russian-annexed but contested Crimean peninsula, where it has focused most of its energy of late. Even then, it hasn’t had a successful run of things, with Ukrainian forces continuing to bomb its soldiers, forward bases, and logistical routes using long-range drones. Speaking of long-range Ukrainian drones, international media has been filled with images lately of Moscow being bombarded by suicide drones that have flooded Russian airspace and repeatedly struck a major oil refinery despite being shot down by the hundreds, according to Russian state media. Ukraine has captured some Russian territory, but like Russia's gains in Ukraine, many of those advances have been pushed back, leading to a prolonged stalemate between Russian forces and Ukrainian troops. Ukrainian scientific organizations, military units, and defense sector firms are all eligible for access to TrophyLab, as are the governments and defense departments of Ukraine’s allies and defense contractors in partner nations. That said, access is being tightly controlled. In order to get a peek at the TrophyLab data, applicants need to prove they don’t have any ties to Russia, haven’t been sanctioned by Ukraine, and meet other criteria set by the MoD. “Every missile, drone, and vehicle seized on the battlefield is now a source of knowledge for the free world,” Ukrainian defense minister Mykhailo Fedorov said of the new platform in a social media post over the weekend. “What was meant to be the enemy's secret advantage is being dismantled to defend democracy.” ®

Pages