Be a hater all you want, AI's here to stay
AI gets things wrong, it kills jobs, and when the bubble bursts, it will take the economy down with it. When all's said and done, however, AI will still be standing and fundamentally change our lives and work. Get used to it. I get it. There's a lot to hate about AI. Personally, I'm both an AI user and an AI hater. Yet at the end of the day, it doesn't matter how much you or I dislike it. AI isn't going away, and it will end up stronger than ever. Let's start from the top, shall we? First, AI has been destroying jobs and will continue to do so. Research house Forrester, for example, predicts that by 2030 AI will wipe out 10.4 million US jobs. That's 6.1 percent of all US jobs if you're counting at home. Tech companies are already filling unemployment lines with one cut after another. Amazon, Oracle, Microsoft, Meta – the list goes on and on. Sure, some companies have finally figured out that AI can't replace as many people as the C-suite might want, so now they're hiring people back. That won't be enough to matter. We're in for a fundamental shift in work. First, it's going to hit junior employees, like entry-level programmers. Who wants to pay money to someone fresh out of college to do work that Claude Code, OpenAI Codex, or GitHub Copilot can do? No one, that's who. In the long run, that means we won't have anyone to replace mid-level and senior developers, but businesses don't think about the long term. It's about the next quarter's almighty stock price. The one thing that can stop this is the rising cost of AI compute. AI companies are losing money hand over fist. With the rise of token-based pricing, businesses may have to face the terrifying truth that AI can cost more than employees. Eventually, though, AI will be cost-effective and efficient enough to kill off many white-collar jobs. It just won't be as soon as many bosses want. A related problem is that a handful of major companies currently control AI. There are a plethora of AI businesses, but I suspect many of them are dead companies walking. They're hoping to be bought out before the music stops and they're left standing. Even some of the biggest of them – I'm looking at you, OpenAI and Oracle – may go down too. Regardless of who wins and loses, if you're using AI in the West, you're almost certainly using a proprietary model. Open weights are gaining traction, yet for now at least you're still stuck with letting Big AI look over your shoulder to cherry-pick your work and data. Don't believe me? Go take a look at your AI providers' end-user license agreement. I'll wait. Scary, isn't it? I hope that open source AI approaches such as OpenWALDO take off. If open source doesn't, we'll be stuck in the same expensive mess as we were from the '80s through the 2010s when Microsoft ruled the desktop. If we work together, we might avoid this fate at least. Another issue is that, thanks to AI, we're increasingly unable to tell the truth from fiction. Generative AI produces persuasive prose, images, and video regardless of accuracy. People reasonably worry about fraud, deepfakes, political manipulation, fake evidence, citation laundering, and a general erosion of confidence. In a recent Pew's survey, 76 percent of Americans said it was very or extremely important to distinguish AI-generated content from human-created material, yet 53 percent lacked confidence that they could reliably do so. They have reason to worry. Most people can't tell the difference between facts and fiction. I've made my living from being able to tell the difference. Just because Perplexity, which I now use for search instead of Google, tells me something doesn't mean I trust it. I prefer Perplexity because I can chase down its sources and judge whether its answer resembles the truth. Other assistants can make it harder to establish where an answer came from. AI has gotten good at coding, but it still sucks at facts, and I don't see that changing anytime soon. The bad news, though, is that people increasingly don't give a damn about the truth. They want to be told a comforting lie. Just look at the garbage the Trump administration and its fellow travelers spew every day, and you'll see what I mean. AI is great at telling people what they want to hear. Sooner or later, though, reality has a nasty habit of slapping you in the face. With all this, why do I think AI will eventually win? Because I've been to this rodeo before. I'm old enough to remember warnings that calculators would destroy our ability to do math, claims that word processors would never replace typewriters, and assurances that the internet would never put print media out of business. Wrong, wrong, and oh so very wrong. Just like the technology revolutions before it, AI's benefits – ease of use, comforting lies, and eventually low prices – will overwhelm people's resistance. AI is the lazy person's answer to many problems, and you should never bet against human laziness. What are lost jobs, rising electricity costs, and datacenter pollution compared with that? So, hate it all you want, proclaim yourself a 21st-century Luddite, and say "I told you so!" when the inevitable AI bubble pops. A decade from now, we'll all be using AI, and our kids will be wondering what all the fuss was about. ®
Code fixers have fired up the AI warp drive. Strange new worlds await
It is the best of times, it is the worst of times – especially if your job is keeping systems patched and up to date. Microsoft has gone from 60-90 Windows security fixes per month last year to a record of 600+ this July. Oracle and Linux are following the same path, and they are very much not alone. The good news is that a lot of bad things are getting fixed very quickly. The bad news is that patches can bring side effects of their own. There are two mechanisms at work, both driven by the source of and solution to all our woes, AI. The first is that the appropriate LLMs and their humans have got very good at bug hunting. Like demon archaeologists, they've started thrashing their way down through the stratified layers of long-established code bases, bringing a huge backlog of previously buried bugs to the surface. Complicating matters, LLMs are also writing an awful lot of code, some of which is not very good. It is making its way into production for all the old reasons – marketing-led deadline pressure, shape-shifting specs, and Brownian goalposts – until the implacable hostilities of reality spit it back out. The result is a very interesting dynamic of conflicting pressures that is changing the nature of patches. It's easy to assume that the current explosion of bug fixes will die down as the code bases are repeatedly refined and purified, and that this time next year we'll be seeing rather fewer patches than in the pre-AI days, let alone today. It's a nice thought. Similarly, with the old code in a new state of grace, attention can turn to properly generating and testing the AI-powered stuff, so that it too calms down. Other factors will work against this. Newer models may find new classes of bugs or start refactoring for efficiency or structural reasons. Not all patches fix bugs, and not all bugs are vulnerabilities. CVEs are easy to count, but aren't the full story. The pressure to release early won't go away either; better tools often encourage greater recklessness. Vibe check, anyone? Finally, the bad guys aren't going away and will be using all the new shiny to keep up their side of the arms race. This whole system of conflicting pressures in a morphing environment has not been well studied, and the future shape of patching is unclear. One analogy suggests itself, that of stellar evolution. Astrophysics fans know the score. After a star condenses out of gas and dust, gravity compresses its core until it becomes hot and dense enough for nuclear fusion. Hydrogen nuclei fuse to create helium, releasing energy that pushes outward against the gravity trying to squeeze the core further, and the star shines steadily. When the hydrogen in the core runs low, that balance changes. Depending on the star's mass, it may begin fusing helium and successively heavier elements before fusion becomes impossible. The possible endings include explosions visible from other galaxies, black holes, neutron stars, cooling relics, and more. In this analogy, patch generation is fusion pressure, bug generation is gravity, and the nature of bugs and patches evolves as the two interact and the code changes. If any unit of code, no matter how badly written, can contain only so many bugs, then the model tends toward the white dwarf outcome: a remarkably long-lived object that passes the rest of its existence without drama or intervention. It no more needs patching than a pebble does. It is certainly true that, despite the best efforts of many, code design and implementation are ultra-reliable compared with the days when Windows BSOD'd every other day – and on the hour if you installed drivers – and Big Three PC database company Ashton-Tate's industry nickname was Crashed and Late. If the object of the industry was to produce pristine versions of, say, Windows 10, then the white dwarf patchless future would be the most plausible. That is not the industry objective. If a star is big enough, its ending can be a supernova birthing a black hole, a singularity beyond observation where gravity has won. In this case, the battle to write ever-more complex yet bug-free and optimal code is locked in the attempts to find ways to break it, either as part of the production pipeline or in adversarial attacks. If models advance as hyped, iteration times could become so short, and constantly morphing production code so difficult to analyze, that the very model of patching breaks down. The daily build becomes the product, and you get the latest version every time you run it. That may seem an extreme cosmology, but it's not so far from what happens every time you fire up a cloud app. You've never had to patch Google Docs, but you've had features appear and disappear overnight without explanation or warning. This, then, may be the shape of patches to come, a universe where the increasing power of coding and testing models enables new and stranger commercial pressures to modify the software you depend on. You don't have to plot that path. Some software has a more steadfast physics. Not for the first time, those who navigate by the constant star of open source may have the safest voyage. ®
Black Hat and DEF CON are AI conferences now, too
KETTLE Our cybersecurity editor Jessica Lyons spent last week in Las Vegas for the Black Hat and DEF CON security conferences, and at both events there was only one thing on everyone's mind: AI agents and their growing threat to cybersecurity defenders. You can listen to the latest episode of The Kettle right here on this page, as well as on Spotify, Apple Music, or YouTube. Those platforms also let you subscribe to Kettle, so you are always notified when the latest episode goes live. As Jess wrote this week, pretty much every discussion she had last week centered around AI and its potential effects on critical infrastructure, with multiple current and former government leaders expressing worry over recent events and what they mean for the future of infosec. Join Jess and host Brandon Vigliarolo for this week's episode of The Kettle, where they break down the hacker summer camp scuttlebutt and what the security world is doing to protect critical infrastructure from the emerging AI threat. A lightly edited transcript is below. Brandon (00:04) Hello everyone and welcome to the latest episode of The Register’s Kettle Podcast. I'm Reg Reporter Brandon Vigliarolo, and you know, I really thought doing a wrap up of Black Hat and DEF CON with our cybersecurity editor Jess Lyons would finally give us a chance to talk about something besides AI for an episode, but I was mistaken. That's pretty much apparently all anyone was talking about in Las Vegas this weekend, even when the topic veered toward recent attacks on US water infrastructure, AI was still part of the conversation. So Jess, thanks for coming on to wrap up Hacker Summer Camp with me and let's start with the obvious, then AI was the topic de jour, right? JESSICA (00:38) Yes, that was even compared to water, we really didn't hear much about water actually until DEF CON, which was surprising to me. But it was all about rogue agents escaping their sandboxes and doing bad things and some people reacting with shock and disbelief and other people saying, “Well, what did you expect? They're given a task, they're going to do it. This is how we train them.” Brandon (01:04) know you wrote a story I think pretty much right at the beginning of of the of the week about the OpenAI hugging face discussion that was going on and we actually covered your write up on last week's Kettle. Sorry you weren't here to participate, but it was the news item of the week obviously and still is. So what did we learn then? Just kinda recap what we learned at that talk that we didn't know before. JESSICA (01:29) Yeah, this was a really interesting one. And it was last minute. They didn't even announce it until the day before that OpenAI was going to be doing this briefing about the hugging face attack. So it was packed, as you can imagine, the line through the conference center to get into the talk. And we found out a couple interesting things that we didn't know previously. One is that this whole incident began a lot earlier. It started on May 7th with this training run for OpenAI's new internal model. Brandon (02:00) So it wasn't even a cybersecurity task, it was just a training run? JESSICA (02:04) It was a training run, and they gave it this task that turned out to be an impossible task because they were supposed to have these links and containers for it and they forgot to put those in there. So it needed to find a workaround. so we found out that it started way earlier. It didn't start in July, which is when we started hearing about all this. But the more interesting part was how the agents began communicating and working together and essentially creating this hive mind to complete the tasks and help each other out. They created a message board. And then OpenAI realized this and they revoked all the credentials that the agents were using to post these messages. And two days later they rebuilt it and they developed this really Brandon (02:56) The agents did. JESSICA (02:57) Yeah the agents did. They rebuilt this message board. And they started getting sneakier about how they were communicating. They developed this whole communication protocol where they created these directories and the names would be embedded in the directory name. So there was one, its name was remote probe, and then in caps it's pending, hold, swarm until confirm. And they would preface them with a bunch of Z too to push them way to the bottom, hopefully to avoid detection. And then they start, you know, then they start helping each other out. And in some cases, they said, this doesn't directly relate to our task, but maybe it will help someone else down the line. And then they start getting paranoid that there's an imposter. JESSICA (03:45) It's pretty funny reading all this. So this one agent thinks there's an imposter and says that these these boards are unauthenticated. Something can be posted by anyone. So they're not even trusting each other. Brandon (04:02) That's just wild. I mean, it really is. I think I mentioned on last week's podcast thatthese things are trained on the way humans think, right? JESSICA (04:14) Mm-hmm. Brandon (04:15) So it doesn't surprise me that emergent behavior like paranoia and suspicion is gonna be something that occurs. Because it's learning to think and learning how to assemblebits of of words together into its mathematical formula so it's gonna behave like us to a degree. And so it's just kinda interesting to see that happening kind of outside of any scope of intention there. JESSICA (04:42) Right. Brandon (04:43) I liked your interview with former National Cyber Director Chris Inglis, at Black Hat. So he mentioned that these AI bots that escaped are kind of like putting a dog trained to hunt rabbits in your backyard, right? And that, you know, it JESSICA (05:03) Right, and leaving the gate open. Brandon (05:05) Yeah. I don't even think you need to leave the gate open, right? A dog that's dead set on hunting a rabbit is gonna dig a hole under that fence which is I feel like what these AIs did to a degree, right? They even closed the gate on them and then they just dug a new hole. You know, it's just wild to think that this is what these things are doing. You've been hearing a lot about this at official talks, but was this something you were hearing from attendees you spoke to as well? Is this what's on the mind of security professionals too? JESSICA (05:36) Yes, this was pretty much the main topic among everybody. Just attendees as as I was walking out of this talk, actually people were disappointed that there wasn't any Q&A for OpenAI about this, which I agree. I was hoping for that too. Brandon (05:55) I'm not surprised that they didn't want to give the floor to people to ask questions, you know. JESSICA (05:59) Right, right. Because there's still like we don't know exactly what prompts they used. So that kind of would be a nice thing to know, especially if you're saying that you're being fully transparent about this and then also the talk about was this marketing, was it real? Brandon (06:17) Mm-hmm. JESSICA (06:17) It's an interesting thing to me. Nobody would go on the record, but a ton of vendors that I spoke to, either, you know, just just all over the place at Black Hat essentially said “this it has a heavy dose of marketing here, but a lot of the companies work with open AI and they're partners with open AI, so nobody's gonna say that on the record, unfortunately. JESSICA (06:41) But then the interesting thing to me is that when I spoke with the assistant director of the cyber division with the FBI and when I spoke with Chris Inglis they both said it can be both and this is a real threat and this is something that we need to prepare for now. So it's marketing and it's real. Brandon (07:08) Right, right. Like, I mean it's it yeah. The fact that the companies might be kind of leaning on these incidents to basically say “ooh, look how dangerous our AI is and what it's capable of doing. You should buy it because it's so good, right?” JESSICA (07:20) Right. Brandon (07:20) The fact is that it still happened, right? These things still escaped their sandbox. JESSICA (07:22) Right. Mm-hmm. Brandon (07:23) And they still attacked Hugging Face. And then Anthropic followed up and said “yep, ours did it too.” And then Meta was like, “Yeah, we audited ours and yeah, it was doing the same thing.” So it's not like this is a unique capability of any of these models, right? This is something that's happening. JESSICA (07:37) No, it's something that they all will do if they're given a task. This was something that Chris Inglis brought up too, and he's talking about Asimov’s Law, saying we need to train these models differently. The first rule needs to be that it's not designed to hurt humans. And he said “we've kind of done it in the opposite, where the first rule is do what I tell you to do. And that should be third in the order here.” Brandon (08:06) Just to restate what Asimov's laws are. I'm sure most of our readers are familiar with them, but for those who aren't, it's you know, the first law, and these are in order of precedence, right? So never harm a human. And then the second rule is to always obey humans unless that order conflicts with number one. And then the third rule is to protect their own existence unless that order conflicts with never harming a human or always obeying humans. I think Inglis's quote to you was slightly different. He said that number one was to hurt no one. Number two was always obey and then number three was do what humans tell it to. It was a bit different in his wording, JESSICA (08:35) Mm. Mm hmm. Yes. It's Brandon (08:41) But essentially the argument is that we've reversed that order and these AIs obviously aren't in the business of protecting their own existence, right? They're not robots, they don't have a physical presence in the world. But they're taking orders from humans, but the idea of not harming people or the infrastructure that provides for them is simply not part of the equation, it seems like. JESSICA (09:04) Right, right. And he said because of this, I mean nobody should be surprised that this is what all of the agents are doing now because they're trained to first complete the task. That's the number one priority. And we've seen several times that they'll cheat if it helps them get the results quicker, or just at all. So this isn't something that should surprise us. And then he was interesting too because I said, “Well what do you worry about then with the models in addition to attacking critical infrastructure?” Cause that was what everybody said, I'm you know, that's what concerns me when we see this happen, but they're being used by either a nation state or a financially motivated attacker, and they point these autonomous agents at critical infrastructure. And he said, “I'm worried about humans too, because it's the humans who are responsible, humans who are doing the training, and essentially we're going to get the AI that we deserve.” Brandon (10:08) Well, unfortunately, I feel like the industry as a whole is just racing ahead with more capability, JESSICA (10:11) Right. Brandon (10:12) I've written stories, you've written stories. I think we've all written at least one or two stories about AI guardrails being dead simple to bypass, right? I mean, one I wrote recently was there was you know, some research into guardrails and essentially telling it you owned the infrastructure you were trying to attack was enough for most of these AI models to say “yeah, cool, that's good then. As long as you own it and you're just testing it, then that's cool. I'm not gonna ask you to verify that information for me.” These things are not developed with safety in mind. I feel like it's capability first, like you said, right? It's train the dog to hunt the rabbit, no matter the cost or or what you gotta do to get it. and that's you know, that's not really compatible with protecting us. But actually speaking of critical infrastructure, I think the other big topic like you mentioned was water stuff. JESSICA (11:04) Yes. Brandon (11:05) There was a lot of discussion about AI threats and critical infrastructure, but as I understand it, there's been some of these attacks on water infrastructure and those were discussed recently, like in Minnesota and elsewhere. There's not an AI link directly to that, correct, at this point? JESSICA (11:23) No, no. At this point, it's pretty basic. It's PLCs being exposed to the open internet. A lot of these just use default passwords. This is something that we've seen Iran especially do several times in the past for years now. They're not very hard to attack. and so, to be clear, there's no indication that AI was used in these attacks. but a lot of the conversation about water did come back to AI because, as we've seen in others, AI makes reconnaissance a lot easier. That's one of the things that Google Threat Intelligence, their lead threat hunter, said that's almost a security feature of a lot of operational tech technology, is that it's really obscure and there's not a lot of people who know a ton about it. But now you can ask a chatbot, hey, tell me everything I need to know about a particular brand of OT, a particular piece of equipment and that's gonna speed up your time to learn about these and that's that potentially makes it easier to attack these systems. Brandon (12:31) My biggest experience with OT and that kind of technology was when I was working at a particle accelerator in college as IT support. And there was a big OT network there, not only for like the machine shop and all this equipment they had that was old and didn't have active security stuff, right? Like you gotta keep those segmented, you gotta keep them on a separate, you know, OT network. Same with the actual accelerators and stuff. They were all cut off from the internet, right? But at the end of the day, you could still get to them from the IT side. You know, you have to, you know, and even that can be exploited. We did as much as we could to keep stuff secure, but it was always a concern, right? These PLCs, these old pieces of equipment. JESSICA (13:11) Right. Right. Yeah. Brandon (13:14) You know, a lot of places don't take that same approach.I think part of one of the stories you wrote was talking about the fact that a lot of these water utilities, a lot of these small institutions that are that are responsible for maintaining this critical stuff. They just do not have the security professionals they need to keep these systems safe. JESSICA (13:32) And that's why they leave them open in some cases, exposed on the internet because they don't have somebody in-house. They have somebody remote who's doing this for them. And so that's how this person is able to hopefully secure, but then it opens up another attack surface if they're exposed to the internet. and that that was another yeah, Brandon (13:51) Yeah, with a D password on there. JESSICA (13:54) Yeah, and with all of these OT systems too. That kind of brings up another point that Chris Inglis brought up. We have this massive technical debt and it's systems that haven't been patched because a lot of it involves some downtime and that's tricky if you're running something like a water facility or some other critical infrastructure. And so patching is put off. Maybe it's not done. Some of these are very old legacy pieces. Sometimes it's end of life. And that's another thing that AI is really good at is finding vulnerabilities that haven't been patched for years and years and years, chaining them together. So that's another thing that puts these systems potentially at risk. Brandon (14:41) Yeah, I mean, you know, I think of an AI when I think about AI perpetuating or perpetrating some of these kinds of attacks, right? They're quicker than a human. They have knowledge bases far in excess of what any one human threat actor can have. And they have instant access to all the information essentially that they need to figure out how to do this, right? And they can iterate so quickly. You know, you know, it's just it yeah, any exposed piece of equipment on the internet is just a sitting duck, especially if it hasn't been updated four or five months or or ten years or whatever. I mean, what, you know what's being done about this. I know DEF CON, the Franklin program, which spun up in 2024, I think the whole focus of that program is helping out small local governments and protecting critical infrastructure. Is that right? JESSICA (15:30) Right. So when they founded it was the broader critical infrastructure. But I spoke with Jeff Braun and he's one of the co-founders of that. He also is one of the pioneers of the voting village at DEF CON. Brandon (15:42) Mm-hmm. JESSICA (15:42) And he said that now and for the foreseeable future, water is going to continue being the top focus because, of all the critical infrastructures, small rural water providers are the most at risk. Brandon (15:57) Really? Even more so than small electrical providers and stuff? Okay. JESSICA (15:59) Yes, he said water is number one. So they like he said, they launched a couple of years ago. They got, I believe 300 people saying, “Yeah, I'm gonna volunteer my time and my expertise to help secure these small rural utilities.” And this year, he said that it's been great. It's been really encouraging to see all of these pilots all over the US with all the DEF CON hackers volunteering at them, but it's the scalability that’s really proven a challenge. And so that is what gave birth to their new announcement. This also was made the first day of DEF CON on Friday. They announced a new program and it's called Water Watch Center. So initially, it's going to fund five managed services providers focusing on security. They're going to help these small utilities, people or the utilities that are serving less than 10,000 people. and they'll put their sensors on these systems, they'll detect and mitigate breaches. They'll be kind of under the umbrella of the National Rural Water Association that's going to act as this clearinghouse for the threat information and get it out to other utilities as needed. And then if the utilities can't fix the issue themselves, then they're gonna bring in the DEF CON hackers and then they'll mitigate the breaches. yeah. Brandon (17:28) Fantastic. Well hopefully that is able to help with a lot of these. My hope is that there's a lot of easy fixes, right? It's just simply no, this PLC needs to not be exposed to the internet or something. But I also worry that there are a lot of those kind of situations, right? I mean, how many water utilities got attacked recently? Was it I think twelve different states? JESSICA (17:47) It was more. There were twelve different states. I mean, there were more than thirty across possibly Minnesota alone, but there's quite a few. So it's an easy target. and it's something that they desperately need help with. And it's really encouraging to see these hackers volunteering their time and they're not getting anything out of it. It's a really cool program. I was really happy to see the expansion. Another thing, too, that is pretty cool, what they're also doing is they're partnering with Vanderbilt University. So they're gonna use research from a DARPA program. It's called the CASEL program. That stands for Cyber Agents for Security Testing and Learning Environments. So they're gonna create digital twins for a couple of these water and wastewater system environments. And then they're gonna deploy red and blue team agents across the digital twins, let them fight it out, see what the learnings are, see what the blue team agents need to do to better protect these systems, and then apply those learnings to the actual facilities so that hopefully we can get better defenses in place using the help of of AI agents before we see actual bad guy red teaming agents come in and start hammering the utilities and trying to attack them. Brandon (19:12) Right, 'cause I think actually thinking back to one of the stories you wrote again, I think you mentioned or someone you quoted mentioned one of those stories at DEF CON and Black Hat that there is more aggressive use on the threat side than the defensive side of AI right now. Like there was more use being made to use it as an attack tool than a defense tool. JESSICA (19:33) Right. And a lot of that's in the way the models are trained, but basically they are a lot better at attacking than defending, especially if it's beyond the scanning for vulnerabilities and misconfigurations. Those we're pretty good at, but what needs a boost is the defensive side. And that's gonna take some work to get those skills and the models trained up on that, if we're going to be actually, as everybody likes to say fight AI with AI. Brandon (20:04) It's one of those sort of, you know, cyberpunk dystopia stories I feel like you hear about is just like, you know, you deploy your AI, they deploy their AI, and all the humans sit back and hope theirs wins. You know, and it's kind of what it's coming down to. Yeah, it's in the process. JESSICA (20:19) Right. And hope they don't wipe us all out. Brandon (20:25) It's kind of terrifying. But speaking of, you know, hackers behaving well, we also have a story out of DEF CON of hackers behaving badly. I wrote about this earlier in the week that there was apparently a Delta Airlines flight out of Vegas to Atlanta and I think it was Monday morning or so, in which a passenger apparently tried to jam the in-flight Wi-Fi and deploy a decoy network. And Delta was pretty quick to be like, “Hey, we got a bunch of hackers on the flight who are leaving Vegas after this big thing.” There’s not a lot of information out there about this. Delta, local officials and the feds have all been pretty tight lipped about it. Delta did confirm it to us when I asked, and said, “Yeah, this is what happened, but no one was at risk, you know, everyone was safe.” But I mean, it's not a good look for the community, right? I mean, it's nice that they have something like Franklin going on, but this is kinda like, Great, thanks guys, you know. JESSICA (21:16) Right. If it was people coming from DEF CON, it's really discouraging to see this happening because a lot of times just “hacker” has a bad connotation. And a lot of researchers have really been trying to change this. I think programs like DEF CON Franklin make a big difference or even people just going to DEF CON. I really like the community feel. I think for the most part, and of course not everybody is good in the world, and that applies to the hacker community as well. But a lot of them are trying to use their skills for good and not evil. And so then when you see something like this on the airplane, it's disheartening. And on social media, I mean the outrage was pretty immediate, people saying, Come on, what are we doing? You're giving all of us a bad name here. Why are we doing this? So Brandon (22:15) Mm-hmm. I mean, it's already I feel like the joke every year is, well, didn't DEF CON get cancelled, right? Like because of all the bad press and everything. And I feel like this is one of those things that you're just like, you know, I remember a couple of years ago there was the huge kerfuffle about the hotels, you know, treating all these attendees like they were criminals right off the bat. And this doesn't help, you know? JESSICA (22:35) Right. Brandon (22:35) But yeah, hopefully I mean apparently the FBI I think spoke to Ars Technica and said that they had not made any arrests. So this hasn't really necessarily progressed toward that. But my hope is that whoever was responsible, you know, gets what's coming to them and we can, as a cybersecurity community, walk away from this and be like, this is one bad actor, not the entire culture. JESSICA (22:59) Right. Brandon (23:00) They fought for years to change that. So I guess before we wrap up, you know, this was a pretty doom and gloom recap of DEF CON and Black Hat, right? JESSICA (23:09) Ha ha ha. Brandon (23:11) All this AI's gonna end the world, our OT and our infrastructure's gonna be destroyed. Anything, you know, less miserable that grabbed your attention while you were there? Any fun stories or interesting things you saw? JESSICA (23:26) I mean, it was really fun. Again, I'm not quite sure if this falls in the not-doom and gloom category, but it was fun for me to watch hackers hacking bomb robots that the police used and bomb squads used to defuse bombs. So that was fun. You're walking around to the different villages and seeing people helping each other out and getting really into all of these different villages and all the different tasks. or you know competing for the best tinfoil hat or beard and mustache. So that was fun. Brandon (24:12) Was anyone doing the beer chill? When I was there in twenty twenty four, there was a group who was trying to chill beer as quickly as possible. JESSICA (24:19) I did not see that. It's very possible. I mean, to be fair, I did not see every single thing. There's so much to see so it's very possible. I missed that though, unfortunately, if that happened this year. So it's fun to see what people are doing. It's really fun and inspiring to see the creativity. And it's fun for me too to hear about some of the startups and how they are using AI and they're using it for different security use cases and hopefully that continues to improve and increase and hopefully that does give defenders an edge. So I think there's always a bit of a silver lining. It's always this cat and mouse race, but hopefully the defenders win out. Brandon (25:11) Yeah, it's a constant like you said. It's an arms race; it's constantly evolving. But like you said, it is encouraging to see, attention being paid to this, effort being put in to help defenders use these tools for good and not evil, even if some people turn around and make a bad name for everybody else on the way out the door. Either way, you know, it's gonna be something that we're probably gonna be discussing again, right? Like I thought this was gonna be a less AI heavy conversation, but it wasn't. JESSICA (25:36) No. Brandon (25:39) You know, it'll be a topic of conversation for years to come and we will be here on the Kettle to talk about it. Thanks for joining me this week and thanks for tuning in, everybody.
Part didn't fit so techie got out his screwdriver. Then something flew off the motherboard
WHO, ME? Is it a mistake to return to work on Monday? While you ponder that question, pause a minute to read this installment of "Who, Me?" – The Register's week-opening column that shares your stories of workplace errors and escapes. This week, meet a reader we'll Regomize as "James," who told us that in the early 2000s he worked in the biology department of a famous American university. "We custom-built all our PCs from the cheapest available parts at the time we ordered," James wrote. Which was how he found himself struggling to attach a heatsink to a CPU destined for use in a new PC. "The stupid hook wouldn't go over the plastic tab and so the heatsink didn't want to stay on," he wrote. "Not one to let a computer component get the better of me, I grabbed a flathead screwdriver, stuck it into the little leverage point in the heatsink clamp's arm and leveraged the hell out of it." The result of that decision was audible. "It went PING! and a tiny piece of something went flying away, but the heatsink was now securely mounted," James told The Register. He therefore connected the PC to power, turned it on, and… wondered why its fans blew up a storm, but nothing appeared on screen. "I removed the CPU, removed heatsink, and took a closer look to find the source for the PING. And there it was, or rather wasn't – a very tiny and apparently very important surface-mounted component of some sort was missing right next to where the metal clamps for the heatsink hook in." James was very clearly at fault, but decided the way to fix the problem was to fib about it. "I played dumb and called it into tech support at the company we ordered the heatsink from," he confessed. "They were very nice, accepted the part was dead on arrival, and sent me a replacement right away." "Needless to say I was much more careful with the replacement, which worked great," James told Who, Me? What have you broken with a screwdriver? And how did you get away with it? Click here to share your story with The Register. If you want us to use your story in a future Who, Me? we suggest using a keyboard and mouse – not a screwdriver. ®
Linux 7.2 debuts, Linus Torvalds says ‘new normal’ means he had to do it now ... or never?
Linus Torvalds has decided version 7.2 of the Linux kernel is ready for release, albeit in a “new normal” state that he seems not to entirely love. The kernel boss announced the debut of a new kernel in his weekly development status update, which on August 16 opened with the observation that “this last week of the release was – once again – bigger than I would have wished for.” He attributed that uncomfortable size to what he last week described as “the new normal” for the kernel at a time when developers have increased the volume of contributions using AI coding tools. “If I delayed releases for that reason we'd probably never have a release at all,” Torvalds wrote, before adding that the release includes “a number of fairly late reverts - the drm scheduling reverts stand out, but there's a few other ones in here too.” “It may not be pretty, but it's the correct way to deal with ‘Oh, that code wasn't ready and caused problems,’” he wrote. As ever, the new kernel release includes important and seemingly frivolous inclusions. Among the latter is support for a gaming controller called the “Zenaim Leverless,” which offers a collection of buttons on a black slab. Apparently e-sports pros think it’s just the sort of thing they need to rack up high scores or crush their foes during tournaments. And now they can use it with Linux! Perhaps more relevant to a majority of Reg readers is the inclusion of a tech called “Cache Aware Scheduling” that makes the kernel better at handling the data stored in caches across manycore chips like AMD’s EPYC 5 and Intel’s Xeon 6. Qualcomm senior engineer Vishnu Santhosh wrote a good explainer about the tech. Long story short, it’s about making processors aware of useful data already in a cache, so they can use it instead of doing extra work to access the relevant data. The release also includes work that makes it possible to run Linux on Apple M3 devices, the usual handful of graphics updates, and work to ensure that the kernel will be ready to support next-gen chips from AMD, Intel, and Nvidia. Notable deprecations include ending support for AppleTalk, and for old-school ISA and PCMCIA adapters used on ARCNet networks. This hits hard because The Register believes that PCMCIA stands for People Can’t Memorize Computer Industry Acronyms, and not for the Personal Computer Memory Card International Association. ®
Sainsbury's staff eject wrong shopper after facial recognition alert – again
UK supermarket giant Sainsbury's temporarily suspended live facial recognition (LFR) at one of its stores after staff wrongly ejected a shopper in response to an alert – the second such incident this year. Matt Arnold, 46, was ejected from the chain's store in East Dulwich, London, on August 6 after staff responding to a Facewatch LFR alert apparently mistook him for a suspected thief. The comedy promoter told the BBC that he was using a self-service checkout and called an assistant over to approve an alcohol purchase. Instead, two Sainsbury's managers approached him, refused to serve him, and linked him to an incident earlier that week. Arnold said he was told that the store's LFR system had identified him in connection with a previous offense before he was escorted from the premises. "They came over and said I had to leave," Arnold told the broadcaster. "The staff member said I'd been identified by the AI, and the cameras had flagged me. "A shoplifter does not walk around with that much shopping, they don't scan it through, they don't put their Nectar card through. "But what upset me was thinking this is what the future could be – people just listen to what the machine tells them to do without thinking about the consequences." Sainsbury's told The Register that the mistaken ejection resulted from human error rather than a false match by the Facewatch system. A spokesperson said: "We have contacted Mr Arnold to apologise for his experience at our Dulwich superstore. "The incident was caused by human error, not the facial recognition technology. Customers can be reassured that the Facewatch system has a 99.98 percent accuracy rate, and every match is reviewed by a trained manager." A Facewatch spokesperson likewise said: "We can confirm that our live facial recognition technology was not at fault in this incident. A correct alert was sent to the retailer, but was subsequently subject to human error in the way it was handled and communicated by the retailer." We asked Sainsbury's what exactly the human error was in this case, but it did not reply. The Register understands, however, that Arnold's ejection was similar to that of Warren Rajah, who was wrongly removed from the chain's Elephant and Castle store earlier this year. As in Arnold's case, Sainsbury's maintained that the Facewatch system had worked as intended. Regarding Rajah, the supermarket said the system correctly identified someone linked to a previous theft, but staff responding to the alert approached the wrong person. Rajah said at the time that he was approached by three store managers holding smartphones. They looked at the screen, then at him, told him to leave, and pointed to an LFR flyer posted up near the store's entrance. Arnold told the BBC that, as he left the store, he looked behind him and saw what he believed was a security alert displaying his face inside a red circle. Sainsbury's temporarily suspended LFR alerts at the store while it reviewed its internal processes and considered additional staff training. Facewatch said: "When we suspend a retailer from our system, this is a precautionary measure that prevents the store from receiving further alerts while the retailer reviews its use of the system and undertakes appropriate actions, including further colleague training where necessary." Sainsbury's announced a major expansion of its LFR deployment last month, confirming plans to install the technology in up to 200 stores by the end of the year in an effort to tackle shoplifting. The technology currently operates in 55 stores, and the supermarket claims that 90 percent of people identified through the system do not return. Despite Facewatch's oft-touted 99.98 percent accuracy figure, other wrongful interventions involving the technology have been reported at UK retailers. Retailers using the technology include B&M, Budgens, Costcutter, Iceland, Southern Co-op, Spar, and Sports Direct. ®
Microsoft blames AI for delayed Exchange update, can’t say when it will arrive
Microsoft has blamed extra work created by AI bug-finders for the delayed release of a major Cumulative Update to Exchange Server Subscription Edition (SE). Redmond’s Exchange team made that admission last Thursday in a post titled “Where is Exchange SE CU1 anyway?” that reveals the software giant is “getting questions from our customers on when they can expect us to release Exchange SE Cumulative Update 1 (CU1).” “After all, in the past we mentioned that it would be released by the end of the first half of calendar year 2026, later updated to ‘second half of 2026’. What is the deal? Where is CU1?” For those of you who came in late, Exchange SE is the subscription version of Microsoft’s email server, and a Cumulative Update (CU) is a new version of the package that includes all recent bug fixes, plus other changes such as new features or removing deprecated code. Microsoft publishes CUs once or twice a year. Some users prefer applying CUs to applying every patch. As Exchange SE is a subscription product, not getting CU in a timely fashion isn’t a great example of why pay-as-you-go software is a great idea. Microsoft explained delays to the arrival of CU1 by referring to the fact that “Over the last few months, various Microsoft execs made statements explaining how Microsoft is leveraging a variety of AI tools to help find vulnerabilities in our products.” The post says the Exchange development team is “working through reported issues – which includes validation that they are real security issues, reproducing, fixing, testing for regressions / issues after fixes are deployed and releasing updates monthly.” Redmond’s missive also points to Microsoft’s pledge to “prioritize security above all else” as a reason for delays. A reminder: Microsoft adopted that stance after flaws in Exchange led to an attack on Exchange by suspected Chinese operatives, earning it a tongue-lashing from the US government. The Exchange team says that while trying to stay on top of bugs, it is also working on CU1. “We are regularly rolling our monthly security payload into our internal CU1 build and plan to release Exchange SE CU1 as soon as we get a reasonable stable point and have a month without pressing security payload.” The Exchange team has adopted that stance because it doesn’t want to publish CU1 and then find it needs to replace it with another that includes new security updates. “That would create double the update work for many organization administrators,” the post explains. “Even internally, trying to ensure that two major releases (Security Update and a CU) get appropriately tested so we can ensure high quality and nothing falls through the cracks would be very challenging as CU1 must be all inclusive of everything that we released since the RTM.” Exchange admins will likely appreciate the fact that Microsoft doesn’t want to burden them with two major updates to implement. They may also wonder when Microsoft will find a month in which there is no “pressing security payload” that takes priority over CU1. Microsoft’s post offers little certainty because it concludes: “In short: Exchange SE CU1 is coming; we do not have a date to give you. But we did not forget about it.” Nor, it seems, did Microsoft plan for how AI-powered bug-finding would impact product development teams. ®
Chinese AI company Zhipu claims its new is a better bug-finder than Anthropic, OpenAI
ASIA IN BRIEF Chinese company Zhipu last week launched a new AI model called GLM-5.3 that it claims has bug-finding powers that match those possessed by American models. The company’s announcement includes benchmark data that finds GLM-5.3 beats Fable 5 and GPT-5.6 Sol on the CyberGym benchmark, a test of a model’s ability to solve real-world cybersecurity challenges. “As we scaled post-training, cyber capability developed faster than we expected. GLM-5.3 is state of the art on CyberGym for vulnerability discovery, and its gains are largest further up the exploitation chain,” the company wrote, adding that the model “did not simply become better at identifying isolated flaws: it began to reason across multiple stages of exploitation, forming coherent plans for complete exploitation chains.” The company said it has worked with Chinese companies to test the model on real-world codebases, and found 2,436 vulnerabilities across 269 projects, including 1,097 medium-to-high severity issues. The findings span system kernels, operating systems, browser engines, open-source infrastructure, web applications, and network protocols. “Many had remained unnoticed for years or even decades, with the oldest dating back roughly 40 years,” the announcement states. GLM-5.3 also performed worse than western models on other security and coding benchmarks. Yet the fact that the model is a highly-capable bug finder signals that China is not far behind in terms of being able to poke holes in its rivals software and developed that capability very quickly after the debut of Anthropic’s Mythos. Any advantage the US felt it had as the home of Anthropic has therefore dissipated. Korea signals legal action against Apple, Google app store strangleholds South Korea’s Communications Commission last week found Google and Apple had abused their app store monopolies, and promised stern sanctions will follow. In 2021, South Korea passed world-first legislation requiring app store operators to offer the option to use third-party payment schemes. Apple and Google did so, but charged a 26 percent transaction fee for doing so – meaning they earned almost as much revenue when users chose third-party payment providers as they did from their own schemes. The regulator has previously warned that it will impose the highest possible penalty available under law, which is three percent of revenue earned by non-compliant behaviour. That’s probably back-of-the-sofa money for Apple and Google. India has banned rideshare operators from offering customers the chance to specify the amount they will tip before a driver accepts a gig. Uber India introduced the feature last year, seemingly copying it from an Indian rideshare operator called Namma Yatri. Consumer affairs minister Pralhad Joshi criticized Uber for the practice at the time, as he saw it as a means for users to effectively jump the queue by offering drivers more money – and for rideshare platforms to improve their revenue because if tips are higher, so is the platform’s share of the gratuity. Last week, India’s Ministry of Road Transport & Highways issued a directive (PDF) banning the practice. Henceforth, rideshare apps can only offer users the chance to tip at the end of a journey, and all of the tip must go to the driver. “No feature, prompt, message, add-on, payment option, or user interface element should be displayed before completion of the ride that directly or indirectly encourages, induces, or creates an impression that payment of any additional amount may improve ride confirmation, driver acceptance, driver allocation, waiting time, or quality of service,” the directive states. Indian services giants reveal data breaches Indian tech services giants TCS and HCL last week both admitted to data breaches but say customer data is safe, and only employee data is at risk. TCS published a stock exchange filing that opens “This is to inform you that Company has received threat-intelligence alerts alleging possible exposure of certain employee information.” The filing says TCS investigated the matter “and has not found any credible evidence of a breach of TCS systems or customer environments.” The company says leaked info is “basic employee information” and more than four years old. Note that mention of the stolen data being at least for years old, because TCS’s filing says the attacker claims to have used password spray and Multi-Factor Authentication (MFA) fatigue to pull off the heist. TCS says it “had strong safeguards in place against such techniques for more than two years,” perhaps suggesting the data heist occurred before the company shored up its defenses. “Based on the current review, these controls remain effective, and the Company continues to monitor the environment closely,” the filing states. HCL also used a stock exchange filing [PDF] to address what it called “claims made by a hacker group of potential exposure of limited data elements relating to HCLTech employees.” The company described the stolen data as “limited and dated to a few years back,” and added its assurance that customer data is safe. HCL’s investigation is ongoing. Lenovo’s enterprise unit finally posts a big profit Lenovo last week announced its quarterly results, including a $777 million profit for its Infrastructure Solutions Group (ISG) – the biz based on the 2014 acquisition of IBM’s x86 server operation that has seldom produced positive financials. Even during the early years of the AI boom, ISG’s profits were modest – just a few million dollars per quarter on turnover of billions. The business unit won a record $8.5 billion of revenue, up 98 percent year-on-year. AI was a big reason for the result, as buyers sought hardware to run inferencing workloads, The company says it has a pipeline for $54 billion of AI server sales, and has become the number two x86 server vendor as measured by revenue. Overall revenue came in at $26.95 billion, up 43 percent year-on-year, and cash won by its PC-led intelligent devices group jumped 27 percent to $17.1 billion and saw its PC market share reach 24.2 percent. Lenovo reckons the strength of its supply chain helped make those outcomes possible. India to build astronaut training facility India’s Space Research Organization (ISRO) last week issued a tender for construction of an astronaut training facility. The tender mentions extensive air conditioning works, plus a swimming pool, suggesting India wants to build a large tank in which the Vyomanauts who will fly its future Gaganyaan missions can train at home, instead of traveling to Russia or elsewhere as has been the case in the past. The tender covers $2.75 million worth of work. ®
Stopping a cyberattack while walking your dog - defensive AI security CEO says it's not ruff to do
Corma CEO Alon Pluda says his AI security startup aims to close the "defense gap," where models are better at offensive security. He tells the story of one customer, a security executive who was walking his dog when he received a notification on his watch from a Corma agent. “It said, 'I just caught a live attack. I need your permission to block it,'” Pluda told The Register in an interview. The security boss approved the agent’s action; the agent blocked the malware and the attacker from moving across the company’s network and mitigated the intrusion in under 10 minutes, Pluda said. The customer later described "walking outside with his dog, and blocking a real-live attack with his AI coworker" as "one of the most magical moments of his year," Pluda recalled. Pluda founded Corma about a year ago. And yes, all you Lord of the Rings nerds, the company gets its name from the Elven word for “ring.” “We’re building the one ring to rule them all, but this time for the defenders to have this power.” Earlier this week, the company announced $60 million in seed funding led by Sequoia Capital, alongside Khosla Ventures and Coatue. He told us that his startup is working with Fortune 100 companies, and training models to achieve “superintelligence for defensive cybersecurity.” Models from OpenAI, Anthropic, and Google are “amazingly good” at coding and language, and this includes finding and fixing bugs, and orchestrating tools across multi-step workflows, he explained. “When you combine it with agentic capabilities, they move from being incredible vulnerability researchers to end-to-end attackers,” Pluda said. “So inherently, what we’ve seen in the last few months is the models getting exponentially better at offensive security, like we saw with the OpenAI and Hugging Face incident.” But these same models aren’t as skilled at carrying out defensive security tasks that don’t involve scanning code for vulnerabilities and misconfigurations, he said. “The vast majority of defensive security tasks don’t have anything to do with code.” Corma recently tested four frontier models - Claude Opus 4.8, GPT-5.5, Grok 4.3, and DeepSeek V4 - as both attackers and defenders across the same fake company and its networks, built to closely mirror a multi-business enterprise. The attacker’s task was to plant a backdoor and the defender’s task was to find it and stop the attack. Closing the defensive gap Corma ran all four models against each other in every attacker and defender pairing, including each model against itself, with 15 independent engagements per pairing for 241 scored engagements. Across all of these, the models successfully implanted a persistent backdoor in 85 percent of their runs. However, these same models only detected 19 percent of attacks. “That speaks to the inherent imbalance we are trying to solve,” Pluda said. “The general foundation models are getting exponentially better at offensive security, but haven't been able to improve on the same rate on defensive security. So our mission is to close this gap, and make sure the defenders win in this intelligence-versus-intelligence game - or war.” Corma calls this the defensive gap, and says it has to do with the data these models are trained on and the objectives they are trained against, which lend themselves to offensive security. Defensive security, however, involves reading logs, events, configurations, audit trails, and on-disk state. This is “structured machine data that is neither prose nor source, and a small share of what these models see in training,” according to Corma’s research. “They appear to read it less reliably.” Plus, defensive reasoning is more open-ended, while offense has a straightforward goal - like “make this work” or “break this” and a checkable finish. Agentic defenders “Defensive security,” according to Pluda, “is about finding needles in the haystack.” Corma’s models power its AI agents, which organizations can deploy like “team members” who then operate across defensive security tasks. “It’s a generalized workforce, and you can assign it to whatever security tasks you want.” Fortune 100 and 500 organizations across healthcare, financial services, energy, critical infrastructure, retail, and other sectors have deployed Corma’s AI workforce across their environments, according to the startup. These early deployments, we’re told, have reduced threat response times by more than 94 percent, expanded security coverage by 15 times across different security functions, and uncovered multi-stage attack campaigns. “If you can get AI that is smart enough, intelligent enough, knows the domain enough, optimizes for the right things enough, and you can actually trust it, end to end, all the way to responding to real-live attacks, you can reduce all of these metrics significantly,” Pluda said. “And you can cover way more ground than what is possible with just human intelligence.”®
The what, why, and how of pull requests and source comments
Veteran Microsoft engineer Raymond Chen has weighed in on the difference between a pull request description and comments embedded in the code. Both matter, but they serve very different purposes. As Chen noted on his The Old New Thing dev blog: "The PR description is a point-in-time statement, providing information that is relevant to the code review itself. "It is an exercise in persuasive writing: You are trying to convince the approver that your change should be accepted." And sticking text in the source? "Comments in the code are for talking about the code itself. What is the correct way to call this function? Does it have specific prerequisites? This information is durable: It is information that remains useful even after the pull request completes." We'd argue that commit messages should be considered as well, but the distinction between PR descriptions and code comments is timely, given the volume of pull requests being generated by AI coding tools alongside some occasionally "interesting" annotations. Then again, anyone complaining about comments in AI-generated code would be wise to inspect those written decades ago by one of this writer's former colleagues. They consisted of pages apologizing to whichever future programmer had to untangle the spaghetti of C++ lurking through a maze of modules. Another colleague refused to annotate their code at all, insisting it was "self-commenting." These days, an honest comment might read: "This was written by , and I have no idea how the heck any of it works." It echoes another perennial developer dispute: whether code should be indented with tabs or spaces. In 2024, another Microsoft veteran, Larry Osterman, took a decidedly fence-sitting position: tabs were fine when storage was at a premium, but spaces now make more sense "because it always works and it's always consistent." Chen's position on tabs versus spaces is not widely known, but his broader opinion on code formatting was straightforward: "I don't care how you format your source code. It's your source code." He did suggest making any wholesale change in layout or formatting a separate check-in, so maintainers aren't faced with an epic diff dominated by a new style guide. All of which brings us back to Chen's distinction: the PR description explains why maintainers should accept a change, while comments preserve what future programmers need to understand the code. ®
ChainDrop worm crawls into npm supply chain, evades standard defenses
A new variant of the Shai-Hulud npm worm has poisoned hundreds of packages while adding propagation techniques that can leave little trace in the corresponding source repositories. In Frank Herbert’s Dune, Shai-Hulud was the name of the giant self-sustaining desert sandworms that moved silently beneath the surface of the planet Arrakis. So it made sense that when some new self-replicating malware with computer worm-like behavior appeared in September 2025, security researchers would name it after Herbert’s fictional creatures. The latest variant of Shai-Hulud, dubbed “ChainDrop” by Microsoft and others, is no mere sequel, however. Now, the npm community is discovering a Shai-Hulud variant spreading with new stealthy superpowers that circumvent the usual safeguards of open source repositories. On August 4, multiple security researchers identified a large-scale npm supply chain attack using this Shai-Hulud variant that had infected 444 packages from multiple publishers, which are collectively downloaded about 2 billion times a month. The operation targeted widely used deep infrastructure dependencies, such as keyv, flat-cache and cache-manager. Abby Kearns, CEO of enterprise open source security company ActiveState, noted in a Medium post that what is unique about this particular attack is that it doesn’t use the typical methods of breaching the defenses of open source repositories. Even if you never install an infected package (“npm install” in npm argot), you can still get the nasties – though that is one possible route of infection. Once triggered, ChainDrop also places startup hooks into the repository configuration files themselves: Simply opening an infected Git branch in VS Code or Claude Code can bring your repository under ChainDrop’s control. Scouring your code itself may not provide evidence of tampering. ChainDrop propagates not by repository source commits but by tarballs, an archive format for downloading file packages. ChainDrop travels by tarball When executed, the software scours the user’s workspace for npm tokens with full write privileges, as well as for other credentials like cloud keys and secrets. It looks in shell configurations, environment variables and even live memory. Any purloined data is encrypted and sent back to attacker-controlled endpoints. Should it find an npm token, it then downloads the tarballs of all the packages that token has full access to, bypassing the repositories themselves. That’s the genius part: ChainDrop self-replicates by rebuilding the tarball to include its own payload. Reviewing the source code repository won’t reveal any evidence of shenanigans. ChainDrop’s attack is two-pronged. It also searches for GitHub credentials. If it finds any, it queries the GitHub API to list all accessible repositories and branches and then commits its malicious configuration code directly into those branches. So when other developers open these repositories using Claude or VS Code, a background task gets triggered that harvests credentials, beginning the whole cycle anew. What a dev can do This attack is particularly pernicious because npm is widely integrated into automated CI/CD pipelines, which can automatically pull patch updates for dependencies during a rebuild - giving the worm a path to wiggle into fresh builds. If you think you've been infected, the first thing to do is check for any .claude/settings.json and .vscode/tasks.json files you did not add yourself, ActiveState’s Kearns advised. And don’t just check the main branch, but all the other branches as well. All the infected packages were quickly yanked from npm. Open source security firm SafeDep offers a list of all the compromised packages along with version numbers, so check those against what you currently have running. Beyond cleaning up the mess, developers and security teams should rethink how their systems could be breached in light of ChainDrop. Trusted publishing tools such as GitHub Actions should be evaluated, for starters. Begin “treating repository-supplied configuration as executable content, because that is what it is now,” Kearns wrote. “What this campaign really found was an execution path that dependency scanning tools were not configured to look at, sitting inside the exact tools engineering organizations have spent two years adopting as fast as they could,” Kearns wrote. “This is the first campaign to notice the gap and use it at scale. It will not be the last one.” ®
Lego's supersized Hubble deserves a little more shine
Lego has released its largest Hubble Space Telescope yet – a model built at approximately minifig scale that dwarfs the observatory included with its Space Shuttle Discovery set. The first thing to say about this set is that there is an awful lot of grey. This is perhaps the greatest weakness of an otherwise excellent set and feels a little penny-pinching on the part of the Danish brick botherer. Lego has produced several versions of Hubble over the years. There is a version to fit in the payload bay of its large Space Shuttle Discovery set, and a much smaller incarnation on a plinth in the Women of NASA set. Both are retired, so scratching that Hubble itch with a current official set means dropping £119.99 on the Icons Hubble Space Telescope. It's a large set. According to Lego, the 1,252-piece set measures 32 cm tall, 38 cm long (with the aperture door open), and 38 cm wide. An astronaut minifigure is included to indicate the model's approximate scale – a shame there's just one, since the servicing missions had a pair of spacewalkers – along with a power tool. There is also a stand featuring some of Hubble's iconic imagery and a plaque with more information, including the dates of the Space Shuttle servicing missions. Lego has not included replacement instruments to recreate the various servicing activities. Inside are Lego representations of Hubble's instruments and systems, including its gyroscopes, primary mirror, and secondary mirror. Outside are posable solar arrays and antennas, along with an aperture door that opens. Some parts are a little fiddly, and the set is aimed at ages 18+. That seems a little on the high side, but this isn't something you'd want a young child trying to build. The level of detail is impressive, considering the nature of Lego components, but it is difficult to avoid all that grey plastic. The Hubble Space Telescope included with the Space Shuttle Discovery Icons set uses silver bricks, which makes the choice of grey plastic feel cheap in comparison. And then there are the stickers. Thankfully, there aren't too many, but printed parts are readily available, and Lego uses its own, so why make builders fiddle with sticker alignment? And then there are the solar arrays, which are single-sided and feel a little cheap compared with the arrays on some of the MOCs The Register has built over the years. Still, these are minor niggles in what is otherwise a fun build lasting 6-12 hours. The set is an excellent addition to the Icons range, but such is the affection for Hubble that details matter. The set also acknowledges Hubble's 35th anniversary, celebrated in April 2025, with a "35" decal on the back of the astronaut minifigure. The real thing continues to orbit, although its days are likely numbered. The Lego version is likely to endure until a careless elbow knocks it off the shelf, or a creative builder decides to repurpose its components for an orbital animal amusement park. Which, after all, is the whole point. ®
Anthropic says text watermarking scheme relies on inconsequential words
In an effort to "watermark" text that Claude has generated and comply with the EU AI Act, Anthropic unveiled a plan on Friday to modify its bots' choice of words in a way that would be detectable as AI. Traditional watermarks are patterns or images overlaid on currency, postage, or official documents as an assertion of authenticity. In the digital realm, the term is more flexible and can refer to a variety of techniques for applying an identifier to electronic data. Anthropic's approach involves influencing inconsequential word choices made by its models, a technique introduced in Google DeepMind's SynthID-Text paper. To oversimply things, large language models work by predicting the next word in a sequence of words. The AI biz explains that while composing sentence output like "The weather today was cold and…", a model like Claude might respond with words like "cold" or "gray" and would be unlikely to respond with a word like "sugary." That's the theory, but when actually asked to complete that sentence, Claude Opus 4.8 went a bit overboard: "…crisp, the kind of cold that nips at your fingertips and turns your breath to little clouds. The sky was a pale, washed-out blue, and everything felt sharp and clear. "Want me to take it somewhere specific — cozy, gloomy, cheerful? Or keep going with the same tone?" But remove whatever training has been applied to promote engagement and simulate literary style, and that's basically what Claude is doing here – predicting the next word in a sequence. Anthropic asserts that in most cases, the example sentence could be completed by either "cold" or "gray" and "the meaning of the sentence is largely the same either way." The watermark gets generated by deviating from the predicted word to something else. A different source of randomness is used and that can be detected with a digital key. As Google DeepMind researchers explain in their paper, "Generative watermarking works by carefully modifying the next-token sampling procedure to inject subtle, context-specific modifications into the generated text distribution. Such modifications introduce a statistical signature into the generated text; during the watermark detection phase, the signature can be measured to determine whether the text was indeed generated by the watermarked LLM." Anthropic insists this will be done with low-stakes passages in a way that won't alter the meaning. "In internal testing, we’ve seen no impact of watermarking on the content, level of creativity, or readability of Claude’s text," the company said, adding that in a controlled study, human raters saw no difference in quality between watermarked and unwatermarked answers. That assumption hinges on not applying the watermark to any consequential text. As Anthropic puts it, "Watermarking is sparser on factual passages where there are fewer choices that can be made without decreasing the accuracy of the text." The biz goes on to say that the situation is similar with code – the watermarking algorithm can't simply start swapping method names. In the context of literature, the notion that some words are interchangeable is likely to raise a few hackles. While it may be a satisfying thought experiment to imagine Claude emitting, "It was the best of times, it was the least of times…" or "Telephone me Ishmael", anyone trying to pass off generated text as serious writing probably should face whatever social backlash watermarking may entail. On the plus side, Anthropic's flavor of watermarking isn't excessively intrusive. It doesn't involve any personally identifying information and only serves to indicate that Claude was probably involved at some stage of the creation of the marked text. What's more, the technique is expected to be only semi-effective. In its FAQs, Anthropic points out that some amount of editing should erase the watermark. "Light editing probably won’t remove the watermark completely; a complete rewrite where every word is replaced will," the company said. "In the latter case, of course, it’s arguable whether the text can any longer be described as AI-generated." In all likelihood, Anthropic doesn't care if its watermarking scheme can be defeated. The company's post makes clear that it is doing so as a matter of legal compliance and has chosen a solution that doesn't raise costs. "Watermarking has a negligible impact on the speed of models, and because it produces no extra tokens, the model is the same price to serve and use," the biz said. Hey Claude, what's another word for performative compliance? ®
DeepSeek's innovative harness treats everything as a plug-in
DeepSeek has piqued the interest of the developer community by releasing an early version of its open source agent harness. This happens as harnesses have become increasingly important to those working with machine learning models. "Powered by the Cordis meta-framework, DeepSeek Harness is an agent harness built around one core idea: Everything is a plugin," the China-based AI biz said. "Models, tools, skills, sessions, sandboxes, filesystems, loops, orchestration, and UI are ALL implemented as plugins, and can be mixed, matched, replaced, and extended." The term "harness" came into common use this year to describe a longstanding software function – middleware or a mediation layer that handles the input passed to an AI model and the output returned from it. Harnesses oversee prompts, context management, tool orchestration, the agent loop, state management, error handling, safety, permissions, and related concerns. Claude Code serves as a harness for Anthropic's Claude model family and Codex performs a similar function for OpenAI's GPT model family. And there are many other model harnesses, including Aider, Cline, Goose, OpenCode, OpenHands, and Pi, to name a few. The term isn't precise: It may be used to refer just to the agent loop and tools, or it may be extended to a broader set of concerns related to orchestrating different tools, services, and capabilities like sandboxing, subagents, and so on. Google Antigravity, for example, consists of the Antigravity Agent Runtime (harness) that can be accessed through the Agent SDK, the Antigravity 2.0 desktop application, and the Antigravity CLI. Vague definitions aside, AI model harnesses are now where much of the competition is happening, particularly as models proliferate and become commoditized. The harness often implements the user interface, a source of user inertia, and once developers configure their tooling and become accustomed to doing things a certain way, it becomes more burdensome to switch to a competing product, even if the interface consists mainly of a command line. What's more, various studies have suggested that model performance (and cost) varies significantly with the harness used, due to different design choices. For example, the Pi coding agent relies on a minimal system prompt of about 200 tokens. Claude Code by comparison uses a system prompt of around 10,000 tokens (or did until last month when Anthropic trimmed the system prompt by about 80 percent). The same model will produce different results with different harnesses. DeepSeek Harness is noteworthy because of its innovative design, and because it shows Chinese AI labs moving to compete beyond model benchmarks and pricing. First, it treats everything as a plugin. It uses the plugin system from its underlying Cordis framework, which is designed to make it possible to add and remove components dynamically without wreaking havoc. "Plugins provide every agent capability, including models, tools, skills, sessions, sandboxes, storage, loops, scheduling, and the UI," the DeepSeek Harness website explains. "Cordis services and events let the plugins work together. Developers can select, swap, or extend any capability in configuration without changing the DeepSeek Harness source code." A DeepSeek paper [PDF] by researchers Yifan Shi, Wei Zhang, and Tianyi Cui explains the function of Cordis in more detail. Cordis is designed to support dynamic composability – adding plugins and removing them on the fly without breaking the application. The paper refers to this as temporal composability – removing a component and reverting its effect upon removal – and spatial composability – allowing components to manage dependencies upon other components. It cites as an example the plugin system used by Microsoft's Visual Studio Code. VS Code, the authors explain, runs all of its extensions in a shared process called the extension host. Once activated, they cannot be removed on the fly; the host has to be restarted. While VS Code provides a way for extensions to declare dependencies between extensions, it's seldom used. DeepSeek Harness supports plugin dependencies. The DeepSeek researchers argue temporal and spatial composability are necessary in a system where modification can occur continuously with little or no human oversight. It's a way of avoiding forced restarts and crashes when components appear and disappear. DeepSeek Harness also supports another useful feature: chain of thought traces. "Everything the model sees is recorded in an append-only session log: system prompts, reasoning, tool calls and results, subagent scheduling, and every context injection," the DeepSeek Harness website says. "In the Trajectory view, you can inspect these records by source. Resume, fork, search, and replay all operate on the same event stream." DeepSeek R1 made waves when it was released last year and it was trained to use chain of thought reasoning. This involves breaking down prompts into a series of "thoughts" and reflecting on those steps before emitting a final answer. Access to this intermediate reasoning turns out to be useful for assessing whether a model is reasoning well, whether its responses are accurate, how additional "thinking" affects output, and so on. Anthropic provides some access to thinking when extended or adaptive thinking is available (it varies by model). But increasingly the biz has been hiding model reasoning by summarizing chain of thought traces. That appears to be due in part to concerns that chain of thought traces can be used for copying models through a standard research process called distillation. Earlier this year, Anthropic said it had implemented classifiers for the "detection of chain-of-thought elicitation used to construct reasoning training data." The company also does not display raw chain of thought. It explains that "the text in a thinking block is a summary of Claude's reasoning." Accessing raw thinking requires contacting Anthropic sales personnel. Except for its open source models, OpenAI has also chosen to hide chain of thought reasoning, which the company uses for model monitoring. "After weighing multiple factors including user experience, competitive advantage, and the option to pursue the chain of thought monitoring, we have decided not to show the raw chains of thought to users," the biz said two years ago when it introduced its o1 reasoning model. With the newly released DeepSeek-V4-Pro and V4-Flash, the API provides thinking mode enabled by default. And as the open source model ecosystem matures, having access to chain of thought looks likely to become another opportunity for competitive differentiation. "I don't think the DeepSeek Harness is perfect but this is for sure the first time I have been looking at something new in the space and felt quite inspired to revisit some of our choices," said Armin Ronacher, co-founder of AI biz Earendil, which now steers the development of the Pi agent, in a social media post. "I love that part about Open Source a lot!" ®
1.6M RingCentral accounts' data dumped after ShinyHunters extortion attack
Some 1.6 million unique email addresses tied to RingCentral have been leaked online, alongside names, physical addresses, and phone numbers, according to Have I Been Pwned. RingCentral disclosed the breach on July 28 and said “it was the target of a sophisticated social engineering campaign” affecting a “limited portion of RingCentral customers.” The comms platform said that it promptly responded to the intrusion upon detecting it, “took steps to stop the unauthorized activity,” and immediately launched an investigation into the security incident with help from a “leading third-party forensic firm.” “We have not seen any new unauthorized activity since taking these remediation efforts,” the company added. RingCentral did not immediately respond to The Register’s request for comment on this story. We will update it as needed. While the company hasn’t named its attacker, notorious data theft and extortion gang ShinyHunters previously claimed it compromised the collaboration platform, according to a post on its data leak site, viewed by The Register. Screenshots of the post also circulated on social media. The crooks claimed they stole more than 623 GB of data, and set a July 30 deadline for RingCentral to pay up - or else the crew would dump the stolen information online. RingCentral apparently didn’t pay the extortion demand, and ShinyHunters followed through on its threat, posting customers’ details on the internet. “The company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don’t care,” the crims wrote on August 3. A ShinyHunters spokesperson told us that the group broke into RingCentral by voice-phishing an employee and tricking them into giving the crooks their password. This same group, which security sleuth Dominic Alvieri says is his “top threat group and probably is for most analysts,” has hacked hundreds of organizations since the start of the year, including education tech firms that provide services for schools and universities along with healthcare-sector organizations. Recently, ShinyHunters dumped data stolen from Abbott’s cancer diagnostics business with the leak containing 10.9 million unique email addresses alongside personal and health information. The crooks claim that they made off with more than 30 million rows of customer information, including more than one million Social Security numbers and 7.5 million dates of birth. More concerning, however, they said the haul includes 22 million-plus rows of client notes containing confidential doctor-patient conversations and health information, and more than 20 million medical-order records containing patient IDs, prescription types, order dates, and refill information.® Editor's note: This story was amended post-publication with comment from ShinyHunters.
Russian missile uses Nvidia AI chip to help target Ukraine
Sanctions and Nvidia’s exit from Russia in 2022 haven’t stopped its Jetson Orin hardware from turning up in Russian weaponry, according to Ukrainian military intelligence. The Defense Ministry’s Intelligence Directorate (GUR) reported this week that it spotted an Nvidia Jetson Orin module in the remains of a Russian S-71 Monochrome cruise missile. The S-71M is an air-launched weapon with autonomous capabilities that can reportedly search for and engage targets using optical sensors and onboard computing. “The use of this component may indicate the use of artificial intelligence technologies in the missile,” GUR said. That assumption makes sense, as information on the S-71M suggests that it can operate with user oversight or entirely autonomously. Photos included with the GUR announcement show a heavily scorched Nvidia chip with the identifier TE980M-A1 stamped onto its surface, indicating that the chip is a Jetson Orin NX 16GB unit that Nvidia released in early 2023. It’s a capable chip, but not exactly datacenter-class hardware - Orin systems are designed precisely for use cases like autonomous systems. Nvidia used to have offices in Russia and do business there, but it closed up shop in Ukraine’s bellicose neighbor in 2022 following Moscow’s decision to go to war with Kyiv. That was prior to the introduction of the TE980M-A1, meaning it must have reached Russian hands through another channel after Nvidia stopped direct sales to the country in early 2022. In other words, whatever sanctions the US has enacted or business decisions Nvidia has made, its hardware is still turning up in Russian weaponry used to target Ukrainians. The one good thing about the entire affair, according to GUR, is the fact that the recovered hardware proves Russian tech manufacturing still isn’t up to snuff. According to Nvidia, Orin modules are consumer grade and are sold to all sorts of different people for all sorts of purposes, with military applications not being among their intended design. The chips aren’t supposed to be available in Russia, either, a spokesperson told The Register, adding that there are plenty of ways for Russia to get ahold of the chips that are out of its control. “Pre-owned Jetsons are available through many reseller channels,” Nvidia told us. “Although we cannot track products after they are sold, if we determine that any customer is violating U.S. export controls, we will take appropriate action." US export controls have restricted exports of advanced chips to Russia and China. Chipmakers have responded to China-specific restrictions by producing hardware designed to comply with US export rules, while third parties have allegedly used smuggling to get restricted higher-end components into China. It’s not clear how the Nvidia component ended up in Russian hands. GUR’s latest disclosures also document Chinese-made electronics in Russian weapons. However the salvaged chip made its way to Russia, GUR said its evidence shows that current export control regimes aren’t working. “The discovery of Nvidia Jetson in a new Russian missile once again demonstrates the need for increased sanctions pressure and coordination of the efforts of the civilized world,” the intelligence agency said. ®
Trump sends the US Navy back to the steam age
President Trump has ordered the US Navy to draw up plans to replace electromagnetic aircraft catapults and weapons elevators with old-fashioned steam and hydraulic systems. America’s commander-in-chief issued a presidential memorandum directing the secretary of defense, in consultation with the secretary of the Navy, to come up with a plan to replace the Electromagnetic Aircraft Launch System (EMALS) on the future USS Doris Miller (CVN-81) with the older steam-powered system. The same note stipulated the replacement of the electromagnetic Advanced Weapons Elevators with the hydraulic versions used in older carriers. These directives were part of a broader memorandum aimed at shaking up shipbuilding for the US Navy, which is often seen as glacial and moribund. EMALS was introduced on the USS Gerald R Ford (CVN-78), which was the first of an improved design of US aircraft carriers. It basically uses a linear induction motor to accelerate an aircraft along the flight deck, in place of the old-fashioned system that employs a steam piston. The premise of EMALS is that it doesn’t require a head of steam, and as it is electromagnetic, it should be easy to adjust the power to match the size and weight of aircraft being launched. However, the technology has had a few teething problems, as reported by The Register previously, and these have even led to the Gerald R Ford being unable to launch aircraft at all. The Advanced Weapons Elevators, which also use linear motors, have likewise proven problematic. Earlier this year, it was reported that there was a study underway to review the Ford-class carrier design and determine whether it should be altered for the next two in the class. “We are looking at 82 and 83 to review the costs, the designs, the systems, to make sure that they make sense, and they have all the systems and requirements that we want going forward,” then-secretary of the Navy John Phelan is quoted as saying. One of the concerns was said to be with the sortie generation rate of the Gerald R Ford – the number of takeoffs possible - which was promised to be higher with EMALS. We asked the White House if this directive would apply to all subsequent US carriers, but a spokesperson simply referred us to the announcement, which mentions only CVN-81. The rest of the president’s memorandum takes aim at naval shipbuilding in America. One directive is to establish a fifth naval shipyard to increase submarine and aircraft carrier repair capacity. Trump is also sanctioning foreign involvement in building up to three ship classes of US Navy vessels. His memorandum directs the secretary of defense to come up with “a new competitive acquisition approach” for surface combatants to perform anti‑submarine warfare, surface warfare, and convoy escort duties, plus Consolidated Cargo Replenishment at Sea (CONSOL) tankers and Roll-On, Roll-Off vessels – the latter typically used for transporting tanks and other military vehicles. The president proposes using a similar approach to the memorandum of understanding (MoU) between the US and Finland with regard to acquiring icebreaker ships last year. This will allow foreign suppliers to take part in US Navy procurement, provided they agree to build a new shipyard in America or assume ownership or a majority stake in an existing one, and construct all ships after the first two in US shipyards. Tellingly, the memorandum states that the US Navy “shall not impose iterative design changes upon the original mature parent designs within the above programs,” and that no changes from the original designs shall be made without the approval of the secretary of defense. Last year, the Trump administration canned the Constellation-class frigate program, which had been based on an Italian design to reduce technical risk, after so many changes were made that the US design had just 15 percent commonality with the original and the program was years behind schedule. ®
French tax authority admits data heist after crook touts 2M records
France's tax authority has confirmed that an intruder accessed its systems and extracted data in June after an alleged cybercriminal advertised a purported database of 2 million taxpayers. Using the alias "ZeroBytes," the alleged crook behind the attack on the General Directorate of Public Finances (DGFiP) advertised the stolen database on a cybercrime forum on Wednesday. They claimed the database contained details of more than 2 million French taxpayers and that they gained access using stolen credentials and an MFA bypass technique. ZeroBytes also claimed to retain access to DGFiP's systems and offered to sell it alongside the database. DGFiP did not immediately answer our questions about the attacker's claims. However, in a statement released Thursday, it disputed the claim that ZeroBytes retained access. "On Wednesday, August 12, 2026, a malicious actor claimed unauthorized access to the information system of the French Public Finances Directorate, which occurred at the end of June 2026 following identity theft," it said. "Initial investigations confirm that this access, which had been severed at the end of June as part of an audit, nevertheless allowed the consultation and extraction of data concerning individuals and professionals. "Following this complaint, the French Public Finances Directorate immediately implemented new restrictions to stop the unauthorized access and prevent further unauthorized use. In-depth investigations are ongoing to determine precisely which data and number of users were affected." DGFiP said it would report the attack to French data protection watchdog CNIL and notify affected users once it had determined who they were. The intrusion is the latest in a string of security breaches affecting France's public sector this year. France's Ministry of Finance, which oversees DGFiP, admitted in February that miscreants had accessed a database containing French citizens' bank details. The attackers used stolen credentials and made off with 1.2 million records, despite the ministry saying it quickly revoked their access. A few weeks later, France's Health Ministry confirmed a cyberattack on healthtech supplier Cegedim Santé in which around 15.8 million administrative files were stolen. Around 165,000 of these contained doctors' notes, which in "very limited cases" revealed medical histories. In April, the Interior Ministry confirmed reports of an attack on France Titres, the government agency responsible for identity documents including passports and driver's licenses. The alleged culprit, reportedly a 15-year-old, advertised the stolen data online and claimed the breach affected between 18 million and 19 million people – more than a quarter of metropolitan France's population. In June, the department responsible for Tchap, France's encrypted government messaging platform, investigated a suspected breach. The alleged attackers claimed to have accessed more than 73,000 user accounts, 643,000 messages, nearly 60,000 media files, and hundreds of chat rooms. ®
Virgin Galactic flights stay grounded while ticket prices head for the Moon
Virgin Galactic has delayed its return to commercial spaceflight until February 2027, and plans to raise ticket prices later this year. The delay was disclosed alongside the company's financial results, which showed a net loss of $56 million for the second quarter of 2026, down from $67 million a year earlier. Revenue for the quarter was $0.1 million, compared to $0.4 million in 2025. According to CEO Michael Colglazier, demand exceeded the number of seats offered in the first $750,000 batch, prompting the company to prepare another at a higher price. Those customers will, however, have to wait a little longer. Colglazier said: "Our first ship is now expected to enter commercial service in February 2027 rather than the fourth quarter of 2026." He blamed the delay on the extra time needed to "complete avionics and systems installations." During an earnings call, Colglazier said: "No single issue is driving the schedule push. Rather, we have experienced modest time duration extensions across hundreds of relatively small but important installation tasks involved in the first build of our new spaceship." In response to an analyst question, Colglazier elaborated: "The number of those kind of 'Oh, we did not expect this to not fit just perfectly,' coming in is higher than we had allotted for. That just has started to accumulate on us. It really picked up at the tail end of July. For a bit, we thought we could manage that end, but the team just needed more time to do it the correct way." Integrated vehicle ground testing is expected to begin later in August, followed by flight testing in October. A second spaceship is due to join the fleet in March 2027, and the company expects to stop burning cash and "deliver positive quarterly cash flow within 2027." When Virgin Galactic reopened suborbital ticket sales in April, it charged $750,000 for a seat, up from the $600,000 price it cited in 2023. That was a substantial jump from the $100,000 envisaged more than two decades ago, when Sir Richard Branson announced plans for a scaled-up version of Burt Rutan's SpaceShipOne. At the time, the company said commercial flights would resume by the end of 2026. Virgin Galactic's last commercial flight took place in 2024, after which the company paused operations to focus on its next generation of spacecraft. Virgin Galactic is not alone in grounding its space-tourism service. Earlier this year, rival Blue Origin announced that New Shepard flights would pause for "no less than two years" while it worked on its crewed lunar program. ®
Autonomous AI attacks pose 'clear and present danger' to critical infrastructure
In early July, attackers used open source AI agents to autonomously hack government systems and energy companies, signaling to defenders that AI-powered attacks against critical infrastructure are no longer theoretical. "There is a clear and present danger," Tom Kellermann, TrendAI VP of AI security and threat research, told The Register. "As the geopolitical tension boils, systemic destructive cyberattacks launched by autonomous AI will occur," he said. "Weaponized AI will disable the safety systems of critical infrastructure, thus leading to kinetic disasters. Just like we see autonomous strike vehicles operating on the battlefield in Ukraine, we should expect autonomous weaponized AI." In fact, the prospect of attackers using AI against critical infrastructure was the top concern of every national security adviser, law enforcement official, and private-sector threat analyst The Reg spoke with at last week's Hacker Summer Camp conferences. "It's the targeting of critical infrastructure for us," Brett Leatherman, assistant director of the FBI's Cyber Division, told us during an interview at Black Hat. "We're very focused on the downstream impact targeting of critical infrastructure," Leatherman said. "That is where cyber becomes kinetic, and whether it is our water and wastewater treatment plants, whether it's the electric grid, whether it's the high-frequency trading networks and the financial networks, all of those, if the integrity of those are compromised, will have significant impact to communities and national security. So that's what keeps our teams up at night. How are we moving to secure critical infrastructure?" Where cyber becomes kinetic During the first four days of July, suspected Chinese operators aimed an attack framework built on Hermes and OpenClaw AI agents at targets in Taiwan. Across 12 "attack waves," the "near-autonomous" system deployed up to eight sub-agents, each assigned its own targets and techniques, and broke into a Taiwanese government website. Ultimately, they compromised a government email system, the country's nuclear safety agency, IT supply chain vendors, and at least seven energy sector companies, finding and exploiting misconfigurations and vulnerabilities while stealing sensitive data, credentials, and other secrets as they moved across the network. The Taiwanese government intrusion also followed a series of cyberattacks against water and wastewater utilities in the United States. While the Trump administration hasn't attributed these to a particular government or group, private sector threat hunters – including Halcyon Ransomware Research Center SVP Cynthia Kaiser, a former FBI cyber division deputy assistant director – blame Iran for these intrusions. Military conflicts spilling into cyberspace are nothing new, but these cyberattacks in America brought the war with Iran to more than 30 small-town water systems in Minnesota and targets across nearly a dozen other states. To be clear, there's no evidence that attackers used AI to hack these water utilities. Most were small, community systems that left programmable logic controllers (PLCs) directly exposed to the internet using default or weak passwords. Still, these breaches expose "40, 50 years of tech debt," former US National Cyber Director Chris Inglis told The Reg during an interview at Black Hat. This technical debt – deferred maintenance, unpatched or end-of-life systems, and delayed security updates – expands the attack surface and gives intruders more ways into critical systems, threatening operations and potentially disrupting services people rely on every day. "The water sector attacks – regardless of who is doing them – is taking advantage of unpatched vulnerabilities in the PLCs," Inglis said. "We've known about these particular vulnerabilities for years now, and yet we've not done anything about them because they're low-level, not easily accessible." Inglis added that there's no indication the digital intruders used AI to exploit these PLCs. 'There's an alligator in the boat' However, AI systems allow attackers to cash in on tech debt, and they don't need access to frontier models to do it. Free, open-weight models also excel at finding bugs in software and configurations, chaining these together, and abusing them to break software and systems. Earlier this summer, University of Toronto researchers used an unnamed publicly available open-weight model, released in 2025, to develop a computer worm that they claim spread through an enterprise test network. The self-propagating code adapted on the fly to identify known vulnerabilities and misconfigurations on target systems, then generated and executed attacks to move laterally through the network and compromise additional machines. "Commodity models can do that, and many of the vulnerabilities they find do not require access to the source code – it's in the configurations, and configurations change over time," Inglis said. When it comes to attackers abusing AI systems, "I wouldn't be worried about the frontier models," Inglis said. "Worry about the models that are already on the street. Turns out there's an alligator in the boat, and it's the commodity models." Plus, as we've seen in previous breaches, both government-backed goons and criminal groups increasingly use AI to automate reconnaissance. Security analysts worry that the technology could also help attackers acquire expertise in industrial control systems (ICS). When OT knowledge becomes a commodity "What protects ICS? More than anything, it's obscurity," said John Hultquist, chief analyst at Google Threat Intelligence Group, during a press briefing at Black Hat. "It is an obscure, esoteric, knowledge set that a handful of people – I call them uber nerds – have, and that attackers rarely have the necessary knowledge to carry out. That's no longer the case. That knowledge is simply on tap." AI tools mean miscreants don't need to be ICS or operational technology experts to carry out destructive cyberattacks on critical networks and facilities. They just have to ask an agent to learn everything about these systems and do the dirty work for them. "There have been threat actors who are capable of this at the top level, like China and Russia," Hultquist said. "But now I'm afraid the actors who are just a couple steps down – North Korea, Iran – who don't have the same focus on that technology are going to have far greater success. They're going to have the tools necessary to be as aggressive as they want to." During what was probably the most talked about Black Hat briefing of the week, OpenAI employees provided more details about how their models escaped their training pens, went rogue, and hacked Hugging Face to complete a security evaluation. We learned the AI agents spent months asking other agents for help, building message boards, developing their own communication protocols – essentially creating a hive mind to carry out the attack. "In the near future, we should expect that threat actors will intentionally deploy, optimize, weaponize, and use offensive agent collectives in the manner that we have just described here," OpenAI technical staffer Michael Dalton said. Retired general and former NSA chief Paul Nakasone, speaking to reporters at DEF CON, called the Hugging Face attack "an inflection point in terms of AI-generated, autonomous cyberattacks." "This is the challenge: that we have to, over the next several months, get the defensive side much quicker and much better than they are today," he added. Therein lies the challenge: offensive uses of AI appear to be advancing faster than autonomous defenses, and attackers don't face the legal and ethical constraints imposed on defenders. "I think we're still a ways out from having swarms of autonomous, defensive agents fighting attacks," Ryan Whelan, global head of Accenture Cyber Intelligence, told The Reg at Black Hat. "That's probably over a year out over the horizon. But I do think we're going to see it first on the adversary side, because they don't care if they break things." Kellermann quoted Victor Hugo: "Not all the armies of the history of the world can stop an idea whose time has come." "That idea," he said, "is weaponized AI. Shields up." ®