Subscribe to The Register feed
Articles from www.theregister.com
Updated: 58 min 17 sec ago

Less than a year on, Microsoft tells Mico to pipe down

Fri, 08/14/2026 - 05:16
Microsoft has yanked Mico from the Copilot spotlight less than a year after unveiling the anthropomorphic assistant intended to make its AI a little less soulless. As part of Microsoft's announcement that its consumer and work Copilot applications will merge, the company confirmed that the weird blob thing would shuffle out of Copilot Voice and into Learn Live, a voice-based study mode that guides users through subjects and assignments. "Mico helped us learn about warmth, expressiveness, and how people want to talk with AI," Microsoft wrote. "Those learnings are shaping Copilot going forward." "Learn is where the character has the most room to grow, with tutoring sessions that give Mico more to react to and teach through." As the update rolls out, Mico will no longer be the face of Copilot Voice. Users can still speak to Copilot and receive responses, but will be spared the blob's gurning. Mico is only the latest in Microsoft's long line of anthropomorphic assistants. There was Clippy (or Clippit), which arrived with Office 97 but had been pushed into Microsoft's desk drawer of doom by the time Office 2007 appeared. Then came Cortana, named after the character from the Halo video game franchise and pitched as a far more intelligent assistant. Microsoft introduced Cortana on Windows Phone in 2014 and brought it to PCs with Windows 10 the following year, before losing interest. Mico didn't even last a year as the face of Copilot Voice before Microsoft pulled it from the spotlight, although both the character and its Copilot "brain" live on in Learn Live. In terms of lifespans, it's easy to compare it to the catastrophic Microsoft Bob, which was launched in 1995, with the last release happening that same year. However, the product lingered a little longer and later resurfaced, hidden as digital ballast on the Windows XP installation CD for licensing and encryption. Modern digital distribution means that such a second life is unlikely to await Mico. Dave Plummer, the engineer responsible for Bob's inclusion as an encrypted blob, said: "What's ultimately important is that while Bob never got to play on the big stage, he always followed the band around and got to ride on the bus." Mico hasn't been thrown off the bus just yet. Microsoft has merely made the blob sit with the schoolchildren. ®

TalkTalk Business and ARO to borg into UK tech services giant

Fri, 08/14/2026 - 04:44
TalkTalk Business and UK technology services biz ARO plan to merge, creating what they say will be one of the country's largest communications and managed services providers. The pair claim the combined organization will be "uniquely positioned" to serve as a single technology partner for British firms pursuing digital transformation. It will have annual revenue of about £200 million ($270 million) and a combined customer base of more than 70,000 companies. Analyst firm Megabuyte noted that ARO, formerly known as Arrow, is the larger of the two businesses by earnings. However, the vast majority of the combined customer base will comprise TalkTalk Business's small-business clients, with the remainder mainly ARO enterprise customers. Megabuyte expects fixed-line and mobile communications and connectivity to generate most of the combined revenue – about £130 million ($176 million) – with IT and cybersecurity services providing the remainder. Megabuyte said the immediate priority would be integrating the businesses and finding opportunities to sell their services across the combined customer base. "One can see why the deal is being sold in terms of cross-sell, with relatively little overlap in terms of customers and products. TalkTalk Business has a large base of small business customers who should be receptive to ARO's mobile and Microsoft offerings, as well as other IT and cyber services," says chief analyst Philip Carse. TalkTalk Business completed its separation from the wider TalkTalk Group earlier this year as it sought to expand as an independent managed network provider. It recently acquired Planet IT, a service desk biz selling IT support and professional services. ARO provides cloud, cybersecurity, and datacenter services and is a Microsoft Solutions Partner. The two firms describe their operations as highly complementary. The deal remains subject to approval under the UK's National Security and Investment Act (NSIA), apparently because ARO supplies some government customers, and is expected to close by the end of the summer. Initially, both businesses will retain their existing brands and offices while the companies develop their integration plans. The implication there is that there could be a shake-out of duplicate products and staff roles coming later, as often happens with corporate mergers. We asked what the combined business would be called and who would lead it, but the companies declined to answer. "This is a defining moment for both ARO and TalkTalk Business," claimed ARO chief Ciaran Rafferty. "By bringing together our complementary strengths, we are creating a stronger partner with broader capabilities, deeper expertise and greater capacity to invest in innovation, service delivery and long-term customer success." TalkTalk Business CEO Ruth Kennedy said it represents a key step in the firm's ambitions to become a leading managed services provider. "The market is evolving rapidly, with organizations increasingly seeking technology partners that can combine strategic expertise, operational excellence and broad service capabilities at scale," she commented. ®

Crypto wallet maker Trezor confirms 13,000 customers' details exposed in logistics breach

Fri, 08/14/2026 - 03:29
Cryptocurrency hardware wallet maker Trezor has confirmed that a breach at one of its shipping partners exposed the personal data of more than 13,000 customers. The company's initial findings suggested the breach was limited to orders placed in certain countries during the previous 90 days. New information indicates that earlier orders may also be affected. The breach exposed the names, email addresses, phone numbers, and shipping addresses of 11,742 customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who ordered Trezor products between May 10 and August 8. An additional 1,947 customers had their names, home cities, and email addresses exposed. Some members of this group may have placed their orders before May 10. "We are verifying this information and the timeframe with ShipMonk," said Trezor. ShipMonk is Trezor's logistics partner. It stores and ships products on the company's behalf and collects the information needed to fulfill orders. ShipMonk is subject to Trezor's 90-day retention policy, which requires partners to delete or anonymize customer data within 90 days of collecting it for an order. ShipMonk did not immediately respond to a request for comment. Trezor markets itself as a purveyor of secure, offline, hardware-based cryptocurrency wallets. With its products, it aims to shield customers from cyberattacks and malicious apps. While it assured customers that its own systems and devices remain secure, Trezor warned that "affected customers could experience an increase in phishing attempts." The exposed details could help criminals craft convincing phishing attempts impersonating banks, crypto exchanges, or Trezor itself. The company said it contacted affected customers directly and advised them to check any communications against information published through its official channels. "Never enter your wallet backup on a website or share it with anyone," Trezor said in an apologetic advisory. "This is the first time since Trezor was founded in 2013 that we have experienced a breach that exposed customer phone numbers and shipping addresses. "We absolutely understand how serious this is and the potential risks it poses to our customers and are deeply sorry to those affected." Trezor said in a supplementary social media post, separate from the advisory, that its "top priority" project at the moment is to establish an "Anonymous Delivery" option for customers. The service will allow buyers to complete checkout without linking their home address or real-world identity to an order. Customers using Anonymous Delivery will go through a dedicated checkout, use a nickname or label ID in place of a real name, and have their product shipped to an automated delivery locker instead of their home. The delivery will also come in unbranded packaging with a generic sender label. The carrier will only use email or SMS to send a PIN for the locker. Trezor said the service is gearing up for a September launch in the EU and by the end of the year in the US. Alas, that didn't stop Cake Wallet, a rival crypto wallet, from poking fun at Trezor. "Another rough day for self custody," it Xeeted, before suggesting crypto holders instead use an old smartphone with Cake Wallet installed because "there is no order, no shipping address, or customer data tied to the purchase." ®

BOFH: How our Covid ransomware protocol's Y2K blockchain lowered uptime

Fri, 08/14/2026 - 02:29
EPISODE 15: The Boss has popped into Mission Control to remind us to send him the numbers he needs for his monthly management report. Once's he's gone the PFY sighs, makes up a set of numbers, appends believable exponents, adds some fancy sounding units to the end and then sends them to through a script file to convert them into something the Boss can use. None of it matters, as no one cares about the numbers anyway. At Management level there's likely to be more interest in the undigested-meat portion of the Boss' stool sample than our uptime stats, firewall throughput, or the Company's online storage totals... Still, the PFY will fabricate the data, extrude it through a Perl script to create a graphic panel complete with a pie chart or two, and maybe a Venn diagram, then send it to the Boss. The Boss then pastes it into the top right corner of his report document, which gets sent on to the higher-ups, month after month, year after year. The real shame is that none of the higher ups has ever taken the time to flip through the Boss' reports chronologically - and thereby view the PACMAN-like animation the PFY's data has been so diligently creating all this time. You've got to make your own fun in this job. And no one cares if the numbers are wildly inaccurate. Back in the old days, someone might wonder how we'd achieved 117 percent uptime, or whether 17.6267 terafleptules was a real thing or not, but at this point no one will ask any questions so long as the pie chart isn't a single color. As stated, we stopped producing real data years ago, and, on the rare occasion we're questioned about the validity of the data, we have an excuse close at hand. For a good part of the '90s we leaned heavily on blaming "The internet" for faulty data, though from '97 till around 2001, "Y2K" was solid gold. In recent times - i.e. the data-faking era - "Blockchain implementation" was surprisingly short-lived as an excuse - but we got a good four years out of "It's a COVID thing," before flipping between quantum computing and privacy restrictions for a bit. If pressed, we'll occasionally just shake our heads and quietly murmur "Viruses", "Hackers" or "Zero day attacks", as that covers a multitude of sins, and both the PFY and myself can ramble aimlessly for hours about viruses we have known, and what they might have done to our systems. The only thing we'd be missing in a scenarios like that would the onions in our belts, but no one would notice that while they were thinking up a good excuse to leave the room... "AI" has at least another two years in it - unless of course AI becomes sentient during that time and kills us all... Still, AI might need someone to produce fake stats about how well they're doing... ... The Boss is back surprisingly fast with a query. "I was just looking at the graph and I think there might be a data error." He says, pointing to the graphic. "See there, where is says Terafloptules." "Uh-huh." the PFY says. "Is that a spelling mistake? Only I can't find the work Terafloptules on Google. And last month it was in Terafloctules, not Terafloptules, but I can't find Terafloctules either." "Well, you wouldn't would you. I mean Google looks up data after the fact." "I'm not sure I follow." "Well, say you created a word. Idiomanagement, say. Will Google know about it?" "Yes?" "No, it won't. It won't notice it until it becomes a commonplace word or phrase. In the interim period, before it gets accepted and has a wider use, Google will simply skip over it, assuming it's a spelling mistake of some similar word." "So... we're... using a word that doesn't exist?" the Boss asks. "No, we're using a word that doesn't exist in common usage. It's like DVD Player in 1996. If someone saw that written down then, they might have thought it was DUD player and thought you were referring to Aly Dia. Now though, the word's in common usage." "So is there a word we could use that people would be more familiar with?" "I guess we could use Gigafloptules, but then I'd have to mention on the legend that the units are in thousands." "What is a gigafloptule?" "I'm glad you asked!" the PFY blurts happily. "To get to the bottom of that you really need to know a little bit about the parsec measurement of the speeds of data - but don't worry, it's not nearly as complicated as it sounds! You see, when Rutherford split the neutron with a nitrogen atom back in the 1850s, he noticed that a small amount of energy, a floptule, was ejected from the uranium positron... I leave the PFY rambling while I pop up to the cafeteria to see if they have any onions. Yellow ones, because of the war... BOFH: Previous episodes on The Register The Compleat BOFH Archives 95-99

Scottish prosecutors cast eye over leaky supplier after staff data exposed

Fri, 08/14/2026 - 01:46
Scotland's public prosecution service has warned 300 staff that their personal information may have been caught up in a cyberattack on one of its suppliers. The Crown Office and Procurator Fiscal Service (COPFS) disclosed the incident on Thursday, saying an unnamed third-party supplier detected suspicious activity on August 5 and subsequently launched an investigation. COPFS said its own systems were not compromised and that the incident involves information provided for an online data maturity assessment completed by the prosecution service last year. The Scottish government organized the assessment, which was managed by the affected supplier. COPFS said the potentially exposed information is limited to employment-related data submitted for the exercise, including staff names, roles, and work email addresses. In a statement to The Register, a COPFS spokesperson said: "COPFS is aware that a Scottish Government partner has been subject to a data security breach. We understand that this has affected around 300 COPFS colleagues who participated in a public sector data maturity survey. "This is unconnected to casework and did not involve sensitive or confidential case information. There is no impact on the work of the prosecution service. "Colleagues have been reminded of guidance on responding to any phishing or scam attempts which may arise from this third-party breach." According to COPFS, the supplier has taken steps to secure its systems and is still investigating how the intrusion happened and precisely what information may have been accessed. COPFS said it would provide further updates if "significant new information" emerges. It is unclear whether the incident is connected to the recent exploitation of a zero-day vulnerability in business intelligence platform Metabase. The Scottish government did not answer our question about whether the affected supplier used the software. Metabase disclosed this month that attackers had exploited a previously unknown vulnerability in its cloud service, potentially allowing them to gain administrator access and reach connected databases. As we reported earlier this week, modular laptop maker Framework was among those affected. For now, the supplier breach leaves plenty of questions and few answers about who got in or what they accessed. ®

Claude Code returns blank thinking blocks, but reasoning still costs you

Fri, 08/14/2026 - 00:30
Anthropic's Claude Code appears to be having trouble displaying summaries of its "thinking," according to several bug reports, while the underlying reasoning tokens still cost money. According to complaints, the API has been returning empty thinking blocks for Opus 4.8 and Sonnet 5 even when users explicitly request summarized thinking. Models from several sources can display their "thinking," a process that gives models additional tokens to reason through complex problems before producing a response. Software with this capability delivers a summary that explains how it tackled a task. Some can also indulge in "extended thinking," though this capability is now deprecated. Developers often enable "thinking" in the hope that it produces better results, at the cost of additional tokens and latency. Developer Michael Hood has noticed that some of Anthropic's models are currently not always good at sharing their thinking. "As of 2026-07-16 ~15:00Z, the API returns empty thinking blocks (thinking: '', signature only) for Claude Opus 4.8 and Sonnet 5, even when display: 'summarized' is explicitly requested — including when injected directly into the raw request body," Hood recently observed. We're told this issue is under investigation but doesn't appear to be a broad, ongoing concern. It may simply be an artefact of tests that change how Anthripic displays summaries. Similar behavior involving missing thinking blocks has been reported in Claude Code for VS Code. Another bug report claims thinking block summaries are being truncated while token bills are not adjusted accordingly. "The thinking is generated (and billed) in full; a portion of the summary stream is silently dropped," the anonymous author claims. This particular claim, that customers are being billed for text not delivered, may follow from a misunderstanding of Anthropic's terms: "You are charged for all thinking tokens generated, even when collapsed or redacted," the company's documentation explains. Under that legalese, a thinking summary costs the same as the full output. And it's unclear whether bug-based truncation would change the billing picture. "Thinking has a cost: the tokens Claude spends reasoning are billed as output tokens, even when the thinking text isn't returned to you, and they count toward max_tokens alongside the response text," the company explains. To reduce spending on thinking, customers are advised to lower their budget setting or disable thinking. Separately, the Anthropic API has been seen terminating data streams during long-running thinking sessions. There have been at least seven other related API bug reports, but the streaming issue identified by developer Hector Bernstorff describes client-side defects. The Register understands this particular issue has to do with tuning network behavior, specifically to terminate or retry long running requests. Work is ongoing to balance perceived latency against the risk of requests getting stuck. "Claude Code ships updates nearly every day, and reports from the community like these GitHub issues are a big part of how we catch problems quickly," an Anthropic spokesperson told The Register. "We're grateful to the developers who take the time to file them, and we'll keep fixing things as they come up." ®

Pages