AWS buys DuckLabs, the people behind the popular in-process OLAP database
Amazon Web Services has bought DuckLabs, the support and development company behind open-source DuckDB. The deal — the financial details of which were not disclosed — will see DuckLabs, founded by authors of the in-process OLAP database, become part of AWS. AWS said DuckDB and its related projects would remain free and open source under their MIT licenses, with the nonprofit DuckDB Foundation continuing to guide them. Written in C++, the database is embedded within a host process and, as such, there is no DBMS server software to install, update, or maintain. For example, the DuckDB Python package can run queries directly on data in Python software library Pandas without importing or copying data. The brainchild of academics at Amsterdam's Centrum Wiskunde & Informatica mathematical and theoretical computing research center, DuckDB first went public in 2022 and has gathered a strong following among developers and analytics users. It achieved its 1.0 release in 2024 and has since launched into data lakes with DuckLake, which uses DuckDB as metadata storage to get around the “small changes” problem experienced by data lakes. AWS has been a fan for a while. Speaking to The Register last year, AWS veep and distinguished engineer Andy Warfield said the cloud giant's engineering team was "super excited" about the DuckLake announcement. "It was passed around broadly across the teams, and people have been playing with it. It's captured people's imaginations for sure," he said. The AWS and DuckLabs teams have already collaborated around S3 Tables, announced by AWS in December 2024, to ensure “we built first-class support for S3 Tables in DuckDB,” Hannes Mühleisen, co-founder and CEO at DuckLabs told The Register on Wednesday. Although the database itself is fully open source under the MIT License, most of the contributions and strategic direction have come from DuckLabs. However, following the merger, Mühleisen sees a greater role for the independent DuckDB Foundation in avoiding any potential conflicts of interest with other technology giants. The database can read and write to Google Sheets and query and manage Google BigQuery datasets via an extension, for example. “We can expand the role of the Foundation as a place where the stakeholders or the people that are building things with DuckDB are coming together. We are thinking about adding a Technical Advisory Board to the Foundation, so that whoever is betting on DuckDB can come together in the Board and have a communication channel through the Foundation, which stays independent,” Mühleisen said. The Foundation, which is led by Mühleisen and Mark Raasveldt, DuckLabs CTO and co-author of the database, has yet to decide the exact governance and voting rights which will determine the direction of the project’s development. Nonetheless, Mühleisen said it would create a mechanism by which the community could play a greater role. In a prepared statement marking the merger, AWS’s Warfield said: “DuckDB is an incredible open source project with an amazing community; it is broadly used and very much loved by S3 customers today. After about two years of working closely with Mark, Hannes and the team at DuckLabs, I’m excited at the opportunity to help the project have an even broader impact. A lot of what has made DuckDB so successful is the fact that it is completely open source and easily embeddable in so many types of applications. We are committed to the project's continued development in open source and under the stewardship of the DuckDB Foundation.” The DuckLabs team will continue to be based in Amsterdam.®
Gates warns society faces an AI-pocalypse unless we get more socialist
Bill Gates thinks that experts underestimate the potential havoc AI will wreak on society and says preparations to ease the transition are inadequate. The Microsoft founder and former CEO is usually a cheerful proponent of AI tech, talking up its potential to transform healthcare, education, and business productivity. Yet in a missive posted to his personal website, the billionaire philanthropist says the AI era is likely to be one of the most turbulent times in human history, and how we allow it to play out will determine whether the world becomes a fairer place or if the divide between rich and poor becomes greater than ever. This kind of talk will sound dangerously close to socialism for many Americans. There are always winners and losers in a market-led economy, so why should things be any different with AI? Those wealthy enough to invest in it and control it will prosper, as others will find themselves on skid row. But, Gates says, this time it will be different. Previous technology transitions happened over several generations and created new jobs where human cognition was required, whereas AI is starting to replace human cognition. The winners are likely to be a small group of people, and the losers will be everyone else. It will not affect just one or two sectors, according to the AI fab club: AI will replace human roles in fields as diverse as law, customer services, medicine, software, and manufacturing. And it will hit these industries rapidly, over the course of a decade or less, rather than taking a few generations. Gates wrote: There will be some new jobs created, Gates says, but without the right policies in place there will be far fewer than today, and entry-level jobs are among those most likely to vanish (as we're already seeing in the tech industry). Blue-collar jobs will also be affected, as AI-powered robots are advancing faster than people realize - much of the progress is happening in China. These may begin to compete with people on some physical tasks, such as in the construction and hospitality industries, within a few years. Gates says there are several big risks from AI adoption, foremost of which is that many work roles are set to disappear forever. He notes that during the Great Depression of the 1930s, unemployment in the US hit 25 percent and remained in double digits for much of that decade, but ultimately recovered as demand, investment, and growth returned. He fails to mention, however, that it took a global war for that to happen. The biggest shift comes when AI operates error-free operation, without humans prepping its work or checking its output. Gates says we need to think now about reducing job losses, or risk much of society ending up unemployed. Another danger, Gates says, is that AI empowers people to do harm: AI-driven malware already lets low-skilled attackers launch cyberattacks, while generative AI makes fraud, disinformation, and deepfakes easier to produce. The third big threat is that AI systems could stunt the mental development of children, and crowd out human relationships. So how is society meant to avoid this apocalyptic vision and ensure AI becomes the force for good that Microsoft’s progenitor believes it to be? Gates says AI needs both a domestic and international framework. Nationally, that means bodies that can set priorities across government agencies to ensure every risk is accounted for. Yet even a nation with its own house in order remains exposed to cross-border risks, so an international body must be built in parallel. If that sounds like wishful thinking, get in the queue. Gates notes it would require US-China cooperation, and under the current Washington administration, that's about as likely as pigs flying.. Beyond that, some jobs - social care for instance - should stay human. Gates also thinks the tax system will need rebalancing, as more people out of work means less income tax to fund government itself. A starting point, he suggests, is taxing AI tokens and robots to reduce corporations' incentives to swap meatbags for machines. This could fund retraining and a stronger safety net, but would need careful targeting so it doesn't hinder beneficial uses of AI, like drug discovery and better education Again, critics will likely dismiss this as socialism and point out that Microsoft was ruthless in pursuing profits under Gates' leadership. In a final message to world leaders, Gates urges them to act now, “before unemployment rises sharply, communities are hurting, and public trust has eroded.” This marks a shift for the Microsoft founder, who two years ago told people not to worry about AI, in particular energy use and increased greenhouse gas emissions, arguing AI would eventually solve the problems it creates. ®
Nitter no more? X sends in the lawyers to shut down open source project
X, the social media mouthpiece of free speech absolutist Elon Musk, has reportedly sent legal takedown notices to Nitter and related service XCancel over alleged data scraping and rules violations. XCancel's home page now contains some minimal text stating: "On Monday 24th August at 8 PM EST, we received at [sic] letter from X Corp. asking to cease and desist the service XCancel." It says the service has been halted "until further notice." Nitter's maintainer, zedeus, adds in a separate statement : "nitter.net is offline and development has stopped for the time being. I'm seeking legal advice and won't be commenting further on the specifics for now." Although the repository is still on GitHub, it is marked as archived and read-only, with some explanatory text added to the README.MD. Nitter provided a way for users to read posts on X without requiring an account. There was no JavaScript or ads, a user's IP could not be tracked, and it was generally a good deal snappier than the official X client, just read-only. It was the service behind platforms such as XCancel. It has also been a thorn in X's side for years, giving privacy-minded users a way to view posts without logging into Elon Musk's social media mouthpiece. This isn't the first time Nitter has reeled at the hands of X. In January 2024, zedeus announced the end of the project after Twitter (the original name of X) removed the guest account feature. A year later, the project was back after it found a way to work around the restrictions. However, this appears to have triggered the lawyers, judging by reports that the letter alleges data scraping and violations of X's rules. The Register asked X for comment, but has yet to receive a response. X isn't alone in taking exception to data scraping. Meta, for example, fired a sueball at Israel-based web scraping firm Bright Data in 2023, but X's cease and desist notice sits awkwardly alongside Musk's own proclamations about free speech, and his corporation's use of public X data to train Grok. Plenty of organizations continue to post on X, but accessing those posts without an X account has become an order of magnitude more difficult without services such as Nitter and XCancel. ®
SpaceX plans to plant $100B Starbase on Louisiana coast
SpaceX has announced plans to spend $100 billion on a Louisiana spaceport designed to support thousands of launches annually. According to SpaceX, construction is planned to start in 2027, and the first Starship launch from the facility is earmarked for 2029. The spaceport will have its own propellant production, power generation, deep-water shipping capabilities, vehicle processing facilities, and an airport. Louisiana Economic Development (LED) was cock-a-hoop about the plans and estimated that the project would generate 3,000 direct new jobs over the next decade, and 8,100 indirect new jobs. When complete, the project will comprise five launch complexes, each with two launch pads and a propellant farm. Vermilion Parish is the intended location and, according to LED, "SpaceX has also already engaged the Louisiana Department of Wildlife and Fisheries, Coastal Protection and Restoration Authority and other appropriate state agencies to proactively address potential impacts to wildlife, fisheries and their supporting habitats." SpaceX performs its Starship flight tests from its Boca Chica facility in Texas. The company has come under criticism and scrutiny over its environmental record over the years, and we can only hope it has learned some lessons in the meantime. According to SpaceX, the Vermilion Parish shoreline "is eroding between 3.3 and 23 feet [between 1 and 7 meters] per year." It says it'll work with state and federal agencies on projects including Gulf shoreline protection breakwaters, marshland restoration, and coastal wildlife preservation. Louisiana authorities would be wise to remember the experience of the Boca Chica facility, which has hosted a good many exploding Starships over the vehicle's test program, and seen concrete sprayed from a damaged launchpad. Starship has also yet to reach orbit, let alone demonstrate the reusability required by the "thousands of launches" for which the Louisiana facility is designed. "With Starbase, Louisiana," SpaceX wrote, "we will enable frequent missions to Earth orbit to support the expansion of internet connectivity, launch Starmind (AI data centers), build a city on the Moon, make life multiplanetary, and extend the light of consciousness to the stars!" A lofty goal, and one that omits the commitment made by SpaceX to NASA's Artemis missions or the fact that Starship has yet to reach orbit, let alone venture beyond. ®
Nigel Farage wants to scrap 'suffocating' UK GDPR
Reform UK says it wants to scrap the UK GDPR after eight years of the regulations “strangling” small businesses. The party’s leader Nigel Farage and economy chief Robert Jenrick announced additional pledges on Tuesday evening, which include scrapping the UK’s data protection regulation for a “light-touch” alternative more akin to New Zealand’s approach. The UK’s Information Commissioner has powers to issue multi-million-pound fines to businesses that violate UK GDPR, which in 2021 replaced the pre-Brexit Data Protection Act 2018. New Zealand’s equivalent, however, only has the power to issue fines up to NZ$50,000 under its Privacy Act 2020. The legislation is weaker in some areas compared to the UK GDPR, but imposes similar restrictions on handling and transferring data. Building a more prosperous business environment features heavily among Reform UK’s policies, we're told. “Small businesses are the beating heart of our economy, yet they have been suffocated by years of punishing taxes, suffocating EU red tape and a big-state obsession that rewards dependency over hard work,” said Farage via news wire PA. “While the establishment parties drive small firms to the brink of closure, Reform UK is offering a bold, common-sense rescue plan.” Jenrick added: “GDPR has strangled small businesses and tech firms alike in a web of unnecessary regulation. “Ten years after the Brexit referendum, we should not still be following ridiculous EU privacy laws that hurt British businesses.” “For decades governments have focused on big corporations while leaving small businesses to fall by the wayside. No more,” Jenrick added. “Reform UK believes the 6 million small businesses in the UK are the backbone of our high streets and our economy, and we will back them to the hilt.” The UK must keep an active adequacy decision from the European Union so that personal data can flow freely across borders without extra legal hurdles. Any plans to diverge from EU data protection law in a major way could jeopardize the adequacy decision. The Reform UK party itself is currently embroiled in a data protection-related legal battle brought against it by the Good Law Project, which claims Farage's party failed to comply with current UK GDPR. The campaign group sued Reform UK in March 2025 after it claimed the party was refusing to disclose to people the data it stored about them and failing to respond to requests to delete that data. The party tried to have the case thrown out, but a High Court judge ruled in June that the case should proceed to trial. Reform UK did not respond to our request for information about its pledges. Big on business, or a big load of pipe dreams? Farage’s GDPR-related pledge was made as part of a broader list of promises to create a more pro-enterprise business environment for smaller organizations that it said were confined by “damaging” regulations. The party vowed to reverse the National Insurance increase announced in 2024 by then-chancellor Rachel Reeves, as well as a range of tax-related easements. Farage said Reform would scrap income tax on full-time workers’ overtime pay, referred to as a “hard work bonus,” loosen inheritance tax related to farms, and increase the VAT registration floor from £90,000 to £150,000 ($122,662-$204,437). He also said he would alter the Seed Enterprise Investment Scheme to make it more tax-efficient for parents and grandparents to invest in their children’s business, and scrap the 2035 Zero Emission Vehicle mandate. A Labour spokesperson described the pledges as “unworkable and unserious.” They accused Farage and Reform of trying to undo the Online Safety Act and distract from the recent story of the party leader accepting a £5 million ($6.8 million) gift from an overseas crypto-billionaire. Shadow chancellor Sir Mel Stride said Reform’s pledges “collapse on contact with reality,” and would cost billions of pounds to implement. Of the party’s data protection plans, Sir Mel said “there is little detail on how their proposals to scrap GDPR would work.” GDPR was first tabled after lawmakers grew conscious of the need to update data protection regulations in the post-social media and cloud computing world, and in the wake of scandals, such as Cambridge Analytica, to protect individuals’ rights to their own information. Aside from its intention to reform the UK GDPR, Farage’s party has not introduced many tech-specific policies, other than to make the UK a leader in emerging technologies, such as AI. Reform UK isn’t the only party looking to tweak the UK GDPR, however. Labour’s plans date back to 2024 and came into effect last year with the Data (Use and Access) Act 2025. The legislation tweaked the UK GDPR, loosening restrictions related to data-sharing between critical sectors and automated decision-making, while also paving the way for a digital ID rollout, which is another matter entirely. ®
UK supermarket scales go 404 on shoppers
BORK!BORK!BORK! The scales are empty, and so what else can there be but a 404? Today's entry in the pantheon of bork takes us to the UK city of Coventry, where a set of scales at a Tesco store shows the number 404. Spotted by eagle-eyed Register reader Rowan Archer, the scales have logged off and done the computing equivalent of popping down to the pub. It's an odd number to choose. Hopefully it's a device identifier rather than a message code. After all, netizens have long associated the number with a browser being unable to find a resource on a server. 404 means not found. 400 is a bad request and, in fact, pretty much anything starting with a 4 generally means the client has likely done something naughty and the server is patiently replying with the computing equivalent of "don't do that." Archer sent us another image, with a 403 number and a plea for a human to deal with its label feed. 403 means Forbidden, so… could these be the forbidden scales? Only for weighing Eldritch Horrors? We're not sure how much Cthulhu weighs, but this might be the place to find out. The device in question looks like one of the Avery Berkel XT scale series, perhaps an XTi100, i101, or perhaps an x100 or x101. There's a large color touchscreen that lets the customer select the produce to be weighed. The screen can also show video ads to "increase customer basket value," which is exactly what we'd want to see after plopping a bag of onions on top of the thing. As far as we can tell, the scales run a version of Linux. The i incarnation has only 2GB of memory, while the x version pushes the boat out with 8GB, and so has a bit more headroom. Whatever the amount, it feels a little like overkill compared to the mechanical versions of yesteryear. There, no power or open-source operating system was required. Just an assistant capable of doing some basic mathematics, spotting what was in the bag, and knowing the difference between exotic berries and a cabbage. Still, progress, eh? And the only thing an old-fashioned scale could advertise was an audible notification when it was time for a squirt of WD-40. ®
Debian polls its developers on whether to burn the bots, tame the bots, or let 'em loose
The Debian project is polling its developers over AI usage: use it, impose limits, or ban it outright. The second Debian vote of the year, General Resolution: LLM usage in Debian is underway. More saliently, it is still underway – Debian Project Lead Sruthi Chandran extended the voting deadline by an extra week. (She was elected in March, in the first project poll of 2026.) Debian is a large and complicated project: the release announcement for version 13 says it has 69,830 packages, which take a total of 403 GB of disk, and contain 1,463,291,186 lines of code. So, suitably, it is a large and complex poll. The poll is more than 5,000 words long, and contains eight different proposals, which are both numbered and lettered. Each of them is seconded by between six and 17 developers. They are as follows: No LLM contributions to Debian via Social Contract. Allow AI-Assisted Contributions with conditions. Reject LLMs as far as practical, update Code of Conduct. Accept AI contributions for Debian specific work. Responsible Use of Generative AI. A cautious approach to generative AI. Debian is created by humans. Avoid the use of LLM: climate destruction is a deal breaker. The poll also notes: “Proposal A needs a 3:1 majority, the other proposals need a simple majority.” This aside, there’s a lot of variation under each proposal. Some are structured, some contain explanations and lists of what they would or would not apply to, some contain summaries, and so on. Only recognized Debian developers are eligible to vote, but we hope that they’re not put off by the wall of text and take the time to work out which of the fairly subtle variations best represents their views. Proposal A is one of the longest. The closest thing it has to a summary is its “preamble,” which says: “This proposal aims to expressly forbid any contributions to Debian written with the use or assistance of large language models (LLMs) or other generative AI tools.” Proposal B would permit LLM-based contributions, so long as they meet six requirements. These cover “legal compatibility,” “licensing and attribution,” “accountability,” “disclosure,” “prior discussion of bulk or automated changes,” and “confidentiality and privacy.” Proposal C calls for a total ban, and its summary is simple: “Reject LLMs (generative”AI”) as far as practical.” It’s backed by “Debian grandee Ian Jackson”, who wrote dpkg and runs Chiark. Proposal D attempts a pragmatic compromise, saying it “acknowledges that these practices are already in use and here to stay. Rather than banning their use, which seems counter-productive and unenforceable, the project chooses to place responsibility on contributors and therefore defines the following guidelines.” It continues with a reasonable enough set of restrictions – the work must be clearly described, comply with the Debian Free Software Guidelines, and so on. Proposal E is similar, and ends by saying that “responsibility for every contribution rests with the contributor who submits it, who remains accountable for its technical quality, legal acceptability, and suitability for inclusion in Debian.” Proposal F urges caution and “encourages contributors to avoid the use of generative AI where practical”. Proposal G “aims to ensure that contributions directly to Debian are created by humans” – in other words, code should be written by hand, but it’s permissible to use LLM tools in other ways while creating it. It ends by saying “we disallow the output of generative AI as direct contributions to Debian.” Finally, Proposal H focuses on just one of the many ethical concerns – but overall, the single most important one, as it affects everyone. “LLM usage accelerates the destruction of our ecosystem (planet Earth) and that is a deal-breaker.” If Proposal H has a weakness, it's that it does not distinguish between local and cloud-based LLMs, although there’s an argument that the environmental impact of the training process is the predominant aspect here and whether the end result is local (and relatively resource efficient), or remote (and extremely inefficient) is nowhere near as significant. In the humble opinion of this vulture, there are too many propositions, with too much overlap between them. We suspect this makes a three-to-one majority for the first very unlikely. To make it easier to arrive at a decision, we would have wanted to see the positions consolidated to fewer, clearer, mutually exclusive positions. But then, we’re not Debian contributors and have no skin in this game. The vote still has a few days to go, although the votes so far are climbing, at the time of writing under 350 ballots have been received. Some other projects and distributions have already chosen a position in this dispute. Back in April 2024, Gentoo chose to forbid it – as NetBSD did too soon afterwards. As we covered looking at the latest OpenBSD release, the project says that since AI code can’t be copyrighted, it can’t be committed to OpenBSD – but the project grandfathers in code from the Tmux project, which allows LLM-assisted contributions, so the barrier is somewhat permeable. Other such projects may yet follow. As we reported in September 2025, FreeBSD didn’t want AI code, but it has yet to update its official guidance with an explicit position. From some social media posts, we believe that an active debate is happening right now, possibly including a ballot similar to Debian’s – but the information is not public. The Register approached the project leadership at FreeBSD for comment, but at the time of writing, had received no response. Some distributions may forbid LLM code, but how much that changes things is a difficult question. The Linux kernel itself is now officially not an anti-AI project, and of course, Red Hat is all-in – and the IBM subsidiary does create a lot of the code used in most distros. These things being so, arguably what individual distros choose to do becomes something of a moot point. ®
Sopra Steria's £370M Capita spat heads for 2028 courtroom showdown
System integrator Sopra Steria is set to have its day in court to contest a £370 million contract awarded by the UK government to Capita to run shared services for finance and HR across a number of Whitehall departments. A judge has set a trial date for early 2028, pending attempts to settle the case out of court. Sopra Steria's allegations center on the award of a business process outsourcing deal led by the Department for Work and Pensions valued at £370 million over ten years, less than 40 percent of the £958.7 million estimated value outlined during the tender stage, according to court filings from late last year. The French headquartered SI is the incumbent provider for some of the departments through SSCL, formerly a joint venture with the British administration that Sopra Steria now entirely owns. In its claim, Sopra Steria alleged Capita's bid to run the services for four major government departments was "abnormally low" and based on staffing "significantly below the current levels." In statements following the claim, both Capita and the DWP told The Register the government conducted a robust procurement process and were committed to providing a high level of service and value for money for the public. The French tech and services biz later claimed the Capita bid was 42 percent below the DWP’s "Should Cost Model", designed to protect against a bias towards low bids, which provided a total price of £642 million, according to court papers. According to papers released by the court last month, the trial is set to be listed for seven weeks from 17 January 2028 at the Technology and Construction Court, part of the High Court of Justice. Alternative dispute resolution is set to continue in efforts to settle the case out of court, the participants response to which may affect how costs are awarded should the case come to trial. The case comes at a difficult time for Capita and government procurement of technology and business services. Capita is in the spotlight over its disastrous handling of the Civil Service Pensions Scheme (CSPS), which angered MPs after leaving some of the 1.7-million members struggling to make ends meet as they wait for payments. Capita apologized for its shortcomings in running the scheme, and pointed to a higher-than-expected backlog of cases from the previous provider. Capita won the contract for £239 million ($318 million) to build and run the scheme in November 2023. Problems with the project first came to light in December last year, following reporting by The Register. The DWP award to Capita was announced in March 2026. During a meeting of the House of Commons Public Accounts Committee in July, Labour MP Clive Betts said the government had given the shared services contract to Capita “even though things were beginning to go wrong with” the CSPS. Andrew Forzani, Government Chief Commercial Officer, responded: “We went through a ‘lessons learned’ on what had gone wrong with the [CSPS] transition and how that could be applied to the [DWP shared services] contract. That resulted in the Department asking for additional assurances through that process, which it worked through.” ®
India’s crewed space program will fly this year, after missing 2022 and 2025 targets
India plans the first launch of its crewed space program this year and has expanded its orbital ambitions to include operating a space station by 2035. India’s crewed space program is called Gaganyaan and has already missed deadlines to fly in 2022 and 2025. The nation’s space research organization (ISRO) agency and government did not say anything about the future Gaganyaan schedule after last year’s deadline passed without a launch. That silence ended earlier this week, when ISRO Chairman Dr V. Narayanan used the occasion of India’s third annual National Space Day to reveal that testing of the rocket and crew module to be used by Gaganyaan missions is almost complete, and the first of three test missions will launch this year. The test flights will use India’s LVM3 launcher, which ISRO has flown nine times without failure. The version ISRO will use for Gaganyaan missions is rated for human use thanks to the inclusion of a crew escape system equipped with solid-fuel motors designed to speed Vyomanauts – the Sanskrit-derived word India has unofficially adopted for its astronauts –to safety. The Gaganyaan crew module is built to carry three Vyomanauts and spend three days in a 400km orbit before splashing down into Indian waters. ISRO has previously said it will launch a robot on at least one Gaganyaan test mission. It’s unclear if that’s still the plan. The aerospace agency has also not said when it plans to launch its second and third test flights, or a first crewed mission. If India can put Vyomanauts in orbit it will become just the fourth country to do so on its own vehicle – after Russia, the USA, and China. Dr Narayanan and other officials and government figures used this year’s Space Day to tease other future initiatives, one of which is putting an Indian space station into orbit around 2035. More involvement from private space companies was also on the agenda, perhaps as manufacturers of the launchers ISRO uses. If India chooses that path, it will mimic the USA’s current approach, which sees NASA make just one vehicle – the ultra-expensive Space Launch System – and contract its other launches to commercial launch companies. Japan’s space agency uses a slightly different approach, defining specs for its vehicles and contracting industrial giants like Mitsubishi to make them, but then runs its own missions under its own name. ®
Self-hosted email is in steep decline, Microsoft and Google are taking over
The number of large users hosting their own email servers has halved in the last decade, according to Artem Berezin, a researcher who works at business e-mail company Live Direct Marketing. On the Internet Society blog, Berezin explained that DNS records reveal a lot about email. “The MX record says where the mailbox lives. The SPF record says who may send on the domain's behalf. The DMARC record says what should happen when a message fails authentication,” he wrote. Berezin says he analyzes those records using daily forward-DNS snapshots captured by the OpenINTEL project run by the University of Twente, SURFnet and SIDN Labs. He also consults the Tranco project’s assessment of the most popular domains to determine the million most popular domains, then “classifies each domain's MX hostname and SPF includes against open dictionaries of mailbox providers, sending platforms and SaaS applications.” The data he uses goes back to 2016, but he admits the dictionaries he accesses don’t offer a complete view of the world’s email servers. His lead finding is that in 2016, 44.6 percent of the top million domains ran their own mail server. In 2026, that’s down to 22.4 percent. The number of self-hosted mail servers is falling fast – down by half a percent in 30 days. Self-hosting an email server remains the most common way to process mail, however Google Workspace is hot on its heels with 21.8 percent of detectable MX records, ahead of Microsoft 365’s 16.8 percent. Berezin thinks the fact that two tech giants handle 38.6 percent of email is concerning. “The RIPE [NCC] community has spent years discussing DNS and CDN centralization; email is following the same path, just more quietly,” he wrote. “When more than a third of popular domains depend on two providers to receive mail, an outage, a filtering change, or a policy decision at either one propagates through the whole ecosystem at once. And unlike a CDN, email has no graceful fallback – a rejected message is simply gone. “There is a second-order effect, too. The fewer independent operators there are, the more the remaining ones inherit the deliverability problems of a world tuned for the big two. Anyone who has tried to stand up a fresh Postfix box in 2026 and get its mail accepted at scale knows exactly what I mean.” Postfix is a FOSS mail server. Berezin’s reference to the struggle to get mail accepted at scale reflects the fact that Google and Microsoft operate filters to detect messages they believe come from untrustworthy sources. If those two tech giants don’t accept messages from Postfix or other sources, they make their own services more attractive - marketers who want their email blasts to land will move to the service providers most likely to let their messages through. Another thing that worries Berezin is the use of DMARC (Domain-based Message Authentication, Reporting, and Conformance) records – the instruction in DNS settings that tells email servers how to handle emails that fail an authenticity check. His research found that over half of DMARC records have no valid policy or monitor email without enforcing policies. That low rate is happening despite Google and Yahoo changing their bulk sender requirements in 2024 to require use of DMARC. “At what concentration does inbound mail become a systemic dependency worth the community's explicit attention?” Berezin asks. “What would actually move DMARC from published to enforced, given that the 2024 mandates demonstrably did not do so? And how much of the Internet's mail infrastructure are we all failing to see because our dictionaries don't know its name?” Berezin wrote that he can’t answer those questions but hopes his daily download of email server data and ongoing analysis means he can one day. ®
Now Perplexity is trying to get into the local AI action
AI company Perplexity has already tried its hand at search services, advertising, personal assistants, browsers, and a hosted agent platform – and now it's getting into local AI services. The biz, having already built a hybrid agent inference orchestrator that connects cloud and local inference, has crossed that bridge to build a local agent called Portable Computer. That's in contrast to its cloud-based agent platform, Computer. Portable Computer consists of an agent harness, an orchestrator, and local AI models running on an Nvidia DGX Spark workstation, with the ability to tap into cloud inference if the situation demands. What's Nvidia DGX Spark doing there? Well, apart from the fact that DGX Spark is a capable bit of AI kit, Nvidia is said to be contemplating a $30 billion investment in Perplexity. Maybe, just maybe, that has something to do with six brand name mentions in one announcement. Perplexity casts its Portable Computer as a way to control AI costs, an issue of interest over the last few months as users find locally run open weight models may offer relief from bulging cloud bills. "Progress is most visible in very small and efficient models such as Nvidia Nemotron 3.5 Lightning (30B total parameters), Qwen 3.6 (35B), and Qwen 3.8 (27B)," the biz said in its post, paying somewhat more attention to Nvidia's model than other local AI enthusiasts. "These small models punch above their weight and are now capable of complex agentic workflows." What hardware might one run such models on? It may just be coincidence but Perplexity suggests Nvidia DGX Spark. "This local-first approach enables significant cost savings, since local inference avoids per-token API fees," Perplexity said. "It also naturally resolves the privacy and intellectual-property concerns: private tokens never need to be transmitted to remote clusters and remain safely within the boundary of the local device." Perplexity's current privacy policy doesn't specifically mention Portable Computer, but does reveal that Perplexity collects quite a bit of data through its other services. Most of Perplexity's pitch to potential customers involves sharing benchmark results that compare Portable Computer to two other agent harnesses, Pi and Hermes. The AI biz reports, "Across the various benchmarks, Computer matched or exceeded Hermes and Pi in accuracy while running Qwen 3.8 27B on an NVIDIA DGX Spark." And Portable Computer, Perplexity claims, proved fastest on BrowseComp and ParseBench-100 and used the fewest tokens on all three. The AI biz concludes that a decent open-weight model and capable local hardware, together with a suitable harness, "can handle real knowledge work at near-zero inference cost without requiring sensitive data to leave the device." And in the event Nvidia does invest $30 billion, Perplexity will have plenty of time to explore how much it can charge in a market where harnesses like Pi and Hermes are free. ®
Intel's 256-core Xeon 7 CPUs are a Diamond in the rough
DEEP DIVE Intel's Xeon 7 platform, better known by its codename Diamond Rapids, was supposed to launch this year with up to 192 cores backed by a whopping 16 memory channels. But that's not going to happen. This being Intel, the launch was, to no one's great surprise, delayed until 2027 to give what remains of the company's engineering team time to cut and polish the chip — and polish they certainly have. At the Hot Chips show this week, Intel revealed the chip won't ship with 192 cores after all — but hold your disappointment because Chipzilla's flagship SKU will actually cram 256 performance cores into a single socket. In fact, spec-for-spec, the platform is surprisingly well positioned to compete with AMD's sixth-gen Venice Epycs, which will also top out at 256 cores. Well, at least on the high end it will. An eye on HPC As we reported earlier this year, Diamond Rapids won't be a mainstream part. It lacks hyperthreading — what the rest of the industry calls simultaneous multithreading — entirely and it can only be offered in high-core-count SKUs aimed at HPC applications. There will be no eight channel Diamond Rapids-SP parts. Those got canned earlier this year, which leaves us with just the high-end AP variants. These always are the cooler of the two anyway, but they're not what enterprises have historically bought. What this means is Diamond Rapids — which for the sake of brevity we're going to refer to as DMR from here on out — won't compete with AMD in every regime, just the very top end. Intel's next chip, known as Coral Rapids, will see the return of hyperthreading and presumably the next round of SP processors, but we wouldn't write off DMR just yet. The chip is without a doubt Intel's most sophisticated Xeon ever built. In many ways it feels a bit like Intel's Rome moment. As you may recall, AMD's Epyc Rome saw the House of Zen embrace a truly modular chiplet architecture that disaggregated compute from I/O and memory, and could be added, removed, and reused depending on the kind of CPU it was trying to make. After faffing about for three generations trying to make chiplets work for them, Intel appears to have found the right glue to stitch everything together and is now having its own Rome moment. Intel ups its advanced packaging game Cutline: Forget your glasses or squint hard enough and you'd think you were looking at an old Eypc circa 2019. DMR's resemblance to Rome is hard to miss, but the resemblance is only skin deep. Intel really is using a different kind of glue to build its chips. The chip comprises up to 22 chiplets, which can be added or subtracted depending on the ratio of compute, cache, and memory Intel needs — just like AMD has been doing for the past seven years. Those chiplets can be broken into three core groups. There are up to 16 core compute dies built on Intel's bleeding-edge 18A-P process tech, four compute building block (CBB) base dies fabbed on Intel 3-T, and two fabric hub dies built on Intel 3 that tie everything together. We've discussed 18A-P in the past so we won't rehash too much here, but it's a refined version of the 2 nm-class process tech Intel started churning out earlier this year with its Panther Lake mobile processors. Intel claims the tech delivers the same performance at 18 percent less power, or up to 9 percent higher performance at the same power, and that's before taking into account microarchitectural improvements from DMR's all new performance cores. Working our way down the stack, each core chiplet contains up to 16 cores and their respective L2 caches. Up to four of these core chiplets are stacked atop the CBB base die using its Foveros 3D direct hybrid bonding packaging tech. This base die is where all of the chip's L3 cache lives, with 320 MB per CBB, or 1.28 GB for the top-specced DMR SKUs. While Intel is using 3D packaging to assemble its CBBs, it's not using its 2.5D Embedded Multi-Die Interconnect Bridge (EMIB) packaging tech to connect the compute assemblies to the two I/O and memory dies or Scalable Fabric Hub (SFH) dies, as the x86 giant is calling them now. Much like the I/O dies found on AMD's last few generations of Epyc datacenter CPUs, Intel's SFH dies combine the chip's memory controllers and I/O interfaces into a single piece of silicon. This die can then be duplicated for added connectivity or channels, which is exactly what we see with DMR. Combined, the two SFH dies offer up to 16 channels of DDR5 at 8,000 MT/s, or 12,800 MT/s when using MRDIMMs, and 128 lanes of PCIe 6.0 / CXL 3 / UPI 3, along with an additional eight PCIe 4.0 lanes, presumably for ancillary I/O like onboard networking, USB, or baseboard controllers. This is a pretty big departure for Intel, which has either crammed everything into one homogeneous die or disaggregated I/O into standalone chiplets while keeping memory on its compute assemblies. For Xeon 7, Intel wanted to deliver a chip with uniform memory access (UMA) rather than the three non-UMA (NUMA) nodes that Granite Rapids-AP showed up as by default. This is part of the reason why Intel skipped EMIB in favor of a more traditional UCIe-S type interconnect, where data is carried over the organic package rather than silicon bridges. EMIB would have required edge-to-edge connectivity between the compute and I/O and would have prevented the CBBs from talking directly to both SFH dies without additional hops. In any case, Intel is calling this new chiplet architecture "fan-out-fabric" and it's what allows it to have UMA while also keeping packaging cost under control, something we strongly suspect may have become an issue with Intel's Xeon-6+ products, known as Clearwater Forest. Questions remain Beyond the physical makeup of the chip, there's a lot we still don't know about the platform. For instance, we have no idea how high the chip's cores will clock nor how much of an IPC gain we can expect from DMR's all-new performance cores relative to Granite. We also don't know anything about the cache hierarchy beyond the fact this thing is going to have a lot of L3. We do know that the cores will feature Intel's updated AMX instructions, which add FP8 support for on-CPU machine learning workloads, and that it'll be one of the first parts with full support for AVX 10.2. We explored the latter in detail a few years back, but in a nutshell, the revised advanced vector extensions aim to address some of the shortfalls faced by Intel's original AVX-512 implementation. HPC and supercomputing enthusiasts, eat your heart out. But on the topic of HPC, we still don't know how Intel plans to handle NUMA beyond the fact that UMA will probably be the default config. That's fine, but there are a lot of HPC workloads that benefit from carving up high-core count CPUs into smaller pieces. While UMA was obviously a major design consideration, we don't see any reason why one wouldn't be able to carve the chip up into two, four, or potentially more sub-NUMA clusters if you wanted to. As far as we can tell, Intel would just need to enable it in the BIOS. Product segmentation is another open question. We already know to expect 256- and 192-core variants of the part, but we don't yet know how far down the stack Intel will go. Presumably Intel could cut the chip down to a single CBB base die with one 16-core chiplet if it thought someone would buy it. More realistically, we expect DMR to bottom out at somewhere between 64 and 128 cores. Taking DMR to Venice Without a full picture of what DMR will offer, it's tough to say how the part will stack up against the competition. Having said that, the specs Intel has already disclosed suggest this is going to be Chipzilla's most competitive fight in years. Both AMD and Intel parts will offer up to 256 cores, 16 memory channels operating at the same speeds, and a gigabyte or more of L3 cache on board. Both parts will offer similar connectivity, while TDPs are expected to land around 600 watts for both parts. As we mentioned before, the one thing Intel doesn't have is hyperthreading, a fact that could give AMD a double-digit percent advantage in certain thread-happy workloads regardless of which chip slinger ends up having the more potent cores. Intel's saving grace is that this is an HPC-centric part and a lot of HPC apps — including the HPL benchmark used to rank the world's most powerful supercomputers – don't always benefit from hyperthreading. In fact, Arm claims that simultaneous multithreading actually hurts more than it helps. If true, we could see Intel position DMR as yet another CPU for low-latency agentic sandboxes (containers where AI-generated Python code is executed or C and Rust are compiled and run). But unless that happens, the reality is DMR probably won't be a high volume product for Intel. Certainly not with Nvidia pushing its in-house Vera CPUs as its preferred AI head node. DMR's success ultimately is going to come down to price and value. When AMD launched Rome, it couldn't touch Intel on core-for-core performance. What it could do is deliver more cores, more I/O, and more memory for the dollar than anything in Intel's lineup, and that largely remained true up until AMD's 5th-gen Epycs forced Intel to concede it was no longer top dog and slash prices. If Intel can deliver more cores for less than AMD with its Xeon 7 processors, for the right buyer, it may not matter who has the better performance. ®
Apple defies memory shortage with new Mac minis
Apple on Tuesday heralded the imminent refresh of its headless Mac kit with new versions of the Mac Studio and the Mac mini that you can pre-order now for shipping on September 22, 2026. The diminutive desktops promise a high level of local AI performance with memory prices to match. "[T]he new Mac Studio is our most powerful Mac ever," said Johny Srouji, Apple’s chief hardware officer, in a statement, citing the integration of Apple's Neural Accelerators into processor GPUs and the utility of high-bandwidth unified memory to justify the assessment. The Mac Studio became Apple's high-performance standard bearer following the retirement of the Mac Pro in March. With the "most powerful" slot taken, the Mac mini has been dubbed "our most versatile Mac," as Srouji put it, highlighting the machine's recently discovered role as "an always-on agentic device." Earlier this year, the excitement around OpenClaw and open weight AI models led to a run on Mac mini hardware as AI aficionados found Apple's compact desktop made a comfortable home for AI agents and local inference. The Mac mini has unified memory – the CPU and GPU share the same RAM – making a Mac with ample unified memory (eg, 64 GB) well suited to GPU inference compared to a PC with 64 GB system RAM but only 16 GB GPU VRAM. What's more, Apple silicon hardware supports the company's MLX machine learning framework, which provides respectable private inference performance on hardware that draws far less power than a desktop GPU workstation. You have less power, but more money for memory. As outgoing CEO Tim Cook admitted in June, memory prices have been rising due to AI demand, and those costs are being passed on to customers. The Mac Studio comes with two flavors of chip, M5 Max ($2,499) and M5 Ultra ($5,499). The M5 Ultra, with up to 36 CPU cores and up to 80 GPU cores, is an inference beast, supporting up to 512 GB of high-bandwidth unified memory with 1.2 TB/s of unified memory bandwidth. That memory configuration isn't available until October, but the existing 256 GB memory option for an extra $4,000 should give you a sense of how pricey a maxed-out Mac Studio will be ($18,299 for 256 GB RAM, 16 TB SSD). The Mac mini can be had with an M6 chip ($899) or an M5 Pro chip ($1,699), but the base model has just 16 GB of shared memory and it costs a whopping $400 to step up to 32 GB. The M6 is the first Apple silicon to use a 2 nm process. It's a 12-core processor, which Apple notes is "two more cores than before." "Built using the cutting-edge 2 nm process, M6 combines a new CPU complex, two additional CPU and GPU cores, a Dual 16-core Neural Engine, and more unified memory bandwidth to power through workloads with amazing energy efficiency," Sri Santhanam, VP of Apple's silicon engineering group, said in a statement. The M5 Pro offers more in the way of memory and memory bandwidth, making it a better choice for data-intensive development applications. The M6 supports up to 32 GB of memory and up to 170 GB/s of memory bandwidth, while the M5 Pro supports up to 64 GB of unified memory and 307 GB/s of memory bandwidth. The Mac mini comes with Wi-Fi 7, Bluetooth 6, two USB-C ports that support USB 3, and a headphone jack. Its rear gunport comes with three Thunderbolt 4 ports for M6 and three Thunderbolt 5 ports for M5 Pro, not to mention HDMI and Ethernet (2.5 Gb or 10 Gb). Thunderbolt 5 allows for clustering, so multiple Mac minis can be connected together to run large AI models on-device. The Mac Studio also does Wi-Fi 7, Bluetooth 6, and Thunderbolt 5, with support for PCIe expansion chassis. All of Apple's incoming hardware comes with macOS 27, which is expected to debut in mid-September. ®
Claude and Cowork now share what they know about you
Anthropic’s Claude chatbot knows a lot about its users, and now it's sharing its memories with the company’s everything-but-coding assistant, Cowork. The frontier lab on Tuesday announced that Claude and Cowork now share a memory, meaning that what Claude remembers about users is also available to Cowork. That’s a two-way street: Memories generated through users’ interactions with Cowork will also be available to the regular Claude chatbot. Services like Claude are able to store information about users, like what they’re interested in, the names of their friends, family members, and coworkers, or almost anything else that’s mentioned in the course of a conversation. Those memories are used to contextualize later responses so that Claude isn’t answering from a blank slate every time a user chats. As Anthropic explains in the announcement, memories are particularly helpful for work tasks of the type that Cowork is designed to perform. Cowork is a lot like Claude Code in that it’s designed to automate manual work tasks, but in this case it’s not about software development and is instead about everything else professionals deal with on a daily basis, like writing a report from a spreadsheet, creating a presentation from said report, or what have you. Y’know - work. “Ask Cowork to draft an update for your manager, and it already knows who that is and how she likes updates written,” Anthropic offers as one use of the new shared memory. As other examples, Anthropic posits brainstorming a conference agenda with Claude Chat and having Cowork know all about the event as it builds budget and logistics documents, or having to define once how a team likes metrics presented in a Claude chat and relying on Cowork to remember that format every quarter as you force it to do the work an intern used to have to be trusted to whip up. It’s worth noting that Claude Code’s memory is staying separate, Anthropic told us. The company also mentioned it had nothing to share about the future of Claude Code’s memory and whether it’d join the hive in the future. As for how Claude and Cowork create their shared memories, that’s changing, too, Anthropic explained in the announcement. Whereas the pair previously created memories by reviewing a conversation at its conclusion, memories are now created on the fly during chats. Memory generation is on by default for users on free, Pro, and Max tiers (Cowork isn’t available on Free accounts, though), but Anthropic said it doesn’t remember “sensitive” things without users opting to allow those to be stored in memory. Sensitive topics include things related to health, ethnicity, religious beliefs, politics, gender identity, and the like, though adding those to memory can be enabled if users so choose. Cowork will know those things too, mind you, and Anthropic told us there’s no option to separate Claude Chat and Cowork’s memories since they now use a shared system. An Anthropic spokesperson explained that the only way to keep Claude Chat and Cowork memories separate is to use different accounts. Other options, we’re told, are to entirely pause Claude’s ability to remember stuff, use incognito chats for conversations users don't want remembered, or manually prune Claude’s memory to get rid of individual topics. The new shared memory is available from Tuesday; for Team and Enterprise customers, admins control whether memory is available, so if any of those great business features mentioned above sound useful, you may have to call IT and have them enable it. ®
McKinsey says enterprise AI is finally 'on the road to ROI'
Four years into the generative AI revolution, consulting giant McKinsey reckons we've finally started the engine and are officially "on the road to ROI." Whether that road leads to actual profit-making and how long it takes to travel is anyone's guess, because the firm's data suggests most respondents still aren't reporting an enterprise-level earnings contribution from AI. McKinsey surveyed 1,719 professionals and business leaders from around the world and across industries for its report on the State of AI in 2026, and what it found sounds a lot like what similar studies have determined in the past couple of years. According to the report, more businesses are deploying more AI in the belief that their investments will start paying off, but the number of people reporting an actual earnings boost from their AI initiatives has remained flat. According to the survey data, 37 percent of respondents “attribute at least some EBIT [earnings before interest and taxes] impact to AI use,” which is “about the same” share as respondents to its 2025 survey. The word "some" is doing a lot of heavy lifting there, because only a small minority of respondents qualify as McKinsey’s AI high performers. McKinsey considers AI high performers to be respondents who attribute at least 5 percent of their organizations’ EBIT to AI use and describe the technology’s impact as “significant.” The number of high performers has remained flat since last year - just 6 percent of survey respondents met both criteria. Despite the face-slapping reality of hard-to-find benefits, companies are plowing ahead with their AI investments - at least for now. “Organizations’ conviction in AI is growing faster than the immediate financial returns they can attribute to it,” McKinsey said. “More expect AI to reshape their business over the next three years than did a year ago, and they continue to plan to invest more.” Once you sink your tech budget into all that Kool-Aid, it’s hard to put the powder back in the pack, it seems. Agentic AI use is up, says McKinsey, with 40 percent of respondents at organizations with more than $1 billion in annual revenue saying they’re scaling AI agents, compared to 27 percent last year. Coding agents are also on the rise, with nearly a third of respondents saying their organizations decided against buying one or more software products or features in favor of building the functionality in-house with agentic coding tools. Hopefully those firms have set aside a budget to bring in developers to fix the issues AI-generated code can introduce, too. McKinsey also found that, while a majority of organizations plan to increase their AI investments, many are butting up against the fact that it’s really expensive, with 20 percent of respondents saying AI-related operating costs have constrained their use of the technology. All of that set aside, 80 percent of respondents who use AI in their roles said the technology has improved their individual productivity, even as those gains have yet to translate into broad financial impact for organizations. What do respondents expect AI to mean for headcount? Well, more cuts, apparently. While 43 percent of respondents still expect little or no AI-related change in total employment, an increasing number (39 percent this year compared to 32 percent in 2025) expect their employer to cut jobs thanks to AI in the coming year. Like the belief that AI is eventually going to pay for itself, that might not be reflected in reality either, if McKinsey’s prior year data is anything to go on. According to the consulting outfit, workforce reductions in 2025 “fell well short of what respondents in last year’s survey had anticipated,” suggesting that turning to AI to replace humans isn’t a sure bet, which we could have told you without you having to pay McKinsey big bucks to suss that out. So, where does that leave the future of AI in the enterprise? Pretty much in the same place as it was before: A huge money sink that has yet to prove it’s worth the cash businesses are dumping into it. Individual productivity boosts thanks to the automation of soul-crushing busywork may help employees feel better, but that’s not measurably beneficial to a business’ bottom line. As to when McKinsey thinks organization-wide AI benefits reported by respondents, like increased employee and customer satisfaction, “improvements in innovation,” and competitive differentiation, might actually lead to returns on those ever-increasing investments in tools provided by big AI, that wasn’t mentioned in the report. We asked the firm what its experts think, but didn’t hear back. For now, AI ROI remains in the same place as fusion power, fully autonomous driving, and practical quantum computers: Forever a few years away from reality and in dire need of more capital. McKinsey has been in touch since publication to qualify what it meant by the business world being on the road to AI ROI. "Some ROI is already being achieved, and we expect more over time," report coauthor and McKinsey Quantum Black senior fellow Michael Chui told us in an email. "It’s a journey, not a destination." Chui explained that the "high performers" mentioned in the report are seeing "real ROI," but he believes it takes organizational change to make that happen, not just plugging in AI tools and hoping for the best. Chui also said we shouldn't be surprised it's taken several years for AI to begin showing even the smallest bit of ROI for the biggest businesses. "It should not be surprising that it has taken time, because it is a reflection of trends we’ve seen with other technologies," Chui explained. "History doesn’t repeat itself, but it rhymes." ® Updated at 1903 with a statement from McKinsey.
EPA to drop requirement for public notice of polluting datacenters
Soon, you may not even be able to find out what that new neighborhood bit barn could do to your air quality. A proposed change by the US Environmental Protection Agency (EPA) would eliminate federal minimum requirements for public participation in minor-source air permits, a move critics warn could affect some datacenter projects. The Environmental Protection Network, which is made up of former employees of the EPA itself, says the proposed rule change would eliminate mandatory public notice and comment requirements for so-called minor New Source Review (NSR) industrial air pollution permits in state plans under the Clean Air Act (CAA). Instead, state and local air quality regulatory authorities would be able to determine whether and to what extent public participation in minor NSR programs is necessary, effectively allowing them to decide whether the public is notified about new sources of pollution or modifications to existing sources. The EPN, which has submitted formal public comments on the proposed changes, warns that it would leave communities in the dark regarding industrial developments. These could include large-scale, fossil-fueled power generators for AI datacenters that may be permitted as minor or synthetic-minor sources, and therefore avoid more stringent major-source review, it claims. “By eliminating the long-standing federal requirement for public notice, this proposal continues efforts by the current administration to turn its back on the fundamental EPA principle of transparency,” said Mike Koerber, a former deputy director of EPA’s Office of Air Quality Planning and Standards. We asked the EPA for comment. The agency’s current administrator, Lee Zeldin, stated earlier this year that the Trump administration was not going to set national-level environmental rules for the growing datacenter industry. He argued that state and local governments were best equipped to make such decisions, as local conditions like water availability, air quality, and electricity needs differ between regions. But the EPN says that the current proposal directly contradicts Zeldin’s earlier transparency memorandum, which pledged that “the public must be able to trust our work” and called for “the fullest possible public participation in our decision making.” Without public review, facilities such as datacenters may be able to avoid major-source controls on pollution altogether, it warns. The build boom in new server farms to profit from the AI gold rush has often run into difficulties when it comes to getting a connection to the grid. Rather than wait years, many developers or operators opt for on-site power generation, typically supplied by gas-burning turbines. But this can have an effect on local communities, thanks to emissions of smog-generating nitrogen oxides (NOx) and other pollutants. This comes against a background of rising public opposition to bit barns, with a recent Gallup survey finding that more than 70 percent of Americans would be against the construction of a facility in their neighborhood. But President Trump has become more vocal in his backing for datacenters. Speaking out about the Texas governor’s decision to pause new grid-connection approvals for datacenter projects, he claimed it would be a mistake to push back on datacenters, saying "taxes are going to go way down because this is a tremendous source of income." ®
You could've applied all 1,449 Oracle patches and still been hit by this attack
In late July, Oracle released a mammoth security patch dump with 1,449 patches, in a perhaps unprecedented bad day for database admins. None of them, it turns out, would have prevented the credential theft on an Oracle database server described by security platform Huntress. “Even if it had been fully patched, everything working, it still would have happened,” said Craig Savage, cybersecurity lead at Oracle third-party support vendor Spinnaker Support, referring to the attack. In July, Huntress was alerted to credential theft activity, according to a post from the security company. The attack involved a "simple" SQL injection exploiting an unnamed organization's public-facing web app. Although SQL injections have a long history and are easy to avoid with good info-sec housekeeping, what happened next was more unusual. “After gaining initial access, the threat actor dropped a post-exploitation toolkit (called khunt) via a Java Source within an Oracle database, which is a novel aspect of this attack,” Huntress said. Because a code-object can be loaded directly in Oracle's database engine, the malicious actors were able to upload their toolkit directly into the database. “This is a technique that's previously been discussed and described over the years, including via a technique described as oraexec – however, the use of the technique in the wild has rarely been documented,” Huntress said. Oracle's database has an embedded Java Virtual Machine (JVM), and users can take Java source code and store it as a database object. “This is what attackers did during this incident: they fed CREATE JAVA SOURCE commands to the Oracle database from [Java implementation] Tomcat, through the [database] connection, and the Java source code contained within was then compiled directly inside the database as a stored schema object,” the vendor said. Speaking to The Register, Savage said: “Oracle has its own JDK. You are able to build and run Oracle Java programs within the database. It should never be something a web server can do. In fact, in a production Oracle environment, it should be locked down. It should only be re-enabled during a development or maintenance window, for example. It was poorly configured, poorly secured, but it wasn't an Oracle breach.” The ability to run Java in the database should be limited to only the DBA user, Savage argued, and users should disable the ability to compile code on a production server. “If they’d done that, it would have downloaded that Java code, and JDK would not have been configured to compile it,” he said. Savage said cybercriminals were seeking to exploit this kind of functionality more commonly, rather than simply looking to find and use vulnerabilities. “We're starting to see more and more of this: these cybercrime gangs now know about these products. They don't just know how to break them. They also know what legitimate functionality they could potentially use if it's been turned on, and that's what we saw here. That's the wake-up call. Oracle published something like 1450-ish patches. Organizations are totally focused on patch, patch, patch, but you still need to do the basics,” he said. ®
Microsoft warns that transitioning Excel workbooks to new Exchange connectors might not be smooth sailing
Microsoft has issued a warning to Excel users. Want to keep using the Exchange Connector? You'll have to migrate your workbook connections and switch to Microsoft 365 or Office 2024. The software giant just published a timeline for the switchover in its Message Center. The roadmap puts customer validation of the new Exchange Mail and Calendar connectors as starting in August (along with access for early adopters), sets the final phase of the Exchange Web Services (EWS) retirement enforcement in Exchange Online to begin in October, and a plans retirement of the current Exchange connector in Excel Power Query for April 2027. Microsoft did not share its plans for Contacts and Tasks, saying only that "Guidance for Contacts and Tasks scenarios will be shared separately." The challenge users face is that existing workbooks won't automatically transition to the new connectors. Instead, workbooks requiring Exchange Mail and Calendar data will need to be reconnected. A further potential problem is that users might also need an Office update – they will require Microsoft 365 or Office 2024 to use the new connectors. And then there is determining which users and workbooks use the existing Exchange connector for Mail or Calendar data. While the new connector experience has yet to be made available, preparation will be key (along with developing migration and validation plans well ahead of the transition). The countdown for the end of Exchange Web Services (EWS) is ticking, and the Exchange connector is just another service that will be retired alongside the veteran platform. However, although plenty of notice has been given for EWS, it is less than a year until the Exchange connector in Excel Power Query is due to be pulled, potentially taking non-migrated workbooks down with it. Although Microsoft has given users notice, it has not provided a timeline for rolling out the new connectors. Only a request that administrators "identify users who actively use Exchange-connected workbooks and may be interested in participating in validation of the new Exchange Mail and Exchange Calendar connectors." ®
Slop factory bans Russians for using slop factory to create slop
ChatGPT may spew a lot of digital garbage onto the internet, but the same bots that output the trash can be used to stop it. The company draws the line at influence operations that want to slop in the name of love . . . of mother Russia. OpenAI said in a Tuesday blog post that it had identified a cluster of accounts originating from Russia using ChatGPT to produce social media posts and comments directing internet denizens to what appears to be a fake Israeli think tank critical of the west and supportive of Russia. “What began as an investigation into AI-generated social media posts led us to a much broader influence operation,” OpenAI said in its report on the ban of the accounts and what it had found. That said, it appears the Russian efforts were still largely ineffective. “Although the campaign appears to have reached relatively small audiences, its elaborate construction distinguishes it from other Russia-linked influence operations we have disrupted,” the company added. OpenAI further noted that it doesn’t allow access to its platforms from Russia, but it's easy to subvert that ban with a VPN account. OpenAI found posts from the Russian ChatGPT operation on a number of platforms, with Substack, Telegram, X, Facebook, and LinkedIn all playing host to the slavic slop. Most of the comments generated by the Russian actors were in English, but since OpenAI has access to every interaction between its AIs and the account holders, it knows the prompts were all in Russian and included instructions to ChatGPT to hide any linguistic clues that might clue English speakers off to the fact that the original text was in Russian. That said, those attempts to mask awkward translations don’t appear to have been particularly successful, with OpenAI pointing out several awkward phrases used in English-language posts by the group behind the misinformation op. In one case, a passage describing a German coalition of socialists, liberals, and greens was described as the “Svetofor coalition,” a term used in some slavic languages to refer to those parties’ colors in reference to traffic lights. The fact it wasn’t translated into “traffic-light coalition,” or the German “Ampelkoalition,” makes it obvious the original came from a slavic speaker, OpenAI said. In another case, the description of a Telegram channel pretending to be an American political news source is filled with gibberish, including the claim it provides “a totally unhackneyed perspective on hazzy,” whatever that may be. In many cases, the Russian op attempted to direct users to research pieces from the International Burke Institute (IBI), a think tank that claimed to be headquartered in Israel, but which appears to be a completely fictional operation. “In a review of a sample of 36 articles linked to experts on the IBI website and published between September 2025 and May 2026, 34 of the articles were copied from elsewhere on the internet,” OpenAI said. “Some of these articles were years old; others were attributed to the wrong authors.” In one glaring instance, a supposed migration policy expert named in a misattributed paper was actually a food sciences professor from Australia. None of the papers on the IBI’s site were linked to ChatGPT generation in any way, OpenAI noted. The IBI’s most glaring feature, according to the OpenAI writeup, was its "sovereignty index,” which relied on some internal IBI calculation that was uniformly critical of western countries who were at odds with Russia over its invasion of Ukraine and used language that was “typically critical, veering into the polemic” against its targets, OpenAI said. All said, Russia’s antics using OpenAI to generate social media posts related to the campaign were largely pointless, the company said. “The operation’s immediate impact appears to have been limited: typical social media posts only received low numbers of views, and the official IBI accounts had low subscriber numbers,” per OpenAI. “The significance of the operation lies less in the audience it reached, however, than in the infrastructure it had built.” In other words, misuse of AI was just a part of what seems to be a much larger scheme. “Influence actors can use AI as a supporting tool within a broader effort to manufacture authority, obscure the source of favored narratives, and establish assets that could be scaled over time,” OpenAI said. We’ve known this for a while now, but apparently OpenAI is finally getting wise to the fact that the creation it unleashed on the world might not be entirely beneficial. But hey, what AI unleasheth, AI can also help solve, obviously - according to OpenAI, use of its tools in the creation of misinformation might actually be a good thing for hunting it down, as what the company found “illustrates how … use of AI can lead to the broader operation being exposed.” There. Now maybe you can be thankful that everything you ask an AI bot gets recorded on a tech company’s servers in perpetuity. ®
US convicts ex-Philips engineer for exposing X-ray secrets to competitor
A 71-year-old Philips engineer has been found guilty of stealing the company’s medical imaging trade secrets and passing them on to a Chinese competitor. Chih-Yee Jen worked at Philips’ Aurora, Illinois, facility where engineers researched, developed, and manufactured X-ray tubes for the company’s computed tomography (CT) medical imaging machines. X-ray tubes contain multiple components that combine to transform electricity into X-ray images. Jen left Philips on December 29, 2017. The company announced as early as June 2017 that it would close its Aurora facility by the end of the year, affecting around 200 jobs, transferring the responsibilities to Hamburg, Germany. Talks between Jen and Xiaoqin Du, 64, a veep at vacuum electronic business Kunshan GuoLi Electronic Technology, began in August 2017. According to court documents, Suzhou-based Du had sought Jen’s assistance in stealing Philips’s trade secrets and using them to develop X-ray tubes for a Kunshan GuoLi subsidiary, also based in Aurora, IL. Court documents list nine different types of trade secrets that were pertinent to the case, including seasoning protocols, component specifications, manufacturing and assembly processes, tolerance measurements, annealing specifications, and code. Jen, who had worked at Philips’ Aurora facility developing X-ray tubes for its Dunlee brand since 2006, was accused of stealing four of these secrets by accessing company databases “and other locations." The engineer joined the Chinese Aurora subsidiary, referred to only as Company A in legal filings, in January 2018 – soon after he left Philips a month earlier. He went on to develop X-ray tubes for Company A using stolen Philips trade secrets. Company A was sold to Kunshan Yiyuan in May 2018, which sold Company A’s X-ray tubes in China. Prosecutors stated that Philips requires all employees to sign an Ethics and Intellectual Property Agreement, which prohibited them from using, publishing, or otherwise disclosing any secret, confidential, or proprietary information during or after their employment. They also said that the staff who departed Philips after it closed the Aurora facility signed a Settlement and General Release Agreement which, in short, prevented signatories from using Philips technical information to benefit rivals. Philips filed its civil lawsuit on April 19, 2019, although it’s alleged that Jen continued to possess and conceal trade secret information well into July 2022. “The theft of proprietary information is a serious economic crime that harms American jobs and stifles critically important research and development driving the future of our nation,” said Andrew S. Boutros, US attorney for the Northern District of Illinois. “When individuals, corporate entities, or nation states steal proprietary information, they are threatening our country’s technological edge. The Chicago US Attorney’s Office will continue to prosecute trade secret theft to protect innovation, ensure fair competition, and safeguard national economic security.” The lawsuit further alleged that Jen helped recruit fellow Philips engineers to steal trade secrets on behalf of Du and Kunshan GuoLi. Named in the court documents are Fince Tendian, 57, of Aurora, Illinois, and Vladimir Nevtonenko, 77, of Arlington Heights, Illinois. Both pleaded guilty to their charges before trial, whereas Jen was found guilty after one week in front of a jury. According to the indictment, both Tendian and Nevtonenko had worked on Philips’ X-ray tubes since 1998, before the Aurora facility was even opened in 2001. Nevtonenko is scheduled for sentencing on December 1, 2026. Tendian’s sentencing will follow a week later on December 8, while Jen will wait until January 5, 2027. ®