OpenAI's upcoming Jalapeño chip looks like it'll be an inference beast
OpenAI offered its closest look yet at its spicy new Jalapeño AI accelerator at the annual Hot Chips semiconductor development conference at Stanford on Tuesday. The chips, first teased earlier this year, were developed in collaboration with Broadcom, and are the first in a series of custom silicon from OpenAI, designed (in part) by AI, for AI. Compared to contemporary GPU systems from Nvidia, OpenAI says the parts will deliver both higher throughput and lower latency when they start trickling out later this year and reach volume production in 2027. To be clear, Jalapeño won’t replace OpenAI’s long-time hardware partners, which also happen to be some of its most important investors. OpenAI still needs compute for training, and the highly programmable nature of GPUs means that OpenAI is likely to deploy on AMD and Nvidia first and then transition to in-house silicon later. It’s also worth noting that AMD’s MI455X and Nvidia’s Rubin GPUs, also expected to ramp production in early 2027, are very different kinds of chips optimized for a mix of training and inference, whereas OpenAI’s custom silicon only needs to excel at one job: inference. Memory bandwidth is king When it comes to inference, compute is key but memory bandwidth is king. And based on early benchmarks OpenAI shared with the press before its Hot Chips presentation Tuesday, the chip is shaping up to be an inference beast. Testing on SemiAnalysis’ InferenceX benchmark suite — presumably this is an unofficial test — shows OpenAI’s Jalapeño-based systems delivering between 1.5x and 1.9x more “AI work” at peak throughput, and 1.7x to 3.6x lower end-to-end latency than the competition across GPT-OSS-120B, DeepSeek R1, and Kimi K2.5. If the latter two seem like weird models for OpenAI to be testing against, it's not that OpenAI plans to use these chips to run competitors' models, it’s just the models InferenceX uses. In any case, the test shows that Jalapeño isn’t some model-specific architecture designed for maximum performance at the expense of programmability… cough, cough Taalas. Meanwhile, for ultra-low-latency inference, which has become the hot new segment for AI infrastructure providers, OpenAI says its chips are 2.1x to 4.1x faster. At a system level — we're starting here because the frontier models OpenAI trains rarely run on a single chip any more — each Jalapeño system with its 128 accelerators packs 1.7 exaFLOPS of 4-bit compute, 27.5 TB of HBM4 and just shy of 2 petabytes a second of memory bandwidth. By comparison, AMD and Nvidia’s latest rack systems are faster, delivering 1.46x to 2x more compute and up to 12 percent more memory on Helios, but just 85 percent the memory bandwidth of OpenAI’s rack. As of writing, OpenAI hasn’t shared system-level power consumption, but based on what we know about the accelerators we’d wager each rack will use between 40 and 60 percent of the power of competing GPU systems. As usual, take all of these claims with a grain of salt. The competitive systems in question are Nvidia’s GB200 NVL72 and GB300 NVL72 rack systems, which launched in 2024 and 2025 respectively. OpenAI’s point of comparison also excluded speculative decoding, which uses a small draft model to boost inference performance by predicting the outputs of another. While it can be argued this makes for a cleaner apples-to-apples comparison, when you're measuring inference performance, you’re not just comparing hardware but the platform as a whole. Joining the rack-scale revolution Jalapeño’s system design won’t surprise anyone. The chip is designed around a rack scale architecture similar to Nvidia’s NVL72 or AMD Helios. Each rack is equipped with 128 Jalapeño accelerators on board, each of which, we're told, is capable of churning out 13.4 petaFLOPS at MXFP4. That compute is fed by 216 GB of HBM4 memory (we assume six 12-high stacks) good for 15.4 TB/s of memory bandwidth. OpenAI is expected to shed more light on the system and shipping during its Hot Chips presentation on Tuesday, but from what we gather, the chip also appears to feature a large SRAM cache. According to Richard Ho, VP of hardware at OpenAI, the chip was designed to minimize data movement and keep intermediate operations and things like key value caches, which track state, on the chip. "We designed Jalapeño to minimize data movement and communication delays. This means that model state, including the KV cache used while generating a response, can be explicitly placed and kept local while the system activates the right combination of compute, memory, and networking for each inference phase,” the company explained in a blog post. A large SRAM cache would be the most intuitive way to go about this, and it's what we’ve seen the likes of SambaNova, dMatrix, and others do in their own AI XPU designs. However, unlike Nvidia’s Groq LPX racks, Jalapeño isn’t a one-trick pony. Instead, we’re told, it’s optimized for both the compute-heavy prefill operations where prompts are processed, and the memory-bandwidth-intensive decode phase where output tokens are generated. “A system that excels at one phase can lose that advantage while waiting for data or moving model state between different resources,” the company explained. Designed with AI for AI Perhaps the least surprising detail in all of this is that OpenAI used AI to help design, architect, and optimize the chip for inference, cutting time from inception to tape out (the point at which a semiconductor design is finished and ready to be sent off to the foundry for fabrication) to just nine months. This included using its models to optimize its inference-serving engines and to write custom kernels as new models were introduced. But, as impressive as that might sound, AMD and Nvidia have been doing essentially the same thing internally for a while now. In fact, at Advancing AI last month, the House of Zen opened its ROCm.AI offering to the public. Moreover, building a chip that can scale to hundreds of thousands of accelerators isn’t a trivial task, and AMD and Nvidia likely have the edge with regard to programmability, what with GPUs being general purpose accelerators. In any case, Jalapeño won't be the last chip we see from OpenAI, assuming of course the bubble doesn’t pop before its second-gen chip tapes out. ®
Windows XP was released to manufacturing a quarter of a century ago
It is a quarter of a century since Microsoft packed Windows XP off to manufacturing, finally drawing a line under the Windows 9x codebase (behind Windows 95, 98, and Me) and making Windows NT something for consumers. Before Windows XP, consumers and businesses lived in two different software worlds. XP was released to manufacturing on August 24, 2001, succeeding Windows 2000 for professionals and Windows ME (Millennium Edition) for home users. Compared to Windows ME, XP was rock solid (although, to put things in perspective, compared to Windows ME, an elephant perched on a traffic cone is rock solid.) Codenamed Whistler, the operating system marked the start of Microsoft's relentless tinkering with the Start Menu it introduced in Windows 95. With XP, the Windows maker moved to a two-column layout, and took the chance to overhaul the user interface entirely. Redmond engineers tweaked the taskbar too, and introduced grouping by application. As many will fondly remember, they also brought in plenty of visual effects and new icons. And Microsoft made an effort, although this was not always successful, to make backward-compatibility a viable option for that one, weird application that could not be ditched. At launch, there were two editions: Home and Professional. While Windows 98 and ME could be upgraded to Home or Professional, Windows NT 4 and 2000 users were limited to the Professional edition. The latter included features aimed at corporate environments, such as domain account support, and functionality for power users, such as support for more than one processor. Over the years, Windows XP became the cockroach of the IT industry, refusing to die no matter how much it was stomped on. Extended support for the operating system ended on April 8, 2014, more than 12 years after its debut, and XP could still be found lurking under the cover of Windows Embedded POSReady 2009, which came to the end of Extended Support on April 9, 2019. That wasn't quite the end of the road, as in May 2019, Microsoft issued a patch for XP, aimed at warding off malware targeting a flaw in Remote Desktop Services. As late as 2024, Microsoft was still issuing security updates for Windows XP SP3. Famously, many organizations found Windows XP a hard habit to break. 90 percent of the UK's National Health Service (NHS), for example, was still relying on the operating system at the end of 2016, and in 2018 the Reserve Bank of India gave the country's banking sector a 2019 deadline to get XP out of its ATMs. Users also still find the predecessor of Windows XP, Windows 2000, lurking in ticket machines if they look hard enough. Several years ago, a since-departed Microsoft employee told The Register that a chunk of the global banking sector continued to ron on the server version of Windows XP – Windows Server 2003. Windows XP was made available in retail channels in October 2001, but arguably represented peak Windows for many. While for this writer the earlier versions of Windows NT were superior, for consumers Windows XP ushered in a new era of stability (at least compared to Windows 9x), and its user interface and the iconic Bliss wallpaper remain familiar decades on. It was a shame that Windows Vista was waiting just around the corner. ®
SiFive pushes development server to take RISC-V into the datacenter
RISC-V chip champ SiFive has launched a development server built around its own CPUs to help port key workloads to the open compute architecture, and claims it already has hyperscalers and software customers signed up. The processor design firm biz showcasing its BigSky SF-2U870 datacenter development platform at the Hot Chips conference in Palo Alto, California, this week. At the show, it will run a variety of server workloads, and is built specifically for customers to accelerate RISC-V datacenter software porting, workload optimization, and system validation, SiFive says. RISC-V is an “open” instruction set, free for anyone to use – so long as they are capable of designing and producing processor chips that are compliant with the RISC-V specs. The system is based on silicon sporting 32 of SiFive’s P870-D cores operating at 2 GHz, with 256 GB DDR5 memory, a pair of 7.68 TB NVMe SSDs for storage and a 10/25 Gbps OCP-compliant network adapter. SiFive touts it as the world’s first enterprise-grade, rack-mount 2U RISC-V server, a claim that is hard to verify because of the surprising number of little-known companies that make up the global RISC-V ecosystem. There is China-based Sophgo, which sells 2U rack-mount RISC-V servers, for example – but this is understood to be blacklisted on the US Commerce Department’s Entity List. SiFive also claims it has lead customers currently running workloads on deployed BigSky systems, including hyperscalers, software developers, and major system-on-chip (SoC) vendors. The latter is important as the company is a fabless chip designer, akin to Arm, and does not make or sell the physical chips itself. Nevertheless, it says its IP is featured in more than 500 designs, and over 10 billion cores have shipped to date. Chairman and CEO Patrick Little says SiFive is working with others to boost deployment of RISC-V technology in the datacenter, and the BigSky box is vital in getting key software tools working on the architecture. “Ultimately, we are focused on enabling customers to meaningfully optimize the TCO of their custom SoC solutions with SiFive IP. RISC-V in the datacenter isn't a distant aspiration any more, it is happening right now.” It isn’t enough to have hardware that is capable of doing the job, as Arm knows too well. It spent many years and much cash promoting its architecture as an alternative to x86 for servers and the datacenter, getting development systems into the hands of coders and sponsoring the porting of software to run on Arm chips. But it took hyperscalers like Amazon seeking custom processors tailored to their exact requirements for it to take off in servers. SiFive is mostly keeping quiet about who is backing its efforts, apart from naming Linux distributors Canonical and Red Hat. “Getting RHEL 10 running on SiFive’s BigSky platform isn't just a validation exercise, it’s proof that we’re moving from the 'theoretical' phase into production-grade reality,” said Red Hat Technology Strategist Brian Harrington. “We’re excited to be partnering with SiFive to demonstrate that open standards can absolutely deliver the rigorous performance and reliability the modern datacenter demands." SiFive has been working with GPU giant Nvidia on porting its CUDA software stack to RISC-V, and integrating its NVLink Fusion high-speed interconnect technology into future SiFive designs. As a demonstration of its progress, SiFive says it now has CUDA running on the BigSky system. These two developments would allow future systems based on SiFive silicon to operate as AI servers for LLM workloads using clusters of Nvidia GPUs, a capability it says has never been seen before on RISC-V hardware. The SiFive BigSky SF-2U870 is available today, but currently being produced in limited quantities. ®
Microsoft breaks WPF printing with .NET update
Having some unexpected printer problems? Microsoft's August 2026 .NET update might have broken printing on your device. According to Microsoft, "After installing the August 2026 .NET Framework cumulative update, some WPF applications may fail with a System.IO.FileFormatException when printing or generating PDF/XPS content that uses certain fonts, including Calibri." Ah yes, Calibri, the default font in some versions of that little-used application, Microsoft Word. The cumulative update for .NET Framework released on August 11 came jam-packed with fixes, but also printer problems afflicting the company's client operating systems (Windows 10 and 11) and Windows Server 2012 through 2025. Microsoft's workaround is a tweak in the app config file to enable Switch.MS.Internal.TtfDelta.DisableCmapAndSbitOverflowProtection. However, as the company notes, doing so carries with it its own risks: "This switch disables security protections introduced in the August 2026 update and may increase exposure to the vulnerabilities addressed by that update. "Microsoft recommends using this workaround only as a temporary measure and only when required to address this issue." Microsoft says it's still investigating the issue. Printing can be enough of a pain without Microsoft rolling out updates to make the experience even more unpleasant. However, the mention of "certain fonts" suggests the problem is more about how and which fonts are processed during XPS/PDF content generation by WPF applications. August has marked a return to form for Microsoft when it comes to updates breaking systems. The August 11 security update for Windows, for example, broke several games running on Microsoft's flagship operating system. While the exact cause remains unclear, the Windows-maker reckons it has something to do with peripherals or internal device components with RGB lighting features. Microsoft published a registry edit to disable the suspect driver, inpoutx64, to resolve the game crashes, although editing the Windows registry carries with it its own risks. The company said it "is investigating the interaction between these RGB-related components and the affected games. Additional details will be provided as they become available." As for the printing problem after the .NET update installation, the only workaround on offer is to turn off the security protections that arrived in the August 2026 update whenever the affected applications need to print on patched devices. ®
CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw
The US Cybersecurity and Infrastructure Security Agency (CISA) just dished out another three-day deadline for patching an actively exploited vulnerability, the most urgent in its wheelhouse. The culprit: a max-severity Oracle bug affecting Windows VMs. Tracked as CVE-2026-21962 (10.0), the improper access control (CWE-284) flaw affects Oracle’s HTTP Server and WebLogic Server Proxy Plug-in. Successful attacks targeting CVE-2026-21962 can allow miscreants to create, delete, or modify access to critical data, and even gain “complete access” to all data stored on the affected systems. Oracle disclosed and provided patches for CVE-2026-21962 as part of its January 20, 2026, updates. At the time, it said versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0 were affected, and that the vulnerability could be exploited in low-complexity attacks. CISA added CVE-2026-21962 to its Known Exploited Vulnerability (KEV) catalog on August 24, giving federal civilian executive branch (FCEB) agencies three days to protect themselves against attacks – the tightest deadline it is authorized to set. Other bugs to have recently been given the three-day treatment include the critical remote code execution (RCE) flaw affecting Python scaling framework Ray. Despite being disclosed in 2025, CISA added it to the KEV catalog last week. N-able’s “god mode” vulnerability, the one that offered attackers "full administrative access to an N-central console" and was exploited as of July 31, according to the vendor, was also lumped with a three-day deadline when CISA added it to the KEV catalog on August 3. Although CISA only added Oracle’s CVE-2026-21962 to the KEV Catalog on Monday, seven months after it was first disclosed, reports from the private sector suggest attackers had the bug in their sights much earlier in the year. Vikas Kundu, cyber intelligence analyst at CloudSEK, operated a honeypot for 12 days between January 22 and February 3, shortly after CVE-2026-21962 was first disclosed and public exploit code was released. The honeypot captured attacks attempting to exploit the vulnerability, as well as other WebLogic RCE bugs dating back to 2020 and 2017. “The overall activity was characterized by high-volume, automated scanning, with tools like libredtail-http and the Nmap Scripting Engine dominating the malicious traffic,” he said. “Furthermore, the logs revealed significant background noise, including attempts to exploit non-WebLogic-specific vulnerabilities (e.g., Hikvision CVE, PHPUnit RCE, and generic command injections), indicating a broad ‘spray and pray’ approach by threat actors.” Kundu said the findings demonstrated “the critical and immediate need for organizations to prioritize patching” the vulnerability at the time. ®
Ukraine unveils native jet-powered drone interceptor
Ukraine’s Ministry of Defence (MoD) says the country has brought into service its first home-grown jet-powered drone interceptor, intended to take out Russian attack drones. The weapon, known as the Alexa Spatium, is a v-tail unmanned plane developed by Ukrainian engineers to destroy small airborne and surface targets. It was designed primarily to engage Russian kamikaze drones such as the Geran-3, Geran-4, and Geran-5, plus the infamous Shahed-131. Measuring 1.5 by 1.7 meters, it is launched from a mobile catapult and can also return to the launch site for re-use if it does not complete its mission, according to Ukraine’s MoD. The aircraft can be fitted with high-explosive, fragmentation, shaped-charge, or thermobaric (fuel-air) warheads. It can fly to a target using pre-programmed coordinates or use direct guidance. It features both TV and infrared search and targeting systems. Ukraine is being somewhat vague about the Alexa Spatium’s exact capabilities, which is understandable for a country at war. Thus the MoD says only that the aircraft has a high operational ceiling, a substantial combat radius and a powerful turbojet engine, but does not detail what speed it is capable of. Britain unveiled a similar weapon earlier this year, in the shape of the Skyhammer from Cambridge Aerospace. It is likewise designed to counter Shahed-style attack drones and powered by a turbojet engine. It features an X-band radar seeker in the nose and a blast-fragmentation warhead to disable the target. However, while interceptors can take out drones, they are not effective against ballistic missiles. Ukraine has been increasingly vulnerable to attack by these as its stockpiles of American-made Patriot interceptor missiles have run low. A group of 10 European nations, including the UK and Ukraine, launched the Anti-Ballistic Missile Coalition in July to develop an alternative. During a visit to Kyiv, British Prime Minister Andy Burnham announced that the UK authorized European defence firm MBDA to release classified data on Storm Shadow components, enabling Ukraine to manufacture the Anglo-French Storm cruise missile domestically. The move was announced during Burnham’s visit to the country to mark Ukraine’s Independence Day on August 24.®
Crooks push Mac malware through fake OpenAI Codex ads
Cybercrims are using fake OpenAI Codex download pages to trick Mac developers into running malware disguised as installation commands. Researchers at Cato Networks uncovered the campaign after spotting sponsored Google search results targeting people looking to download Codex for macOS. The ads direct would-be users to a convincing-looking download page hosted on Google Sites, complete with the familiar OpenAI branding. There is, however, no Codex waiting at the other end. Instead of serving up an installer, the fake site tells Mac users to open Terminal, paste in a supplied command, and run it. The instructions are dressed up as part of the installation process, but the command quietly kicks off a multi-stage malware infection. It's a variation of the increasingly popular "ClickFix" technique, in which attackers convince victims to execute malicious commands themselves rather than relying on a dodgy attachment or executable to do the dirty work. In this case, the command begins with what appears to be a legitimate npm instruction for installing Codex. Tacked onto it, however, is code that decodes a Base64-encoded URL, fetches an attacker-controlled shell script and pipes it into zsh. That script pulls down another stage, which contacts the attacker's server to report that someone has taken the bait before downloading a Mach-O executable to “/tmp/helper.” It then removes security information macOS uses to flag suspicious downloads, helping the malware dodge the usual warnings before it launches. Cato said the final binaries are universal Mach-O files, meaning they can run natively on both Intel-powered Macs and newer Apple Silicon machines. The researchers found substantial similarities between the campaign and Atomic macOS Stealer, better known as AMOS, an infostealer previously spread through fake software downloads and malicious advertising campaigns. Cato isn't quite ready to slap an AMOS label on the malware, but says plenty of fingerprints point in that direction, from how the attack is staged to how the final payload is built. The crooks have also taken steps to keep researchers from getting a good look at their handiwork. Although victims initially land on Google Sites, the malicious content itself is pulled into the page from attacker-controlled infrastructure using an iframe. That infrastructure checks details including the visitor's operating system and the path used to reach it, allowing it to show harmless-looking content when a visitor doesn't fit the profile the attackers are after. Cato said the decoy site offered both macOS and Linux download buttons, although it only observed the malware chain being delivered to Mac users. Codex isn't the only AI coding assistant getting this treatment. During its investigation, Cato found a similar ClickFix page masquerading as Anthropic's Claude Code and sharing infrastructure with the Codex campaign. The attackers don't have to work particularly hard to find their victims, either. Developers searching Google for Codex do that work for them, with sponsored ads pushing the fake download page above the legitimate results. ®
HMRC dangles £500M carrot for National Insurance system revamp
The UK government is inviting suppliers to bid to build a new national insurance system with a price tag of up to £500 million. The tax collector, HM Revenue & Customs (HMRC), has issued a call to speak to suppliers about the procurement to continue to run and then update the National Insurance and PAYE System (NPS). The “change” aspect of the new contract, which could last up to seven years, is to support “strategic milestones, key business events, and legislative or business-driven updates,” an official notice says. The Preliminary market engagement notice states: “NPS currently operates on a legacy technology estate with limited modularity and scalability. HMRC's future ambition is to transition towards a more agile, service-oriented architecture that supports strategic goals for Income Tax and National Insurance Contributions (NICs) administration, including increased real-time processing capability.” HMRC says the investment — the potential contract is earmarked at £500 million including tax — would lay the “groundwork for future innovation by ensuring HMRC has access to adaptable and resilient support services that can respond effectively to evolving policy, customer needs, and technology opportunities.” The department is set to hold a “supplier market engagement event” next month to provide an overview of the requirement, outline the anticipated procurement approach and timelines, and give suppliers an opportunity to ask clarification questions. HMRC will publish the tender notice, inviting suppliers to bid for the contract, in September. It expects to start in June of 2027. In January last year, HMRC handed Accenture an additional £35.2 million without competition on a £70.4 million contract to run the NPS system, which is part of the UK's critical national infrastructure, collecting 40 percent of revenues into HM Treasury with nearly 40,000 users in HMRC and the Department for Work and Pensions. The system was first introduced in 2009, when the tech services integrator provided application development and support services to the £10 billion Aspire contract, a tech deal which also included Capgemini, Fujitsu, and BT. ®
What is virtualization modernization?
Virtualization modernization is the process of rethinking how you manage virtual workloads across your hybrid estate. IT challenges are expanding, with organizations facing a mixture of licensing challenges and new workloads. This is prompting them to examine their virtualization portfolios. Many are trying to modernize by pricing alternative hypervisors, a rational reflex that often produces the wrong answer. The temptation is to treat virtualization as a line item, swapping out the product while keeping everything else the same. Teams that follow that urge end up paying for a migration and still suffering the same operational drawbacks a year later. What is virtualization modernization? Virtualization modernization takes a longer-term view of virtual workloads and reassesses how they are placed, managed, secured and governed across hybrid IT environments, rather than substituting one hypervisor for another or scheduling a hardware refresh. The right question is not "which platform do we buy?" but which operating model delivers the flexibility, control, consistency and resilience the workloads need. That conversation is harder than a bake-off between hypervisors, and it is the one that current IT challenges are now forcing. What happens if I don't modernize my virtualization? Changing platforms without changing operations moves the complexity around rather than reducing it. When all you do is shift the VMs, you still end up managing the same tasks: VM provisioning Ticket queues Configuration drift Integration debt This becomes less tractable as workloads span multiple datacenter clusters and spread across alternative hypervisors, private cloud, containers, public cloud and edge sites. A lift-and-shift assumes one target when in practice there are several. Organizations that don’t modernize will also find themselves less capable in other areas, such as platform flexibility, operational consistency, governance, and phased modernization across their broader IT portfolio. How should I approach virtualization modernization? Start with the workloads, not the platform A proper analysis covers several areas: Workload assessment Application dependencies Performance requirements Data location Uptime needs Compliance requirements Lifecycle stage Business criticality Migration risk Work through all of these to understand what each workload requires. Should workloads move to VMs, containers, or the cloud? The goal is to align placement with performance, cost, control, governance and operational needs rather than forcing every workload onto a single default target. Design security in, not on top Identity, access, firmware integrity and recovery are not after-the-fact controls to be bolted on once migration begins. Security has to be designed in from the outset. Assume coexistence Most organizations will not modernize their whole estate at once. HPE Morpheus Software — VM Essentials, pitched as a way to cut licensing exposure and avoid vendor lock-in while coexisting with existing VMware and KVM environments, offers one route into that phased shift rather than a substitute for the planning work. What are the benefits of virtualization modernization? A modernized virtual estate should be easier to operate, less fragmented, more flexible and more consistent across environments. Success is measurable beyond cost savings alone, with agility, resilience, governance and visibility all counting, along with the ability to keep options open the next time a vendor rewrites its licensing terms. HPE frames virtualization modernization inside its wider multi-gen compute story and packages the work alongside ProLiant hardware, iLO security and Compute Ops Management rather than as a standalone product decision. Treat it as a conversation about how you want to run IT for the next several years, not another line item on this quarter's invoice. Sponsored by HPE.
Australia’s record industry won’t chart tunes recorded in the key of AI
The Australian Recording Industry Association (ARIA) has decided it won’t list AI-generated music on its charts of best-selling music. The decision comes into effect this week and follows two interesting musical moments of note. One came when an AI-assisted cover version of Madonna’s Like a Prayer hit the top ten in Australia, stirring debate about whether using AI to make music is an off-key creative decision. The other was the International Federation of the Phonographic Industry (IFPI) pitching a set of principles “governing the eligibility of recordings developed with generative artificial intelligence services for inclusion in official music charts.” The IFPI distilled its principles into the following chord of criteria that must be met for a tune to be included in the charts: Any generative AI services used to develop the recording are properly authorised and lawful; They are substantially human made; They do not raise manipulation concerns; They comply with applicable laws, including those relating to copyright, related rights, and personality rights; The making available of the recordings does not breach the terms of the generative AI service used; The use of generative AI services to develop the recording is appropriately signaled to consumers on downstream services (e.g., digital streaming platforms), in accordance with any applicable legislation and/or industry labelling standards. The IFPI’s real beef with AI seems not to be the technology, but AI services that produce music without licensing it. “Tracks created using generative AI systems have been appearing on streaming services, however many of these have been developed with tools that have been trained on artists’ music without authorization,” the IFPI’s announcement states. “To tackle this, record companies are driving the development and licensing of AI music services that respect the rights of music creators.” A veritable choir of record companies – among them Sony Music, Universal Music Group and Warner Music Group – had a hand in developing the principles. And now those companies and chart-compilers won’t publish counts of sales and streams by artists who create their works using AI services that don’t license music. The IFPI announced its principles in late July. On Tuesday, ARIA became the first organization to adopt them. CEO Annabelle Herd offered a canned quote that rammed home the licensing message. “Artists already use AI tools in their work, the charts can and should evolve to keep room for that, but music generated wholesale by services built on artists’ recordings is a different matter,” she said. ®
SpaceX claims it will put a Vera Rubin NVL72 rack-scale system into orbit next year
SpaceX will send at least one datacenter rack into space next year, according to Elon Musk, with more to follow in 2028. The occasional trillionaire made that claim on Monday on the user-generated content platform – a.k.a. the social network X – that he runs in part to feed the Grok models SpaceX develops with up-to-date contextual data. “SpaceX, in partnership with Nvidia, has designed a space-optimized Vera Rubin NVL72 system for launch to orbit in Q4 next year, with significant scale in 2028,” he Xeeted. Nvidia offered a slightly different version of events in a press release that states SpaceX’s datacenter satellites “will be based on the optimized NVIDIA Vera Rubin NVL72 rack-scale system.” The full NVL72 comprises 72 Rubin GPUs, 36 Vera CPUs, ConnectX-9 SuperNICs, and BlueField-4 DPUs – all housed in 18 compute trays, plus a further nine NVLink switch trays. Nvidia says each unit, plus rack, weighs “roughly 4,000 lbs, or about the weight of a pickup truck” – or 1,800kg. SpaceX hasn’t said which rockets it will use for the launches Musk mentioned. The company’s workhorse is the Falcon 9, which can launch 22,800 kg to low Earth orbit. The fairing that contains payloads on the Falcon 9 measures 13.1 meters high with a diameter of 5.2 meters. The MGX racks Nvidia uses to house each NVL72 are around 600mm x 2,293mm x 1,068mm deep, so the Falcon 9 can fit a few inside its fairing. SpaceX has proven it can launch over 100 Falcon 9 missions each year, so can clearly get a lot Nvidia racks into space. Nvidia says each rack draws 120 kW and uses novel liquid cooling. SpaceX has published details of its datacenter satellite design that says it will possess a 210 kW solar array, and use liquid radiators that “reject heat into the vacuum of space, built upon SpaceX's extensive experience operating vehicles on-orbit.” The company is, however, yet to build such a satellite. It therefore looks conceivable that SpaceX and Nvidia could make this work – but because space is hard many obstacles also exist that could derail the promise of launches at scale in 2028. Note, also, that neither Nvidia nor SpaceX has said what “space-optimized” means. The Register presumes the term covers radiation-hardening and work to ensure the delicate machines can handle the stress of launch. We’ve asked if it also means changes to the number of servers or other kit SpaceX will launch. Elon Musk’s companies have an impressive track record of out-innovating rivals, but Musk also has a history of making grand predictions that either don’t arrive or eventuate years after his promises – such as his forecast to deliver self-driving Teslas and millions of robo-taxis. The New York Times recently found Musk delivered on 19 percent of 602 promises made in public and was either years late or did not deliver on 35 percent of promises. ®
IBM announces chip that natively executes Arm and Z instructions concurrently
IBM has revealed it is working on a chip with processor cores that can execute instructions for its own mainframe chips and for the Arm architecture – and for the LinuxONE architecture too for good measure. Big Blue says the unnamed chip will be built on a two-nanometer technology node, include 11 high-performance cores operating at more than 5.7 GHz, plus AI inference accelerators for in-transaction fraud detection, a dedicated on-chip data processing unit for I/O acceleration, and a large cache architecture for demanding enterprise workloads. “Each processor core can natively execute Arm and IBM Z, or Arm and LinuxONE, instructions concurrently,” the computing veteran promises. In a blog post, IBM’s Vice President for the zSystems Ecosystem Meredith Stowell pointed out that “The Arm ecosystem includes more than 22 million developers worldwide and supports a rapidly growing portfolio of cloud-native, AI, analytics, infrastructure, and enterprise applications.” IBM’s Z platform is powerful and very well suited to demanding applications. But while mainframes are a big business for IBM, the overall market is small. Rocket Software, a vendor that provides mainframe modernization tools, yesterday told The Register that it is aware of 42 IBM mainframe users in Australia – and that the land down under is therefore a market it needs to prioritize. Commercial application vendors therefore won’t rush to prioritize z/OS and IBM knows it. Big Blue also knows that major hyperscalers have introduced their own Arm processors and that customers are flocking to them in part because almost all major open source infrastructure, cloud-native, and AI tools run on the architecture. George Cozma, an analyst at TechInsights, told The Register that while the mainframe market is “small in unit terms” it remains “strategically important.” “Customers do not casually replace these systems because core applications, decades of operational practice, and data gravity make migration expensive and risky,” he wrote. But while Z is important, the analyst feels it “sits outside the mainstream software targets that define modern cloud and AI infrastructure.” This new chip, Cozma said, represents “ending the platform’s historical isolation from the broader computing mainstream. While IBM Z’s core strengths – reliability, security, and virtualization – remain the gold standard for mission-critical operations, they are tethered to an architecture that has increasingly diverged from the modern software development lifecycle.” IBM is therefore trying to get the best of all possible worlds: continuity for the small group of ISVs that currently make mainframe products and their customers, expanded software choice for existing IBM customers that also makes Z a more interesting choice for the mainframe-curious, and the nine-nines resilience of the mainframe for more workloads. IBM suggested the new chip will arrive in 2028. Big Blue released its most recent generation of mainframes, the z17, in 2025, and typically delivers new models every three years. The chip therefore looks a good candidate to power z18 machines. One last thing: Cozma pointed out that IBM has form developing dual-architecture chips. “Back in the deep, dark annals of the mid-1990s, IBM developed the PowerPC 615, a chip that could run both PowerPC and x86 code, with the active ISA selected at boot,” he wrote. “The chip was reportedly intended for Apple during the clone era, but it was never sold publicly.” ®
Microsoft AI watermarks in Paint and Photos are linked to user IDs, researcher finds
When Anthropic disclosed earlier this month that it would be applying a statistical word-choice watermark to its Claude text output, the company noted that at least 190 AI providers have agreed to abide by Europe's AI transparency rules. One such company is Microsoft, which has been applying its own form of watermarking to images created with the assistance of AI in its Paint and Photos applications for Windows. The EU's Code of Practice on Transparency of AI-generated Content requires that signatories mark content created with the help of AI in a machine-readable format and that associated metadata indicates at least whether content has been manipulated by AI, or entirely created by it. The regulation creates an obligation but does not specify the method of compliance, so signatories can employ whatever technology best achieves the goals [PDF] of "effectiveness, interoperability, robustness, and reliability." Microsoft has gone beyond minimum requirements in an effort to address AI safety concerns. The EU rules encourage, but do not demand, the inclusion of metadata that does more than answer whether creators used AI to produce content. Redmond, as one of the founders of the Coalition for Content Provenance and Authenticity (C2PA), has chosen to embed AI-assisted images in Paint and Photos with a globally unique identifier (GUID) linked to the prompt that created the image. Xusheng Li, a software developer at Vector 35, recently published an analysis of Microsoft's approach, which the Windows biz previously disclosed in the Paint and Photos documentation but did not detail. "Microsoft Paint and Photos embed a server-issued GUID as an invisible watermark in locally generated AI images," Li explained in a LinkedIn post. "Your prompt is sent to Microsoft for moderation, and the returned GUID is encoded into the pixels." Li notes that the invisible GUID watermark – a 16-byte integer – is distinct from the visible watermark option that Microsoft provides to users of its Paint software and Microsoft 365 AI features. If Microsoft associates each prompt with the user who sent it, then the company could in theory identify users by referring to the watermark in an image. Long ago, manufacturers of laser printers implemented this sort of tracking and the practice alarmed privacy advocates when it came to light. "Microsoft receives and moderates the prompt, then issues the unique GUID that Paint embeds into the locally generated image," Li said. "Paint also sends the previous promptGenerationId as lastPromptGenerationId with its next moderation request, allowing successive requests to be linked explicitly." Li argues that while Microsoft has disclosed its AI safety measures, it hasn't sufficiently clarified that its C2PA manifest contains a GUID linked to users' AI image prompts. Microsoft did not immediately respond to a request for comment. Other companies are thinking along similar lines. Meta last month said it is working on its own watermarking technology called Content Seal. And OpenAI has been applying Google DeepMind's SynthID and C2PA metadata to its images. Those seeking to avoid having a tracking number embedded in their AI-generated images may want to explore running an open weight model like Stable Diffusion and running on-device open-source tools. ®
You don't want this Sleepwalker backdoor on your Windows machine
Like a sleeper cell awaiting activation, a never-before-seen Windows backdoor dubbed Sleepwalker waits silently in memory for one specifically crafted network packet to wake it up and deliver commands using the malware's 23-instruction language. The commands can do everything from running code directly in memory to moving data off the computer. Malware researcher Dominik Reichel discovered the passive backdoor, which also has its own command language, and detailed Sleepwalker in a technical analysis on Monday. “What makes it worth writing up is what that packet carries: not a readable command, but a short program written in a command language of the backdoor’s own design,” Reichel said. “Its 23 instructions cover scheduling, several ways to move data, staged file delivery and running code directly in memory. Recovering the encryption key is not enough to understand one of these programs. The internal command language must be reverse engineered as well.” In addition to having its own command language, it's also notable that the remote host can be a VMware VMCI target instead of a normal network address. “Taken as a whole, the approach here is consistent with a targeted, well-resourced operation rather than an opportunistic one,” Reichel wrote. The malware, hidden inside a 64-bit Windows DLL file, impersonates Microsoft's dpapi.dll, part of Windows' data protection API for protecting sensitive data. It exports the same seven functions as the real dpapi.dll, but attempts to forward calls to a file named dpapisvc.dll, which is not a real Windows component. The file also has a forged ESET Management Agent version resource, and loads via side-loading into ERAAgent.exe, the Windows executable for ESET Management Agent. After confirming that its host process is named ERAAgent.exe, Sleepwalker goes to sleep inside the computer's memory, which also helps it remain hidden from traditional anti-virus tools. Unlike most backdoors, which call back to an attacker-controlled command-and-control (C2) server and start receiving commands, Sleepwalker lies in wait, checking every packet that passes through the network looking for a specific pattern - this is called a magic packet. Once it sniffs out a packet that matches the exact pattern, the backdoor decrypts the data and treats it as a command. “Because the backdoor never sends anything out on its own and does not open any obvious listening port by default, tools that watch for connections to known-bad domains or unusual outbound traffic will not see anything unusual,” Reichel wrote. “The absence of outbound connections to known-bad infrastructure does not rule out an infection, either. A machine can be fully compromised by this backdoor while producing nothing at all for a network monitor to flag.” Hidden commands Every command sent to the backdoor is encrypted using AES-256-CCM, and the command language is unique in that, once decrypted, it is neither text nor a document. Instead, each command is a short sequence of raw bytes, and it only makes sense when read in a specific order. Reichel’s write-up includes a key that shows how to read the bytes, and each of Sleepwalker’s 23 instructions is written in this command language. Some of the instructions carry an inner program. For example, a scheduler can also contain a network listener, with a routine that waits for a particular file to be assembled and checked before it will run on the compromised computer. Beyond the two magic-packet sniffing instructions and basic instructions - such as an exit command that stops all running programs and the packet listener, and an instruction that starts a second, smaller program running concurrently with the parent program - the backdoor has multiple others. These include four instructions on sending and hiding data. One of these opens a TCP connection to a chosen address and port, and then sends a block of data to a remote host, which can be a VMware VMCI target instead of a normal network address. Another one writes a block of data to a Windows named pipe on a chosen computer, and can optionally log in with a username and password first. Five other instructions focus on inbound task reception, such as waiting to receive - or reaching out on its own - a follow-up instruction, opening a TCP or UDP port, or creating and/or connecting to a named pipe. Additionally, the malware has five different instructions on building and running programs. A lot of unknowns…and detection tools As Reichel notes, however, a lot remains unknown about Sleepwalker. “I have no collection context tying the file to a confirmed intrusion, so I cannot identify a victim, industry, country or affected organization,” he wrote. While we know that the DLL is designed to execute via side-loading after being placed beside ERAAgent.exe, we don't know how the malware operator first gained access to the computer or delivered the malicious file. We also don’t know the operator or developer, or what post-compromise activity, if any, took place. “I found no related code that would support attribution to a known group, and this one sample cannot establish when or how widely Sleepwalker was deployed, whether variants exist or whether it belongs to a continuing campaign,” Reichel wrote. Perhaps most importantly, for anyone who believes that they may be infected with Sleepwalker or a related malware sample, Reichel wrote, “I have created a toolkit to help decode its bytecode, examine encrypted and network artifacts, summarize behavior and indicators and safely reproduce its receiving pipeline without executing commands or transmitting traffic,” urging targeted individuals to contact him. He also created a mitigation guide, with a remediation script for use after Sleepwalker is detected.®
Browser fingerprint tool shows how easy you are to track using the latest sneaky tricks
If you're curious how easily tech companies can fingerprint your browser and device and potentially single them out from the crowd, a new utility Glassbox will show you. Aside from pinging a public geolocation API, it runs entirely in a user’s browser and doesn’t ship any info out to the web while acting just like all the various trackers, anti-fraud scripts, and other browser fingerprinting tricks one is likely to encounter online. Unlike some other available tools that do the same, Glassbox provides a whole bunch of raw, unfiltered data you can sift through to see what makes your browser stand out, along with an estimate of how identifiable its fingerprint may be. In this vulture’s testing, Glassbox's estimate ranged from 99 percent in the Chrome window I use daily for work to a low of 56 percent in Tor Browser with an active circuit. “The ‘identifiability’ number is an honest model, not a measurement,” Glassbox developer David Dale said of his tool in a Hacker News thread. “It sums published per-signal entropy, discounts your browser masks, and caps at the ~33 bits needed to single out one person on Earth.” Dale added in the thread that, since it runs locally, that identifiability number is an estimate, as Glassbox doesn’t have a live population to pull against. AmIUnique and the EFF’s Cover Your Tracks, the other tools mentioned above, provide real population numbers, he noted. Dale got the idea for GlassBox after learning about silent sawtooth waves used by fingerprinting code found on Alibaba's AliExpress site to identify browsers using audio. Rather than fork one of the existing open source tools - both EFF's Cover Your Tracks and AmIUnique have GitHub repos - he decided to build his own, with some help from AI. “I'm a solo entrepreneur and long-time security engineer; tools like Claude Code have made it much easier to polish ideas and offer the useful ones to a wider audience,” Dale told us in an email. “I knew a fair number of fingerprinting methods but not that one, and I wanted to see all of them in one place, running against my own browser,” he said on Hacker News. In other words, Glassbox factors Alibaba’s tricks into its identifiability estimates alongside 30 other probes for unique browser data - things like canvas, WebGL, font libraries, WASM features, API matrices, and cross-site login states. According to Glassbox, my particular Chrome session I use for work is unique to around 1 in 7.6 billion browsers, and my IP address narrows that further (my ISP apparently uses IPv6, making me even more identifiable). As for which browsers appear to be safer, I have Safari, Edge, Firefox, and Tor on my machine alongside Chrome; Firefox and Tor are the only ones that didn’t label me “effectively unique,” giving me estimated identifiability ratings of 89 and 56 percent, respectively. What that means is that I share the same fingerprint as 1 in 681 million Firefox users and 1 in 408 thousand Tor users - that still doesn’t exactly make me a ghost online, but it definitely puts me in a pool much larger than Chrome, Edge, or Safari. Again, those are estimates, Dale reminded us, not a hard truth as, he says, “a no-server tool [can’t] measure true rarity.” “The single highest-impact move is to use a browser that puts you in a large, identical crowd,” Dale explained in an email. “Counterintuitively, a heavily customized ‘hardened’ setup often makes you more identifiable, because almost nobody else looks exactly like it. Blending in beats standing out.” Aside from using a browser that does a good job of obfuscating its user, Dale said a VPN or Tor is a must, as is finding a way to close the WebRTC leak that has long dogged internet users and leaves browsers identifiable through some VPNs thanks to being enabled by default in most web browsers. Glassbox includes a page of suggestions for how to anonymize yourself online, and let’s face it: With everything from invisible pixels to silent sound waves doing their damndest to figure out who’s behind a browser in order to make money off them, that’s more important than ever. ®
Conjure cash with old Macs by linking them to AI inference Borg
Eigen Labs, a five-year-old tech biz based in Seattle, Washington, estimates that owners of Apple Silicon hardware can earn $120 to $200 per month on average by selling idle compute power for AI inference. Gajesh Naik, an engineer at Eigen Labs, said on Friday that the Darkbloom project, a distributed network of Apple Silicon devices, has become a paid inference provider on OpenRouter and invited Mac owners to add their machines to the Darkbloom network. "We have fulfilled on track close at 4.5B tokens served and $102K ARR," Naik said in a social media post. "We are [an] open network of Mac machines (250 online right now). On average, people are earning $120-200 per month per machine. If you have a Mac and it's idle most times: put it on darkbloom.dev." Mac mini machines, still scarce in the wake of the OpenClaw buying frenzy and in the run-up to the anticipated M5/M6 refresh, are probably best suited for the job. But an M1 MacBook Pro and any other Apple Silicon-equipped macOS device, as detailed in the hardware requirements document, can probably contribute something. Would-be machine rentiers can enlist a personally owned device – sorry, no cloud-provider rental arbitrage, per the terms of service – by installing the Darkbloom software. The code aims to overcome the privacy risk of running AI inference – prompts and responses – on someone else's hardware. "The inference engine runs directly inside a single hardened Swift process – no subprocess, no local server, no inter-process communication – using mlx-swift-lm on the Apple Silicon GPU," Naik explains in a technical paper [PDF] detailing the Darkbloom architecture. "The macOS kernel blocks all external access to this process’s memory: debuggers are denied at the system call level (PT_DENY_ATTACH), memory-reading APIs are blocked by Hardened Runtime, and these protections cannot be disabled without rebooting, which terminates the process and erases its data." Essentially, an inference consumer sends a request over HTTPS via an OpenAI-compatible API to a server running a Go-based coordinator in a Confidential VM (AMD SEV-SNP) that routes the request to an inference provider – someone running an Apple Silicon Mac with the Darkbloom Swift CLI. The provider connects outbound over WebSocket, avoiding the need for port forwarding or firewall changes, decrypts the inference job within a Secure Enclave, and runs the inference on the Apple Silicon GPU using MLX, Apple's machine learning framework. The plaintext is exposed only within the coordinator's hardware-encrypted CVM memory, is never logged or retained, and is immediately re-encrypted for the selected provider, the documentation claims. The privacy model and threat scenario are similar, in other words, to Apple's Private Cloud Compute, but in the context of a distributed network. Darkbloom began as an experiment in April and now has more than 900 providers (not all of which are active at any given time) that have served more than 42 million inference requests. The network previously served up inference capacity for free through OpenRouter, but now has become a paid provider. The top earning model at the moment, per Darkbloom's own stats, is Qwen 3.6 35B A3B, at $399 per month of usage, followed by GPT-OSS 20B, at $52 per month of usage, and Gemma 4 26B, at $27 per month of usage. Usage isn't necessarily continuous, so top earners at the moment are averaging $26/day, $19/day, and $15/day, respectively. The biz estimates network participants can earn anywhere from $192 to $4,983 per year, which includes estimated average electricity costs of almost $2 per month (not to mention fan noise where applicable). Whatever the payout, that's money going toward people running open weight models on personal computers and not frontier labs with data center debt that are struggling to attract customers to premium models. ®
Windows NT 4 went on sale 30 years ago today
Today marks the 30th anniversary of Microsoft Windows NT 4.0 becoming available on August 24, 1996. Windows NT 4.0, codenamed “Tukwila,” went on retail sale exactly 30 years ago. This was the version that started to deliver on the promise of Microsoft’s long-running Windows NT project. NT 4 married the very solid NT operating system with a slightly modified version of the Windows Explorer desktop from Windows 95, which is why it was also internally known as the “Shell Update Release”. NT 4 had been released to manufacturing on July 31. As it happens, Windows 95 itself was launched exactly one year earlier, on August 24, 1995. Codenamed “Chicago” and originally planned to be called “Windows 4”, Windows 95 went through a long, iterative development process during which the desktop shell changed dramatically. Various unfinished versions leaked over the years, and the excellent ToastyTech has screenshot tours of Windows Chicago Build 58 and Build 73 in which you can see the UI taking shape. In early versions, programs didn’t minimize to the taskbar yet, and the prototype Start Button didn’t do much. By 31 years ago, the Explorer desktop had come together enough to launch. Explorer had some missteps. For instance, Windows 95 had no web browser; that was a paid-for optional extra in the Windows 95 Plus! Pack, along with Space Cadet Pinball. Instead, Windows 95 had a desktop icon for the Microsoft Network (MSN), a dial-up social network that displayed forums and participant lists using desktop file-explorer style windows, in an effort to blur the lines between local and remote resources. Some of the features of the Explorer desktop were to avoid stepping on Apple’s toes – it had already sued Digital Research over the quite Mac-like GEM Desktop. So, Windows 95 didn’t have drive icons on the desktop – they lived inside a virtual folder called “My Computer” instead. Another virtual folder, “Network Neighborhood”, showed visible file servers and let the user browse for share volumes using the Explorer UI. The whole Explorer desktop lived in a single Windows process: so, if you started a long file operation, such as copying files to an external drive, you couldn’t do anything else. The whole desktop locked up for as long as the dialog box with the progress bar was visible. For one awkward year, Microsoft’s two separate and independent OS product lines had very different UIs. The first release of Windows NT was called “Windows NT 3.1”, keeping it in harmony with the existing DOS-based Windows 3.1. For a first release, it was remarkably stable and reliable, but it required a formidable PC for 1993. The youthful Reg FOSS desk deployed it in production in the City of London, and to be even vaguely usable it needed a Pentium CPU and a whopping 16 MB of RAM – at the time, that meant a PC costing over £5,000 (£11,000 or $15,000 in 2026). This was followed by NT 3.5, which tightened up the code a bit and introduced the ability to store long filenames on FAT drives. Then came NT 3.51, which was smaller, faster, even more reliable, and also supported PCMCIA cards, file compression on NTFS, and hardware-accelerated OpenGL. But all NT 3.x versions still had the old-fashioned GUI from Windows 3 and OS/2 1.x, with a separate “Program Manager” for launching programs and “File Manager” for handling media. After Windows 95, this suddenly looked very dated. This vulture ran it at work, and it was rock-solid and quick once we manually defined a few hotkeys for launching applications. (We used Ctrl+Alt+W for Word, Ctrl+Alt+E for Excel, Ctrl+Alt+F for File Manager, and Ctrl+Alt+D for a Command Prompt – which still used the old MS-DOS icon. “D” for DOS, you see, even if it didn’t involve actual DOS at any point.) Windows NT 4 fixed this: a small team ported the Explorer UI from Windows 95 over to the NT kernel, although not without some effort thanks to NT’s native Unicode support. The Explorer got a few adjustments: rather than storing the Start menu entries in a single folder tree with shortcuts, it merged two trees, one for the current user and one containing entries from the global “All Users” tree. This gave users with a high-end PC the best of both worlds: the stable and reliable NT OS, plus the fancy modern Explorer desktop. At the time, Windows 95 was still on its first release. So, it only supported the 16-bit version of the FAT filesystem, compared to which NT’s fancy journaling NTFS was much more resistant to corruption. If you had the high-end hardware on which to run it, NT 4 was a very strong proposition: modern UI combined with modern kernel and modern filesystem. It was not without flaws. To improve the responsiveness of the new desktop, Microsoft chose to move NT’s 2D graphics rendering subsystem, the Graphics Device Interface or GDI, directly into the Windows kernel for improved performance. This eliminated an elegant aspect of the NT 3.x design, and meant that a bug in a display driver could crash the OS, introducing issues that would persist for over a decade, until the release of Windows Vista in 2007. NT 4 also didn’t include the long-promised Cairo object-based filesystem – that never shipped, although its user interface influenced the Explorer design. NT 4 also started to date quickly. The next few releases of the DOS-based Windows family rapidly added support for several handy new tech innovations. Less than a week after the release of NT 4.0, Windows 95B, AKA “OEM Service Release 2” or OSR2, introduced FAT32. A year later, Windows 95 OSR 2.1 added support for the new USB interface. NT 4 never got those things – or at least, not official versions from Microsoft. Its Plug ’n Play support remained all but nonexistent until it was replaced by NT 5, marketed as “Windows 2000”. Even so, NT 4 was more than good enough. It combined a solid OS core, rich server functionality, and a friendly GUI. Thirty years ago, Windows NT started to deliver on its promise. It was the beginning of the end for Novell NetWare. It also compounded Apple’s technological difficulties, leading to the company acquiring Steve Jobs’ NeXT Computer four months later. ®
YouTuber's backyard fab ambitions expand from RAM to homebrew LEDs
A YouTuber on a mission to liberate semiconductor manufacturing from the grip of multinational megacorporations is back with a new round of DIY success, this time manufacturing working LEDs in his backyard fab. Dr. Semiconductor, also known as semiconductor engineer Dr. Matthew Hartensveld, per his recently launched website, first caught the internet’s attention five months ago when he built a class-100 cleanroom in a shed in his backyard. Back in April, we wrote about his successful project to build his own DRAM in the clean shed, and the video he posted over the weekend on building his own LEDs follows that project with more ingenious success. Hartensveld’s decision to construct his own LEDs is directly connected to his RAMbitions, mind you - this isn’t some side project to light stuff up for fun. As Hartensveld notes in the video’s introduction, working DRAM cells are great, but they’re a far cry from functional DDR5 chips that can be plugged into a computer in lieu of ever-costlier chips from a major manufacturer. Turning cells into a RAM chip requires a lot more fabrication and packaging work, but there’s a problem there: attaching a finished silicon die to a circuit board requires lining up a whole bunch of tiny contacts with corresponding pads on the board. Because silicon is opaque to visible light, it takes more work to get everything aligned correctly. Enter LEDs made with gallium nitride (GaN): GaN is transparent, and LEDs still have to be attached to a circuit board to provide them with power, making them the perfect test bed for home packaging experimentation. “Not only does gallium nitride LED material help us develop our packaging process, it also helps us make some RGB,” Hartensveld said in the video. “And everyone knows RGB makes RAM faster … at least emotionally.” Etching GaN into LEDs traditionally requires the use of hazardous chlorine gases, which Hartensveld said in his video made it impractical and unsafe for his purposes - not to mention ridiculously expensive to either build or acquire the equipment necessary to do it safely. He instead decided to go with a laser etcher, using a 355 nm ultraviolet wavelength that GaN absorbs. After testing the laser etching process and finding it successful, Hartensveld moved on to a more traditional LED production flow, adding p-type contacts that supply positive charge and n-type contacts that supply negative charge using a typical process of applying photoresist and using metal deposition to fabricate his diodes. A bit of indium added to the etched GaN and supplied with power showed that the process worked, emitting the blue light expected from the InGaN quantum wells. From there, Hartensveld was able to add indium bumps to an ENIG-finished circuit board, which he used to attach the LED to the board. Because the LED itself is transparent, Hartensveld was able to show in the video how the indium contacts melted and formed a bond to the LED. Supplying power to the circuit board itself led to the same bluish light. Hartensveld also succeeded in changing the color of his LEDs to emit a warmer white light by covering them in the same yellowish material that is found covering the LEDs of most commercially available LED lightbulbs: Cerium-doped yttrium aluminum garnet. In other words, the project was a smashing success, not only for the democratization of LED manufacturing but also for his future efforts to build working RAM modules. “Going forward we can leverage our newfound packaging ability for RAM or really anything,” Hartensveld said in the video. He hasn't applied the new method to RAM module manufacturing yet, and while Hartensveld tells The Register he intends to do so soon, he has some additional work to do before he gets there. "The next step is shrinking both the transistor and, more importantly, the capacitor so I can increase the density and start experimenting with some of the techniques used in more modern commercial DRAM," Hartensveld said in an email. After shrinking comes scale, naturally. "As the features get smaller, alignment, process control, yield, interconnects and packaging all become much more difficult," The semiconductor doc added. "That's really what makes this interesting to me, figuring out how much of modern semiconductor fabrication can be reproduced with simpler, lower-cost equipment and processes." Chip democratization dreams While Hartensveld’s early work has been confined to a trio of YouTube videos, it appears he intends to go considerably further with his work. “Semiconductor fabrication is treated as something only billion-dollar fabs can do. It isn't,” he states in the about section of his website, semiconductor.diy. “A Class 100 cleanroom fits in a garden shed, sub-micron lithography can run on a modified microscope, and working devices can be made at home. This site documents how, openly, so anyone can build on it.” Hartensveld added in the video that he is working on open-source documentation for his entire process; bills of materials and instructions for his cleanroom shed and the LED project are already included on the site. The YouTuber also said that he’s planning to release videos on a more regular basis now that he has sponsorship from Vensa, a nonprofit backed by Ethereum cofounder Vitalik Buterin dedicated to the development of open-source silicon. “Microchips are the foundational technology for modern civilization, but making them is out of reach for most,” Vensa says of its project on its about page. “'Open Silicon' holds the most promise for democratizing chip design and improving the safety and sovereignty of computers.” LEDs made in a garden shed are just the first step. "I don't expect a shed fab to replace a billion-dollar commercial semiconductor fab, but I do think there is a huge unexplored space between 'you can design a chip' and 'you need access to an industrial foundry to actually make one,'" Hartensveld told us. He added that he hopes his work will give students, researchers, startups, and hobbyists the ability to experiment with semiconductor fabrication and make their own devices, making the process more accessible. "Democratizing semiconductor manufacturing and enabling a sort of small-scale or 'cottage' semiconductor ecosystem is definitely part of the vision," Hartensveld added. "The DRAM and LED projects are demonstrations of what's possible; now I want to keep shrinking the devices, improving the equipment and seeing how far this approach can actually be pushed." ®
Iran-linked cyberattack shut down a UK power plant
A suspected Iran-linked cyberattack shut down a small UK power plant around the time that a series of digital intrusions disrupted American water utilities across 12 states. A British government spokesperson confirmed the hack to The Register on Monday and told us that the security incident affected a “small-scale energy generator.” “At no point was there a risk to the wider energy system,” the spokesperson said, adding that the UK’s energy system is “highly resilient,” and that the government works “closely with the energy sector to protect infrastructure.” In a series of xeets about the cyberattack, UK Energy Minister Michael Shanks said that his department briefed energy CEOs after the incident and “shared further advice with companies on the steps they should take to stay secure.” Government officials did not disclose which power station shut down, and the UK has not formally attributed the cyberattack to Iran - or any other government or hacking group. The Telegraph, which first reported the news, said that the incident shut down the power plant for four days in what is believed to be the first disruptive Iranian cyberattack of its kind in the UK. In late July, suspected Iranian cyber operatives disrupted more than 30 water facilities in Minnesota, with similar intrusions subsequently reported across at least 11 other US states. While neither state nor federal officials have attributed these hacks to Iran, private-sector threat analysts have told The Register that Iran is “almost certainly” behind these breaches, which are a direct response to the ongoing Middle East conflict. While these earlier water-system intrusions didn’t appear to have an AI assist - most or all of the American utility cyberattacks involved internet-connected programmable logic controllers (PLCs) - last week the feds warned that attackers are now using AI-generated exploitation scripts to break into internet-exposed Siemens S7 Series PLCs at water, manufacturing, energy, and other critical facilities. “This is not a theoretical risk – it is an active threat,” the FBI and four other federal agencies warned. “This appears to be a continuation of the same suite of activity we suspect is affiliated with Iran targeting PLCs,” Cynthia Kaiser, Halcyon Ransomware Research Center SVP and a former FBI cyber analyst, told The Register. “Iran-affiliated actors and adversaries are actively targeting a wide swath of operational technology because these PLCs underpin essential health, safety, and critical infrastructure across society,” Kaiser said. ®
Logitech hit by sueball over tariff refunds
A complaint filed in a California District Court has accused peripheral maker Logitech of withholding tariff refunds from customers, and asked for the proceeds from its activities to be returned to punters. When the US administration imposed tariffs on imports, companies quickly passed them on to US customers. While we won't go into the whys, wherefores, and the what-were-you-thinking, of tariffs imposed by the US administration, the upshot was that customers often ended up paying more for the same item. It has made for an exciting time in the IT world. Logitech was no exception, and US customers faced higher prices. According to the 102-page complaint [PDF], "in or about April 2025 … Logitech raised United States retail prices across approximately half of its product catalog, by an average of approximately 14 percent and by as much as 25 percent on individual products." The complaint goes on: "Logitech's own executives and securities filings confirm that these price increases were in response to, and calibrated against, the IEEPA tariffs." It is difficult to argue with the logic – tariffs go up, and so do prices. However, a problem with the tariffs emerged. On February 20, 2026, the US Supreme Court stated that the IEEPA (International Emergency Economic Powers Act) did not, after all, authorize the US President to impose tariffs. On July 15, 2026, an order was issued, directing the US Customs Border Protection (CBP) to refund the IEEPA duties. Those refunds go to the importers rather than the consumers who paid the higher prices. Some are returning money to customers. Some… are not. According to the complaint, the vendor was one of the latter. The filing claims that in addition to not refunding customers, Logitech also kept prices where they were. The complaint goes on to say that "as of June 30, 2026, Logitech received a full refund of $61 million for the tariffs invalidated by the Supreme Court." However, it alleges, rather than this being given back to customers, "The entire $61 million was recorded as a reduction of cost of goods sold in Q1 FY2027, according to reporting on Logitech’s Form 10-Q filings with the United States Securities and Exchange Commission (SEC)." The complaint alleges: "Logitech has made clear it will keep both the refund and the consumer overcharge." Logitech has yet to respond to a request for comment. The company is far from the only tech firm to face complaints over the imposition of tariffs and subsequent refunds. In July, Microsoft was sued over Xbox tariff costs and refunds. Nintendo was also sued and, in July, stated it had no intention of passing a tariff refund back to customers. "Plaintiffs," wrote Nintendo in its motion to dismiss, "have no legal entitlement to the tariff refunds Nintendo stands to receive." ®