Subscribe to The Register feed
Articles from www.theregister.com
Updated: 59 min 15 sec ago

An ultra-rare piece of Microsoft history could be hiding on your shelf

Sun, 08/23/2026 - 05:32
In a future edition of The Antiques Roadshow, the hosts might get all excited about a mint Microsoft Entertainment Pack for Windows… with a sticker on the box instead of a printed Tetris promotion. Veteran Microsoft engineer Raymond Chen explained the reasoning behind using the sticker instead of simply printing what was in the box. Microsoft hadn't locked down the rights for Tetris before the first print run of the packaging, so went with what it had. The Microsoft Entertainment Pack for Windows debuted in 1990, the same year that Windows 3.0 was released and ushered in an era of Microsoft desktop dominance. Three more iterations of the entertainment pack followed, which included FreeCell, before Microsoft pulled the plug in 1992 (although a Best Of version arrived in 1994, and there was another version for Windows CE later in the 1990s). We'll draw a discreet veil over the ad-festooned version currently in the Microsoft Store. The floppy disks in the box included several card games, Minesweeper, and a Windows version of the fiendishly addictive and massively popular game of the era, Tetris. But it might not have gone that way. Chen explained in a post on his Old New Thing blog, "At the time the first run of boxes were being printed, the negotiations to license Tetris hadn't yet concluded. There was a chance that the negotiations would fall through, and the Entertainment Pack would have to be released without Tetris." So, rather than risk throwing away a production run, Microsoft went ahead with the Tetris-less branding, and added a sticker when the deal was done. Later print runs made the sticker part of the box art, hence the rarity of the original. Microsoft has a bit of a history of inadvertently creating collectibles. Chen recalled an incident with Windows 95, when an anti-piracy hologram on the case depicted a child pointing at a computer monitor and the Windows 95 logo. The child was shirtless, which caused offense in some quarters. Microsoft's solution? A new hologram with the baby in a shirt and overalls. However, some original versions still exist. Chen said, "So if you still have your copy of Windows 95, go look at the hologram. If the baby in your hologram isn't wearing a shirt, you have a genuine collector's item." We can just imagine the excitement at the recording now, as someone produces not only a stickered version of the Microsoft Entertainment Pack for Windows, but also the topless baby version of Windows 95… ®

If you're not using AI to attack your own systems, your adversaries will

Sat, 08/22/2026 - 08:02
AI agents excel at hacking organizations, as they’ve demonstrated in real-life attacks multiple times over the past few weeks. They also expose a whole new attack surface for organizations trying to protect against both human and AI intrusions. As if defenders needed more worries to keep them up at night, agents introduce new data-integration channels that attackers can abuse. They also introduce a new type – and ever growing number – of non-human identities that are difficult to manage and can bypass traditional, static security policies. “There is tremendous risk associated with agentic AI and machine identities,” Matt Hartman, former acting head of cyber of the US Cybersecurity and Infrastructure Security Agency (CISA), told The Register. “As AI moves from generating content – yesterday's use case – to taking actions, it is inevitable that agents are going to receive access to sensitive systems and sensitive data,” Hartman said. “One area where organizations are struggling today is that they're going to need to treat every agent as a privileged identity.” Enterprises also face agentic threats from outside their organization, he added. “AI-enabled or AI-amplified identity and social engineering attacks are increasing significantly by the minute,” Hartman said. “We're seeing very highly personalized phishing, very good impersonation, automated reconnaissance. That really makes traditional indicators of trust increasingly unreliable.” For defenders, this means a “continued focus on strong identity, on phishing-resistant authentication, on behavioral signals, and on zero-trust principles therein,” he added. “Nothing deeply new here - but it is a whole new attack surface.” Meanwhile, on the attackers’ side, agents don’t take time off, and they remain singularly focused on completing a task, whether that’s finding vulnerabilities and exploit chains or mapping networks and identifying sensitive files. All of this makes these near-autonomous attack bots a gift from the heavens for financially motivated criminals and government-backed cyber operatives. It also presents a security use case for defenders: agentic red teaming. As former NSA cyber boss Rob Joyce said during a talk at RSAC: if you aren’t using AI agents to attack your own organizations, you can bet that someone else is. “You are going to be red-teamed whether you pay for it or not,” Joyce said. “The only difference is, you know who gets the results delivered to them.” Hartman echoed Joyce’s words. “What we are seeing as the leading capabilities to help defenders – there is a burgeoning market for continuous, AI-native, AI-enabled, automated red teaming and pen-testing,” he told us. After spending nearly two decades in the federal government at CISA, Hartman joined Merlin Group in October as its chief strategy officer. In his new private-sector role, he helps determine which early- to growth-stage cybersecurity and emerging technology companies the group invests in, and then works with these firms to navigate government, critical infrastructure, and other highly regulated markets. The goal is to integrate and scale “promising technologies” into critical environments, Hartman said. Right now, most of these technologies use AI agents to fight AI agents. “Organizations are just inundated with vulnerabilities, and adversaries are able to leverage AI to find vulnerabilities and exploit them in seconds when it used to take days,” he said. Agentic red teaming “is a category of products that every organization, including federal agencies, absolutely needs in the near term just to keep pace.” 'Largest controlled live AI cyberattack on record' Mandiant founder and former CEO Kevin Mandia has a new company, Armadin, which launched in March with a startling $190 million in seed and Series A funding. The firm builds and trains autonomous attacker swarms – thousands of AI agents that run 24/7 in organizations’ infrastructure to simulate real-life attackers. Ahead of Black Hat earlier this month, the startup said it and Tenex.ai, an agentic security operations provider, executed what they called the “largest controlled live AI cyberattack on record” for an unnamed “leading” global institution. Over the three-day attack, Armadin's swarm generated 17 million offensive actions, discovered 38 validated attack paths, and produced 238 security findings. Tenex.ai's agentic platform separately triaged 100 percent of 101,169 alerts and reconstructed the entire attack across 231 billion raw events. This exercise, we’re told, would have taken a five-person analyst team about 2,400 hours – or four months – to pull off. Co-founder and Chief Offensive Security Officer Evan Peña was the global red-team lead at Mandiant before co-founding Armadin. At Mandiant, he led a 210-person team whose members spanned the globe. “The problem was it was 100 percent human-led security assessments, and that would generally limit the amount of time that we would have,” Peña told The Register. His red team “would do a couple weeks or a one-month engagement, and then we would report on the engagement, give them a PDF file, walk away, and they would hire us again in a year. In today’s age of AI, it’s very archaic to think about that when we can scale so significantly with AI.” Attack yourself before someone else does At Armadin, Peña leads the human team that trains the AI agents. One of the lessons learned from OpenAI’s models autonomously attacking Hugging Face, according to Peña, is that organizations need to perform safe offensive AI attacks against their own systems. "Safe" is the keyword here: remember OpenAI’s rogue models intentionally didn’t have any guardrails in place. Yes, his statement is self-serving as it's core to Armadin's business. But he’s not wrong. “Organizations can cover so much more attack surface because we are able to leverage these agents at scale, and we have three things that we didn’t have before,” he said. “We have more time, because agents don’t sleep and they don’t take holidays. There’s no workforce requirements for them.” Number two, he said, is expertise. Attack agents need pre-training before they are set loose on organizations’ infrastructure. They need to know how to code, and perform source-code review. They need to know how to do application security, how to spot network misconfigurations, and hack into different systems and networks. “And then you add post-training to that from human expertise,” Peña said. “Number three is coverage,” he said. “We were only able to cover a finite amount of attack surface in the past. So if you had 10,000 external systems with a limited amount of time and humans, you could maybe cover 2,000 or 1,000 of those within that particular period of time. Now we can cover all 10,000 in probably hours.” Armadin’s AI agents have broken into every single customer’s environment, according to Peña. “We have found over 50 zero-days, and by zero-days, I don't just mean this zero-day allowed you to deface a web page. That’s cool, but I want to break into your network from the internet,” he said. “The zero-days I'm referring to allow an attacker to get remote code execution on an actual system. They're very high-impact zero-days. We don't care about noise, we care about impact.” Quarterly pen-testing doesn't cut it anymore The biggest challenge these days for defenders is the scale and speed AI brings to previously manual attackers’ dirty work – like scoping potential victims, performing reconnaissance, identifying vulnerable systems and exploits, and reading logs. Now all of these tasks can be automated. Penetration testing needs to keep up, Jay Bavisi, founder and group president of EC-Council, told The Register. The largest and best organizations do pen-testing once a year to meet compliance requirements, and “the better ones” run these exercises quarterly, Bavisi said. This is largely because human-led pen-tests take about three months. “So you have a serious problem with speed,” he said in an interview. “Then comes the second problem, which is scope. Nobody pen tests the entire organization.” There’s also what Bavisi calls a “sophistication problem,” because different human pen-testers will produce varied results, and organizations can’t hire hundreds of thousands of humans to try to break into their networks on a continuous basis. “The bad guys are already using AI to get rid of the speed problem. You pen-test once a year for compliance. They do it all the time because you're a gold mine. They don't have a scope problem because they're not just looking at the crown jewels - they're looking at your entire organization. And they don't have a sophistication problem because they're using algorithmic systems.” In June, the global cybersecurity training organization began offering pen-testing professionals a sponsored attempt to take the CPENT AI examination, and upskill themselves for the AI era. For every participant who passes, the council donates $1,000 in cybersecurity training and certification credits to nonprofit partners. For every completed training program, regardless of an exam pass or fail, the nonprofits get $250, and all of this has a $1 million max. “The traditional model of pen-testing once a year or once a quarter, that’s going away, and AI will take over with automated pen-testing,” Bavisi said. “But will the role of pen testers vanish? No, it will not. It will evolve into something much bigger and something far more important.” AI systems and AI-integrated applications mean there’s a lot more for security professionals to try to break and break into, and humans need to determine: What is the result of this system breaking? What’s the business impact? What do I prioritize fixing? “The present pen-testers have to be reskilled into understanding business impact and being able to make those important engineering decisions,” Bavisi said. Meanwhile, “offensive AI security professionals are the ones that are going to have to test the robustness of AI systems, because AI systems will become the heartbeat of organizations,” he added. “Pen-testers have to become masters of testing LLMs, understanding agentic behavior, thinking about what is the harm taxonomy, figuring out what kind of guardrails did we put in place.” The job of pen-testers has changed, in other words. “It now has a far wider scope.” ®

AI slop is good for business if you know what you're doing

Sat, 08/22/2026 - 06:19
Amazon founder Jeff Bezos is known for saying, "Your margin is my opportunity." Substitute "irresponsibility" for "margin," and you have a formulation that applies to AI-driven software development. AI models or coding agents make mistakes, and many of the people using them multiply those errors by asking their AI helper to build software without the knowledge necessary to build actual proper software. The resulting vibe-coded apps have created a new growth industry – AI slop sanitation. Witness Slopfix, "a team of three senior engineers who refactor vibecoded codebases back to maintainability." Konstantin Klyagin, the Lisbon, Portugal-based founder of contract software biz Redwerk and QAwerk, a quality assurance consultancy, told The Register that a growing number of clients are asking for help to fix vibe-coded apps. Klyagin said he's been developing software for the past two decades, and with the adoption of generative AI, customers have been seeking help with their vibe-coded applications. "Back in November," he said, "we posted on our website that we do vibe code cleanup. And for us, it's not just reducing the amount of lines of code but also making sure the product is production ready and can serve actual customers, because I don't think that volume [lines of code] is a fair criterion to consider. Less [code] volume doesn't necessarily mean more successful software." On the surface, Klyagin said, vibe-coded apps tend to look good. But what's important to understand is how the business logic is implemented and how the app handles arbitrary user behavior. "It's not just how it was coded and what it was supposed to do in the best case scenario, but also how validation works, if there are security problems," he explained. A common issue, Klyagin said, is code duplication. In an app his company reviewed for a New York-based client, he said, there were duplicate payment paths. So a price mentioned on the front page of the app differed from the number presented during the onboarding flow, he said. Then there was a problem with the permission handling. "So you could go straight to the sign up page and to the payment page, skipping the creation of the profile," he said. Then there were problems with the forms, which were insufficiently accessible for screen readers. And the test coverage was incomplete. Technically oriented company founders who create apps, Klyagin said, tend not to need vibe-coding cleanup services. But those who lack software development experience don't know how to set up the proper architecture and practices for building a maintainable app. "It's up to you to set certain restrictions and steer [the AI model] in the right direction towards better software architecture and also infrastructure," he explained. Before vibe coding became a thing, Klyagin said, clients asked for code reviews and refactoring, which he described as an integral part of the software development life cycle. Or they might ask for a code review when planning to acquire an application. Now that people commonly use Claude Code and Codex - although he hasn't yet seen codebases built with open-weight models - there's a lot more QA and bug fixing. Klyagin said his company has been managing the extra work with the help of AI. "AI makes everyone faster," he said. "We and our customers are now able to ship more code and more features. Some do it with more discipline and some with less discipline. "So what we do, we just explain discipline to founders and to enterprises that adopt gen AI for coding. Because you know this discipline is not going anywhere. You still need to specify what you're building and you still need to test it." ®

Skylab completists, clear some shelf space for 26 DVDs

Sat, 08/22/2026 - 02:15
The team behind the Searching for Skylab documentary is releasing almost every surviving piece of video it could find from the mission. The collection will span three volumes and 26 DVDs, including an updated version of Searching for Skylab, which we reviewed in 2019. It gathers almost everything the team could find that was downlinked from the station or returned to Earth aboard the three Apollo spacecraft that visited it. Interested in the prelaunch preparations, briefings, and launch itself? It's all there. How about the efforts to make the station habitable after a solar array and shield were torn off during launch? Yep – that's there too. That time the crew tested maneuvering equipment inside Skylab that would become the Manned Maneuvering Unit used during early Shuttle missions? Also there. Skylab was NASA's first space station. Launched in 1973 aboard the final Saturn V to fly, its orbital workshop was based on the S-IVB rocket stage. The mission almost ended in disaster when one solar array and the station's micrometeoroid shield, which also served as a sunshade, were torn away during launch. The first crew deployed a parasol to protect the station from the Sun and freed the remaining solar array, which had been pinned down by debris. Three crews visited the station, with the last returning to Earth in 1974. Skylab re-entered in 1979, scattering debris across a sparsely populated part of Western Australia. Rather than an expanded cut of Searching for Skylab, the collection is a companion archive aimed squarely at completists. Those seeking an accessible introduction to the missions should start with the documentary; these discs are for viewers who want the surviving footage in all its raw detail. The collection is a labor of love for Dwight Steven-Boniecki, who told The Register that material gathered for Searching for Skylab supplied about half of its footage. "Intense searches uncovered a lot of previously forgotten footage. Things like rollout and launch TV were a crucial discovery to round out the sets. As it turns out, some of the footage comes exclusively from kinescopes in my possession." Steven-Boniecki recalled tracking down footage of a tour conducted by the SL-2 crew during the first crewed mission. "I located the footage but sans audio," he said. "I got in touch with a collector who had a copy of the downlink, but no technical means of recording the audio, other than recording it on their mobile phone. "So I had them point their iPhone at the screen and hold it near the loudspeaker from the projector. Using the off-the-screen footage, I was able to synchronize the audio with the pristine footage I had. I had to apply noise reduction using a learned noise print of the projector to eliminate as best as possible all extraneous noise. To top it off, the audio was already bad when it was sent down in 1973, due to signal strength during the telecast. "I opted to have subtitles for that particular segment, as understanding what the crew were saying proved to be difficult." Most experiments aboard Skylab were recorded and transmitted later. Conferences, spacewalks, and the crews' initial entry and setup tended to be broadcast live, while film canisters containing several reels from each mission returned with the astronauts. "One instance for SL-2 had me dancing for joy," recalled Steven-Boniecki. A set of observations from the Apollo Telescope Mount did not show up on any data cards in any of the official archives he searched. "It turns out a kinescope I had won in an auction years earlier contained nearly 30 minutes of solar observation TV. It was silent, so I used mission audio recorded on the same day, that closely matched the point at which this TV feed was recorded. "A similar situation arose with one of the training films where tests were done transporting items via an EVA. This reel has not been located anywhere, and I suspect the film is the only surviving master, as the reel specifically states 'Do not Project' on it." Indeed, some clips lack audio, and the video quality reflects the era. Blu-ray would have required fewer discs, but, as Steven-Boniecki noted, "the benefit of HD is lost on the sequential color TV kinescopes." We looked at Volumes 1 and 2, which cover SL-1 (the launch), SL-2 (the first crew, comprising Pete Conrad, Joseph Kerwin, and Paul Weitz), and SL-3 (the second crew, which consisted of Alan Bean, Owen Garriott, and Jack Lousma). The forthcoming Volume 3 covers the final Skylab crew, SL-4 (Jerry Carr, Ed Gibson, and Bill Pogue). A physical copy of Searching for Skylab can be found in the Volume 1 case. Steven-Boniecki isn't quite done with the story of Skylab. After plans to use the Space Shuttle to boost Skylab's orbit came to nothing, controllers reactivated the station and attempted to control its attitude ahead of re-entry. "The planned Vol. 4 set will cover the reactivation and subsequent re-entry of Skylab over Western Australia," he said. "There is some outstanding footage, including the Channel 9 Australia TV of Skylab breaking up in the night sky!" Volume 4 is still several months away while Steven-Boniecki transfers the footage and masters the discs. "Plus," he added, "it will give people time to save for it." An important factor: the sets are not cheap, although they contain a great deal of material. Each physical DVD volume costs £89.99 plus postage. Digital editions cost $69.99 for Volume 1 and $79.99 each for Volumes 2 and 3. As the team notes, this is very much for "hardcore space fans." After Volume 4, Steven-Boniecki plans to gather footage from another often-overlooked mission and Apollo's last hurrah: the Apollo-Soyuz Test Project (ASTP). "Work has already begun," he said. "There is a LOT of unseen footage there!" ®

Casio decides it's about time the simple digital watch got a little smarter

Sat, 08/22/2026 - 01:43
Casio has added Bluetooth and step tracking to a £55 digital watch without turning it into a smartwatch or sacrificing replaceable-battery convenience. The snappily named F-B100W pairs with Casio's smartphone app to record activity, adjust settings, and keep its clock accurate. Despite the additional electronics, Casio claims approximately two years of operation from a replaceable CR2016 battery. It is very much not a smartwatch. There is no touchscreen, app store, or stream of notifications – just a conventional digital watch with a step counter and a little Bluetooth connectivity. That combination has nevertheless attracted attention on Hacker News and Reddit. We admit it: this ape-descended life form is so astoundingly primitive that he still thinks digital watches are a pretty neat idea. Douglas Adams first mocked humans' fondness for digital watches when the original Hitchhiker's Guide to the Galaxy was broadcast in 1978 – nearly half a century ago. The Casio F-91W is only a decade younger. This strangely ubiquitous watch, once labeled a supposed "sign of al-Qaida," is widely regarded as the classic quartz digital watch and has been described as the bestselling watch of all time. One reason is that it's only £20 ($30) new. Another is that if you bought one of the first batch, it's probably only on its third or fourth battery by now: they are rated for seven years, but often last longer. The F-91W is very simple and very cheap. Its main rival for all-time bestselling watch is the reverse: the Apple Watch has also shifted about 300 million units. This is not a radical innovation for Casio. The existing ABL-100 does much the same, but costs over 25 percent more and weighs more than twice as much. What is interesting is that Casio has brought the functionality to a smaller, cheaper, and lighter watch – and possibly a more robust one. It's also retained an impressive battery life. These Bluetooth-enabled models should still run for two years or more on a single, replaceable, CR2016 lithium button cell. Since those only cost a buck or so, that sounds good to us. The Reg FOSS desk has a fondness for inexpensive technology that performs a modest set of tasks well. Our first budget smartwatch was an Amazfit Bip, bought new for about £60 ($80). It had an always-on, daylight-readable color display, lasted a month and a half on a charge, and did everything we asked of it. After five years of daily use, its battery stopped holding a charge. We replaced it with the then-latest Bip 5, only to find that the newer model lacked its ancestor's always-on display and offered less than a quarter of its battery life. Our next move was therefore backward to a secondhand Amazfit Neo. It is the most basic smartwatch we have encountered. A conventional segmented LCD displays the time, while a smaller strip cycles through the world clock, step count, pulse, estimated calories burned, battery level, and waiting notifications. It cost £15 ($20) and still lasts a week and a half on a charge. This "beyond retro" design is, we need hardly say, no longer made. That is why Casio's move in the opposite direction – adding a few connected features to a basic digital watch – interests us. We found the existing threads about these devices highly educational. There's a whole world of digital watch geekery that we barely even knew existed. Some posters raised concerns we found very relevant. For instance, the vexed issue of date formats: it seems many low-end Casios can only display dates in US MM/DD format. Apparently, to get European-format dates, you need to go to more high-end models such as the GW-M5610U-1ER at a princely £135 ($185). These lower-end Bluetooth-equipped Casio devices send only one Bluetooth Low Energy update to the phone at the end of each day, which is why they can boast such impressive battery life. In its pricier G-Shock range, the company does offer devices with bidirectional Bluetooth support, so that the watch can display on-screen notifications, such as the £129 ($165) G-Squad GBD-200 and GBD-300. Better still, it seems these can deliver silent vibrating alerts. Another concern is that officially syncing these watches requires Casio's proprietary smartphone app, but there are FOSS alternatives such as Casio G-Shock Smart Sync. The Register asked Casio for more information and a review unit but had not received a response at the time of publication. ®

AWS Security makes an inscrutable choice

Fri, 08/21/2026 - 16:42
One of the best ways to lower your AWS bill by 99 percent or more is by not checking your keys into public GitHub repositories. Many of us have done this inadvertently over the years, and the defenses against it have improved dramatically (my personal favorite being "using non-ephemeral credentials derived from OIDC or SSO is an anti-pattern"), but it still happens. On Friday, BleepingComputer reported on a Truffle Security finding that hundreds of leaked AWS keys are root keys and are somehow still active and valid. AWS Security is full of very smart people who care deeply about a number of things, including "not abetting crime." If they detect (usually via automated means) that a credential has been leaked, they're quick to apply a Quarantine Policy to it. Trouble is, that policy enumerates a bunch of bad behaviors in an ever-expanding graph of principals and associated behaviors. AWS' considered position on this is that they don't want to break customer environments: "The policy aims to limit the potential damage that may be caused by fraud-related activity leading to unauthorized charges, while not impacting the existing resources." AWS' considered position on this is wrong. If I get access to your credentials (much less a root credential, good god), deactivating them may very well break your workload because anything that relies on those credentials will start failing. Until you rotate them, those workloads will continue to fail. That's not good! But I promise you, as a bad actor, I can do far worse to you. Hold my tea Go ahead and apply a quarantine policy to a credential set and toss it my way. I won't be able to buy savings plans, read your S3 data, modify Lambda functions, and do a host of other things. But here's what I can do. Anything I damn well feel like on RDS. You don't have anything important in databases, right? ssm:SendCommand / ssm:StartSession are permitted, which means I can run commands as root on EC2 instances, which will in turn invoke with that instance role’s permissions. sts:AssumeRole means that I can assume any other role in the account and get its permissions, rendering the entire restriction list potentially moot. I can use autoscaling:CreateAutoScalingGroup / UpdateAutoScalingGroup to launch instances via the Auto Scaling service-linked role, so the ec2:RunInstances deny never applies. cloudtrail:LookupEvents gets denied (that'll stop you from... reading the audit log), but I can call both cloudtrail:StopLogging and DeleteTrail which do exactly what you expect; you don't have an audit log anymore. SES denies ses:GetSendQuota / ListIdentities actions, but y'know what's missing? SendEmail, so I can blast my spam out to your entire list. sns:GetSMSAttributes means I can't get your SMS configuration, but I can absolutely sns:Publish to send fraudulent text messages wherever I'd like. s3:DeleteObject gets denied, but s3:PutObject is allowed. I can't delete your data, but I can fill a bucket to petabytes. Next, they fail to block s3:PutBucketVersioning, s3:PutObjectLockConfiguration, s3:PutObjectRetention, and s3:PutObjectLegalHold. So on any existing bucket, like that one I just stuffed petabytes into, I can enable versioning, turn on Object Lock, and set a bucket-default COMPLIANCE-mode retention out to 2126, or alternatively slap it on per object. COMPLIANCE retention can't be shortened or removed by anyone, including the account root and AWS Support. The only way to remove it is to delete the entire AWS account. secretsmanager:GetSecretValue, ssm:GetParameter* (WithDecryption), and kms:Decrypt are all unencumbered, so your secrets are now my secrets. Sharing is good! Backups are important, so it's a shame you don't have any. Well, not after I kick off backup:DeleteRecoveryPoint / DeleteBackupVault, and rds:DeleteDBSnapshot. If you're using CloudFormation, and for some things you almost certainly are, cloudformation:DeleteStack going unmentioned means you're not using it anymore and all of your stacks are gone. I would make different choices This isn't a comprehensive list - just a few things that occurred to me over the course of about an hour. I'm not a bad actor; I'm almost positive that I'm missing a whole bunch. AWS is almost certainly going to change this. My question for them is simply, "how big of a customer incident needs to happen before you do?" ®

Cloverleaf deal is latest example of Nvidia using its war chest to patch cracks in the AI bubble

Fri, 08/21/2026 - 16:00
Nvidia has made its fortune on the AI boom, but the company has a problem. It faces a growing number of roadblocks which, if left unchecked, could pop the bubble. Thus, the AI arms dealer has been forced to play a game of Whac-a-Mole, shoring up the foundations of its empire by investing its spoils into ensuring its customers don’t stop buying. The latest example of this came Friday, when Nvidia announced it’d become a minority investor in Cloverleaf. Founded in 2024, Cloverleaf specializes in laying the literal foundations – by which we mean the land and power – necessary to build bit barns so they can be leased by the cloud providers and model devs that actually pay the bills for Nvidia’s hardware. Nvidia can only sell as many GPUs as there are datacenters to put them, and those datacenters can only be deployed where there’s adequate power to support them. And since its latest round of GPUs can’t just be dropped into any old bit barn, Nvidia is going to need a lot more datacenter capacity, and by extension a lot more power. A new breed of datacenter Up until 2024, the majority of Nvidia’s systems were air-cooled. Supercomputers, like those built by Cray and Eviden, were the exception to the rule. Unless you were deploying tens of thousands of GPUs, its accelerators could be deployed just about anywhere with minimal modification to the facility. That began to change with Nvidia’s Blackwell generation. You could still get air-cooled systems from Nvidia and its partners, and it certainly sold a lot of eight-way HGX B200 boxes, but deploying its most powerful NVL72 systems required liquid cooling that not every facility was capable of supplying. Liquid-cooled facilities are harder to build than their air-cooled counterparts. Liquid-cooled racks tend to be more compute dense, and therefore heavier and power hungry to operate. That means in addition to larger UPS backups and beefier PDUs, these facilities now need a bunch of coolant distribution units (CDUs) to pump coolant around — about one for every one to three megawatts of compute capacity. Datacenters must be designed to support all this extra weight, and the problem is only going to get thornier as Nvidia transitions from roughly 250kW to 600kW racks starting next year. With Nvidia’s Rubin generation of GPUs, air-cooled GPUs may as well be a thing of the past, at least in the HGX and NVL-style form factors that power the majority of AI training and inference deployments today. For the first time, Nvidia is offering the chips only in liquid-cooled varieties. So, to sell its next-generation GPUs, Nvidia not only needs its customers to have adequate capacity, but also needs those facilities to offer the right mix of power and cooling. Right sizing for deployment It’s well established that Nvidia prioritizes customers with datacenters ready to fill. However, many of the GPU-slinger's biggest customers don’t actually own datacenters, but instead lease capacity from others. For example, Crusoe built OpenAI’s Stargate facility in Abilene, Texas, and Oracle runs it. Altman and crew are simply supplying the demand. So, Nvidia has invested in model devs and neocloud partners by helping them get financing or even investing directly in their businesses. Nvidia’s investments in OpenAI, CoreWeave, and Nebius are just a few examples. That works so long as the bit barns available for rent are the right size and shape for the hardware. But, as we noted earlier, many existing facilities aren’t. To further reduce friction and make it easier for its customers to find space to deploy its kit, Nvidia introduced its DSX platform last fall and officially launched it this spring. In a nutshell, DSX is a set of blueprints outlining exactly how much power, cooling infrastructure, and space are needed to support a given amount of compute. It also provides tools to optimize that compute to minimize wasted capacity. The power problem But even designing to a spec won’t do bit barn builders any good if they can’t get their hands on enough power. The proliferation of AI datacenters has begun to strain grid capacity, forcing many new ones to employ behind-the-meter power generation. For example, Nebius has begun using Bloom Energy's natural gas fuel cells to power its datacenters, rather than relying entirely on existing grid infrastructure. Nvidia’s investment in Cloverleaf is the latest example of how the GPU slinger is using the circular AI economy to its advantage. The terms of the deal haven’t been disclosed, but the benefits are obvious: Cloverleaf gets an influx of cash, while Nvidia gets greater control over the build process. As part of the deal, Cloverleaf is also embracing Nvidia’s DSX spec. In theory, this should enable bit barn builders to drop a DSX-compliant datacenter on a Cloverleaf-supplied site and be serving customers without delay. For Cloverleaf, Nvidia’s spec includes a wealth of power-related capabilities, including DSX Flex, which allows datacenters to scale back their workloads in response to grid conditions. So if grid demand spikes during a heat wave because everyone’s AC just kicked on, datacenters know it’s probably not a good idea to kick off another training run. The tech can also be used to offload demand onto onsite power generation or storage systems, like batteries — all things a company tasked with supplying powered sites for datacenters might be interested in. The deal is the latest example of how Nvidia is using its war chest to shore up cracks in the broader AI ecosystem before they become a problem. We wrote a few weeks ago about how the company was helping AI infrastructure startups secure financing in exchange for a share of the revenues, but it's now clear Nvidia is attacking potential roadblocks from every angle. ®

Salesforce partners not seeing meaningful revenue from Agentforce AI platform, report says

Fri, 08/21/2026 - 13:50
Salesforce partners say they have yet to see any meaningful revenue from Agentforce, two years after the CRM giant launched its AI platform, promising spectacular growth. That's according to a recent report from TD Cowen, which surveyed Salesforce partners and found muted interest in the technology, designed to let users build AI agents for customer interactions. The survey of partners in the US, Europe, and Asia found growing customer interest in Agentforce, but no revenue yet. Asked about interest in Agentforce AI Agents, 11 percent of respondents said they had not seen much immediate interest, while 56 percent said they expected to see interest but needed time for initiatives to mature. A third of partners said there was strong interest in Agentforce as they were starting to see buying and trial activity. However, none were seeing Agentforce become a driver of bookings activity. The report also noted weaker commercial growth among partners across Salesforce's portfolio. A third were meeting or beating targets as opposed to 43 percent in the previous quarter. “Agentforce adoption [is] still subdued," the report said. Salesforce did not immediately return a request for comment. In its most recent results for Q1 FY2027, ended April 30, the CRM vendor said its current remaining performance obligation – a measure of future contract values – had grown 14 percent year over year to $33.6 billion, “propelled by Agentforce, Data 360, and Slack, partially offset by softness in commerce and Tableau.” “We are seeing incredible demand for Agentforce with annual recurring revenue now greater than $1 billion,” CEO Marc Benioff told analysts. Salesforce has backed Agentforce to help it beat the so-called SaaSapocalypse — where AI agents perform common enterprise tasks and obviate the need for software upgrades. It says Agentforce will help customers build, test, deploy, manage, and orchestrate AI agents in the enterprise. The TD Cowen report is not the only dark cloud over the strategy. Last month, a report from KeyBanc Capital Markets cited its CIO survey, which found customers did not view the CRM plan favorably. "Our checks and customer conversations have not been strong, nor has the feedback been on Agentforce. What we can piece together in the disclosed numbers does not signal building momentum and, most recently, our CIO survey delivered another blow with Salesforce being a standout for the wrong reasons," the report said. KeyBanc found that partners and customers thought enterprise data was not coherent enough to do meaningful AI work and that Agentforce, “as a product, just isn't there." ®

AI companies are burning books, advocates complain to FTC

Fri, 08/21/2026 - 13:23
AI companies are buying loads of physical books, hoovering up the texts for model training, and then physically destroying the originals. A group of 18 advocacy organizations on Friday asked the US Federal Trade Commission to investigate the book butchering and knowledge hoarding. Fresh details of the practice emerged earlier this year via document disclosures in Bartz v. Anthropic PBC, a copyright case brought by authors of books that the AI company used for training without permission. Anthropic's book scan-and-destroy operation was known as "Project Panama." It was described in a 2024 internal memo as "our effort to destructively scan all the books in the world." Anthropic gave the operation a codename "because we don’t want it to be known that we are working on this," the court exhibit explains. "This document is visible to all Anthropic employees, but you should avoid talking about it in public areas, and the fact that we are working on this should not be shared with anyone outside Anthropic." Older books turn out to be valuable for AI training because they're unpolluted by AI-generated text, which has been seeping into recent written work. And destroying books once they've been scanned avoids the cost of storage. In some circumstances, scan-and-destroy operations may support fair use claims. In the Bartz case, the district court accepted the argument that a physical book can be digitized and destroyed, substituting the electronic copy for the physical book in a transformative act of fair use. But that didn't work out for the Internet Archive. Anthropic, which did not respond to a request for comment, is not the only company consuming and trashing texts. A recent report found Amazon has been participating in book scanning and shredding. Amazon also did not respond to a request for comment. The subject has become a public relations headache, in part because of the barbarism of book destruction and its association with authoritarian regimes, and in part because of the broad backlash against AI companies for pillaging public resources in pursuit of private gain. Intermediaries appear to be feeling the heat. ISBNdb, which reportedly helped broker the acquisition of books for destructive scanning, recently disavowed the practice. The biz noted last month, "We've removed a recent landing page, 'Printed Books Sourcing for Your AI LLMs Dataset Needs.' It was part of exploring demand, and we've chosen to pivot away from that direction." In light of these revelations, civil society groups want the FTC to look into book buy-and-destroy operations on the basis that they prevent competing AI developers and the public from accessing those resources. "The secretive and reckless way that major AI companies like Anthropic and Amazon are acting shows that there is real smoke here that the FTC needs to investigate," Kate Oh, special advisor to the Demand Progress Education Fund, said in a statement provided to The Register. The groups' letter [PDF] casts scan-and-destroy operations primarily as anticompetitive – the FTC being notionally a competition watchdog – but it hints at the anti-democratic consequences of monopolized knowledge. "Through their practice of permanently destroying books en masse and thus removing those non-renewable resources from broader access, AI companies are engineering a future where only the wealthiest incumbents can build high-quality AI models and operate as the sole holders of humanity's written works – after having destroyed the originals to get there," the letter says. We're unaware of whether any texts have been shifted entirely into AI models without leaving any physical copies. But then how would anyone verify that when AI companies refuse to divulge their training data? The letter asks the FTC to answer that question: "What the public record does not establish – and cannot, from the outside – is how often the destroyed physical books are the last or among the last surviving copies of a given work." ®

Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it

Fri, 08/21/2026 - 09:29
CISA has ordered US federal agencies to patch two exploited flaws in TrueConf, a Russian-built video conferencing platform, after compromised servers were caught handing malware to unsuspecting meeting participants. The US cybersecurity agency on Thursday added CVE-2026-72529 and CVE-2026-72530 to its Known Exploited Vulnerabilities catalog, saying both have been used in real-world attacks. What CISA doesn't say is who is being attacked, or where. The only publicly documented attacks exploiting these two bugs so far come from Kaspersky, which linked them to Head Mare, a pro-Ukrainian hacktivist group that has repeatedly gone after Russian organizations. Its latest campaign targeted Russian companies across industries including transport, energy, electronics, IT, and software development. CISA doesn't say whether it added the flaws to KEV because of those attacks or because it has evidence of exploitation elsewhere, potentially including against organizations in the US. That question is particularly interesting given what TrueConf is and who uses it. TrueConf is a Moscow-based maker of video conferencing software that offers an on-premises alternative to cloud services such as Zoom and Microsoft Teams. Organizations can run TrueConf Server on their own infrastructure, including in private networks, giving them control over where their calls and associated data go. While the company's roots and much of its customer base are Russian, TrueConf has users worldwide. It says it has users in its portfolio that include Switzerland’s Department of Justice and Home Affairs, Istanbul Airport, and a news org, which The Reg has contacted to confirm. Most of the customer success stories are dated before 2022. Used together, the two bugs flagged by CISA can give an attacker control of the underlying server. According to Kaspersky, an unauthenticated attacker with network access to TCP port 4307, which TrueConf documentation says is open by default, can exploit the first flaw to run a malicious script. The second flaw lets the attacker break out of the isolated environment where the script runs and execute arbitrary code on the underlying server. Kaspersky says Head Mare used that access to plant a web shell, move through victims' infrastructure, and gain privileged access to the TrueConf database. From there, the attackers replaced the legitimate TrueConf Windows client installer on compromised servers with a trojanized version carrying the PhantomCore backdoor. Kaspersky warns that this creates a risk beyond organizations actually running vulnerable TrueConf servers. Employees joining conferences hosted by suppliers or other third parties could potentially download a compromised client from someone else's hacked infrastructure. The researcher says the flaws affect TrueConf Server releases going back to 2022. TrueConf shipped fixes in versions 5.3.9, 5.4.9 and 5.5.5 on June 18, warning customers that skipping the update could leave their conferencing systems exposed to attacks over the public internet. That doesn't mean every TrueConf box is sitting on the internet waiting to be popped. Exploitation requires network access to the vulnerable service, so a server confined to an internal network would not be directly reachable from outside unless an attacker had another route in. Federal agencies have until September 10 to patch the flaws. Other TrueConf admins can take their time, as long as they're comfortable with a conferencing server potentially moonlighting as a malware distribution point. ®

Musk fumbles the timetable for first Starship catch

Fri, 08/21/2026 - 09:14
CEO Elon Musk says SpaceX probably won't attempt to catch a returning Starship for several months, walking back his earlier suggestion that it could happen on the next test flight. In a post on his social media platform, X, Musk said: "We will probably catch the ship with the tower in a few months." He added that if a tower had been waiting at sea where Starship splashed down last month, "it would have been caught." During SpaceX's first earnings call as a public company, Musk was more bullish, saying: "We could possibly catch the ship as soon as the next flight." A few weeks later, that attempt appears to be off the table. In his post, Musk also predicted that the "first reflight of the ship will be either end of this year or early next" – a timeline that, given his record for hitting Starship targets, should perhaps be written in pencil. Musk's post coincided with a SpaceX static-fire test of a single Raptor engine on Starship. The test simulated the deorbit burn required for upcoming orbital missions. Starship's previous test flight went relatively well. The Super Heavy booster made a hard splashdown in the Gulf of Mexico, while the upper stage settled into the Indian Ocean more gently and survived intact. This was not anticipated, and the vehicle ended up having to be towed into port – something Starship wasn't designed for. Starship is expected to reach operational orbit on its next test flight and deploy a batch of Starlink V3 satellites if all goes to plan, according to Musk's comments during the earnings call. Reaching orbit consistently is also critical to SpaceX's work for NASA. Artemis III, scheduled for 2027, is intended to test rendezvous and docking between Orion and one or more commercial lunar lander test articles in low Earth orbit. NASA plans to use the results to prepare for the Artemis IV crewed lunar landing in 2028. Catching Starship is not required for the Artemis III demonstration, but a faster launch cadence will become increasingly important as SpaceX prepares for later missions, including the multiple launches needed to fuel a lunar lander in orbit. As Musk's latest post demonstrates, however, Starship milestones have a habit of slipping. Full reuse is also central to the economics SpaceX has pitched to investors since its IPO. Catching the upper stage, rather than fishing it out of an ocean, is a substantial part of that promise. ®

SickKids children’s hospital bandages up careers website after intruder breaks in

Fri, 08/21/2026 - 08:45
Toronto’s Hospital for Sick Children, commonly referred to as SickKids, says the data of current and former staff, as well as job applicants, was exposed after an intruder exploited a security flaw in a third-party software application used by the hospital. SickKids, which may ring a bell for those who have kept close tabs on ransomware news in recent years, said the intrusion affected its external careers site, which has now been restored. “Clinical systems and patient information were not affected, and patient care has continued as usual,” it said, after explaining that the break-in was a result of a vulnerability in a “third-party software application used by SickKids and other organizations." Current and former employees of SickKids, the SickKids Foundation, and the hospital’s Vaughan, Ontario-based Boomerang clinic may all be affected, as were SickKids job applicants. The hospital did not comment on the scale of the breach, but said those affected will be offered the usual identity and credit monitoring services. “Our review of the impacted information is ongoing. Individuals determined to have been impacted will be notified directly, though, out of an abundance of caution, all potentially impacted individuals have been alerted and offered 24 months of complimentary credit monitoring and identity protection services. “Safeguarding the privacy and security of personal information is a responsibility SickKids takes seriously. We remain committed to maintaining strong protections and continuously enhancing our cybersecurity measures to help protect the information entrusted to us.” SickKids’ lucky ransomware escape The children’s hospital is no stranger to cyber struggles. On December 18, 2022, it was targeted by a LockBit ransomware affiliate – a particularly egregious attack even for LockBit and one that attracted an overwhelmingly negative reaction. The ransomware operator issued an ultra-rare apology on December 31, 2022, announcing that it would offer SickKids a free decryptor and that the affiliate who carried it out was expelled from the program. Banished from the darkest corner of cybercrime… now that’s a feat. By that time, however, SickKids had been handling the recovery well, and had restored around 60 percent of its systems after refusing to pay the crooks a ransom. LockBit’s gesture of goodwill later turned out to be an anomaly, however, as exactly a year later it refused to roll back the attack on Saint Anthony Hospital, a children’s healthcare facility in Chicago. ®

Hackers poison popular Rust crates to steal developers' credentials

Fri, 08/21/2026 - 07:57
Hackers slipped malware into several popular Rust packages this week, turning routine software builds into a route onto developers' machines. The Rust Security Response Team disclosed the supply chain attack on Thursday after receiving a tip about a crate called proc-macro1. An investigation found that its build script fetched malware from a remote server. The attack extended beyond a single dodgy crate. Someone had published a new version of arrayref, a legitimate and widely used Rust package, with proc-macro1 added as a dependency. The attacker had also yanked recent legitimate releases of arrayref, helping steer users toward the poisoned release. The Rust team does not believe arrayref's maintainer was responsible. It suspects the developer's computer or credentials were compromised and locked the account while attempting to contact them. The attacker also published malicious versions of two other crates maintained by the same developer, internment and append-only-vec. The poisoned releases weren't around for long. Arrayref 0.3.10 was available on crates.io for 86 minutes, internment 0.8.7 for 90 minutes, and append-only-vec 0.1.9 for 107 minutes before they were removed. That's a narrow window, but arrayref is hardly some forgotten package gathering dust in the registry. Security firm Aikido, which separately analyzed the attack, puts arrayref at roughly 245 million lifetime downloads and append-only-vec at more than 4 million. However, those figures don't tell us how many developers pulled the malicious versions during the brief period they were live. Aikido found that the attacker largely left the legitimate source code untouched, adding only a dependency on proc-macro1, a typosquat of the legitimate proc-macro2 package. The malicious code was tucked inside proc-macro1's build.rs file. Cargo, Rust's package manager, runs build scripts during compilation. This allowed proc-macro1 to identify the operating system and processor architecture of the developer or build machine, download a matching payload, and execute it. Aikido found malware built for Linux, Windows, Intel Macs, and Apple Silicon Macs. The second-stage payload was more than a simple downloader. Aikido found code targeting Chromium-based browser data, including profiles for Google Chrome, Brave, and Microsoft Edge, as well as browser extension storage used by cryptocurrency wallets. It also found functionality to establish persistence and receive commands from the attacker's server. The Rust team also deleted proc-macro-en, aovine, arone, aronenao, and tinymember, warning that every version of those crates should be considered malicious. Developers have been urged to check their Cargo lockfiles and local registry caches for the affected packages. Rust credits Nextron Systems' research team with initially discovering and reporting the attack. It has not said how the legitimate maintainer was compromised, how many developers downloaded the poisoned releases, or how many systems ultimately executed the payload. The malicious packages may have lasted less than two hours on crates.io, but whoever was behind them chose a well-traveled route into developers' machines. ®

AMD grabs more CPU share while pricier PCs punish desktop demand

Fri, 08/21/2026 - 07:05
The processor market is sending mixed signals, with server and mobile shipments rising while desktop CPU volumes decline amid higher system prices. Meanwhile, AMD's House of Zen has taken market share from Intel across every category. For Q2 2026, Mercury Research says total processor shipments were lower than in the same period a year ago, attributing this to much lower system-on-chip (SoC) and embedded volumes due to AMD's declining games console business, plus a large drop in desktop CPU volumes. Mercury associates the decline in desktop chips with weaker demand for high-end gaming PCs. Although the second quarter is not typically strong for consumer sales, it adds: "We believe that higher PC prices and limited GPU supplies are having a significant impact on end demand for desktop PCs, and thus desktop CPUs, as well." Those higher PC prices are the result of increases in the cost of memory components due to a shortage caused by chipmakers prioritizing output of more profitable high-bandwidth memory chips used in AI servers, as The Register has been covering for some time. A shortfall in the availability of consumer GPUs appears to have much the same cause. According to Mercury, desktop CPU shipments fell by more than 20 percent year on year, although AMD's decline was smaller than Intel's. As a result, AMD gained market share, taking nearly 35 percent of desktop chips compared with about 32 percent a year ago. In contrast, shipments of mobile processors for laptops and tablets were up strongly on the previous quarter, running counter to Mercury's earlier expectations, although there was only a modest increase compared with a year ago. The growth followed a sharp increase in Intel's output, particularly of mobile chips, after two heavily supply-constrained quarters. Intel added millions of units of mobile CPU capacity during Q2, significantly narrowing the gap between supply and demand. However, AMD's share of this mobile segment is now up to nearly 29 percent, a significant increase from the 20.6 percent it stood at in the same quarter a year ago. Server processor shipments also rose, increasing 20 percent year on year and more modestly from Q1. According to Mercury, demand was higher for both datacenter-class CPUs (Xeon SP and AMD Epyc) and chips aimed at networking and storage applications. Once again, AMD gained market share, accounting for 34.5 percent of server processors compared with 27.3 percent a year ago. Mercury adds that if the calculation included only Intel Xeon SP and AMD EPYC chips, AMD's share would reach 46.4 percent. The research firm also keeps an eye on the Arm-based CPU market for PCs and servers, with the usual caveat that its estimates have significant uncertainty as there is no centralized reporting of Arm server or client CPU revenues. It recorded significant growth in Apple's Mac products, including the new lower-cost Neo line, while Arm-based Chromebooks also posted strong gains. Mercury estimates that Arm-based systems captured 15.3 percent of the client market in Q2 2026, up 0.9 percentage points to a record high. In servers, it estimates that Arm's share reached a record 13.6 percent, up 0.5 percentage points. ®

'We let you down': GitHub pledges to scale up before developers give up

Fri, 08/21/2026 - 06:15
GitHub's handwringing continued this week as CTO Vladimir Fedorov offered more detail about the August 17 outage – while carefully avoiding the word "sorry." The outage lasted 7 hours and 47 minutes and disrupted developers worldwide. Actions, pull requests, issues, Copilot, and APIs were among the services affected as the platform failed to scale with demand. "If you were trying to ship software that day, we let you down," wrote Fedorov. The incident followed another outage involving Actions on August 6. The platform has been wobbly for some time, something it acknowledged in April, but work to address the underlying issues has not kept pace with the relentless rise in traffic. In April, monthly commits were at 1.4 billion. GitHub says it now handles 2.9 billion commits, 24 million new repositories, and 130 million merged pull requests each month. Microsoft Azure currently handles approximately 58 percent of GitHub's platform load and half of all Git operations. According to Fedorov, GitHub has accelerated the migration of more workloads to its parent company's cloud. "Our next milestone is an architecture that scales read capacity linearly with the number of readers, enabling unlimited read operations," he stated. "We will roll it out gradually, beginning with the largest monorepos." Before that architecture arrives, GitHub must address the scaling weaknesses exposed by retry storms and misconfigured limits. Fedorov stressed that "neither outage was caused by a code or configuration change" – in other words, the failure modes were already lurking in the platform rather than introduced by a fresh deployment. The company is also working to isolate critical systems to reduce the blast radius of future failures, tighten retry limits, and add alerts for early signs of traffic spikes. GitHub's repeated outages have rattled at least some developers. Responses on social media mixed sympathy for the challenge of operating at such scale with frustration from paying customers who say the service is falling short. Fedorov concluded: "The developer community depends on GitHub to build, ship, and operate their work. That is only possible if you can rely on us, and on August 17, you couldn't. It is our responsibility to fix that. We'll earn your trust through the scaling and reliability of the platform." ®

$10K phishing kit claims it can plant rogue passkeys for persistent access to pwned accounts

Fri, 08/21/2026 - 05:18
A phishing kit for sale on Russian-language cybercrime forums claims it can enroll attacker-controlled passkeys on compromised accounts, providing persistent access after passwords are changed. Advertised at around $10,000 for the base package, with additional modules sold separately, iAuthFlow v2 aims to solve a common problem for attackers: being locked out after the victim detects the compromise. Defenders would ordinarily revoke session tokens and rotate credentials. Those measures remain necessary, but may not be sufficient if the attacker has enrolled a passkey on the compromised account. According to Abnormal Security, which examined the kit's documentation and demonstration videos, the technique uses a browser-in-the-middle (BitM) model involving two separate browser environments. In a BitM attack, the victim appears to complete the login on their own device, while the attacker's infrastructure relays the interaction through a separate browser session. The victim sees a phishing page impersonating the targeted service. The iAuthFlow v2 demos focused on Google, but the seller advertises packages for iCloud, LinkedIn, and Microsoft too. The victim enters their account details into the phishing page, while iAuthFlow v2 operates a separate browser on the attacker's server. It sends the victim's input to Google and relays Google's prompts back to the victim. The process repeats until the authentication flow is complete. Once authentication is complete, iAuthFlow v2 controls an authenticated browser session and uses it to enroll an attacker-controlled passkey, Abnormal says. That credential can remain valid after the victim changes their password. Rather than sending the victim to their Gmail inbox after authentication, iAuthFlow v2 displays a brief loading screen reading: "Verification, Processing." Meanwhile, the toolkit works behind the scenes to register a passkey to an attacker-controlled device. "During that pause, the seller's demonstration shows the passkey module opening the target's Google passkey settings through the authenticated browser and requesting a new credential," Abnormal said. "Google may require further identity verification before allowing the change. In the recorded run, the toolkit log indicates that the passkey was created six seconds after authentication." It is unclear where the private key associated with the attacker's passkey is stored. Abnormal hypothesized that the kit may use a Chromium-based virtual authenticator capable of completing WebAuthn registration without storing the private key on the victim's device. However, because the researchers did not buy and test the kit, they could not confirm its storage mechanism – or independently verify the seller's broader claims. Whatever the storage mechanism, organizations should look for newly registered passkeys when investigating an account compromise. Responders should also hunt for other post-compromise changes, including rogue passkeys, OAuth grants, recovery methods, Gmail filters, and forwarding rules. "Response and recovery cannot end with a password reset or session revocation," said Abnormal. "Organizations must also examine what changed after authentication – especially newly enrolled credentials, recovery methods, OAuth grants, and mailbox settings – and remove anything the attacker left behind. "As toolkits like iAuthFlow v2 expand their post-authentication capabilities, effective response increasingly depends on treating account restoration as a comprehensive investigation, not a simple reset." Passkeys are routinely heralded as the future of account security. Designed to resist phishing, they can replace passwords and more vulnerable forms of MFA. Registering a passkey does not make an account bulletproof. Attackers can instead target fallback login methods, active sessions, account recovery processes, and other weaknesses surrounding the credential. Stealing session cookies, often through infostealer malware, can grant access to an authenticated session without triggering a passkey prompt. Another route is device code phishing, although it depends on the organization permitting the underlying OAuth device flow – something generally discouraged unless operationally necessary. ®

Microsoft lets you swap New Outlook's looks with the face of Outlook Classic

Fri, 08/21/2026 - 04:15
Microsoft is rolling out a setting that makes Outlook on the Web and New Outlook for Windows look and feel like Classic Outlook through a theme that tweaks the visual style and layout. "This update is designed to help users who are transitioning from classic Outlook by providing a more familiar experience while maintaining the capabilities of the new Outlook," Microsoft said. Importantly, it won't add back the bits from Classic Outlook that are currently missing from New Outlook. For example, the offline capabilities of New Outlook are still a poor relation to its predecessor. It has been possible to import calendars and contacts from .pst (Outlook Data Files) files for a few months now, but full support remains in the future. The app framework (COM add-ins and so on) that many enterprises use to glue Outlook into their workflows will never appear in New Outlook, but at least the fonts and layout are optionally available. A targeted release of the toggle, which can be accessed in the appearance settings, is expected to be complete by the end of September. A worldwide rollout to general availability is planned to happen between late September and the end of October. The change is Microsoft's latest attempt to nudge users off Classic Outlook, which is set to be phased out in the coming years. Users will have to migrate to the new platform at some point, although the process won't be quick. At present, New Outlook is in the opt-in stage, where users can opt to try it out before switching back. Earlier this year, Microsoft pushed the opt-out phase, where users must choose to opt out of New Outlook to 2027. Eventually, there will be a cutover stage when users won't be able to switch back to Classic Outlook. Microsoft has, however, promised at least 12 months' notice for administrators to prepare. It also stated that support for Classic Outlook through perpetual and subscription licensing would continue "until at least 2029." In the meantime, it will be possible to make New Outlook and Outlook on the Web look a bit like the doomed Classic Outlook. "When enabled, the setting applies coordinated changes across the Outlook experience, including visual styling, layout, typography, icons, and selected interactions," Microsoft said. There's a popular saying about putting lipstick on a pig, but we're sure that doesn't apply here. ®

Microsoft sounds alarm as perfect-10 Entra ID flaw comes under attack

Fri, 08/21/2026 - 03:15
Microsoft has fixed a maximum-severity vulnerability in Entra ID that attackers were already exploiting in the wild. Tracked as CVE-2026-69836, the vulnerability carries the maximum CVSS score of 10.0 and could allow an unauthenticated attacker to execute code remotely in Microsoft's cloud identity service. Microsoft disclosed the flaw on Thursday, along with the unwelcome news that exploitation had already been detected. Entra ID, formerly known as Azure Active Directory, sits at the heart of identity and access management for Microsoft customers, handling authentication and access to cloud applications and other corporate resources. According to Microsoft, the vulnerability stems from unsafe deserialization, in which software reconstructs data supplied from an untrusted source without adequately validating it. An attacker could exploit the weakness over a network without an account and – crucially – without persuading a user to click, open, or otherwise do anything helpful. "Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network," Microsoft's advisory says. That is about as much as Redmond has said about the observed exploitation. The software giant hasn't disclosed who is exploiting CVE-2026-69836, when the attacks began, how widespread they are, or what attackers have done after successfully exploiting the flaw. There are also no public technical details explaining the attack chain, and Microsoft didn't immediately respond to The Register's questions. There is, however, one welcome piece of news for administrators: no customer-deployed patch is required. "This vulnerability has already been fully mitigated by Microsoft," the company said. "There is no action for users of this service to take." Because Entra ID is a Microsoft-operated cloud service, Redmond could fix the vulnerable infrastructure itself rather than ship an update for customers to install. The CVSS metrics explain the perfect 10: the flaw is remotely exploitable, has low attack complexity, requires neither privileges nor user interaction, and could have a high impact on confidentiality, integrity, and availability. Microsoft credited principal security engineer Robert Fitzpatrick with discovering and reporting the vulnerability, although the advisory does not explain how the company detected its exploitation in the wild. Microsoft may have closed the hole, but customers will still want to know who exploited it, what they reached, and how long the activity continued before Redmond shut it down. ®

Wi-Fi 7's WPA3 protections come with a compatibility catch

Fri, 08/21/2026 - 02:14
Broadband industry research body CableLabs is warning that attempts to make Wi-Fi 7 access points accommodate older devices can create compatibility problems of their own, and wants hardware makers to prioritize support for the industry's workaround. Wi-Fi 7 products have been finding their way into buyers' hands for a couple of years now, with the Wi-Fi Alliance kicking off its certification program for the latest iteration of the wireless network tech at the start of 2024. CableLabs is concerned about how Wi-Fi 7 hardware implements WPA3, the latest version of the Wi-Fi Protected Access security standard. The Wi-Fi Alliance made WPA3 mandatory on the 6 GHz band used by Wi-Fi 6E and Wi-Fi 7. WPA3 itself is not new, having been supported by Wi-Fi 6, while access points operating on the older frequency bands could use a transition mode to accommodate WPA2 devices. According to CableLabs, more than 23 billion Wi-Fi devices are in use worldwide, many of them based on Wi-Fi 5 or even Wi-Fi 4 hardware. This is especially true in domestic environments, where networks often comprise an eclectic mix of client devices, meaning that compatibility issues can arise despite industry efforts to maintain seamless interoperability. WPA3-Personal Transition Mode allows an access point to offer WPA2 and WPA3 authentication on the same network, supporting both legacy and newer clients. Alas, some legacy clients are not as forward-compatible as intended. They are supposed to ignore any security options they don't recognize when setting up a connection, but some may misinterpret this information, leading them to fail to connect to the access point. A consumer may therefore upgrade to a Wi-Fi 7 router or access point only to find that some older devices can no longer connect, "causing confusion and increased customer service calls for operators," CableLabs notes. There is a technical answer, and CableLabs wants chipset vendors and makers of Wi-Fi 7 access points and clients to prioritize support for it. The Wi-Fi Alliance devised WPA3-Personal Compatibility Mode (PCM), which moves the WPA3 and Wi-Fi 7-specific security information into Robust Security Network Override (RSNO) elements. The access point can then advertise WPA2-Personal through the legacy RSN element, while clients that understand the new RSNO element can negotiate the stronger security required for Wi-Fi 7. But nothing is ever that simple. Doing this introduces a new requirement that client devices must support the RSNO elements mechanism in order to operate in Wi-Fi 7 mode with a Wi-Fi 7 access point. With WPA3-PCM enabled, clients that do not support RSNO will be limited to Wi-Fi 6 operation using WPA2-Personal, even if their hardware might otherwise support Wi-Fi 7. Because RSNO support is still relatively new, many devices lack it. CableLabs therefore wants hardware makers to treat the capability as a priority. CableLabs also wants makers of low-cost and smart home devices, many of which rely on older chipsets, to test their products against the latest Wi-Fi access points. Good luck with that. The Register asked CableLabs why the WPA3 problem hadn't been encountered before, when WiFi 6 and 6E supported it. It responded: "WPA3 itself is not new - it has been part of the Wi-Fi ecosystem for several years. Prior to Wi-Fi 7, whenever some legacy devices had problems connecting to a network with WPA3 enabled, the alternate configuration was to use WPA2 only and that allowed all devices across the different Wi-Fi generations to connect. "Today, Wi-Fi 7 requires WPA3 and its deployment in residential networks continues to grow. The alternate configuration that was used is no longer feasible so another solution has been developed. This new solution is the WPA3 Personal Compatibility Mode that uses the RSN Override mechanism mentioned in the blog." CableLabs works with cable operators and the industry ecosystem to test interoperability across the diverse mix of devices deployed in real home networks, which gives us early visibility into compatibility issues like this one before they reach consumers at scale. All this fuss concerns Wi-Fi 7, which now accounts for about 7.2 percent of the US market, according to some estimates. But hold onto your hats, as Wi-Fi 8 is just around the corner as well, with vendors such as Broadcom setting out their silicon stall already. ®

Debian is 33, Haiku is 25, and neither is standing still

Fri, 08/21/2026 - 01:26
This is a quiet time of year in tech circles – perhaps explaining why, 25 and 33 years ago, the people behind two ambitious operating system projects kicked them off. Debian Last weekend, the Debian project turned 33 years old. The Linux kernel first appeared in September 1991, so it was not quite two years old when Ian Murdock announced the new distribution. (Indeed, the term "distribution" itself hadn't really caught on yet – his announcement only uses the word as an adjective.) Sadly, Murdock died in 2015, before his project became one of the world's most widely used forms of Linux in the world. We examined the project's history and success when it turned 30, and it continues to thrive. It's not the oldest maintained distro: that distinction goes to Slackware, which is about a month older – it turned 30 that July. Slackware remains actively maintained, although it has not produced a new release in a while. The Register's own Slackware enthusiast Richard Speed looked at version 15.0 back in 2022. Since then, we have had Debian 12 in June 2023 and Debian 13 a year ago. And in case you're curious, as far as this vulture can see, the first release The Reg covered was Debian 2.1 in 1999. Haiku beta beckons Meanwhile, the Haiku OS project keeps on going. The Desktop on Fire blog celebrated with an article on 25 Years of Haiku. Its development was prompted by Palm buying Be in August 2001, as The Register covered at the time. A couple of days later, an email modestly titled "OK, let's start" set the OpenBeOS project in motion, as this history of project milestones describes. Doubters might note that after a quarter of a century of work, there's still been no Haiku OS 1.0 release. Fair, but this is not a Linux distro – it is an entirely new OS built from the ground up. Although it now boasts impressive Unix compatibility, it remains quite different: for a start, it is written in C++ rather than C, and its 32-bit x86 version is also BeOS binary compatible. That matters less today, however, because Haiku has developed a substantial software catalog of its own. The latest activity report from Haiku's dedicated paid developer "Waddlesplash" discusses the possibility of a new version any time now: "Are we beta6 yet? We have a definite release timeline now: a branch should be made by the end of this week, with a target release date of mid-August. Keep an eye on the forums for details to come about how you can help test!" Never mind the version number: the project continues to make impressive technical progress. A PowerPC port has been in the works for more than five years, and in July YouTuber ActionRetro demonstrated an AI-assisted build running on the architecture. This joins a preliminary Arm64 port that was demonstrated back in May. Not Haiku, but adjacent Several Haiku-adjacent projects are also making progress. The cross-platform BeOS-derived programming toolkit Cosmoe, which we covered in June 2025, is still in active development. Its source code is available on GitLab, and it now builds and runs on Linux, Windows, and macOS. Another project with overlapping goals, although no apparent direct relationship to Cosmoe, is VitruvianOS. V, as the team calls it for short, is a port of the Haiku display server and desktop to run on a Linux kernel. Porting the BeOS desktop onto a Linux kernel has been tried before – the first such effort we saw was called BlueEyed OS, back in 2003. V seems to be unconnected with either BlueEyedOS or Cosmoe, but it's making impressive progress all the same. The Reg FOSS desk first heard about V when the project announced version 0.3.0 back in March. At the same time, we read an interview with Dario Casalinuovo, its primary developer, but we couldn't get it running. However, V is making headway. Since its public debut, the project has produced another half-dozen releases: it is now up to version 0.6.0, which gets considerably further in our testing – it boots to a very Be-like startup screen, with a language selection dialog and the choice to run a live environment or start installation. Sadly, that's as far as we can go. The idea certainly has potential. Linux has enviable hardware support now, and given the rivalry between X11 and Wayland, we admire how V sidesteps the dispute: it does not attempt to be either. Instead, it replaces both with a new system based on BeOS's clean design from 1995 – when the original XFree86 Linux X11 server was only about three years old. ®

Pages