EE invites mobile users to live life in the 5G Fast Lane – for a price
Mobile operator EE has launched Fast Lane, using 5G network slicing to prioritize subscribers' connections when its network is congested. According to EE, BT Group's mobile network, Fast Lane anticipates congestion and seamlessly moves eligible connections onto a dedicated network slice. EE says this should help Fast Lane users continue streaming or accessing the internet when nearby customers may be waiting. Naturally, EE is offering the feature through its new premium pay-monthly plan, Full Works Plus, which costs £5 ($7) per month more than its existing Full Works plan. It is available to consumers, while eligible small business customers can access it through an EE Full Works business plan. "Powered by our advanced 5G+ network, Fast Lane gives our customers access to a dedicated 5G+ lane at the busiest times," said Claire Gillies, CEO of BT's Consumer Division. "Whether they're live streaming a special moment from a sell-out gig or processing mobile payments and ticketing at a festival, Fast Lane helps keep customers connected even when thousands of people around them are trying to connect at the same time." Network slicing is enabled by 5G Standalone (5G SA), which the UK’s mobile operators have been rolling out as they upgrade their networks. It is akin to network virtualization, allowing operators to create slices optimized for different uses, such as gaming or enhanced mobile broadband (higher data rates). To add to the alphabet soup, EE markets its upgraded 5G SA network as 5G+. BT demonstrated network slicing at its Adastral Park research facility a couple of years ago, as it readied the technology for commercial rollout. However, Vodafone beat EE to market, launching a 5G+ Local Slicing service earlier this year. This is a slightly different proposition, aimed at enterprise customers seeking tailored network performance across a defined site or local area, such as a sports stadium, office campus, or construction site. Using network slicing to offer a "Fast Lane" was the subject of some controversy in the US a couple of years ago, when advocates of net neutrality claimed that such services would violate core net neutrality principles. Shortly afterward, the Federal Communications Commission (FCC) ruled out fast lanes when it restored net neutrality rules – only for those rules to be overturned by a federal appeals court at the start of last year. So far, EE’s launch has shown little sign of igniting the same furious debate in the UK. Telcoms analyst Paolo Pescatore of PP Foresight told The Register that while there are similarities with the US controversy, EE is prioritizing a customer's overall connection rather than favoring particular apps, services, or content providers. "I see this as a logical evolution of premium mobile pricing. Operators have invested years in 5G Standalone and have talked about network slicing, and EE is now turning that technology into a simple consumer benefit that people can understand and potentially pay for," he said. Pescatore acknowledged that some users may view this as paying extra for the level of service they expect as standard, particularly in busy locations – cue reader remarks about being unable to access 5G at all. But if Fast Lane delivers a noticeably better experience, he said, it gives EE a credible way to compete on service quality rather than price or data allowances. "This feels like an important test for the wider industry. If EE can demonstrate that consumers will pay for greater consistency and priority, other operators will follow." Fast Lane requires a compatible 5G+ plan, phone, and SIM, as well as coverage in an enabled area of the UK. ®
Developer given Mission:Impossible - fixing rubbish code that could crash a city - simply chose not to accept it
ON CALL Making it through a working week can feel like a dangerous adventure. That's why The Register offers a little certainty and safety by always using Friday morning to share a new edition of On Call – the reader-contributed column sharing your tales of tech support. This week, meet a reader we'll Regomize as "Socrates," who many years ago was the "fresh-faced manager of a small software department." Socrates' employer had sold some monitoring hardware to a client that made equipment for power stations, but whoever installed the system had neglected to document it properly. Socrates' boss asked him to visit the site and bring the client up to speed. "In those days I considered myself to be a bit of a programming hot-shot, and a visit to a power station sounded really interesting, so off I went," Socrates told On Call. He therefore drove to the plant, presented himself at the security gate, and was eventually led to something called a "turbine overspeed detector." "This power station was seriously big and impressive; massive rotating machines humming away, with barely anyone around," Socrates wrote. "In a dark remote corner, there it was, the equipment I had come here to see: a dusty CP/M computer with various I/O cards, connected to wiring that snaked off into the far distance." But Socrates had no idea what it did. In his email to On Call, Socrates pointed out that at the time of this story, Tom Cruise was yet to appear in a Mission:Impossible movie, and The Matrix was still years from release. But his memory of these events is is somehow entangled with both franchises. "I didn't know much about electricity generation, but I did know that a turbine is a thing with pointy blades, that are pushed around by steam to drive a generator," he wrote. "And these turbines were absolutely enormous, and the thought of them overspeeding was truly scary." "You know the scene in Mission:Impossible where Tom Cruise is on the back of a train, pursued by a helicopter that crashes with its rotor blade just inches from Ethan Hunt’s throat?" he asked. "That image would have been uppermost in my mind; knife-like turbine blades being ejected in all directions, requiring all my Matrix-like skill to dodge them as they headed my direction." He then reasoned that an overspeed event would probably shut down the turbine – before imagining cascading faults blacking out an entire city. Keen to avoid either scenario, Socrates sat down at the keyboard, opened the relevant software, and vowed not to break anything. He got into the code and found it was "horrible." "Despite my tender years, I'd gained some exposure to well-structured programs, and this was truly awful," he told On Call. "There were plenty of random GOTOs, a lot of I/O accesses to random addresses, with arithmetic, ANDing and ORing with arbitrary-looking numbers." And all without a single comment to help Socrates understand what he was seeing. As he pondered what to do, only one sensible course came to mind: "Back away carefully from the keyboard and leave the system as-is." So that's what he did. Socrates now rates the experience as an important life lesson. "Some things are best left alone," he told On Call. Have you bailed out of a tech support job? If so, click here to email us what happened and why. We promise not to give up on your story. ®
Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5.
Cisco has revealed its Secure Workload Software, a micro-segmentation tool formerly known as Tetration that is supposed to stop attackers moving laterally across a network, has four critical flaws plus another high-severity bug. CVE-2026-20315 and CVE-2026-20317 are the two perfect-ten-rated bugs. Both relate to improper access control. Cisco has not offered much detail about either, saying only that 20315 “covers authorization, authentication, privileges, and bypasses” and that 20317 has to do with “missing authentication, authentication bypass, and reliance on untrusted inputs.” The 9.9-rated flaw is CVE-2026-20231, which describes issues related to “Improper neutralization of special elements (covers command, OS, argument injection).” CVE-2026-20318 is the 9.6-er and is an improper input validation problem. Coming in last, at 7.5, is CVE-2026-20319, a problem related to “Improper restriction of operations within the bounds of a memory buffer” including overflows and out-of-bounds writes. Cisco offers Secure Workload Software as a SaaS-y service and for on-prem deployment. The company has fixed the flaws with its SaaS, but users still need to upgrade the Agent and Connector tools needed to use the cloudy software. On-prem users who have deployed version 3.10 or earlier need to get to version 3.10.9.1. Users of version 4.0 or later need to adopt 4.0.4.16 sooner rather than later. Cisco revealed the flaws on Thursday and says it discovered them after “a comprehensive internal security review” that involved “existing testing processes as well as frontier AI models.” Cisco is a known participant in Project Glasswing, which grants access to Anthropic’s too-powerful-for-public-release Mythos bug-finding model. So maybe that’s the frontier model involved in this research. Thankfully, Cisco says it has detected no malicious use of the vulnerabilities. ®
Alibaba Cloud plans to use fewer Western chips, to boost its already huge AI margins
Alibaba has revealed margins from its cloudy AI operation are rising so quickly it will be able to achieve return on investment for new hardware purchases faster than previously planned. Speaking on the company’s earnings call yesterday, CFO Toby Xu said the company runs its servers for five years, and that AI servers produce enough revenue to cover their costs in three years. In the fourth and fifth years of a server’s life, the machines therefore generate free cash flow. CEO Eddie Wu said some servers deliver cash for longer, and said machines acquired in 2018 and 2020 – and packing the Nvidia V100 and A100 accelerators – “are still being used by customers at near full capacity.” Alibaba thinks it can shorten the initial payback period for AI hardware to 2.5 years, because margins for AI services are increasing. One way the company makes that possible is by using more of its own chips. “Self-developed chips are a long-term and important direction for us,” Wu said. “As the production capacity of our self-developed chips continues to increase, the proportion of self-developed chips in our data centers will continue to rise, replacing more commercially purchased chips.” “We know that in this era of scarce computing power, commercial chips already have very high gross margins, so a significant increase in the proportion of self-developed chips will greatly enhance our product competitiveness and our gross profit margin.” Interestingly the company announced that over 650 external customers chose to use cloudy resources running Alibaba’s own chips. By way of comparison, AWS has said over 120,000 customers use its Graviton chips. Wu said Alibaba could possibly achieve a two-year payback period for its servers, but only if it spent less on new infrastructure builds. The potential upside of AI means Alibaba will continue to spend on AI infrastructure, after sending $10 billion out the door in its first quarter – 75 percent higher than its spend for the same quarter last year. The company attributed the increase to “fluctuations in procurement cycles, increase in CPU-compute capacity driven by anticipated growing customer adoption of AI agents, and higher pricing of a broad range of chip components.” Alibaba will keep spending because Wu thinks AI has become Alibaba’s “most certain growth engine.” That’s a fascinating remark because Alibaba started as an e-commerce company, and Beijing sees it as a key vehicle for selling Chinese exports to the world. Yet e-commerce revenues grew just four percent year over year, to $30.34 billion. With its 45 percent growth, Alibaba Cloud’s AI offerings did far better, but its quarterly revenue of $7.14 billion is well behind AWS, Microsoft, and Google. Note, also, that Alibaba counts itself as a customer of its cloud. Execs predicted Alibaba Cloud revenue will reach around $10 billion next quarter. Alibaba Cloud looks unlikely to deliver Beijing an export bonanza more customers outside China. The business unit already has a strong international presence, but several Western governments have either banned public sector agencies from using the Chinese cloud or recommended against its use. Europe’s push for sovereign clouds is also likely to deter many from considering Alibaba Cloud. Whatever happens in the AI market, Wu is confident Alibaba can build infrastructure fast enough to meet demand because it has cut its delivery time for hyperscale AI data centers to 100 days. The CEO described that as “a world-leading pace that will significantly speed up our global compute infrastructure buildup.”
Supermicro fired staff after probe into $2.5 billion GPUs-to-China smuggling operation
Supermicro has fired some staff after conducting an investigation into allegations that its execs participated in a scheme to ship $2.5 billion worth of servers packing Nvidia GPUs to China, in violation of US export controls. In March, the US Department of Justice indicted Supermicro co-founder Yih-Shyan "Wally" Liaw, one of the company’s Taiwan-based execs Ruei-Tsang "Steven" Chang, and a man thought to act as a broker, Ting-Wei "Willy" Sun, with conspiring to violate the Export Controls Reform Act, conspiring to smuggle goods and defrauding the US government. Supermicro promised to investigate and on Thursday delivered its verdict: nobody on its current senior management team “had knowledge of the alleged diversion scheme or of any actual diversion of restricted products by the Company.” “Nor did the investigation find that the Company directly sold export-controlled products to known restricted parties or locations. It also did not find any evidence that the Company’s previously issued financial statements could not be relied upon based on the potential diversion of restricted products,” the company states. But not all is well, as it seems Supermicro did find staff who failed to properly implement US export controls. The company says the three people named in the indictment “no longer have any relationship with Supermicro.” That suggests Liaw and Chang were let go. Supermicro’s statement also revealed the investigation led to sackings elsewhere in the company. “In connection with the investigation, the Company took several personnel actions with respect to employees within its sales, technical support and business development functions, including terminations, for failure to follow Company policies or the Company’s code of conduct,” the announcement states. We’ve asked Supermicro how many staff it dismissed or disciplined, and how they breached company policies and the code of conduct. We will update this story if we receive a substantial response. The company has also revealed that the investigation led to recommendations that “further enhance the Company’s export compliance program.” Supermicro’s board has adopted those recommendations in full, and has already implemented some of them. Supermicro has therefore admitted that its compliance program was not sufficient, and that some of its staff conducted activities deemed worthy of dismissal. That adds to the company’s long list of past governance issues, which includes twice dodging de-listing due to accounting dramas, another unauthorized export probe spanning Singapore and Taiwan, and struggling to cash in on the AI boom. ®
Russian snoops add OAuth abuse to targeted phishing campaigns
Google is tracking three distinct suspected Russian cyber-spy groups that are targeting individuals in academia, aerospace, defense, government agencies, and think tanks across Europe and the US. The UNC (unclassified) groups, as Google calls them, have been orchestrating these highly targeted campaigns since at least last year, and they remain ongoing. Some of the phishing and OAuth-abuse operations used in the attack took place this month. Each campaign had fewer than 100 targets, and under 10 victims, the threat-intel team told The Register. Despite the small numbers, if you work in government, NGOs, academia, or aerospace, you may be a target, and over the past few months the Russian snoops have adapted their attacks to abuse legitimate authentication flows. This makes these types of social engineering tactics appear more legitimate – and allows the cyber operatives to compromise personal accounts across multiple platforms, Google warns. It also means that potential victims may not recognize these as phishing attempts. Google says it wants to raise awareness about these campaigns “so that targets can more readily recognize malicious outreach.” In other words: don’t blindly trust that calendar invite that purports to come from the US State Department. UNC6293 The security analysts have been tracking one of the three, UNC6293, for almost two years. UNC6293 is a suspected APT29 (aka Cozy Bear, which Google now tracks as Ice Relic – insert eyeroll) phishing squad that poses as US State Department employees to lure victims into giving the snoops long-term access to their email correspondence. APT29 is probably best known for the 2020 SolarWinds hack, and infosec analysts from the UK and US governments, and the private sector, often link it to Russia's Foreign Intelligence Service (SVR). On Thursday, Google’s Threat Intelligence Group (GTIG) said it's now tracking two other suspected Russian groups, UNC7005 and UNC5976, which also conduct phishing, abuse OAuth flows, and/or deploy malware to these same types of targeted individuals. Last summer, GTIG documented UNC6293 phishing for app passwords belonging to people who are critical of Russia. In this campaign, they impersonated State Department personnel, and they’ve continued using that lure while also adding OAuth phishing into their toolkit. “In June 2026, GTIG observed OAuth phishing where UNC6293 requested targets share either the full URL or ‘verification code’ after performing a legitimate login to an external provider,” Google threat analysts Gabby Roncone and Wesley Shields said in the Thursday report. “By providing the requested verification code the target would grant UNC6293 access to the account.” UNC7005 GTIG also asserts, with “moderate confidence,” that UNC7005 is another initial access group connected to APT2/Cozy Bear/Ice Relic – and the SVR. This crew, first identified in February, usually targets academia, diplomatic, and nonprofit personnel across Ukraine, Western Europe, and the US. While it shares similarities with UNC6293, Google tracks it separately “due to its lower sophistication and poor operational security, infrastructure with divergent characteristics, and incorporation of malware.” Reliaquest and Microsoft first sounded the alarm on this group - Redmond tracks UNC6293 as Storm-2945 - after spotting a campaign compromising captive portal networks to deliver infostealers, keyloggers, and other malware. The Russian intelligence operatives targeted users of public Wi-Fi networks at places like hotels, conference centers, and other shared venues in the hospitality sector in an AI-assisted operation that began in February. UNC7005 also enjoys device-code phishing for both Microsoft and WhatsApp accounts. Most recently, the phishing lures look like invitations to diplomatic events and conferences delivered via email with links to attacker-controlled websites. The crew also tends to reuse website templates. They did this in May, we’re told, re-using the website template from an operation that used the theme of an "embassy invite." The later campaign spoofed the real GLOBSEC forum - a geopolitical gabfest that focuses on Eastern Europe. Once victims visit the attacker-controlled website, the snoops fingerprint the victim’s system and prompt them to confirm their attendance at a conference. “The registration process is thorough, and notably contains an epicurean wine selection, which was a theme in multiple previous ICE RELIC-linked phishing campaigns,” the Googlers wrote. In May and June, UNC7005 carried out social engineering attacks spoofing WhatsApp and prompting the victim to either join a voice call, encrypted chat, or download a file. Joining the voice call triggers a malicious JavaScript that records audio and video of the target, which the malware uploads to the attacker’s command-and-control server. While Google doesn’t say how the Russians use the stolen images and audio, attackers can use both to help carry out convincing social engineering campaigns. Also in May, the goons conducted “a much broader phishing wave than any we had previously observed,” Roncone and Shields wrote. This one targeted prominent, mostly US-based academics, diplomats, and researchers whose work focused on Russia and former Soviet states. The miscreants’ website was more “elaborately built to social engineer the target,” with specific information about a resolution supporting Ukraine, plus contact details for general questions or tech support. Those contacts were a hotline to the attackers, not a helpdesk. information (that led to the attacker) for questions or tech issues. When users click the button that, they believe, will download a “Summit Companion App” to read the full resolution, they inadvertently put infostealers on their own Mac OS and Windows devices. Since August, the same crew also started both Google and Microsoft account OAuth phishing operations using cloud infrastructure. UNC5976 Finally, UNC5976 is yet another suspected Russian cyberespionage group and again likes to steal OAuth tokens. GTIG began tracking OAuth-related activity from this crew in March 2026. In these campaigns, UNC5976 buys up several domains with names related to file sharing and then creates a cloud project related to the domain. The domains host a fake file sharing page that prompts users to “Continue with Google” via a popup link. The links takes them to a legitimate Google OAuth login page, asks them to sign in, and after authenticating the credentials redirects the victim to a Google Cloud project URL that saves the authentication token for the attacker. GTIG calls UNC5976 “distinct” from the other two initial access groups, and notes that this may indicate “differing strategic mandates and potential alignment with alternative Russian intelligence services.” It also uses dedicated infrastructure for post-compromise activity instead of residential proxies, plus more malware and tooling in its OAuth operations. ®
Google tethers Antigravity to enterprise controls amid AI shakeup
Google Antigravity, which came out of the DeepMind AI research group, has drifted into the orbit of Gemini Enterprise app subscriptions, putting the Chocolate Factory's agentic development platform under the influence of Google Cloud controls. Antigravity is an agentic AI coding assistant that can be accessed through various surfaces, including a desktop app (Antigravity 2.0), a command line interface (Antigravity CLI), a software development kit (Antigravity SDK), and a full-fledged integrated development environment (Antigravity IDE). Following the announcement of Google Antigravity in the Gemini Enterprise Agent Platform back in May, enterprise customers prodded Google to integrate more security, compliance, and governance controls, and to make Antigravity available through familiar development tools, said Scott Densmore, senior director of engineering at Google, and Damith Karunaratne, group project manager, in a blog post. Hence, Antigravity is now available as an extension to other IDEs, specifically Visual Studio Code, Visual Studio, JetBrain, or Zed. According to Densmore and Karunaratne, adding Antigravity to eligible Gemini Enterprise subscriptions should make it easier for administrators to manage tool licenses, invoices, and security settings. Gemini Enterprise's billing and cost management tools provide a way to set project-level budget caps, with user and team controls coming later this year. There's also a token pooling mechanism so individual consumption differences don't leave purchased tokens sitting around unused. Admins also have the option to enable overages and have broader visibility into token usage, API calls, and other developer activity. "Administrators and IT teams can set clear boundaries around workspace access, enable full audit logging, and enforce data privacy from a single console," said Densmore and Karunaratne. They can do so through controls that affect how the Antigravity agent behaves. File access settings can be configured, for example, to deny access to all files outside of the agent's working folders. Agents can be directed to always ask before executing a terminal command, to do so in a sandbox, or to always proceed. Agents can also be granted or denied access to a web browser and limited to specific websites. Admins get access to centralized audit logging and organizations may be reassured by Google Cloud's data privacy commitment and its accompanying Cloud Data Processing Addendum, which runs a mere 15,000 or so words. Further cheerleading may be needed in light of Google's struggles to keep pace with AI rivals, exemplified by the continued absence of Gemini 3.5 Pro, which remains unreleased despite the appearance of Gemini 3.6 Flash and 3.7 Flash. Perhaps not coincidentally, Google chief scientist Jeff Dean and three colleagues departed the company earlier this month and Google's once-independent AI lab, DeepMind, saw its CEO Demis Hassabis shift into the role of chairman, replaced by Koray Kavukcuoglu who will serve as SVP rather than CEO – a signal DeepMind is becoming more tethered to the mothership as Google tries to revitalize its AI research efforts. Google CEO Sundar Pichai's missive on the subject brims with the obligatory upbeat messaging but at least acknowledges that there's work to be done. "We are committed to being at the frontier, and are super focused on the areas where we need to improve," he said. ®
Go updates may delight diehard gophers but displease AI overlords
The keepers of the Go programming language on Wednesday released the latest version, v1.27, and with it come considerable advances in generics. In a nutshell, generics allow developers to write logic where data types are treated as variables, eliminating the need to rewrite (or copy and paste) a separate method for each different data type (int, string, floating point, etc.). It was "absolutely barbaric," noted one YouTube tutorial creator. Go introduced generics for both functions and custom data types in version 1.18, released in 2022. The v1.27 release expands generics to support methods, which are basically just functions that are bound to a data type. These new generics will save a lot of typing, at least if the programmer has some chops. Golang’s standard random number generator, for example, can produce either a 32-bit integer (int32), 64-bit integer (int64) or whatever integer size the CPU expects (int). Prior to v1.27’s generics, the developer would have to write a method separately to support each numerical data type they wanted to use. Beyond generics, v1.27 allows developers to more easily work with structs, which are composites that collect different data types within a single object. Now, they can set values for nested or embedded fields directly without specifying all the intermediate steps to reach them. This will save time when working with deeply nested structs. This release also gets smarter in its ability to infer data types from functions without the developer explicitly typing them out. Previously, Go required explicit type arguments whenever a generic function was passed into a slice literal, channel send, or type conversion. Save a keystroke, break a brain Go continues to evolve into a programming language capable of tackling tasks as sophisticated as building the new TypeScript language server, but some wonder if it’s losing its approachable charm along the way. Generics and these other time-saving features will come as a relief to the busy Gopher who grows weary of how much identical code they’re typing. But these language shortcuts also make the code on the screen more abstract, which has its own mental overhead. When Google engineers Rob Pike, Robert Griesemer, and Ken Thompson created Go, first released in 2009, they prioritized readability over writability. The designers “recognized that developers spend far more time reading existing code than they do typing it out,” wrote Google Group Product Manager Cameron Balahan and Google Cloud Chief Evangelist Richard Seroter in a blog post earlier this month. Generics and other keystroke-saving measures will create more indirection that can confuse someone trying to understand what the code is doing, others have argued. Generics will “make every code base entirely different,” complained the popular YouTube tech commentator (and former Netflix engineer) known as ThePrimeagen (Michael Paulson). “You're going to jump into code bases and have no idea how they work. You're gonna have to go through layers of abstraction and whole new ways in which to express things, which is just gonna be like every other language, just without all the conveniences.” Go’s value is in its simplicity. Adopting higher-level constructs makes it more of a C++ or Rust imitator, he said. “Generics aren’t needed in most of practical Go code,” observed VictoriaMetrics founder Aliaksandr Valialkin in a 2024 Medium post. The downside of these new features is that they make it “harder to understand what’s going on by just reading the code.” Think of the agents And for AI agents, Golang’s easy readability is more than just a personal preference; it’s critical to staying on target. “When code generation is offloaded to AI, the primary bottleneck of software engineering shifts entirely from the speed of writing to the rigor of reviewing, verifying, and maintaining,” the Google execs wrote. The more complicated the language, the more work it’ll take agents to understand. Syntactic magic like generics helps seasoned programmers save coding time, but does it bring any value when agents write all the code? Would learning generics contribute to an agent’s cognitive overhead (possibly leading to context rot) when writing a random number generator method for each data type takes a second or two, and is easier to debug? It’s a question that the maintainers of Go, like those of every other language, will be facing.®
OpenAI chases Anthropic's biz customers with zero data retention pledge
OpenAI appears to have found a way to balance AI model safety with commitments to retain no customer data, a feat rival Anthropic hasn't yet managed. For orgs concerned about who has access to their data, this could be a game-changer. The free-spending AI biz on Wednesday announced Private Safety Processing, a mechanism for automatically scanning customer model interactions for safety risks without violating Zero Data Retention (ZDR) commitments. Anthropic meanwhile has noted that its implementation of ZDR includes a non-zero amount of data retention for covered models – currently Mythos 5 and Fable 5. For commercial customers using ZDR as of June 9, 2026, "we are requiring limited data retention and review as part of our safety work. Prompts submitted to, and outputs generated by, covered models are retained for 30 days to support our safety work, on every platform where these models are offered." OpenAI, Anthropic, and various other AI model makers agree some oversight of rapidly advancing model capabilities is a good idea. The devil is in the details, which in the case of Private Safety Processing have not yet been published. Generally speaking, both companies have similar policies for commercial customers using lower tier models. "For Anthropic API users, we automatically delete inputs and outputs on our backend within 30 days of receipt or generation," Anthropic says, with exceptions for certain services, ZDR agreements, and legal/policy enforcement. For OpenAI ChatGPT Business customers, "Your workspace admins can control how long your data is retained. Any deleted or unsaved conversations are removed from our systems within 30 days, unless longer retention is required by law, or is reasonably necessary to protect our services or any third party from harm." That 30-day policy also applies to OpenAI's API in most cases. When Anthropic detects usage violations, it may retain model inputs and outputs for up to two years and trust and safety classification scores for up to seven years. The major distinction now is ZDR and how the two frontier AI companies define that concept. Anthropic has a ZDR exception for those using its top models. For OpenAI ZDR deployments, customers may control the infrastructure or they may choose to store data on OpenAI infrastructure, where OpenAI says it will soon provide customer-controlled encryption keys. "In both cases, automated systems can identify potential misuse and return limited safety signals without exposing the underlying prompts or responses to OpenAI personnel," the company explains in its post. Anthropic allows more room for human review when content is flagged by its automated systems. "By default, no Anthropic personnel can read your retained conversations," the company says in its documentation. "Human review can occur only through a controlled access path—for example, when content is flagged by our automated trust and safety systems for potential harm." OpenAI's human intervention scenario is narrow – in the event child exploitation material is detected. With the addition of Private Safety Processing – to be explained in more detail next month, OpenAI insists – whatever data gets stored is unavailable to company personnel. "Private Safety Processing builds on the automated protections already used in ZDR and other deployments," the AI biz explains. "Existing ZDR-compatible safety systems evaluate interactions individually. Private Safety Processing extends those protections across related interactions, allowing automated systems to identify patterns without OpenAI personnel having access to retained customer content." What's noteworthy about this beyond the privacy commitment is the company's expanded interest in "related interactions." That suggests OpenAI's safety assessment is looking not just at prompt input and output but tool use and network data signals. Keeping AI interactions and data flows private has become a major concern. Apple has its Private Cloud Compute. Google has its Private AI Compute. Nvidia offers Confidential Computing. Even Meta, not exactly known for its commitment to privacy, talks up its Private Processing for AI. And much of the interest in running local AI models reflects a desire to keep sensitive data safe from potentially prying service providers and adversaries. OpenAI may have read the room well with its celebration of private model policing, but as Matthew Green, associate professor of computer science at Johns Hopkins University, observed recently, "private inference isn't private enough." Green notes that AI agents – models connected to tools – often rely on sensitive data when they act on our behalf, and while private inference may protect some part of the data flowing to and from AI agents, there are many other gaps in the system. "At the risk of saying more obvious things, the difference between a helpful private agent, a corporate advertising bot, and a government spy comes down mainly to a matter of prompting, and maybe a bit of model fine-tuning," he wrote. "Once you combine private data access and the ability to send messages, there is essentially no technical protection that private inference alone can offer." ®
Waymo has designed a robocar chip to stay ahead of Tesla
To reach their destinations safely, autonomous vehicles have just milliseconds to ingest and process streaming data from more than a dozen cameras. It's a job that's been handled with off-the-shelf AI components thus far, but Waymo has begun rolling its own AI ASICs to optimize the process. It's not alone. Revealed in a blog post Thursday, the Alphabet-backed robo-taxi startup's first custom silicon is designed to convert raw sensor data into driver responses as quickly as possible. Built on Taiwanese foundry giant TSMC’s 5 nm process tech, the chip is specifically optimized to run both more traditional machine learning algorithms like convolutional neural networks and modern transformer models similar to those used to run AI chatbots or image generation models. According to Waymo, the chip's design incorporates more than 200 million miles worth of autonomous driving data, and is tuned to maximize responsiveness, reliability, and redundancy. Prior to this, Waymo had employed Intel FPGAs for sensor processing. FPGAs are ideal in low latency applications, which is one of the reasons why high frequency trading often takes place on them. However, compared to dedicated silicon, FPGAs are notoriously difficult to program for and lack the compute density achievable using application specific hardware. Accidents can unfold in a fraction of a second, far too quickly for a remote operator to take over. So Waymo designed the chip with a major focus on minimizing latency. “Within those critical milliseconds, advanced ML models build a high-fidelity understanding of the environment to evaluate the safest path forward,” the company explained. This includes performing temporal noise reduction to improve low light visibility in real time. All of that requires a considerable amount of computation. The robo-taxi startup claims its ASICs are capable of churning out more than 1,000 TOPS of AI performance. But without knowing the precision and power levels the chips are operating at, it’s difficult to draw comparisons to existing autonomous vehicle and robotics platforms. We’ve reached out seeking clarification, and will let you know if we hear back. But considering that Waymo is specifically advertising TOPS, we’re probably looking at INT8 performance, which would put it in the same ballpark as Nvidia’s Drive AGX Thor platform. In addition to offering plenty of compute, the chip also needs to be reliable. Vehicles are exposed to a near-constant stream of vibrations, shock, and extreme temperature swings, unlike anything you’d see in a datacenter. In order to combat this, Waymo has employed multiple layers of redundancy. The chips themselves are liquid cooled by the same coolant system used by the vehicle itself, ensuring that the silicon maintains optimal temps regardless of the weather. Meanwhile, to ensure a hardware fault doesn’t put passengers at risk, Waymo says each vehicle is equipped with a pair of ASICs. Under normal conditions, the chips behave as a single unit. But in the event one fails or produces an erroneous result, the other can take over. Air and space craft often include a third system to serve as a tiebreaker in the event of an upset. So, it’s not surprising to see this level of redundancy employed for a vehicle that’s going to be hurtling down roads filled with other vehicles, pedestrians, and obstacles. To be clear, Waymo's custom ASIC isn’t responsible for all of the vehicle’s functions. The company says that it is working on several other custom chips and systems, but for now, non-ML tasks like orchestration, data movement, and logging are handled by components provided by its partners, which include AMD, Micron, Samsung, Sandisk, and Nvidia. Waymo is far from the only autonomous vehicle vendor rolling its own custom silicon. Tesla, which launched a limited Robotaxi service in Austin after years of missed deadlines, has been developing custom chips for its vehicles for years. Waymo will share more detail on its ML accelerators next week during the annual Hot Chips conference at Stanford. ®
US Bank investigates LockBit's claims as ransomware crims set pay-or-leak deadline
US Bank says that it's investigating ransomware crew LockBit’s claims that it breached the financial institution and stole data, which the crims threaten to leak on September 3 unless the bank pays an extortion demand. “We’re aware of claims regarding a potential cybersecurity incident,” Lee Henderson, US Bank VP of public affairs, said in an emailed statement to The Register. The bank declined to answer specific questions about the claims, including whether it has communicated with the extortionists and how much LockBit demanded. If the extortionists’ claims are true, and even if the bank pays the ransom demand, there’s still no guarantee that the digital thieves will delete the stolen files. When cops took down an earlier iteration of LockBit in 2024, they found evidence that the crooks retained victim data - even after the victims paid the extortion demands. “At this time, there is no indication that our internal systems are impacted and no evidence of unauthorized access to our network,” Henderson continued. “US Bank takes the security and privacy of our clients' and employees' information very seriously. We continue to investigate and closely monitor these claims and remain, as always, vigilant in our efforts to mitigate potential exposure to cyber events.” LockBit added the bank to its leak site late Wednesday night, and gave the bank 14 days to pay a ransom demand or else see its data dumped online. The post doesn’t say how many files the crew allegedly stole, or what they contained. In February 2024, international cops seized servers, domain infrastructure, and decryption keys in an effort to dismantle the notorious ransomware group, and in May 2024, they outed LockBitSupp's true identity - although Dmitry Yuryevich Khoroshev, a Russian national, remains at large. In September 2025, however, LockBit reemerged with its new LockBit 5.0 ransomware variant. LockBit’s latest claims follow previous third-party breaches affecting US Bank customers’ data, and at least one law firm says that it’s considering a class-action lawsuit against US Bank National Association, the primary banking subsidiary of US Bancorp, on behalf of a small group of customers whose credit card information may have been exposed in a third-party security snafu that reached the bank through its vendor, Fidelity National Information Services. US Bank reportedly found out about the third-party incident on May 7, and in June, began notifying 537 customers, all Massachusetts residents, that their names, mailing addresses, and credit card numbers may have been stolen by the digital crooks. Customers’ Social Security numbers, online banking credentials, and account balances reportedly weren’t accessed. A much larger incident affecting around 11,000 customers occurred in 2022, after a different vendor “accidentally shared” a file containing personal information associated with closed US Bank credit card accounts, including names, addresses, Social Security numbers, dates of birth, closed account numbers, and outstanding balances.®
Microsoft gives Task Manager another task: Watching AI workloads
Once upon a time, Windows Task Manager was a stone-cold killer. Optimized to within an inch of its life, it struck fear into errant processes. These days, Microsoft also wants it monitoring AI workloads. Task Manager has come a long way from the application Dave Plummer developed in the 1990s, inspired by what he called a "very Unixy impulse." This week, Microsoft highlighted its latest addition: deeper visibility into AI workloads. "Previously, the Processes tab didn't show per-process activity for the neural processing unit (NPU) or graphics processing unit (GPU) neural engine," Microsoft explained. Now it does, at least on supported newer devices. The Processes tab can show NPU use alongside CPU and GPU activity, while the Performance tab displays overall utilization. It is handy, although Task Manager appears to be spending ever more time monitoring tasks rather than managing them. That said, knowing which processes are using which hardware can help diagnose performance and power consumption problems, particularly on a battery-powered laptop. Microsoft was keen to point out the metrics that can be monitored. "As AI workloads become more common on Windows devices, visibility into NPU and GPU neural engine utilization can help you make better-informed decisions," the company said. "With the latest Task Manager improvements, you can monitor AI processing activity alongside CPU, memory, storage, and networking data from a familiar interface." Whether users want that degree of telemetry in Task Manager is another question. Finding a memory leak or killing a CPU hog fits its traditional remit; extended system analysis might be better left to Performance Monitor. Notepad was once a lightweight application focused on doing one thing well. It has since accumulated tweaks and enhancements before enduring the indignity of AI-powered text editing services. The same fate could await Task Manager. The additional metrics will undoubtedly be useful to developers. Whether they represent helpful visibility or another step toward feature bloat depends on whether Microsoft can add them without compromising the speed and simplicity that made Task Manager indispensable. ®
US claims 15 of the world's top 20 hyperscale datacenter locations
The US now accounts for 15 of the world's 20 largest hyperscale datacenter markets, with Northern Virginia alone hosting nearly 12 percent of global capacity. US locations have increased their dominance of the rankings as cloud infrastructure expands, according to Synergy Research. Since last year, Tokyo, Sydney, and South Carolina have dropped out of the top 20, replaced by Indiana, Tennessee, and China's Guangdong province. Of the remaining five markets, four are in Asia-Pacific, while Europe has just one: Dublin. Synergy attributes the US dominance to two factors: 62 percent of the world's hyperscale operators are headquartered there, including the four largest, and the country accounts for almost half of cloud revenue across several key segments. The US also has abundant land for enormous campuses such as Meta's Hyperion project in Richland Parish, Louisiana, which is expected to accommodate up to 5 GW of infrastructure. Hyperscale datacenters are vast facilities designed to support the computing requirements of major cloud and internet operators. Synergy's analysis covers the infrastructure of 21 such companies across cloud services, search, social media, ecommerce, and gaming. Amazon, Microsoft, and Google have the broadest datacenter footprints and together account for 57 percent of global hyperscale capacity, according to Synergy. They are followed by Meta, Alibaba, Tencent, Oracle, Apple, ByteDance, and CoreWeave. A range of factors influence the choice of location for hyperscale infrastructure, says Synergy chief analyst John Dinsdale. These include proximity to customers; the availability and cost of real estate and power; networking infrastructure; local financial incentives; political stability; and exposure to natural hazards. "With the extremely rapid growth in demand for AI technology and infrastructure, availability of power has become an ever more critical criterion, as has the ability to overcome or work around local community objections to building large datacenters. These factors are heavily influencing the geographic distribution of future infrastructure developments," Dinsdale adds. According to the New York Times, Loudoun County in Northern Virginia is home to roughly 250 datacenters and expects to collect about $1.3 billion next year from taxes on the equipment inside them. Loudoun County may be an exception. A report earlier this year found that states were forgoing billions in revenue through incentives offered to datacenter operators, with Virginia's concessions estimated to cost it $1.94 billion. Northern Virginia does not feature as prominently in new development plans as it once did, according to Dinsdale. Meanwhile, operational hyperscale capacity in Texas has grown by 71 percent over the past year, compared with 36 percent worldwide. Synergy is tracking another 915 hyperscale facilities at various stages of planning, development, or fit-out, Dinsdale adds. ®
Researcher tricks Apple’s Find My into sharing location data with Linux
A young security researcher figured out a way to enroll a Linux device into Apple’s Find My network and read live location data from it. Find My is Apple’s app for, you guessed it, finding things – whether AirTags, iPads, or other supported devices and items. It also works for people. Families can track each other's whereabouts for safety reasons, and friends can tell when others are hanging out without them. In typical Apple fashion, though, the full Find My experience is limited to Apple hardware, like an iPhone or Mac. iBiz also offers Find Devices via the iCloud website, although it lacks Find My’s people-tracking feature for viewing locations others have shared with you. However, the 22-year-old researcher, who goes by “Zerotistic,” devised a way to enroll a Linux-based machine into the iNetwork, tricking Apple into sending the people-location data it exclusively reserves for Apple devices. It’s important to note, at this point, that this is not an exploit that allows anyone to arbitrarily retrieve any Apple user's location. It refers to registering a non-Apple device to the Find My network and retrieving the location data of people who had already chosen to share their locations with the Apple account owner. Retrieving people-location data requires Apple to trust that the machine you’re using belongs to its network and is capable of receiving the data, which is sent over Apple’s Push Notification service (APNs). The first step was tying the Linux machine to the researcher’s Apple account. Zerotistic obtained an identity delegate by going through Apple’s standard GrandSlam authentication protocol. In pursuit of an Apple Identity Services (IDS) device certificate, which links the intended device to an Apple Account, they then used that delegate to build a custom certificate signing request (CSR). Lots of trial and error later, Zerotistic discovered that the CSR had to use the PKCS#10 format and a 2048-bit RSA key signed using SHA-1, linking the Linux machine to their Apple account. They bundled this up into a compressed XML file and sent it to Apple’s authenticateDS profile-enrollment endpoint. The SHA-1 signature requirement and XML encoding were surprises. The researcher’s “best guess” is that the CSR had to conform to older standards because authenticateDS is a legacy endpoint. Apple signed the CSR, handing the Linux device the IDS certificate needed to register its public key to the researcher’s Apple account. The Linux device was registered at this point, but further work was needed to convince Apple that it was capable of running Find My. Zerotistic found that a Find My registration request required the device to subscribe to six different subservices, define the types of encryption it supported, and provide the public keys to support Apple’s device-to-device messaging format. It also had to be signed using an IDS certificate and an APNs certificate obtained during initial network setup. At this point, the researcher had enrolled the Linux machine in an Apple account and convinced Find My that it was capable of receiving location data via a persistent binary TLS connection to Apple’s private APNs servers. However, this registration did not automatically retrieve the location data of people who had previously shared their locations with Zerotistic, as a box-fresh Apple device would after setup. Issuing a SubscribeAndFetch request fixed this, prompting the device of the researcher’s friend to push an encrypted location key to the newly registered Linux device. The final challenge was reading the location data the Linux device fetched from Apple’s SearchParty service. Zerotistic was not simply using the GUI Find My app on Linux; they were receiving the encrypted data and had to figure out how to unpack the location message. This required a Linux script to unwrap Apple’s messaging envelope, extract the shared location key, and decrypt the Find My location data, which is comprised of coordinates, timestamps, and accuracy information. Once developed, the script could fetch and decode subsequent location reports for the existing location share. It took the researcher less than a week of tinkering to develop the Find My-busting technique, they said. The Register asked Apple if it was aware of the researcher’s work and if it had any plans to address the issue, but it did not immediately respond. ®
Slack Code taps into collective vibe, puts AI agents into the group chat
Slack has decided that AI coding agents have spent quite enough time alone with developers and would be better off doing their work where everyone can watch: on Slack. The Salesforce-owned chat factory has introduced Slack Code, which gives coding agents their own project channels where they can work alongside the humans supposedly keeping an eye on them. Slack calls this "multiplayer AI," which is another way of saying the coding bot is leaving the developer's terminal and joining the group chat. Tag an agent from a Slack conversation, and it can create a code channel for the job. From there, people can follow what it's doing, review its proposed changes, view live HTML previews, and tell it to change course when needed. Once the work is finished, the channel can archive itself, leaving behind a searchable record of what happened. Slack says each channel maps to a particular project, presumably sparing the main company chat from several hundred lines of an agent enthusiastically explaining why it has rewritten the authentication layer. The pitch isn't aimed solely at developers. Slack reckons product managers, designers, and other non-engineering staff can participate because they don't need to open a terminal or learn another specialist tool to see what the agent is doing. Its example has a product manager spotting a bug report, asking an agent to work out a fix, and then bringing in an engineer to review the resulting diff before the agent opens a pull request and merges the change. Slack summarizes the process as: "No ticket, no meeting, no waiting – just a fix, shipped." Slack insists humans remain in charge. Anyone in a code channel can pause, redirect, or stop an agent, while higher-stakes actions such as pushing code to production are supposed to be packaged up for an expert to approve. The company also says agents inherit Slack's existing permissions, security policies, and administrative controls rather than requiring organizations to build a separate management layer around them. Slack isn't planning to have the playground to itself. Anthropic, Cognition, GitHub, OpenAI's ChatGPT, and Vercel are among those developing integrations for Slack Code, with Claude, Devin, Copilot, and ChatGPT among the agents destined for its code channels. Slack says the APIs will eventually open to the broader developer community, with code channels potentially hosting agents doing jobs beyond software development, from marketing work to legal document review. Alongside Slack Code, the company is giving agents more conventional places to lurk. Agent DMs provide direct conversations with AI workers, while a new Agents tab lets users find agents, revisit sessions, check their status, or stop one that's gone wandering. An "Add to Slack" feature is also intended to make deploying agents built using third-party platforms a matter of a few clicks. Slack's argument is that much of this AI-assisted coding currently happens out of sight. A developer works with an agent in a terminal or browser, then brings the result back to everyone else when it's time for a review. Code channels put that process in Slack from the start, giving colleagues a chance to see what the agent is doing – and object before it gets too carried away. Slack says users can "get started with Slack Code today," although its announcement doesn't spell out which Slack plans have access, how broadly the feature is being rolled out, or which of the named coding-agent integrations are available at launch. The Register has asked Slack for clarification. Whether watching a bot write software alongside your coworkers marks the future of collaborative development or simply gives everyone another Slack channel to monitor remains to be seen. Either way, the coding agent is joining the group chat. ®
Thunderbird to flap twice as fast from September
Thunderbird is moving to fortnightly releases to keep pace with Firefox's accelerated schedule. Mozilla and its subsidiary MZLA updated their flagship apps this week, releasing Firefox 154 and Thunderbird 154, respectively. Since last month's version 153 releases are the latest Extended Support Releases, users who prefer a slower pace can remain on them for the next year. "ESR" is Mozilla's term for what Canonical calls LTS, Long Term Support. The new 154 versions are therefore short-term, or interim, releases. As we reported, the Mozilla Firefox release schedule speeds up from next month to new versions every two weeks, instead of every four weeks. According to a message from MZLA's Corey Bryant, Thunderbird will adopt the same cadence in September. Firefox picks up a few extras Firefox does get some new features, although most are of little interest to FOSS fans. Several of the additions are Windows-only for now, including the ability to give Firefox a custom app icon. Also reserved for those who like to pay for their OS, Firefox 154 now supports GeForce NOW. The Register covered its launch in 2018. It is a subscription service that lets users play supported games remotely, with the rendering handled by cloudy Nvidia hardware. Outside the Microsoft world, Mac users can now back up their Firefox profiles. The prompt-fondlers out there may enjoy playing with the new Smart Window, which lets you use artificial idiocy to interact with the browser. Sounds awful to us, as AI in general now does to more than half of Americans. Thunderbird brings the bigger payload This time, Thunderbird gets more new features – and, to this vulture's eye, more useful ones. Thunderbird 154 enables Microsoft Graph support for Microsoft 365, using the API that the company announced in 2015 to interact with Microsoft 362.5 services. The addition is timely because the Exchange Web Services API is on the way out for Redmond's cloud products. That makes Graph support a useful addition – although EWS will still work for outfits that host their own Exchange Servers. The release improves handling of messages encrypted with Cryptographic Message Syntax, along with drag-and-drop and context-menu copying of messages and attachments. Attachment previews have also been improved on macOS. Finally, on desktops with a system tray, Thunderbird can now be minimized to it when the last window is closed. This version also handles interrupted connections during large IMAP operations more gracefully – a significant improvement, since this issue has bitten this vulture before. If that sounds arcane, imagine knowing that you will soon lose an email account and you want to back up its contents first. Thunderbird makes this easy: create some local folders, or folders on another server, select everything, and drag and drop it. It's all fine until your internet connection falls over, which, as we all know, tends to happen at the worst possible moment. There are also more than 30 assorted bug fixes and more than 50 security fixes. This is, after all, an internet-facing app. We don't know who or when, but at some point, some damned fool thought: "Wouldn't it be great if you could format your emails in HTML?" The answer to this, of course, is: "NO! No, it would not! That is a terrible idea!" However, that ship has not merely sailed. It had an active service life of several decades before being towed away, broken for scrap, and turned into cutlery. As a result of this, you have a choice: either run an email client that has all the latest web security fixes, or do your email in the terminal and get used to telling people that you couldn't read their important missive. ®
Ransomware crook poses as recovery firm to steal payments from fellow extortionists
A ransomware affiliate appears to have found a new way to squeeze victims for cash: pose as the good guy and undercut the criminals it was working with. Researchers at GuidePoint Security say an outfit calling itself "Ransom Busters" has been contacting ransomware victims before their attacks become public, offering to recover encrypted files and delete stolen data for a considerably smaller payment than the original extortion demand. The catch, according to GuidePoint's Research and Intelligence Team (GRIT), is that Ransom Busters isn't an enterprising band of ransomware hunters at all. The researchers assess with "moderate confidence" that it's a ransomware affiliate working across several ransomware-as-a-service operations and attempting to steer payments away from its criminal partners. GuidePoint came across Ransom Busters while investigating attacks linked to DragonForce, Settra, and Anubis. The outfit emailed victims claiming it had hacked the ransomware gangs themselves and discovered their stolen data on the crooks' servers. Ransom Busters claimed it could delete that data and retrieve encryption keys, all for the bargain-basement price of between $20,000 and $60,000. It also demonstrated access to the same datasets held by the ransomware affiliate behind the attacks, GuidePoint said. That alone raised eyebrows, but the forensic evidence proved rather harder to explain away. GuidePoint examined two incidents in which Ransom Busters approached victims and found the intrusions shared a collection of unusually specific fingerprints. Both used SoftPerfect Network Scanner for reconnaissance, s5cmd to shovel data into AWS cloud storage, and the Remotely remote-management tool installed using PowerShell. More damningly, the attacker created a local backdoor account using the password "Numlock!123" in both environments. The same attacker-controlled hostname, "DESKTOP-BBETH6K," also turned up in both intrusions. This might be explained by ransomware operators sharing tools or a prebuilt attack environment. GuidePoint said it has seen the same activity across several separate RaaS programs, however, leading it to conclude that one affiliate is likely moonlighting across multiple gangs and then cutting its employers out of the payday. GuidePoint also warned that paying the supposed rescuers provides no assurance that stolen information will actually disappear. So if a mysterious stranger somehow knows you've been ransomwared before you've told anyone, and generously offers to make the whole problem disappear for $20,000, you may want to question how they got your number in the first place. ®
NetBSD 11 lands with RISC-V support and lightning-fast VM boots
NetBSD's 19th major release adds 64-bit RISC-V support, improved Linux compatibility, and a MICROVM kernel that can boot in milliseconds. NetBSD 11.0 arrived at the end of July, a little over two years after the project celebrated its 30th birthday with the release of version 10.0. We looked at what was coming last year. After multiple release candidates, the final version is here, and we tried it. NetBSD is a stable, somewhat minimalist, and relatively slow-moving project. If you're willing to put some work in, this arguably makes it a refreshing change from the ever-accelerating techbro world of Linux. As The Register noted of Linux 7.2 earlier this week, it is a huge release: the increasingly AI-assisted development process is rapidly adding features and expanding Rust support while shedding compatibility with older hardware. NetBSD is not static, though. Version 11.0 nonetheless brings some significant additions. In addition to nine platforms with Tier I support, including x86-32 and x86-64, Arm32, Arm64, MIPS, and PowerPC, it also has an impressive 52 platforms with Tier II support. Version 11 brings support for 64-bit RISC-V, greater compliance with POSIX.1-2024 and C23, improved Linux system-call compatibility, and better operation under Xen and QEMU. A new dedicated MICROVM kernel supports both 32-bit and 64-bit x86 guests and can boot in about 10 milliseconds on 2020-era processors, according to the project. The new RISC-V port supports QEMU, while the new virt68k port runs the Motorola 68000 version of NetBSD under QEMU using paravirtualized devices. There's preliminary support for Qualcomm Snapdragon X Elite, meaning PC-like Arm64 systems, and the npf firewall has been improved. NetBSD is a general-purpose OS. It tends not to attract as much attention as the other BSDs, perhaps partly because they have more clearly defined roles. FreeBSD is a server-oriented OS with ZFS and rich container support, including Linux OCI containers… but even the latest version has a text-only installer. If you want a GUI on FreeBSD, you must install it yourself. DragonflyBSD is the x86-64-only experimental research OS. OpenBSD is the extremely minimalist, very portable, and very secure OS, to the extent that it doesn't even support Bluetooth. NetBSD's strength is that it is not confined to any one of these roles. It can run as a Xen host or guest, and its new MICROVM kernel is designed for lightweight, fast-starting x86 VMs. The external SmolBSD project can also help users build customized NetBSD VM images. It's a capable server OS: the SDF public-access Unix system mostly runs on NetBSD. It can run Linux binaries, and as the compat_linux manual page describes, the NetBSD repositories contain cut-down sets of openSUSE libraries to help build a Linux environment. The repos also have packages of many of the usual FOSS suspects, such as Firefox and even WINE. There is a choice of desktop environments, including LXDE, LXQt, KDE Plasma, MATE, and GNOME, along with numerous more minimal window managers. Since NetBSD 11.0 was released, for instance, it got a newer version of Enlightenment. The packaged versions often lag behind the latest upstream releases, but they do the job. The classic Common Desktop Environment is there, but despite multiple helpful posts on the NetBSD-users mailing list, we were unable to get it working. However, NetBSD requires more manual work than a typical 21st-century Linux distribution. Its base package tools include pkg_add, but users wanting higher-level features such as repository searches and convenient upgrades may prefer to install pkgin. Handily, the text-mode installer, called sysinst, is installed with the rest of the OS. You can run it after installation to do any steps you might have forgotten or skipped, such as configuring your network connection, adding user accounts, or indeed, installing the package manager. You need to become comfortable editing configuration files and scripts, including enabling services manually in /etc/rc.conf. You will also have to rely on FOSS drivers, as very few vendors produce proprietary drivers for NetBSD. If you have a high-end graphics card and want the latest PC games, forget about it – this is not the OS for you. But if you want to build your Unix muscles and really learn your way around a Unix box, this is a good option. This will teach you a lot more than getting Arch Linux installed and tweaking its desktop settings. If you want to learn about contributing code and patches, it also has one of the most welcoming communities we've encountered in years. ®
£37M SAP overhaul could extend Capgemini's run with UK tax collector to 28 years
The UK's tax collector has awarded Capgemini a £37 million contract to help migrate a critical tax system from SAP's legacy ECC platform to S/4HANA, extending a supplier relationship that began in 2004. HM Revenue & Customs (HMRC) has hired the French IT services company to move the Enterprise Tax Management Platform (ETMP) from SAP ECC 6.0 to its successor, S/4HANA, a completely re-engineered application platform. The system provides 40,000 users with returns processing, tax accounting, payments, and data management capabilities, and handles more than £800 billion in tax revenue and payments annually. The contract runs until 2032, potentially extending Capgemini's involvement with HMRC's tax systems to 28 years. Capgemini became HMRC's lead technology supplier in 2004 under the Aspire contract, with Fujitsu and Accenture serving as subcontractors. In 2014, the National Audit Office (NAO) said HMRC was set to spend £10.4 billion on the contract, compared to the £4.1 billion estimate used to evaluate Capgemini's bid. In 2022, Capgemini won a £51 million, three-year contract to provide run and change services for ETMP and Enterprise Operations (EOPS). In 2024, the French supplier again won the contract to provide run and change services for ETMP and EOPS. The five-year agreement, which runs until June 2029, is valued at between £403 million and £574 million. HMRC has previously denied that its later ETMP contracts with Capgemini were extensions of Aspire, which formally ended in 2017, although some services continued until 2020. Separately, Capgemini won a Contact Centre as a Service contract worth up to £600 million over ten years. The Register understands there were several bidders for the new ETMP migration deal, but HMRC officials argued the details were commercially sensitive. They said HMRC took steps to ensure a fair and transparent procurement and a level playing field for all bidders. The competitors came from Lot 3 of the Digital & Legacy Application Services (DALAS) framework, which lists Accenture, Atos, Capgemini, CGI, Cognizant, and IBM as suppliers. Ethical wall arrangements and non-disclosure agreements were put in place to prevent commercially sensitive information from being shared with bidders already working for HMRC through other contracts, officials said. In January, HMRC awarded SAP a £275 million contract for S/4HANA without competition, saying in the award notice that the German software giant was the "only supplier with sovereign capability." In June, Capgemini said it had become an SAP Sovereign Cloud Partner for the UK. Andy Allen, a relationship director at Capgemini, later said the company would work with Invenio to support ETMP's migration to S/4HANA on SAP's UK Sovereign Cloud. "It's a complex and important programme, helping to ensure continuity, resilience and a platform fit for the future," he said. A Capgemini case study published in 2012 (now removed but archived here) said that ETMP was one of the projects it ran under Aspire. It also migrated Stamp Duty Land Tax onto the system. In 2014, the NAO said [PDF] Aspire had delivered improvements fundamental to HMRC's administration of tax, but found that the department had not evaluated the contract's overall strengths and weaknesses. The watchdog estimated that HMRC would spend £10.4 billion over the contract's lifetime, compared with the £4.1 billion figure used to assess Capgemini's bid. It said Capgemini and Fujitsu had earned considerably more profit than initially modeled, while pressure to cut costs had led HMRC to surrender some negotiating power. A parliamentary committee subsequently accused suppliers of outmaneuvering HMRC at key points. It said [PDF] Aspire cost £7.9 billion between July 2004 and March 2014 and generated £1.2 billion in combined profit for Capgemini and Fujitsu, equivalent to a margin of 15.8 percent. In January 2025, research by The Register and public sector spending specialist Tussell found that HMRC had awarded £3.8 billion in contracts since 2020 to technology suppliers previously involved in Aspire. At the time, an HMRC spokesperson told The Register: "We follow government procurement rules when awarding contracts and look for solutions that will improve services and get the best deals for taxpayers. For transparency, we publish contract awards along with contract variations."
Grok chat duped into swallowing injected instructions
xAI's Grok web chat agent is currently vulnerable to a novel form of prompt injection, according to security researchers with Adversa AI. The technique allows an attacker to create a web page poisoned with malicious instructions that induce an AI model summarizing the page to carry out harmful actions. That describes a well-known attack known as indirect prompt injection. Frontier AI models have become better at dealing with such attempts through existing guardrails, though the issue is far from resolved. Adversa's approach comes with a twist: It relies on encrypted malicious instructions, which attackers place on a web page alongside an encryption key. The model guardrail scanner – an input filter – can't read the encrypted text despite the presence of the key. The scanner therefore passes it on to the model, which can use the key to decrypt the instructions. The model then carries out instructions in the decrypted text as would be the case in any other indirect prompt injection attack. Adversera calls its method "cryptographic context injection." "An attacker ships ciphertext along with the key material and an instruction to decrypt it, and the model runs that decryption inside its own code execution sandbox," wrote Rony Utevsky, lead researcher at Adversa AI, in a blog post. "Everything a guardrail’s scanner would need is right there on the page, but recovering the plaintext means running PBKDF2 and AES-256-GCM, which no content classifier does at inspection time." Other attacks on AI models have relied on cipher-based evasion, such as base64 encoding. But because these are weak and reversible cipher mechanisms, models can decode them natively from their own training data, Utevsky said. That doesn't work for strong encryption, so decryption must be done through the code execution runtime. The runtime thus becomes a mechanism for trust laundering – the model trusts its own output, namely the malicious instructions that it decrypted. In a proof-of-concept demo, Adversa shows how the technique can be used to exfiltrate the victim's chat history with Grok.com. The attack transmits the user’s name, coarse location, subscription tier, and the full set of the user’s prompts in the conversation by appending them to a URL as parameters. Other models may be vulnerable to varying degrees. With Google's Gemini public chat interface (gemini.google.com), Utevsky told The Register, the Grok scenario doesn't work because Gemini doesn't provide Python with access to external websites. "So it's useful only to sneak bad questions and answers past guardrails," he explained. When Adversa tested cryptographic context injection on Gemini, they were able to get the model to produce content that normally would be blocked by safety filters – instructions for how to build an incendiary weapon. xAI, according to Utevsky, was informed about the attack on June 3, 2026, directly and through its HackerOne bug bounty program. We're told xAI acknowledged the report but did not provide a mitigation timeline. Additional attempts to raise the issue are said to have occurred on August 4 and August 10. As of August 19, we're told, the technique still worked on Grok.com. SpaceX, which acquired xAI earlier this year, did not respond to a request for comment. Google was not informed of the attack, according to Utevsky, because it considers jailbreaks – bypassing guardrails to make models emit harmful content – to be out of scope for its vulnerability disclosure program. Nonetheless, the attack success rate against Gemini declined significantly by August, which Utevsky suggests could be due to filter updates, model version changes, or both. Asked whether cryptographic context injection can be compared to return oriented programming (ROP) in terms of the way it assembles attack gadgets from separately harmless parts of stored memory, Utevsky said, "The ROP analogy is close, though ROP works that way out of necessity – the attacker can't inject code at all, so they're stuck reusing gadgets already in memory. "Same shape here otherwise. A static guardrail reads text one artifact at a time. If no single artifact is harmful, they all pass, and the malicious meaning appears only once the runtime assembles them. And guardrails can't see into the runtime. But Utevsky added that cryptographic context injection is more open than ROP. "The agent's runtime is a general-purpose interpreter, so the pieces are arbitrary," he explained. "You could split an instruction across several encrypted fragments, fetched pages, or tool outputs, none meaningful in isolation, and let the runtime concatenate them. We haven't demonstrated that, but nothing rules it out. "So yes, cryptographic context injection is one kind of link, not necessarily the whole chain. "The moment agents got code and tools, the guardrail's unit of inspection (a string) stopped being the unit of action (a composed, executed program). This is a big playing field. Our earlier SymJack attack reached the same place through symlinks and shell behavior. Encryption adds another trick to the game." ®