French tax authority says break-in exposed data of 600K, including some private messages
France's tax authority says attackers may have stolen the contents of messages exchanged with hundreds of taxpayers during the data raid it confirmed last week. In an update published this week, the General Directorate of Public Finances (DGFiP) said lists of messages exchanged with the authority were exposed. For around 250 people, the compromised information also included the messages themselves. Slightly more than 350,000 individuals were affected. The other exposed data included tax identification numbers, marital status, email and postal addresses, and phone numbers. Tax records also exposed details such as household composition, number of dependents, family quotient, reference tax income, and withholding rates. Beyond the personal and tax information, DGFiP said the other affected datasets contained information that was already publicly available. For approximately 250,000 businesses and professionals, the affected data was limited to company names and SIREN numbers, the unique nine-digit identifiers assigned to French businesses. The compromised cadastral data was limited to property addresses and dimensions, which DGFiP said were already publicly available. DGFiP said it was notifying affected taxpayers by email or post this week. DGFiP's latest FAQ pegs the total number of affected parties at roughly 600,000. That appears lower than the 678,000 "individuals and professionals" DGFiP said were affected last week, shortly after the alleged cybercriminal behind the attack, "ZeroBytes," claimed to have stolen data belonging to more than 2 million. The authority did not explain the discrepancy. The notifications warn that criminals could use the stolen details to make phishing attempts appear more convincing. DGFiP highlighted impersonation attempts, CEO fraud, and scams involving bogus bank advisers as possible follow-on attacks. The authority said it would never ask taxpayers to provide sensitive information such as PINs or identity documents by phone, text message, or email, and would request such material only through its secure portal. Separately, the tax authority disclosed a "technical vulnerability" in the government's Vacant Successions Portal (PSV), which is used to search for estates without known heirs. DGFiP suspended the service after discovering the flaw. It said there was no evidence so far that personal data had leaked, although its investigation into possible exposure of applicants' details continues. The incident adds to a torrid year for cybersecurity across France's public sector. In February, the finance ministry, which oversees DGFiP, 'fessed up to an intrusion into a database containing citizens' bank details that affected 1.2 million people. The Health Ministry confirmed in March that 15.8 million administrative files, 165,000 of which contained doctors' notes, were stolen during an attack on healthtech company Cegedim Santé. A month later, a 15-year-old allegedly carried out an attack on France Titres, which handles the country's identity documents. The attacker claimed the breach affected between 18 million and 19 million people. In June, France also began probing an alleged breach of Tchap, the government's encrypted messaging platform, after attackers claimed to have accessed 73,000 user accounts, 643,000 messages, and nearly 60,000 media files. ®
OpenAI glitch locks out vetted cyber researchers – and some can't get back in
OpenAI says a technical stuff-up booted some vetted security researchers out of its Trusted Access for Cyber (TAC) program, only for its recovery process to decide some of them aren't welcome back. The problem surfaced this week when participants reported that their previously approved status had vanished without warning. OpenAI's cyber verification page instead invited them to "Start verification" as though they had never been cleared. Some also found that Daybreak Blue, an access tier offering vetted cyber defenders expanded capabilities, had disappeared from Codex Desktop and the command-line interface. OpenAI has since acknowledged the problem. Responding to complaints on its community forum, the company said "a limited set of users" had lost Daybreak Blue access because of a technical issue and would need to complete verification again. "This isn't the experience we want to deliver, and we're making sure the issue doesn't happen again," OpenAI said. Affected users were told to look for an email titled "Action required: Reverify your Daybreak Blue access," containing instructions for getting back through the door. For some, however, it appears to remain shut. One researcher said they followed the instructions and selected "Start verification," only to be told that the process could not begin because their account was ineligible. Another participant said they had held Daybreak Blue access for more than a month before losing it in the technical snafu. After OpenAI support told them to reapply, the verification system reportedly said it could not verify their identity or that the account was currently ineligible. According to their account of a subsequent exchange with support, OpenAI could neither reset the verification state nor restore or override the previous approval. TAC gives security professionals access to advanced cyber capabilities that are more restricted for other users. Applicants must provide identification and undergo verification before getting access. The aim is to give legitimate defenders more powerful tools for finding and fixing vulnerabilities while restricting access for those with less wholesome intentions. Anthropic operates a comparable scheme called the Cyber Verification Program. That makes this more than an option mysteriously vanishing from a menu. OpenAI had already vetted these researchers – then its own technical problem kicked them out, and its verification system apparently changed its mind. OpenAI didn't respond to The Register's questions about the number of affected users, the cause of the removals, why some previously approved researchers are now deemed ineligible, or whether it can restore access when re-verification fails. It instead directed us to a statement posted on X that blamed the access removals on a "technical issue," saying only a limited number of users were affected, and telling those users they would need to re-verify. For now, some of OpenAI's trusted cyber researchers have discovered an unexpected vulnerability: the front door. ®
Microsoft probes reports of games taking exception to Windows 11's August update
Microsoft is investigating reports of games crashing after users installed August's Patch Tuesday update for Windows 11. The company acknowledged the reports on its Release Health page. Affected games may become unresponsive, close unexpectedly, throw an "EXCEPTION_ACCESS_VIOLATION" error, or trigger an unexpected device restart. Reports of the problem followed the release of KB5121003 for Windows 11 24H2 and 25H2. The KB5121003 support page still lists no known issues, but Microsoft has separately confirmed on Release Health that it is investigating the game crash reports. The problem does not affect every title. Microsoft named ARC Raiders, MARVEL Tōkon: Fighting Souls, and The Finals among those generating reports. The Windows giant has not accepted responsibility, writing: "We are presently investigating to determine if this is an issue caused by Microsoft." Users have theorized that tighter kernel handle validation may have exposed problems in third-party drivers that Windows previously tolerated, causing crashes when code ventures where it should not. That might be good for security, but less so for software that depended on the previous behavior. Microsoft has not confirmed the theory. August's Patch Tuesday was a big one, addressing 421 Microsoft CVEs, including 236 affecting Windows. As such, uninstalling it as a workaround is probably not a good idea. The reports come as Microsoft tightens its treatment of old and incompatible kernel drivers. In March, it removed trust for kernel drivers that hadn't been through the Windows Hardware Compatibility Program (WHCP) to lock down the Windows kernel further. Microsoft has also launched its Driver Quality Initiative (DQI) to improve operating system stability. The crashes remain under investigation, and Microsoft has asked affected users for feedback. ®
Software development and tech services in the cross-hairs as AI marches on
Business transformation, software development, and technology implementation are among the tech job categories likely to be hit hardest by AI, according to new research from Forrester. The global IT analyst company has researched how AI will disrupt various activities within the tech market, both among end users and vendors. It concluded that labor-intensive knowledge-work industries would face the greatest disruption. At the same time, enterprise software will be reshaped rather than displaced, allaying some concerns about a SaaSpocolypse. “Every technology and service market is facing an AI overhaul,” said Craig Le Clair, vice president and principal analyst at Forrester. “Our research shows that AI’s benefits will not be distributed evenly across technology markets. Only markets in three categories — infrastructure; data and AI; and identity, access, and network security — are broadly positioned for clear growth. Technologies in the other categories will be forced to adapt.” Forrester argued that business applications, governance and compliance, process automation, and customer experience would change as AI transforms workflows and user experiences. “While these categories are vulnerable to disruption, embedded workflows, regulatory requirements, switching costs, and growing demand for data, orchestration, governance, and trust capabilities help sustain their relevance,” the report said. The analyst firm singled out application development and software as a category likely to be hit hard by AI rollout. “These markets include tooling, content management, and IT management software that produce and run applications and connect bodies of knowledge. This includes application generation and low-code platforms, autonomous testing platforms, content management systems, digital experience platforms, knowledge management solutions, as well as enterprise architecture management suites,” the report said. These activities and technologies are “directly in the path of genAI-code development,” Forrester added. Other markets in the crosshairs of AI include IT services. “Direct AI substitution reduces core implementation work. Services to implement Oracle, Salesforce, SAP, and Workday all showed headwinds. The most severely disrupted market is business process outsourcing that will see lowervalue services, testing, and software development services sell at reduced rates,” Forrester said. The colossal investment in AI — including astronomical datacenter building plans — has led Gartner to raise its 2026 estimates for the total IT market to $6.37 trillion, a surge of 14.2 percent year-on-year. That's up from April's forecast of $6.31 trillion and February's $6.15 trillion. A lot of that growth comes from the technology industry itself, which already invests around $1 trillion. That figure is set to grow by 34.7 percent over 2026.
No lift for Swift as NASA abandons orbital rescue
NASA and Katalyst Space have abandoned an ambitious attempt to boost the Swift observatory into a higher orbit and postpone its fiery return to Earth. Katalyst Space's LINK spacecraft will still attempt to rendezvous with and maneuver near Swift, but plans to grapple the observatory and raise its orbit are dead. The problem, according to NASA and Katalyst Space, is an "ongoing commercial spacecraft attitude control issue." Shortly after launch, LINK entered a spin, and two of the three reaction wheels used to control its orientation were declared inoperable. Engineers regained control using the spacecraft's electric thrusters and transmitted a software update reflecting its diminished capabilities. The work kept LINK operational, but could not make the planned reboost safe. NASA and Katalyst Space have put a brave face on this. The space agency's administrator, Jared Isaacman, stated: "NASA should be willing to move quickly and take smart risks when the potential return is worth it, and that is exactly what we did with this mission. This is not the outcome we were working toward, but it does not change why this mission was worth attempting." Katalyst Space CEO Ghonhee Lee said: "Katalyst designed, developed, and launched an experimental spacecraft to go after an ambitious mission on an aggressive timeline. We took on this high-risk, high-reward challenge and are proud of the milestones we reached along the way." LINK's mission is not over, but Swift's rescue attempt is. NASA it is working closely with Katalyst Space "to assess next steps for rendezvous and gather as much data as possible to inform future satellite servicing operations." NASA expects Swift to re-enter Earth's atmosphere later this year. The breakneck pace of the LINK mission was driven by the observatory descending more quickly than expected. The Swift team cut back on many science activities to slow the observatory's orbital decay. Those efforts bought enough time for LINK to attempt a rendezvous, if not a reboost. Swift was launched in 2004 to study gamma-ray bursts. Designed for a two-year primary mission, it has operated for more than two decades, but increased solar activity has accelerated the decay of its orbit. In September 2025, NASA awarded Katalyst Space a contract to mount a robotic servicing mission, leading to LINK's July 3 launch aboard a Northrop Grumman Pegasus XL rocket. Swift's end is now approaching, and NASA will return to its existing plans for the observatory's final months. The agency said it "will continue to prioritize finding new options to react rapidly to cosmic events, using current missions to help fill the gap in the meantime." ®
SparkyLinux 8.4 rekindles support for 32-bit PCs
Almost exactly a year after SparkyLinux 8.0 abandoned installation images for 32-bit PCs, version 8.4 has brought them back. The distro remains based on Debian 13 and retains the codename "the Seven Sisters." The Register first checked out SparkyLinux back in 2015, and this vulture took a look at version 7 a couple of years ago. Beyond the changes inherited from the move from Debian 12 to Debian 13, this version isn't hugely different. The project's own self-description covers the basics. (The project also offers release info in Polish, jeśli wolisz to.) It comes in both rolling-release and stable variants, and you get a choice of versions with different desktops: LXQt, MATE, Xfce, and KDE, plus a minimal command-line only edition, and a minimal GUI edition with Openbox. All offer Sparky's improved package manager, called Aptus. Sparky 8.4 isn't the first Debian-derivative we've seen that offers a 32-bit edition. That distinction goes to Window Maker Live 13.2, and earlier this year, we also scoped out antiX 26, which offers several older kernel versions. We tried the 64-bit LXQt flavor of SparkyLinux 8.4, and installation was a cinch with the cross-platform Calamares installer. It ships with Linux kernel 6.12 by default. For comparison, we tried the 32-bit edition, in its "minimal GUI" variant. There is no graphical installer, so you must run a command-line one in a terminal. It asks numerous questions about locales and keyboard layouts, but gets the job done. At the end, it offered a comprehensive choice of desktop environments, including the original CDE – open sourced in 2012 – and its modern recreation, NsCDE. We compared the two in 2022. To see how it looked, we chose CDE. A few minutes later, we rebooted and logged directly into the third-of-a-century-old environment. It works fine: we left the VirtualBox defaults on for a 32-bit VM – 1 GB of RAM and 8 GB of disk – and the system fit comfortably, consuming 6.9 GB of storage and 259 MB of memory. There's no Snap or Flatpak support installed, but it does use systemd, just like Debian itself. The 32-bit edition uses the same kernel version 6.12 as its 64-bit sibling, although the minimum spec has been increased a little: it now requires a 686-class CPU with PAE support. Mozilla ended mainstream 32-bit Linux builds after Firefox 144, with ESR 140 serving as the final supported branch. Sparky supplies its own 32-bit build of Firefox 140 ESR, which worked without complaint. This could be a useful way to revive an old Atom-powered netbook or similar machine: 32-bit code generally has a smaller memory footprint than its 64-bit equivalent. It could also suit extremely small VMs, while remaining worth a look on more capable hardware. ®
AI agent suggested installing a malware package. Engineer almost took its advice
PWNED Welcome back to PWNED, the column where we make fun of those who are security self-owned, so hopefully you don’t do the same. This week, we have a story that’s hot off the presses about a company almost sabotaging its security by using AI for programming. Have a story about someone leaving a gaping hole in their network? Share it with us at pwned@sitpub.com. Anonymity is available upon request. Our tale of machine learning malfeasance comes courtesy of Sergiy Fitsak, managing director of Softjourn, a consulting and software development company. He reminds us that, when it comes to AI, don’t trust: verify. During the course of business, one engineer asked an AI agent to recommend a package that they needed for a common task. The agent came back with the name of a legitimate-sounding package, which was formatted like a familiar library. At many organizations, this would have been the end of the story. The developer would have taken the AI agent’s advice and downloaded and installed the recommended package. However, at Softjourn, the company has a policy which they actually followed: double-check any software recommendations made by AI to make sure they are legit. The developer skimmed the recommended package’s source code on GitHub and noticed that it had few downloads and had just been created a few days earlier. In other words, it was suspicious. According to Fitsak, attackers have found a way to exploit package names hallucinated by AI models. “The problem is that AI models sometimes invent package names that sound plausible but don't exist, a pattern security researchers have started calling 'slopsquatting,'” he told us. “Attackers have caught on and now register real packages under those exact invented names, betting that a developer under deadline pressure will install first and check later.” If Softjourn hadn’t been so careful, they could have installed a malware package. We don’t know the exact payload, but this malware package could have given crims a backdoor into their systems and the ability to steal data or wreak other havoc. “We caught it because we'd already built a habit of verifying download counts and reviewing source code on GitHub before installing anything an AI recommends, even when it looks routine,” Fitsak said. “It takes a few extra minutes. Skipping that step once is how a team ends up explaining a supply chain compromise instead of shipping a feature on time.” The lesson here is a very simple one: Don’t trust the package names that AI agents recommend. Have a human check the supply chain. And always have a human in the loop so they can take the time to stop and approve any outside code that comes into a project. ®
China marches towards re-usable rockets with successful first-stage landing
Chinese space startup LandSpace has landed a first-stage booster on land, the first time a Middle Kingdom company has achieved the feat. LandSpace flies rockets called Zhuque and has built three generations of the craft. Zhuque-1 only flew once, in 2018. Zhuque-2 became the first liquid oxygen-methane vehicle to reach orbit when it first flew in 2022. It can can carry 6,000 kilograms to a 200km low Earth orbit or 4,000kg to a 600km Sun-synchronous orbit. LandSpace has flown it eight times since 2022. Six missions succeeded. Zhuque-3 is the company’s new flagship and can hoist 21,300 kg to a 450km orbit. The rocket uses LandSpace’s own TQ-12A engines, which burn liquid oxygen-methane fuel. The rocket’s first stage is re-usable, and can land on its four legs. LandSpace flew the Zhuque-3 for the first time last December, but the mission failed – although its on-board Ethernet performed brilliantly. The company did better yesterday, when a Zhuque-3 sent a satellite into orbit and managed to land its first stage. You can see a video of the landing on the company’s Weixin account. The company says the rocket lifted off at 7:35 AM yesterday, split its first and second stages 137 seconds into the flight, and landed the first stage at 7:41 AM. The launchpad and landing site are about 250km apart. LandSpace says the rocket performed a high-altitude return attitude adjustment, reentry ignition powered deceleration, aerodynamic gliding control, landing ignition deceleration, and deployed its landing legs. “The mission systematically verified the entire process of the first stage returning to the land landing pad from high-speed flight,” the company trumpeted. Re-usable rockets reduce the cost of space flight by removing the need to build a vehicle for every launch. LandSpace has designed its engines and first stages to fly up to 20 times. It hasn’t proven it can re-use a rocket even once, yet, or how quickly it can get a used vehicle back on the launchpad. Just landing a first stage is, however, mightily impressive as only SpaceX and Blue Origin have previously achieved the feat. China has big ambitions in space, including huge constellations of broadband satellites, extending its space station, and building a moon base. Beijing knows re-usable rockets will help – it recently tested catching them in a net mounted on a barge at sea. State media has hailed LandSpace’s feat as a “major breakthrough” and reported that China’s National Space Agency is working on other re-usable tech to advance the nation’s ability to launch more stuff, more often, at lower cost. ®
IBM says super-chill boxes that connect through 'cryogenic tunnels' will get quantum computers scaling
IBM has shown off designs for cooling hardware it says will allow quantum computers to scale. Quantum computers rely on qubits – atoms or circuits put into a state of probability that means they can simultaneously store a value of zero and one – and which computer scientists make using complex circuitry or by suspending an atom with lasers. IBM produces qubits with chips that can only run at temperatures close to absolute zero. Big Blue’s quantum boxes therefore need serious cooling, and the company has to date made its fridges round and large. On Wednesday, the company revealed smaller, rectangular, modular cryogenic cabinets. The image below shows two of them holding some IBM quantum kit. IBM says the boxes you see above are three times larger than a domestic fridge, are made of solid aluminum panels and framing, and provide “approximately 0.53 square meters of available wiring area and 2.75 cubic meters of vacuum chamber volume.” That’s enough space to hold “larger single processors and denser system configurations.” Big Blue sees these boxes as a design that it can re-use for future generations of quantum hardware, suggesting that such machines will become less exotic, and cheaper to acquire and operate. It’s also possible to connect the coolers, which matters because IBM has hit limits in terms of scaling the number of qubits it can pack into a single chip. The company therefore envisions connecting quantum processors so they each work on different parts of a job. Standard practice in the datacenter has long been to use racks full of hardware that nestle right next to each other, to allow for best use of space, and for neater and more manageable cabling (which can even make a difference to performance with a shorter cable path). Short connections and clean cabling are even more important for quantum computers. Indeed, IBM admits that its current cylindrical coolers “require long and noisy connections between processors.” Noise is the enemy of quantum computers, as it can destroy a superposition and ruin a calculation. The boxes shown above therefore include openings through which IBM will run “quantum cables,” protected by “multiple layers of thermal shielding” that form “a protected cryogenic tunnel between systems.” Temperatures inside that tunnel remain at the extremely low temperatures needed to keep a quantum computer operating without frequent glitching and improve fault tolerance. IBM is therefore hopeful that its boxy adaptation of racking for the quantum age will let it build bigger Q-puters, which will mean AI is not the only source of “This new type of computer will deliver amazing breakthroughs in everything” hype. ®
Microsoft ends one of the last ways to buy VMware without big bundles
Microsoft has signalled it will end one of the last remaining ways to acquire VMware products outside of a big bundle. Redmond’s main offer for Virtzillains is the Azure VMware Solution (AVS), a cloudy affair that includes vCenter, vSAN, vSphere, and NSX and licenses for them all – but not the Software-Defined Datacenter Manager tool that Broadcom uses to package its wares into a centrally-manageable hybrid cloud in its flagship Cloud Foundation (VCF) suite. Since acquiring VMware, Broadcom has gone all-in on VCF and no longer sells a standalone low-end server virtualization product. The Register understands the VMware channel and sales team almost never sell licenses for vSphere Foundation, a bundle that’s useful on the edge or branch office, unless it’s part of a bigger deal that includes VCF. Services like AVS therefore represent an alternative for orgs that want to keep using VMware, but don’t want to jump to VCF. Broadcom isn’t keen on licensing anything other than the entire VCF bundle and made that plain with licensing changes that mean its hyperscale partners are not allowed to sell VMware licenses. The code-and-chips shop therefore requires customers to bring their own VCF licenses to any cloudy VMware service. Microsoft this week announced that it will therefore retire the license-included version of AVS, and that customers who use the service will need to acquire a VCF license and move to a different Azure arrangement by August 30, 2027. The Windows giant said it will stop selling license-included AVS from October 31, 2026 and warned users to start planning a move because their current rigs won’t work in the future. “Allow plenty of time to purchase VCF licenses from Broadcom and complete the transition to AVS VCF BYOL,” the company advises. “For customers evaluating modernization opportunities, start assessing current AVS environments immediately, and develop a transition roadmap to ensure you have ample time to exit AVS and avoid service disruption on August 31, 2027.” Broadcom announced the requirement for BYOL licensing late last year, and other hyperscalers have already adopted it, so VCS users should have had an inkling that change was coming. For some, this will not be their first recent VMware migration, as Broadcom has twice made changes that meant smaller cloud providers had to discontinue service, making a move to an alternative provider or platform necessary. Broadcom doesn’t mind much if smaller VMware customers move to another server virtualization vendor: it unashamedly focuses on larger customers it thinks will get the most benefit from VCF and points to most of its target customers acquiring the suite, and increased VMware revenue, as evidence its strategy is working. ®
AMD inches closer to its goal of making AI suck less ... energy
AI’s thirst for power remains an ongoing concern, but fear not: AMD says it’s making steady progress towards its goal of boosting rack efficiency 20x by the end of the decade. In a blog post published this week, the House of Zen estimates that, as of 2026, its systems are already 4x more efficient than they were in 2024. Certainly, a lot has changed since then. As you may recall, AMD began volume production of the MI300X, its first true datacenter GPU designed for AI, that year. The 750-watt part boasted up to 2.6 petaFLOPS of dense FP8 performance, which at the time made it competitive on paper with Nvidia’s Hopper generation of AI accelerators. Since then, AMD has pulled every lever and pushed every button at its disposal to squeeze more FLOPS per watt from its GPU systems, push its memory and scale-up fabrics harder, and optimize its software stack in order to catch up with its larger, more successful rival. This included adding support for 4-bit floating point data types, new memory technologies, increasing interconnect speeds, and transitioning from conventional GPU servers to fully-integrated rack-scale systems. "The counterintuitive thing here… is the bigger the device, the more efficient it is," AMD SVP and Fellow Sam Naffziger told El Reg last year when the chipmaker announced the initiative. Last month, AMD revealed the fruits of its labors with the launch of said rack-scale compute platform, codenamed Helios, which crams 72 MI455X GPUs into a single massive system. Compared to the MI300X, each MI455X boasts between 7.7x and 15.4x higher floating point performance, 2.25x more HBM, 4.4x faster memory, and 4x chip-to-chip interconnect bandwidth. Without question, the chip is faster, but it also requires more than 3x the power. Instead, the biggest performance gains come from just how efficiently AMD can scale AI workloads across the system’s six dozen accelerators. As usual, AMD isn’t exactly a pioneer here. Nvidia made the leap to rack-scale in late 2024, with the launch of its Grace Blackwell-based NVL72 systems that also pack 72 GPUs into a single rack-sized system. At the time, Nvidia CEO Jensen Huang boasted that compared to an equivalent number of Hopper GPUs, GB200 NVL72 racks delivered a 4x uplift in training and 30x improvement in inference performance. While the benefits of rack-scale architectures are clear, it’s worth emphasizing AMD is using a very different methodology to calculate efficiency, by weighting max achieved FLOPS, memory, and interconnect bandwidth differently for training and inference, rather than basing their comparison on real-world application performance. It’s also worth nothing that AMD’s 4x claim is an estimate. The first Helios units should ship to customers this calendar quarter. We expect the first MLPerf and InferenceX benchmarks to follow not long after. However, assuming AMD can make good on its goals, it says two Helios racks will be able to do the same work that required 570 racks full of kit in 2024. Put more realistically, for the same power customers will be able to deploy 20x more compute, assuming the bubble hasn’t already popped by then and taken demand with it. ®
'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers
Attackers are using AI-generated exploitation scripts to break into internet-exposed Siemens S7 Series programmable logic controllers (PLCs) at water, manufacturing, energy, and other critical facilities, in what five US federal agencies on Wednesday called an “active threat.” In this latest round of intrusions against American critical infrastructure, the attackers use open source industrial automation libraries – specifically snap7.dll/python-snap7 – combined with AI coding assistants. Armed with the open source libraries and AI, the miscreants create custom tools that mimic operational technology (OT) monitoring software and provide read/write access to the PLC devices’ memory, configuration data, and ladder logic programs via the S7comm protocol. “This is not a theoretical risk – it is an active threat,” the feds warned. While the joint alert from the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Energy (DOE), and Environmental Protection Agency (EPA) doesn’t attribute the threats to a particular government or criminal group, Iranian cyber operatives are suspected of being behind recent attacks targeting PLCs at water and wastewater facilities across at least 12 states, including a cyberattack that disrupted more than 30 community water systems in Minnesota in late July. “This appears to be a continuation of the same suite of activity we suspect is affiliated with Iran targeting PLCs,” Cynthia Kaiser, Halcyon Ransomware Research Center SVP, told The Register. “Iran-affiliated actors and adversaries are actively targeting a wide swath of operational technology because these PLCs underpin essential health, safety, and critical infrastructure across society.” National security and infosec experts last week told The Register that while there is no indication that the water-system hackers used AI in their intrusions, they worried that attackers would soon add AI to their arsenals for attacks against critical infrastructure. Now, that threat appears to be here. “What the advisory highlights with regard to AI usage aligns with what we’ve expected: state-sponsored adversaries are leveraging AI across the board for discrete tasks, like code checks and scripting, to scale their operations and move faster,” Kaiser, a former FBI cyber division deputy assistant director, told us on Wednesday. “The advisory reflects the broader reality that threat actors are using AI to increase their efficiency.” Siemens S7 Series PLCs under fire According to the Wednesday security alert, the latest attacks specifically target internet-exposed Siemens S7 Series PLCs across critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities – in other words: most of the critical industries providing goods and services that Americans use in their daily lives. “Additionally, Siemens S7 Series PLCs are used in other sectors, including the Defense Industrial Base (DIB), and could be targeted there as well,” the feds warned. The Register reached out to the agencies for additional information about the attacks but did not receive any response to our questions. Attackers use internet-scanning services such as Censys and ZoomEye to find exposed, “poorly protected” PLCs running outdated software or using default passwords – and now they’ve got an AI boost. “Threat actors are using AI assistance to generate exploitation scripts using publicly available information on these Siemens S7 Series PLCs for initial access, credential access, denial of service, and other objectives,” the agencies said. “If these PLCs are exposed to the Internet or insufficiently segmented, then threat actors can exploit various critical and high severity known vulnerabilities in these PLCs.” The use of AI also indicates “an evolution in threat actor capabilities,” reducing the need for advanced technical knowledge about OT, and allowing the attacker to more rapidly develop working industrial control system malware and attack chains, the alert says. “I think that the bigger issue is still how exposed OT environments are,” Benny Czarny, CEO and founder of critical infrastructure security firm Opswat, told The Register in an email. “AI makes it much easier for an attacker to create and modify scripts targeting PLCs, so the barrier to attacking industrial systems continues to fall. But for me the answer is not simply better AI detection.” To mitigate this threat, the feds say critical infrastructure owners and operators should first – immediately – inventory all Siemens S7 Series PLCs in their environment, apply security patches as needed, and make sure no PLCs are accessible from the internet. It's also worth checking for anomalous S7comm behavior, including connections from non-engineering workstations, unusual data block access patterns, or write operations outside change windows, the feds suggest. Sequential IP scanning on port 102 and repeated connection attempts with varying parameters can indicate attackers conducting reconnaissance, and Snap7.dll library usage outside approved workstations may also indicate the presence of intruders on the network – so be sure to use these and the rest of the detection strategies detailed in the government security advisory to hunt for anomalies that may indicate a compromise. In addition to looking for indicators of compromise relevant to these intrusions, Czarny said it's critical to reduce the OT attack surface. “If data only needs to leave an OT network, use a data diode,” he said. “There should be no network path back to the PLC for an attacker to exploit. Yes, AI makes this more urgent. But the real lesson for me is still the same: stop giving attackers a path to the critical system in the first place. And do not rely on antivirus and sandboxes to protect your data flow.” ®
SvelteKit 3 puts heat on Next.js with radical approach to RPCs
In today's sprawling JavaScript ecosystem, Svelte was designed to be a simpler alternative to the React.js front-end framework, and SvelteKit follows the same path, setting out to be a backend framework like Next.js but with fewer headaches and even better support for dynamic content. The new-ish SvelteKit 3.0 release candidate includes an experimental feature called remote functions that rethinks how data is delivered to the browser. “Remote functions make everything else look a bit clunky, including SvelteKit’s load functions and actions,” the project team enthused in the release candidate announcement page. A slender stack U.K. journalist Rich Harris, then a graphics editor at the New York Times, released Svelte 1.0 in 2016 as a JavaScript component builder that didn’t carry all the boilerplate that lumbered React.js. He needed an easier way to build graphical components for NYT online stories. Unlike React, Svelte compiled its code ahead of time, and shipped to the user without much accompanying framework. The fact that Svelte builds components from standard HTML elements also lightens the cognitive overhead for the developer. SvelteKit grew from Svelte to manage back-end chores, such as routing, rendering, and streamlining pages, all in a manner befitting Svelte’s simplicity. SvelteKit has been nipping at Next.js’ heels for a while. A recent benchmark found that SvelteKit’s Server Side Rendering (SSR) function returned an HTML payload three times smaller than Next.js for an equivalent product page — great news for performance-minded web shops. SvelteKit’s remote functions is another method that minimizes overhead – one so radical that adherents say it could disrupt the landscape of remote procedure calls (RPCs). It has been an experimental release since SvelteKit 2.27, though the upcoming v3 will embrace remote functions alongside its traditional load functions as equals (assuming the remaining bugs are sorted). Type-safe data fetching, no page refresh required Remote functions provide a way for individual components on a web page to update their data from the server, without refreshing the page as a whole. This limitation has been a real bummer for coders, who have had to come up with various ways around this issue, but their solutions have tended to be hacky and they often lose type safety in the process. “This is our take on RPCs,” explained Vercel Svelte core developer Simon Holthausen, in a Svelte Society podcast. Server-side, SvelteKit does the typical RPC stuff: validating incoming data requests, querying the database or other data source, and routing the serialized results back to the requesting component. The remote function, written in JavaScript or TypeScript, and compiled beforehand into a lightweight client-side RPC wrapper, performs a fetch call to the server from within the component itself. No special routing or additional boilerplate is required. “You don’t have to worry about where this code is running,“ said developer Scott Tolinski in an episode of a Syntax developer videocast enthusiastically entitled “SvelteKit has solved data loading.” The videocast hosts offered as an example a case where all the content on a site is static, except for a footer on the bottom of each page, which requires updated information. With remote functions, the footer component fetches and refreshes its own server data directly, keeping the data fresh. Traditionally, this would require the whole page either to be marked as dynamic (computationally costly, slow to load) or require the developer to write a top-down route loader (more brainwork, keystroking). “From within a normal Svelte component, you can just straight up import that query or mutation as a function, then call that function in your code,” Tolinski explained. The call is coming from within the client To be fair, the maintainers of Next.js have also addressed part of this problem with Server Functions (formerly called Server Actions), which allow client components to invoke server-side mutations directly. However, unlike SvelteKit's remote functions, Next.js Server Functions were primarily designed for writing data rather than fetching or querying it. Harris now works at Vercel, which sponsors Svelte but owns Next.js. Nonetheless, Vercel supports both approaches, each of which reflects “a broader convergence toward typed, server-side functions callable from the client,” a Vercel spokesperson told us. For Tolinski, though, the upside to Svelte’s remote functions is how seamlessly they fit into the overall Svelte framework. “I’m not saying no other RPC systems have done it as good as this, but it better be as good as this if you want me to use it,” he said. ®
Google pits Marvell against Broadcom as it chases AI crown
It's an open secret that the major cloud providers don’t actually design their custom silicon from scratch. There's not much value in reinventing the wheel, so they often outsource big and undifferentiated chunks of chip design to IP houses like Broadcom, Marvell, Arm, and others. Google's partner of choice for its Tensor Processing Units (TPUs) has largely been Broadcom — though the chip giant's involvement was only made public earlier this year. However, Google's relationship with Broadcom was apparently never monogamous. In an SEC filing this week, Marvell entered the chat, announcing that the Chocolate Factory had tapped the IP house to develop custom silicon for the search and advertising giant. Among the products slated for development were “custom silicon programs that attach to the TPU ecosystem” including AI inference accelerators, storage controllers, network interface controllers, memory interface controllers, and near memory compute. The SEC filing doesn't go into specifics as to which technologies Google will adopt, nor does it offer any insights into the cloud provider’s relationship with Broadcom. All of the technologies listed in the filing are ones Broadcom is more than capable of furnishing. It also doesn’t mean that Broadcom will stop building TPUs for Google, it simply means Google isn’t putting all its eggs in one IP basket. It's not unusual for cloud providers to acquire technologies from multiple vendors to ensure they're always getting the best deal. Networking is a prime example. Of course that didn’t stop Wall Street from dumping shares of Broadcom Wednesday, sending its stock price down about 4% as of late afternoon trading. Marvell clearly expects this deal to be a major revenue driver for the company going forward, and it issued Google a warrant to acquire nearly 59 million shares worth roughly $12.2 billion. Whether Google will actually exercise the warrant is an open question. Doing so would embroil the company in a years-long chip design collaboration. But, looking at Marvell's tech stack, it's not hard to see why Google might be interested. Over the past few years, Marvell has developed a comprehensive suite of hardware IP, including high speed SerDes used in network switches and NICs, multi-die XPU reference designs, CXL memory controllers, and silicon photonics interconnect. Google could have licensed all these things from Broadcom, but now they're in a position to pit the two companies against each other on price and performance. So where might we see Marvell's tech appear first? If we had to guess, Google's interest in Marvell may stem from the photonic memory tech it acquired from Celestial AI late last year. Unveiled earlier this month, Marvell's new Photonic Fabric NIC and Photonic Fabric chiplet technologies allow multiple racks up to 50 meters away to share a common memory pool. Google's TPUs rely on high-speed optical circuit-switched links to talk to one another. One could imagine Google using this tech to dynamically reallocate additional memory to different TPU clusters based on the workload rather than needing to attach memory in a fixed ratio. And because the link is optical, the memory in question doesn't need to be in the same system or rack; that memory becomes a fungible resource. Of course, this is all speculation. Marvell has no shortage of IP that Google might be interested in, including SSD and CXL controllers and XPU reference designs. Or could simply be that Alphabet CEO Sundar Pichai wants to avoid becoming overly reliant on Broadcom lest Hock Tan get any ideas like hiking up prices the way he did on virtualization tech following the VMware acquisition. Or could be that Marvell’s tech is just better for the specific use cases Google is currently developing for. ®
Dev taps Claude Code to craft custom printer driver for macOS
There's a new and very helpful use case for AI coding agents: designing drivers for devices, such as old printers, that were never meant to work with a particular operating system. Kuber Mehta, a New Delhi, India-based developer and founder of PolyThink, has published an account of how he coaxed Anthropic's Claude Code into creating a macOS driver for his HP Laser 1008a, for which HP offers only Windows and Linux drivers. "My HP Laser 1008a is a rebadged Samsung host-based printer that speaks a proprietary raster language (SPL3), and it has no macOS driver and no AirPrint," Mehta explained in a blog post. "So on paper it just does not print from a Mac. This is the (lightly redacted) transcript of me and Claude Code getting it working anyway." The GitHub repo for the driver – published under an open source MIT license – outlines the problem, which is that none of the common connection options work. There's no support for AirPrint, PostScript, or PCL (Printer Command Language), and SPL/QPDL drivers didn't work. What Mehta and Claude did was create a patch to SpliX, an open source driver for SPL2- and SPLc-based printers made by Samsung, Xerox, Dell, Lexmark, and Toshiba. Mehta's series of social media posts about the project appears to have touched a nerve. The discussion elicited appreciation for what people see as a positive use of technology, one that recognizes the finicky nature of printers and offers hope that old devices are potentially salvageable. Mehta's conversation with Claude Code took around 30-40 prompts and cost about 4 percent of his monthly usage. It's worth reviewing for anyone unfamiliar with AI model interaction because it illustrates how the model – Opus 4.8 in this case – makes confident statements that have to be corrected and often characterizes its remarks as "honest" (a behavior drilled into Opus 4.8). The project also serves to validate one of the often-cited benefits of AI tools – that they allow people to participate more broadly in the way they use software. Writing a device driver traditionally required specialized programming knowledge, and Mehta, by his own admission, "knew very little about macOS drivers but learned along the way." While it's fair to say that AI assistance encourages people to tackle tasks they're not really prepared to manage on their own, the sense of enablement is clearly catching, despite the technical debt being generated. Others have also used AI coding agents to come up with ways to make their printers more functional. Vercel CEO Guillermo Rauch articulated the sense of possibility that animates the AI-pilled in a social media post about the general utility of AI. "Every idea you shelved as 'too ambitious' is now back in play," he said. Indeed, every shelved idea is becoming software. There were about 1 billion commits to GitHub in 2025, according to Kyle Daigle, chief operating officer at GitHub. If current trends continue, that figure could reach 14 billion by the end of 2026. Enjoy the abundance while it lasts. ®
ICE boss to agents: Leave the Meta spy glasses at home
Some ICE employees seemingly needed a reminder not to wear their Meta pervert glasses to work. Because only ICE can spy on ICE. Meta smart glasses are essentially “body-worn cameras,” as they can covertly record video and audio, David Venturella, Immigration and Customs Enforcement acting director, reportedly reminded agency employees on Tuesday. “The use of Meta Glasses or similar devices could unintentionally capture, record or transmit sensitive information, potentially compromising privacy and legal protections,” Venturella said in a Tuesday memo, according to a New York Times report. ICE policy [PDF] prohibits employees from using personal body-worn cameras in the workplace. As such, ICE employees’ personal Meta glasses - along with similar wearable devices capable of recording audio or video - are banned from use on the job. An ICE spokesperson told us that ICE, on occasion, reminds its employees of existing policies like this one, and that the agency takes privacy and operational security seriously. “This isn’t news - nothing has changed,” an ICE spokesperson said. “Personally owned body-worn cameras and unauthorized recording are prohibited, as they always have been.” The spokesperson declined to answer The Register’s questions including what prompted the reminder and whether more ICE agents have been bringing their Meta glasses to work. Meta said it had no comment on the story. While the ICE policy isn’t new, the outright ban on Meta’s so-called pervert glasses has been trending upward since DEF CON told hackers to leave any glasses equipped with recording capabilities at home. “Be sure to pack non-violating eyewear if you need them,” DEF CON organizers told conference attendees ahead of the annual August event. Several restaurants, pubs, and private clubs including Soho House and UK pub chain Wetherspoons have also prohibited - or strongly discouraged - patrons from wearing these types of smart glasses in their establishments, citing privacy concerns. Apart from CCTV cameras, “the general code that applies in our pubs, and most pubs, is that you can't film customers or employees without their permission,” a Wetherspoons spokesperson previously told The Register. “Meta glasses seem to breach this code, and common sense, by enabling surreptitious surveillance, so our instinct is to say turn off the cameras.” Some National Basketball Association arenas have also reportedly told fans to go put their glasses with recording capabilities inside their vehicles and not wear them at NBA games. Meanwhile, the UK's privacy watchdog in March began investigating Meta's smart glasses after reports that human contractors reviewing recordings from the devices were exposed to extremely private moments captured by unsuspecting users. ®
Epic Games dismisses Apple's simplified EU App Store fees as 'junk'
Apple's latest attempt to settle its App Store dispute with the European Commission has drawn criticism from Epic Games and a cautious response from a consumer group, which warned that "the devil is in the detail." Announced on August 18, the changes introduce new business terms for applications distributed in the European Union. Apple says the changes "reduce complexity by moving every developer that distributes apps in the EU to a single set of business terms" and resolve its long-running spat with the Commission over fees and alternative distribution. An App Store app using Apple In-App Purchase will attract a 26 percent commission, reduced to 15 percent for developers in qualifying programs and auto-renewing subscriptions after their first year. The rate for apps using alternative payment processing will be 20 percent, or 10 percent for qualifying developers. Apps linking to the web to complete purchases will incur a 15 percent commission, again reduced to 10 percent for qualifying developers. Apps distributed through an alternative marketplace or the web will pay Apple a 5 percent "Core Technology Commission" on digital transactions. The structure is simpler than Apple's previous terms, which were revised after the company was slapped with a €500 million fine. Complaints about Apple's antics continued through the end of 2025 amid accusations that the company was persisting in non-compliance with the Digital Markets Act (DMA). Apple claims the changes follow "close collaboration with the European Commission" and "resolve Apple's disagreements with the Commission over business terms and alternative distribution." Naturally, there was plenty of hand-wringing and "think of the children" rhetoric from the iPhone slinger. The company would obviously prefer users to stick with Apple In-App Purchase, calling it "the safest, most trusted way for users to purchase and download apps and make seamless and secure payments in those apps." It also noted that it had worked with the Commission on child safety measures for alternative payments, including parental gates and restrictions on links from apps aimed at children. Epic Games, a longstanding critic of Apple's App Store practices, called the scheme "junk fees," adding that the plan did "nothing to open up the mobile app ecosystem to competition, as required by Digital Markets Act." "The law makes it clear that Apple must allow developers to offer link outs to the web for purchases 'free of charge' and has to allow 'effective use' of competing stores," the company wrote. The European Consumer Organisation (BEUC), an umbrella group representing 42 independent consumer organizations across 31 countries, was also cautious. Sébastien Pant, the group's senior officer for competition and digital enforcement, wrote: "On paper, there seem to be some improvements with a simpler and lower fee structure. But it remains to be seen if these commitments will satisfy app developers who will, in any case, pass on the fees to consumers. "We also need to see the full user flow to see if consumers will truly benefit. For example, will consumers be able to easily conclude contracts with app developers on iPhones outside the App Store without having scare screens displayed? Will it be possible to easily download and use alternative app stores on iPhones and iPads without the artificial friction Apple deliberately created? "Also, we must remember this is not a gift Apple is giving consumers, but something they are required to do so by EU law. It might be a cliché, but the devil is in the detail!" Developers can sign the new terms immediately, with the changes taking effect on October 1. ®
Flock surveillance backlash mounts as fiendish Halloween plans circulate
Surveillance tech company Flock has struggled with its public image for years, but the problem has become particularly acute in recent weeks. Its network of ALPRs has long attracted criticism over mass surveillance and the retention of location data belonging to motorists who are not suspected of any offense. Days after its CEO apologized for documented abuses of the company's system, The Register contacted the company's usually responsive media team about an online campaign calling for its automated license plate readers (ALPRs) to be vandalized on Halloween, and received an automated response. "Thanks for reaching out to Flock. Our media team is currently touching grass and taking a break," the email said. "Unlike our cameras, we can't work 24/7, so we'll get back to you when we've had a snack and regained the ability to form coherent sentences." The media handlers have a lot on their plate. More recently, reports of ICE agents accessing local police forces' Flock systems, and police officers using the technology to stalk former partners, have coincided with an increase in vandalism targeting the cameras. This week, US social media users began promoting Halloween 2026 as a night of action against Flock's ALPRs, which continue to attract negative coverage. X grouped posts about the so-called "De-Flock America" campaign into a dedicated trending story, which recorded more than 36,500 posts over two days. Similar calls have appeared on other major social platforms. Posts encourage participants to wear costumes, leave their smartphones at home, and disable nearby ALPRs while concealing their identities. The Reg asked Flock whether it was aware of the campaign and planned any countermeasures, but received only the automated response. Apologies and changes Last week, Flock CEO Garrett Langley apologized after a woman was stalked using his company's ALPR system. "It kills me that she went through that," he told CBS News in an interview, less than two weeks after The Washington Post published a story highlighting 46 cases involving US police officers abusing their access to Flock's system. Some allegedly involved officers abusing that power to stalk women. Langley gave the interview after Flock announced an array of changes, including reducing its standard data retention period from 30 days to seven. Customers may retain information for longer, however. A new "Evidence Mode" allows law enforcement to retain data beyond that seven-day period if it's required for ongoing casework. Flock also introduced controls allowing police agencies to restrict the types of searches that outside forces can run against their data. For example, City A might request permission to search data belonging to City B as part of an investigation. With the new feature, City B can restrict City A from making searches related to "immigration enforcement," a nod to ICE agents accessing police Flock systems without a dedicated contract. Flock will also require customers to enable its existing Audit Assistance feature by year-end. The tool detects unusual search activity and flags it for review. It is currently optional but will become mandatory by year-end, having been "associated with arrests of several law enforcement officers who allegedly abused the system." Flock said more than a third of customers have voluntarily opted in to Audit Assistance so far. Langley's interview appeared one day after People reported that Haines City police officer Christopher Goodson, 31, allegedly used Flock to search for his estranged wife's license plate 717 times. The searches took place between September 1, 2024, and June 30, 2026, according to a probable cause affidavit. Goodson was suspended with pay pending further investigation. ®
More than half of Americans now view AI negatively
Attitudes towards AI are shifting in America. More than half of adults now say that they are more concerned than excited about the technology, and that includes those under 30 for the first time. This comes from a survey conducted by the Pew Research Center, which says that concerns over potential job losses caused by AI are the main factor influencing opinion. It found that 71 percent of US adults think AI will lead to fewer jobs in their country over the next two decades, up from 64 percent two years ago. And just 5 percent believe the optimists who say AI will lead to more jobs. 10 percent think it won’t make much difference, and a slightly larger share are unsure. The non-profit think tank says that worries have been expressed about employment ever since it started asking this AI question back in 2021, but back then, more people were excited (or a mix of excitement and concern) than were concerned by the technology. Since those days, the number who were more excited has halved (18 percent to 9 percent) while those with issues have now risen to 52 percent. They could be right – Forrester Research was forecasting earlier this year that AI and automation could erase 6.1 percent of jobs in the US by 2030. The situation is even more stark among young adults, where 55 percent of those aged 18 to 29 are now concerned, up from less than a third in 2021. Their concern is now on a par with those in their 30s and 40s, and those aged 65 and up. Across most age groups the trend has been for Americans to increasingly foresee job losses from the use of AI in business. Pew points out that 73 percent of adults under 30 now say AI will lead to fewer jobs, up from 61 percent two years ago. Perhaps this isn’t surprising, as AI automation is often pitched as a replacement for some of the entry-level roles that workers in the under 30 age bracket are likely to be starting out with. Americans 65 and older are a bit less likely to think AI will lead to fewer jobs in this latest survey, but this remains the majority view among this age group. Adults under 30 are also more likely to think AI will be bad for society. They believe it will make connecting with others more difficult and creativity harder to come by, according to Pew. While most young adults say they use chatbots, they are just as likely to say that these tools hurt their creativity as help it. Perhaps US workers can take some comfort from Anthropic, which says that AI is not eliminating as many jobs as experts had predicted. Or else move to China, where a court has ruled that it is illegal to replace human workers with AI. ®
ISS spacewalkers discover there's no such thing as a quick antenna job
Stubborn electrical connections and bolts thwarted an attempt to replace an antenna on the International Space Station (ISS) yesterday, forcing spacewalkers to leave the new unit for another day. We've all been there. That "quick job" expected to take a few minutes stretches into hours as bolts refuse to budge and unforeseen problems eat into time better spent enjoying a cookie and tasty beverage. A pair of ISS spacewalkers had much the same experience yesterday. Removing a faulty antenna from the orbiting outpost took longer than expected, leaving too little time to install its replacement. NASA's Anil Menon and European Space Agency astronaut Sophie Adenot were carrying out the work. The spacewalk had already been delayed after a carbon dioxide sensor in the suit Menon wore during an August 6 spacewalk produced an unexpected reading. The sensor returned to normal after Menon removed the suit. The August 18 excursion made Adenot the first French woman to perform a spacewalk. She and Menon ventured out of the station's Quest airlock to replace the failed space-to-ground antenna. Menon rode on the Canadarm2, while Adenot remained tethered to the station's truss structure. They were to remove the failed antenna, install a spare stored on an external platform, and stow the old unit. Alas, it wasn't quite that simple. Disconnecting electrical cables and loosening bolts took much longer than expected. The pair removed the antenna and secured it temporarily, but managers called time before they could install the replacement. Space-to-ground antennas provide high-data-rate communications through NASA's Tracking and Data Relay Satellite system. The ISS has another fully operational unit, but managers will want to restore the redundancy promptly. The next spacewalk is scheduled for Tuesday, August 25, although NASA has not said whether the unfinished antenna work can be added to its planned tasks. ®