Google’s parent company Alphabet is managing its fleet of AI accelerators to prioritize research on artificial general intelligence, rather than renting them all to customers. CEO Sundar Pichai revealed the company’s priorities during its second quarter earnings call, during which the company confirmed it has delivered on its plan to sell its tensor processing units (TPUs) to some customers. In response to news of those sales, Goldman Sachs analyst Eric Sheridan asked how Alphabet balances demand from customers who want to buy its TPUs and the web giant’s own need for processing power. “In terms of allocating our TPUs … our first priority is making sure we are allocating what we need to compete at the frontier in terms of AGI development,” Pichai replied, referring to Artificial General Intelligence –AIs that possesses human-like intelligence. “That is the foundation for everything we do,” Pichai added. Another analyst, Mark Shmulik of Bernstein, revisited the matter by asking how Google allocates processing capacity among its search business, cloud operation, and model training efforts. “On allocation, I think the baseline with which we start is what it takes to continue AGI development at the frontier,” Pichai responded. The CEO said Alphabet is also “prioritizing our core product areas like Search, YouTube, et cetera, as well as Cloud.” And in the G-Cloud, Google is “prioritizing the compute to make sure we can serve our models in the context of Vertex and Gemini Enterprise, and our core solutions, be it data analytics and cybersecurity.” “Our core services for our core products across consumers and enterprises is where the compute is primarily going, and that’s how we think about it,” the CEO added. Google’s core services are going gangbusters. Google Cloud revenue leapt 82 percent year over year, to $24.75 billion for the quarter, and delivered an $8.8 billion profit which represented 214 percent growth. The Big G said that growth came from “strong demand for AI infrastructure and AI solutions.” There’s probably more to come as the G-Cloud now has $514 billion of cloudy backlog on the books, meaning customers have signed up for services they’re yet to consume. Search revenue grew 17 percent and YouTube ads grew 13 percent. When generative AI came along some pundits suggested it could threaten Google’s search ads biz. That was not a good take because Pichai said the company’s AI Mode for search is “driving an incremental increase in Search queries overall.” AI search needs specialist hardware that is expensive to buy and run. Pichai said Google is on top of that. “Thanks to our engineering and hardware optimizations, this quarter we reduced the cost of AI Mode responses to its lowest level since launch, even as we’ve brought more advanced AI capabilities.” Google continues to spend megabucks on AI infrastructure – CFO Anat Ashkenazi said the company now plans to spend between $195 billion and $205 billion this financial year, up from a previous estimate of $180 billion to 190 billion. Ashkenazi said Google can’t get all the kit it needs due to what she described as “the supply-constrained environment.” Google therefore plans to “expand the use of third-party capacity in Q3 as a bridging strategy while we build out more internal capacity.” Pichai said buying bridging capacity will help Google to land monster cloud clients. “There are very, very large customers of ours on Cloud who we are trying to support them through this extraordinary moment,” the CEO said. “The incremental opportunities they are bringing to us, while a short-term cost over a few months may be very high, in the lifetime of the deal, as we bring more capacity on, is highly ROI positive.” “Those are factors we are taking into account. Are you willing to take upfront six-month deal to be able to serve that customer in what is a multi-year opportunity, where the margins and the returns are very, very attractive over that multi-year horizon?” Alphabet’s quarterly revenue landed at $119.8 billion, up 24 percent year over year. Operating income hit $40.8 billion, up 34 percent. Yet even those torrents of money couldn’t stop Google’s free cash flow landing at -$5.9 billion – the first time the company hasn’t had spare cash to splash since 2004. Investors seem not to like that and sent the price of the company’s shares down by four percent in after hours trading. ®
OPINION OpenAI has acknowledged its models powered the autonomous agents that compromised HuggingFace infrastructure. It might be taken as a convoluted marketing stunt, were it not the perfect advertisement for China-based competition. The company's AI-culpa fits the narrative spun by US rival Anthropic about its Mythos models, which it deemed too dangerous to release except to totally trustworthy corporations and governments. OpenAI says: "The incident makes clear that advanced models can discover and exploit novel attack paths in real-world systems without source-code access. It highlights that advanced cyber capabilities must be developed alongside stronger safeguards and defensive tools." Are we surprised? It's been clear that AI models have the potential to go rogue and damage computers for several years. Academics have repeatedly warned about this possibility - even those affiliated with OpenAI and Anthropic. And anyone who has used AI models for software development has probably seen them code unexpected and perhaps unwanted workarounds to fulfill some directive. On Tuesday, the UK's AI Security Institute published findings about how frontier models all cheat. OpenAI's admission that its models devised a sandbox escape to obtain internet access and found a zero-day flaw to exploit, all to solve a benchmark evaluation problem, may be unprecedented in terms of the scale and prominence of the systems affected. But it's a reenactment of every Claude or Codex prompt in which the model responds to a disallowed command by trying an alternative. We were warned. The compromise of HuggingFace's systems is no more surprising than locking a bear in a supermarket and finding a mess the following day. AI models are billed as artificial intelligence, but when they power agents handling tools in a loop to achieve some objective, it's the equivalent of a brute force attack – the agent will keep trying things until something works or breaks. The surprising part came when HuggingFace sought to employ US frontier models to defend itself. It failed. That should raise eyebrows. "When we started the log analysis, we first used frontier models behind commercial APIs," the AI model-mart said in its blog post last week. "This did not work: the analysis required submitting large volumes of real attack commands, exploit payloads, and C2 artifacts, and these requests were blocked by the providers' safety guardrails, which cannot distinguish an incident responder from an attacker." Stymied by model refusals – which developers have been complaining about for months – HuggingFace had to rely on GLM 5.2, an open-weight AI model made by China-based Z.ai, to conduct its forensic analysis. And it did so on its own infrastructure, so nothing sensitive got sent to a cloud-based model provider. Coincidentally, the leaders of OpenAI and Anthropic have reportedly been warning the US government about the threat posed by increasingly capable Chinese models like Kimi K3 and GLM 5.2. And the US government is said to be mulling possible responses to limit competition from China. That won't work. It's just naïve to think that the US government and a handful of worthy organizations – however that is defined – will be able to enforce a global monopoly on highly capable AI. The infrastructure required to run open weight models that more or less rival the current state of the art is available for a price. And potential consumers of those services are not going to be satisfied with model refusals when there are other options, particularly if they're more cooperative and more affordable. The best course for governments, industry, and the public is to push for AI services that are open and available to all. For that to work, lawmakers around the world need to act fast to set some common ground rules that grapple with AI's impact on jobs, and find a way to compensate those whose work fuels machine learning. Some industry leaders appear to realize that. David Sacks, an external White House adviser and tech investor, recently urged Silicon Valley to rally around openness. "The leading closed labs, already a duopoly in terms of AI model revenue, want the government to eliminate their open source competition," he wrote in a social media post. "They have laid their cards on the table. It is time for the rest of Silicon Valley — the vast majority that still values open competition — to do the same." The fact is that US AI companies have sandboxed themselves into a corner: They've created demand for a product that they can't be relied upon to provide. And when they do make their most capable AI models available, they hobble them and demand terms tailored to serve their vast debt rather than their customers. OpenAI said that it has invited HuggingFace into its trusted access program so the company can use its most capable models. Chinese AI companies, meanwhile, have invited the world. ®
Since the beginning of the year, several people have remarked to me off the cuff, apropos of nothing in particular: "Google Cloud is killing it." Parent company Alphabet reported Q2 earnings [PDF] after the bell on Wednesday and the numbers speak for themselves. Let's go to the tape: Google Cloud revenue was up 82 percent from the same quarter last year, increasing from $13.6 billion to $24.8 billion. Google Cloud operating income more than tripled during the same period, going from $2.8 billion to $8.8 billion. Once the distant-third-place laughingstock of the IaaS platforms, Google's cloud business is now the growth engine of Alphabet and a significant contributor to the company's overall business, making up 21 percent of revenues and 22 percent of operating income. How'd this magic happen? The company's claiming it's all AI, citing "demand for AI infrastructure and AI solutions." We have no idea if that's actually the case, given the plethora of more prosaic offerings from the Google Cloud team, but the company's Gemini marketing strategy – pushing it in front of hundreds of millions of searchers every day – can't be faulted. Informal checks against our own sources suggest Anthropic Claude remains the go-to frontier model for most enterprise customers, and we're definitely hearing about companies switching between models to make the most of token costs vs effectiveness. But when the AI bubble finally pops, it could bring down money-losers OpenAI and Anthropic, and maybe even Oracle, which has gotten in a bit too deep. Google, like the janitor at the end of the universe, will be there to pick up the pieces – and talent. ®
HANDS ON If you've got a drawer full of old phones, unloved tablets, or even an ancient monitor, you can now give those devices new life in your home by turning them into wall-mounted status boards, clocks, weather stations, or photo frames. ScreenWall is a web platform developed by German software engineer Tuan Anh Bui that’ll turn any compatible device with an internet connection into a widget display without the need to install anything. If you can scan a QR code, you can have that old device displaying any number of things in no time. “Use it to build clocks, status boards, ambient screens, signage, and shared walls from the hardware you already have, without asking people to install anything first,” Bui says on the app’s website. Currently in beta and free for users (with some restrictions on the number of widgets one can deploy), ScreenWall comes with a number of demo widgets, like a clock, weather display, and a split-flap screen able to display various types of information. You can customize pre-existing widgets with some JavaScript tweaks, which is how new ones are written as well, and you can connect data sources via JSON files. Placing a widget, whether preconfigured or homemade, is simple: Add it to a workspace (called a “wall”), and it’ll sit waiting for a display to be paired with ScreenWall, which is done by either scanning a QR code from a device with a camera, or clicking on a link and inputting a six-digit code for devices that lack one (like an old monitor paired to a thin client, no matter how ancient). Once paired, ScreenWall detects the device’s resolution and shows it on the wall as a blue square. Drag it over the widget you want it to display, and that’s that. The screen won’t go to sleep or shut down as long as the ScreenWall widget is present, as it uses the standard Screen Wake Lock API baked into modern browsers. Just connect it, get the widget fitting properly on the screen, and set the device up wherever you want - preferably somewhere with access to a power outlet. What it offers in simplicity and device reusability, ScreenWall also lacks in terms of seamlessness that might make it a tough sell to replace that ticket status board that might be getting long in the tooth. Devices connect via a web link and are presumably running a full-fledged OS, so any reboot of a system means the device has to be re-paired in order to function. When testing at home, closing the ScreenWall tab on my iPad showed the device as offline on my wall, and the only way I could figure out to reconnect it was to scan the QR code again. Because the code is randomized each time you open the screen, reconnecting my iPad meant adding a third display to my wall, creating a bit of chaos as it re-created the clock widget I had displayed on my iPhone, dropping it on top of the picture of my chipmunk friend and necessitating some manual adjustment. When I put my iPhone to sleep without closing the ScreenWall tab, it similarly said that the display was disconnected. Unlocking my phone and navigating to the ScreenWall Safari tab brought the clock widget back up. So, as long as that tab stays open, reloading the widget should work more easily. Bui confirmed to The Register that devices maintain their unique identifier as long as the tab isn't closed, so be sure you don't get rid of that if you intend to deploy a ScreenWall widget for long-term use. It’s also important to note that, if using an old smartphone, tablet, or some other smart device set up to receive notifications, those still pop up. ScreenWall doesn’t put a device into do-not-disturb mode by default - don’t forget to set that if you’re going to try this out. As Bui noted, it's on the user to ensure "do not disturb mode" is set properly. A simple web app like this one simply doesn't have that level of device control. As Bui notes on the ScreenWall website, the platform “is still in beta, which means the core experience is usable, but we are still improving stability, compatibility, and polish.” Feel free to tinker with it, in other words, but don’t go tossing those old devices on every wall you can find just yet unless you’re ready to do some legwork to keep ‘em running. Bui told us that he still hasn't come up with a monetization plan, but that he does plan to address concerns that people may have about running a hosted service. "I want to prevent people from throwing old tech away, and the tinkerer community are kinda privacy focused and want to use their beloved devices offline," Bui said in an email. "That’s why I am currently thinking of to publish a self-hosted version that users can run locally." Beyond that, he told us, he's not sure where to take the tool next. "This project was built out of curiosity and scratching an itch I had really long time ago after seeing all old phones going to waste," Bui explained. "I still don’t know who actually wants this except me." As for what might get added once stability, compatibility, and polish are addressed, that might be up to the community. "I hope to see people to do very cool things with it, while I try to extend the platform with new features." ®
OPINION Cory Doctorow, tech gadfly and coiner of the eminently relevant term "enshittification," posted a useful argument on Wednesday related to Trump's dismantling of the US-led world order and the need or lack thereof for other countries to control their own AI destinies. Doctorow has positioned himself as an AI skeptic in his writings, including his recent book, The Reverse Centaur's Guide to Life After AI – the name comes from the visualization of a human body (you and me, humble users) being led by a mindless horse's head (AI) – and this latest post fits into that vein well, calling the need for a sovereign AI "nonsense." The conversation began with a post from Australian writer John Quiggin, who explained how the US president is systematically dismantling all of the sources of the United States' strength over the last century – diplomatic, military, financial, and, most relevant to Reg readers, technological. Quiggin posited that the current American dominance of AI poses a particular risk to the rest of the world, which understandably doesn't want to rely on a chaotic and unpredictable American state, although even he was skeptical that the frontier labs' Vegas binge-spending approach would necessarily pay off: "My optimistic view is that this is a race that will be won by low-energy tortoises rather than hyper-active hares. Second movers like Deepseek and, more recently the French Mistral, running maybe a year behind the US leaders, can replicate their capabilities at a fraction of the cost, and without reliance on massive data centres." Not wrong, in our view, as our systems editor Tobias Mann recently opined. But as Doctorow points out, that is only relevant if you believe AI is relevant. And Doctorow clearly does not. He notes that if Trump were to suddenly turn off all the AI chatbots being used by other nations, it probably wouldn't damage their businesses in any significant way. But if he were to order Microsoft to disable Office 365 or John Deere to brick its tractors, that would have an immediate, measurable economic impact. As he put it: "In the face of these real, non-speculative, immediate, grave threats, focusing on AI – the money-losingest technology in human history, which has consistently underperformed relative to its boosters' promises – is just misguided … The real digital challenge is building apps and data centres to run everyday administrative, telecoms and e-commerce software on, and then moving your country's, ministries', companies' and households' data over to the new platforms." Amen to that. AI may or may not be the future – it's certainly a lively topic of debate at Vulture HQ – but there's a clear and present danger, and American tech companies have made it abundantly clear that they will not speak or act out against the president or US government until and unless the shifting political tides dictate it's advantageous for them to do so. Same as it ever was. Europe would be wise to invest in alternatives wherever it can. ®
After cutting over 4,000 jobs due to AI, fintech biz Block is back with Buzz, a shared workspace where humans and bots can collaborate in ways that are more auditable, sovereign, and secure than what you can do in chat tools such as Slack. Block's human-bot co-op is built upon a turducken of tech jargon: The platform is free and open source. It's based on the decentralized Nostr protocol, so there's cryptographic identity. It's "sovereign," a naively optimistic term readers of Neal Stephenson's Snow Crash should recognize, which in this context means self-hostable. And it's intended as a replacement for Slack, GitHub, and various other communication and collaboration tools. If "Buzz" sounds familiar, that's because Google used that name in a social media faceplant more than 15 years ago. For those who missed the first go-around, Google Buzz, a failed social media service, gave rise to Google+, also a failed social media service. Block appears to believe that a decade and a half is sufficient for a brand cleanse. The project's GitHub repo offers a more apologetic assessment: "Yes, it's another AI-adjacent developer tool. We're sorry. The difference is what agents can actually do once they're inside: open repos, send patches, review code, run workflows, edit canvases, orchestrate other agents, drop into voice huddles, create channels, and pull in whoever needs to see it. The same affordances as a human teammate, the same audit trail, a different keypair." You can already sic software agents on collaborative workspaces. Block's main insight is that it would be useful to link AI agents with cryptographic identities. Others have already arrived at that conclusion. Hence OWASP's Agent Name Service, DNS for AI Discovery, Estonia's digital IDs for agents, and so on. But Buzz's badging of humans and bots with cryptographic key pairs is bound to tick governance boxes. "Every company is going to need a place where humans and agents work together," said Bradley Axen, head of AI capabilities at Block, in a statement. "The question is whether that place is proprietary or open. We built Buzz because we believe it should be open." Moat-seeking tech incumbents would probably disagree about the need for openness, even though they're fond of using the word without applying it. We note that OpenAI sells closed AI. And Anthropic's decision to disallow third-party tools from using Claude subscriptions highlights the seemingly inevitable path from openness to barriers when revenue is at stake. What's more, it's not obvious that every company will need people and bots in the same space. There's a strong case for keeping humans and agents apart because they work at different speeds. Git at least was built for handling many distributed code edits, pull requests, and merges. It's hard to see how people and bots can share a text-based communication space unless the bots are rate-limited or just talk among themselves. "The bet is that one community can do what teams currently fake with chat, forges, bots, CI dashboards, release tools, search indexes, and a pile of glue code," Block's Buzz developers state. "Not all at once, not magically, but with one substrate instead of seven tabs pretending they know about each other." If tools for these sorts of things didn't already exist, and no large tech companies had designs on this space, Buzz might face less daunting odds. But it's worth a shot. ®
If you're responsible for Linux security, someone just dumped a pile of work onto your desk: 432 Linux kernel CVEs were published across Sunday and Monday this week. Linux watchers at nixCraft pointed out the volume on Monday morning, and it didn’t take long for seasoned sysadmins to start expressing concerns. Jan Schaumann, chief information security architect at Akamai Technologies, took to the OSS-SEC mailing list Tuesday to express concerns over the sheer volume of Linux kernel CVEs published in recent days. Aside from noting that the CVE system isn’t the best way to track security changes, Schaumann also wondered in his post whether there was any good way to deal with so many kernel security issues. “This onslaught really shows it's not feasible to attempt to prioritize individual kernel changes,” Schaumann said. “You might attempt to process this large set of changes by pointing an LLM at the intake and asking it to prioritize them,” he suggested, “but if it spits out a dozen today and another 25 the next, you haven't won much.” Schaumann also suggested waiting to see which ones emerge as serious issues and focusing on those in the weeks to come, or updating one’s entire fleet of Linux machines on a weekly basis. “I sure would like to be able to do [that], but reality keeps getting in my way,” Schaumann said. “I'm not sure what to do here going forward.” In an email to The Register, Schaumann said that individually reviewing vulnerabilities for patching was already difficult enough before things rose to this level, and that automation may be the only option - but it's not a great one. "Automated, regular, and frequent updates that pull in all changes within a given time window of tolerance seem to me the only reasonable approach, but that is very difficult for many large organizations," Schaumann explained. Those orgs often rely on lengthy QA processes, slow and staged development cycles, and may even have contractual requirements for long-term support that make an automated approach an impossible one. The nixCraft team speculated on social media that AI bug reports are a likely reason for all those kernel CVEs, which wouldn’t be without precedent - Linus Torvalds himself said in May that the Linux kernel security mailing list had become “almost entirely unmanageable” due to AI-assisted bug hunting. Nonetheless, Torvalds has described AI as a useful tool for Linux development while still noting it can be a drag for maintainers, both from a workload standpoint and the fact "it keeps finding embarrassing bugs." On that note, it's worth understanding what a Linux kernel CVE actually means - many of the vulnerabilities included in the Sunday-to-Monday batch are small in scope, but they're vulnerabilities nonetheless. As senior Linux maintainer Greg Kroah-Hartman noted in a February blog post, the Linux kernel CVE team follows the CVE Program's definition of a vulnerability: a weakness in a product that can negatively affect a system's confidentiality, integrity, or availability. “At the level that the Linux kernel runs, almost any type of bug that can affect a running system can be classified as a vulnerability,” Kroah-Hartman noted. The kernel team looks at every bugfix that is added to stable kernel releases, he added, and if it fixes an issue that meets that CVE criteria, a CVE is assigned. AI-assisted bug hunting has increased the volume of reports reaching Linux kernel maintainers. We reached out to the Linux kernel team, but didn’t hear back. Kroah-Hartman did tell The Register earlier this year that AI bug reports had become worthwhile in recent months, and he predicted they're likely to keep adding to his workload. Unfortunately for Linux sysadmins, the position in which they find themselves in this current mess isn’t one that’s readily solved. CVEs might be a messy way to track and prioritize security updates, especially when hundreds of them are published over a short period, but without something better, it falls to IT and security teams to determine which vulnerabilities affect their systems and which kernel updates they need to deploy. Hope you’ve got the coffee machine filled up: The onslaught is unlikely to ease if other recent patch cycles are any indication. ®
Scientists may have found the first moon outside our Solar System – depending on what astronomers ultimately decide counts as one. Either way, the groundbreaking research, published in Nature this week, promises a path to clearer sightings of so-called exomoons. Kevin Hoy, a PhD student affiliated with Universidad Diego Portales and the European Southern Observatory in Chile, has found an object orbiting a brown dwarf, which in turn orbits a host star, which sits about 73 light-years from the Sun in the southern celestial hemisphere. Brown dwarfs present a problem for astronomers. They fill the gap between gas giant planets – like Jupiter or Saturn – and the smallest stars. They are not massive enough to sustain the hydrogen fusion that powers the Sun and other main-sequence stars, although they can fuse deuterium, a heavier isotope of hydrogen. That leaves the object found by Hoy and his collaborators in a definitional gray area. "This is the first time, to our knowledge, this technique has produced evidence of satellites around a companion brown dwarf," the paper said. The first confirmed exoplanets were discovered orbiting a pulsar in 1992, but exomoons have so far proved elusive, despite there being hundreds in our own Solar System. The researchers found that the new object, which for now they are calling an exosatellite, is decidedly unmoon-like, being at least as massive as Jupiter. The brown dwarf it orbits is around 30 times the mass of Jupiter. "This system is somewhat hard to define using Solar-System-based words like 'planet' and 'moon,'" Hoy said in a statement. "The exosatellite is clearly massive enough to be a planet, but it does not orbit a star, though it orbits an object that orbits a star. Being the third wheel in this system makes us want to call it a moon, even if it is nothing like the small, rocky moons we have in our system." The research team employed the radial velocity method used by Michel Mayor and Didier Queloz to discover 51 Pegasi b in 1995, the first exoplanet found orbiting a Sun-like star. The technique detects the gravitational "wobble" induced in a host object – usually a star, but in this case a brown dwarf – by something orbiting it. Modeling of the data indicates that there is at least one orbiting satellite. Models for two satellites are possible but highly unstable. Whether a moon or not, the object has a minimum mass about nine-tenths that of Jupiter and completes an orbit every 170 days. "Although it is uncertain whether this exosatellite will fulfil the presently undefined criteria for qualifying as an exomoon, it is a marked step towards that first uncontroversial detection, as advancing technology will allow the same method to be applied to less massive targets," the paper says. At roughly Jupiter's mass, this is no forest moon of Endor. Finding something more like the moons in our own neighborhood will have to wait for sharper instruments. ®
Tesla's latest vehicle has two wheels, no motor, and a target market still mastering walking: the $225 Balance Bike for Kids. The contraption, designed for children aged two to five, "features a lightweight magnesium frame, adjustable seat and futuristic design," and can handle up to 35 kg. The price tag puts it at the higher end of such devices. Cycling Weekly recommends the Hornit Airo at £139, although there are plenty of alternatives aimed at introducing children to two wheels. Although a manually powered bicycle might be a surprising choice for Tesla, a company that made its name selling electric cars, there is some historical precedent – Morris and Triumph, for example, both began in the bicycle trade. Still, a Tesla fan and their money are soon parted. The company says preorders open on July 31, although only existing Tesla vehicle owners are eligible to buy one. The determined can already find units on auction sites. We spotted one on eBay that would set a buyer back a cool $1,200 plus shipping from the US – quite a premium for a toddler to learn how to use a bike. Then again, another Musk venture persuaded fans to queue up for a $500 "flamethrower" that was really a glorified blowtorch, so perhaps a four-figure toddler bike isn't such a hard sell. In this case, lessons learned about balance might prove useful when it comes to landing a Starship on the lunar surface or training the Tesla Optimus robot, which took an embarrassing tumble at a Miami event last year. It is also worth wondering just how old those kiddies, about to receive their Tesla Balance Bikes, will be when SpaceX finally manages to land a crew in a Starship on the Moon. ®
You've got an idea for an Excel spreadsheet, but building it is another matter. Microsoft's Copilot can help, and now SpaceXAI is offering an alternative: the Grok add-in for Excel. Available on the Microsoft Marketplace, the add-in places a sidebar in Excel that can "search the web, update spreadsheets, or build powerful financial models," according to the product description It isn't without cost. The add-in is currently available for SuperGrok, Heavy, Business, and Enterprise plans, although, as xAI states, the Microsoft 365 add-in itself is free. xAI is parking its tanks on Microsoft's Copilot lawn with the add-in, although the level of integration is quite a bit lower. For example, in 2025, Microsoft announced a COPILOT function in Excel allowing users to invoke its assistant at the workbook cell level. At its most basic, Grok turns prompts into workbook actions. However, we'd strongly recommend that a human review the results, just in case the AI has spewed nonsense. Grok, the AI that spawned MechaHitler and non-consensual deepfake nudes, hit version 4.5 this month and xAI claimed it was "capable of building complex Excel models." Grok Build was then caught sending entire repositories to the cloud, before boss Elon Musk stated that Grok Build CLI would be open source. All of which should give users pause before installing the component. Microsoft warns: "When this app is used, it can read and make changes to your document, can send data over the internet." The add-in inserts a button on Excel's ribbon to show the Grok pane. Text can then be entered. We asked it to "create a chart showing SpaceX stock performance since IPO, with the y axis showing value and the x axis showing time." Grok said it had reached usage limits and suggested that we upgrade our plan. Thinking that might have been a bit complicated, we tried simpler requests, all of which failed, confirming that a subscription is indeed required. This puts Grok up against some tough competition. Copilot is deeply entrenched in Microsoft's Office applications, and Google is not shy about promoting Gemini in its productivity tools. Organizations that already have a Grok subscription might get some value from the add-in, but others are spoiled for choice when it comes to AI assistants in their productivity applications. An Excel esports championship for AI assistants, anyone? ®
Having popularized AI with the cheapskate masses, OpenAI has turned its attention to enterprise customers who might actually pay for its services. The debt-fueled maker of frontier models on Wednesday announced the debut of Presence, a web service designed to make it easier for enterprises to deploy AI agents for a handful of common business tasks. "Today, Presence supports real-time experiences across voice and chat, such as customer support, outbound sales, and high-risk internal workflows," the company said in a blog post provided to The Register. "A customer might use it to resolve a billing issue – from understanding the request and verifying the customer to looking up account information, applying company policy, and taking an approved action." Presence lets companies set policies and governance controls to determine how agents behave, so that orgs can have some degree of reassurance that AI banter will remain polite, professional, and pertinent to the task at hand. The control interface includes an agent editor, an agent playground, and a tool for simulating how an agent handles tasks like customer refunds, order status queries, account deletion, and other administrative interactions. Rather than releasing another self-service API, OpenAI is making Presence available through its consulting arm, the OpenAI Deployment Company and Forward Deployed Engineers, a tech installation workforce that debuted last year and was bolstered by the acquisition of consultancy Tomoro in May. "Deployments are led by OpenAI Forward Deployed Engineers and select global systems integrators," OpenAI said. "Presence is not yet available as a self-serve product." OpenAI insists it has been dogfooding Presence, which now runs its AI English phone support channel. "It can understand open-ended requests, verify a caller’s identity when needed, use relevant account context, and take approved actions – including resolving billing issues, making account changes, and processing eligible refunds," the company said. "When a request requires human support, it can bring in a person." That may occur more frequently than OpenAI would like. Tech consultancy Gartner last month predicted that by 2027, half of organizations that were planning to shift customer service to AI will abandon those plans. "While AI offers significant potential to transform customer service, it is not a panacea," said Kathy Ross, senior director analyst for the Gartner customer service and support practice, in a statement. "The human touch remains irreplaceable in many interactions, and organizations must balance technology with human empathy and understanding." Undeterred by Gartner's skepticism, SoftBank, which is so enthusiastic about OpenAI's prospects that it has committed $60 billion to the AI biz, appears to be enthusiastic about AI's appeal for customer service. "Through our collaboration with OpenAI, we are exploring how Presence can enable trusted customer agents that communicate naturally, connect to the processes needed to resolve requests, and represent SoftBank consistently across customer interactions," said Tadahisa Murakami, VP and head of SoftBank's data and digital transformation division, in remarks provided to The Register. "Our frontline teams have rated the agent’s Japanese-language conversations highly for their natural and accurate quality." One reason SoftBank might be optimistic about Presence is that it costs actual money, which is vital as OpenAI attempts to cover the costs of its massive datacenter buildout commitments and work towards eventual profitability. "During this limited GA phase, deployments are scoped individually based on each customer's use case and implementation needs," an OpenAI spokesperson said. "Broader pricing details to come as availability expands." Presence is available to eligible enterprise customers, but OpenAI insists it will continue to support existing voice customers who access its models via API. ®
EXCLUSIVE A Windows information-stealer targeting more than 300 applications comes equipped with a novel surveillance tool: an AI profiler that ranks infected victims so crooks know who to target first. Varonis Threat Labs spotted the new stealer and remote access trojan (RAT), called Dolphin X, for sale on a cybercrime forum, and shared their research exclusively with The Register. The ad for the malware claims it can target upwards of 300 applications and has the ability to bypass browser passwords and steal enterprise credentials, cryptocurrency wallets, .env files, SSH keys, cloud tokens, and DevOps secrets. Dolphin X also promises users a super-sneaky surveillance feature called the AI Profiler. It scores infected users by app usage, browsing history, and installed software, and sends the cybercriminals a daily summary that ranks victims’ based on the likely payoff from an attack. “There's two things that stand out,” Daniel Kelley, a senior threat researcher with Varonis, told The Register. “The first thing is the AI profiler. That's something I've never seen before. And then it’s also the breadth of applications that it steals - and it’s not even just applications. It’s everything, you name it: it will steal files, or credentials, cryptocurrencies. It’s probably one of the biggest stealers I’ve ever seen, and covers the biggest attack surface.” A malware vendor using the alias “Kontraktnik” posted Dolphin X for sale, promising: “You can use it as a stealer, as an HVNC [Hidden Virtual Network Computing], as a DDoS botnet, as a loader.” The crimeware currently only runs under Windows, but “we are working on Debian,” Kontraktnik claimed, adding that the malware also only supports English and Russian. Kelley suspects the developer is Russian-speaking, and told us that the stealer includes an option not to infect any users in the Commonwealth of Independent States (CIS) countries, a common choice among Russian-based ransomware and cybercrime gangs. Kelley and his team obtained and analyzed the malware builder, operator panel and its network traffic, but didn't examine a malware sample. Varonis therefore can’t guarantee that all of the developer’s claims are true. However, “when we looked at the builder, it had everything to suggest the features were legitimate,” he said. “We couldn’t test out the malware itself, but I would say it probably lives up to most of its expectations.” Feedback left on the forum where the malware is sold supports that analysis. As of Tuesday, the sales thread has passed 3,000 views, we’re told, with Kontraktnik closing at least two confirmed deals. Both of these included positive feedback from the buyers. Three-tier subscription model Beyond the 300 + apps it targets, Dolphin X's operator panel lists 329 features across 10 categories. Buyers can subscribe to one of three tiers, each unlocking new features, or buy a lifetime subscription. The minimalist suscription costs about $80 per month, which buys rewriting and altering capabilities across Windows Portable Executable (PE) timestamp, Rich headers, and section padding, along with capabilities allowing the malware to exploit the brittle YARA rules to bypass detection and hash-based blocklists. The middle tier advertises shuffling the import table, which would change the binary's import hash between builds. The top level sub (about $230 per month) claims to rewrite the code’s control flow, substitute instructions, and re-encrypt embedded strings with a new random key each time, thus making stable byte sequences harder to identify. Lifetime subscription cost about $1,140 for basic access, $2,280 for mid-tier malware, or $3,420 for perpetual pro-level Pwnage. “It really lowers the barrier to entry,” Kelley said, adding that in the not-so-distant past, cybercriminals needed a certain level of technical expertise to develop and use different types of malware. “Now it's set up in a way where it's almost like SaaS. Anyone can purchase it. Anyone can take it out of the package and use it.” All of this suggests two takeaways for defenders, according to the security sleuths. First, keep long-lived credentials off disk if possible. “Infostealers are designed to grab everything in one pass, so anything stored locally should be treated as potentially exposed,” the report warns. Second: focus threat detection on behavior - not file signatures - because this and other malwares include capabilities to bypass signature-based detection. “For example, explorer.exe running under a non-default desktop is a strong indicator of an HVNC session, regardless of how the malware binary is packed or what hash it uses,” the authors wrote. Varonis’ threat hunters previously uncovered other AI-powered malware, including an all-in-one phishing kit called Bluekit, and an email attack tool called SpamGPT. “It’s a huge trend,” Kelley said. “Cybercriminals are finding a lot of unique ways to integrate AI, and then they're using it to make their lives a lot easier, which is problematic.” ®
The Irish government has kicked a Microsoft procurement potentially worth €1 billion into touch amid a political debate about the nation's overreliance on US tech providers and a move to free and open source software. In Ireland's parliament (Dáil Éireann), Frankie Feighan, Minister for Public Expenditure, Infrastructure, Public Service Reform and Digitalisation, said the recent tender for suppliers to take part in a framework agreement to supply Microsoft software and services had been canceled after "matters of concern were raised by an interested party." "Having carefully considered those matters, the [Office of Government Procurement] determined it was prudent to cancel the competition and notify the market accordingly," he said. The Irish government's current framework, valued at a maximum of €350 million, is set to expire in September 2027. Cian O'Callaghan, deputy leader of the opposition Social Democrats, said the estimated value range of the proposed replacement had been between €750 million and €1 billion, according to an earlier response in parliament. He challenged the Irish government over whether it had assessed the risks of the new Microsoft framework "at a time when other European countries are moving away from technological dependence on American companies." O'Callaghan pressed the government on whether it had considered alternatives to Microsoft. "There are a number of alternatives out there that other European countries and states are moving towards," he said. "They are doing so for value-for-money reasons, and so they are no longer technologically dependent on the US but can rely on European-regulated services and products. There is LibreOffice, Collabora Online, Open-Xchange, Nextcloud, Thunderbird and openDesk by Germany's Zentrum für Digitale Souveränität der Öffentlichen Verwaltung, ZenDiS, which is a readily assembled government-grade suite." Feighan responded that the Irish government was reviewing the operation of the existing framework and talking to experts in the hope that it could improve the "scope, specification, and features" of the framework. However, he acknowledged that the framework covered only Microsoft licenses and services. O'Callaghan said: "What I do not understand is why alternatives to Microsoft have not been at least explored as part of this process. The German state of Schleswig-Holstein recently moved 30,000 staff from Microsoft to LibreOffice, Linux, Thunderbird, and Open-Xchange. It is saving more than €15 million a year. The French police, the Gendarmerie Nationale, switched over 100,000 desktops to Linux. They will save roughly €500 million, half a billion, over 15 years." He again pressed the minister on why the government had not considered alternatives to Microsoft, particularly given concerns about digital sovereignty and Ireland's current presidency of the Council of the European Union. Feighan responded that the government intended to publish a new Microsoft tender "as early as is feasible." Digital sovereignty has become a pressing issue in Europe since President Trump returned to power, and it was only heightened after Karim Khan, the International Criminal Court (ICC) chief prosecutor, was sanctioned by the US government and later lost access to his work-based Microsoft services. Microsoft claimed the ICC had removed his access to its services. The Dutch press later reported Microsoft had told the ICC it would have to end services to the whole organization unless the court denied Khan access. Gartner has estimated investment in sovereign cloud across the EU is set to treble over the next five to seven years as the bloc seeks an exit ramp from dominant US suppliers amid heightened geopolitical tensions. European providers account for only around 15 percent of the region's cloud infrastructure. The EU has proposed new procurement measures that would require public sector buyers to take digital sovereignty into account when launching tenders. The plans also include procurement guidance intended to encourage greater use of open source alternatives to proprietary software. Outside the public sector, others are taking an interest in digital sovereignty. Last week, European aerospace giant Airbus announced it was migrating its most critical applications for sensitive workloads from AWS to French cloud provider Scaleway as part of a drive to increase digital sovereignty. ®
Authorities have long warned organizations not to pay ransoms, and fresh figures underline why: handing over the money doesn't mean the crooks leave you alone. Proofpoint survey data suggests that 58 percent of affected UK organizations paid a ransom. Worse, 22 percent of those who pay get extorted again anyway. The UK broadly tracks the global picture: 54 percent of victim organizations paid, though the rate swings sharply by region, from just 19 percent in Japan to 93 percent in the US. Cybersecurity biz Proofpoint, which published the data on Wednesday, attributes the regional variation to "a combination of regulatory environment, recovery capability, insurance incentive structures, and cultural norms around negotiation." "But the core finding holds everywhere: ransomware creates enough pressure that a significant share of organizations in each of the surveyed markets choose to pay." UK organizations that paid fared somewhat better than the 37 percent global average for repeat extortion. Still, the core lesson stands: paying doesn't reverse an attack. You can't trust a criminal's word. It just restarts a negotiation where the attacker holds every card, including the data, decryption keys, and the threat of publishing what they've stolen. Operation Cronos, law enforcement's LockBit takedown, provided hard proof of what had long been suspected: cybercriminals often retain victim data even after being paid. Before Dmitry Khoroshev's cybercrime empire collapsed, this was an assumption, not evidence-based. Cronos didn't just shutter the then-leading ransomware gang; it undermined the entire premise that paying restores the status quo. Proofpoint found that 2 percent of victims who paid a ransom never recovered their files at all. Earlier this year, Nitrogen's ESXi ransomware victims hit a similar wall after a coding error in the decryptor left some unable to fully restore access, and it was far from an isolated case. Attackers don't need to hold up their end of the bargain to keep the payments coming. The better answer is to build cyber-resilience into the organization itself. A word on AI No 2026 security report is complete without AI. In the UK, 65 percent of surveyed security practitioners said AI had sharpened the attacks that precede ransomware and extortion, most notably malicious links, business email compromise, malicious attachments, and credential harvesting. AI is not yet a key tool in ransomware payloads themselves, despite recent reports suggesting this may soon change. However, it is being used for more convincing phishing lures, sharper impersonation attempts, and faster system reconnaissance once attackers are inside a network. "AI hasn't fundamentally changed ransomware, but it has materially improved the attacks that lead to it," said Ryan Kalember, chief strategy officer at Proofpoint. "Today's attackers are using AI to create highly convincing phishing emails and credential theft campaigns that exploit human trust at scale. "Organizations that continue treating ransomware as an endpoint or recovery problem are missing where these attacks most frequently begin: people, identities and trusted communications." ®
A new GNOME extension called Simple-taskbar does a pretty good job of giving GNOME 50 a taskbar and start menu very much like the ones from Windows 11. It's so new that it's still not listed on the GNOME Extensions website – at the time of writing, it's still under review. We built it and installed it, and it works. This single extension merges GNOME's built-in panel (across the top of the primary screen) and what it calls the "dash" – the icon bar down the left side – into a single taskbar, styled like Windows 11: icons centered, a Start menu with columns, a search box, and so on. The handy feature here is to have all this in a single, integrated extension. There are already other extensions to do some of this, such as Dash to Panel, whose development is now sponsored by Zorin OS. It doesn't provide a Start menu replacement, though. For that, you need another extension, such as Arc Menu. Like many things in Linux, this sort of tool needs the user to do a little manual config. There is also a risk with this kind of DIY GNOME customization using lots of extensions. Extensions are tied to specific versions of the GNOME desktop – so, for instance, the new Simple-taskbar only supports GNOME 50. If you add lots of extensions and then upgrade the underlying OS to a new version, meaning a new version of GNOME, there's a significant chance that the extensions won't work any more – you may even be unable to log in. Zorin OS takes Ubuntu and does this for you, and the result sells – that's how the company can afford to sponsor extension developers. We rather like Zorin OS as a distro, especially its handy Zorin Appearance accessory, which it showcases on its homepage. If you don't need the customization and just want a Windows 11-like look, last year we looked at AnduinOS, which does this to a stripped-down Ubuntu. At the end of last month, the project released version 2.0, based on Ubuntu 26.04. Another tactic, of course, is to fork the whole of GNOME and change it to make a whole new, more Windows-like environment. Back in 2011, Linux Mint 12 offered MGSE, a set of Mint GNOME Shell Extensions to make GNOME 3 more Windows-like, but by 2013 that became the Cinnamon desktop. Since its launch in 2011, Mint has also offered the MATE Desktop, a fork and continuation of GNOME 2. There are multiple ways to keep GNOME but make it look Windows-like. Even the GNOME ecosystem recognizes the need. Early versions of GNOME 3 offered GNOME Fallback mode, intended for machines that didn't support hardware 3D rendering. GNOME dropped that mode with version 3.8, but two alternatives emerged: GNOME Classic, which uses GNOME Shell extensions, and GNOME Flashback, a continuation of the panel-and-Metacity-based Fallback environment. This is still around and maintained. For instance, Ubuntu 26.04 uses GNOME 50, and includes the packages for GNOME Flashback version 3.58.0. It's installed by default on some distros – in Debian 13 it's a standalone desktop – but on Ubuntu, you must manually install it. You'll probably want to put back the network icon – it's an easy graphical way to manage Wi-Fi connections and so on. All you need is one command: sudo apt install -y gnome-session-flashback network-manager-gnome Log out, or reboot, and on the login screen, you can now use the cogwheel button at the bottom right to choose to log in to the new GNOME Flashback session. By default, Flashback has a GNOME 2 and MATE-style two-panel layout, but if you hold down the Alt key while right-clicking the controls on the panels, you can open a context menu that allows you to move (or remove) them. We moved the Menu Bar control to the beginning of the bottom panel, the Indicator Applet Complete control to the bottom right, and the Show Desktop button to the end, and that's it: a basic classic Windows-style layout. You can place panels on the left or right screen edge. The snag is that the controls on them don't reorient accordingly, which renders vertical panels unusable. That's completely faithful to GNOME 2 at least. There are some small oddities – you need to use GNOME's session applet to shut down or log out, for example. However, it's usable, and it uses no GNOME extensions at all, so in our testing it's unaffected by OS upgrades. It uses the Metacity window manager: this is an X11 environment, and it will pull in X.Org as a dependency. This does mean it works fine in VMs without 3D acceleration, a more relevant benefit today than its original role of supporting very low-end hardware. Flashback's appearance varies between releases – the version in Ubuntu 24.04 had a more GNOME-like, softly rounded look. In the current version of GNOME Flashback, it has an old-fashioned 2D look, which we rather like, but it's also much more customizable: it behaves rather like a drastically cut-down Xfce, and MATE users should find it familiar too. We were surprised but happy to discover the improved customizability in Flashback in GNOME 50. The old GNOME Wiki is coy when it comes to Flashback releases, and doesn't list version 3.58 at all. The banner at the top redirects users to the GNOME handbook instead, but that doesn't contain any mention of Flashback whatsoever. This is still a desktop based on GNOME. Flashback doesn't magically give apps running under it proper title and menu bars or anything like that – but then neither can any combination of GNOME extensions, and that includes environments built around them such as Zorin OS or AnduinOS. If you want to stay close to the GNOME mainstream in most distros, but want a more traditional desktop, we suggest checking out Flashback. Room for improvement? For reconfiguring your desktop quickly to look like existing OS layouts, most distros do have an equivalent to Zorin Appearance – but only if you're using Xfce. This desktop has an optional add-on called Panel Profiles that does the same, although sadly, it doesn't help with plugins such as the Docklike taskbar, Whisker menu, or Xfdashboard. A KDE version of Xfce's Panel Profiles would be a huge win, and something like it for Flashback would really help too. We don't know if GNOME is accepting contributions to the Flashback session; it seems reluctant to mention Flashback at all in its current documentation. The Flashback GitLab does show that it's in active maintenance, though. Development of the MATE desktop is slow. It's two and a half years since the last new version. But then the team has an entire codebase to maintain that was abandoned by its own creators. Porting the functionality of MATE over to the GNOME Panel in Flashback, and replacing a few of GNOME's bundled apps with tradition Gtk ones, such as Linux Mint's XApps, would result in a much more familiar and usable desktop with a smaller maintenance burden. It's a possible future for those who remain disenchanted with GNOME Shell. ®
October 2026 is shaping up to be a busy month for administrators as it heralds the end of several big products, along with the retirement of components that could mean sleepless nights for the ill-prepared. After the demise of Windows 10 in October 2025, sysadmins might have hoped for some respite from Microsoft's ax, but 2026 will see the demise of more beasts. First, there's the end of support for Office LTSC 2021, which means everything from Access 2021 to Word 2021 is for the chop. A move to LTSC 2024 is required to keep the support lights burning, or - and we don't doubt that this is Microsoft's preference - a switch to Microsoft 365. M365 isn't a great option for organizations steering clear of the cloud. The on-prem version is very much a snapshot of where things were at release (although security patches keep flowing). Speaking of on-premises, Windows Server 2022 will drop out of mainstream support on October 13, 2026. Extended support will linger until 2031. Windows 11 24H2 Home and Pro reach the end of the road on the same date. Windows 11 23H2 for enterprise and education will get until November 10 to tidy up their affairs. As for the more minor products? Publisher 2021 will wrap up decades of the Microsoft Publisher brand in October. First appearing as a desktop publisher for Windows 3.0 in 1991, it has had an inexplicably long life, which will come to an end once and for all in a few short months. And unlike the rest of the Office 2021 LTSC suite, there won't be anything to replace it (or its annoyingly proprietary file format). There are also services due for the chop that might cause headaches for those that fail to prepare. Entra ID Sign-In risk policies, formerly known as Identity Protection, is being retired on October 1, 2026. Microsoft wants admins to migrate to Conditional Access, and make sure their policies cover user and sign-in risk. Not done the update? Then risk protection will go away after the retirement date. A Register reader remarked, "Given how many orgs use O365 I can't see how disabling sign-in protection might go wrong." October 2027 looks quieter, with only SQL Server 2017 gasping its last. However, with the coming October loaded with already announced terminations, getting the corporate house in order well ahead of time would be prudent. ®
Raspberry Pi has supersized its Touch Display 2 with a new 10.1-inch model aimed at dashboards, entertainment systems, and other projects that need more room for prodding. The panel is designed for use cases such as touch-enabled information displays. This is the big brother to the 5-inch and 7-inch variants, with a resolution to match – 1,200 x 1,920 pixels are available on the native portrait display. The 10.1-inch panel supports 24-bit RGB color and ten simultaneous touch points, up from five on the smaller models. The in-plane switching, thin-film transistor, liquid crystal display also touts a black surface that acts as a magnet for greasy fingerprints. According to Raspberry Pi, the touch response time is a maximum of 35 ms, and its backlight brightness is 400 cd/m2 – not class-leading, but more than adequate at a list price of $80. The viewing angle is 85 degrees and, as with the other Touch Display 2 variants, there is a hefty bezel. The unit is 161.8 x 247.3 mm, while the actual active area is 135.4 mm x 216.6 mm. We'd expect integrators to use that bezel when mounting the screen in enclosures. Speaking of which, while there is a handy mounting point on the back for a Raspberry Pi, the device is only compatible with the Raspberry Pi 5 and Compute Modules (not included). Since the screen draws power from a pair of GPIO pins, you'll need an IO Board or similar to use it with a Compute Module. The need for the Pi 5 could cause some cooling issues – we've noted before how much heat the unit can generate when under load. According to Raspberry Pi, the justification for the requirement is all those extra pixels. A spokesperson told The Register: "The higher resolution of the new display requires four DSI lanes of data to communicate with the host Raspberry Pi, rather than the two used by previous Touch Displays. The newer display connector on Raspberry Pi 5 and our Compute Module IO Boards support this!" Otherwise, attaching a Pi 5 to the back of the unit and connecting it is ludicrously simple. There's just a ribbon cable and something for power (both provided in the box) before screwing the Pi to the risers with the included screws and firing up the unit… Which didn't work initially. Does this screen come pre-borked? No. It transpired that we needed to update the EEPROM on our Pi 5 – the firmware needs to be from February 2026 or later. After a swift sudo rpi-eeprom-update -a and a restart, we were in business. In use, the screen is bright and relatively responsive. It also needs to be kept well away from moisture, so consider the enclosure carefully in environments where that might be an issue. According to Raspberry Pi, "Raspberry Pi OS provides touchscreen drivers with support for ten-finger touch and an on-screen keyboard, giving you full functionality without the need to connect a keyboard or mouse," which is true. It would, however, be a stretch to call Raspberry Pi OS optimized for touch (even with the pop-up on-screen keyboard). If you're expecting to build yourself an iPad out of the box, you'll be disappointed. However, that would miss the point of the 10.1-inch Touch Display 2. It's designed for entertainment systems and information dashboards. The image is crisp, and the additional pixels will make for better clarity. Considering the cost of Pi computers nowadays, the requirement for a Pi 5 could be irritating. It not only runs hot, depending on workload, but adding a 2 GB variant to the system will almost double the price of the screen. The technical reason is understandable, but the requirement could still hit customers in the pocket. Still, as with the earlier models, the Touch Display 2 represents an easy way to get a touchscreen up and running with the diminutive computer. For use cases that require users to jab fingers at a multitouch screen, we'd recommend it. Just don't forget the EEPROM update – documented with the release, if not in the press kit – and spend hours as we did repeatedly reconnecting cables in search of life. ®
A council worker who "abused" his position to unlawfully access "highly sensitive" personal records of family members and other people known to him has received a suspended sentence after admitting to violating the Computer Misuse Act (CMA). Geoffrey Smith, 31, from Ledbury, was a new Herefordshire Council employee working in the Children and Young People directorate. Over a four-day period, he accessed roughly 490 records and downloaded 94 documents relating to family members and "families known to him." This included data on adults and children, the Information Commissioner's Office (ICO) said. The data accessed included "highly sensitive material" such as medical records, social worker reports, and child and family assessments, the watchdog said. Smith pleaded guilty to an offence under Section 1 of the CMA 1990 relating to "unlawful accessing of personal data held on computers." He was sentenced at Worcester Magistrates' Court on July 17 to two months' imprisonment, suspended for 12 months. Smith was also ordered to complete 120 hours of unpaid work and pay £2,000 in costs plus a £154 victim surcharge. Andy Curry, ICO head of investigations, said: "Smith abused his position as an employee and used his access to Herefordshire Council's systems to view the personal information of people known to him, without any legitimate reason to do so. "The sensitive nature of the records held within a Children and Young People directorate, and Smith's systematic misuse of that information, makes this particularly serious. People have a right to expect that their personal information is kept safe, and that those with access to it will only use it for the purposes for which it was intended." Tough words from the ICO, whose former information commissioner resigned after admitting that his conduct had fallen below the standards expected of public officials. ®
The advent of generative AI spurred an enormous and controversial datacenter building boom that has seen almost anyone who knows how to run a bit barn try to expand their business ASAP. Fujitsu, however, wants out. The Australian outpost of the Japanese giant’s business this week announced the sale of five datacenters down under. The company said selling the bit barns “enables us to further invest in the technology services where customer demand is growing fastest.” In Australia, that apparently means “helping organisations modernise critical systems, strengthen cyber resilience, adopt sovereign AI, and access the high-performance and quantum computing capabilities needed for their next phase of transformation.” Fujitsu said its datacenter business “is a strong platform, and its next phase will benefit from dedicated commercial ownership and investment.” That new owner, private equity outfit Next Capital, may have its work cut out for it because some of the bit barns it bought appeared to be rather modest. Fujitsu’s manifest of its Australian properties lists one facility capable of hosting 92MW worth of kit, another with 28MW capacity, plus bit barns that can host 10MW, 4.8MW, 3MW, or 2MW worth of kit. Keen-eyed readers will have noticed that the paragraph above mentions six datacenters and that earlier in this story we said Fujitsu is selling five. The Register understands Fujitsu has already disposed of the other one to another buyer. Whatever Next Capital bought, it will surely be aware that a modern rack filled with AI kit can require 500KW or more. Fujitsu Australia’s littlest datacenters therefore won’t help the private equity company to catch the AI wave unless it invests in upgrades – a process that might be cheaper than building new AI-ready datacenters from scratch and could also involve fewer regulatory complications than greenfield builds. Next Capital was quiet about its plans, but shared a local media report suggesting it’s spent AUD$200 million ($139.97/£104 million) to do the deal. The firm promised continuity for tenants. Fujitsu Australia’s services business won plenty of blue-chip and government clients, and The Register understands many are long-term residents of the offloaded datacenters. Next Capital can probably therefore bank on solid cashflow for months or years to come. Fujitsu sold its US datacenter business in 2023 and at the time hinted at divestments elsewhere. The company has also “absorbed” its Japanese public cloud and quit the mainframe business. The Japanese giant plans to return to the big iron business with machines built on the Monaka CPU which it hopes to deliver next year, and perhaps also get into the quantum computing biz. ®
China’s Cyberspace Administration on Tuesday issued a plan for wider adoption of IPv6 between now and 2030, and for more work on a non-standard set of services that Beijing calls “IPv6+”. The Implementation Plan for Deepening Technological Innovation and Integrated Application of Internet Protocol Version 6 (IPv6) (2026-2030) contains the usual promises to increase use of IPv6. Beijing wants 900 million users to be connected over IPv6 by 2027, and for the protocol to carry 38 percent of network traffic. China also wants all connected devices to be IPv6-enabled by 2027. “By 2030, IPv6 will be widely and deeply integrated with all sectors of the economy and society, building a technologically advanced, open, innovative, self-driven, and secure IPv6 industrial ecosystem,” the regulator wrote. “The number of active IPv6 users will reach 950 million, and IPv6 will account for 42 percent of network traffic.” The Administration also expects that by 2030, “New networks will be prioritized for IPv6 addresses by default, accelerating the evolution towards IPv6 single-stack, and promoting the formation of a network service and application system dominated by IPv6.” News that China is planning for the day it runs a single-stack internet will excite some, notwithstanding the fact that IPv6 has proven less important than its creators hoped. The most interesting part of the new plan is the call for more work on IPv6+ – a set of enhancements to IPv6 that allows those who send information to embed metadata describing content into packets and even suggest the route it should take. As Think Tank the Mercator Institute for China Studies last year observed, IPv6+ “has obvious appeal for authoritarian regimes looking to control their citizens,” because a carrier could read metadata and act on it. One possible action could be to allow network operators to identify traffic they would like to charge extra to carry, an idea telcos like because they feel it is unfair that they bear the burden of investing in last-mile infrastructure to deliver content from the likes of Netflix and YouTube. Reading metadata could also enable censorship: Beijing already blocks a lot of content, and if dissidents had to identify themselves in packets, they’d be easier to find and block. The Institute also notes that China’s telco equipment companies have implemented IPv6+ and exported kit that runs it to several nations. That’s worrying because China already tried to create a protocol called “New IP” that also included surveillance-friendly features. China tried to have the International Telecommunications Union sign off on New IP, despite the Internet Engineering Task Force maintaining existing IP protocols. That effort failed, but Beijing is pressing ahead with its efforts to spread its own version of IP at home and abroad. The new plan doesn’t suggest that Beijing abandon vanilla IPv6. Indeed, it calls for Chinese participation in global standards development. But the document also says China will work on “national IPv6 standards and accelerate the development of national IPv6 standards in key areas.” ®