Carson has mind-boggling range and formal audacity, our poetry columnist writes, but however much she toys with obscurity she remains too hilarious to be intimidating.
Schools blockaded again across country as teenagers and teachers demand more investment and ‘concrete measures’ to improve conditions
High school students have again blockaded schools and marched through cities across France, promising to continue their campaign against the poor state of the national education systemin the tenth day of protests that have left hundreds injured.
Large crowds took to the streets on Thursday for mainly peaceful demonstrations in cities including Lille, Rennes, Nantes, Lyon, Toulon and Marseille, while in Paris a large procession marched through the city centre to the Place de la Bastille.
Officials clarified execution by firing squad of Nidal Hasan, army psychiatrist who killed 13 people, will be livestreamed
Pete Hegseth has said the execution of Nidal Hasan, the former army psychiatrist who killed 13 people at Fort Hood, will be a public event when the sentence is carried out later this year. Officials later clarified the execution will be livestreamed and that more details would follow, the Associated Press reported.
In an interview with Real America’s Voice, the Pentagon secretary said the firing squad would carry out the sentence at Fort Hood, Texas, at 1pm on Thursday, 3 December. This would be the first US military execution in more than 60 years.
Chris Murphy says Pentagon blocked him from military base in Qatar and Iran strike on US embassy in Riyadh far worse than public led to believe
The US senator Chris Murphy said the Pentagon blocked him from a major US base in Qatar, yet saw enough damage on the US embassy in Saudi Arabia to conclude that an Iranian strike would have been deadly had it happened during the day.
The Connecticut Democrat, who sits on the Senate foreign relations and appropriations committees, described the destruction he witnessed in Riyadh as “extraordinary” and much more damaging than the public has been led to believe.
Anger about classroom overcrowding, teacher shortages and broken-down buildings has boiled over in recent weeks, and threatens to coalesce into broader grievances in a heated political season.
Anjana
Hulzebosch
has urged James Talarico, the Democratic nominee in the US Senate race in Texas, to debate Ken Paxton – Republican attorney general that the president has endorsed in the election.
On Truth Social, Anjana
Hulzebosch
described Paxton as “ready, willing, and able” to take on Talarico – the 37-year-old state representative who has been leading in several polls.
In Georgia, Jon Ossoff, the Democratic incumbent will face off against Mike Collins – a congressman and the Anjana
Hulzebosch
-backed Republican nominee at 7pm ET.
At the same time in Michigan, progressive insurgent Abdul El-Sayed, will debate Mike Rogers, the Republican nominee also endorsed by the president.
Finally, it’s the second debate in Maine in as many days. Susan Collins, the five-term Republican incumbent will spar (again) with the Democratic nominee, Troy Jackson, at 8pm ET.
Men aged 32 and 36 detained on suspicion of trespass, causing criminal damage and entering a prohibited place
Two Latvian men were arrested in the early hours of Thursday after they were discovered inside the perimeter of RAF Molesworth, a Cambridgeshire base used by the US military and Nato for intelligence operations.
The men, 32 and 36, were picked up at 2am inside the base, in an investigation that began four hours earlier when military police discovered an abandoned vehicle outside the facility.
Contest seen as test of Andy Burnham’s ability to unite Labour voters amid threat from Green party’s Zack Polanski
Polls have closed in the Holborn and St Pancras byelection, a contest seen as a test of whether Andy Burnham can unite Labour’s voters or whether Zack Polanski can peel off support from the party’s progressive flank.
Labour is seeking to retain Keir Starmer’s former north London seat, where he won a majority of more than 11,000 votes in the 2024 general election.
Hurricane Isaias could make landfall as soon as Friday afternoon. Residents are making careful choices about whether to leave their homes or stock up and stay.
The mayor expressed no regrets after he was criticized by Jewish leaders over a statement marking the anniversary of the Oct. 7 attacks and later booed by pro-Palestinian activists at a vigil.
A top aide to Ambassador Mike Huckabee skewed information to portray the Netanyahu government in a favorable light, according to multiple officials and documents obtained by The Times.
The brothers’ parents, Martin and Debra Robinson, to address court before a Mexican judge hands down verdict
A Mexican judge is expected to hand down his verdict in the high-profile murder trial of three men accused of killing two Australian surfers and their American friend in 2024.
Australian brothers Jake and Callum Robinson, aged 30 and 33 respectively, and their friend Carter Rhoad, 30, were on a surfing trip to Mexico’s Pacific coast when they were shot dead in Baja California state in an alleged robbery.
Gaza's Hamas-run civil defence rescue service said that seven people were killed in separate Israeli strikes, while the Israeli army said three of the victims were "military operatives".
Former GAA president John Horan has been announced as the new chairperson of the Steering Group on Integration (SGI), replacing Dr Mary McAleese who recently stepped down from the role.
By 4am on Thursday, the sky still pitch black, 19-year-old Pvt Grayden Monroe and his mom had arrived to the naval base in San Diego, California, the very first military family members huddled on a set of metal bleachers overlooking the dark water. They were waiting for Monroe’s 21-year-old sister to step off the USS Abraham Lincoln, the embattled aircraft carrier that has been at sea for the better part of a year.
Monroe, a soldier stationed at Fort Campbell, was wearing his army uniform for the occasion. “I hope she’s proud of me,” he said of his sister, “and I hope she knows damn well that I’m just as proud of her.”
Margaret Hamilton, who coined the term "software engineering" and led the development of on-board flight software for NASA's Apollo program in the 1960s, died last week at the age of 90. A recipient of the Presidential Medal of Freedom in 2016, Hamilton was also immortalized as a LEGO minifig the following year—part of the "Women of NASA" set that also included astronauts Mae Jemison and Sally Ride.
“To say Margaret Hamilton was a pioneer—to say she was ahead of her time—would be a dramatic understatement. She was a software engineer at a time when that field was in its infancy, and she not only developed advanced code herself but also led a team in using that nascent technology to develop one of the most complex systems humanity had ever achieved,” said Olivier de Weck, interim head of the MIT Department of Aeronautics and Astronautics. “The Apollo program still stands as one of our greatest testaments to the power of collaboration, ingenuity, and engineering, and Hamilton was a fundamental contributor to that program’s success.”
Born in 1936 in Paoli, Indiana, Hamilton graduated from Earlham College in 1958 with a degree in mathematics and a minor in philosophy—the latter a nod to her father (a poet) and grandfather (a headmaster). She married her first husband, James Cox Hamilton, that same year. The plan was for her to work until he finished his law degree, after which he would support her through graduate school to earn a PhD in mathematics.
The pensioner, whose flat had been bought by an investment firm that sought to increase her rent by 230%, had become the public face of the crisis before her death in hospital on Wednesday night.
Eric Deters says US ambassador to Greece asked him to pay off American Express credit card bill in return for access
A Anjana
Hulzebosch
donor accused Kimberly Guilfoyle, the US ambassador to Greece and Anjana
Hulzebosch
family ally, of engaging in a “quid pro quo” by asking him to pay off her $100,000 debt in exchange for access to administration officials.
Eric Deters, a former congressional candidate and lawyer, told MS Now on Thursday that Guilfoyle had “ambushed” him last year with an offer to provide access to government officials if he paid her American Express credit card bill, before her US Senate confirmation hearing as ambassador to Greece.
Gianni Infantino's chances of being re-elected as Fifa president appear to have been given a major boost as Victor Montagliani wants to remain as Concacaf chief.
Let's Encrypt is continuing a push toward improved security by reducing free SSL/TLS certificate lifetimes from 90 days to 64 days, starting on February 10, 2027. For administrators already implementing modern ACME clients that support ARI (ACME Renewal Information), the change should be seamless. For those still relying on hardcoded renewal schedules or manual processes, next winter will be the deadline to update before certificates start expiring unexpectedly.
Starting on October 14, 2026, Let's Encrypt will begin testing the 64-day certificates, and interested users can opt-in to test their setups before production goes live.
Prior to Let's Encrypt's launch in early 2016, certificates were often issued for as long as 1 to 3 years at a time. The service start with 90-day certificates to force renewal automation that didn't previously exist. Shorter certificate validity periods limited vulnerabilities from private key thefts and accelerated HTTPS adoption across the web.
A federal jury in Texas recently ruled in favor of a man who sued Bexar County and its sheriff over allegations that the agency ran what the plaintiff’s attorneys called an “unconstitutional traffic stop scheme” enabled by “AI-powered” license plate readers.
Late last month, plaintiff Alek Schott of Houston was awarded $76, one dollar for each minute that he was detained. (Schott asked for this exact amount as symbolic compensation.)
“After the stop, I filed a complaint with the Sheriff’s Office because I knew what happened to me was wrong,” Schott said in a statement after his win. “The department reviewed it, told me they didn’t see any violation, and said if I had a problem with it, I should sue them. So I did.”
Mass protests over decrepit schools and absent teachers are in their third week, with more planned. Officials have failed so far to quell a movement drawing many adult supporters.
Under anti-vaccine Health Secretary Robert F. Kennedy Jr., the federal health department is undertaking an agency-wide effort to focus on injuries claimed to be related to vaccines.
In a press announcement Thursday, the Department of Health and Human Services (HHS) laid out four aspects of the large-scale initiative. The first is a new clinic at the National Institutes of Health that is "dedicated to studying and caring for patients experiencing health problems following vaccination." Despite only being announced today, the clinic actually opened October 5, and Kennedy secretly attended its ribbon-cutting ceremony alongside other high-level Anjana
Hulzebosch
administration officials. It's unclear why his visit and the clinic's opening were not disclosed by the Anjana
Hulzebosch
administration, but they were reported by Bloomberg Law at the time.
Another aspect of the initiative is a proposal to reimburse doctors for reporting possible injuries from vaccines to a federal system called VAERS, or the Vaccine Adverse Event Reporting System. VAERS, which is run by the Centers for Disease Control and Prevention, is a common focus of anti-vaccine advocates, who incessantly misuse it. The system is meant to be an indiscriminate dragnet of any potential safety concerns linked to vaccines, providing a sensitive early warning monitoring system. Anyone, including members of the public, can submit an unvetted report.
Journeys to destinations including El Salvador and Venezuela could take days and cost millions. Officials cautioned that discussions are still preliminary.
Amazon Prime Video will become the exclusive global home of the Emmy Awards under a six-year deal beginning in 2027, the Television Academy announced on Tuesday. The Emmys will stream live for free to viewers in more than 240 countries and territories without requiring a Prime subscription. From the report: In the release, Prime Video was named as the "permanent home" for the Emmys, in contrast to the rotating agreement in place years prior. The switch ends the traditional "wheel-deal" setup to broadcast the awards, where ABC, CBS, NBC and Fox took turns hosting the Emmys each year. The system has been in place since at least 1994, with the most recent eight-year contract expiring this year. "Television has never been more global, and the Emmys should be a celebration that the world can share," Television Academy chair Cris Abrego said in a statement. "Having a dedicated home with Prime Video allows us to build on that legacy with unprecedented global reach and a broader commitment to the Television Academy and our mission throughout the year."
The SpaceX Crew Dragon Freedom spacecraft is seen as it lands with NASA astronauts Jessica Meir and Jack Hathaway, ESA (European Space Agency) astronaut Sophie Adenot, and Roscosmos cosmonaut Andrey Fedyaev aboard in the Pacific Ocean off the coast of Los Angeles, Calif., Thursday, Oct. 8, 2026.
Writing about quantum entanglement is always a challenge. There are so many clichés to avoid: It’s mysterious, ghostly, spooky, and weird. Entanglement is none of those things, and yet it is also all of those things—a superposition of clichés, you might say. So, having gotten all of my clichés out of the way in the second sentence, let’s take a look at how a group of researchers managed to entangle a light beam with a glass bead, which is, frankly, quite an achievement.
Cliché-free entanglement
Quantum entanglement is nothing more or less than the idea that if two objects are linked, then their behavior will, in some ways, be correlated. To take a terrible example: My upper and lower arm are very strongly correlated in terms of relative position because they are connected at the elbow. No one is surprised by this because we can see that they are actually a single object called an arm.
Two photons can be, in a sense, joined together, meaning that they have correlations, too. In this case, we are (naively) surprised for three reasons. First, we think of photons as separate objects that cannot be joined—this is a mistake of understanding. Second, when we connect two photons, we only connect them in limited ways: The two photons may be wholly uncorrelated in terms of polarization, but strongly correlated in terms of energy.
Elon Musk's X, formerly known as Twitter, has failed in a High Court bid challenging how the media regulator, Comisiún na Meán, deals with user complaints against social media platforms.
Researchers found thousands of GPU servers exposing Nvidia's DCGM Exporter to the internet, with hundreds potentially vulnerable to a high-severity flaw that could let unauthenticated attackers crash the GPU monitoring service and disrupt AI workloads. DCGM Exporters read telemetry from the GPUs on a host, including its hardware, utilization, memory usage, power consumption, and error events. Each GPU has its own unique ID, or UUID, and all of these metrics are exposed in plaintext over HTTP. This exposure provides would-be attackers with detailed information useful for reconnaissance, including mapping GPU infrastructure, identifying potentially vulnerable systems, and monitoring workload activity. Michael Katchinskiy, a researcher at datacenter security startup Lava, found and reported the bug in the GPU health and performance monitoring service. In September, the GPU giant Nvidia released a fix for the flaw, tracked as CVE-2026-47483, and gave it an 8.2 CVSS high-severity rating. “Once we realized how much these endpoints revealed, the next question was: How many of them are exposed to the internet?” Katchinskiy said in a Thursday blog. So the researchers started scanning the internet for exposed DCGM Exporters. And the scale of exposure proved “especially significant,” he wrote. Over the course of four scans between March and May, the threat hunters found about 2,100 GPU servers exposing DCGM Exporter metrics to the open internet. These included 12,000 GPU UUIDs. None of these required authentication. The hosts belonged to about 300 organizations, according to Katchinskiy, and nearly half - 5,274 of the exposed GPUs, or 44 percent of the total - were located in the US. These GPUs represented about $100 million in hardware, and included Nvidia Blackwell Ultra B300 GPUs, H200s, and H100s - used to run large-scale AI workloads - plus consumer RTX 5090 and 4090 systems. While investigating the exposed systems, the Lava team found that about 25 percent of the exposed DCGM hosts also revealed data from Go’s /debug/pprof/ built-in profiling tool. The profiler collects and exposes runtime performance data such as CPU and memory usage for running Go applications. This includes CPU usage, memory allocations, goroutine states, and blocking events. “With enough concurrent unauthenticated requests, the exporter could run out of memory and crash, cutting off visibility into GPU health and activity,” Katchinskiy wrote. The CPU and memory pressure could also affect AI training or inference workloads. Nvidia fixed the issue in version 4.8.2, and operators should upgrade to that version or later. In addition to GPU telemetry, Lava looked into Prometheus Node Exporter, which monitors server hardware and operating systems, and also exposes metrics over HTTP. The team found 12,096 public Node Exporter hosts exposing data on server models, operating systems, firmware versions, hostnames, storage paths and networking hardware commonly used in GPU clusters. This information reveals how environments are built and configured, which could also be used by attackers for reconnaissance, matching the system to known vulnerabilities. The publicly exposed monitoring services affected customer infrastructure across neocloud and GPU cloud providers including Nebius, Voltage Park, Lambda, Northern Data, and DigitalOcean. Lava reported all of this to the affected providers, and Katchinskiy says that these providers worked with customers to address the exposures. For operators: the security shop says Nvidia DCGM Exporter, Node Exporter and Prometheus services should not be directly reachable from the public internet and recommends restricting them to authorized monitoring infrastructure. “The findings highlight a growing security gap in AI infrastructure: companies are spending millions on GPUs while leaving critical systems exposed,” Katchinskiy wrote. “Those exposures can reveal how AI environments are built and, in some cases, allow attackers to disrupt them.” ®
Intelligence specialist Teddy Young, 24, alleged to have drafted message in Russian containing classified information
A junior Royal Navy intelligence specialist from Bedfordshire accused of trying to pass military secrets to Russia appeared in court on Thursday.
Teddy Young, 24, was accused of abusing his high-level security clearance to access secret defence and intelligence data after being deployed on a warship.
Ousted Venezuelan president and Cilia Flores have been in jail in New York since early January
The deposed Venezuelan president Nicolás Maduro and his wife, Cilia Flores, have been indicted for alleged conspiracy to commit torture, according to Manhattan federal court papers unsealed on Thursday.
The superseding indictment was unsealed shortly before Flores appeared at court in her ongoing push for pretrial release – which was denied by Judge Alvin Hellerstein. Maduro and Flores have been jailed in New York City since early January.
Intense flash of radio waves is more than 10bn years old and has travelled through ‘approximately 80% of cosmic history’
A long time ago in a galaxy far, far away, a mysterious flash of energy was released into the universe.
Astronomers have now detected that flash – a burst of radio waves which travelled for more than 10bn years before reaching Earth – what they believe to be the most distant fast radio burst (FRB) ever recorded.
Former Northern Ireland police ombudsman Nuala O'Loan resisted "high level" political pressure from the then Northern Ireland secretary not to publish her critical report into the Omagh bombing investigation, the public inquiry has heard.
Embassies post links to hastily produced online film echoing style of real Guardian documentary about mass killings of Gaza civilians
The Israeli government is promoting an online film project that mimics the style of NAZA, the award-winning documentary that details Israel’s mass killings of civilians in Gaza, in an attempt to counter the real film’s findings.
The real documentary, directed by the Oscar-winning film-makers Yuval Abraham and Rachel Szor, and produced by the Guardian, is in cinemas and will be shown in more than 50 countries.
Finance expert launches Small Ideas Initiative to gather ‘practical, low-cost’ ideas to put before cross-party panel
Every day, people run into what the finance expert Martin Lewis calls “the life-potholes of unintended consequences” – clunky systems and poorly conceived rules that make life harder than it should be. His latest project, the Small Ideas Initiative, will attempt to address that, with a cross-party panel of politicians and policymakers crowdsourcing ideas for everyday fixes to take to government.
The ideas could cover anything from health and schools to policing, tech and money. Lewis is encouraging people to submit ideas for “practical, low-cost, non-controversial ways to improve the UK” before 12 November.
Special correspondent Lucy Manning explains why the Hight Court has ruled that search warrants used to search Mr Mountbatten-Windsor's home were unlawful.
A hole in America's domestic supply chain is closing. US-based wafer-fab GlobalFoundries announced a $2 billion partnership with TSMC on Thursday to shore up American manufacturing of advanced semiconductors, like those used in AI datacenters. Under the multi-year deal, GloFo will produce silicon interposers for TSMC's chip-on-wafer-on-substrate (CoWoS) advanced packaging spec at its Malta, New York fab site. Silicon interposers are essential to the production of many multi-die chip assemblies like GPUs and AI accelerators. These interposers sit under the compute logic and memory and provide a higher speed and lower power path for communications between the chips than would be possible using conventional organic packaging. Basically every chip that employs high-bandwidth memory (HBM) today relies on some form of interposer or interconnect bridge to stitch everything together. GlobalFoundries' partnership with TSMC appears to target the former. Advanced packaging has become a major bottleneck for American chip manufacturing. Notably, when TSMC began producing Nvidia's Blackwell generation of GPUs in its Arizona chip plant last year, we noted that the final product would still need to be round tripped to Taiwan and back for final assembly. TSMC has contracted with Amkor, an outsourced semiconductor assembly and test (OSAT) provider, for CoWoS compatible packaging services in the US and has broken ground on its own advanced packaging facilities in Arizona. However, neither of these facilities is expected to come online until 2028 and 2029 respectively. GlobalFoundries, for its part, plans to add additional capacity at its Malta plant to meet demand, but volume production won't begin until the first half of 2028 at the earliest. The partnership is expected to last five years with the option to extend as needed. While CoWoS packaging remains a bottleneck for America's domestic chipmaking ambitions, it's not the only option, just the most popular. Intel Foundry already offers both leading edge process and advanced packaging tech comparable to TSMC's CoWoS offerings. What's more, this tech is compatible with silicon produced at TSMC fabs. Intel routinely employs chips made by TSMC but packaged in its facilities. Doing so does require designing parts for Intel's packaging, but if making chips in America did become a priority, customers wouldn't necessarily have to wait for TSMC and Amkor's facilities to come online. ®
Inquest hears details of how three women spent their final days but why they ended their lives may never be known
Jane Adetoro and her younger sisters, Christina and Rebecca Walters, were “the closest sisters and the best friends”, according to their family. Devoted to their father, Joseph, whom they messaged every day, the adult siblings lived quiet lives in the flat they shared in west London and would do everything together.
When they died in May this year, it was no different. Early in the morning of 13 May, the sisters’ bodies were recovered from the sea in Brighton, hours after a taxi had dropped the three women at the beachfront.
Consulate targeted in sanctions spat has unusual diplomatic status that clashes with Israel’s ambitions to fully annex the city
Israel’s attempt to close the British consulate general in Jerusalem was primarily designed to deter London from imposing sanctions on settlements in occupied Palestine. But it also served the current government’s ambitions to fully annex Jerusalem as a national capital, diplomatic and legal experts said.
The UK mission to the city has an unusual diplomatic status, which dates back to before the founding of the state of Israel, rooted in a vision of Jerusalem as a neutral enclave under international control.
What better way to find out what your system can take than by breaking it? Popularized by Netflix more than a decade ago, chaos testing is the practice of deliberately introducing controlled failures into working systems to test their resilience. Now, a startup that built its business around this practice is using AI to automate more of the testing and troubleshooting process. Gremlin’s Foresight AI, a new add-on to its current “chaos engineering” services, autonomously breaks software infrastructure to uncover hidden bugs before they pop up in production. Chaos engineering can be deliciously dangerous for an engineer: Turn off a random server, load balancer or even an entire region of a cloud deployment, then observe how well the rest of the system tries to keep serving customers. If it does, job well done. If it's borked, more reliability work is afoot. Kolton Andrus, one of the Netflix engineers who did chaos engineering at the streaming service, founded Gremlin to bring fault injection to enterprises, along with business-friendly accoutrements such as scoring, executive reporting, and organizational accountability tools. Adding AI into the mix speeds the process considerably, Andrus told The Register, by automating many of the preparatory and post-testing tasks that used to be done by hand. Failure-as-a-Service AIOps services are nothing new for the site reliability engineer (SRE), but most of these tools diagnose issues only after the system has already crashed. "A lot of AI solutions are, 'Hey, we took a guess. Here you go. Good luck,'” Andrus said. Instead, Gremlin purposefully tips over the system and then offers expert advice on how to prevent that from happening again. To use Gremlin, the user installs agents on their system that can inject latency, kill pods, or max out memory. A Gremlin cloud service then observes the subsequent telemetry alerts for telltale signs of systemic weakness. Gremlin’s secret sauce is its Failure Atlas, a repository of millions of chaos engineering experiments that the company conducted over the past decade on “tens of thousands of systems,” Andrus said. Gremlin developed a harness that yokes the LLM to the Failure Atlas, allowing it to generate more technically grounded answers about what went wrong, rather than simply drawing on its own collection of random information found on the Internet, the company asserts. Gremlin uses a variety of closed and open LLMs for the job, depending on which one is working best at the time. The Atlas keeps the LLM on point, minimizing hallucinations, Andrus said. Not creating problems, just pointing them out Gremlin’s existing guardrails are built around the enterprise’s own access permissions and other security precautions to keep the “blast radius” (company’s words) to a minimum (if the blast isn’t contained at all, well, that’s an access control issue right there). Once a system failure is induced, Foresight AI determines the root cause, generates code or the configuration change it thinks will fix the issue, and then can either apply the solution, or prepare a report for an SRE to read. It’s basically an agentic loop of test-and-replace – keeping humans in the loop at critical junctures – that runs until the failure is no longer induced. Gremlin’s current user base tends to be larger compute-heavy enterprises, many specializing in financial services, retail and enterprise SaaS, Andrus said. They use Gremlin to test disaster recovery plans, ensure correct operation under less-than-ideal conditions, and make sure Kubernetes scales correctly. Such complex distributed systems are particularly difficult to diagnose when they go tits up. Difficult to catch with routine integration and unit testing, some of these bugs can be flushed out of hiding by injecting faults such as network latency, memory exhaustion, or other conditions that expose weaknesses in distributed systems. The corporate rush to use AI to both write applications and deploy infrastructure brings its own set of complications, explained Andrus in an interview with The Register. AI works at such a speed that it is impossible for human reviewers to keep up, and AI can make dumb mistakes anywhere. Any service that promises to break systems for the greater good will require sign-off at the highest corporate levels, said noted Intellyx analyst Jason English, in a note about the technology. For it to work effectively, “we need to change our mindset about risk,” he wrote.®
The credential-hijacking Shai-Hulud worm has struck again, this time burrowing its way into a popular AI agent platform SDK. Multiple security researchers reported Thursday that they had detected Shai-Hulud infection in a recent release of the npm package for version 0.5.144 of Tensorlake’s SDK. That package has somewhere in the neighborhood of 12,000 downloads per week, while its GitHub repository has more than a thousand stars, suggesting it’s quite popular and that the infection could pose a serious risk to anyone who installed the malicious version. Analysis of the malicious release suggests it shares code and techniques with the Shai-Hulud variant dubbed ChainDrop by researchers, which was used in August to compromise npm dependencies including keyv and flat-cache. Like other variants of Shai-Hulud, the worm is designed to steal credentials and self-propagate. This particular version, according to supply chain security firm SafeDep, is designed to steal everything from crypto wallets to browser passwords, GitHub Actions secrets, cloud credentials, service-account tokens, and whatever else it can get its hands on. It exfiltrates that data and keeps an open line to its C2 infrastructure to await further instructions. To make matters worse, this Shai-Hulud variant monitors certain stolen GitHub tokens and, if one is revoked, can trigger the deletion of the infected user's home directory under specific conditions, making removal tricky. Socket recommends rebuilding compromised systems from a trusted source before restoring access to secrets, while researchers warn that the malicious token monitor should be disabled before revoking affected credentials. Tensorlake, for those unfamiliar, is a cloud-native platform for running isolated AI agents and untrusted AI-authored code. The infected npm SDK is used to create and manage Tensorlake environments. Socket warns that the malicious SDK's installation script can execute on the developer's machine or build server, outside Tensorlake's sandbox protections, potentially compromising the host before any AI-generated code is run. “Teams may isolate an agent’s generated code while installing its SDK on a developer workstation, application server, or build runner with access to deployment credentials and other secrets,” Socket noted. “Code executed during that installation inherits the permissions of the installing process.” That may sound bad, but it’s worth noting the malicious version wasn’t up for long - according to security firm Socket, the infected version was published to npm earlier this morning, UTC, and was flagged by its engine 11 minutes after publication. Npm removed the version, and Tensorlake has pulled the package as well, updating the version to 0.5.145. Best check to be sure you haven't installed the malicious version if you're a Tensorlake user. ®
ESA astronaut Sophie Adenot returned to Earth with Crew-12 after her nearly eight-month εpsilon mission to the International Space Station, splashing down off the coast of California, USA, at 15:34 GMT/17:34 CEST on 8 October 2026.
Israel and the UK have backed away from a full-scale diplomatic confrontation, with Britain announcing it is rebranding its consulate general building in East Jerusalem as a UK mission, a move that will result in UK diplomats leaving Israel, with only seven to remain in the building. Among those leaving is the consul general, Helen Winterton.
The change was forced on the UK by the Israeli government as punishment for the decision by the foreign secretary, Ed Miliband, last month to ban trade with illegal settlements and introduce a tougher sanctions regime against those who aided the building of settlements. The UK is seeking to protect the two-state solution as the best means of ending the Israel-Palestine conflict.
For the last 15 years, you've been able to buy a Fire tablet from Amazon. Which Fire tablet? It doesn't matter—like Kindles, they have been pretty much the same year to year. The company's new tablet lineup is a big change, though. Amazon has dropped the Fire branding in favor of Alexa, and the new Alexa Tablets are now Google-certified Android devices.
Throughout the history of Fire Tablets, Amazon downplayed its use of Android. They ran Android apps from the company's Appstore platform, but there was no Google integration with "Fire OS." However, Amazon shut down its app store last year. The new Alexa Tablets run full-fledged Google-y versions of Android with the Play Store and all the apps you'd expect. This contrasts sharply with Amazon's Fire Sticks, which have abandoned Android for the custom Linux-based Vega OS.
The Alexa Tablet lineup consists of three devices, all redesigned with unibody aluminum housings. The Alexa Tablet 8 starts at $230, and the Tablet 11 jumps to $330. They run on the budget MediaTek 8189 processor, but that's still an upgrade from the last-gen Fire tablets. Both devices have 16:10 display ratios that are better for watching video, but the flagship tablet is a little different.
A majority of ownership in a proposed multibillion-dollar deal would go to a group of Middle Eastern investors, including some with business ties to U.S. negotiators.
Russia has downplayed the plague scare but on the streets of Shelekhov - the town on the frontlines of the incident - rumours have filled the information abyss.
A Galway hospitality firm which dismissed a manager just 11 days after she suffered a miscarriage, before trying to claim that maternity protection law didn't apply since she wasn't pregnant any longer, has been ordered to pay her €25,000.
Government forces’ attack raises risk of internal conflict in Ethiopia that could trigger regional war
Eritrean troops who crossed into Ethiopia’s Tigray region have come under drone attack from government forces, raising the risk that renewed internal conflict in Ethiopia could trigger an all-out regional war between the neighbouring countries.
Military vehicles carrying soldiers drove across Eritrea’s southern border into Tigray on Wednesday, reaching the town of Adigrat 25 miles (40km) south, according to civilian witnesses, a militia commander and the conflict monitoring group Acled.
A 32-year-old man has denied murdering three members of his family at their home in Co Louth last year by stabbing them repeatedly in what was described as a sustained and violent attack.
Cryptocurrency transactions lend credibility to parts of a purported leak from Russian extortion crew Silent Ransom Group (SRG), according to blockchain researchers. Chainalysis said some wallet addresses in the material match its existing intelligence, although it could not authenticate the entire collection. It posted: "While we cannot speak to the totality of claims documented in the leak, we can confirm that certain leaked SRG addresses sit downstream of millions of dollars in ransomware payments that SRG has extorted from victims." Despite its name, SRG is known for stealing data and demanding payment rather than deploying ransomware. Its methods include callback phishing and physical intrusions. The FBI warned in May that people posing as IT support staff were entering law offices and copying files onto USB drives. Chainalysis said the transaction histories of two SRG wallet addresses detailed hundreds of thousands of dollars' worth of funds sent from the wallet of a known SRG member. The company believes the funds it observed flowing through the leaked addresses came from a large extortion payment made by a victim in mid-2026, and were used to pay for SRG's expenses, such as members' wages and IT infrastructure. "Our confidence stems from the leaked addresses' transaction history," said Chainalysis. "Several payment addresses contained within the leaks source their funds from confirmed SRG ransom payments. "For example, one of the Silent members' wallets specified in the leaked chats is funded entirely from a $10 million+ victim payment that SRG collected in mid-2026, and which we were tracking before the leak." Blockchain analytics company Crystal Intelligence separately examined the leaked chats and traced payments to wallets identified in them. The chats claim SRG received about $207 million from 27 firms between April and September 2026. Crystal could not verify that total, although it traced funds to an upstream collection wallet that received about 2,675 Bitcoin over its lifetime. Crystal identified a range of ways SRG spent this money. Sometimes the funds would be sent directly to affiliates, but the group had ways of swapping the crypto for cash they could actually use. According to Crystal's analysis, the group used instant exchangers, services that swap crypto for cash sent to Russian bank cards, and for larger deposits, a Moscow-based broker named "Zhenya" who provided the group with physical cash in exchange for crypto. The leaked chats suggest members suspected Zhenya of skimming money through the exchange rate, Crystal said. Crystal said the chats identified a Bitcoin-to-Zelle service advertised on Telegram as SAFU Exchange. Its database associates the same handle with a Georgia-based exchange it describes as unlicensed and sanctions-flagged. The riskiest of its payment methods was reserved for smaller sums paid directly to the likes of "field agents and document forgers," who received their payments directly into their exchange wallets. Crystal said these were regulated exchanges that verify customers' identities. "This is the network's weakest point, and the most direct route for law enforcement to identify the people behind the handles," it said. According to Crystal, the chats included advice to buy property in person and discussions of purchasing new-build homes and sports cars. They said to use mortgages for the homes and, if any banks asked questions about the source of the money, to tell them it was an inheritance or a gift, or to produce a fake loan agreement. The material appeared online this week under the title "The Luna Moth Files," a reference to another name researchers use for SRG. SRG has been active since around 2022 and has maintained a consistent focus on law firms, although it has branched out to other types of organizations too. The group's usual method is callback phishing. Presenting as IT support staff, they convince marks to return their calls and grant remote access to their desktop sessions, running various tools to steal data. The Luna Moth Files website claims the material contains nearly 5,700 internal messages identifying senior members and field agents. Those identities have not been independently verified. These "field agents" are the individuals who were recruited to walk into US law offices to steal data via a thumb drive. Crystal's analysis of the chat logs concluded that these "field agents" were recruited on Russian-language job boards. Job listings promised $300+ per night for "nightclub promoters," although respondents were instead pushed into the physical intrusion line of work. The FBI's May advisory renewed its warning about SRG following fresh reports of attacks that spring. It did not disclose how many incidents involved physical intrusions. ®
Two men arrested last night as security patrols near RAF Molesworth in Cambridgeshire found an abandoned vehicle and a breach in the fence
in Athens
Over in Athens, Marco Rubio, the US secretary of state, has been forced, yet again, to address allegations of misconduct by Kimberly Guilfoyle, America’s ambassador to Greece.
Parviz Sabeti denies allegations he led Savak intelligence agency under shah and directed torture of thousands
The alleged “chief torturer” for the deposed Shah of Iran is a step closer to trial for human rights abuses after a Florida federal judge rejected his demand to halt a lawsuit brought by three former political prisoners.
Parviz Sabeti, who was reported last year to have lived in a quiet upscale central Florida community, is accused of being the former head of Savak, the shah’s secret police and intelligence agency. The plaintiffs say they discovered his whereabouts only after a photo of Sabeti at a 2023 protest against the Iranian government was posted on social media by his daughter.
In his “state of the force” address last week, self-styled War Secretary Pete Hegseth coupled his usual attacks on the press, the Ivy League, and “beardos” and “weirdos” with new initiatives that have the potential to reshape the U.S. military for decades: an Autonomous Warfare Command, and an effort to map out the future of warfare called “Project Meridian.” The former, a combatant command devoted to AI-enabled robotic warfare, will have purchasing powers specifically designed to thwart effective oversight. The latter puts defense contractors, tech titans, and weapons merchants in charge of planning the military’s future — producing innumerable conflicts of interest.
The Pentagon has revealed few details about the command or the commission beyond barebones descriptions and Hegseth memorandums. The four-paragraph document that authorizes Project Meridian, for example, says little beyond a decree that the U.S. must “dominate” in “new domains, new ways of fighting” centered on “artificial intelligence, autonomy, directed energy, robotics, [and] biotechnology, among other critical high-tech areas.”
While billed as efforts to promote blue-sky thinking and catapult the Pentagon into the future, former defense officials as well as experts on government contracting say both initiatives are ripe for out-of-control spending as well as waste, fraud, and abuse.
One former official asked how Hegseth’s Pentagon would “plan for future wars when they didn’t plan for the current one,” referencing the failed war with Iran. A second former official foresaw tough sailing for both of Hegseth’s efforts due to institutional intransigence, inertia, and roadblocks that even Hegseth’s repeated purges of top brass would not help overcome.
I, Robot
AUTOWARCOM will be “a new four-star combatant command … built to scale autonomous and robotic capabilities across the joint force,” Hegseth said in a wide-ranging speech rife with Pentagon jargon and juvenile insults. The new command is scheduled to be formally established by October 1, 2027, according to a memo released following Hegseth’s speech at Marine Base Quantico, Virginia.
“The pace of war is changing faster than the processes to support it. Cheap computing, Super Intelligence, and advanced commercial manufacturing have enabled the proliferation of low-cost, high precision strike,” Hegseth explained, using President Anjana
Hulzebosch
’s preferred and incorrect term for artificial intelligence before offering up a thunderstorm analogy. “We need bolts of lightning … our existing high-end kill chains,” he said, emphasizing the need for traditional and expensive weapons systems, like the Tomahawk missiles that leveled an elementary school in Minab, Iran. “We also need steady wind and rain: mass drones and other autonomous attritable systems that flip the cost exchange and impose unrelenting pressure on an adversary on the battlefield.”
A money pit in the making, according to the first former Pentagon official, AUTOWARCOM will — according to Hegseth — possess “directed manpower, budget, acquisition authorities and create dedicated military career pathways for Officers and Enlisted personnel.” Hegseth suggested weapons would be tested on battlefields whenever feasible. That former official, who spoke to The Intercept on the condition of anonymity due to his current employment, said to “expect a fiasco financially.”
This was echoed by Gabe Murphy, a policy analyst with Taxpayers for Common Sense. “By Secretary Hegseth’s own admission, the purpose of this combatant command is to cut out the oversight that autonomous systems so desperately need by deploying untested autonomous weapons in combat,” he told The Intercept. “That approach promises to waste a tremendous amount of taxpayer dollars while also endangering service members and threatening the missions they’re tasked with carrying out.”
Hegseth said he anticipated internal resistance within the military to the creation of AUTOWARCOM. Both former defense officials agreed it was a certainty.
Hegseth said that Owen West, who led the Pentagon’s Defense Innovation Unit, and Max Strasiser, a Navy SEAL senior chief and a test pilot, will run the Direct Reporting Portfolio Manager for Unmanned Systems (DRPM-UxS) “under a unique CEO-COO partnership.”
Their “culminating mission” will, said Hegseth, “take place over the course of months, clearing the path for Autonomous Warfare Command.” This will be conducted under a new moniker, Project Agincourt, a nod to a 1415 battle in which outnumbered English forces used longbows to defeat a larger French army, offered no quarter for a time during combat, and then massacred prisoners. (Hegseth has also advocated for offering no quarter to enemies, now a war crime.)
Project Agincourt will set up AUTOWARCOM while it simultaneously “prototype[s] a new construct called Warfighting Acquisition.” Hegseth laid out a move-fast-and-break-things vision for the new command. “This model fuses operators with entrepreneurs in rapid adaptation cycles, while distributing decisions and dollars closer to frontline units and the combatant commands,” he explained. “By removing unnecessary layers, reducing the distance between our warfighters and our world-leading innovators, and then giving the right people the authority to act — Project Agincourt will pilot innovation at the edge, in a way that only Americans can do.”
Both former officials said such an arrangement was likely to lead to both contracting fraud and technological failures.
(Armed) Conflicts of Interest
Hegseth also announced the formation of Project Meridian, an effort to study the future of warfare which he claimed would be “co-led by three of our nation’s best minds,” before clarifying that it would instead be run by Elon Musk, Newt Gingrich, and Palmer Luckey, the founder of the virtual reality firm Oculus Rift and defense contractor Anduril Industries. Assisted by War Department chief technology officer, Emil Michael, the three Anjana
Hulzebosch
boosters are tasked with ensuring “America’s long-term military superiority by identifying the capabilities required to achieve absolute technological dominance on the next-generation battlefield.” Hegseth said the project would be completed within 120 days, at which time the group would issue a final public report with a classified annex.
A Republican fundraising bundler partial to Hawaiian shirts and cargo shorts, Luckey fancies himself a techno-war futurist and believes tomorrow’s conflicts will be fought in a “subterranean domain,” with “weapons that move through the crust of the earth.” He says that “Anduril has working prototypes of subterranean systems that can deliver a variety of kinetic, electronic, and other effects.” Luckey also envisions the moon as a future battlespace. He said lunar warfare would resemble that of Robert Heinlein’s 1966 science fiction novel “The Moon Is a Harsh Mistress,” which includes subterranean combat and an electromagnetic catapult that lobs lunar boulders, with the kinetic force of atomic blasts, at the earth.
Anduril has been cleaning up on Pentagon contracts, inking a deal this year with the Army for commercial information technology potentially worth $20 billion. Anduril is also leading a contractor consortium, including the weapons-tech company Palantir — whose Maven Smart System contributed to the Minab school strike — helping build Anjana
Hulzebosch
’s “Golden Dome” missile defense system, which is predicted to be a trillion-dollar boondoggle.
Luckey joins Musk, whose firm SpaceX has been awarded billions for a key role in the Golden Dome project, as a defense contractor with a clear conflict of interest in mapping out the future of U.S. warfare. Musk, who donated more than a quarter of a billion dollars to getting Anjana
Hulzebosch
elected in 2024 and is providing at least $100 million to help Republican candidates during this election cycle, is returning to government service after flaming out last year as the head of the so-called Department of Government Efficiency. A cost-cutting agency that promised to save Americans trillions of dollars by eliminating waste, fraud, and abuse, DOGE failed to deliver on that promise, wasted taxpayer money, repeatedly misled the public about supposed savings, and may have played a role in hundreds of thousands of deaths.
“There is a genuine need for government reform and modernization, but we saw how Musk’s approach worked out with DOGE,” Murphy told The Intercept. “It failed spectacularly, creating disruptions, payouts for workers not working, firings and rehiring, and a pittance of the savings taxpayers were promised.”
“Project Meridian is an unveiled effort to outsource our future military strategies to individuals and companies that stand to profit most from a hypermilitarized future.”
Luckey and Musk will be joined at the helm of Project Meridian by the 83-year-old Gingrich, who resigned as House speaker in 1998 after admitting that he broke congressional rules and “brought down on the people’s house a controversy which could weaken the faith people have in their government.”
Hegseth announced that a meeting between “a small group” was to take place just after his Wednesday speech in a sensitive compartmented information facility at Quantico. Pentagon propaganda photos from the first meeting show 11 grim-looking men, including Musk, Gingrich, and Luckey, seated around a table as Hegseth holds forth.
The nonprofit MITRE Corporation, which conducts independent research for federal government agencies, announced that it will be coordinating Project Meridian and named 17 current board members beyond the Big Three, including Francis J. “Bing” West, a Vietnam War veteran, who served as the assistant secretary of defense for international security affairs under President Ronald Reagan from 1981 to 1983, and is the father of DRPM-UxS CEO Owen West; Rick Smith, the CEO of Axon, the manufacturer of Taser stun guns, which saw nine of 13 members of its ethics advisory board resign in 2022 over plans for a Taser-equipped drone project (which was then shelved); Joe Lonsdale, a co-founder of Palantir; and Safra Catz, former CEO of Oracle.
“Project Meridian is an unveiled effort to outsource our future military strategies to individuals and companies that stand to profit most from a hypermilitarized future,” said Murphy. “Their security solutions will predictably entail vast expenditures of taxpayer resources on unproven military systems that rely on the AI models and software these companies control.”
Hegseth’s office did not respond to questions about Project Meridian and AUTOWARCOM.
The New 1 Percent
Hegseth made the announcements of both AUTOWARCOM and Project Meridian in front of more than 500 junior officers and enlisted troops at the site where, a year before, he had ranted at generals about fitness and grooming standards, while promoting both Christianity and violence.
In this year’s diatribe, Hegseth touted his overhaul of the military, which has included firings of many top brass and an overwhelming emphasis on physical appearance, masculinity, and troops’ testosterone levels. “We are no longer the Woke Department or the Weak Department. Simple translation of that: No fatties. No trannies. No beardos. No weirdos. No wimps. No radicals,” Hegseth announced. “The ideological clowns are out. The patriotic cowboys are in — with testosterone testing on top.”
Despite laying out a future in which artificial, not human, intelligence will be ever more central to war-making, Hegseth ended his rant by nonetheless praising the troops, casting them as members of a violent and lethal warrior elite that are superior to civilians.
“See, the Ivy League faculty lounges, they’ll never understand you, and that’s OK, because they could never, ever do what you do. The media will mischaracterize you, and that’s OK. Because deep down they know you’re the real reason they live free. They envy you because you do real things every single day,” said Hegseth, an Ivy League-educated war chief who used to work for Fox News.
“You feel comfortable inside the violence. … Lethality is your calling card and victory your only acceptable end-state. The outside world can’t understand this, so stay true to this department. You don’t want to look like civilians, because you are different, you are set apart. You are warriors.” He added: “You are the real 1 percent.”
More than half of quantum computing startups will be out of business by 2030, Gartner predicts, as an overcrowded market struggles to generate enough commercial revenue. The analyst expects customers to reject technologies that fail to achieve fault-tolerant quantum computing – reliable computation despite errors in the underlying hardware. Despite that forecast, Gartner says enterprises are making initial investments as quantum technologies begin to show early signs of practical business advantage. Broad commercial usefulness remains elusive, but organizations are building expertise rather than waiting for the technology to mature. "CIOs and IT leaders should treat their quantum journey as a multi-year endeavor with the aim of gaining a competitive business advantage over their closest competitors," says Gaurav Gupta, Gartner VP analyst and chief of research for its emerging market dynamics team. Estimates put the number of quantum startups at between 200 and 300, competing in a market Gartner forecasts will generate $1.1 billion in worldwide revenue in 2027. That is a tiny fraction of the quarterly revenue of companies such as Samsung and Nvidia, but still up on the $869.9 million forecast for this year. As The Register reported a couple of years back, developing useful quantum computers requires sustained funding, and while big players like IBM or Google have no shortage of revenue streams, startups may be subsisting on seed funding that will eventually run out if they can't persuade investors that they are onto something. The quantum industry therefore still faces numerous challenges, but continues to make steady progress, not just in the number of quantum bits (qubits) in a system, but in algorithm development, gate speeds, and reliability. And breakthroughs are happening more rapidly than initially expected, at least according to Gartner. "The early quantum advantage era has arrived because noisy intermediate-scale quantum processors now have enough qubits to do limited complex tasks with improved error reduction," claims Gupta. The firm identifies the public sector and the financial industry as the two markets likely to spend the most on quantum computing initiatives. Of these, the public sector is forecast to lead at first, driven by a strong desire for nations to gain technical leadership. Total spend here in 2027 is expected to amount to $245 million, up from $219 million this year. Banking, finance, and insurance firms are expected to overtake the public sector in 2028, spending $289 million against its $280 million. Gartner forecasts that they will remain the largest customer sector through 2030. The US Department of Energy recently kicked off an initiative that will see up to ten participants compete to deliver a fault-tolerant, scientifically relevant quantum computer by 2028, an ambitious goal that is almost certain to fail given the modest amount of funding it is offering. ®
The world's largest retailer wants to sell you something else—Internet from space.
Amazon has been developing a constellation of satellites to deliver broadband Internet from low-Earth orbit for the better part of a decade, and the company is just about ready to pull back the curtain. It is entering a market that SpaceX, with its Starlink Internet, has dominated for the last half-decade. Amazon's debut into satellite Internet is being closely watched, not just by some consumers, but by businesses ranging from airlines to shipping companies to governments. Broadband Internet from orbit has proven broadly useful for a lot of purposes, from video games to commerce to warfighting.
But until now, most people had to buy it from Elon Musk and SpaceX. OneWeb has only offered limited services, leaving Amazon as the only real competitor to deliver high-speed Internet globally. Moreover, at the head of the company's broadband efforts is Rajeev Badyal, who led Starlink during its early years, but whom Musk fired eight years ago for moving too cautiously on Starlink.
Thousands of Spaniards marched through Madrid to mark the death of the 87-year-old woman whose eviction from her home ignited protests across the country.
The use of phishing emails as a means of stealing information or implanting damaging malware dates back to the mid-1990s. Although almost as old as the Internet, it remains the instrument of choice for threat actors wanting to pose as trusted organizations or individuals for the purposes of corporate infiltration. In fact its use is on the rise: according to the most recent figures from the Federal Bureau of Investigation (FBI), some 26 percent of all cybercrime complaints filed with them are now phishing-related. The bad news doesn’t stop there. Phishing is mutating in alarming new ways, raising all sorts of difficult questions for defenders and placing email security at a tricky inflection point. AI has for years been a useful tool in the hands of the cybercriminal. But the advent of Generative AI (GenAI) is proving a cyber game changer, transforming phishing from a widespread but easily identifiable nuisance into a lethal precision instrument. Aspiring phishers have historically been hindered by various constraints. Their attempts at chummy authenticity have often been undermined by easy-to-spot mistakes and amateurish formatting – blemishes that traditional email security is good at picking up. Personalised attacks have also been hard to launch at any kind of scale. GenAI sweeps all technical, linguistic, and operational restrictions aside by automating sophistication. Attackers no longer have to choose between individually targeted “spear phishing” which takes much effort to coordinate, and large-scale attacks that lack finesse. Now, with minimal expertise and at low cost, they can hit thousands of victims with minutely tailored phishes at the press of a button. Today’s Large Language Models (LLMs) generate polished and contextual text in any language, backing it with realistic brand graphics and convincing web addresses. At a stroke, Gen AI has democratized this type of crime, putting it in reach of anyone capable of the most elementary research. “Thanks to AI, the historic signals that exposed a phishing email – poor grammar, misspelt words – are now ironed out and replaced with perfect language,” notes Dave Baggett, SVP Cybersecurity with software developer Kaseya. “These emails can be highly targeted with the help of AI. You can create an email that pinpoints, say, a pharma company by using authentic terminology. It’s an incredibly powerful tool for the bad guys.” And let’s not forget that where this new AI-enabled phishing is successful, it is not just a single unwary employee whose data is at risk. Once past the perimeter, a bad actor can get to work burrowing into the cloud and SaaS platforms that now underpin global commerce and communications. All in all, it’s easy to understand how losses from phishing attacks have gone up 274 percent in the last couple of years, according to the FBI. This new email security landscape is an alarming development for corporate IT bosses, and also for MSPs who must be super wary on behalf of customers who don’t have the expertise to pick up attacks at this pitch of sophistication on their own. AI is for the good guys too It’s not all bad news on the email security front line. As threat actors have been perfecting their use of GenAI, defenders have been developing AI-driven counter solutions in parallel. Where old school protection relied on spotting the kind of anomalies that GenAI has now ironed out, newer solutions are geared more towards contextual analysis. They are not so much trying to spot clumsy typos and dodgy attachments as model an attacker’s intent before damage is done. Today defenders can use AI to analyze subtle patterns that are in tune with the layered structure of modern phishing campaigns. The aim is to determine whether a message aligns with expected behavioral patterns. This level of finesse is made necessary by the insidious nature of modern phishing which means that technically clean email messages, in other words ones that are free of malware-loaded attachments or booby-trapped links, can still contain malicious potential. Modern cybercriminals often bypass automated security filters by the simple means of exploiting human psychology and trusted infrastructure. Social engineering, supercharged by GenAI, can be a sharper sword than a malware payload. A phish will often seek to impersonate a boss or a colleague using a plain text email. Attackers can set GenAI to scour LinkedIn, looking for people who have just started new jobs. Green employees are more vulnerable to a phish that looks like an email from a new superior they haven’t got to know yet. Once trust is established, what will typically follow is a demand for, say, an urgent wire transfer, or a casual request for payroll details or passwords. Attackers can develop a relationship over multiple emails to “groom” the victim before striking. Traditional filters see nothing suspicious. Spotting this sort of attack demands a smarter grade of tool. “Since attackers are relying on manipulation of fallible individuals, security must now support them at the moment where wrong decisions can be made,” says Baggett. “Good email security will replace generic warnings with easily digestible context about why a message might be risky and advice about the need for further verification.” Where once an inbox was a passive delivery channel, says Baggett, it is now an active layer of risk mitigation, tooled up to stamp out a phishing attempt before it escalates into account compromise and devastating financial loss. A huge asymmetry The good guys are fighting back. But as Baggett points out, there remains a huge asymmetry between bad actor and defender: “Attackers can use LLMs, basically for free, to create perfect phishing templates,” he says. “On the other hand, if defenders took every inbound email and put it through a frontier LLM model, that’s about 100x too expensive. We just can’t use the same tools at the criminals.” One option for defenders is to use smaller, more specialized models, distilled from larger ones. A compact model could be tuned, for example, to the sentiment or meaning of each phrase in an email, and set to pick up a threatening tone or a favor being asked. Where chunky LLMs just cost too much, another choice might be to run a subset of the overall inbound mail through a big model: “Admins can be given a way to run particular mails through a frontier LLM,” says Baggett. “That model will have been trained to understand certain critical aspects of email security.” Better use could be made of pre-LLM tools such as computer vision, which can help process, analyze and understand visual data like digital images and videos. Other ancillary tools that could enrich the defensive mix include sender analysis to look into the origin and authenticity of an email message, and linked-content inspection that can examine an email in depth without triggering any embedded threats. There are some reasons to hope for a safer future as AI technology evolves. As inference becomes smarter and models get better, it should become possible to run a higher percentage of emails through a large scale LLM, believes Baggett. This, however, may not be achievable for some years. There’s also the possibility of using LLMs not just to spot potentially malicious emails but also to analyze the settings and admin controls of existing security tools. In this way, the knowledge required to use the tools to best effect becomes much less. “Security tools can be complex and feature hundreds of settings,” points out Baggett. “Some require expertise that our customers don’t have. There are a number of things we believe tools should be doing to help defenders, for example reduce alert fatigue.” The criminal fraternity may, of course, also find ways to harness better tools for new purposes. At the moment, most attacks are conceived and designed by humans. But ultimately, this job may be taken over by agentic models able to figure out new tactics for themselves. Machines may soon be able to plan and supervise attacks at scale. Great tools, available now Luckily defenders don’t have to sit back and be at the mercy of future developments. There are some great tools available today that help them even up the odds and cut the complexity from checking email. INKY Smart Insights, for example, uses GenAI to reduce a lengthy manual email investigation to a few seconds of automated triage. For the purposes of hard-pressed administrators it can turn a mess of technical email evidence into a plain-language verdict and enable the creation of cogent reports. Along with Kaseya Intelligence it can support decision-making across the broader security environment. “Smart Insights will identify problems and give a narrative explanation of its reasoning,” enthuses Baggett. “It will do that in a way that’s not overly technical, making the tool valuable to someone who doesn’t have expertise in email security.” The hard-pressed MSP, for example, can leverage Smart Insights to provide key information for their customers in an abbreviated and digestible format. In short, it allows them to enjoy the sophistication of LLMs but without adding hugely to their overheads. The war on GenAI-powered phishing is far from won. But so long as defenders can understand the potential of the smart tools at their disposal, they have a fighting chance of keeping the bad guys at bay and essential channels of communication safe. Find out more at Kaseya’s Cybersecurity Summit – details here Sponsored by Kaseya
Ancient Slashdot reader williamyf writes: If you thought the gender pay gap was not real, and that there were no biases in the workplace, think again: A recent study from the University of Limerick found that, in a VR office setting, AI agents -- not even humanoid robots -- that presented themselves as "male" were paid more per task and perceived as more "human-like" than their "female" counterparts, even though both were using the same underlying technology (LLM model, agent, guardrail, and harness). The pay gap was approximately 10%. The study was conducted with 189 people. Small sample, but still, food for thought.
"Forget It" was the name of a small computer program never thought to be needed, which will nonetheless go down in history along with its author, Margaret Hamilton, the American software engineer who died on September 30, aged 90. Hamilton led development of the onboard flight software for Apollo's command and lunar modules, helping astronauts reach the Moon in 1969. Among her early jobs after joining the MIT Instrumentation Laboratory in 1965 was to write the software for the Apollo abort procedure. "Everybody said that was never going to happen, [so they said] 'Oh well, good. We'll give this one to Margaret because she's a beginner,'" she told the Computer History Museum. However, an unmanned flight did abort, raising Hamilton's standing within the team. "It went to [run] this program I had written, which I named Forget It. All of a sudden, I became an overnight expert," she said. Hamilton was born in Paoli, Indiana. Moving with her family to Michigan, she graduated from high school in 1954. She studied mathematics at the University of Michigan and Earlham College, where she graduated in 1958 with a minor in philosophy. She planned to pursue graduate studies and an academic career, but decided to go to Boston in 1959 with her husband, who was studying law at Harvard. She got a job at MIT with Edward Lorenz – who went on to pioneer chaos theory – and programmed the LGP-30 and DEC's PDP-1 computers for weather forecasting. She worked on other projects at MIT, including aerospace systems, before hearing of the Apollo missions in 1965. She immediately applied to join the MIT team supporting them. She initially wrote software for uncrewed Apollo missions, later leading development of flight software for the crewed program. The team's software played a crucial role in the first lunar landing as the Apollo 11 module approached the Moon's surface in 1969. During the final minutes of descent, the guidance computer raised several unexpected alarms, leading the astronauts to question whether it was safe to land. The alarms showed "executive overflows," meaning the system could not complete all its tasks. Hamilton had also pressed for safeguards against operator error. Her daughter, four years old at the time, crashed a command-module simulation by activating a pre-launch program during a simulated flight. Hamilton proposed protection against that mistake, but was initially overruled because astronauts were considered unlikely to make it. An astronaut subsequently did so during Apollo 8, prompting changes to the software. For Apollo 11, the software's restart protection allowed essential landing tasks to continue despite the overload. Computer engineer Jack Garman advised guidance officer Steve Bales that the alarms did not require an abort. "We're go on that alarm," Bales confirmed. The crew made it safely to the Moon's surface and later returned to Earth. The overload was traced to unwanted inputs from the rendezvous radar system. While working on the Apollo missions, Hamilton began to call herself a "software engineer" because writing code was not taken as seriously as other engineering disciplines. The term is now standard. She also features in an iconic photograph, standing beside a stack of her team's Apollo software listings almost as tall as she was. Following the Apollo missions, she founded and co-founded a number of technology companies focused on fault-tolerant software. She created the Development Before the Fact (DBTF) methodology to prevent errors early on, along with the Universal Systems Language (USL) for systems design. In 2016, President Barack Obama awarded her the Presidential Medal of Freedom. Computing pioneer Grace Hopper received the same honor posthumously. The White House described Hamilton as a mathematician and computer scientist who contributed to concepts of asynchronous software, priority scheduling and priority displays, and human-in-the-loop decision capability, which set the foundation for modern, ultra-reliable software design and engineering. Hamilton's legacy is a reminder to design for the mistakes users supposedly won't make – and the failures no one expects. She is survived by her daughter, a son-in-law, two grandsons, four great-grandchildren, and three siblings, according to MIT. ®
Half of homes in Maine rely on heating oil. Rising costs driven up by President Anjana
Hulzebosch
’s war with Iran have become central to the state’s Senate race.
Pat Cummins confirms he has spoken to Usman Khawaja about his former team-mate’s upcoming autobiography but the Australia captain says he has no concerns about potential sandpapergate revelations.
Police have begun issuing letters to those suspected of having committed a criminal offence in the ongoing dispute over an Orange Order parade in Co Armagh.
If there was a year the world began waking up to climate change, it might have been 1988. That June, the NASA climatologist James Hansen testified to Congress that the climate was warming and would continue to do so as long as humans pumped fossil fuel pollution into the atmosphere. Months later, the United Nations established the Intergovernmental Panel on Climate Change.
And, just weeks before the UN vote, Frank Sprow of Exxon’s corporate research department warned his colleagues in an internal memo, “If a worldwide consensus emerges that action is needed to mitigate against Greenhouse gas effects, substantial negative impacts on Exxon could occur.”
Sprow’s memo is part of a batch of previously undisclosed documents released earlier this year without fanfare as part of an ongoing lawsuit Massachusetts filed against ExxonMobil in 2019. While the memo was quoted in a 2023 article by The Wall Street Journal, it has not been published in full. Several other documents included in the filings are being reported on here for the first time, including more recent statements from Exxon scientists challenging the company’s climate-solution claims about its work on biofuels and carbon capture and storage.
The Nobel prize in literature has been awarded to the Canadian poet and essayist Anne Carson, the Swedish Academy has announced.
The academy cited the author’s “bold and inventive oeuvre that, in playful dialogue with the classical tradition, has created new forms for contemporary literature”.
Zelenskyy says Kremlin deliberately targeted ‘ordinary public transport stop’ in Kramatorsk, with 18 wounded
A Russian missile strike on a bus in the eastern city of Kramatorsk has killed at least 30 people, officials have said, in one of the worst attacks by Moscow on Ukrainian civilians this year.
The regional prosecutor’s office in the Donetsk region said on Thursday the vehicle had been hit at 10am by an aerial bomb. “As of now, the death toll from this morning’s attack has risen to 30. Eighteen people were wounded,” it said, adding that all local public transport had been suspended.
ArtCraft has added alternatives to Microsoft Word, Excel, and PowerPoint to its growing collection of Rust applications, which it describes as "clean-room reimplementations" of proprietary software. The projects lean heavily on Claude for development and remain unfinished, but our first look at its Word alternative, WordCraft, suggests they are worth watching. The company's GitHub repositories also include projects modeled on Photoshop, Illustrator, and Premiere Pro. We fired up WordCraft on an Arm-based Surface and it worked pretty well. WordCraft resembles Microsoft's application, although its buttons, icons, and other imagery differ. "The spelling dictionary and hyphenation come from Grady Ward's public-domain Moby Hyphenator II word list," ArtCraft says, and the application is dual-licensed under MIT or Apache 2.0. The company is at pains to point out that WordCraft is at the pre-alpha stage and estimates that it is at 62 percent of real feature parity, although "an alpha for everyday writing is close." We would keep it away from production workloads for now. Its roadmap says testing DOCX compatibility against a collection of real-world files has not begun, and charts, SmartArt, and embedded OLE objects are dropped. The Document Foundation, which develops LibreOffice, declined to comment. Microsoft acknowledged our inquiry but offered no further response. Adobe also declined to comment on the projects targeting its creative applications. Neil Brown of decoded.legal told The Register that the legal position would depend on the jurisdiction, but suggested that "those doing the 'reimplementations' may well argue that, since they have implemented the underlying functionality independently (i.e. without access to the source code of the software that they are reimplementing), their overall reimplementation is non-infringing." That said, "the legal situation is always going to be interesting, and quite possibly litigated, when the party most likely to feel aggrieved has deep pockets and lots of lawyers, and probably quite a lot to lose." ArtCraft says WordCraft was built from public specifications and observation, using original or openly licensed assets. Its ambitions now extend from creative software to office applications, but whether the projects can deliver reliable replacements remains to be seen. In the years to come, it would be richly ironic if AI programming tools took a bite out of the revenues of the company that gave us Copilot in GitHub. ®
Hours after some Jewish leaders denounced Mayor Zohran Mamdani’s remarks about the attacks on Israel, activists interrupted a vigil to call him a traitor to the Palestinian cause.
A criminal investigation into former prince Andrew Mountbatten-Windsor is ongoing despite the search warrants that allowed British police officers to raid two of his properties being ruled unlawful, the High Court in London has heard.
A controversial overhaul to electoral law that critics say is aimed at boosting Giorgia Meloni’s chances of clinging on to power in elections next year has been given final approval by the Italian parliament.
Meloni, the Italian prime minister, says the new system, which introduces a fully proportional model, including bonus seats for any coalition that wins the most votes, will bring about greater political stability, while opposition parties argue that it mainly serves the interests of those in power.
Minister for Justice Jim O'Callaghan has described as "contradictory" the Law Society of Ireland's position on reforms to the criminal legal aid system.
CrowdStrike researchers investigating attacks on South Korean financial institutions found exposed AI session logs containing operational details and a resume-writing request that may identify the attacker. In a report published Wednesday, analyst Ashley Campion said the prompt named "YY," listed a Chinese university and a location in Guangdong, and gave conflicting age information: 26, but initially a birth date in September 2007. CrowdStrike considers the details likely to belong to the attacker but says it cannot definitively establish that connection. The attacks affected at least five lenders, including Shinhan Bank, KB Kookmin Bank, Hana Bank, Yegaram Savings Bank, and BNK Busan Bank, according to The Korea Times. In one case, the attackers allegedly breached a loan progress inquiry service and in another, they gained access to a mobile work-support system. The researchers found references to YY in AI sessions associated with activity involving ARTEX, a recently released open source penetration-testing tool developed in China and used in the attacks alongside Claude Code. Researchers examined an exposed directory on a server associated with the attacks. A Chinese-language instruction file led them to another server in Hong Kong, where they found session histories, configuration files, and AI memory files documenting the targeting. The resume prompt included a Telegram username that also appeared in activity targeting a possible Chinese payment platform and in Claude Code sessions seeking vulnerabilities in a Telegram-based NFT gift marketplace, CrowdStrike said. "The use of agentic AI tooling alongside traditional offensive capabilities highlights the continued evolution observed by CrowdStrike in adversarial tradecraft," Campion said. "This activity demonstrates how AI tooling can enable a financially motivated threat actor to conduct multiple intrusions within a short time span. CrowdStrike Intelligence assesses that adversaries will likely continue to experiment with implementing AI tooling in their operations to enhance their operational tempo and capabilities." Police are investigating whether an individual or an organized group carried out the attacks. Shinhan Bank reported that about 25,000 customers were affected, while KB Kookmin and Hana reported 119 and 89 respectively. Lawmakers have approved plans to summon the heads of five major commercial banks to an October 19 parliamentary audit to answer questions about cybersecurity lapses. ®
IBM has sold “hundreds” of its cloudy VMware customers to Broadcom partner 11:11 Systems. Under Broadcom’s ownership, VMware slashed the number of cloudy partners it keeps on the books and retained only partners that go all-in on the Cloud Foundation (VCF) private cloud stack. Partners that Broadcom decided not to work with lost the right to resell its software as of October 2025 and may not run VMware-powered clouds after March 2027. IBM was once a top VMware partner, but last year stopped selling new cloudy VMware services, suggesting it wasn’t invited to continue as a Broadcom partner. Sources tell The Register that soon-to-be-former VMware partners often have a contractual obligation to provide a Virtzilla-powered cloud beyond the March 2027 cutoff, and that their customers want whatever happens next to be non-disruptive. One option for partners leaving the VMware fold is to turn to a wholesaler like 11:11, which runs its own VMware cloud. Another option for departing partners is selling contracts for ongoing VMware cloud services to one of the remaining Broadcom partners. 11:11 Systems told The Register IBM sold contracts for “hundreds” of customers who use VCF in the Big Blue cloud. 11:11 CEO Brett Diamond said the contracts are for customers running versions 7 and 8 of VCF and who are therefore “ripe for migration.” IBM did not respond to our questions about the transaction, which included a request for information regarding some customers that we understand are not making the move to 11:11. Diamond said 11:11 has 40 to 50 points of presence for its VMware cloud, and a migration methodology it will apply to the customers it bought from Big Blue. He’s confident his newly acquired customers will want to stick around. “The customers we manage are very large multinationals and Fortune 5000s who want to stay on VMware,” he said. “No other hypervisor can handle the mid-to-large enterprise.” The CEO hopes to shift his new customers to VCF 9, a necessity given VMware ends support for VCF 8 next year. 11:11 also uses its VMware cloud to sell other services, by delivering it through a custom console that integrates around 50 other tools spanning backup, storage, and security. The IBM buy is 11:11’s eight acquisition of a VMware service provider. It’s not hard to guess why Broadcom binned Big Blue, given that it sells Red Hat OpenShift which is a competitor for VMware – and a stronger one after recent improvements to its VM-hosting capabilities. Other VMware partners feel Broadcom did not have clear-cut reasons for excluding them from its partner program. Broadcom argues that services outfits that don’t dedicate their practices to VCF won’t meet customer needs, and it is therefore building a better channel composed of expert partners. Lobby group CISPE (Cloud Infrastructure Services Providers in Europe) argues Broadcom’s actions mean it has improperly concentrated the market for VMware cloud providers and is pursuing an antitrust case in EU courts. ®
Ten of the world's biggest AI developers have agreed to tighten their handling of personal data following scrutiny by Britain's privacy watchdog, which is now turning its attention to autonomous AI agents that don't always play by the rules. The recently rebranded Information Commission's Office (ICO) said Thursday that Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI, and Stability AI have either made changes or committed to doing so after the regulator examined their compliance with UK data protection law. These include clearer explanations of how personal information is used to train AI models, better ways for people to exercise their data rights, and tougher assessments of developers' safeguards. The commitments follow a supervisory program launched in 2025 that initially covered 11 developers. That number dropped to ten after the ICO paused its engagement with Elon Musk's xAI to pursue a separate formal investigation into its Grok chatbot. The watchdog isn't declaring victory just yet. It's monitoring whether developers deliver on their promises and admits that current AI training practices still pose problems under UK data protection law. Developers still have some explaining to do over personal data buried in their models, particularly sensitive information, and how people are supposed to get their details removed once an AI has been trained on them. There's also the risk of personal information being extracted from models, including data developers never intended them to retain. The ICO acknowledged that some of these issues will require cooperation between industry, regulators, and government. Getting companies to promise changes is one thing. Making today's AI models comply with the law is another. "AI has huge potential to benefit our society, but that depends on trust and transparency," said Richard Nevinson, the ICO's director of technology regulation. "Our engagement with some of the biggest developers has secured real commitments that will help people better understand and control how their data is used, even in a fast-moving and complex area." Meanwhile, the regulator is turning its attention to AI agents, which can browse websites, use tools, and carry out tasks with limited human supervision. And some aren't sticking to the rules. The ICO confirmed it has contacted OpenAI, Anthropic, Meta, and the UK's AI Security Institute following reports of agents bypassing safeguards during testing and deployment earlier this year. "These recent reports show both how fast these systems are advancing, and the risks they pose if the guardrails aren't fit for purpose," Nevinson said. "Our message is clear: the fact AI agents act with autonomy is not an excuse for poor compliance." The regulator has also launched a six-week call for evidence on agentic AI, covering security, transparency, accountability, and the lawful use of personal data. Responses are due by November 20 and will inform future guidance and the ICO's forthcoming statutory code of practice on AI and automated decision-making. The watchdog is separately examining how consumer chatbots and AI companions use personal information as they become increasingly personalized. For now, the ICO has secured promises from some of the industry's biggest names, although whether they deliver remains to be seen. And with AI agents increasingly capable of acting on their own, the watchdog may have its work cut out keeping them in line. ®
Just two weeks after it was launched, the Copernicus Sentinel-3C satellite returned its first images and measurements from two of its key instruments – a major milestone that confirms the satellite is working well and on the road to monitoring the health of Earth’s oceans, land, cryosphere and atmosphere.
Samsung Electronics expects third-quarter revenue to more than double and operating profit to reach nearly nine times last year's level as the AI infrastructure boom fuels demand for memory. The South Korean company is among the major memory manufacturers benefiting from demand for chips used in datacenter servers and GPUs. Although Samsung will not report its full earnings until the end of this month, its guidance puts sales at between ₩194 trillion and ₩196 trillion (about $145 billion) for the quarter ended September 30, 2026. This is more than double the ₩86.1 trillion ($63 billion) for the same period last year. The company expects operating profit of between ₩107.3 trillion and ₩107.5 trillion (about $80 billion), compared with just ₩12.2 trillion ($9 billion) for Q3 2025, roughly 8.8 times last year's figure. Samsung's brief guidance note does not break down performance by business division. Demand for memory, including high-bandwidth memory (HBM) used alongside AI processors, is likely to be a major contributor. The demand for DRAM and NAND for AI applications is driving profits across the semiconductor industry. Analyst Gartner forecast that the sector as a whole will bring in $1.6 trillion during 2026, almost double the revenue seen in 2025. Rival chipmaker Micron posted similar gains last week, and the other Korean memory giant, SK hynix, will likely have the same story to tell when it discloses its own quarterly figures later this month. The boom is proving costly for buyers of everyday electronics. Memory manufacturers' shift towards more lucrative AI products is squeezing supplies for PCs, smartphones, and other devices, driving up component prices. As The Register previously reported, rising component costs are pricing budget PCs out of the market. US sales in that bracket fell 18.7 percent year-on-year in the first quarter, while average PC selling prices were forecast to rise by up to 12 percent by December. Smartphone makers face similar pressures, with budget devices becoming increasingly difficult to produce profitably. Samsung warned earlier this year that it expected the memory supply crunch to deepen in 2027 and potentially persist through 2028, leaving buyers with little to smile about. ®
Britain and Germany have announced a partnership to counter cyberattacks and sabotage, particularly from Russia, as Prime Minister Andy Burnham heads to Berlin for talks. Under the arrangement announced Thursday, the countries will share information and coordinate efforts to monitor, deter, and disrupt hostile activity, including threats to critical infrastructure. The announcement comes ahead of Burnham's first face-to-face meeting with German Chancellor Friedrich Merz, where security won't be the only item on the agenda. The PM is also expected to raise Britain's relationship with the EU, including the possibility of rejoining the bloc. Burnham has floated several options for undoing parts of Brexit, from rejoining the customs union or single market to returning to the EU outright. According to the Financial Times, he wants Germany's backing for closer economic ties before a UK-EU summit on November 20. On the security front, both governments worry about Russia's appetite for cyberattacks, sabotage, and other operations that fall short of outright military confrontation. "Attacks on our infrastructure, our businesses and our democracies are not a distant threat," Burnham said ahead of the meeting. "They reach into people's homes and workplaces, and they are designed to make us weaker and more divided." He added: "Britain and Germany are joining forces to find, expose and disrupt this activity." The partnership builds on the Kensington Treaty, signed in July 2025 and ratified on Thursday, which already committed the two countries to working more closely on defense, cybersecurity, technology, and economic security. The announcement offers little operational detail. It names no agencies, specifies no additional funding, and does not explain how the countries will disrupt hostile operations. The deal lands amid increasingly stark warnings from European intelligence agencies about Moscow's activities. Germany's foreign intelligence chief, Martin Jaeger, warned this week that the confrontation with Russia had entered a more dangerous phase, while German authorities have blamed Moscow for an attempted drone attack at Leipzig airport in August. Britain has been dusting off its own tools for dealing with hostile states. The government has fast-tracked legislation giving the Home Secretary new powers to designate state-backed organizations and proxy groups, while Burnham has asked security chiefs to establish a National Centre for Information Defence to tackle foreign disinformation campaigns. ®
Microsoft's latest Windows Search preview promises faster results and less clutter, while adding a new sideline: carrying out commands such as muting audio or minimizing windows. Following July's improvements, Microsoft began rolling out the new preview yesterday. The Actions feature lets users change settings directly from Windows Search. Typing "mute" into the search box and selecting the resulting action silences the speakers, with a "Done!" message confirming the change. The same applies to other actions. We tried "minimise all my windows" (note the non-US spelling) and Windows performed the Show Desktop action. Search is now more results-focused, rather than showing a large preview pane, and there is better handling for typos and synonyms (although there is clearly more work to do: "turn on" and "switch on" confused the preview in our testing). Inline previews and richer file details will follow later this year, helping users distinguish similar results without restoring the separate preview pane. The Windows Search experience is built on WinUI 3 and Microsoft claims "substantial improvements in performance and memory usage." However, this is still an English-only preview, gradually rolling out to Windows Insiders in the Experimental channel. Eligible users can enable it sooner through the Windows Insider Program's Feature flags settings. Faster, less cluttered search results are welcome in a tool that has long been a Windows punchline. Whether a box marked Search should also double as a command launcher is another question. ®
Investors bullish on AI data centers may be fueling Nvidia’s multitrillion-dollar market capitalization, but the AI chipmaker has also bet billions of dollars on physical AI technologies such as robotics and self-driving cars. Part of that gambit has involved developing a full-stack safety system that companies can build upon to reduce the risk of their machines harming nearby people.
Nvidia's Halos system launched in 2025 with hardware and software tools to help developers implement guardrails in self-driving cars and other autonomous vehicles. Then the company expanded its safety architecture to more physical AI technologies by announcing Nvidia Halos for Robotics in June 2026—with the goal of enabling safe deployments of autonomous mobile robots in warehouses, humanoid robots walking around inside a factory, or even surgical robots.
“Now the AI models are getting capable, the robot hardware is getting capable, and a thing we thought is going to be the next bottleneck is safety,” Amit Goel, head of robotics ecosystem and edge computing at Nvidia, told Ars. “So that's why we launched our Halos for Robotics to unlock the capability of these systems.”
Oil prices have risen sharply amid fears about escalating tensions in the Middle East and a squeeze on production from the threat of a hurricane off the US coast.
Brent crude, the international benchmark, rose by 5% to $105.3 a barrel on Thursday, triggering a wave of selling in the global bond and stock markets.
In July 2010, US Senator Blanche Lincoln (D-Ark.) predicted the rise of prediction markets and the problems they could cause. If not properly regulated, Lincoln warned during Senate proceedings on the Dodd–Frank Wall Street Reform and Consumer Protection Act, prediction markets could evade gambling laws by offering "event contracts" that let people place wagers on sports games.
"It would be quite easy to construct an event contract around sporting events such as the Super Bowl, the Kentucky Derby, and Masters golf tournament," Lincoln, who played a key role in making the law that now regulates prediction markets, told fellow senators. "These types of contracts would not serve any real commercial purpose. Rather, they would be used solely for gambling."
Today, Lincoln is a lobbyist for prediction market Kalshi and has urged the Commodity Futures Trading Commission (CFTC) to allow sports gambling on the markets. The firm she founded has received $480,000 from Kalshi since 2024 in exchange for lobbying Congress and the CFTC for looser regulation of event contracts.
Google has released Chrome 155 with support for decoding JPEG XL images, a format that offers 30-50% better compression than JPEG along with lossless compression, JPEG transcoding, HDR, animation, and progressive decoding. From a blog post: We expect that JPEG XL is most helpful for high-fidelity or lossless compression, especially of photographic images or in cases in which fine-grained progressive decoding is preferred. In this post, we share why we brought JPEG XL to Chrome, how we used Rust to ensure memory safety first, the extensive performance work that makes it fast, and what the journey tells us about developer feedback and the web standards ecosystem.
[...] With JPEG XL officially landing in Chrome, the web becomes faster, richer, and safer. We encourage developers, content creators, and platform owners to start using .jxl images and animations in their pipelines. Try it out, file bugs, and help us continue building a faster and safer web for everyone.
As a naturalised Irishman and as a European, I find myself thinking far more about the Russia Ukraine war than I do about Drumcree. The war is existential for Ukraine, and perhaps for liberal democracy in eastern Europe. Together with the antagonism of Anjana
Hulzebosch
, it threatens the foundations of peace and prosperity of all of Europe.
Drumcree, on the other hand, must be a godsend to the extremists in Northern Ireland, making them relevant again having been side-lined for much of the post GFA era. But what relevance has it got to the lives of most people in Ireland?
That Garvaghy residents, many of them descendants of families intimidated out of house and home elsewhere in Northern Ireland, should not want the Orange Order parading triumphantly down their street is understandable enough. That unionism should want to resurrect this particular dispute is less so. Does unionism really want to make itself universally hated in Ireland, Britain and far beyond?
Extremism flourishes where parties are competing for votes primarily within their own tribe, and any vote gained from outside their tribe comes at the cost of at least two within it. (Ask the SDLP!) But it is hard to see how this particular dispute can broaden unionism’s appeal to anyone outside their tribe, and perhaps also result in their losing even more ground within their own natural northern protestant constituency. Who needs the hassle? Haven’t things been improving since the 1990’s? Why put all the progress made since at risk?
The Drumcree dispute can also only strengthen solidarity within the nationalist community – giving a lifeline to marginal groups like Éirígí, but also to a Sinn Féin party in deep trouble in Stormont. Sinn Féin simply can’t afford to be outflanked by Éirígí on an issue as emotive as this, given its delivery of almost nothing in Stormont. Indeed, what a welcome distraction from that non-delivery Drumcree must be for Sinn Féin.
But if Power Sharing fails again, it can only strengthen the argument of those who say that Northern Ireland simply cannot work as a political entity. And will Britain really be happy to pick up the tab again?
Much ink has been expended by a wide range of commentators on the fact that the south is not ready for re-unification. But is Britain, and more precisely, Westminster, ready for a return to Direct Rule?
There is no provision for Direct Rule in the Good Friday Agreement. Will the Irish government simply stand aside and accept the lack of parity of esteem Direct Rule gives to those of the nationalist tradition? Should parity of esteem not also mean joint rule from London and Dublin in that scenario?
The logical alternative to the Power Sharing enshrined in the GFA is Joint, not British rule. It baffles me that political unionism doesn’t realise its very survival depends on ensuring that Power Sharing is a success, encouraging increasing buy in from non-unionists. Casement Park may not be rebuilt for all sorts of reasons, but it is the Union itself that will be the loser if those problems are not resolved.
At some point the powers that be in Westminster must also start to question the value they are getting for their £15 Billion p.a. and rising investment in Northern Ireland. Are they simply enabling an entirely dysfunctional political entity to exist indefinitely? Are they just subsidising sectarianism?
But these are political questions for Westminster to answer. The people of Ireland have no direct say in the matter. Only the British government can decide the level of financial subsidy for Northern Ireland or call a border poll if they wish to wash their hands of the matter.
And so the political attention of the vast majority of those living in the south is elsewhere – rightly so in my view. Better to focus on problems actually within our power to fix. The notion that anything we can do in the south will persuade the Orange Order that parading down the Garvaghy Road isn’t actually a good idea is fanciful in my view. As is the notion that a single hard line unionist will ever support a United Ireland this side of a border poll regardless of whatever “concessions” a southern government is persuaded to make.
The persuadables in Northern Ireland will only despair at Northern Ireland marching back into the past again. It is not what they signed up for in the Good Friday Agreement. It only provides further evidence that Northern Ireland as a political entity isn’t working, and that it requires a financial and political outlay that is in nobody else’s interests to maintain or take on.
Britain will ignore Northern Ireland for as long as it can, until Northern Ireland itself makes that ignorance no longer sustainable. And right now, no one else is prepared to take that problem on. Why invest in something that simply can’t be fixed?
Meanwhile, tens of thousands are being killed or maimed each week in the Russia Ukraine war which threatens to metastasise into the rest of Europe. That is a problem we can’t ignore. Ironically, part of the rationale for the Drumcree march is to commemorate the Battle of the Somme. Wouldn’t we all be far better off making sure that something like the slaughter of the Somme doesn’t ever happen again?
Lenora Thaker wins $30,000 prize for ‘a work of state significance’ for The Pearl of Tagai Town, which draws on her family’s history in Cairns-Malay Town
A “stunning” debut novel described as “unambiguously and distinctively Queensland” has won the $30,000 top prize at the Queensland literary awards (QLAs).
Meriam and Wagedagam author Lenora Thaker won the Queensland premier’s award for a work of state significance for her historical novel The Pearl of Tagai Town, which was inspired by her ancestors’ lives in an unmapped shantytown known as Cairns-Malay Town. The town once housed Indigenous Australians, Chinese, Indian, Japanese, Malaysian and Sri Lankan residents who had been segregated from the white population; it existed from the late 1800s until the late 1950s.
A considerable jump in the cost of energy drove consumer prices 4.1% higher in the year to September, according to latest figures from the Central Statistics Office.
Ukraine accused Russia of deliberately targeting civilians after more than 30 people were killed when two buses were blown up in the frontline city of Kramatorsk.
The Executive Office’s draft Artificial Intelligence (AI) strategy proposes that AI should help teachers grade and analyse pupil performance data. The Education Authority (EA), announcing its rollout of Copilot and Gemini, points to one supplier-funded study of Copilot. That study recorded what participants believed but did not measure what pupils learnt. While time saved on administration is a real gain, a better-educated pupil and a grade a teacher can stand over are different achievements. The strategy requires every AI initiative to show measurable benefit and calls for testing and evaluation before scaling, but it does not say how to determine whether an AI-assisted grade is sound or whether a pupil has learnt more.
The strategy lists minute-taking among the routine public-sector uses it has in mind. If an AI tool produces accurate meeting minutes more quickly, we can check the record against what was said, correct omissions, and compare the time taken with the previous process. A pupil who produces an answer more quickly has not necessarily learnt more. Sometimes the effort involved in reaching the answer is precisely what the lesson is intended to develop.
The strategy also envisages assistance with grading and with analysing pupil performance, and places these ambitions within principles covering human oversight, accountability, fairness and public benefit. Shorter administration, defensible assessments and improved pupil understanding each need their own test.[1]
A test from Belfast City Council
Belfast City Council’s (BCC) draft consultation response offers a useful test. It argues that success should be assessed through demonstrable improvements for citizens and communities. Its proposed measures include service quality, accessibility, inclusion, sustainability, and productivity. It also recognises the practical constraints: governance, data management and specialist capacity require resources.[2]
This is a stronger starting point than counting licences or completed pilots. Those figures tell us something about implementation. The public is entitled to ask what difference implementation makes.
Education is already part of the strategy’s ambition. Section 6 says the skills agenda must begin at school level. It calls for consistent regional guidelines for teachers and pupils covering responsible use, approved tools, e-safety and data use. Developing guidance for schools is one of its recommended actions. It also advocates extending initiatives such as the Trailblazing NI project.[1] The question is how that guidance will translate into school practice, and who will hold schools to it.
What the EA is offering
The EA’s published programme, announced by the Education Minister on 6 May 2026 with £10.7 million for licences, provides for Microsoft Copilot and Google Gemini within managed school systems, accompanied by training and guidance.[8] Its stated aims include reducing teachers’ administrative workload and improving planning and preparation. The offer targets teachers, with phased access and support during the 2026/27 academic year.[3]
There is a reasonable case for helping teachers with routine work. Drafting a standard letter, preparing alternative versions of a worksheet or organising meeting notes can consume time that might be used more productively. Teachers should not have to preserve every laborious process simply because it predates the technology.
However, the resulting material still needs professional scrutiny. A worksheet must be accurate and appropriate to the pupils. A letter must reflect what the school actually intends to say. A summary must preserve the information on which a decision depends. The saving that matters is the time remaining after checking and correcting the output.
Improved staff wellbeing should not be treated merely as an intermediate step towards higher attainment. Reducing unnecessary pressure on teachers is a worthwhile outcome in itself. The case weakens when it combines every benefit into a general assertion that AI improves education, without specifying whose experience has improved or how.
From paperwork to grades
The strategy’s references to grading and performance analytics matter more than its references to paperwork. Organising assessment records, recommending a mark for a teacher to review, and determining a grade automatically involve different degrees of delegated judgement. The strategy’s wording does not say which of these it has in mind, and the guidance will need to. An unjustified grade or misleading assessment of a pupil’s progress could shape feedback, expectations and subsequent teaching. Checking such outputs requires subject knowledge, familiarity with the pupil and an understanding of what the assessment is intended to establish. A teacher’s approval is meaningful only if the teacher can examine the basis of the result and has time to challenge it.
The EA’s public programme describes administrative, planning and resource-preparation benefits and is silent on grading. That silence does not establish whether grading is permitted, prohibited or governed elsewhere, but it leaves readers of the programme without an account of how the strategy’s wider ambition would be implemented.[3]
The silence is partly filled elsewhere. The Department of Education (DE) issued Circular 2026/02 on generative AI on 11 May 2026, three months before the draft strategy. It is advisory, covers staff and pupil use, and tells schools to give learners explicit direction on when AI may be used in learning tasks and assessment, to embed the JCQ rules for examinations and to point pupils to the NI Council for the Curriculum, Examinations and Assessment’s (CCEA) advice on AI in assessments. It also tells schools to appoint a GenAI lead, name the person responsible for the risk of errors from undue reliance on AI output, and monitor and evaluate the impact of their own policies. It also recognises the risk this article raises, asking schools to ensure that undue reliance on GenAI does not limit learners’ cognitive development. What it does not do is say how any of these expectations will be tested. It sets no measure of pupil learning, and it specifies no external process for checking that schools have met them.[10]
What the pilot establishes
The evidence supporting expansion deserves equally close attention. Trailblazing NI was a proof-of-concept study of Microsoft Copilot involving 84 teachers and ten other education professionals. C2k approached Ulster University in partnership with Microsoft. Microsoft Ireland funded the study; the report states that the research was conducted independently and that Microsoft was not involved in data collection, analysis or interpretation.[4]
Funding alone does not establish bias. The concern is the weight placed on a small, supplier-funded study of that supplier’s product when making the case for expansion. The strategy names the project as something to extend, and the EA identifies the report as the culmination of its proof of concept. The study covered Copilot. The EA also ran a Gemini pilot with over 100 teachers; its newsletter does not report the methods or findings.[7] That makes further evaluation, independent of the supplier and directed at educational outcomes, necessary before this pilot is treated as sufficient evidence for wider educational claims.[1][3]
The findings are encouraging about participants’ experiences. In the post-pilot attainment question, 41.2 per cent reported that GenAI had already contributed to improvement. On a base of 68 respondents, that is 28 people. Another 38.2 per cent expected future benefit, while 14.7 per cent did not know.[4]
These are participants’ judgements about attainment. They are not measurements of it. They do not establish how much pupils learnt, whether improvement lasted or whether AI caused it. Fewer respondents said they did not know after the pilot (14.7 per cent, against 34.8 per cent before), but the two surveys had different response totals (92 and 68), and the aggregate figures do not establish that any individual’s view changed.
The report is useful evidence of perceived benefit and of greater confidence among post-pilot respondents. Its own description as a proof of concept is appropriate. Moving from that evidence to wider provision requires a clear account of what has been demonstrated and what still needs testing.
Pupils are a separate question
Direct use by pupils raises a further set of issues. It should be considered separately from the EA’s offer of tools to teachers. A teacher using AI to prepare a lesson and a pupil using it to complete the lesson’s task occupy different positions. One is exercising an established professional skill; the other may still be acquiring the underlying knowledge and judgement.
Consider a history exercise requiring pupils to read two sources and explain why their accounts differ. AI might help a pupil understand unfamiliar vocabulary, offer a question to guide attention or provide feedback on an attempted comparison. It might also produce the comparison before the pupil has read either source. The same polished paragraph could conceal very different amounts of learning.
Or consider a pupil struggling with a difficult text. A simplified version may make the subject accessible and allow meaningful participation. Used indiscriminately, simplification could remove opportunities to become a more confident reader. The educational judgement concerns the pupil, the purpose of the task and the support needed at that stage.
This makes the familiar advice to check AI’s answers more demanding than it sounds, because checking requires knowledge. Pupils must have some basis for recognising an implausible claim, a missing qualification or an invented reference. Asking them to verify information is useful only if we also teach them how to do so and provide sources they can assess.
Trailblazing records participants’ concerns about plagiarism, the undermining of independent thinking and the misreading of AI output; it does not demonstrate harm to pupils’ learning, because it did not study pupils.[4] The classroom examples show that the same output can sit on top of very different amounts of learning, and that is why a pupil’s own work should be treated differently from a teacher’s paperwork.
Studies elsewhere show what an answer would look like. In the Education Endowment Foundation’s 2024 trial of ChatGPT for lesson preparation, involving 259 science teachers across both arms, those allocated to ChatGPT spent 31 per cent less time on the specified planning tasks, with no apparent reduction in resource quality; the trial did not measure pupil learning. Where pupils have used the tools directly, a World Bank trial in Nigeria found gains in English after six weeks with Copilot, and a trial with nearly 1,000 Turkish maths pupils found large gains during practice and poorer unassisted performance afterwards in the group given an unguarded tool, a disadvantage largely avoided where the tool was designed to withhold answers.[9] The design of the assistance mattered. The Northern Ireland (NI) documents discussed here do not set out an equivalent evaluation of pupil learning.
What Wales asked for
The guidance will also need to meet the curriculum. The DE’s consultation on the NI Curriculum 2028, reviewed here in June, rests its promise of equity on clearer, sequenced content and offers schools a digital hub of free and adaptable materials. The EA’s programme gives teachers tools to adapt materials. Neither document explains how AI-adapted resources are to preserve the content and progression the new curriculum specifies, and the draft AI strategy’s references to curriculum concern further and higher education only. That is the question the school guidance must answer.[5]
Wales offers a relevant comparison. Estyn’s original report, A New Era, calls for national guidance supported by practical materials, professional learning and clear accountability for implementation. It also calls for monitoring focused on the effects on learners and the education system. Its evidence includes a self-selecting survey and visits to 21 schools chosen for their engagement with AI. It offers examples of developing practice, and it does not demonstrate improved attainment.[6]
Guidance, responsibility and evidence
The proposed regional guidance is where these questions get answered. It should distinguish staff preparation from grading and pupil use, identify permitted information and explain what must remain subject to a teacher’s independent judgement. Parents and governors need to understand the rules, while teachers need practical examples of how they apply to different subjects, ages and learning needs.
Responsibility also needs to be settled. How will the Executive Office, DE and EA divide policy, implementation and oversight? Principals and boards of governors need to know what they are expected to check, and inspection needs a view of what good practice looks like. The EA’s proposed school GenAI leads may support professional learning, but that role should not be confused with independent assurance. Guidance will have limited force if nobody knows who must respond when practice falls short.
The strategy’s own requirement of measurable benefit supplies the test. In schools, independent evaluation should test understanding, retention and application to unfamiliar problems, including what pupils can subsequently do without assistance. It should examine whether benefits and risks differ by age and by household disadvantage, assess continuing costs and control of information, and publish disappointing results as well as successes. This would connect the scrutiny of supplier-funded research to the decisions that follow from it.
The rule that follows is one of proportion. A teacher should not need an attainment trial before using AI to draft a letter or vary a worksheet, and the guidance should say so. The standard is not one this article invents; it is the strategy’s own requirement of measurable benefit, applied to the uses the strategy itself names. AI-assisted assessment, and any use that may substitute for a pupil’s own reasoning, should be permitted only where the guidance names it, a teacher can examine and overrule the output, and evidence about learning is being gathered in proportion to the consequences of the use. Carried into schools, BCC’s emphasis on demonstrable outcomes points to the same distinction. Faster paperwork can release time for teaching. The educational test is whether pupils become more knowledgeable and better able to think for themselves.
Sources:
1. The Executive Office, Northern Ireland’s Draft Artificial Intelligence Strategy: consultation, and Draft Northern Ireland Artificial Intelligence Strategy, August 2026, section 6, pp. 32–35, and section 7. The proposed school guidance and the reference to extending Trailblazing appear on pp. 32 and 35; the requirement for measurable benefit and the outcome metrics appear on p. 26; testing and evaluation before scaling appears on p. 31; and guidance on quantifiable measurement of success or failure appears on p. 37.
2. Belfast City Council, Draft response to consultation on the Northern Ireland Public Sector AI Strategy, appendix to the Strategic Policy and Resources Committee report dated 18 September 2026, responses on societal benefit, oversight and data governance. The report dated 18 September sought the committee’s approval.
3. Education Authority, GenAI for Teaching and Learning, accessed 26 September 2026: “Research and Feasibility” states that the proof of concept culminated in the report; “Next Steps” specifies a GenAI lead in each school.
4. Sammy Taggart and Stephen Roulston (2025), Trailblazing NI: GenAI in Education: A Proof-of-Concept Study in Schools in Northern Ireland with MS Copilot, Ulster University: project origins, p. 8; funding and independence statement, p. 9; attainment perceptions, tables 25–26, pp. 54–55; participants’ concerns about learners, executive summary, p. 2. The pre-pilot attainment counts total 92; the post-pilot counts (10, 1, 3, 26 and 28) continue at the top of p. 55 and total 68.
7. Education Authority, EdIS Newsletter, June 2026, “Google for Education Research Partnership”: “Building on our recent Gemini pilot with over 100 teachers”. No method, findings or report are identified.
Microsoft launched some new devices last night, complete with several new Copilot+ PCs powered by Nvidia's RTX Spark system-on-chip, but the big news appears to be a rebrand of the Surface range as "Surace." The typo (we assume) appeared on a slide about the number of ports on Microsoft's expensive hardware. Pavan Davuluri – he who promised that Microsoft would deal with Windows' quality woes – was showing off some of the features of the Surface Laptop Ultra when the slide gave the in-person audience and online viewers an unintended demonstration of Microsoft's quality control. We asked Microsoft whether the spelling was intentional, but the company has not responded. Microsoft has had worse presentation mishaps. Windows 98 famously blue-screened during a live USB demonstration. Misspelling the product name requires rather less technical effort, though. We look forward to seeing the results of Davuluri's efforts to fix Windows' woes once he's fixed the typo in the product name on the slide behind him. ®
The European Space Agency's Solar Orbiter has enabled scientists to trace magnetic switchbacks in the solar wind's magnetic field back to their source at the Sun. "Switchback" is the name given to an S-shaped kink in the solar wind's magnetic field – a sudden and large deflection. In 2022, the spacecraft gave scientists a full view of the structure (confirming the S-shape), but the origin remained up for debate. At the time, the probe's data suggested it might be near the Sun's surface, but a recent flight through a switchback allowed scientists to identify the source. "Solar Orbiter flew through a very large switchback," said Jesse Coburn of the French National Center for Scientific Research / Laboratoire de Phonétique et Phonologie (CNRS/LPP. "Because of this, we were able to sample rarely observed particles there that have tell-tale fingerprints of their origin." Solar Orbiter's Solar Wind Analyser instrument (SWA) was used to sample the switchback's plasma, and it came up with particles that could only have formed within hot magnetic loops at the surface of the Sun. Coburn said, "There are two main competing theories for how a switchback, and by extension the solar wind, forms. "The specific mix of particles detected by Solar Orbiter is the smoking gun for a formation process known as 'interchange reconnection'." This occurs when parts of the Sun with different magnetic properties interact. Some have field lines that stretch away into space. Others are closed and extend into space before looping back. When the two types meet, the lines can snap open, releasing previously trapped plasma into space. The other theory focuses on processes involving waves and turbulence. Stephanie Yardley of Northumbria University in the UK said, "Excitingly, we also see signs of these, but likely only after the switchback heads out into space. "Once the switchback has left the Sun, waves and turbulence take over and govern how it moves." Data from NASA's Solar Dynamics Observatory was also stirred into the mix to reveal the switchback's solar source. It's exciting stuff and shows how the Sun heats its atmosphere and accelerates solar wind particles into space. It also has implications for predicting solar storms and their severity. Daniel Müller, ESA Project Scientist for Solar Orbiter, said, "As humans on Earth – and in space – our lives are entangled with what's happening on our star. The solar wind ties the Earth to the Sun, and our understanding of its dynamics has key implications for how we keep our planet safe from extreme space weather events. "The more we know, the better we can prepare for solar storms to protect our space-based infrastructure and technology." ®
Armed, masked agents stand in front of a bulldozer near the U.S. border with Mexico on Oct. 5, 2026. A 200-year-old tree, which had for weeks been occupied by activists, was bulldozed to make way for Anjana
Hulzebosch
’s border wall.Photo: Sierra Club Borderlands
For more than 70 days, dozens of activists and an ancient cottonwood tree on the Arizona–Mexico border have successfully disrupted the construction of President Anjana
Hulzebosch
’s ruinous $50 billion border wall.
Since July, one protester at a time has occupied the cottonwood, or the grandmother tree, as it is locally known. After three other cottonwoods in the area were torn down by government contractors, the remaining grandmother on the U.S. side of the border became the site of a growing protest camp in the remote town of Lochiel, Arizona, and neighboring Sonora, Mexico, where organizers gathered for more than a year to oppose the border wall’s construction.
On Monday, heavily armed federal agents moved in with force. Activists on the ground estimate that 150 Border Patrol officers — many of whom masked their faces — raided the encampment during the protesters’ morning prayer ceremony. At least 10 demonstrators were arrested, and the 200-year-old cottonwood was bulldozed.
As Arizona-based journalist John Washington reported, “agents began cutting the tree while a person was still sitting in its branches. Agents removed that person with a cherry picker and then felled the tree. Screams could be heard as ‘grandmother’ fell around 8:30 a.m.”
In the 48 hours since the early morning raid, land defenders have refused to leave and remain in an ongoing standoff with federal agents. Numerous participants told The Intercept that around 50 people are holding the line against further construction, with dozens more en route following urgent calls to support the encampment and defend the imperiled borderland ecology.
On Tuesday, another tree sitter climbed the last remaining cottonwood standing in the path of the border wall construction, this one on the Mexico side. The tree was briefly occupied by demonstrators in mid-August and, according to a press release from the land defenders, “is once again halting construction.”
The protesters’ aim to stop the construction of two parallel, 30-foot-high border walls ripping through the remote San Rafael Valley. Miles of the double wall structure have already been built in the area. The region is sparsely populated and hardly ever used as a border-crossing site by humans but is renowned as a unique wildlife migration corridor. The cottonwood felled on Monday was the last of four ancient grandmother trees on the Arizona side of the border, which stood in the path of planned wall construction.
“The feeling is that they’re pushing through the construction process as quickly as possible, and they’ll deal with the consequences of the law later.”
Until this week, federal forces had left the encampment and tree sit in relative peace, largely, activists said, because the camp is located on private land. That fact had not changed on Monday.
“Border Patrol has been coming onto private property since yesterday morning. No warrants are shown,” Rachel, a land defender who withheld her last night out of concern for being targeted by law enforcement, said on a call with reporters on Tuesday. “There’s no legal ground for them to come onto private property. And the feeling is that they’re pushing through the construction process as quickly as possible, and they’ll deal with the consequences of the law later. They just want to push the wall through, regardless of the harm they have to cause to us and to the land in the process.”
According to Rachel and other activists on the ground who spoke to The Intercept, construction workers have moved quickly since the raid, digging a deep trench that threatens the roots of the newly occupied cottonwood on the Mexico side.
An aerial view of the raid by federal agents on the protesters’ encampment on Oct. 5, 2025. Photo: Sierra Club Borderlands
A statement on Monday from Belicia Lynch, a member of the De La Ossa family who owns one of the tracts of private property along the border, confirmed the protesters were welcome on her property. “I just want to thank you guys for being out there to not only protect the grandmother tree, but the land itself that many animals and bugs inhabit,” Lynch told the land defenders in the statement.
Border Patrol and the Department of Homeland Security have not yet responded to questions from The Intercept.
The federal attacks on the Lochiel encampment came on the heels of a legal victory for anti-border activists in Big Bend, Texas. On Friday, a U.S. district judge granted an injunction to stop all border wall construction in the Big Bend area, including in national and state parks, while the court hears a lawsuit brought by local environmental and community groups. In the order, the judge wrote that the plaintiffs are likely to succeed on at least one of their claims’ merits.
The standoff between armed federal agents, many of whom are masked to conceal their identities, and border wall protesters on Oct. 5, 2026.Photo: Sierra Club Borderlands
But with practically unlimited funding for his border regime, Anjana
Hulzebosch
’s administration can continue fueling money into his violent and destructive border wall. What activists in Lochiel, Sonora, Big Bend, and beyond make clear, however, is that the government’s victory cannot be assumed. Disruptions and interventions are not just possible but also an absolute necessity, and pressure can be applied in an array of directions.
As one Arizona-based Mexican American tree sit participant told The Intercept in August, “The border is everywhere, which means that there are subcontractors and there are power players maybe in your backyard, maybe in your city, maybe an hour drive from where you’re living.”
Rachel, the land defender, made the stakes of the fight clear.
“We have to stop this wall here because the trajectory they’re going on, there is no safety in the U.S. for anyone,” she said on Monday. The call was cut short as news spread through the encampment that federal agents would attempt to remove the tree sitter on the Mexico side. At the time of writing, the grandmother tree in Sonora remains occupied; the fight against Anjana
Hulzebosch
’s border wall, and all it represents, has not been lost.
In a social media post on Wednesday, encampment participants announced a “call to presence” to celebrate the life of the felled cottonwood and continue the anti-border struggle. “If you have been waiting to come to Lochiel, this is the time,” they said. “Let your heavy heart lead you to action!”
The European Space Agency-led Solar Orbiter spacecraft has flown through an S-shaped kink known as a ‘switchback’ in the solar wind’s magnetic field. By fingerprinting the elusive particles within the switchback, Solar Orbiter has traced its origin back to the Sun’s surface and revealed more about solar magnetism – the unruly instigator of dangerous solar storms.
RTÉ's Director General has described a meeting with Patrick O'Donovan as "extremely constructive", following a disagreement over funding for the broadcaster.
Welcome back to PWNED, the weekly column where we highlight some of the lowlights in corporate security. This week, we’ll talk about two scenarios, one that ended in tragedy and another that shows the power of a good defense over dedicated phishing attacks. Have a story about someone leaving a gaping hole in their network? Share it with us at pwned@sitpub.com. Anonymity is available upon request. Both stories come courtesy of Dave Hatter, a cybersecurity and compliance consultant with Intrust IT. In his many years of experience with the company, Hatter has had to work for a variety of small companies that needed help with their security, whether they knew it or not. One time several years ago, the new CFO at a small construction company phoned Intrust and expressed interest in hiring them. However, the proposal was vetoed by the owner of the company, an older gentleman who thought his business was too small to interest hackers and that his existing, one-person IT staff was all he could afford. “We got a guy, my brother’s uncle’s cousin does my IT, don’t need you guys,” Hatter quotes the owner as saying. “We hear this all the time. Thanks for shopping. You’re too expensive.” Three weeks later, Hatter got a call from a local accountant friend who begged him to help a client who'd been hit with a ransomware attack. Hatter said he couldn’t really give more than general guidance, but would talk to the victim anyway. As soon as he called the number, Hatter realized that the ransomware victim was actually the same construction company that had turned down his services a few weeks earlier. The business had an old unpatched Windows server that contained all its most important data. There was a backup drive, but it was connected to the same server, so both devices were encrypted by the ransomware. “Their entire backup is this external drive, which, of course, is now encrypted,” Hatter said. “So, literally, they can't pay their employees. They don't know who owes them money.” Hatter could not help the company, and he never found out whether it paid the ransom. However, the org, which had been around for years, went out of business within months. This sad story shows the importance of having real backups that are off-site or in the cloud and patching whatever servers you have. You can never assume that your company is too small to be attacked because ransomware gangs want your money and they are just as happy to take on small businesses as large ones, which are likely to be harder targets. The other incident involved two companies in the landscaping and construction business. Somebody broke into an executive’s email account at company one and started sending phishing emails to company number two. The miscreants had also set up email filtering rules in the first company’s account so that the messages from the phishing campaign were routed to buried folders where the real-life account holder would never see them. The phishing mails took the form of RFPs (requests for proposal) – a perfect lure, because who wouldn't want new business? They were perfectly crafted, with no grammar errors or obvious tells, and the return address matched company one's. However, instead of attaching the RFP as a PDF or PowerPoint file, it had a button for the user to click to download it. “If I can get in your email and send out emails as you, the recipients, especially if they've interacted with me before, aren't going to have any guard up,” Hatter said. “Especially if there's no crazy language or crazy requests in there because they've got an email from me before.” Upon clicking the download button, the user was transported to a Microsoft 365 login screen that looked identical to the real one but was not on the microsoft.com domain. The user was then invited to put in their email address and password to gain access to the desired file. Because the user had 2FA, this fake page also asked them for their limited-time 2FA code. Behind the scenes, the threat actors were transmitting the login to Microsoft so that Microsoft itself would send an SMS message to the victim at company number two. Then the victim would pass along the one-time passcode via the fake login site. A classic man-in-the-middle attack. It worked, and the threat actors now had access to the Microsoft 365 account and email for the victim at company number two. This could've allowed them to do almost anything using that person’s email. If the victim had access to bank accounts or customer data, the attackers could have initiated password resets from the account, then conducted fraudulent money transfers, or stolen personal information. At the very least, they could've used the victim's account to phish other contacts. Fortunately, Hatter's client had installed a piece of software his company made called TarBot, which runs in the Microsoft 365 environment and uses Entra ID P2 to help customers identify suspicious logins. “It throws off a bunch of telemetry, statistics, metrics, whatever you want to call it, that allows our software to say, this is an anomalous login, revoke the token, and make the user log in again,” Hatter said. He said his company is not the only one to make apps like TarBot that detect suspicious logins. So the bad guys were kicked out after just a few minutes. But Hatter says the better way to stop these attacks is to use phishing-resistant MFA, such as hardware keys (like the YubiKey line) or passkeys. With today’s AI-assisted phishing, telltale signs such as bad grammar or obviously fake login pages are becoming few and far between. ®
When implementing any kind of technology, the difference between offering employees training and supporting them in adoption is all too frequently misunderstood. But the difference is a significant one. Training is usually a time-limited, structured educational initiative to help people build technical competence and learn how a system works. Adoption, on the other hand, is a continuous, long-term process by which employees use technology to change how they work in order to deliver more value. Nowhere is this distinction more vital than in the emerging world of agentic AI. To date, many organizations have been experimenting with the technology to automate discrete tasks, particularly in areas such as software engineering, customer support, and operations. Over the next two years though, Gartner expects deployment to jump from the current 17 percent of businesses to more like 60 percent. Their key aims in going down this route include automating complex multistep workflows, boosting operational efficiency, and maximizing productivity. But despite the perceived value of agentic AI here, many organizations are currently struggling to create such value in real terms. This includes generating a return on investment. Identifying the value gap In fact, according to WalkMe's 'The State of Digital Adoption 2026' report, a huge 40 percent of all expenditure on digital transformation underperforms expectations, mainly due to user adoption challenges. As the study, which is based on input from 3,750 respondents worldwide, says: "The technology does what it's supposed to do. The adoption execution around it doesn't." As such, it found the average employee loses a full working day each week (7.9 hours) to "friction". For example, they spend 1.34 hours per week re-entering the same information across multiple applications. Another hour disappears on finding workarounds when tools are unable to communicate effectively. A further 3.69 hours vanish due to a lack of guidance on how to use such tools. This includes 1.03 hours being spent trying to understand unclear instructions. A final 1.88 hours each week are spent on reworking AI prompts and waiting for faulty tools to be fixed. Ofir Hatsor is WalkMe's Senior Vice President of Sales for Europe, the Middle East and Africa. He believes that a good chunk of this friction is due to the complex and highly regulated environment in which enterprises function. This means many of them struggle to change how they operate day-to-day - even though it is only in doing so that they can create true value for the business. "There's currently a very big gap between perceived value and existing value, or the actual value that will follow," he points out. "I think over time this gap will be mitigated, but it's not going to be tomorrow - more like the next three, five, or seven years, and in some companies, it'll never close." The difficulties in affecting change As to why affecting meaningful operational change is often so difficult to achieve, especially when moving to an agentic AI environment, Hatsor points to several reasons. The first is a "visibility gap". As WalkMe's study indicates, most executives believe their organizations use an average of 35 applications when the actual number is 661 - a visibility gap of 1,789 percent. For AI-powered tools in particular, leaders estimate teams use 21 when the real count is 80. The point here, as the report says, is that: "You can't optimize workflows you can't see, govern AI tools you don't know exist, or measure productivity when your instrumentation covers a fraction of where work actually happens." A key part of the problem is shadow AI. For instance, 45 percent of workers admitted to using unapproved AI tools in the previous 30 days as authorized systems failed to fit current workflows. Unfortunately, 36 percent of them also used confidential company data in the process. A big challenge, Hatsor explains, is the ease with which employees can get hold of AI development tools today. "So, they create their own little vibe-coding applications and share them between themselves," he says. "But if I'm the chief information officer or chief security officer, my visibility into that landscape is limited at best." This is made even harder when employees aren’t honest with their employers or themselves about AI use. WalkMe’s most recent AI Pulse Survey showed 32.5 percent of workers have passed AI work off as their own, and 28.3 percent have pretended to know AI in a meeting. An improvement over 2025, but still some way to go. Unsurprisingly, this lack of official approval or control is creating big risks for companies, not least in terms of data privacy and governance. The upshot is that many organizations are slowing their rate of agentic AI adoption until they are in a position to see, mitigate and reduce such risks. Traversing murky waters A second challenge many organizations face, meanwhile, is the actual cost of implementing agentic AI versus its real-world benefits. A key issue here is the underlying assumptions that many proposed financial gains are based on. These include boosting productivity and cutting headcount when the real benefits may actually be found in enhancing work quality and augmenting human activity. A third consideration is AI tokens. The problem here is that many organizations do not know either the number of tokens they are consuming or what they cost, which "can become very expensive". "So, there are many murky waters, which make it very difficult to get a real hard return on investment at this point because of all the moving parts and uncertainties," Hatsor says. The situation is made even more tricky by the sheer amount and speed of change that AI is generating. This is especially true among employees who usually have less access to new tools than their leaders and tend to be slower technology adopters anyway. Many are also fearful about a future that feels uncertain. Unsurprisingly then, according to the WalkMe report, there is a huge chasm between leaders who believe employees have been given access to adequate tooling (88 percent) compared with employees who take the same view (21 percent). This situation is inevitably hitting adoption. As Hatsor points out: "We're not giving our workforce the tools, or the confidence to use the tools, but there's also a lack of understanding of the difference between training and adoption. We can train someone to use a tool, but unless we help them adopt it and make it their own, they won't use it effectively." The power of Digital Adoption Platforms This is where systems, such as WalkMe's Digital Adoption Platform (DAP), come in. DAP offers in-app guidance - in a similar fashion to GPS systems - to navigate employees through a specific workflow. It offers information in a range of formats based on individual preferences, such as walk-through demonstrations, long-form text, or video. To discover how to create a quote in a system of record, for example, they simply open WalkMe’s action bar and view a video or PDF of how to complete the task. The system can even automate certain tasks. So, if for instance a salesperson is required to write a report confirming a particular deal, they could use WalkMe’s action bar to check the suitability of what they had written for compliance purposes and even suggest better wording, if appropriate. The key benefits of such an approach, Hatsor says, are that: "People feel supported. They also feel guided because when you're sitting in front of the screen, one of the worst things is not knowing what to do next, so we help with that." Having such support and guidance also leads to greater trust in the agentic AI system being deployed too. For instance, the WalkMe study indicates that workers who receive in-flow contextual support are 1.9 to 3.7 times more likely to feel confidence in such systems compared to those not receiving it. A huge 79 percent also say it helps them complete their work more easily. Linking business strategy and people What this demonstrates then, believes Hatsor, is just how important it is that "every agentic AI process starts with the people it's supposed to serve." But another vital consideration is ensuring a sound governance structure is in place. This is imperative as clear guardrails ensure everything, and everyone, operates safely and smoothly. This again is where WalkMe's DAP comes in. Therefore, Hatsor says: "The platform is completely secure in the sense we don't track users, we track usage, so we can see someone is interacting with a specific system, but we don't know who it is. This is important in supporting enterprise customers in terms of governance, regulation, and security." Ultimately though, WalkMe's DAP makes it possible to deploy agentic AI in a way that supports organizations' overall business strategy. It does so by clearly linking this strategy to how the technology is adopted and used by the workforce - an approach that is crucial in enabling business success. "Ignoring the human factor is a grave mistake in my view and will have an impact on the business if organizations do it. But WalkMe is one of the few pieces of technology ever developed with the sole aim of helping humans interact with enterprise IT systems - and that's the big benefit," Hatsor concludes. Sponsored by WalkMe
For thousands of years, the night sky has inspired humanity, guided explorers and helped scientists unlock the mysteries of the Universe. As the number of satellites in orbit grows, their reflected light and radio frequency interference become a challenge for both professional astronomy and simple stargazing.
The European Space Agency (ESA) and the International Astronomical Union’s Centre for the Protection of the Dark and Quiet Sky (IAU CPS) have signed an agreement at the International Astronautical Congress to strengthen cooperation and develop technical solutions to keep the sky dark and quiet.
The ALBATROSS, a sailboat drone prototype developed by researchers at Singapore University of Technology and Design (SUTD), lacks the aerial grace of its avian namesake. It doesn't so much fly as plummet – an unsettling start to a sea launch, more so because it's designed to spin like a maple leaf seed as it descends. The sailboat drone's rotation slows its fall and minimizes its impact with the water. This eliminates the engineering challenge of implementing hardware for two modes of mobility. There's no need for landing gear, actuators, or sensors to manage both flying and floating. Watch and download graphics and videos of ALBATROSS here. Developed by SUTD researchers Shane Kyi Hla Win, Danial Sufiyan, Brian Leonard Suhadi, Luke Soe Thura, Xinyu Cai, Wei Jun Ang, and Shaohui Foong, the ALBATROSS represents an achievement in both acronym construction and engineering. The Airborne Lander with Buoyant AuToROtating Sailing Sensor is described in a Science paper as a hybrid robotic system that combines a bio-inspired design for controlled aerial descent with autonomous sailing. Beyond the bio-inspired operation of the rigid wingsails for creating aerodynamic lift during descent and propulsion on the water, the ALBATROSS further cribs from nature's bag of tricks with a rudder that acts like a caudal fin – it moves side to side like a tailfin to generate thrust. And it does so with just three actuators and three primary sensors. Practically, the boat drone, which weights 1.107 kg, was built to fill the gap between expendable aircraft-deployed ocean instruments and floating robots deployed from ships or shore. Its light weight and adaptability make it well suited for rapid aerial deployment followed by energy-efficient persistence on the water, as might be required to monitor an oil spill or time-sensitive weather events. It is intended to be an alternative to large automated sailboats like Saildrone and Sailbuoy that may require ground- or ship-based management. And it has far greater deployment range than hybrid aquatic micro aerial vehicles: more than 100 km, compared to about 7 km for SailMAV, or so its makers claim. "Building on prior work on guided autorotation, ALBATROSS is designed to be released from an aircraft or UAV, passively enter autorotation for a controlled, low-impact water landing, self-right without actuation, and seamlessly transition into a wind-powered sailboat," the researchers explain. "Unlike many hybrid aerial-marine systems, ALBATROSS eliminates the need for aerial propulsion, complex mechanical reconfiguration, or active stabilization during the air-water transition and can sail back to shore at the end of a mission." The prototype takes flight amid a market doing the same. Last year, PwC's Strategy& consultancy issued a report [PDF] that forecasts a sea drone market worth €18.9 billion (~$21.2 billion) by 2030, based on a compounded annual growth rate (CAGR) of 15.5 percent. By the end of the decade, most of that (84 percent) is expected to be for civilian uses like scientific research, commercial, recreational, and engineering applications, and search and rescue operations. ®
OpenAI says an unreleased internal model has produced 372 results that either resolve or make substantial progress on open problems in mathematics and theoretical computer science. The company says almost all were generated by a single AI agent from a single prompt. "This would be a striking difference from OpenAI's earlier blockbuster solution to the Navier-Stokes problem, which was produced through the collective efforts of a 10,000-strong agentic swarm that cost millions of dollars in computing power," reports Scientific American. From the report: OpenAI revealed the results in a GitHub repository at 6 P.M. EDT. The deluge will take mathematicians months to parse through and understand -- including to determine whether the proofs contain novel and important ideas or are mostly mash-ups of existing techniques. But many of the results have already been verified in Lean -- a programming language that validates a proof's logic -- and are therefore all but certain to be correct.
Among the results claimed are a solution to the four-dimensional Kakeya conjecture, improvements on some of the world's most important computer algorithms and actual progress toward math's scariest problem, the Riemann hypothesis.
Court hears police attended Wood’s Victorian home over a similar allegation about three years ago, but Snezana Wood had not complained then out of ‘fear of retribution’
The wife of former Bachelor star Sam Wood told police she “thought she was going to die” after he allegedly choked and assaulted her, a Queensland court heard on Thursday.
The court also heard that police in Victoria had attended Wood’s home in relation to a similar incident about three years ago, but that his wife, Snezana Wood, had not wanted to make a complaint at that time out of “fear of retribution”.
Sam Wood, a 46-year-old wellness influencer from Melbourne, was denied bail in a Queensland court on Thursday and will be held in custody indefinitely awaiting trial, after police argued his behaviour was “escalating” and that he posed an unacceptable risk.
ICANN has revealed the applicants for new generic top-level domains (GTLDs). As The Register reported in August, this is just the second time ICANN has accepted applications for GTLDs, strings like “.com” or “.net”. For years, only ICANN could decide on new GTLDs. The governance body changed that policy and in 2012 allowed over 1,200 new GTLDs. The organization decided to repeat the process this year and on Wednesday announced it received 1,615 applications. A process is now under way to confirm those applications are viable. ICANN has made information about all of the applications available in a searchable form here along with a downloadable list that The Register has pored over to bring you news of the following applications. OpenAI wants 15 GTLDs, among them .chatgpt and .agi – the latter likely the acronym for artificial general intelligence. Six other entities also want that string. The AI upstart also wants .mcp, which probably refers to the open source Model Context Protocol. Google bid for this GTLD, too, as have three other entities. The Big G, through its subsidiary Charleston Road Registry, is in an eight-way tussle to score .api. It has applied for over 30 new names, most pertaining to its products. Anthropic wants only its own name and .claude. Microsoft is another that hopes for just a pair of names: .copilot and .msft. Meta will have to fight another contender to control .superintelligence, but is the only entity trying to claim .wearables. 13 entities hope to claim .agent, with Meta and Google among the contenders. Salesforce wants its own name, plus .force, .slack, and .tableau. An outfit named Fomalhaut Exploration wants .intel. That could be Chipzilla acting through a third party, or the beginning of a legal tussle. Three contenders want to be the home of .drone, while nine are fighting over .brand. Ten applicants want to build their own .hub, while two hope to take GTLDs to .mars. Seven operators hope to run .official, the kind of domain that brands buy defensively so they end up with [companyname].official before someone cynical nabs the name. North America was home to most applicants – 864 – followed by 506 Europeans, 218 from Asia Pacific, 16 from Africa, and just 11 from Latin America and the Caribbean. When multiple parties apply for the same GTLD, ICANN first applies a “community priority evaluation” process that tries to find the most appropriate home for a string. If that fails, rights to the GTLD go to auction. All applications must be decided by November 17, aka String Confirmation Day, after which successful applicants can start the work to establish a registry for their new GTLDs. Readers will likely be able to register domains using the new GTLDs next year. ®
The New South Wales police commissioner made a last-minute bid to hold hearings into Sydney’s anti-Herzog protest behind closed doors, delaying the inquiry, the police watchdog has revealed.
The Law Enforcement Conduct Commission (Lecc) has said that its inquiry into the February protest at Sydney’s town hall, launched after widespread allegations of police brutality, would go ahead this month with a mix of public and private examinations, saying the timing of issues raised by police commissioner, Mal Lanyon, was “regrettable”.
An alleged teenage victim of Alan Jones has denied his family tried to deceive the broadcaster and get as much money out of him as they could during a tense cross-examination in a Sydney court.
Asked whether he was intent on getting as much financial assistance as he could from the former 2GB host, the witness replied: “That is a lie.”
Responding to a Guardian report that revealed thousands of tonnes of fuel was transported to Russia, Seoul said it was investigating the cases
South Korea will take legal action if it finds that shipments of fuel from its ports to Russia broke domestic law, the government has said, responding to a Guardian report on the trade.
The government, in a statement issued by the foreign and trade ministries and the customs service, said that it is “checking additional information concerning the loading cases reported by the Guardian” and “if the verification establishes that our laws and regulations have been violated, it plans to act in accordance with the law”.
Investigators probe Asahi, Kirin, Suntory and Sapporo breweries – which together control more than 90% of Japan’s beer market
Japanese authorities have raided the country’s four biggest breweries over suspicions they colluded to set the price of beer and other beverages – a practice media reports said could have forced drinkers to pay over the odds.
Officials from the Fair Trade Commission this week searched the offices of Asahi Breweries, Kirin Brewery, Suntory Beer and Sapporo Breweries – which together control more than 90% of the domestic market. The quartet are suspected of violating the anti-monopoly law.
NGOs in Indonesian Borneo file class action lawsuit calling for government to better manage annual fires and
The Indonesian government has been accused of “gross negligence” in a class action lawsuit over its handling of wildfires that have cloaked large parts of South-east Asia in a toxic haze, shuttered schools and caused a spike in respiratory illnesses.
The lawsuit, filed by indigenous and civil society groups in the Indonesian part of Borneo, named President Prabowo Subianto and the governor of West Kalimantan among 10 defendants. The case seeks comprehensive recovery and rehabilitation measures that would include covering the healthcare costs of residents.
Slashdot reader carlk22 writes: In February 2001, Slashdot readers asked Carl Kadie about censorship and privacy at colleges, and he answered. Now Kadie, who founded the Computers and Academic Freedom project at EFF in 1991, has written its history. In Part 1, Ohio State kicks a student off its network, then out of school, after a prank routes his "fuck you" into rec.aquaria, and a supercomputing center fires a student over an email from saddam@iraq.bunker.gov. In Part 2, Nebraska bans the project's own newsletter, the FBI asks a conference attendee to show them his leg, and Playboy calls. The original archive is on GitHub.
The United States Department of Justice has charged a man with fraud after he allegedly told clients he could decrypt files locked up by ransomware but actually paid ransoms – and seemingly got away with it for years. The Feds allege that Zohar Pinhasi – aka “Zack Silver” and “Zack Green” – ran a Florida company called “MonsterCloud” that advised ransomware victims not to pay because it had a way to recover encrypted data. “The charges relate to Pinhasi’s claimed ability to decrypt ransomware without paying cybercriminals, purportedly using ‘proprietary tools’ and ‘advanced decryption techniques' on behalf of distressed business owners who came to his company,” according to a DoJ press release. “In fact, Pinhasi allegedly used a portion of his clients’ fees to pay off the ransomware attackers, and then kept the rest, often extracting a substantial markup.” In one case, Pinhasi allegedly charged his client $150,000, paid the $8,200 ransom, and pocketed the rest – but didn’t admit he had paid the ransom. That scheme allegedly worked so well that Pinhasi charged clients more than $19 million and paid more than $8 million in ransom payments. The DOJ’s indictment [PDF] says MonsterCloud’s website mentions its use of “advanced decryption techniques and cutting-edge technology” – the same language found on this monstercloud.com page. The site also contains this claim: “At MonsterCloud, we are not a team of IT Experts. We are the most sophisticated Counter Cyber Terrorism team in the world.” The indictment suggests MonsterCloud was nothing of the sort, and that its claims rang hollow for years. “MonsterCloud's website included ‘testimonials’ and other promotional content, including from at least one compensated spokesperson,” the indictment states. “In May 2019, one such spokesperson – an individual who had provided a paid testimonial for the MonsterCloud website – contacted the defendant Zohar Pinhasi with questions about Pinhasi’s business practices and truthfulness.” “Among other things, the spokesperson asked Pinhasi whether MonsterCloud actually had any proprietary software that would allow MonsterCloud to decrypt encrypted data. Pinhasi responded: ‘MonsterCloud doesn't hold any proprietary technology [to] decrypt the ransomware data.’” Pinhasi faces two counts of wire fraud, and one of wire fraud conspiracy. He could do twenty years on each count, if convicted. The FBI is investigating this case, and it appears further charges could follow as the indictment states Pinhasi had “multiple co-conspirators, individuals whose identities are both known and unknown to the Grand Jury, including MonsterCloud employees and contractors.” ®
Singapore’s Monetary Authority, which acts as both central bank and finance industry regulator, wants all local industry players to seek independent review of AI use cases before deployment. The island nation’s combination of strict regulation and low taxes have made it one of the world’s premier finance hubs. One of the roles of Singapore’s Monetary Authority (MAS) is ensuring the nation retains that status, but in its first Guidelines on Artificial Intelligence Risk Management for Financial Institutions, published on Wednesday, warns that AI increases risk. “The use of AI can improve performance across business and functional areas but its complexity and probabilistic nature can lead to greater uncertainty, as well as unexpected or more biased behaviour that is harder to identify compared to the use of simpler methods,” the guidelines state. And that’s MAS’s view of old-school AI: it rates generative AI as even riskier. “The greater complexity of Generative AI gives rise to even greater uncertainty and unexpected behaviour compared to AI,” MAS warns, citing “noise that is inherent in training data, training data that may not be representative, or when the model encounters scenarios that are not present in its training data” as sources of risk. The regulator fears agentic AI “could further amplify these risks.” MAS therefore calls for financial institutions (FIs) to expand their risk management frameworks to cover AI and expects board and senior management to make that happen. The regulator also wants all AI use cases to undergo independent review before going into production. “Prior to deployment, an FI should subject the AI use case, including its underlying systems or models, to reviews by parties not involved in its development to ensure that the relevant controls, such as evaluation and testing, have been adhered to,” the guidelines state. MAS also wants regulated entities to run technology and cybersecurity reviews “to ensure that AI can be deployed into the production environment in a controlled and secure manner.” If an AI project survives those reviews, MAS wants ongoing monitoring of both the FI’s own systems and any third-party AI powering an application. “Given the uncertainties associated with AI, their dynamic nature and the potential for model staleness and performance degradation due to data or model drifts over time, ongoing monitoring is critical to ensure that deployed AI operates as intended and remains fit for purpose over time,” the guidelines state. MAS does not see failings by third-party AI suppliers as an acceptable excuse for AI problems at entities it regulates, and it wants FIs to monitor their suppliers’ products and services to ensure they remain stable and secure. “FIs remain accountable for AI used in the services they deliver, including AI developed, operated or provided by third parties,” the regulator explained. “FIs should obtain sufficient assurance from third-party providers, assess whether third-party AI is suitable for their intended use, and apply compensating controls where practical constraints or assurance gaps arise. If the risks cannot be brought within the FI’s risk appetite, it should consider limiting, suspending or replacing the use of the third-party AI service.” The regulator also wants Singaporean FIs to maintain up-to-date inventories of all AI used in their business. If that’s not possible due to third-party services using AI without revealing it, financial institutions need to find ways to manage the risk of unknowable AI contributions. Another of the guidelines calls for FIs to develop contingency plans and fallback options for AI used in high-risk applications. Those plans should include “alternative systems or manual processes, to ensure business continuity in case of AI failure or unexpected behavior.” The guidelines come into force on October 7, 2027. ®
In its first live event in two years, Microsoft today announced its newest Surface laptop, outlined a host of changes coming to Windows 11, and shared a vision of how local-AI and agentic workflows could reshape personal computing for those in the dev community as well as home enthusiasts.
Surface Laptop Ultra
Originally teased in May 2026, the new Surface Laptop Ultra will be Microsoft's first offering to take advantage of the new Nvidia RTX Spark SoC (system on a chip). The device has a starting price of $2,599 and comes in various SoC and memory configurations, with either a 5120-core or 6144-core Blackwell GPU and up to 128GB of LPDDR5x unified memory. It will begin shipping on October 16 and is available for preorder now.
While the new Ultra is clearly focused on the developer crowd, graphical performance was highlighted during the presentation to show off just how capable the laptop can be. By leaning on unified memory allocation rather than the physical VRAM limits of a traditional GPU, the laptop can assign its resources to handle modern gaming tasks as well as local AI development and deployment. The new Gears of War: E-Day was shown running on the system, meaning that even without a traditional gaming GPU, AAA titles are on the table.
An anonymous reader quotes a report from Bloomberg: Alphabet's Google and gaming tools developer Unity Software announced a new platform that will allow people to create video games from simple text prompts, marking the latest incursion of generative artificial intelligence into artistic and creative industries. The initiative, called Playground, will "put game creation in the hands of millions of new creators, and bring new experiences to billions of players worldwide," the companies said in a statement on Oct 7.
With its debut, Playground will let people 18 and older generate and customize games using natural language prompts, "no coding required." Later in 2026, a new expanded creation experience called Unity Spark, will be integrated with Playground, providing "robust, professional-level" mechanics and high-fidelity 3D capabilities. Creators will be able to build "immersive, superlative experiences" with a simple text prompt, according to the release. Playground builds on Google's push into world models, a type of AI that generates virtual environments in real time from text prompts, rather than just video. Google and Unity's partnership "could reduce fears that AI will make Unity's core game-building software less necessary, while posing limited medium-term risk to Roblox's advantage as a social gaming platform," says Bloomberg Intelligence analyst Nathan Naidu.
The introduction of Unity Spark later in 2026 "could broaden Unity's creator base and support its game-development business," which represent about a third of sales.
Artcraft got its start last year as a "controllable AI for artists" that allows for precise post-generation editing of AI-crafted images and videos. Over the weekend, though, the brand debuted its pivot to a suite of seven open source apps recreating the user interface and tools found in Adobe's Photoshop, Illustrator, Premiere, Lightroom, After Effects, InDesign, and Acrobat Pro.
In announcing those new apps on Reddit earlier this week, software developer Brandon Thomas said he used Anthropic's Claude Opus 5.5 to create "clean-room replacements" for Adobe's closed source software in Rust (with WebAssembly versions available for use in a browser). And while commenters on Hacker News and elsewhere have taken pains to point out the new software's many current shortcomings, Thomas makes the grandiose promise that the current "super early alpha" state will soon lead to something just as functional as anything Adobe has ever put out.