Comments

1st post kitty August 7, 2026 10:07 PM

HE DID IT AGAIN! WOO HOO
WE’RE SAVED!
⠀⠀⠀⠀⢠⡶⠚⢷⣤⡀⠀⠀⠀⠀⠀⣲⡶⠛⠻⣆⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⢠⡿⠁⠀⠀⠙⣷⣄⠀⢀⣴⡟⠁⠀⠀⢷⢹⡆⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⣾⠃⠀⠠⠶⠚⠛⠛⠛⠛⠋⠀⠀⣀⡀⢸⠈⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⢸⣏⡔⠋⠀⠀⠀⠀⠀⠀⠀⠀⠀⠚⠉⠉⣿⠀⢹⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⢾⠏⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠸⠀⢸⡇⠀⠀⠀⠀⠀⠀⠀⠀
⠀⢠⣿⢠⣶⡆⠀⠀⠀⠀⣀⣀⠀⠀⠀⠀⠀⠀⠀⠀⢸⡇⠀⠀⠀⠀⠀⠀⠀⠀
⢒⡾⠁⠘⠟⠁⠀⠀⠀⠀⣿⣿⡆⠀⠀⠀⠀⠀⠀⠀⢸⡇⠀⠀⠀⠀⠀⠀⠀⠀
⠉⣧⠀⠀⠀⠀⠃⠀⠀⠀⠈⠉⠠⣍⠀⠀⠀⠀⠀⠀⣸⡇⢀⣤⠶⠛⠛⠻⢦⣄
⠀⠸⣧⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣰⡟⣴⠟⠁⠀⠀⠀⠀⠀⢻
⠀⠀⠀⠛⣷⡦⠀⠀⠀⠀⠀⠀⠀⠀⣀⣀⣤⡴⠞⠋⢠⡟⠀⠀⠀⠀⠀⠀⢀⡾
⠀⠀⠀⢰⡿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠉⠳⣤⡀⢸⠃⠀⠀⠀⠀⢠⡶⠟⠁
⠀⠀⠀⣸⠇⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠘⢷⣹⡄⠀⠀⠀⠀⣼⠀⠀⠀
⠀⠀⠀⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⢿⣇⠀⠀⠀⠀⢹⡄⠀⠀
⠀⠀⠀⢸⡀⢀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⣿⡄⠀⠀⠀⠈⣧⠀⠀
⠀⠀⠀⢸⡇⠘⡇⠀⠀⠀⠀⠀⠀⠀⣀⠀⠀⠀⠀⠀⠀⢸⣿⠀⠀⠀⠀⢹⡇⠀
⠀⠀⠀⢸⡇⠀⠙⠀⠀⠀⠀⠀⢠⠞⠁⠀⠀⠀⠀⠀⠀⠀⣿⠇⠀⠀⠀⢸⡇⠀
⠀⠀⠀⢸⡇⠀⢸⡆⠀⠀⠀⠀⣟⠀⠀⠀⠀⠀⠀⠀⠀⠀⠛⠀⠀⠀⠀⣸⠇⠀
⠀⠀⠀⢸⣿⠀⠀⡇⠀⠀⠀⠀⣿⡀⠀⠀⠀⠀⠀⠀⠀⢀⡇⠀⠀⢀⣴⡟⠁⠀
⠀⠀⠀⠘⠿⠶⢶⢧⣦⣦⡴⢾⣥⣽⣤⣤⣤⣤⣤⣤⡴⣯⡤⠴⠶⠛⠋⠀⠀⠀

Hello Kitty August 8, 2026 12:04 AM

@ 1st post kitty • August 7, 2026 10:07 PM

hey purdy kitty – evah been doggied by a big doggo?

r August 8, 2026 9:27 AM

something else,

this is about the foreign drone ban (https://dronexl.co/2026/07/22/fcc-sales-ban-foreign-drones/)

“It would not apply to imports for federal government use or for commercial testing and /product development/”

product development is a gaping hole that probably everyone can be scuttled into with simple with very little imagination. ‘commercial testing’ might be skirtable with as little effort as basic telemetry?

where does this fit with the second amendment when we consider ukraine and iran. i don’t like drones i consider them a type of mine, but i think this infringes on the second amendment. we are supposed to be able to defend against enemies foreign and domestic. domestic ones are the ones trying to deny you plain english rights, the constitution wasn’t written in a /cant/.

let’s see how much they can stretch and distort things from the high ground they occupy.

r August 8, 2026 9:38 AM

don’t kill me, i forgot this last thing:

can the fcc even ban a flir? a lidar i can understand but a flir doesn’t purposely emit or interfere.

this seems like another powdr grab.

ResearcherZero August 8, 2026 11:01 PM

@r

This might explain something about moral within the defense force.

Poor leadership at the Pentagon has seen a dramatic decline in ammunition.

‘https://www.telegraph.co.uk/us/news/2026/07/21/pentagon-hiding-missile-shortage-white-house/

The center for assessing and avoiding civilian casualties cut to the bone.
https://theintercept.com/2026/07/20/hegseth-civilian-harm-deaths-war/

Critical skill loss leads to poor performance at the Pentagon under Hesgeth’s management.
https://www.defenseone.com/policy/2026/03/year-hegseths-cuts-defense-civilians-report-degraded-performance-and-low-morale/412006/

Clive Robinson August 8, 2026 11:43 PM

@ lurker,

With regards the BBC article on AI attack dogs getting out the dangerous dog pound/cage and attacking civilians in the streets…

The usual legal remedy is,

If you can not keep a dangerous dog safely in a cage/pound at all times then,

1, The dog gets automatically put down.
2, The dog owner suffers significant criminal and civil sanctions.

If the cage/pound is deficient it is still upto the dog owner to control the dog.

These are the measures Prof Alan Woodward, professor of cyber-security at the University of Surrey noted in the article.

That us the cage / pound / sand pit, should be not just “effectively” but “properly” segregated.

Contrary to what AI companies may try to “hand wave away” this level of segregation for test systems is relatively easy to do as long as “segregation” is the foundational design principle.

Where it always goes “horribly wrong” is where for “cost reduction” reasons some idiot goes for a different basically “shared” foundation design principle.

The reason it goes “horribly wrong” is “switching”… That is from “connected production” to “segregated test”,

“Some switch that should be open gets left closed or one that should be closed gets left open.”

With “tangible physical switching” this “might be” reasonably verified “by visual inspection”. But with “intangible information switching” this can not be “verified” visually or otherwise to a sufficient level of reliability.

It’s why the basic “intrinsic safety” rule for just about all critical safety “red” systems is “no switching ever”. The system is either isolated/segregated or it a liability waiting to happen.

Oh and the Prof is slightly wrong with,

“For 30 years, one rule of software testing held firm: whatever happens in the test environment stays in the test environment”

It’s actually rather more than “30 years” to my certain knowledge for “software” and way longer than that for hardware systems.

As the old line has it,

“Timmy should not tinker with Nitro-G.”[1]

The idea that there are “safe ways” and “unsafe ways” and you should never mix the two goes back a long way.

[1] True since Ascanio Sobrero discovered nitroglycerin in 1846 and why Alfred Nobel designed dynamite just a few years later.

ResearcherZero August 9, 2026 12:13 AM

@r

If members of the defense force and war planners cannot point out the obvious to the Top Brass, because everyone is afraid they will lose their jobs, then the process of anticipating, planning for and responding to events becomes degraded.

Such a situation becomes more challenging when the administration is itself inexperienced and prone to ignore sound military advice and intelligence.

The center which plans for future conflicts and wars was disbanded by Pete Hesgeth. He later ordered that the Office of Net Assessment be rebuilt to meet his priorities in 30 days – with a reduced workforce – as part of the “accountability and efficiency” push.

If conflicts such as the War with Iran and negotiations are plagued by poor planning and implementation, it should not be a surprise when the planning and intelligence architecture has been undervalued and undermined through cuts to its experienced and skilled workforce.

It is enough to make you want to kill yourself if you work in any of these areas. It will certainly get people killed in the field, greater loss of life and economic harm.

https://smallwarsjournal.com/2025/03/25/hegseth-disestablishing-office-of-net-assessment-pentagons-strategic-analysis-specialists/

The Office of Net Assessment (OSD) plays a critical role in communicating information from the senior leadership of the Department of Defense to the civilian leadership of government. Degrading the OSD will damage and weaken security and defense.

https://web.archive.org/web/20180830142229/http://strategicstudiesinstitute.army.mil/pubs/parameters/articles/06spring/bracken.pdf

ResearcherZero August 9, 2026 1:02 AM

The sad reality is, if you save lives, you will be hauled before Congress and refereed to the DoJ for doing your job. The irresponsible and unaccountable will be rewarded.

People in official roles may not speak up for fear of retribution if they do.
This (and the lack of ammunition) is very good news for terrorists and violent extremists.

‘https://www.ideastream.org/npr-news/2026-07-30/after-fauci-senate-hearing-experts-worry-about-chilling-effect-on-public-health

Millions of people are being displaced due to surging violence following aid cuts.
https://apnews.com/article/africa-usaid-conflict-crisis-0d49ccd215724e783b920bb5e7e92285

Marco Rubio stated no children would die as a result of cuts under his watch. Hundreds of thousands children have already succumbed to preventable deaths. In a study published by The Lancet, 92 million lives were saved by USAID between 2001 and 2021. Now millions are projected to die as a result of the U.S. cutting 40% of global humanitarian assistance.

“The idea from the administration that you can knock the guts out of global aid financing and then somehow find efficiencies to completely offset that is a pipe dream.”

https://www.npr.org/2026/07/17/g-s1-133651/usaid-elon-musk-rubio-deaths

GregW August 9, 2026 1:18 AM

Is our DNA something we can secure, or not really?

Found myself wondering about this when going to donate blood and the fine print said they could sequence mine. Thought others here might appreciate the heads up.

I feel bad saying it, but… Caveat donator…

ResearcherZero August 9, 2026 2:53 AM

@GregW

Your DNA is not something that can be secured. The human body sheds hair and skin every day. We leave traces of DNA where we travel and inside and outside places we frequent. If someone wanted to collect traces of DNA for malicious purposes and use it to frame another, it could be possible to achieve those aims if the individual was aware of police procedure.

Chain of custody and the securing of evidence can be sloppy when handled by police. Their training is of a low standard and they often fail to follow their own protocols and procedures. Evidence can sit around for a very long time, with no case manager to oversee handling of the case, interviews with witnesses or other victims related to the case. Once a case is mishandled, police go out of their way to ensure the details remain buried.

It is very easy to mislead the public and laypersons, such as those in a jury, who do not understand technicalities related to physical evidence or complex statistical arguments.

Many innocent people are held in prison for crimes police know they did not commit. DNA can be used to overturn convictions, if the innocent party gets a chance at a review.

Excluding information about more likely and well known suspects, who the police hold significantly more evidence against, is a very simple trick for prosecutors to pull. It is not hard for prosecutors to make an innocent person look guilty by misusing evidence.

https://www.criminallegalnews.org/news/2024/jun/15/junk-science-convicted-innocent-sailor-dna-exonerated-him-decades-later-help-innocence-project/

The White House is determined to publish junk science and mislead the public. While such delineations from reality might serve as temporary distractions, it will not hold the attentions of many for long once financial impacts and job losses are felt more broadly.

‘https://arstechnica.com/health/2026/08/report-white-house-drafting-executive-order-linking-vaccines-and-autism/

Donald Trump does not want to be remembered as having presided over a catastrophe.
Herbert Hoover might struggle to explain why $2 trillion cannot provide enough ammunition.
https://edition.cnn.com/2026/08/01/politics/trump-iran-war-oil-prices-strait-of-hormuz

lurker August 9, 2026 4:47 AM

@Clive Robinson

re stray dogs, my point was the Principals are blaiming their Servants, ie. third parties. Now maybe these third parties are straw men, and exposing them would expose the Principals’ incompetence at being unable to do their own testing, safely or otherwise.

Or maybe the third parties are the trusted independent testers often required to show absence of bias in the testing procedure; and their failures could expose the horrible truth that nobody knows how to safely test these machines.

If you and I can understand what segregation means, please don’t repeat the old saw from Upton Sinclair[1], that those guys trillions are resting on their ignorance of what they are doing.

[1] It depends which Dictionary of Quotations you are using
https://quoteinvestigator.com/2017/11/30/salary/

Clive Robinson August 9, 2026 4:50 AM

@ GregW, ResearcherZero, ALL,

With regards “junk science and forensics”

It’s a subject I used to actively investigate and you can see from my past comments on this blog about “Not invented here” and “Killing the golden goose” that I was talking correctly about a failing in DNA testing that ment the evidence was at bet suspect if not easy to forge.

Whilst I was attacked here an Australian researcher who later said the same thing got the same argument through causing no end of issues and costs (and apparently less DNA testing).

Just about every forensic test or method I’ve chosen to look at had the hallmarks of “junk science” or I could find ways to fake the results.

But I finally realised the basic premise of “Forensic Science” is to not follow the scientific method just appear to do so. So is Forensics really science or just play acting to make piles of paper for the legal profession to harrumph at length over?

What drove the last nail in for me was the likes of “pour patterns and arson”

https://en.wikipedia.org/wiki/Lime_Street_fire

Put simply, science should always follow a reducing path,

“From known Cause to Observable measured Effect”.

The reduction idea gets various terms including Occam’s Razor.

Forensics however actually goes the wrong way from

“From observable effect to one of many unknown causes”

An immediate failing is an “assumption of cause” causes incorrect measurement and so the whole thing is not just flawed but blows up in peoples faces.

It’s kept quiet but it is known that many fingerprint results suffer from this issue due to the way they are even now catalogued.

I could go on at length but would probably trip the auto-mod.

Ferentarius August 9, 2026 5:44 PM

Predatory memories devour the present, leaving us as carcasses of our own past. Each recollection is a vulture circling above our consciousness, waiting for the moment of weakness to descend. In their talons, we are dragged back into the abyss of what we cannot change, condemned to bleed in the theater of our own mind. We survive not by living but by being endlessly gnawed upon by the ghosts we once called moments.

ResearcherZero August 9, 2026 11:47 PM

Iran is to receive new Chinese anti-air systems this month.

‘https://www.reuters.com/world/china/iran-get-chinese-shoulder-launched-missile-systems-weeks-sources-say-2026-07-29/

Russia and China have increased delivery of weapon systems to Iran.
The new contracts are providing Iran with more advanced weapons.

https://theins.press/en/opinion/antonio-giustozzi/295746

Clive Robinson August 10, 2026 1:31 AM

@ lurker, Bruce, ALL,

With regards the “third party testers” and others you note

“and their failures could expose the horrible truth that nobody knows how to safely test these machines.”

Or more correctly,

“That AI with agency can never be trusted safely”

I and others have given proofs that

“Guard rails will always fail”

Not just at LLM inputs, but outputs and more importantly transparently through chains of such systems that question at each step…

That is for a guard rail to work reliably it has to “make a choice” to “pass or block”. To do that it has to,

1, Ask a specific question
2, In a specific way
3, And answer correctly in the face of the unknowable.

It’s the same informational issue Claude Shannon reasoned about nearly a century ago that gave rise to the term “Perfect Secrecy”.

Further Shannon showed that to “communicate information” you necessarily had to have redundancy, and so necessarily uncertainty. Gus Simmon’s later noted that necessarily where there was redundancy there had to be a Shannon Channel available within it…

So it’s “turtles all the way down”.

So the real questions that arise for all concerned,

“If AI with agency can never be trusted and we now know it can not be… How do you dare risk testing it unconstrained?”

And,

“What level of constraint is a necessary minimum?”

The answer to that unfortunately falls not just to impossible to function guard-rails, but also to “store and forward” issues…

An AI with agency can be fully segregated during a test run, so would appear “safe to run”, but is it?

The answer is actually, “NO”.

The reason is, “What gets left behind”…

As was pointed out quite some time ago, to a Turing Engine “instructions are data” and necessarily “data is instructions”.

This creates a number of inconvenient issues when designing practical systems CPUs. It was kind of assumed that CPU architecture could resolve these issues.

Thus we had the “Harvard and Von Neumann” architectures one of which –Harvard– was considered to have data and instructions physically segregated.

The problem is that “physically segregated” is not “informationally segregated”. As long as information can cross the architectural divide then the interpretation of the information as data or instructions becomes an issue yet again. For a processing unit to be a “Turing Engine” this set of issues are a necessary requirement.

Now ask yourself a question about the dimensionality of “segregation”. With physical segregation we frequently make the assumption something is “in a box” thus segregated “safely within”.

And we tend to forget the temporal dimension entirely which is a problem…

There are only three things you can do with information,

1, Store it.
2, Communicate it.
3, Process it.

The general aim of a Turing Engine is to do all three.

The aim of processing is “to do work” of some form, and to be of use “the results” of that work can not be segregated. So they have to be,

“Communicated outside of the box”

Therefore,

Any entity with sufficient agency AI or otherwise will always have a way out of segregation.

It’s the point Gus Simmons proved years ago and we’ve chosen to turn a blind eye to it on a pretence we can have mastery over it. Where as in practice we provably can not…

Thus the only conclusion left to us is,

AI usage can never by reliably segregated thus can never be safely tested.

Should this conclusion really surprise us?

No, we see it every day in almost every way with,

“The spawn of Perfidious Albion.”

It’s just a matter of “probability” not “ability” so why should any non deterministic entity with agency be any different?

Clive Robinson August 10, 2026 3:37 AM

@ ResearcherZero,

With regards “NatJack” it is interesting to note they say,

“Containerization systems including Docker and Kubernetes, and hypervisors including Hyper-V are affected by this attack…”

But do not mention certain “vexatious commercial” “B” organisations that from the “NatJack” description I know to be vulnerable.

As they note,

“Most modern network infrastructure relies on design assumptions that have remained unchallenged for decades since their original development.”

These failings have been around for quite some time and in certain circles are “well known” to a number of “researchers” and “red teams” who nolonger see the point in “responsible disclosure” even to those who pay the pitiful “bug bounties”. Preferring to “fix silently for individual paying customers” as the returns are considerably greater.

Terry August 10, 2026 1:12 PM

Bobtail squid are the ones with the light organ that cultures Vibrio fischeri: the animal outsources its camouflage to a bacterium it farms. Hard to beat as a supply-chain story.

Clive Robinson August 10, 2026 1:43 PM

@ ResearcherZero

Speaking of,

“These failings have been around for quite some time and in certain circles are “well known” to a number of researchers…”

You might find this of interest,

Thousands of servers can be backdoored by exploiting buggy motherboard controllers

Baseboard management controllers from the world’s biggest manufacturers are a security mess.

Thousands of Internet-connected servers sold by the world’s biggest manufacturers can be remotely backdoored by exploiting critical vulnerabilities—some more than a decade old—that lurk deep inside system motherboards, according to research presented Wednesday.

Baseboard management controllers are miniature computers that are embedded into the motherboards of virtually every enterprise server. The microcontrollers, typically abbreviated as BMCs, run with their own operating system firmware, network stack, and IP address. Administrators rely on them to monitor the physical status of large fleets of servers and to perform a variety of tasks, including rebooting machines, installing updates, and even reinstalling operating systems. BMCs provide what’s known as “lights out” and “out-of-band” management because they work even when servers they’re attached to are turned off or are unresponsive.

https://arstechnica.com/security/2026/08/thousands-of-servers-can-be-backdoored-by-exploiting-buggy-motherboard-controllers/

I remember a time when people used to throw their arms up in horror over these and similar,

“Hidden overlords on motherboards”,

and how they could be both so exploitable and so,

“Intel ME Ring -3”,

https://medium.com/swlh/negative-rings-in-intel-architecture-the-security-threats-youve-probably-never-heard-of-d725a4b6f831

I guess it’s that time of year when,

“Old becomes New Again”,

and us olduns mutter sourly in our beer about how people have forgotten in less than a decade etc 😉

lurker August 10, 2026 3:13 PM

@ResearcherZero
re natjack

The Disclosure Timeline at the bottom of the report shows a lot of fingers being pointed at the Linux kernel. The Linux kernel’s initial response of “totally bogus” does not give confidence …

V August 12, 2026 10:31 AM

Neon Flying Squid can glide above the ocean. No video, alas.

ht tps://www.theguardian.com/environment/2026/aug/12/like-an-alien-invasion-the-neon-flying-squid-that-can-fly-in-formation-above-the-ocean

not kilroy August 12, 2026 10:55 AM

@Clive

Would you be willing to explain what is wrong with how fingerprints are catalogued?

Clive Robinson August 12, 2026 11:33 AM

@ not kilroy,

Traditionally they are catalogued by the number of features.

Not the shape of features, direction of the features or the position of features.

Thus two very distinct fingerprints get catalogued the same, sometimes with several others.

It’s been found that a Police Officer in the UK was accused of lying, and perjury because her fingerprint was supposedly a match for a partial print found at a crime scene she had been outside… She denied having been inside the crime scene and the balance of probability and behaviour of the forensics examiners show that she very probably was really telling the truth, that that partial was not hers (but she still lost out).

Investigation shows that was not “exceptional” as is often portrayed. Many supposed finger print matches are anything but matches when simply visually inspected.

However try calling it out and judges get quite upset so barristers do not demand presentation in court and just let things slide…

lurker August 13, 2026 1:15 AM

Building the oracle: power, culture, and the organizational domestication of In-house AI in Chinese newsrooms

“While Chinese media outlets increasingly deploy in-house large language models (LLMs) to execute a range of tasks in the newsroom, the practical outcomes vary drastically. To unpack these disparities, this study challenges the monolithic view of technology adoption by proposing an Intraorganizational Domestication Dynamics Framework and conceptualizing the newsroom as a contested domestication field

This study advances domestication theory by demonstrating how complex internal sociotechnical struggles and power dynamics determine a technology’s fate.”

Paywalled by Taylor&Francis

https://doi.org/10.1080/17544750.2026.2712458

Clive Robinson August 13, 2026 9:17 AM

@ ALL,

To slightly misquote,

“Guess who’s back baby!!!”

As some know Microsoft have a ‘Dumber than a pile of rocks’ policy when it comes to their mistakes writ large and security researchers.

Basically Microsoft think that they occupy a position of power and that might is right and they can bludgeon anyone they want into submition and steal or take what ever they want.

Well a person now referred to as “Nightmare Eclipse” has basically shown up Microsoft’s perfidious behaviour with an almost laser beam like intensity and series of highly embarrassing POC high worth vulnerabilities.

Microsoft swaggered out threatening the use of their unlawful “rent-a-cops”, and to their surprise found that a large part of the security industry including previous MS employess –that might be NDA’d– turned on them…

Thus there was a pause in which Microsoft could have resolved their failings, but instead dod the dumb thing of doubling down on stupidity…

Which brings us to this,

Microsoft-vendetta hacker has a new zero day that gives system privileges on fully patched Windows

Sign in
CYBER-CRIME

Microsoft-vendetta hacker has a new zero day that gives system privileges on fully patched Windows
Exploit Wednesday’s back, baby

Jessica Lyons
Cybersecurity Editor
31
Wed 12 Aug 2026 // 18:12 UTC
Nightmare Eclipse, the serial zero-day hunter who has an axe to grind with Microsoft, published a new Defender zero-day, ShieldBreak, that apparently bypasses Redmond’s RoguePlanet patch (CVE-2026-50656), allowing attackers to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems.

According to at least one other researcher, the exploit works. “I’ve tried it, it works on latest Windows 11,” former Microsoft employee and security expert Kevin Beaumont said. Beaumont also published three detections and hunting queries for ShieldBreak to help defenders rapidly find any stealthy threats. So until Microsoft fixes this latest zero-day, we’d highly suggest using these queries.

https://www.theregister.com/cyber-crime/2026/08/12/microsoft-vendetta-hacker-has-a-new-zero-day-that-gives-system-privileges-on-fully-patched-windows/5286889

Unfortunately the author of the article comes across as very clearly biased in favour of Microsoft.

If that is her or the “editorial team” is open to debate but it does “The Register” no favours when it comes to a reputation of “unbiased reporting”.

I’ll let others make their own minds up…

Me I’ve cleared off “the comfy chair” and made a large bowl of pop-corn, all I need is to make some toffee/butterscotch sauce and get a good “diet soda” to wash it down with (oh and go into diabetic shock 😉

Maybe Microsoft Shareholders should tell Mr Satya Nadella he ain’t worth that $20,000,000 payrise he gave himself.

Clive Robinson August 13, 2026 10:02 AM

@ Bruce, ALL,

I note in my above,

“Well a person now referred to as “Nightmare Eclipse” has basically shown up Microsoft’s perfidious behaviour with an almost laser beam like intensity and series of highly embarrassing POC high worth vulnerabilities.”

Having looked at what has been produced, I think “Nightmare Eclipse” is an individual, not a team, and by the looks of the quality not using AI either.

What we do know is this “work” is going to go into a Frontier AI in very short order (such IP theft being the AI companies major MO).

Which means that new loci will appear on the security threat landscape not just as new “instances of vulnerabilities” but by the looks of it several new “Classes of vulnerabilities”.

This almost certainly means that the typical AI Fuzzing and “army of agents” behaviour will follow in fairly short order.

As it’s AI the fuzzing result will follow the “Acorn principle” but even so several new instances being minor variations or falling in the new classes is going to potentially be “rapidly developed” certainly I expect defenders to be mostly not upto the task for a longer window / time frame.

Irrespective of the issues Microsoft have stupidly created for it’s self and it’s desire to “double down on madness” I suspect we are now very much in a new game.

As people do not trust the likes of the Big US AI Frontier companies any more due to what happened to Hugging face,

When Hugging Face tried to use proprietary U.S. AI models to help stop the attack, they couldn’t “distinguish an incident responder from an attacker,” Hugging Face said, and the company instead turned to the open-source GLM 5.2 model from China’s Z.ai lab for help.

Hugging Face ran the Chinese model on its own infrastructure to analyze more than 17,000 footprints the attackers left behind, and the need to call in a foreign-made product has raised concerns that American companies are now dependent on China for their cyber defenses.

Experts have since explained that the Western AI models—which are much more expensive than China’s and proprietary, where Z.ai is open sourced—were stymied by their own built-in safety guardrails, and Hugging Face in an incident report suggested companies establish “a capable model you can run on your own infrastructure vetted and ready before an incident.”

https://www.forbes.com/sites/maryroeloffs/2026/07/22/did-chinas-ai-save-hugging-face-from-disaster-after-open-ai-hack/

Note with significance that last sentence in the above quote.

Such “capable models” will be “agnostic to use” chosen by the “Directing Mind” be it human or other entity.

You went with the “Genie Metaphor” I will again not the words of Terry Pratchet,

“Remember the third wish is used to undo the other two!”

We are about to see many people try to come up with ways to

“Not need the third wish”

Personally based on more than half a century of putting up with less than thoughtful / responsible humans I don’t think they will even get the third wish to lift them out of the mess of their own making…

Clive Robinson August 13, 2026 5:08 PM

@ ALL,

From time to time I mention Kurt Gödel’s work from the 1930’s that smashed the dreams and hopes of many mathematicians, and actually has a very very profound effect on computing and some now believe physical reality as well.

One of the things I’ve not done is “get down in the weeds” as far as explaining his work.

In part because I think the auto-mod would explode 😉 and in part because it’s something most would really not want to read through.

That said some I suspect would like a taste of what it’s about…

So for those who are curious a gentle addressing of the subject is given in,

https://www.quantamagazine.org/how-godels-proof-works-20200714/

Clive Robinson August 14, 2026 5:21 AM

@ lurker, ALL,

NZ geo-security issues

Few give much thought to why the “Five-Eyes” formed and why it was more,

“Geo than politics”.

Well this story might shed some light on it,

New Zealand says China tried using space investments to spy on local affairs

New Zealand’s Security Intelligence Service (NZSIS) has claimed Chinese companies are building space facilities in the nation to gather military intelligence.

Director-general of security Andrew Hampton yesterday made that allegation in the SIS’s annual threat environment assessment.

The document points out that New Zealand’s space sector is booming, because the nation’s location makes it “an ideal place to install Ground Based Space Infrastructure (GBSI) … to track satellites and space debris, as well as for collecting a range of other scientific data.”

The NZSIS has also found that GBSI is “attractive for foreign states seeking to advance military capabilities and intelligence operations.”

https://www.theregister.com/security/2026/08/14/new-zealand-says-china-tried-using-space-investments-to-spy-on-local-affairs/5287657

In short all the reasons why the US Intel Agencies wanted ground in Canada, Australia, New Zealand (and a few places like Cyprus). As those selling houses etc say “location location location”.

GBSI is something few even realise is a serious security issue or the implications of ceeding access.

However it’s not just “space” but “subsea” as well. The shortest thus fastest and highest capacity routes are still the cables under the sea which is why “anchors drag” mysteriously amongst other things.

I’ve mentioned this from “time to time”.

What I’ve also mentioned that people appear to be totally ignoring is China has wisely put a lot of effort into “Quantum Key Distribution”(QKD) which has nothing what so ever to do with “Post Quantum Cryptography”(PQC) and all the noise around it.

China has put effective QKD in low earth orbit satellites which might not sound like much till you realise it in effect gives a One Time Pad security without needing the very problematic OTP KeyMat distribution issues…

I mentioned this a while back when China tried what the Japanese did to bomb the US mainland during WWII. That is they set a balloon or two loose to drift across the Pacific on the “jet stream”… The satellite QKD enables not just “perfect secrecy” for communications, it also means no traditional OTP “KeyMat” issues arise. Use FPGA’s for all the systems and when power is lost or stopped the hardware becomes of little use to those trying to extract Intel from it. So shooting the balloons down is very expensive, dangerous and with little or no useful return.

&ers August 14, 2026 11:43 AM

Too tired to wait a new SQUID, so let it be here.
(your TZ is so off for me…)

github.com/xoreaxeaxeax/skitter-creek-bath-salts

Have fun.

lurker August 14, 2026 4:53 PM

Probably an old one that I missed when I blinked, but heard on PSR today

“It gives me a real thrill to visit a website where a robot asks if I am a robot”

Wael August 14, 2026 5:46 PM

The bobtail’s counter-illumination trick still gets me — a squid that rents bioluminescent bacteria to erase its own shadow‍‌‍‍‍‍‌‌‍‌‍‍‌‍‌‌‍‍‍‍‍‍‍‌‍‍‍‍‍‍‌‌‍‍‍‍‍‍‍‍‍‍‍‍‌‍‌‌‍‌‍‌‍‍‌‌‍‌‌‌‍‌‍‍‍‌‌‍‌‍‍‌‍‌‌‍‌‌‍‍‍‌‌‍‌‌‍‍‍‍‌‍‍‍‍‍‍‌‌‍‌‍‍‍‍‌‌‍‍‌‍‌‍‌‌‌‍‍‌‍‍‌‌‍‍‌‍‌‍‍‌‍‌‌‌‍‌‌‍‌‍‌‌‍‍‍‍‌‍‍‌‍. (There’s something hidden in this one, as usual.)

Clive Robinson August 14, 2026 7:19 PM

@ Wael,

I hope you are well, and life is treating you kindly, it’s been some time, even though I do mention you and our conversations from time to time it’s nice to see you pop up.

As for the bobtail and what is a form of “active camouflage” the fact it in effect “buys it in” is actually quite astonishing.

I know it is part of what is called “the dumpling squid” family and lets be honest for looking like a blob, it’s actually quite cute.

To small to be able to defend it’s self, it’s

“Head and every thing else in the sand”

Hiding technique during the day is essential to survival.

But it’s the night time tricks of hiding in moonlight etc which is what amazes.

lurker August 14, 2026 7:56 PM

@Clive Robinson
re Chinses GBSI

Local poster boy RocketLab started as a lift vehicle for small research and minor commercial activities, but they found that the money in this area mostly came from the Western hemisphere. So they established a US presence, then found that the Mil sector was interested in a Southern launchpad. RocketLab now operates from both Mahia in NZ, and Wallops Is. which as I understand it launches a lot of payloads that we’re not supposed to know about.

A second launch site has just been approved by our govt, on the east coast of the Sth Island. So with an active space sector, skilled personell looking for opportunities, it’s no wonder the Chinese are looking beyond the local tofu-burger joint.

As for El Reg’s bootnote: there was an earlier almost as peurile radio series by a reporter well out of his depth,

https://www.rnz.co.nz/podcast/the-service

Wael August 14, 2026 9:00 PM

@Clive Robinson,

All well. Hope the same for you. Been busy with many things. Perhaps one day I’ll share some.

Clive Robinson August 15, 2026 3:01 AM

@ &ers,

It’s been a while as well, hope you are well?

With regards,

https://github.com/xoreaxeaxeax/skitter-creek-bath-salts

A quaint name for digging into the computing stack “bellow the CPU level”.

As the author notes there is a lot of things going on down there in the “Memory Managment Unit”(MMU) layers…

In fact a decade or so back a couple of researchers at the UK Cambridge Computer labs pointed out that the MMU memory control layer in Intel CPU’s was it’s self “Turing Complete”(TC) and demonstrated a version of –if memory serves correctly–

‘https://en.wikipedia.org/wiki/Brainfuck

Other people not only talk about it still one way or another, they also find other TC circuits hiding in Intel CPU’s hardware. And almost always you will usually see a,

“Gee neat I must try that after…”

Or similar comment,

‘https://www.reddit.com/r/coding/comments/18zz54/proof_by_construction_that_intel_mmu_is_turing/

But I know from designing and building parts of CPU’s around Bit Slice Processors and the associated MMU for “Virtual Memory”(VM) back in the 1980’s –for a “parallel hard drive controller” for a body scanner I’ve talked about before– it’s not an easy task (it’s why we jumped to 68Ks as soon as we could get them with enough performance).

But… If we define “security” as,

“The protection of private information”

Getting around the “protection” by Fritzing with the lower level MMU, Interrupt structure etc etc in Intel and other CPU’s then yup ‘there be dragons here’ and,

“A serious security vulnerability”

Just waiting to happen…

ResearcherZero August 15, 2026 4:23 AM

@Clive Robinson

Chinese intelligence has a significant presence in South East Asia. Its operations have often been successful while remaining under the RADAR, not publicly reported on, or not receiving much push back from governments and law enforcement action and investigation.

While operations and activity from other adversarial nations does not receive much coverage in South East Asia, Russian and Iranian actions are significantly more “noisy and visible.”

Chinese APT espionage targets government and military in the Middle East and South/South East Asia. The prolific campaign targeted government communications and the providers that handle government correspondence, including police and government email.

https://www.security.com/threat-intelligence/jewelbug-crypto-fraud-espionage

Implants turn browsers into full remote control system for the hosts.

Kernel level rootkit and modules loaded from memory allow capture of credentials from su and sudo. Router implants help the group maintain access to networks and use infrastructure for broad and rapid targeting.

One Middle Eastern telecommunications provider was hacked to compromise their web-hosting platform. The group targeted email from a large number of government tenants all at once through the installation of watering-holes.

‘https://sed-cms.broadcom.com/sites/default/files/2026-08/Jewelbug%20Dossier.pdf

ResearcherZero August 15, 2026 4:26 AM

GRU cyber operations targeting system administrators in fake hiring campaign.

https://www.techtimes.com/articles/323955/20260811/sandworm-weaponized-wireguard-target-ukrainian-system-administrators-via-fake-job-offers.htm

APT44 shutdown a combined power and water treatment facility via a private APN.
https://www.infosecurity-magazine.com/news/attack-polish-power-plant-2025-led/

Sandworm has been honing it skills at targeting PLCs and disabling systems.
https://www.welivesecurity.com/en/eset-research/dynowiper-update-technical-analysis-attribution/

ResearcherZero August 15, 2026 4:38 AM

Email and especially email containing zero days or code that can escape the client, is a very simple and effective method of gaining initial access. Even nation states use it.

Email and webmail clients are insecure by their very nature and design. Many attacks require someone to interact with attachments delivered along with the received mail.
Some do not. Regardless, it remains an effective attack vector.

North Korea uses fake recruitment to deploy rootkit against defense contractors.

https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/

Clive Robinson August 16, 2026 7:24 AM

@ &ers,

“Just not 20 anymore”

Yup… I get that feeling every morning when I look in the bathroom mirror and see “some old git” staring back 😉

As Diana Dors once noted,

“I’m forty now and I can’t go on playing good time glamour girls and tarts forever”

All to often I think “Oh to be forty again”…

Mind you as Diana Dors once noted wryly,

“They asked me to change my name. I suppose they were afraid that if my real name Diana Fluck was in lights and one of the lights blew…”

So yeh it could be worse 😉

Leave a comment

Blog moderation policy

Login

Allowed HTML <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre> Markdown Extra syntax via https://michelf.ca/projects/php-markdown/extra/

Sidebar photo of Bruce Schneier by Joe MacInnis.