Tuesday, 1 September 2026

VMware Borrows Nvidia’s AI Factory Name to Push AMD Hardware in Private Clouds

Broadcom’s VMware unit just renamed and expanded its private AI tools. The new package carries a name long associated with Nvidia. Yet this version runs first on rival AMD silicon.

The announcement landed Monday at VMware Explore in Las Vegas. It arrives as enterprises hunt for ways to control exploding inference costs without handing data to public cloud providers. VMware AI Factory promises exactly that: automated infrastructure from bare metal to model serving, all inside VMware Cloud Foundation.

Call it co-opetition at its finest. Nvidia popularized the “AI factory” phrase years ago to describe end-to-end systems built around its GPUs, networking and software. VMware, a longtime Nvidia partner that helped virtualize those expensive cards, now applies the same label to a stack centered on AMD Instinct GPUs and the open ROCm ecosystem. The move highlights a market shifting from raw GPU scarcity to operational efficiency and predictable pricing.

Prashanth Shenoy, vice president of product marketing at Broadcom’s VCF division, described the offering in The Register as “an evolution” of the earlier VMware Private AI Foundation with Nvidia. “VMware AI Factory represents a full-stack, automated operational system designed to treat AI token generation as a continuous production pipeline,” Shenoy said. He noted the platform supports multiple accelerator architectures and called Nvidia the company’s longest-standing GPU vendor partnership.

But for now the spotlight sits on AMD. Broadcom and AMD are collaborating to deliver a VMware AI Factory that pairs VCF with AMD Instinct MI350 Series GPUs and the open AMD ROCm software ecosystem, according to Broadcom’s official release. Zero-touch provisioning orchestrates the entire stack from vSphere and vSAN through Kubernetes and the AMD GPU operator. An AMD DVX driver attaches GPUs to large VMs consumed by a VMware vSphere Kubernetes Service cluster.

Paul Turner, chief product officer of Broadcom’s VMware Cloud Foundation Division, put the value proposition plainly in coverage by Investing.com: “VMware AI Factory changes that. We give customers a software-defined foundation that automates infrastructure deployment, unifies lifecycle management, and lets them choose their preferred hardware and vetted models.”

The economics matter. Public cloud inference bills can spiral. On-premises setups often suffer from underutilized GPUs locked away in departmental silos. VMware AI Factory lets organizations deploy a model once and share it securely across tenants or business units through isolated namespaces. Token monitoring, rate limiting and an AI Gateway enforce governance. Secure AI sandboxes isolate agent-generated code and limit tool access. And an observability dashboard tracks utilization, latency and cost.

Servers from Cisco, Dell Technologies, Lenovo and Supermicro carry official VCF AI ReadyNode certification. A new integration with MetalSoft slashes bare-metal provisioning from weeks to minutes. The result: time from raw hardware to first model serving shrinks from weeks to hours, multiple sources report.

Model support looks broad. VCF customers can run more than 150 open source and commercial models. Five already validated include Nvidia’s Nemotron 3, Google’s Gemma 4, NEC’s cotomi, Alibaba’s Qwen 3.7-Max and Z.ai’s GLM 5.2, according to Broadcom’s press release and coverage in Network World.

Shenoy told SDxCentral the initial hardware partners focus on AMD but Nvidia remains “top of mind.” The platform does not replace Nvidia’s own AI factory reference architectures. It simply gives customers another validated, automated path that avoids per-token cloud pricing.

Analysts see the announcement as part of a larger industry move toward private AI clouds. A Broadcom survey cited in its materials found 56% of enterprises already run or plan to run production AI inference on private infrastructure. Data sovereignty, cost control and security concerns drive the shift.

AMD itself has pushed hard into rack-scale systems. Its Helios platform, built on Instinct MI400-series GPUs and 6th Gen EPYC Venice CPUs, targets the same inference-heavy workloads now dominating global AI compute. Shipments ramped in recent months with commitments from OpenAI, Anthropic, Meta and Microsoft measured in gigawatts. The VMware partnership validates AMD’s ROCm software in enterprise private clouds and offers a software-defined control plane on top of that hardware.

Yet challenges remain. Nvidia’s CUDA still dominates developer mindshare. ROCm has narrowed the gap but enterprise adoption outside hyperscalers has lagged. VMware’s long history virtualizing Nvidia GPUs gives the new AMD-focused factory credibility, yet customers will watch real-world performance numbers closely.

The broader VMware Explore agenda reinforced the private AI theme. Announcements around agent governance, Tanzu data foundations and strengthened open-source security for Python and Java libraries painted a picture of infrastructure built to handle agentic workloads securely at scale. Those agents, which generate code, call tools and access resources, require exactly the sandboxing and policy controls VMware highlighted.

Enterprises face a simple choice. They can keep buying discrete GPU clusters for every team and watch costs climb. Or they can treat inference as a shared production pipeline with centralized governance, usage-based accounting and hardware choice. VMware AI Factory bets the latter wins.

Whether the borrowed branding confuses buyers or simply borrows mindshare from Nvidia’s marketing remains to be seen. What matters more is the underlying promise: faster deployment, lower and more predictable costs, and the ability to keep sensitive data and models behind the firewall. For CIOs tired of surprise cloud bills and shadow AI projects, that message lands at the right time.

Broadcom has not ruled out a dedicated Nvidia-centric AI Factory variant. For the moment, though, the company is using its virtualization strengths to give AMD a stronger foothold in the enterprise private cloud market. The competition between the two GPU vendors just gained a powerful new layer of software abstraction.



from WebProNews https://ift.tt/APGL3lZ

China’s Factory Gauges Signal Patchy Lift as Policy Hopes Clash With Lingering Demand Weakness

China’s manufacturing sector showed tentative signs of stabilization last month. Official data released by the National Bureau of Statistics painted a picture of modest improvement even as the key gauge stayed below the line that separates contraction from growth.

The manufacturing purchasing managers’ index rose to 49.8 in August from 49.2 in July, according to figures from the South China Morning Post. That beat economists’ expectations. Yet it marked a second straight month in contraction territory after four months of expansion. Production picked up. New orders gained ground. Still, broader domestic demand remained soft.

But a private survey told a different story. The RatingDog China General Manufacturing PMI, compiled by S&P Global, climbed to 51.5 in August. It topped the 51.0 consensus in a Reuters poll and marked the strongest reading in months. Output expanded at the fastest pace in three months. New orders grew more quickly, with export orders posting their sharpest increase in six months. Investing.com reported the details.

The divergence highlights a familiar tension. Official figures, which lean toward larger state-linked firms, often appear more cautious. Private data capture smaller manufacturers and exporters more directly. Both point to the same underlying pressure. Weak consumption at home continues to weigh on the world’s second-largest economy.

Zhao Qinghe, senior statistician at the National Bureau of Statistics, noted that production accelerated while business confidence edged higher. The production sub-index reached 50.4. New orders climbed to 50.6. Large enterprises returned to expansion at 50.6. High-tech manufacturing stood at 52.9, underscoring the shift toward advanced sectors. Those comments appeared in coverage from AP News.

Yet employment sub-indices stayed weak. Factories remained reluctant to hire. Raw material inventories contracted. And while input prices rose on higher commodity costs, many producers absorbed the increases rather than pass them on. Intense competition and promotional discounting kept selling prices in check.

Analysts pointed to several factors behind the uptick. Extreme weather disruptions eased in August after July’s heat waves and flooding. Policy measures aimed at boosting domestic demand began to filter through. Beijing has rolled out support for infrastructure and consumption. The effects, however, have been uneven.

Yao Yu, founder of RatingDog, captured the nuance. “Notably, the manufacturing sector is helping the recovery, but this rebound is patchy,” he said. “With weak domestic demand, potentially overstretched external orders, and slow profit recovery, the durability of the improvement depends on whether exports truly stabilise and whether domestic demand can pick up pace.” His remarks came in the Reuters report on the private survey.

External risks add another layer. A temporary trade truce with the United States bought some breathing room. Yet tariffs loom. Front-loaded shipments ahead of potential duties could fade. Geopolitical tensions and slowing global growth cloud the export outlook. New export orders in the official data remained subdued even as overall orders improved.

The non-manufacturing PMI offered little comfort. It held steady near contraction levels, reflecting softness in services and construction. Property sector troubles persist. Local government financing constraints limit infrastructure spending. Consumers remain cautious amid high youth unemployment and weak confidence.

High-tech and equipment manufacturing stood out as bright spots. Their PMI readings stayed firmly above 50. This reflects Beijing’s long-term push to climb the value chain and reduce reliance on traditional industries. Semiconductor demand tied to artificial intelligence has supported some export strength. Yet these pockets have not yet lifted the broader factory floor.

Economists expect more policy action. Beijing has signaled further fiscal support, potential rate cuts, and measures to stabilize the property market. The question is timing and scale. Early signs of recovery in industrial production may appear in coming months. But without stronger household spending, the rebound could prove short-lived.

Market reaction was muted. Chinese stocks showed limited movement after the data. The yuan held steady against the dollar. Investors appear to be waiting for clearer signals on stimulus before committing capital. Bond yields dipped slightly on expectations of easier monetary policy.

Looking ahead, manufacturers in the private survey remained optimistic about output over the next year. Optimism hit its highest level since March. Yet overall confidence slipped to its softest since January. That mixed sentiment captures the current moment. Factories see potential. They also see risks.

The August readings come as China’s economy grapples with structural challenges. Decades of investment-led growth have left overcapacity in many sectors. Debt levels constrain local governments. Demographic headwinds loom. Policymakers face a delicate balancing act. They must support growth without reigniting financial risks or excess production.

Recent moves suggest a more proactive stance. Authorities have eased some restrictions on home buying and promised infrastructure spending. Stock market stabilization measures have lifted sentiment temporarily. But translating these steps into sustained factory demand will take time.

Global context matters too. U.S. policy under the current administration has kept pressure on trade. Europe’s slowdown affects Chinese exports. Emerging markets offer some offset, yet not enough to replace traditional partners. Supply chain diversification by Western firms continues, though the process remains gradual.

In the end, August’s data offer a sliver of encouragement. Production is picking up. Certain advanced industries show resilience. Demand, however, has yet to follow through convincingly. Until domestic consumption regains momentum, China’s factories will operate in a narrow band between mild contraction and fragile expansion. Policymakers hold the next moves. Markets will watch closely.



from WebProNews https://ift.tt/AngdbLV

Monday, 31 August 2026

Texas Governor Orders Statewide Real-Time Facial Recognition Camera Network

Texas Governor Greg Abbott has directed state agencies to expand the use of automated camera systems capable of scanning large crowds for individuals on watch lists or wanted for crimes. The directive, issued through an executive order, instructs the Department of Public Safety and other relevant bodies to integrate advanced facial recognition technology into public surveillance infrastructure across Texas. This move positions the state as one of the most aggressive adopters of such tools in law enforcement, raising fresh questions about privacy, accuracy, and the balance between security and civil liberties.

The order specifically calls for the deployment of what officials describe as flock-style camera networks. These systems consist of numerous fixed and mobile cameras that continuously capture images of faces in public spaces. Software then compares those images against databases containing millions of entries, including mugshots, driver’s license photos, and federal watch lists. According to reporting by The Verge, the governor’s instructions aim to create a statewide network that can alert authorities in real time when a match occurs. Abbott framed the initiative as a necessary step to combat rising crime rates and enhance public safety in urban areas where large gatherings occur frequently.

Supporters of the program argue that modern surveillance tools provide police with capabilities that were unimaginable just a decade ago. In cities like Houston and Dallas, where crowd sizes at sporting events, festivals, and political rallies can exceed tens of thousands, manual monitoring proves inadequate. Automated systems can scan thousands of faces per minute, potentially identifying suspects who might otherwise slip through traditional checkpoints. Law enforcement agencies in Texas have already experimented with similar technology on a smaller scale. The Houston Police Department, for instance, has used fixed cameras in high-crime neighborhoods to track repeat offenders. State officials believe scaling these efforts through a coordinated network will yield better results in locating missing persons, human trafficking victims, and individuals with outstanding warrants.

Critics, however, point to documented problems with facial recognition software, particularly when dealing with diverse populations. Multiple studies have shown that error rates tend to be higher for women, people with darker skin tones, and younger individuals. The American Civil Liberties Union has repeatedly warned that such disparities can lead to wrongful arrests and disproportionate targeting of minority communities. In Texas, where demographic diversity continues to grow, these concerns carry particular weight. Privacy advocates worry that once the infrastructure exists, mission creep could follow. Cameras installed for crime prevention might later monitor political protests or immigration checkpoints, expanding government oversight into areas protected by constitutional rights.

The technical foundation for this expansion draws from commercial providers that specialize in public safety analytics. Companies like Flock Safety, whose systems inspired the governor’s terminology, market cameras that combine high-resolution imaging with cloud-based matching algorithms. These devices do not require constant human monitoring. Instead, they operate autonomously, feeding data into secure servers where artificial intelligence performs the comparisons. When a potential match appears, human analysts review the alert before any action is taken. Proponents emphasize this human-in-the-loop approach as a safeguard against false positives. Nevertheless, the sheer volume of data generated by hundreds or thousands of cameras creates challenges for oversight. Even with review protocols in place, the risk remains that officers under pressure might act on preliminary matches without sufficient verification.

Implementation will require significant financial investment. The executive order directs state agencies to identify funding sources, which could include reallocating existing budgets or seeking federal grants. Local municipalities may also participate voluntarily, creating a patchwork of coverage across rural and urban regions. Rural areas with fewer cameras might experience lower match accuracy simply due to reduced data density, while dense metropolitan zones could generate thousands of daily alerts. Managing this information flow will demand new training programs for officers and analysts. The Texas Department of Public Safety has indicated it will develop guidelines for data retention, specifying how long images and match records remain stored. Clear policies on these matters will prove essential to maintaining public trust.

Legal scholars have begun examining whether the program complies with existing statutes governing surveillance. Texas law currently places few restrictions on government use of facial recognition in public spaces. Unlike some states that have enacted moratoriums or strict warrant requirements, Texas has moved in the opposite direction. In 2019, lawmakers passed measures encouraging the adoption of new technologies to fight human smuggling and drug trafficking along the southern border. The current executive order builds on that foundation, treating automated camera networks as logical extensions of border security efforts. Federal agencies, including Customs and Border Protection, already employ similar systems at ports of entry. Coordination between state and federal databases could further expand the reach of Texas’s network, allowing matches against national terrorist watch lists and immigration records.

Public reaction has been mixed. Polling conducted in major Texas cities shows that a majority of residents support using technology to catch violent criminals. Many cite personal experiences with property crime or concerns about retail theft rings that operate across county lines. At the same time, organized opposition has emerged from civil rights organizations, technology ethicists, and some local officials. The Texas chapter of the ACLU issued a statement expressing alarm at the lack of independent oversight mechanisms. They called for legislation requiring transparency reports, regular audits of system accuracy, and the ability for citizens to request their own facial data records. Without such measures, the group argues, the technology could erode the expectation of anonymity in public spaces that Americans have traditionally enjoyed.

Beyond immediate law enforcement applications, the expansion carries broader implications for how society views privacy in an age of ubiquitous cameras. Each additional lens added to streetlights, traffic signals, and utility poles reduces the zones where individuals can move without digital tracking. While many people already carry smartphones that broadcast their locations through apps and cellular networks, government-operated camera systems introduce a different level of centralized control. Data from these networks could theoretically be combined with license plate readers, cell phone tracking, and social media monitoring to create comprehensive movement profiles. Safeguarding such information against breaches or unauthorized access represents a persistent challenge for any large-scale deployment.

Advocates for the program maintain that careful design can mitigate many of these risks. They suggest implementing geographic limitations, time-based restrictions, and strict access controls. For example, cameras near schools or places of worship might operate under different protocols than those in downtown entertainment districts. Regular independent audits could measure demographic bias and overall accuracy, with results published for public review. Some experts recommend sunset clauses that would require legislative renewal after a set period, forcing policymakers to evaluate effectiveness before continuing the program. These types of guardrails, if enacted, might address the most pressing concerns while still allowing law enforcement to benefit from the technology.

The governor’s directive arrives at a moment when artificial intelligence tools for visual recognition continue to improve. Newer models trained on larger, more diverse datasets have shown better performance across demographic groups. However, even advanced systems struggle with certain conditions, such as low lighting, partial face coverings, or rapid movement within crowds. Texas officials acknowledge these limitations and plan to supplement automated alerts with traditional investigative methods. The goal is not to replace police work but to provide leads that investigators can then verify through fingerprints, witness statements, or other evidence.

As Texas proceeds with this initiative, other states will likely watch closely. California and Illinois have taken more restrictive approaches, limiting government use of facial recognition to specific circumstances with judicial approval. New York City has implemented detailed oversight boards that review proposed deployments. By contrast, Florida and several southeastern states have embraced broader adoption similar to Texas. The resulting patchwork of regulations creates a complex environment for both citizens and technology vendors. Companies must navigate varying compliance requirements depending on where they sell their products.

The debate in Texas also highlights larger tensions between security and freedom that have intensified since the rise of digital surveillance capabilities. After the September 11 attacks, many Americans accepted increased monitoring at airports and public buildings as a necessary trade-off. Two decades later, the conversation has shifted toward everyday public spaces where the cumulative effect of constant observation may subtly alter behavior. People might self-censor their movements or speech if they believe authorities are always watching. Social scientists refer to this phenomenon as the chilling effect, and measuring its extent in real communities remains difficult.

For now, the immediate focus rests on execution. State agencies must select vendors, install hardware, establish data centers, and train personnel. Pilot programs in select cities will likely precede full rollout, allowing officials to refine procedures based on early results. Community engagement efforts could help address public concerns before widespread deployment. Town hall meetings, educational campaigns, and partnerships with civil rights groups might build confidence that the systems will be used responsibly. Transparency about false positive rates and successful arrests could demonstrate tangible benefits while acknowledging the technology’s imperfections.

The path forward involves balancing genuine safety needs against legitimate worries about overreach. Facial recognition represents one tool among many in modern policing, and its effectiveness depends on integration with sound policies and ethical practices. Texas has chosen to move quickly in adopting the technology at scale. Whether this decision ultimately strengthens communities or strains public trust will depend on how thoughtfully the program is implemented and overseen in the months and years ahead. As the cameras begin appearing on more street corners, Texans will discover firsthand what living under an expanded digital watch means for daily life and civil liberties. The outcomes could influence similar decisions in other states for years to come.



from WebProNews https://ift.tt/VPSKmad

Sunday, 30 August 2026

Taco Bell Stages Dual Comebacks in UAE and China as Global Expansion Accelerates

Taco Bell left the United Arab Emirates in 2012. Fourteen years later the chain is heading back. The move comes at a moment when the Yum Brands subsidiary has set an ambitious target of 3,000 restaurants outside the United States by 2030. And it is not the only market seeing renewed attention.

Just days ago Yum China opened the first Taco Bell in Shanghai near the Oriental Pearl Tower in the Lujiazui financial district. The timing feels deliberate. While the brand retrenches in some Chinese cities after earlier overexpansion, corporate leaders signal fresh commitment to the world’s second-largest economy. The two returns, though separate, reveal a common thread. Success abroad demands more than shipping American menu favorites. It requires partners who understand local appetites, infrastructure and timing.

The UAE agreement pairs Taco Bell UK and Europe Ltd with Americana Restaurants. The operator already runs KFC and Pizza Hut locations across the Middle East and describes itself as the region’s largest quick-service player. Plans call for a first store in the UAE followed by phased entry into other Gulf Cooperation Council countries. “We’re excited to continue our strong international momentum in the UAE, to connect with a new generation of fans, and bring the creativity, innovation and unmistakable Taco Bell experience that only our brand can deliver,” Taco Bell CEO Sean Tresvant said in the announcement reported by Yahoo Finance.

Ankush Tuli, Taco Bell International managing director, sounded equally confident. “Their operational excellence and proven track record of driving growth give us great confidence as we grow Taco Bell in this vibrant market and build the brand for long-term success across the region.” The partnership builds on Americana’s long relationship with Yum Brands. That history reduces execution risk in a part of the world where Western fast-food brands sometimes stumble on labor, real estate or cultural fit.

Taco Bell now operates more than 9,000 restaurants in over 40 markets. Recent openings include the first Irish location inside an Applegreen petrol station last summer. The chain has also flagged interest in France, Greece, South Africa and several other countries. The broader push falls under the company’s R.I.N.G. strategy. Menu innovation, value offers, better customer experiences, digital ordering and international growth sit at its core. The Street reported the 2030 target and the list of priority markets on the same day the UAE news broke.

China tells a more complicated story. Taco Bell first tried the market in the early 2000s and failed. It returned in 2016 under Yum China’s stewardship with a localized menu that included rice bowls, seasoned chicken and items tuned to local spice preferences. Store count climbed above 100 by late 2023 before a sharp pullback. In 2024 the operator closed 31 locations, exited Guangdong province and shuttered several Shanghai outlets including one on Fengshengli road. By the middle of 2026 only around 30 Taco Bell restaurants remained on the mainland, according to Yum China’s investor materials.

Yet the brand refused to disappear. On August 28 Yum China and Taco Bell Corp opened a new flagship in Shanghai’s central business district. Micky Pant, then CEO of Yum China, struck an optimistic tone. “We are thrilled to bring Taco Bell to China with the official opening of the first restaurant at a spectacular location in Shanghai,” he said. “Consumers in China today want the best the world has to offer, and Taco Bell is one of the most exciting brands anywhere.” The executive highlighted nearly 30 years of local consumer knowledge, menu research and early positive feedback. Self-order kiosks and an open kitchen were part of the design meant to speed service and showcase freshness. The article appeared in Marketing-Interactive.

Pant also tied the effort to the “Live Mas” slogan. “Taco Bell is an innovative brand with a strong heritage that we believe will resonate well with Chinese millennials. Built around the concept of ‘Live Mas’ — literally meaning ‘Live More’ — Taco Bell encourages its customers to try things they’ve never tried before.” The message aims squarely at younger urban consumers who have grown up with greater exposure to international flavors yet still favor hot, melty textures and familiar proteins. Earlier attempts to sell straight American-style tacos met resistance. This time the chain appears determined to blend Mexican inspiration with Chinese expectations for warmth, value and convenience.

The Shanghai reopening coincides with other structural changes inside Yum China. In early August the company completed a $1.2 billion purchase of Pizza Hut’s mainland brand ownership from Yum Brands. The deal removes ongoing licensing fees and gives Yum China greater freedom to adjust pricing, real estate and marketing. Updated master license agreements for KFC and Taco Bell now include 12-year performance incentives tied to sales growth. Those legal moves, detailed in regulatory filings and covered by TradingView News, strengthen the operator’s hand as it balances a dominant KFC business with smaller, higher-risk concepts like Taco Bell.

Challenges remain. China’s quick-service sector faces intense competition, softening consumer spending and a preference for domestic or adapted brands. McDonald’s continues aggressive store growth there even as some American companies pull back. Yum China itself reported mixed quarterly results earlier this year. Still, the fast-food market in China is projected to keep expanding. Industry data cited in recent Chinese business reports put Western-style fast food sales above 500 billion yuan in 2025 with further gains expected. Taco Bell’s parent sees the country as one piece of a larger international puzzle rather than the sole growth engine it once represented.

Both the UAE return and the Shanghai flagship share a reliance on experienced local operators. Americana brings decades of Gulf experience. Yum China commands the largest restaurant network in its home market with more than 13,000 KFC stores alone. That infrastructure matters when supply chains must deliver consistent ingredients for items such as nacho cheese sauce or seasoned beef at scale. A job posting that appeared the same week as the Shanghai opening sought a food innovation manager in the city to refine products, secure local suppliers and keep the menu relevant. The role signals that menu work continues behind the scenes.

Executives avoid bold predictions. They speak instead of connecting with new generations, testing concepts and building for the long term. The phrase “unexpected market” has been attached to the UAE move because many observers had written off the country after the 2012 exit. Yet the decision looks less surprising when viewed alongside the 2030 target and recent entries into Ireland and other European markets. Growth abroad now accounts for a rising share of Yum Brands’ attention as the U.S. same-store sales environment stays competitive.

Whether these twin initiatives deliver depends on execution. Early customer reaction in Shanghai has been called encouraging, but sustained traffic, unit economics and same-store growth will decide the next wave of openings. In the UAE the first store has yet to open. Observers will watch whether the brand’s signature items translate to local tastes or require further tweaks. History shows that fast-food brands can return from absence. The harder task is staying relevant once the novelty fades. Taco Bell, its partners and its parent company are betting that careful adaptation, strong operators and a clear global ambition can make the difference this time.



from WebProNews https://ift.tt/PLqTBK0

Friday, 28 August 2026

Judge Slams Pentagon for Retaliating Against Anthropic Over AI Safety Stance

A federal judge delivered a sharp rebuke to the Pentagon on Thursday, ruling that its blacklisting of Anthropic amounted to unlawful retaliation for the AI company’s refusal to strip safety guardrails from its models. The decision hands a major victory to the San Francisco-based startup and sets a precedent for how far the government can go in pressuring private technology firms on national security matters.

U.S. District Judge Rita F. Lin didn’t mince words. In a detailed order, she found the Defense Department’s actions violated the First Amendment. They also ran afoul of Fifth Amendment due process protections. “The undisputed record shows that the challenged actions constituted unlawful retaliation in violation of the First Amendment, and that Anthropic was denied the pre-deprivation process required under the Fifth Amendment,” Lin wrote, according to Reuters.

The case traces back to tense contract talks earlier this year. Anthropic pushed for limits. Its Claude models could not assist with autonomous weapons or domestic surveillance. Pentagon officials pushed back hard. No private contractor should dictate terms to the military, they argued. Talks collapsed.

Defense Secretary Pete Hegseth then took an extraordinary step. He labeled Anthropic a “supply chain risk” to national security. The designation, typically reserved for foreign adversaries, effectively barred the company from military contracts and triggered broader restrictions across federal agencies. President Trump amplified the move with a public directive ordering every agency to stop using Anthropic’s technology immediately.

Anthropic sued. The company argued the label represented punishment for its public positions on responsible AI development. Not a genuine security assessment. Early rulings offered temporary relief. But the fight dragged on through appeals and parallel cases.

Thursday’s 59-page decision changes that. Lin vacated the supply chain risk designation. She ordered the Defense Department to rescind all related guidance, directives and instructions aimed at the company. The empty invocation of national security, she said, does not give officials a blank check to punish critics.

The First Amendment at the Heart of the Dispute

Evidence in the record painted a clear picture for the judge. Officials cited Anthropic’s “increasingly hostile manner through the press” and its criticism of the administration’s views on AI use. They claimed this made the company untrustworthy. Lin rejected that logic outright.

“Neither the Constitution nor the federal statute invoked by defendants allows them to impose sweeping penalties based principally on Anthropic’s critique of the Administration’s views,” she wrote, as reported by CNBC. The ruling draws a firm line. Government cannot wield procurement power to silence protected speech.

But the decision goes further. It highlights procedural failures. Anthropic received no meaningful chance to contest the designation before it took effect. That violated basic due process. And the designation itself, Lin determined, was arbitrary and capricious. It failed to follow the statutory scheme designed for genuine supply chain threats.

Anthropic welcomed the outcome. “We welcome the court’s ruling that this supply chain risk designation was unlawful. We remain focused on working productively with the government to harness AI for our national security so all Americans benefit from this technology,” a company spokesperson told CNBC.

The stakes run high. Executives had warned that the blacklist could cost billions in lost business and inflict lasting reputational damage. For a company valued at tens of billions and backed by Amazon and Google, exclusion from federal work represented an existential threat.

Yet the ruling arrives at a delicate moment. U.S. military leaders have emphasized the need for rapid AI integration. Ongoing conflicts and strategic competition with China add urgency. Some officials view strict corporate guardrails as obstacles to operational effectiveness. Others see them as essential safeguards against misuse.

This tension won’t vanish. The judge’s order blocks enforcement of the blacklist. It does not compel the Pentagon to adopt Claude or similar systems. Negotiations could resume. New contracts might emerge under different terms. Or the government could appeal and prolong the fight.

Legal observers note the decision’s broader implications. It marks the first prominent instance of a U.S. AI firm successfully challenging a national security designation on constitutional grounds. Previous supply chain risk actions targeted Chinese entities almost exclusively. Applying the label to an American company broke new ground. And courts appear unwilling to rubber-stamp such moves when evidence points to retaliation.

The original New York Times coverage detailed how the dispute escalated from contract language to presidential directive in a matter of days. Trump’s social media post set the tone. Hegseth’s order followed quickly. Federal agencies scrambled to comply, terminating pilots and shifting to alternative providers.

Industry reaction split along predictable lines. Defense contractors expressed concern about supply chain stability. AI safety advocates praised the stand against unchecked military applications. Venture investors watched closely. Any precedent that weakens government leverage over startups could reshape funding calculations in the sector.

Lin’s opinion repeatedly returns to the record. Internal communications, deposition testimony and public statements revealed the punitive intent. One passage stands out. The government essentially argued it could not trust a company that criticized its plans. The judge called that position incompatible with constitutional protections.

So what happens next? The administration has options. It could seek an emergency stay. It might narrow future designations to avoid similar challenges. Or it could pursue legislative changes that expand procurement authorities while limiting judicial review.

For Anthropic, the immediate path looks clearer. The company can bid on contracts again. Its models remain available to non-defense agencies that choose to use them. Reputationally, the vindication matters. A federal court declared the blacklist baseless and illegal.

Yet the episode exposes deeper fractures. How should AI developers balance commercial ambitions with ethical constraints? When does a safety policy cross into interference with military decision-making? These questions predated the lawsuit. They will outlast it.

Recent coverage from AP News on earlier stages of the case underscored the unusual nature of the designation. Rarely had such tools been turned against a domestic firm expressing policy disagreements. Lin’s preliminary injunction in March had already signaled skepticism. Thursday’s final ruling removes any doubt.

Analysts expect the decision to influence other tech-government tensions. Cloud providers, semiconductor makers and cybersecurity firms all navigate similar terrain. A ruling that prioritizes constitutional limits over national security assertions could embolden challenges elsewhere.

Short term, the Pentagon must unwind its directives. Agencies will review terminated relationships. Some may quietly restart work with Anthropic. Others will hesitate, waiting for appeals court guidance.

The company, meanwhile, signals openness. Its statement emphasizes partnership and shared goals for national security. Whether that olive branch gains traction depends on shifting political winds and operational needs.

One thing seems certain. This case will be cited for years. It stands as a reminder that even in matters of defense and technology, the Constitution retains force. Government power has boundaries. And courts will enforce them.

The dispute began over specific contract clauses. It evolved into a test of free speech principles applied to corporate expression. Lin’s opinion bridges those elements with careful analysis of the administrative record. Her conclusion? The actions cannot stand.



from WebProNews https://ift.tt/vHi82GC

Thursday, 27 August 2026

U.S. Dismantles Chinese Contractor’s Global Hacking Network That Hit NASA, Federal Reserve and Senate

The Justice Department and FBI moved swiftly on August 26 to seize key internet domains. They targeted two platforms that had quietly powered years of intrusions into some of the most sensitive corners of the U.S. government.

QScan and QTRouter. Those names now mark another chapter in the shadow war between Washington and Beijing. Court documents describe a China-based outfit called Nanjing Xinjiuwei Network Technology Company. It employed a state-sponsored group known as QTFY. The firm sold hacking services to China’s Ministry of State Security and the People’s Liberation Army.

The operation didn’t rely on flashy zero-days alone. It built scale through compromise of thousands of internet-of-things devices worldwide. QScan scanned networks and infected those devices automatically. They fed into QTRouter. That network combined the hijacked gadgets with commercial proxies and leased servers. The setup created an obfuscation layer. Malicious traffic appeared to come from outside China. Sometimes it looked local to the victim network itself. Hard to trace. Easy to deny.

“Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure,” said FBI Director Kash Patel in the Justice Department announcement. “These tools were used by PRC cyber actors to hide the origin of their attacks.”

The list of victims reads like a who’s who of American power centers. NASA. The Federal Reserve. The Justice Department itself. The U.S. Senate. The Department of Energy. Health and Human Services. The National Institutes of Health. Three unnamed Department of Energy national laboratories also took hits. Four private companies in the United States and South Korea. Activity stretched back to at least 2018. Some breaches succeeded. Others stayed at the targeting stage. The affidavit makes clear the infrastructure supported espionage against critical systems.

But this wasn’t a one-off strike. It fits a pattern. U.S. authorities have repeatedly dismantled Chinese-linked botnets and malware networks. In 2025 the FBI scrubbed PlugX surveillance malware from more than 4,000 American machines compromised by the Mustang Panda group. The year before it took down a massive botnet run by Flax Typhoon. That one fed hundreds of thousands of infected IoT devices straight to Chinese government customers. In 2023 authorities disrupted yet another Volt Typhoon botnet used to mask operations against critical infrastructure at home and abroad.

The Wall Street Journal reported that the network hid within normal internet traffic. It spread across hacked devices, cloud resources and even clandestine networks designed to circumvent China’s own Great Firewall. The objective was simple and effective. Blend in. Make attribution a nightmare.

Private contractors have become central to Beijing’s approach. “Over the last decade, the number of companies offering niche offensive services has exploded,” Dakota Cary, a China analyst with SentinelOne, told Reuters. Beijing routinely denies responsibility for such activity. The Chinese Embassy in Washington did not respond to requests for comment.

Alongside the seizures the FBI and National Security Agency released a cybersecurity advisory. It details indicators of compromise drawn from QTFY activity since 2018. Lumen Technologies’ Black Lotus Labs team published its own analysis of the group’s tactics, techniques and procedures. The message to network defenders is clear. Check your IoT devices. Review proxy configurations. Hunt for the specific domains now neutralized.

Yet the victory comes with caveats. These platforms are tools. The actors behind them can rebuild. They have for years. The contractor model gives the Chinese government distance and scale. QTFY didn’t just serve one master. It operated like a quartermaster. Supplying reconnaissance, routing and concealment services to multiple arms of the state.

And the targets matter. NASA holds aerospace secrets. The Federal Reserve manages the world’s reserve currency. The Senate shapes policy. Energy labs guard nuclear and grid knowledge. Health agencies manage sensitive research. Each breach, even partial, feeds a vast intelligence appetite.

U.S. officials cast the action as offensive defense. “Federal law enforcement investigated and disabled the PRC’s malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China,” Attorney General Todd Blanche said in the Justice Department statement.

Assistant Attorney General for National Security John A. Eisenberg emphasized the shift. The department is going on the offensive against threats to national security. Seizures deny access to the very infrastructure the hackers need.

So what comes next? The advisory gives organizations a fighting chance to evict lingering intruders. But history suggests persistence. Chinese groups have adapted after previous takedowns. They rotate infrastructure. They refine malware. They deepen ties with contractors who treat cyber operations as a service.

This time the infrastructure was hard-coded. Domains were baked into the malware for command, control and authentication. That dependency proved fatal once seized. Future campaigns may avoid such single points of failure. The cat-and-mouse game continues.

Still, the operation sends a signal. The FBI’s San Diego field office, its Cyber Division and Justice Department partners executed a precise strike. They combined investigation, technical disruption and international coordination. President Trump’s cyber strategy gets another data point. Shape adversary behavior. Defend the homeland in cyberspace. Disrupt early and often.

Private sector threat intelligence teams will pore over the new indicators. Boards will ask hard questions about visibility into IoT fleets and proxy usage. Government agencies will accelerate hunts for remnants of QTFY activity. The breach list is long enough to demand attention.

Beijing’s hacking machine runs on volume and patience. Contractors like Nanjing Xinjiuwei provide the gears. Today’s action grinds some of those gears to a halt. But the machine has shown it can replace parts quickly. The real test will be whether this disruption forces meaningful change in how Chinese operators hide their tracks or whether it simply prompts a new set of domains and a fresh batch of compromised routers.

Either way, the public acknowledgment of victims at this level is rare. It underscores the breadth of exposure. From space exploration to monetary policy to legislative deliberations, few pillars of American power escaped scrutiny. That fact alone may spur faster hardening of systems that have too often treated such threats as theoretical.

The domains are seized. The platforms are inoperable. For now. The adversaries are already assessing their losses and plotting the next move. In cyberspace, victories are temporary. Preparation for the inevitable counter-move never stops.



from WebProNews https://ift.tt/3HF0P7h

Wednesday, 26 August 2026

Critical Gitea Vulnerability (CVE-2026-60004) Actively Exploited for Crypto Mining – Upgrade to 1.27.1 Now

A serious vulnerability in the popular self-hosted Git service Gitea has drawn urgent attention from security teams worldwide after federal authorities confirmed active exploitation in real-world attacks. The U.S. Cybersecurity and Infrastructure Security Agency added the flaw, tracked as CVE-2026-60004 and carrying a CVSS score of 9.8, to its Known Exploited Vulnerabilities catalog. This move signals that threat actors have already developed reliable methods to compromise exposed instances, making immediate patching a priority for any organization running the platform.

The vulnerability centers on the diffpatch endpoint, a component designed to handle repository patch operations. Researchers discovered that users with write access to a repository can manipulate this endpoint to create and install Git hooks that execute arbitrary commands on the underlying server. Because Gitea runs these hooks under the same service account that powers the application itself, successful exploitation grants attackers full control over the host system. In observed incidents, adversaries have used this access to deploy payloads that behave similarly to cryptocurrency miners, quietly consuming server resources while blending into normal system processes.

Gitea’s default configuration contributes significantly to the risk. The platform enables open user registration by default, allowing anyone to create an account and potentially gain write access to public repositories. Once an account is established, an attacker can create or fork a repository, push malicious changes that trigger the vulnerable diffpatch logic, and plant a post-receive or update hook containing shell commands. These hooks then execute automatically when the repository receives new commits, giving the attacker a persistent foothold without needing additional authentication.

SecurityWeek first reported on the active exploitation campaign, noting that multiple organizations had already detected suspicious activity tied to the vulnerability. In several cases, forensic analysis revealed mining software installed alongside modified configuration files intended to maintain persistence across restarts. The payloads observed so far appear focused on resource theft rather than data exfiltration or ransomware deployment, though experts warn that the same access could easily support more destructive objectives.

The vulnerability affects all versions of Gitea prior to 1.21.5, 1.22.4, and 1.23.0, with the most recent fix appearing in version 1.27.1 and later releases. Administrators running older branches should prioritize upgrades or implement temporary mitigations while planning their migration path. The Gitea project maintainers released patches that strengthen input validation on the diffpatch endpoint and restrict the locations where Git hooks can be written. They also added runtime checks to prevent execution of hooks originating from untrusted repository content.

Organizations that cannot upgrade immediately face limited defensive options. Disabling repository hooks entirely through configuration settings can reduce risk, though this approach breaks legitimate automation workflows that many development teams rely upon. Restricting user registration to approved domains or requiring administrator approval for new accounts can shrink the pool of potential attackers, yet these changes require careful planning to avoid disrupting collaborative environments. Network-level controls that limit access to Gitea instances to trusted IP ranges provide another layer of protection, particularly for servers exposed to the public internet.

The discovery of this flaw highlights ongoing challenges with Git hook mechanisms across multiple platforms. Similar issues have appeared in other version control systems over the years, often stemming from the inherent tension between powerful automation features and the need to contain untrusted code. Git itself allows hooks to run arbitrary executables, and when a web application like Gitea exposes control over hook content to external users, the attack surface expands dramatically.

Forensic evidence gathered from compromised systems shows that attackers typically follow a predictable sequence. After gaining initial code execution through the hook, they download additional payloads from command-and-control servers hosted on bulletproof hosting providers. These secondary stages often include process hollowing techniques to hide mining activity within legitimate system binaries. Some campaigns also install rootkits or modify scheduled tasks to ensure the miner survives reboots and software updates.

The The Hacker News coverage of the incident emphasized that the vulnerability’s high severity stems not only from its technical impact but also from the ease with which attackers can obtain the necessary repository access. In many observed cases, threat actors simply signed up for accounts on public Gitea instances, created throwaway repositories, and triggered the exploit within minutes. This low barrier to entry explains why exploitation appeared so quickly after the vulnerability’s public disclosure.

Security researchers have published proof-of-concept code demonstrating the attack, though they deliberately omitted certain details to slow widespread adoption by less sophisticated threat actors. Even so, multiple independent groups have reverse-engineered the missing pieces, leading to several exploit repositories appearing on public code-sharing platforms. This rapid dissemination underscores the need for organizations to treat the vulnerability as an immediate threat rather than a theoretical concern.

Beyond the technical mechanics, the incident raises questions about supply chain risks associated with self-hosted development tools. Many organizations deploy Gitea as part of larger continuous integration and continuous deployment pipelines. A compromised Gitea server can therefore serve as a pivot point to attack build servers, artifact repositories, or even production infrastructure. Attackers who gain control of a Gitea instance might modify source code undetected, inject backdoors into compiled binaries, or steal credentials stored in repository secrets.

Administrators should conduct thorough audits of their Gitea deployments. Key steps include reviewing all installed hooks across every repository, scanning for unexpected processes consuming high CPU resources, and examining network logs for outbound connections to unfamiliar domains. Tools that monitor file integrity on the Gitea host can help detect unauthorized changes to hook directories or configuration files. Because the service account often possesses broad permissions, investigators should also check for new user accounts, modified sudoers files, or unexpected SSH keys.

The addition of CVE-2026-60004 to the CISA KEV catalog carries regulatory implications for federal agencies and contractors. Organizations subject to binding operational directives must apply the available patches or implement approved mitigations within a specified timeframe. Even private sector entities without formal compliance obligations benefit from following CISA’s guidance, as the catalog serves as a reliable indicator of threats currently targeting production environments.

Gitea’s popularity has grown steadily as teams seek alternatives to larger commercial platforms. Its lightweight design, open-source licensing, and straightforward installation process make it attractive for both small projects and enterprise deployments. Unfortunately, this widespread adoption also increases the number of potential targets. Attackers have demonstrated they can scan the internet for exposed Gitea instances using simple fingerprinting techniques based on default login pages or API response headers.

Looking forward, the Gitea project has signaled plans to implement more granular permission models around hook management. Future releases may separate the privileges required to edit repository content from those needed to modify executable hooks. Such architectural changes could prevent entire classes of attacks while preserving the platform’s automation capabilities. In the meantime, administrators are encouraged to subscribe to the project’s security mailing list and monitor official release notes for additional hardening measures.

The observed mining payloads, while not particularly sophisticated, reveal a clear economic motive. Cryptocurrency mining allows attackers to monetize compromised infrastructure with minimal interaction after the initial breach. Because many Gitea servers run on powerful hardware optimized for compilation tasks, they provide ideal targets for CPU-intensive mining operations. Some victims have reported monthly electricity costs increasing by thousands of dollars before the compromise was discovered.

Security teams recommend treating all self-hosted Git services with the same caution applied to other internet-facing applications. Regular vulnerability scanning, automated patch management, and network segmentation can reduce exposure. Where possible, organizations should consider containerizing Gitea deployments to limit the blast radius of a successful compromise. Running the service under a dedicated low-privilege user and applying strict file system permissions further constrains what an attacker can achieve.

As exploitation continues, security vendors have begun releasing updated detection signatures for common mining tools and anomalous hook execution patterns. Endpoint detection and response platforms can alert on processes spawned from within the Gitea data directory, especially when those processes exhibit network activity associated with mining pools. Web application firewalls may also block malicious requests to the diffpatch endpoint if properly tuned to recognize exploit patterns.

The speed with which this vulnerability moved from disclosure to active exploitation serves as a reminder that modern threat actors monitor security research closely. Proof-of-concept code that appears in academic papers or conference presentations often becomes weaponized within days. Organizations cannot afford to delay remediation while waiting for more detailed technical analysis or vendor guidance.

Administrators running Gitea in air-gapped environments should still apply patches as soon as possible, since insider threats or compromised developer workstations could introduce the exploit through internal repositories. The requirement for repository write access does not necessarily mean the attacker must come from outside the organization. A compromised developer account or stolen credentials could provide the same level of access.

The broader lesson from this incident involves maintaining visibility into all development infrastructure. Many security programs focus heavily on production applications while treating internal tools as lower risk. Yet these internal systems frequently hold privileged credentials, access to source code, and direct pathways into build pipelines. A single vulnerable component like an outdated Gitea instance can undermine otherwise strong perimeter defenses.

Teams should also evaluate whether their current Git platform still meets security requirements. Some organizations have begun migrating to solutions with stronger default configurations and more sophisticated access controls. Others have implemented additional monitoring layers specifically tailored to version control systems, watching for unusual repository creation patterns or sudden spikes in hook execution.

Despite the urgency surrounding this particular vulnerability, experts stress that Gitea remains a capable and widely used platform when properly maintained. The project has demonstrated a commitment to rapid remediation once issues surface, and the latest versions incorporate multiple improvements beyond the immediate CVE-2026-60004 fix. Organizations that upgrade promptly and adopt recommended security practices can continue using the software with reduced risk.

The active exploitation of this remote code execution flaw in Gitea illustrates how quickly a seemingly specialized vulnerability can impact a diverse range of organizations. From individual developers running personal instances to large enterprises managing thousands of repositories, anyone exposing Gitea to untrusted users must act decisively. The combination of easy account creation, powerful hook functionality, and a critical flaw in patch handling has created conditions that attackers have already begun to exploit at scale. Prompt upgrades to version 1.27.1 or newer, combined with thoughtful configuration changes, represent the most effective path toward restoring secure operations.



from WebProNews https://ift.tt/bSv79hf