Sunday, 6 September 2026

Equinix Launches Fabric One: Intent-Based Networking for AI and Cloud Connectivity

Equinix has introduced Equinix Fabric One, a networking service designed to create direct, intent-based connections between enterprise locations, cloud providers, and specialized artificial intelligence infrastructure. Announced on September 2, the offering aims to simplify how organizations link their distributed assets without relying on traditional routing complexities or additional data center regions. The full details appear in the official announcement from Equinix Investor Relations.

At its core, Equinix Fabric One functions as a unified control mechanism for what the company describes as a distributed edge environment. Rather than treating each new cloud region or AI training cluster as an isolated extension that requires separate networking overlays, the platform treats the network itself as the central intelligence layer. This approach allows enterprises to establish any-to-any connectivity across thousands of locations with a single policy framework. Customers define their desired outcomes in plain language terms, such as “connect my European headquarters to this specific AWS workload with encrypted low-latency paths,” and the system translates those instructions into the necessary configurations across physical and virtual infrastructure.

The timing of the launch aligns with growing enterprise demand for direct access to both public cloud platforms and specialized AI compute resources. Major providers including Amazon Web Services and Google Cloud have collaborated on open interconnect specifications that Equinix Fabric One incorporates. These specifications standardize how traffic moves between on-premises systems and hyperscale environments, reducing the friction that often appears when organizations attempt to move large datasets or establish real-time analytics pipelines. By embedding support for these open standards, Equinix positions its platform as a neutral intermediary that works across competing cloud vendors without forcing customers into proprietary lock-in.

One practical outcome of this design is the ability to treat AI-specific sites as first-class participants in the corporate network. Training clusters and inference endpoints often reside in facilities optimized for high power density and specialized cooling, locations that do not always overlap with traditional enterprise colocation footprints. Equinix Fabric One creates virtual circuits that span these disparate environments while maintaining consistent security policies, quality-of-service guarantees, and visibility. Network engineers can apply the same access controls to an AI workload in an Equinix data center as they would to a branch office or a virtual private cloud instance.

The control plane emphasis reflects a broader shift in how enterprises think about infrastructure. Historically, organizations expanded their presence by adding new regions or availability zones, each requiring its own routing tables, firewall rules, and monitoring dashboards. This proliferation of management domains increased operational overhead and created opportunities for configuration errors. By making the network the authoritative control point, Equinix Fabric One centralizes policy definition while distributing actual packet forwarding across a global mesh of points of presence. Changes propagate through automated orchestration rather than manual updates at each site.

Performance characteristics receive particular attention in the announcement. The platform promises sub-millisecond latency increments between connected parties when they share the same metro area, and predictable performance even when traffic crosses continents. Such consistency matters for distributed AI applications that require synchronized model updates or real-time decision making across multiple geographies. Financial services firms running algorithmic trading models, healthcare organizations processing medical imaging at scale, and manufacturers coordinating digital twins can all benefit from these performance assurances.

Security forms another foundational element. Equinix Fabric One integrates zero-trust principles directly into the connection lifecycle. Every virtual circuit undergoes continuous validation against defined policies, and traffic flows through encrypted tunnels by default. The system also provides granular visibility into data movement patterns, helping compliance teams demonstrate adherence to regulations that govern cross-border transfers or industry-specific data handling requirements. Because the service operates at Layer 2 and Layer 3 simultaneously, organizations can choose the appropriate abstraction level without sacrificing visibility or control.

Integration with existing toolchains received focus during development. The platform offers application programming interfaces that align with popular infrastructure-as-code frameworks, allowing network policies to be stored in version control systems alongside application code. This alignment supports continuous integration and continuous deployment practices that many software teams already follow. Terraform providers, Ansible collections, and Python libraries simplify incorporation into automated workflows. For teams that prefer graphical interfaces, a redesigned console presents connection options in context-aware menus that reflect current inventory of clouds, private locations, and AI facilities.

The open interconnect specifications developed with AWS and Google Cloud represent more than technical agreements. They establish common methods for requesting, provisioning, and monitoring direct connections that bypass the public internet. Enterprises gain the ability to create private links that maintain cloud-native billing models while enjoying the performance and security characteristics of dedicated circuits. This combination addresses a long-standing tension between the flexibility of public cloud consumption and the predictability that regulated industries require.

Equinix built the service on its existing global footprint of more than 250 data centers and interconnection points. This physical foundation gives Fabric One immediate reach without depending on third-party transport providers for last-mile connectivity in most major markets. Customers already present in Equinix facilities can activate new connections with minimal lead time, often within minutes once their intent has been expressed through the management portal. For organizations just beginning their colocation journey, the platform includes guided onboarding that maps current network architecture to recommended Fabric One configurations.

Early adopters report simplified architectures after migration. One global retailer consolidated more than forty distinct virtual private network tunnels into a handful of Fabric One policies that automatically adjust as new stores and distribution centers come online. A financial institution replaced multiple direct connects to different cloud providers with a single logical fabric that enforces uniform encryption and logging standards. These examples illustrate how intent-based networking can reduce both capital expenses related to dedicated hardware and operational expenses tied to ongoing configuration management.

The distinction between Equinix Fabric One and traditional software-defined wide area network solutions lies in its focus on data center interconnection rather than branch-to-headquarters traffic. While SD-WAN appliances optimize last-mile links to remote offices, Fabric One concentrates on the high-bandwidth, low-latency paths required between enterprise cores, cloud regions, and AI compute clusters. The two approaches complement rather than compete with each other. Many customers will likely deploy both technologies, using SD-WAN for user access and Fabric One for backend data exchange.

Artificial intelligence workloads introduce unique networking demands that conventional architectures struggle to meet. Training large language models can require simultaneous access to petabytes of data distributed across multiple storage systems. Inference services must maintain consistent response times even when models are updated dynamically. Equinix Fabric One addresses these requirements by allowing dynamic bandwidth allocation and automatic path optimization based on real-time telemetry. If a particular link experiences congestion, the system can reroute flows to alternate paths while preserving the original intent parameters.

The platform also supports hybrid deployments where sensitive models remain on-premises while less critical components run in public clouds. Security teams define which data elements can traverse specific circuits, and the network enforces those rules at line rate. This capability helps organizations balance innovation speed with governance requirements, particularly in sectors such as banking, insurance, and life sciences where data sovereignty rules apply.

Looking forward, Equinix plans to expand the range of supported AI-specific locations and to deepen integration with additional cloud providers. The company has indicated that future releases will incorporate more sophisticated intent expressions, potentially allowing business users to request connections using natural language that gets translated into technical policies. Such advancements could further reduce the specialized networking expertise required to maintain complex distributed environments.

The introduction of Equinix Fabric One signals a maturing market for interconnection services. As enterprises distribute their workloads across more locations and more specialized facilities, the network that binds those locations together becomes the element that determines overall system performance and operational simplicity. By positioning the network as the control plane rather than an afterthought, Equinix offers a different architectural philosophy that prioritizes consistency, automation, and intent over manual configuration at each endpoint.

Organizations evaluating their digital infrastructure strategies now have another option to consider when planning how to connect their growing collection of enterprise systems, cloud resources, and AI capabilities. The combination of open standards, global reach, and policy-driven automation provides a foundation that can scale as artificial intelligence adoption accelerates and distributed computing becomes the default operational model. Whether the goal is faster model training, more responsive customer experiences, or simply more manageable network operations, Equinix Fabric One presents a comprehensive approach to modern interconnection requirements.



from WebProNews https://ift.tt/Oau0iCx

Nvidia Releases Free Tool to Turn Idle GPUs into Private AI Clusters

Nvidia has introduced a new software tool that allows users to combine the processing power of multiple idle computers into a single, private artificial intelligence computing cluster. Announced on September 3, the offering targets individuals and small teams who want to run large language models locally without sending sensitive data to commercial cloud services. According to a report from The Verge, the solution emphasizes simplicity, security through mutual TLS authentication, and complete retention of tokens and data on the owner’s own hardware.

The software, currently available at no cost, works by turning ordinary machines equipped with compatible GPUs into nodes that can be linked together over a local network. A primary device, often a laptop or desktop with an Nvidia RTX graphics card, acts as the coordinator. It discovers other systems on the same network, pairs with them using encrypted certificates, and distributes inference or fine-tuning workloads across all available processors. Because the pairing relies on mTLS, each machine verifies the identity of every other participant before any data moves. This approach prevents unauthorized devices from joining the group and keeps all model weights, prompts, and generated outputs inside the user’s physical premises.

Compatibility extends beyond Windows PCs. The tool also supports Apple silicon Macs through a dedicated bridge layer that translates requests to Metal Performance Shaders. Users with a mix of desktop workstations, older gaming laptops, and recent MacBooks can therefore contribute their spare cycles without replacing any existing software or drivers. The announcement highlights that no modifications to the underlying AI frameworks are required. Popular inference engines such as Ollama, LM Studio, and Hugging Face Text Generation Inference continue to operate exactly as before. The new layer sits underneath these applications and quietly spreads computation when extra capacity is detected.

Performance gains become noticeable once two or more machines join the cluster. A single RTX 4090 can handle a 70-billion-parameter model at modest speeds, but adding a second RTX 3090 or even a Mac Studio with M2 Ultra roughly doubles throughput for batch processing. Larger clusters, perhaps four or five consumer-grade systems, allow comfortable interaction with 405-billion-parameter models that would otherwise demand enterprise hardware. Because the software balances load at the tensor level rather than the full model level, it avoids the memory duplication problems that plagued earlier distributed inference attempts. Each node loads only the slices of the model it will compute, reducing overall RAM and VRAM requirements.

Privacy remains a central selling point. Many organizations hesitate to upload proprietary documents or customer information to services hosted by OpenAI, Anthropic, or Google. By keeping every token inside the local cluster, companies can experiment with generative AI without triggering compliance reviews or data residency clauses. Individual users who worry about chat histories being stored indefinitely in the cloud also benefit. The system logs nothing outside the chosen devices, and all communication occurs over encrypted local links. Even if one computer is compromised, the mTLS certificates limit lateral movement because each node only accepts traffic signed by the cluster’s root authority.

Installation follows a straightforward process. Users download a small daemon from Nvidia’s developer portal and run it on every machine they intend to include. The first device generates a root certificate that must be copied to the others, after which automatic discovery takes over. A simple dashboard, accessible from any browser on the local network, shows real-time utilization graphs, temperature readings, and estimated tokens per second for the combined pool. Administrators can set policies that restrict certain models to specific hardware or schedule heavy jobs for overnight hours when electricity rates drop and machines would otherwise sit idle.

Energy efficiency receives attention as well. Modern GPUs consume substantial power even at idle, but the software includes an optional low-power mode that parks unused nodes until a request arrives. When a user opens a chat interface on their laptop, the cluster wakes only the necessary cards, processes the query, then returns to sleep. Tests reported by early adopters suggest that a four-node setup can remain responsive while drawing less continuous wattage than a single high-end server running 24 hours a day.

Developers working on specialized models also stand to gain. Rather than renting GPU instances by the hour, a researcher can fine-tune a domain-specific model across their own equipment and iterate quickly without cloud bills. The tool exposes a standard API endpoint that mirrors the OpenAI chat completions format, so existing applications require only a change of base URL. This compatibility means that internal tools built for commercial large language models can point at the local cluster with minimal rewriting.

Nvidia positions the software as an extension of its broader RTX ecosystem. Owners of GeForce cards already enjoy hardware-accelerated ray tracing, AI denoising in creative applications, and broadcast features. The new clustering capability adds another practical use for the same silicon. Because the software runs on consumer drivers rather than the datacenter-grade CUDA-X stack, it avoids the licensing costs associated with professional visualization or high-performance computing products. This decision broadens the potential audience to hobbyists, independent consultants, and small businesses that could never justify an HGX server.

Early feedback from the developer community points to several strengths. The pairing ceremony, while requiring an initial manual certificate exchange, feels less intimidating than configuring Kubernetes or Slurm clusters. Error messages clearly indicate whether a node dropped out because of network instability or because its GPU ran out of memory. Automatic checkpointing ensures that a long training run can resume even if one machine temporarily disconnects. These details suggest that Nvidia learned from previous attempts at consumer-scale distributed computing and focused on reliability rather than raw theoretical speed.

Limitations still exist. The current version works best on machines connected by wired Gigabit Ethernet or faster. Wi-Fi can introduce latency spikes that degrade token generation quality, especially for conversational models that expect sub-second responses. Users with many nodes may need to invest in a managed switch and structured cabling to achieve consistent performance. Additionally, the software does not yet support model training across heterogeneous GPU architectures. An RTX 3060 and an M3 Max GPU cannot currently cooperate on the same training pass, although inference across such mixed hardware already functions.

Future updates are expected to address some of these constraints. Nvidia has hinted at adding support for AMD and Intel GPUs through open standards such as Vulkan and oneAPI, though no timeline has been confirmed. Integration with container runtimes could allow teams to spin up isolated environments for different projects without interfering with one another. The company also plans to publish reference designs for rack-mounted “home AI servers” built from off-the-shelf components, complete with redundant power supplies and efficient cooling tailored to continuous 24/7 operation.

For many users, the most immediate benefit is the ability to experiment without financial risk. Running a 13-billion-parameter model locally has become relatively common, but moving to frontier-class models required either expensive monthly subscriptions or significant capital outlays. By pooling existing hardware, the barrier drops dramatically. A creative agency with five employee laptops can, during off hours, combine their GPUs into a resource comparable to a single A100 server while keeping client storyboards and brand voice training data entirely private.

Security-conscious organizations are already exploring deployment in air-gapped environments. Government contractors, legal firms, and medical practices often operate isolated networks where external API calls are prohibited. The new tool offers them a path to adopt generative AI without violating strict data handling policies. Because the software itself contains no telemetry and does not phone home, it satisfies many procurement checklists that would flag cloud-dependent solutions.

Documentation provided alongside the download includes step-by-step guides for common scenarios: linking two laptops for mobile use, building a permanent cluster in a basement office, and configuring the system to wake on LAN so that a phone app can trigger large batch jobs remotely. Sample scripts demonstrate how to expose the cluster through a reverse proxy with additional authentication for family members or colleagues. These resources lower the technical threshold and encourage broader adoption beyond the usual enthusiast crowd.

As more users begin to combine their idle computers, new use cases continue to surface. One hobbyist trained a custom voice synthesis model for audiobook narration by distributing the workload across three desktops and a laptop. Another group of students built a shared research cluster that lets each member run overnight experiments without paying for cloud credits. In both stories, the decisive factor was the tool’s ability to operate without constant supervision and without exposing data to third parties.

Nvidia’s decision to release the software at no cost signals confidence that the real revenue will come from accelerated hardware sales. As clusters grow, participants often discover that one or two faster GPUs would dramatically improve response times. The company expects many users to upgrade their oldest cards first, then gradually modernize the rest of the fleet. In this way the free tool serves as both a practical utility and a gentle introduction to the economics of local AI infrastructure.

The arrival of this personal-scale computing option arrives at a moment when interest in running models locally has reached new heights. Privacy scandals, unexpected content filters, and fluctuating API pricing have convinced a sizable audience that self-hosted solutions offer greater long-term control. By removing the complexity that once made distributed inference accessible only to specialists, Nvidia has opened the door for a wider range of people and organizations to build their own private AI data centers from hardware they already own. The combination of strong encryption, straightforward management, and broad application compatibility positions the tool as a practical answer to a growing demand for trustworthy, on-premises intelligence.



from WebProNews https://ift.tt/FI0jGlo

OpenAI Launches GPT-6 Astra: Major Upgrades for ChatGPT and Codex

OpenAI has rolled out a significant update to its core AI systems, introducing GPT-6 Astra as the foundation for enhanced versions of ChatGPT and the Codex coding assistant. The new model brings measurable improvements in reasoning depth, context retention, and specialized performance across both conversational and programming tasks. Users with Plus, Pro, or Business subscriptions can access Astra immediately through the standard ChatGPT interface, while Codex receives its own targeted refinements aimed at developers who rely on long-form coding sessions.

The Astra architecture represents a step forward from GPT-4o and the earlier o1 reasoning series. According to the details shared in the 9to5Mac report, the model was trained on a mixture of synthetic data generated by previous reasoning models and carefully curated real-world examples. This combination appears to have produced stronger performance on complex multi-step problems without sacrificing speed in everyday interactions. Early benchmarks shared by OpenAI suggest Astra outperforms its predecessor by roughly 18 percent on graduate-level science questions and shows even larger gains on tasks that require maintaining coherence across thousands of tokens.

One of the most visible changes for regular ChatGPT users is the way the model handles extended conversations. Previous versions sometimes lost track of details mentioned dozens of messages earlier, especially when users switched between topics or asked the AI to recall specific facts from the start of a thread. Astra maintains a more stable internal representation of the entire dialogue history. The result is fewer instances where the model contradicts something it stated earlier or asks users to repeat information already provided. In practice, this means project planning sessions, creative writing collaborations, and detailed research discussions can continue for hours with less repetition and fewer corrective prompts.

The upgrade also affects how ChatGPT processes uploaded files. Documents, spreadsheets, and code repositories can now be analyzed with greater accuracy across their full length rather than being compressed into a single summary. The 9to5Mac article highlights that this change particularly benefits users working with technical manuals, legal contracts, or large datasets. Instead of receiving generic overviews, subscribers report that Astra can answer precise questions about content buried on page 47 of a 120-page PDF while still connecting that information to concepts introduced in the first chapter.

Codex, the programming-focused variant of the model, receives its own set of improvements under the Astra umbrella. The most substantial change involves context window management during long development sessions. Earlier Codex versions tended to collapse extended codebases into a single high-level summary after a certain number of interactions, which often led to suggestions that ignored important architectural decisions made earlier in the project. The updated system keeps a more structured memory of the entire repository state, including variable naming conventions, chosen frameworks, and previously discussed requirements.

Developers testing the new Codex report that it can now maintain awareness of custom functions defined hundreds of lines earlier without being reminded. When asked to add a new feature, the model more consistently respects existing patterns for error handling, logging, and testing rather than introducing conflicting styles. The 9to5Mac coverage notes that this improvement stems from better training on actual software engineering workflows rather than isolated coding problems. OpenAI apparently used anonymized data from consenting developers to teach the model how real projects evolve over days or weeks of iterative changes.

Performance on specific coding languages has also shifted. Python, TypeScript, and Rust see the largest gains according to community feedback, with fewer syntax errors in generated code and more accurate implementation of complex algorithms. The model appears better at recognizing when a requested change would break existing functionality and will often suggest appropriate adjustments to related modules. For teams using the Business tier, these enhancements arrive with additional administrative controls that let IT managers set boundaries on which repositories can be analyzed and what types of code the model is allowed to generate.

Beyond raw capability, the release includes several user-facing refinements. Voice conversations with ChatGPT feel more natural because Astra responds with less latency while preserving emotional tone and conversational rhythm. The model can now detect when a user is becoming frustrated and adjust its explanations accordingly, offering simpler breakdowns or additional examples without being explicitly asked. Image analysis has been expanded so that Astra can interpret charts, diagrams, and handwritten notes with higher precision, making it more useful for students and professionals who work with visual data.

OpenAI has also adjusted the way it presents confidence levels. Rather than simply stating that it is sure or unsure about an answer, Astra now provides brief explanations for why it considers certain information reliable or speculative. This change helps users calibrate their trust in the output, especially on technical or scientific topics where small inaccuracies can have large consequences. The 9to5Mac piece mentions that this transparency feature was developed partly in response to educator feedback about students over-relying on AI answers without understanding their limitations.

Privacy considerations received attention in this release as well. Astra processes more of its reasoning steps on-device for Plus subscribers when possible, reducing the amount of conversation data sent to OpenAI servers. Business customers gain additional options for private instances that keep all data within their own virtual private cloud. These measures address growing concerns about sensitive information being used to train future models, although the default behavior still contributes to OpenAI’s broader data collection unless users opt out.

The timing of the Astra launch coincides with increased competition from other AI companies releasing their own large language models. Anthropic, Google, and several open-source efforts have introduced competitive offerings in recent months, each claiming advantages in specific areas such as mathematical reasoning or creative writing. OpenAI’s decision to focus on context stability and coding endurance seems aimed at professionals who spend many hours per week inside ChatGPT rather than casual users looking for quick answers.

Early adoption data shared in the 9to5Mac report suggests that developers have been the quickest to embrace the new Codex capabilities. Within the first 48 hours of availability, API usage for coding-related endpoints increased by more than 40 percent among Pro subscribers. Many reported being able to complete tasks that previously required switching between multiple tools or consulting human colleagues for architectural guidance. Teachers and researchers have also noted improvements when using Astra to analyze academic papers or prepare lesson plans that reference multiple sources.

Despite the advances, some limitations remain. The model still occasionally hallucinates details when dealing with very recent events not present in its training data. Complex mathematical proofs can still contain subtle errors that require human verification. And while context retention has improved dramatically, extremely long sessions exceeding 100,000 tokens can still show gradual degradation if the conversation jumps between unrelated subjects without clear transitions.

OpenAI has indicated that Astra serves as the base for several upcoming specialized models planned for release before the end of the year. These include versions fine-tuned for medical research, legal analysis, and creative industries. Each specialized model will build upon the core reasoning and memory improvements introduced in this release, allowing the company to iterate faster than if every new capability required a completely new foundation.

For individual users, the practical impact of Astra depends heavily on how they interact with ChatGPT. Casual users may notice mainly faster responses and more coherent multi-turn conversations. Power users who maintain long-running projects inside the platform will likely experience the most significant productivity gains. The updated Codex, in particular, could change how many solo developers and small teams approach software creation by reducing the cognitive load of remembering every previous decision.

Companies considering enterprise adoption will want to evaluate not just the raw capabilities but also the administrative features included with Business subscriptions. These include usage analytics, content filtering options, and integration hooks that allow Astra to interact with internal knowledge bases. Organizations with strict compliance requirements will appreciate the ability to run the model in isolated environments that prevent data from leaving company networks.

The release also reflects OpenAI’s shifting priorities toward practical utility rather than raw scale. While the company continues to train ever-larger models, the emphasis in Astra appears to be on making existing scale work more effectively for real tasks. Better memory systems, improved reasoning transparency, and domain-specific refinements may deliver more immediate value to users than simply adding more parameters.

As more people experiment with the new system, patterns of usage will likely emerge that OpenAI can study for future improvements. The company has historically adjusted its roadmap based on how subscribers actually use new features rather than sticking strictly to pre-release plans. This iterative approach has helped ChatGPT remain relevant even as competitors introduce their own innovations.

Users wanting to try Astra should ensure their subscription is active, then look for the model selector in ChatGPT settings. The option labeled GPT-6 Astra should appear for eligible accounts. New conversations will automatically use the updated model, though users can switch back to previous versions if they encounter unexpected behavior during the transition period. Codex users will find the improvements enabled by default in the dedicated coding interface.

The introduction of GPT-6 Astra marks another chapter in the steady progress of large language models toward more reliable and useful assistants. While the technology continues to face challenges around accuracy, bias, and appropriate use, the specific enhancements to context handling and coding assistance address genuine pain points that many users have experienced. As the model sees wider adoption across Plus, Pro, and Business tiers, feedback from the community will help determine which aspects deliver the most value and where additional work remains necessary. The coming weeks should reveal whether these changes represent a meaningful step forward for both everyday users and professional developers working with AI tools.



from WebProNews https://ift.tt/qzNiKkM

Saturday, 5 September 2026

North Korean Hackers Turn Victims’ HAProxy Servers Into Stealthy Web Spies

Security researchers have uncovered a previously unknown Linux malware toolkit that North Korean actors slipped directly into the heart of compromised web infrastructure. The implant, which attackers internally called ted, doesn’t just ride along on a server. It becomes the server.

Rapid7 Labs first spotted the oddity while investigating two South Korean organizations, one in the automotive sector and another in media. Both ran HAProxy version 2.8.12. But the binaries weren’t the clean ones distributed by the project. They contained extra code compiled straight into the load balancer itself. The result? A backdoor that can watch, alter, and control web traffic without ever showing up in backend logs or obvious network chatter. And it does all this while the system continues serving legitimate requests without a hitch.

But ted doesn’t operate alone. It forms the centerpiece of a larger collection of tools. There’s curlRAT, a simple yet effective remote access trojan. An SSH keylogger. Trojanized versions of everyday Linux daemons like crond, agetty, atd, and polkitd. Each piece helps the attackers maintain a low profile during what appears to be long-term espionage.

The discovery matters because it shows how far determined state actors will go to blend into the environment. “The standout feature of this toolkit is its depth of integration with the target environment,” Rapid7 noted in its analysis published September 4. The firm attributed the activity with medium confidence to DPRK-linked groups, based on the victims, the targeting patterns, and similarities in encryption and command-and-control infrastructure seen in past operations.

Installation requires attackers to already possess code execution and sufficient privileges on the target server. They replace the legitimate HAProxy binary with their modified build. No remote exploit of HAProxy itself is involved. The malware hooks into the software’s own filter API, memory pools, event scheduler, and process management features. This tight coupling lets ted intercept HTTP sessions, harvest cookies, inject scripts into pages for selected visitors, and even use the load balancer as its primary command-and-control channel.

One particularly clever mechanism involves a specific image path request that flips the filter into C2 mode. From there, operators can issue commands. The backdoor decrements HAProxy’s live connection counters so the malicious traffic never appears in normal statistics. Commands get written to a named pipe in /tmp. Responses flow back through the same disguised path. It’s quiet. Efficient. Hard to spot unless you’re looking at the binary itself or monitoring for these subtle behavioral tells.

The toolkit also includes features designed to clean up after itself. Selective log wiping. Careful avoidance of leaving obvious artifacts. The curlRAT component even runs a watchdog thread that monitors the HAProxy process state and reports back hourly. If the load balancer restarts or reloads, the attackers know.

Victims weren’t chosen at random. South Korea’s automotive and media industries hold strategic value for Pyongyang. Intellectual property in car manufacturing. Audience data and editorial systems in media. Both offer rich targets for espionage and potential influence operations. The earliest samples on VirusTotal date to mid-2025, suggesting the tooling has been in development and limited use for some time before Rapid7’s public disclosure.

Security teams have reacted with a mix of alarm and practical advice. Verifying the integrity of deployed binaries tops the list. Hash checks against known good builds. Behavioral monitoring for unexpected filter activity in HAProxy. Network segmentation that treats load balancers as high-value assets requiring extra scrutiny.

Yet the attack also highlights a broader challenge. Many organizations treat infrastructure components like HAProxy as set-it-and-forget-it systems. They patch the software but rarely examine the compiled binary running in production. Attackers counted on that complacency.

Related research from the past week reinforces the trend of sophisticated Linux targeting. A September 4 report from Rapid7 provides the most detailed technical breakdown, complete with MITRE ATT&CK mappings, indicators of compromise, and analysis of the full toolkit. It shows how ted can steal session cookies through passive capture, redirect users selectively, and even support drive-by download attacks while hiding the tampering from most IP ranges.

Discussions on X this week echoed the findings. Security practitioners noted the implications for supply chain hygiene. One observer pointed out that simply checking open source project releases isn’t enough when attackers can rebuild and trojanize the exact version a victim uses. Another highlighted the watchdog functionality in curlRAT as a sign of operational maturity. These aren’t smash-and-grab tactics. They’re built for persistence.

The encryption methods used remain relatively basic. XOR and a custom substitution cipher for the keylogger. Feedback XOR plus Base64 for outbound data. Such choices suggest the operators prioritize speed and reliability over cryptographic strength, perhaps assuming that if the traffic looks like normal HAProxy behavior it won’t draw attention anyway.

Defenders face a tough task. Static analysis of running binaries can help, but only if they know what to look for. The ted implant reads specific internal structures at offsets tied to HAProxy 2.8.12. Later versions of the software would break that hardcoding, which may explain why the attackers locked onto that particular release. Current HAProxy 2.8 builds have advanced to 2.8.28 as of late August.

So what should organizations do? Start with inventory. Identify every HAProxy, nginx, or other proxy deployment. Establish a baseline of clean binaries. Implement file integrity monitoring that alerts on unexpected changes. Monitor for anomalous filter registrations or unexpected use of HAProxy’s internal APIs.

Network monitoring should watch for connections that don’t match expected traffic patterns, even if they originate from the load balancer itself. And yes, review logs with fresh eyes. The backdoor tries to hide, but complete invisibility remains difficult when the system is under active investigation.

This incident joins a growing list of cases where attackers invest heavily in custom tooling for specific environments. From kernel rootkits to trojanized system daemons, the bar for stealth keeps rising. North Korean operators have shown particular interest in Linux targets in recent years, especially when those systems sit at the edge of corporate networks and handle sensitive traffic.

The full picture may never emerge. The two confirmed victims represent what Rapid7 could verify. Other intrusions using the same toolkit could exist undetected. The code’s sophistication suggests it wasn’t built for one-off operations.

Researchers continue to dig. Additional samples may surface now that attention has focused on the SHA-256 hashes and behavioral patterns. For now, the message is clear. Trust but verify extends all the way down to the binaries powering your most critical network services. Anything less leaves the door open for implants like ted to slip inside and watch everything that flows through.



from WebProNews https://ift.tt/0PtOiZe

Military Branches Finally Disable Ad Trackers After Location Data Fuels Attacks on Troops

The U.S. military has begun stripping advertising identifiers from government phones and computers. The move comes after confirmation that adversaries bought commercial location data to track and target American forces in the Middle East.

Senator Ron Wyden released letters on September 4 detailing the changes. The Reuters report that broke the story quoted Air Force officials saying they disabled the identifiers two months earlier. Special Operations Command acted even more recently on its Windows machines. The Army had blocked them on mobile devices since early this year.

But these steps arrive years too late. Warnings stretched back a decade. And the data brokers never stopped selling.

Commercial location records reveal patterns. They show where troops gather. They map daily routines. Adversaries then exploit that knowledge. Missiles. Drones. Roadside bombs. Counterintelligence operations. All become easier.

“Commercial location data can be used to identify where U.S. troops congregate and their pattern of life, which can be exploited by adversaries to target attacks such as missiles, drones, and roadside bombs, as well as for counterintelligence purposes,” Wyden wrote in a May letter to the Pentagon, as reported by Reuters.

U.S. Central Command had already received multiple threat reports. The command confirmed adversaries used the purchased data to target or surveil personnel in theater. That acknowledgment, shared with lawmakers, marked the first official admission of its kind.

The ad industry built this system for profit. Apps collect precise coordinates through software development kits. They tie movements to unique mobile advertising IDs, or MAIDs. Data brokers aggregate, clean and resell the streams. Anyone with a credit card can buy access. Foreign intelligence services included.

Zach Edwards, co-founder of privacy ad-tech firm Decryptads, called the military’s decision positive. Disabling MAIDs keeps troop locations out of bulk sales. Yet he warned other tracking methods remain. Apps can still triangulate signals. Device fingerprints combine with network data. The flow never fully stops. (Reuters)

Wyden and Representative Pat Harrigan, a North Carolina Republican, sent a fresh letter to the Defense Department inspector general. They demanded an investigation into existing safeguards. Their message was blunt. Current military efforts have failed to neutralize the threat. Enemies should not buy information that helps them track American troops. (Reuters)

The Pentagon knew. Internal studies flagged the problem. External journalism demonstrated the damage.

In May 2025 the Army Cyber Institute at West Point released a technical report. Researchers examined traffic on stateside unclassified networks. More than 21 percent of the top 1,000 domains visited were pure trackers. Another 10 percent of sites carried embedded tracking code. Advertising trackers made up over a quarter of those domains. The institute noted fixes required minimal funding or resources. The WIRED story laid out those findings in detail.

Yet rollout dragged. Central Command only enabled the ability to disable location sharing on government smartphones this year. Roughly ten years after the first warnings. And the Army recently directed soldiers to use personal phones for some government work. The same phones that broadcast advertising IDs straight to the brokers.

Earlier investigations painted an even darker picture. A 2024 joint probe by WIRED, Bayerischer Rundfunk and Netzpolitik.org obtained a free sample from a Florida data broker. The dataset held 3.6 billion location coordinates from up to 11 million devices in Germany over two months. Analysis traced devices to U.S. military bases, intelligence sites and even locations believed to store nuclear weapons. Patterns exposed entry points, guard schedules and personal movements. The story showed how contractors and service members could be followed from homes to sensitive facilities. Or to German brothels.

That data came from the same advertising pipelines now linked to battlefield targeting. The military’s own digital footprints fed the machine.

Senator Wyden has pressed the issue for months. He warned the adtech sector functions as a national security threat. His office highlighted how data brokers compile information on troops and sell it openly. Lawmakers have called for broader measures. Restrict location sharing on personal devices brought onto bases. Remove Google Chrome from Defense Department systems because of its advertising focus. The May Reuters coverage captured those demands.

Personal devices complicate everything. Troops and contractors carry them onto installations. Videos posted online have already revealed locations in the Middle East. Some deployed personnel were ordered to surrender phones. The Gizmodo article noted these incidents alongside the tracker shutdowns.

A Government Accountability Office report from late 2025 examined digital footprints across the Defense Department. It warned that aggregated data from devices, communications and platforms threatens operations, personnel safety and national security. Data brokers stand at the center. They collect, package and sell information that foreign actors can weaponize. The GAO document reinforced what the Army researchers and journalists had found.

The recent disablement of advertising IDs represents a tactical fix. It breaks the easy linkage between a device and a persistent profile. Location pings become harder to attribute. Yet the underlying market persists. Apps still harvest data. Brokers still trade it. Foreign governments still shop for insights.

And. The military continues to wrestle with personal devices. Service members often prefer their own phones. Convenience wins until it doesn’t.

So the question lingers. How many more threat reports will surface before policy catches up to the data economy that powers modern advertising? The branches have acted. But the system that exposed them remains intact. The TechCrunch coverage on the same day as the Reuters story echoed Wyden’s caution that personal phones could still betray bases and personnel.

Defense officials declined further comment in several cases. The Air Force and Special Operations Command offered no elaboration. The pattern suggests discomfort with how deeply commercial surveillance has penetrated military life.

One fact stands clear. The same technology that delivers targeted ads to civilians now delivers targeting data to America’s adversaries. The military’s belated response underscores a larger failure. It failed to treat the adtech pipeline as the intelligence vector it had become. Years of studies, demonstrations and real-world compromises led to this moment.

Disabling the trackers buys time. Whether the Pentagon uses that time to address the deeper structural risks remains uncertain. The data keeps flowing. The threats keep evolving. And troops in theater continue to operate in an environment where their phones can betray them long before any shot is fired.



from WebProNews https://ift.tt/IPSKQWs

Friday, 4 September 2026

GLP-1 Drugs Show Surprising Protection Against Tuberculosis and Serious Infections

Patients taking GLP-1 receptor agonists for type 2 diabetes or weight management face lower risks of tuberculosis and other grave infections. The pattern emerges from large observational studies released in recent weeks. It adds another layer to the already impressive profile of drugs like semaglutide and tirzepatide.

Diabetes itself heightens vulnerability to infections. High blood sugar impairs immune cells. Obesity fuels chronic inflammation. Yet medications that address both conditions appear to do more than control glucose and promote weight loss. They may actively bolster defenses against pathogens that thrive in compromised hosts.

One analysis drew on records from more than 7 million people with type 2 diabetes across international databases. Those prescribed GLP-1 drugs developed TB at markedly lower rates than peers on other common diabetes treatments. Hazard ratios ranged from 0.49 versus DPP-4 inhibitors to 0.82 versus SGLT2 inhibitors. The findings appeared in Nature Communications.

“These findings suggest that beyond their established metabolic benefits, GLP-1 receptor agonists may confer additional advantages in lowering infection risk,” said Chih-Cheng Lai, MD, of Chi Mei Medical Center in Taiwan, and his colleagues, as reported by MedPage Today. The study ran from 2017 to 2025 using the TriNetX network.

But wait. Observational data always carries risks of confounding. Doctors might prescribe GLP-1 drugs to healthier or more motivated patients. Researchers adjusted for many factors. The consistency across four different comparator drug classes strengthens the signal. Still, only randomized trials can prove cause and effect.

A separate real-world examination focused on tirzepatide, the dual GLP-1 and GIP agonist sold as Mounjaro and Zepbound. Researchers examined over 50,000 U.S. adults with type 2 diabetes and heart disease. They compared outcomes to those taking sitagliptin, a DPP-4 inhibitor.

Tirzepatide users showed striking reductions. Infection-related mortality dropped with a hazard ratio of 0.40. Hospitalizations for infection fell to a hazard ratio of 0.64. Even urinary tract infections occurred less often. All-cause mortality also declined. Nils Krüger, MD, of Harvard Medical School led the work. It was published in The BMJ.

“One plausible explanation that our study supports is the substantial reduction in serious bacterial infections observed among individuals who initiated tirzepatide, suggesting that part of the survival benefit may reflect effects beyond atherosclerotic mechanisms,” Krüger and his co-authors wrote, according to MedPage Today.

The original report that brought early attention to this connection appeared in Gizmodo. It highlighted how GLP-1 drugs correlate with fewer serious infections including TB. That piece helped spark broader discussion among clinicians and researchers.

Additional evidence keeps arriving. A meta-analysis of 136 randomized controlled trials involving more than 164,000 participants found GLP-1 treatment linked to fewer serious infections overall. Relative risk came in at 0.89. Reductions appeared across respiratory, skin, musculoskeletal and vascular infections. COVID-19 infections also occurred less frequently. The analysis was published in the Journal of Infection.

Semaglutide specifically cut infection risks in the FLOW trial. Patients with type 2 diabetes and chronic kidney disease who received the drug experienced fewer serious adverse events from infections. Hospitalizations dropped. COVID-19 events declined. Benefits proved strongest in those with poor glycemic control or high albuminuria. Those details emerged in Nephrology Dialysis Transplantation.

Protection extends to surgical settings. Patients on GLP-1 drugs before dermatologic procedures faced lower odds of postoperative infections and wound complications. Semaglutide and tirzepatide showed the strongest effects. This data came from a study in Dermatologic Surgery.

Even patients with diabetic gastroparesis — a condition that slows stomach emptying and might theoretically raise aspiration risk — saw fewer pulmonary and systemic infections when taking these drugs. Pneumonia, sepsis and bacteremia rates fell significantly in propensity-matched cohorts.

Why would this happen? Several mechanisms seem plausible. Weight loss reduces mechanical stress on lungs and improves mobility. Better blood sugar control enhances neutrophil function and wound healing. GLP-1 receptors exist on immune cells. Activation may dampen excessive inflammation while preserving necessary responses to bacteria and viruses.

Anti-inflammatory effects could explain lower rates of severe outcomes in cancer patients receiving immunotherapy. One analysis presented at the 2026 ASCO meeting found 31% lower five-year mortality among those also taking GLP-1 drugs. Rates of fever, fatigue, sepsis and pneumonia all decreased. The report appeared in CURE.

Not every signal points in the same direction. Some studies have flagged a potential increase in herpes infections with certain GLP-1 agents. A target trial emulation study found higher risks of herpes simplex and zoster in some subgroups. That work was published in BMC Medicine. Clinicians should weigh individual risks.

Respiratory adverse events do not appear elevated. A systematic review and meta-analysis published August 31, 2026, in the Annals of the American Thoracic Society found no increased risk of lower respiratory tract infections, pneumonia or cough with liraglutide, semaglutide or tirzepatide compared with placebo. Ian J. Saldanha, MBBS, MPH, PhD, and colleagues at Johns Hopkins Bloomberg School of Public Health emphasized the reassuring nature of the data.

Experts caution against overinterpreting associations. “The extent of the reduction compared with other diabetic medication was greater with GLP-1. That suggests that this infection prevention benefit goes beyond just reducing sugar and weight,” said Todd Ellerin, MD, of South Shore Health, in a September 1, 2026, segment on WCVB Channel 5 Boston.

Large-scale randomized trials focused on infection outcomes remain absent. Most current evidence comes from secondary analyses or observational cohorts. Residual confounding could still explain part of the benefit. Patients on newer, more expensive drugs often differ in socioeconomic status, access to care and adherence to other therapies.

Yet the breadth of positive signals across TB, bacterial infections, viral complications and postoperative wounds deserves attention. Tuberculosis kills more than a million people annually. Diabetes drives much of the global burden in high-prevalence regions. A medication that simultaneously manages blood sugar, promotes weight loss and appears to lower TB incidence could reshape public health strategies in affected countries.

Pharmaceutical companies have not yet pursued infection-specific indications. Regulatory pathways would require dedicated prospective studies. Those trials take years and substantial investment. In the meantime, physicians may begin considering infection risk profiles when choosing glucose-lowering therapy for high-risk patients.

The pattern fits with growing recognition that these drugs affect multiple organ systems through both direct receptor activation and indirect metabolic improvements. Cardiovascular benefits arrived first. Kidney protection followed. Now immune modulation enters the conversation.

Researchers continue mining real-world data. New reports surface almost monthly. Some examine cancer immunotherapy synergy. Others explore effects in nondiabetic populations. The full picture will take time to emerge. For now the evidence suggests GLP-1 receptor agonists deliver benefits that reach well beyond the scale and the bloodstream.

Patients and doctors should view these findings as promising but preliminary. Individual decisions still hinge on overall health profile, tolerability and specific indications. Yet the accumulating data points toward an unexpected bonus from a drug class once viewed primarily as a tool for metabolic control.



from WebProNews https://ift.tt/ryhfN7C

Wikipedia’s Staff Push for Union Power Tests Nonprofit Ideals

Ballots went out in mid-August. They return for counting on September 3. For the first time, paid workers at the organization behind Wikipedia could soon gain formal union representation.

The effort started quietly among staff. It gained force after layoffs hit a key team. Volunteers rallied with petitions signed by more than 1,190 editors. Some pledged to halt edits if called upon. The clash has exposed fractures in a movement built on openness and shared purpose.

UK staff fired the first shot in June 2026. They asked the Wikimedia Foundation to recognize their union without an election. The group, operating under the Wiki Workers United banner, partnered with the United Tech and Allied Workers branch of the Communication Workers Union. The Verge reported that these workers cited recent organizational changes that eroded trust and transparency.

One month later, US staff followed. They claimed a supermajority of eligible employees had signed authorization cards. Their demand for voluntary recognition came with a short deadline. The Foundation waited until after Wikimania, its flagship conference in Paris, to respond. On July 27 it declined. It insisted on a National Labor Relations Board-supervised election instead.

“We are deeply disappointed that the Wikimedia Foundation has taken the low road,” read a statement from Wiki Workers United US and the Communications Workers of America. The union accused the nonprofit of deploying classic anti-union language shaped by expensive law firms. It pointed to the hiring of Littler Mendelson, a firm known for advising companies on union avoidance. The CWA release detailed these claims.

The Foundation pushed back. In its official statement it affirmed respect for workers’ rights. “The decision to unionize belongs to staff,” it said. “The Foundation’s responsibility is to ensure that they can make their own choice freely.” It pointed to a secret-ballot process as the fairest route. An August 5 update confirmed an agreement on voter eligibility. Ballots would mail August 11. Counting would occur September 3 at the NLRB’s San Francisco office. The Wikimedia Foundation posted the full position online.

Tensions trace back further. In May the Foundation disbanded its Community Tech team. The move affected engineers who built tools for volunteers. Several were active in early union talks. Backlash followed. Volunteers saw it as more than budget trimming. The Wikipedia page tracking these events notes that community members grew “extremely angry” after the July 27 statement, citing coverage in Der Standard.

Over 1,190 volunteer editors signed a solidarity petition by late July. Their combined edit counts exceeded 15 million. The signers included dozens of administrators, arbitrators, checkusers and featured-article writers. They pledged support for collective action, up to and including an editorial strike. Tactics discussed ranged from ignoring vandalism to blocking donation banners. But no strike has been called. The petition remains one of the most backed proposals in English Wikipedia history.

And the stakes run high. Wikipedia draws billions of monthly visitors. The Foundation employs roughly 650 people across dozens of countries, with 342 based in the US. It raised nearly $180 million in donations in recent years, nearly all from small online gifts. Staff handle everything from legal defense to software development to fundraising. Volunteers create the content. That split has long defined the project. Now it fuels debate over who holds real influence.

Volunteer Backlash Meets Institutional Caution

Critics inside the community accuse leadership of distancing itself from the movement’s grassroots ethos. Recent CEO transitions and restructuring added to unease. Bernadette Meehan took the top role earlier in 2026. Public statements from her and others had endorsed workers’ organizing rights. Union supporters saw the rejection of voluntary recognition as walking back those words.

Jason Koebler at 404 Media captured the timing. The Foundation’s announcement landed days after Wikimania ended. Organizers called the delay and legal spending “insulting and expensive.” They argued thousands of tech and nonprofit workers have won voluntary recognition through card-check methods. The Foundation chose the longer NLRB route anyway.

Yet the nonprofit holds firm on process. It notes that an NLRB election includes safeguards for all voices, including those who might oppose unionization. Managers are excluded from the proposed unit. International staff fall outside the current US drive. UK negotiations on bargaining scope continue separately.

Recent coverage adds context. A Wired article published today examines the impending vote and its potential to set precedents for other mission-driven tech organizations. It highlights how staff seek stronger say over priorities such as artificial intelligence integration, content moderation policies and job security amid shifting budgets.

Broader labor trends matter too. Union elections overseen by the NLRB dropped sharply in 2025 amid policy shifts. Win rates hovered near 70 percent. High-profile campaigns at Starbucks and elsewhere showed both the energy and the obstacles. Wikimedia’s case stands apart. Few nonprofits of its scale and cultural weight have faced such organized internal pressure.

So what happens next? If a majority votes yes on September 3, the Foundation has pledged to bargain in good faith. Contracts would cover wages, benefits, protections against arbitrary layoffs and perhaps input on strategic decisions. Failure could deepen rifts with volunteers already wary of centralized power.

Either outcome will echo. Wikipedia’s model rests on trust. Editors donate millions of hours without pay. Donors give because they believe in neutrality and independence. Staff now demand a formal seat at the table. Their success or setback could influence organizing attempts at other open-source and knowledge-focused groups.

Watch the count. The results will reveal whether Wikipedia’s workers secure a stronger voice or whether the Foundation’s preferred process preserves the status quo. The world’s largest encyclopedia hangs in the balance, shaped as much by its internal labor dynamics as by its volunteer contributors.



from WebProNews https://ift.tt/Ty273o6