The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

Bring on the AI swarms. They’re the only thing that can defend us now that AI is free

Unpredictable token bills haunted the first half of 2026 as AI experimenters pushed deeper into the tech and often found useful results could only be achieved after surprising and unwelcome expenditure. We've gone from tokenmaxxers to tokenmisers, counting every character we send to AI services. That changed the way we used AI, focusing users on the ticking meter and unable to cast their eyes up and explore the possible. Those blinkers fell away in the middle of August when Alibaba delivered Qwen3.8-27B, byte-for-byte probably the most powerful language model ever created – and also capable of running on a high-spec laptop. The community of “local AI” enthusiasts noticed and have spent the intervening weeks whittling Qwen down to fit on an ever-widening array of devices, including – surprisingly – my M4 MacBook Air. Their work means millions of similar devices can now access near-frontier-level artificial intelligence from free software. The gap between my MacBook Air and a smartphone isn’t vast. As local AI developers continue whittling Qwen down to size, a few hundred million smartphones will also be capable of running top-tier AI. While that hasn't happened yet, it won't be more than six months away. At the rate things are unfolding, probably closer to six weeks. Suddenly, "good enough" AI isn't something that we will have to rent. We can have it, at no cost, on our desktops, our kitchen tables, our classrooms and in our pockets. That’s great, but also scary because we've been caught unprepared by AI effectively becoming free. Nobody yet knows what we will do with free AI, or if we are ready for it. On the positive side of the ledger, we stand to benefit from a growing “cognition surplus” that brings more thinking capacity into the home or office. Need to wrangle your way through a baroque accounting system? Give it to the AI. Sorting through twenty years of smartphone snaps? Again, let the AI do the heavy lifting. How about a personal newspaper gathered while you sleep, and presented on your tablet at the breakfast table? It's all doable now. All of that feels very much like something I remember clearly from the early 1980s, when the promise of the “home computer” was managing recipes. We knew the device would find a use, but it wasn't until the one-two punch of GUIs and the Web that most people had any real use for a home computer. That's exactly how this moment feels. Sure, managing smartphone photos will be helpful for millions, but the biggest win will be on the darker side of the ledger – where every bad actor – from script kiddies with a grudge through to the worst of the worst – now have equal access to powerful AI that will go with them everywhere. They’ll use it to lie, cheat and vex, at a speed and on a scale never before seen. To deal with that, we'll fight fire with fire. The most important job our AIs will be tasked with will be keeping us as safe as possible from other AIs. We’ll only be aware of this when it fails. But “good enough” AI and “intelligence everywhere” will enable resource pools and defensive techniques that our adversaries could never harness for themselves, so we stand a solid chance. ®

Slashdot

News for nerds, stuff that matters

Ubuntu's 'Rust-ification' Hits New Milestone: Coreutils Migration is Complete

"Ubuntu has managed to do away with GNU Core Utilities in its default stack," reports the blog It's FOSS.


The last three utilities — cp, mv and rm — have been moved to versions from the uutils project (which reimplements utilities in Rust).

Everything else, from ls and cat to chmod and du, made that jump in earlier releases... Canonical started "oxidizing" Ubuntu last year, and Ubuntu 25.10 became the first release to ship [ the uutils project's] coreutils as the default. That release also made sudo-rs the default privilege tool, replacing a command that had been in place for decades.


26.04 was the release where the plan did slow down quite a bit, as Canonical kept cp, mv, and rm on their GNU versions due to a bunch of TOCTOU issues that were blocking the full implementation. These were caught during an audit, when Canonical commissioned Zellic for two rounds between December 2025 and March 2026, focusing on the most security-sensitive utilities first. Across both rounds, Zellic raised 113 issues, and 44 of them were assigned CVEs. Canonical says the vast majority have been resolved.

Getting here has had its ups and downs, and the last stretch was not clean. In July, uutils cp went back into the archive and came straight out again after it broke live image builds. The fix was quick; as the developers marked it "Critical," the fix went upstream, and the migration landed in time for 26.10.

When typing commands, nothing changes for you on the surface. uutils coreutils is designed to be a drop-in replacement for essential GNU tools, and the project treats any divergence from GNU as a bug, further pointing out that some options may still be missing or behave differently. So if you prefer staying on the GNU version, you have the option to install the coreutils-from-gnu package that houses all the required components.

Read more of this story at Slashdot.

Wel.nl

Minder lezen, Meer weten.

Alle uitgestelde bezuinigingen bij elkaar opgeteld: zoveel duurder wordt 2028 als de klap alsnog komt

Minstens vijf grote bezuinigingen uit de Miljoenennota 2027 zijn niet geschrapt, maar doorgeschoven naar 2028 en 2029. De koopkracht daalt volgend jaar gemiddeld met 0,1 procent, maar de gestapelde rekening die erachter schuilgaat, heeft niemand doorgerekend.

Die klap komt later nog

Nibud-directeur Mattias Gijsbertsen waarschuwde na de Miljoenennota dat verschillende nadelige maatregelen niet van tafel zijn gehaald, maar uitgesteld met een jaar. 'Die klap komt dus mogelijk later nog,' aldus Gijsbertsen. Het kabinet trekt €1,5 miljard uit om de koopkracht in 2027 te repareren, maar de doorgeschoven bezuinigingen zitten in die reparatie niet verwerkt.

Wat is er uitgesteld?

  • Eigen risico: extra verhoging van €60 per persoon, uitgesteld van 2027 naar 2028
  • Kindgebonden budget: volledig afbouwpercentage van 12,8% pas vanaf 2028 (in 2027 verzacht naar 9,95%)
  • Compensatieregeling transitievergoeding: afschaffing doorgeschoven van 2027 naar 2028
  • WW-halvering: maximale duur van 24 naar 12 maanden, uitgesteld naar 2029
  • Tegemoetkoming arbeidsongeschikten: afschaffing uitgesteld, met €311 miljoen hogere uitkeringslasten

Eigen risico: van €385 naar €455

Het eigen risico stijgt in 2027 door indexatie naar €400. De extra verhoging uit het coalitieakkoord schuift door naar 2028: het bedrag gaat dan naar verwachting alsnog omhoog naar €455. Wie jaarlijks het eigen risico volledig opmaakt, betaalt €70 meer dan de €385 van 2026. Voor een stel is dat tot €140 per jaar. In de jaren daarna volgt verdere indexatie, tot €520 in 2030.

Kindgebonden budget: volle klap pas in 2028

Het kabinet verzacht de afbouw van het kindgebonden budget in 2027 door het afbouwpercentage boven €60.000 inkomen in twee stappen in te voeren: 9,95 procent in 2027, 12,8 procent in 2028. Eerder berekenden we dat gezinnen boven die grens gemiddeld €670 per jaar minder ontvangen en dat circa 114.000 huishoudens hun recht volledig verliezen. Doordat de afbouw in 2027 lager uitvalt dan gepland, wordt een deel van die klap doorgeschoven naar 2028.

Het koopkrachtpakket van €1,5 miljard dekt 2027. De rekening voor 2028 heeft niemand doorgerekend.

WW en WIA: verschoven, niet verdwenen

De halvering van de maximale WW-duur van 24 naar 12 maanden is uitgesteld naar 2029. Met dat uitstel is volgens RTL Nieuws €684 miljoen gemoeid. De tegemoetkoming arbeidsongeschikten bedraagt in 2026 netto €226 per jaar en de afschaffing daarvan schuift eveneens door. Beide maatregelen raken niet iedereen direct, maar voor wie na 2029 werkloos of arbeidsongeschikt raakt, is het vangnet een stuk kleiner. Eerder schreven we wat de WW-halvering per persoon kan kosten.

Gaat dit door?

Dat is de grote onbekende. Het kabinet heeft geen meerderheid in de Tweede Kamer en heeft steun van oppositiepartijen nodig om de plannen door te voeren. Maar maatregelen als 'uitgesteld' in de begroting laten staan is ook een signaal: de intentie is er. Wie zijn huishoudboekje opmaakt voor de komende jaren, doet er verstandig aan niet alleen naar 2027 te kijken. De echte verrassing kan een jaar later komen.

Bronnen: Rijksfinanciën (Miljoenennota 2027) · Reformatorisch Dagblad · Zorgwijzer · Flexmarkt · NOS · UWV


Flourish

Keith Midson has added a photo to the pool:

Flourish

My place - a lawn daisy taken with a vintage Canon 10D and 28mm lens.

Ius Mentis

Internetrecht door Arnoud Engelfriet

EU verplicht elektronicafabrikanten om cyberincidenten binnen 24 uur te melden

De eerste verplichting uit de Europese Cyberweerbaarheidsverordening geldt sinds 11 september. Dat meldde Tweakers vorige week. Fabrikanten moeten actief misbruikte kwetsbaarheden en grote beveiligingsincidenten voortaan bij Europese en nationale toezichthouders melden bij Enisa, het European Union Agency for Cybersecurity, en bij het lokale Computer Security Incident Response Team (Csirt).

De Cyberweerbaarheidsverordening of Cyber Resilience Act (CRA) is een van de wetten uit het pakket van de Digital Decade. De wet staat naast de Nederlandse Cyberbeveiligingswet, want die implementeert de bekende NIS2 richtlijn. Kort gezegd: NIS2 gaat over kritieke infrastructuur, de CRA gaat over apparaten die over netwerken praten.

De kern van de CRA is “producten met digitale elementen”, mits ze “een directe of indirecte logische of fysieke gegevensverbinding met een apparaat of netwerk” hebben. De robotstofzuiger van het plaatje bijvoorbeeld communiceert met het basisstation links, maar die praat weer via wifi met de thuisrouter en daar weer mee met de clouddienst van de aanbieder. Elk van die afzonderlijk is genoeg om die stofzuiger onder de CRA te laten vallen.

Doel van de CRA is de cyberbeveiliging van dergelijke producten te waarborgen. Essentiële eisen daarvoor staan in een bijlage, en je moet als fabrikant een conformiteitsbeoordeling (die van de CE-markering) doorlopen om vast te stellen dat je daaraan voldoet. Je aansprakelijkheid voor fouten daarbij kun je niet beperken.

De eerste twee plichten uit de CRA (de rest komt in december volgend jaar) zijn de meldplicht kwetsbaarheden en ernstige incidenten, beiden uit artikel 14. Eerst maar die eerste.

Een fabrikant doet tegelijkertijd aan het overeenkomstig lid 7 van dit artikel als coördinator aangewezen CSIRT en aan Enisa melding van elke actief uitgebuite kwetsbaarheid in het product met digitale elementen waarvan hij kennis krijgt.
Dat is een “zwakheid, vatbaarheid of gebrek” waarbij “betrouwbare bewijzen bestaan dat een kwaadwillige actor die heeft uitgebuit in een systeem zonder toestemming van de systeemeigenaar”. Binnen 24 uur na ontdekking daarvan moet je het melden.

Daarnaast moeten ook zogeheten ernstige incidenten worden gemeld:

Een fabrikant doet tegelijkertijd aan het overeenkomstig lid 7 van dit artikel als coördinator aangewezen CSIRT en aan Enisa melding van elk ernstig incident dat gevolgen heeft voor de beveiliging van het product met digitale elementen waarvan hij kennis krijgt.
Een “incident” is dan weer in NIS2 gedefinieerd als een “gebeurtenis die de beschikbaarheid, authenticiteit, integriteit of vertrouwelijkheid van opgeslagen, verzonden of verwerkte gegevens of van de diensten die worden aangeboden  … in gevaar brengt”.

Het incident is ernstig als aan een van deze eisen is voldaan:

  1. Negatieve gevolgen voor de beschikbaarheid, authenticiteit, integriteit of vertrouwelijkheid van gevoelige of belangrijke gegevens of functies;
  2. Injectie of executie van kwaadwillige code in een product of netwerk daar omheen.
En let op, we noemen het wel “de meldplichten” maar óók het moeten adresseren is al van kracht. Binnen 72 uur na ontdekking van een uitgebuite kwetsbaarheid moet je een oplossing of in ieder geval workaround publiceren. Binnen 14 dagen (en bij incidenten 30 dagen) een finale oplossing.

In theorie kún je voldoen door te zeggen “dit is er gebeurd, wij hebben geen patch dus we stellen voor dat je het apparaat uitzet”. De bedoeling is dat niet, maar er staan momenteel geen boetes op het niet daadwerkelijk fixen wat gefixt kan worden. Dat komt pas eind volgend jaar.

Arnoud

Het bericht EU verplicht elektronicafabrikanten om cyberincidenten binnen 24 uur te melden verscheen eerst op Ius Mentis.

The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

UK inflation rises to 3.1%, piling more pressure on households

Annual increase in August comes as Bank of England prepares for decision on interest rates

UK inflation has returned above 3% as soaring energy prices fuelled by the Iran war heap renewed pressure on British households.

Figures from the Office for National Statistics show inflation as measured by the consumer prices index rose from 2.9% in July to 3.1% in August. City economists had forecast a rise to 3.1%.

Continue reading...

Al-Qaida and IS-linked violence in Africa’s Sahel belt set to hit record levels this year

Twenty-five years after 9/11, figures compiled by conflict monitor underline how Sahel region has become centre of Islamist terror

Islamist extremist violence in Africa’s Sahel region is set to reach historic highs after a series of sweeping offensives by groups linked to al-Qaida and Islamic State, according to new figures compiled by the conflict monitor Acled.

As the US marks the 25th anniversary of the 9/11 attacks launched by al-Qaida against targets in Washington and New York, the statistics underline the continued expansion of the veteran organisation in parts of Africa – in stark contrast with its relative weakness elsewhere.

Continue reading...

Redwood by Ben Macintyre review – a superbly wrought tale of cold war defection

This story of Soviet agent and his MI6 handler in revolutionary Iran is a page-turning masterpiece

Ben Macintyre uses the acronym MICE to describe the reasons people betray their countries: Money, Ideology, Coercion or Ego. In the set-piece that opens his latest work of true-espionage, we discover a new reason: erectile dysfunction.

Stressed, drinking too much, under constant surveillance, furious about the corruption of his colleagues and frustrated with his home life, the KGB’s Vladimir Kuzichkin is offering to betray the secrets of his homeland and its Iranian allies, if only a British doctor can help him have sex again.

Continue reading...

The other side of Croatia: ‘a landscape that could out-Tuscany Tuscany’

Weekenders from Zagreb head to the rolling green Samobor Hills for nature, vineyards, delicious local food and Habsburg-era architecture

‘You’re going to Samobor? You must try kremšnita,” my Dubrovnik friends told me before I set off on my trip north. “But I’ve already had kremšnita in Zagreb,” I told them. They do it better in Samobor, they insisted. I wasn’t about to get embroiled in a battle of the cream cakes in a region where Croatians, Slovenes and Austrians all like to celebrate their own versions of this decadently thick, fat custard slice topped with puff pastry and icing sugar. But I was more than willing – happy, even – to follow everyone’s suggestions to try kremšnita in Hotel Livadić’s Kavana Livadić, in Samobor’s main King Tomislav Square, a mere half-hour drive west of Zagreb.

It lived up to the hype – delicately rich, creamy and with a light touch. After spending a few weeks in sun-bleached Venetian Dalmatia, amid the scrubby, limestone Dinaric Alps, I had swapped empires and was firmly in Habsburg Croatia. Here, in Zagreb County’s prettiest town, handsome baroque houses in pastel shades of buttery yellow, apricot and pistachio, festooned with stucco, line narrow King Tomislav Square, whose umbrella-shaded cafe terraces were filled with Croatians getting their morning fix of coffee and chatter.

Continue reading...

Sargasso

Hopeloos Genuanceerd

Werken moet lonen. Behalve voor werkenden

Werken moet lonen is zo’n VVD-slogan waarvan iedereen inmiddels weet wat ermee wordt bedoeld: uitkeringen moeten omlaag, de sociale zekerheid moet soberder en het verschil tussen werken en niet werken moet groter. Ook in het huidige coalitieakkoord staat het weer.

Maar nu gaat het eens daadwerkelijk over de vraag hoeveel werken loont. De Raad van State constateert namelijk dat van de zes miljard euro aan lastenverzwaringen in 2027 maar liefst 5,8 miljard bij werkenden terechtkomt. Weet je wel, die mensen waarvoor werken juist moet lonen en die er bijna allemaal op achteruit gaan. De lasten voor bedrijven en vermogenden gaan ondertussen juist iets omlaag.

Dat is extra pikant naast de discussie over Box 3. Daar dringt juist de VVD aan op een vermogenswinstbelasting waarbij pas belasting wordt geheven als winst daadwerkelijk wordt gerealiseerd. Volgens de NOS scheelt die variant de schatkist de komende jaren 11 tot 25 miljard euro. Geld dat, als het kabinet zich aan zijn begrotingsregels houdt, ergens anders vandaan moet komen.

En we krijgen nu alvast een aardige aanwijzing waar ergens anders kan zijn. Bij arbeid dus, en daarmee bij mensen met een uitkering. Want werken moet lonen.

Daarmee wordt ook duidelijk wat de VVD werkelijk bedoelt met de slogan. Niet dat werkenden zo min mogelijk belasting moeten betalen. Niet dat inkomen uit arbeid gunstiger moet worden behandeld dan inkomen uit vermogen. De partij zegt zelf expliciet dat zij geen hogere belasting op vermogen wil.

Werken moet lonen betekent vooral dat mensen die níét werken minder moeten krijgen: lagere uitkeringen, minder sociale zekerheid, een grotere financiële afstand tot mensen met een baan. Want als werken echt het uitgangspunt was, zou je de huidige bezuinigingen niet zo vormgeven.

Maar ja. VVD hè. Het wordt hoog tijd dat links de term terugpakt en er de VVD mee om de oren gaat slaan.