<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: techaiwire</title>
    <description>The latest articles on DEV Community by techaiwire (@techaiwire).</description>
    <link>https://dev.to/techaiwire</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4114781%2F70285ce6-a546-43c0-ac5c-6d9b40cd574f.png</url>
      <title>DEV Community: techaiwire</title>
      <link>https://dev.to/techaiwire</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/techaiwire"/>
    <language>en</language>
    <item>
      <title>BragJack: one extension can hijack browser AI agents</title>
      <dc:creator>techaiwire</dc:creator>
      <pubDate>Mon, 28 Sep 2026 18:17:21 +0000</pubDate>
      <link>https://dev.to/techaiwire/bragjack-one-extension-can-hijack-browser-ai-agents-23c4</link>
      <guid>https://dev.to/techaiwire/bragjack-one-extension-can-hijack-browser-ai-agents-23c4</guid>
      <description>&lt;p&gt;A single malicious browser extension can take control of the AI assistants now built into web browsers, security researcher Gal Weizman of Forever Security has shown. He calls the attack BragJack. It worked against five products: Gemini in Google Chrome, Microsoft Edge's assistant, Perplexity Comet, Opera Neon and Anthropic's Claude in Chrome. The attack needs no clicks from the victim once the extension is installed.&lt;/p&gt;

&lt;p&gt;This matters because browser AI agents hold far more power than a normal web page. They can see the screen, read files and act on the user's behalf. BragJack hands that power to an extension that was never meant to have it.&lt;/p&gt;

&lt;h2&gt;
  
  
  How the attack works
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://thehackernews.com/2026/09/one-extension-could-hijack-ai.html" rel="noopener noreferrer"&gt;The Hacker News explains&lt;/a&gt; that a browser AI assistant is split in two. A local part runs in the browser, with access to the screen, files, camera and microphone. A remote part runs on the vendor's servers and does the thinking. The two talk over a channel each side trusts.&lt;/p&gt;

&lt;p&gt;BragJack attacks that channel. It uses two extension permissions: one that changes page content and one called declarativeNetRequest. That second permission lets an extension rewrite network requests with rules the browser applies for it. It is the API that replaced the older webRequest system in Manifest V3. That extension format became mandatory when Google &lt;a href="https://techaiwire.com/articles/google-removes-manifest-v2-extensions-chrome-web-store/" rel="noopener noreferrer"&gt;removed every Manifest V2 extension from its store&lt;/a&gt; earlier this month.&lt;/p&gt;

&lt;p&gt;According to &lt;a href="https://www.bleepingcomputer.com/news/security/bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions/" rel="noopener noreferrer"&gt;BleepingComputer&lt;/a&gt;, the extension uses these rules to change security headers and redirect JavaScript files into the browser's privileged AI components. Weizman told BleepingComputer that "browser extensions can manipulate web traffic and pages that these privileged components trust."&lt;/p&gt;

&lt;p&gt;Weizman calls the technique "Prompt Forcing." Older attacks hid instructions inside a web page and hoped the AI would obey them. Prompt Forcing instead pushes a complete prompt into the agent through a channel the agent already trusts.&lt;/p&gt;

&lt;h2&gt;
  
  
  What an attacker could do
&lt;/h2&gt;

&lt;p&gt;BleepingComputer lists what the researcher achieved. A malicious extension could read local files, take screenshots and turn on the camera and microphone. It could also browse the victim's history, intercept communications and steer the AI agent to act for the victim.&lt;/p&gt;

&lt;p&gt;The Hacker News adds details per product. On Chrome, the flaw let an extension read local files, use the camera and microphone, take screenshots and leak profile data. On Edge, it used a race condition, a timing gap between the assistant's "think" and "act" steps, to take over the agent.&lt;/p&gt;

&lt;h2&gt;
  
  
  Which browsers are fixed
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;Identifier&lt;/th&gt;
&lt;th&gt;Severity&lt;/th&gt;
&lt;th&gt;Status&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Chrome (Gemini)&lt;/td&gt;
&lt;td&gt;CVE-2026-0628&lt;/td&gt;
&lt;td&gt;CVSS 8.8&lt;/td&gt;
&lt;td&gt;Fixed in 143.0.7499.192, January 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Microsoft Edge&lt;/td&gt;
&lt;td&gt;CVE-2026-55945&lt;/td&gt;
&lt;td&gt;CVSS 4.2&lt;/td&gt;
&lt;td&gt;Fixed in 150.0.4078.48, July 2, 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Perplexity Comet&lt;/td&gt;
&lt;td&gt;None assigned&lt;/td&gt;
&lt;td&gt;Not given&lt;/td&gt;
&lt;td&gt;No fix confirmed&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Opera Neon&lt;/td&gt;
&lt;td&gt;None assigned&lt;/td&gt;
&lt;td&gt;Not given&lt;/td&gt;
&lt;td&gt;No fix confirmed&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Claude in Chrome&lt;/td&gt;
&lt;td&gt;None assigned&lt;/td&gt;
&lt;td&gt;Not given&lt;/td&gt;
&lt;td&gt;No fix confirmed&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;CVSS is the standard 0-to-10 scale security teams use to rank a bug's danger. The Hacker News says the Chrome flaw was first described publicly in March 2026 under the name "GlicJack."&lt;/p&gt;

&lt;p&gt;All five vendors paid bug bounties, over $20,000 in total, with single payments from $600 to $7,000. The two reports disagree on how the money was split. BleepingComputer lists Perplexity's payment as $600. The Hacker News lists Perplexity at $7,000 and Anthropic at $600.&lt;/p&gt;

&lt;h2&gt;
  
  
  What this means for developers
&lt;/h2&gt;

&lt;p&gt;Update Chrome and Edge first. Chrome needs version 143.0.7499.192 or later and Edge needs 150.0.4078.48 or later. Both fixes shipped months ago, so a current browser is already safe from those two CVEs.&lt;/p&gt;

&lt;p&gt;For Comet, Opera Neon and Claude in Chrome, neither report confirms a fix. If your team uses them, keep them updated and watch each vendor's release notes.&lt;/p&gt;

&lt;p&gt;Audit installed extensions, especially on machines where an AI agent has file or camera access. BragJack starts from an extension the user chose to install. An extension that asks for both page-modification and declarativeNetRequest permissions now deserves a closer look than it did last year.&lt;/p&gt;

&lt;p&gt;If you build an AI browser agent, treat the channel between its local and remote halves as hostile ground. Extensions can rewrite requests and headers on that path. Authenticating those messages, instead of trusting whatever arrives, narrows what an injected prompt can do.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was first published on &lt;a href="https://techaiwire.com/articles/bragjack-extension-hijacks-browser-ai-agents/" rel="noopener noreferrer"&gt;Tech AI Wire&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Also available in
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://techaiwire.com/de/articles/bragjack-extension-hijacks-browser-ai-agents/" rel="noopener noreferrer"&gt;Deutsch&lt;/a&gt; · &lt;a href="https://techaiwire.com/ja/articles/bragjack-extension-hijacks-browser-ai-agents/" rel="noopener noreferrer"&gt;日本語&lt;/a&gt; · &lt;a href="https://techaiwire.com/fr/articles/bragjack-extension-hijacks-browser-ai-agents/" rel="noopener noreferrer"&gt;Français&lt;/a&gt; · &lt;a href="https://techaiwire.com/es/articles/bragjack-extension-hijacks-browser-ai-agents/" rel="noopener noreferrer"&gt;Español&lt;/a&gt; · &lt;a href="https://techaiwire.com/pt/articles/bragjack-extension-hijacks-browser-ai-agents/" rel="noopener noreferrer"&gt;Português&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Related on Tech AI Wire
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://techaiwire.com/articles/google-removes-manifest-v2-extensions-chrome-web-store/" rel="noopener noreferrer"&gt;Google pulls every Manifest V2 extension from the Chrome Web Store&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Sources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://www.bleepingcomputer.com/news/security/bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions/" rel="noopener noreferrer"&gt;BragJack attacks hijack AI browser agents through malicious extensions&lt;/a&gt; - BleepingComputer&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://thehackernews.com/2026/09/one-extension-could-hijack-ai.html" rel="noopener noreferrer"&gt;One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude&lt;/a&gt; - The Hacker News&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>security</category>
      <category>browsers</category>
      <category>aiagents</category>
      <category>extensions</category>
    </item>
    <item>
      <title>PeopleSoft CVE-2026-35273: one encoded letter beats WAFs</title>
      <dc:creator>techaiwire</dc:creator>
      <pubDate>Mon, 28 Sep 2026 18:14:43 +0000</pubDate>
      <link>https://dev.to/techaiwire/peoplesoft-cve-2026-35273-one-encoded-letter-beats-wafs-12d0</link>
      <guid>https://dev.to/techaiwire/peoplesoft-cve-2026-35273-one-encoded-letter-beats-wafs-12d0</guid>
      <description>&lt;p&gt;The hacking group ShinyHunters is breaking into Oracle PeopleSoft servers again, using a flaw Oracle patched in June. This time the attackers slip past web application firewalls by changing a single letter. They write the "P" in &lt;code&gt;/PSEMHUB/&lt;/code&gt; as &lt;code&gt;%50&lt;/code&gt;, its URL-encoded form. Firewall rules that block the literal path miss it, while the server decodes the request and runs the attack anyway.&lt;/p&gt;

&lt;p&gt;Google's threat intelligence unit Mandiant described the new wave in a &lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft" rel="noopener noreferrer"&gt;report published September 25, 2026&lt;/a&gt;. It says the attackers planted web shells on "dozens of systems globally." A web shell is a small script that gives an outsider a command line on the server.&lt;/p&gt;

&lt;h2&gt;
  
  
  The flaw behind it
&lt;/h2&gt;

&lt;p&gt;The bug is CVE-2026-35273. It sits in PeopleSoft's Environment Management Hub, or PSEMHUB, a component that manages PeopleSoft installations. &lt;a href="https://thehackernews.com/2026/09/attackers-bypass-wafs-to-exploit-oracle.html" rel="noopener noreferrer"&gt;The Hacker News reports&lt;/a&gt; a CVSS score of 9.8 out of 10. CVSS is the standard scale security teams use to rank how dangerous a flaw is.&lt;/p&gt;

&lt;p&gt;Mandiant calls it a Java deserialization flaw. The server takes a packaged Java object from a request and rebuilds it without checking it first. A crafted object can make the server run the attacker's code. No login is needed.&lt;/p&gt;

&lt;p&gt;Mandiant tracks the group as UNC6240. It says the group first used the bug as a zero-day, meaning before any fix existed, between May 27 and June 9, 2026. Most victims then were universities. Oracle shipped an emergency Security Alert on June 10.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://www.securityweek.com/google-warns-of-shinyhunters-fresh-oracle-peoplesoft-campaign/" rel="noopener noreferrer"&gt;SecurityWeek reports&lt;/a&gt; that the June wave hit more than 100 PeopleSoft customers in education. It names the University of Nottingham, the insurance regulator NAIC and Nissan among the victims.&lt;/p&gt;

&lt;h2&gt;
  
  
  How one letter gets past the firewall
&lt;/h2&gt;

&lt;p&gt;After June, many organizations added firewall rules that block any request to &lt;code&gt;/PSEMHUB/&lt;/code&gt;. That stopped the old exploit. It did not fix the bug.&lt;/p&gt;

&lt;p&gt;Mandiant explains the gap: "Many WAF and reverse proxy rules match the literal path before URL decoding." The PeopleSoft server, by contrast, decodes the path first. So &lt;code&gt;/%50SEMHUB/&lt;/code&gt; looks harmless to the firewall and identical to &lt;code&gt;/PSEMHUB/&lt;/code&gt; for the server.&lt;/p&gt;

&lt;p&gt;Once inside, the group deployed these tools, according to Mandiant:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Tool&lt;/th&gt;
&lt;th&gt;What it does&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;x.jsp&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Runs commands sent in a POST request&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;code&gt;u.jsp&lt;/code&gt;, &lt;code&gt;u2.jsp&lt;/code&gt;
&lt;/td&gt;
&lt;td&gt;Uploads files in 150 KB pieces&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;code&gt;tunnel.jsp&lt;/code&gt;, &lt;code&gt;tunnel.jspx&lt;/code&gt;
&lt;/td&gt;
&lt;td&gt;Neo-reGeorg tunnel into the internal network&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;Ple64.exe&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Tampered Light Alloy media-player installer carrying the SIDEEYE backdoor&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;MeshAgent&lt;/td&gt;
&lt;td&gt;Remote-management agent kept for Linux persistence&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The new wave reaches well beyond universities. Mandiant lists technology, IT services, healthcare, agriculture, transportation and government as well as higher education.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why ShinyHunters matters here
&lt;/h2&gt;

&lt;p&gt;ShinyHunters runs data-theft extortion. It steals data, then threatens to publish it unless the victim pays, SecurityWeek says. Google advises organizations to "prepare for extortion communications" and watch for stolen data appearing online, SecurityWeek notes.&lt;/p&gt;

&lt;h2&gt;
  
  
  What this means for developers
&lt;/h2&gt;

&lt;p&gt;Install Oracle's patch for CVE-2026-35273. Mandiant says to apply the fix rather than rely on firewall filtering, and this campaign shows why. A blocklist rule matched on a literal string is one encoding trick away from failing.&lt;/p&gt;

&lt;p&gt;If you do not use the Environment Management Hub, disable it or remove PSEMHUB entirely, as Mandiant advises. A component that is not deployed cannot be exploited.&lt;/p&gt;

&lt;p&gt;Search your WebLogic logs for both &lt;code&gt;/PSEMHUB/&lt;/code&gt; and encoded forms such as &lt;code&gt;/%50SEMHUB/&lt;/code&gt;, especially POST requests to the hub. Mandiant also says to check the &lt;code&gt;PSEMHUB.war&lt;/code&gt; folder for files you did not put there. Look for unexpected MeshCentral agents too.&lt;/p&gt;

&lt;p&gt;If you find signs of entry, rotate database and cloud credentials. An attacker with a shell on PeopleSoft may have read the connection details it uses.&lt;/p&gt;

&lt;p&gt;The wider lesson applies to any web application behind a firewall. Rules that match paths should normalize the request first, decoding it the way the server will. Otherwise the firewall and the server are reading two different requests.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was first published on &lt;a href="https://techaiwire.com/articles/peoplesoft-cve-2026-35273-shinyhunters-waf-bypass/" rel="noopener noreferrer"&gt;Tech AI Wire&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Also available in
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://techaiwire.com/de/articles/peoplesoft-cve-2026-35273-shinyhunters-waf-bypass/" rel="noopener noreferrer"&gt;Deutsch&lt;/a&gt; · &lt;a href="https://techaiwire.com/ja/articles/peoplesoft-cve-2026-35273-shinyhunters-waf-bypass/" rel="noopener noreferrer"&gt;日本語&lt;/a&gt; · &lt;a href="https://techaiwire.com/fr/articles/peoplesoft-cve-2026-35273-shinyhunters-waf-bypass/" rel="noopener noreferrer"&gt;Français&lt;/a&gt; · &lt;a href="https://techaiwire.com/es/articles/peoplesoft-cve-2026-35273-shinyhunters-waf-bypass/" rel="noopener noreferrer"&gt;Español&lt;/a&gt; · &lt;a href="https://techaiwire.com/pt/articles/peoplesoft-cve-2026-35273-shinyhunters-waf-bypass/" rel="noopener noreferrer"&gt;Português&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Sources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft" rel="noopener noreferrer"&gt;ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft&lt;/a&gt; - Google Cloud (Mandiant)&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://www.securityweek.com/google-warns-of-shinyhunters-fresh-oracle-peoplesoft-campaign/" rel="noopener noreferrer"&gt;Google Warns of ShinyHunters' Fresh Oracle PeopleSoft Campaign&lt;/a&gt; - SecurityWeek&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://thehackernews.com/2026/09/attackers-bypass-wafs-to-exploit-oracle.html" rel="noopener noreferrer"&gt;Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells&lt;/a&gt; - The Hacker News&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>security</category>
      <category>infrastructure</category>
    </item>
    <item>
      <title>DRAM and NAND prices climb again as AI takes capacity</title>
      <dc:creator>techaiwire</dc:creator>
      <pubDate>Sun, 27 Sep 2026 17:50:34 +0000</pubDate>
      <link>https://dev.to/techaiwire/dram-and-nand-prices-climb-again-as-ai-takes-capacity-1lh3</link>
      <guid>https://dev.to/techaiwire/dram-and-nand-prices-climb-again-as-ai-takes-capacity-1lh3</guid>
      <description>&lt;p&gt;Memory prices are still rising, and the reason is that AI data centers are buying the capacity that used to make ordinary RAM. &lt;a href="https://www.trendforce.com/presscenter/news/20260703-13134.html" rel="noopener noreferrer"&gt;TrendForce&lt;/a&gt; projected on July 3, 2026 that DRAM contract prices would rise another 13% to 18% in the third quarter, with NAND flash up 10% to 15%. For developers that is not a market curiosity. It is the reason a build machine, a cloud instance and a test phone all cost more than they did a year ago.&lt;/p&gt;

&lt;p&gt;DRAM is the working memory a computer uses while it runs. NAND flash is the storage in an SSD or a phone. Contract prices are what large buyers pay, so they set what laptops and servers cost months later.&lt;/p&gt;

&lt;h2&gt;
  
  
  How far prices have moved
&lt;/h2&gt;

&lt;p&gt;The third-quarter rise looks small only against what came before it. &lt;a href="https://sourceability.com/post/tracking-memory-price-increases-across-the-last-several-quarters" rel="noopener noreferrer"&gt;Sourceability&lt;/a&gt;, a components distributor that tracks these contracts, put the earlier jumps far higher.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Period&lt;/th&gt;
&lt;th&gt;DRAM&lt;/th&gt;
&lt;th&gt;NAND&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Q4 2025 to Q1 2026&lt;/td&gt;
&lt;td&gt;Up 80-90%&lt;/td&gt;
&lt;td&gt;Sharp spikes on delivery gaps&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Early 2025 to December 2025&lt;/td&gt;
&lt;td&gt;-&lt;/td&gt;
&lt;td&gt;Up 246% cumulative&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Q3 2026 (TrendForce projection)&lt;/td&gt;
&lt;td&gt;Up 13-18%&lt;/td&gt;
&lt;td&gt;Up 10-15%&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;One line makes the scale concrete. Sourceability records DDR5 moving from $6.84 in September 2025 to $27.20 in December 2025. That is roughly four times the price in three months.&lt;/p&gt;

&lt;p&gt;NAND moved in bursts rather than a steady climb. About 70% of its 2025 increase landed in the final 60 days of that year, when delivery disruptions pushed weekly prices up by 50% to 100%.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why AI took the capacity
&lt;/h2&gt;

&lt;p&gt;The cause is not a factory fire or a shipping crisis. It is a deliberate choice by three companies about what to build.&lt;/p&gt;

&lt;p&gt;Samsung and SK Hynix together hold about 70% of the DRAM market, and Sourceability reports neither has signaled aggressive plans to expand capacity. Micron can fill only 55% to 60% of what its core customers ask for, and its new Idaho plant does not come online until 2027.&lt;/p&gt;

&lt;p&gt;The mechanism inside the fab is the part worth understanding. High-bandwidth memory, the stacked DRAM that sits beside an AI accelerator, eats about three times the capacity of the same amount of DDR5. Every wafer moved to HBM removes roughly three wafers of ordinary memory from the market.&lt;/p&gt;

&lt;p&gt;Demand keeps pulling in that direction. Sourceability puts 2026 capital spending by the top eight cloud providers above $600 billion, up 40% year over year.&lt;/p&gt;

&lt;p&gt;TrendForce adds a detail that explains why this is not only a GPU story. Agentic AI workloads run on general-purpose x86 servers with RDIMM memory, not only on accelerators. So the same wave raises demand for plain server memory too.&lt;/p&gt;

&lt;h2&gt;
  
  
  What it does to the price of a device
&lt;/h2&gt;

&lt;p&gt;Memory used to be a modest line on a bill of materials. It is now one of the largest.&lt;/p&gt;

&lt;p&gt;HP's chief financial officer said memory moved from 15% to 18% of a PC's parts cost to around 35% in 2026. At the ISSCC conference in February 2026, MediaTek chief executive Rick Tsai put it more bluntly: "Memory now accounts for roughly 50% of the total BOM."&lt;/p&gt;

&lt;p&gt;Kingston's data center SSD business manager said in December 2025 that "NAND prices had surged 246% since the start of 2025."&lt;/p&gt;

&lt;p&gt;TrendForce expects the rally to run past 2028.&lt;/p&gt;

&lt;h2&gt;
  
  
  What this means for developers
&lt;/h2&gt;

&lt;p&gt;Treat memory as a budget line that now moves, not a constant. If you size cloud instances or CI runners by habit, re-check them. RAM-heavy instance families are where provider price changes land first. An over-provisioned runner fleet costs more than it did last year.&lt;/p&gt;

&lt;p&gt;Buy hardware earlier than you otherwise would. That is unusual advice, and it follows from the forecasts rather than from panic. When the analyst who called the last four quarters expects the rally past 2028, waiting for a better price is a bet against the only published view.&lt;/p&gt;

&lt;p&gt;Local AI work is hit hardest. Running models on your own machine is mostly a question of how much memory you can afford, and that is exactly the component being rationed. Apple's recent &lt;a href="https://techaiwire.com/articles/apple-mac-mini-m6-mac-studio-m5-ultra-local-ai/" rel="noopener noreferrer"&gt;Mac mini and Mac Studio refresh put more memory bandwidth behind local AI&lt;/a&gt;, and machines like those get more expensive as the same shortage works through.&lt;/p&gt;

&lt;p&gt;There is a software response too. Memory efficiency has been an unfashionable thing to optimize for a decade of cheap RAM. Profiling a service's actual working set, and fitting it into a smaller instance, now pays back in real money rather than in tidiness.&lt;/p&gt;

&lt;p&gt;Watch DDR4 specifically if you maintain older fleets. TrendForce notes Taiwanese suppliers are expanding DDR4 output, but not by enough to offset cuts elsewhere. Legacy parts can get scarce faster than current ones, because nobody is investing in them.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was first published on &lt;a href="https://techaiwire.com/articles/dram-nand-price-surge-2026-ai-capacity/" rel="noopener noreferrer"&gt;Tech AI Wire&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Also available in
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://techaiwire.com/de/articles/dram-nand-price-surge-2026-ai-capacity/" rel="noopener noreferrer"&gt;Deutsch&lt;/a&gt; · &lt;a href="https://techaiwire.com/ja/articles/dram-nand-price-surge-2026-ai-capacity/" rel="noopener noreferrer"&gt;日本語&lt;/a&gt; · &lt;a href="https://techaiwire.com/fr/articles/dram-nand-price-surge-2026-ai-capacity/" rel="noopener noreferrer"&gt;Français&lt;/a&gt; · &lt;a href="https://techaiwire.com/es/articles/dram-nand-price-surge-2026-ai-capacity/" rel="noopener noreferrer"&gt;Español&lt;/a&gt; · &lt;a href="https://techaiwire.com/pt/articles/dram-nand-price-surge-2026-ai-capacity/" rel="noopener noreferrer"&gt;Português&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Related on Tech AI Wire
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://techaiwire.com/articles/apple-mac-mini-m6-mac-studio-m5-ultra-local-ai/" rel="noopener noreferrer"&gt;New Mac mini and Mac Studio put more memory bandwidth behind local AI&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Sources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://www.trendforce.com/presscenter/news/20260703-13134.html" rel="noopener noreferrer"&gt;AI Server Demand Continues to Support Memory Prices in 3Q26&lt;/a&gt; - TrendForce&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://sourceability.com/post/tracking-memory-price-increases-across-the-last-several-quarters" rel="noopener noreferrer"&gt;Tracking memory price increases across the last several quarters&lt;/a&gt; - Sourceability&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>hardware</category>
      <category>pricing</category>
      <category>datacenters</category>
    </item>
    <item>
      <title>India smartphone prices up 21%, the steepest anywhere</title>
      <dc:creator>techaiwire</dc:creator>
      <pubDate>Sun, 27 Sep 2026 17:47:57 +0000</pubDate>
      <link>https://dev.to/techaiwire/india-smartphone-prices-up-21-the-steepest-anywhere-37j2</link>
      <guid>https://dev.to/techaiwire/india-smartphone-prices-up-21-the-steepest-anywhere-37j2</guid>
      <description>&lt;p&gt;Smartphone prices in India have risen 21% during 2026, the steepest increase of any market, according to Counterpoint Research figures &lt;a href="https://www.latestly.com/technology/india-smartphone-prices-soar-21-in-2026-know-why-your-next-phone-may-cost-more-7596940.html" rel="noopener noreferrer"&gt;reported by LatestLY&lt;/a&gt; on September 9, 2026. The world average is 15%. The cause is the memory shortage, and the effect on developers is specific: the cheapest Android phones in the largest Android market are disappearing.&lt;/p&gt;

&lt;p&gt;India matters to anyone shipping an Android app. It is a huge market built largely on inexpensive handsets, so what happens to entry-level pricing there changes the devices real users hold.&lt;/p&gt;

&lt;h2&gt;
  
  
  What actually got more expensive
&lt;/h2&gt;

&lt;p&gt;At least 13 brands have raised prices, &lt;a href="https://gadgets.beebom.com/guides/india-smartphone-price-hike-roundup" rel="noopener noreferrer"&gt;Beebom&lt;/a&gt; reports, among them Oppo, Realme, Vivo, iQOO, Nothing, Xiaomi, Redmi, Poco, Motorola and Lava. Increases run from Rs 500 to Rs 8,000 per device.&lt;/p&gt;

&lt;p&gt;The rises came in waves rather than all at once. GizmoChina recorded a batch effective May 1, 2026.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Phone&lt;/th&gt;
&lt;th&gt;Increase&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Nothing Phone (4a) Pro&lt;/td&gt;
&lt;td&gt;Rs 5,000&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Nothing Phone (4a)&lt;/td&gt;
&lt;td&gt;Rs 3,000&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;OnePlus 15&lt;/td&gt;
&lt;td&gt;Rs 5,000&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;OnePlus 15R&lt;/td&gt;
&lt;td&gt;Rs 2,500&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Xiaomi Redmi Note 15 Pro&lt;/td&gt;
&lt;td&gt;Rs 2,000, to Rs 31,999&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;A second wave followed in late August and early September, with changes effective August 18 and 19 and again on September 1 to 3.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why memory is the reason
&lt;/h2&gt;

&lt;p&gt;The component behind it is the same one raising server and PC costs. Memory makers have moved capacity toward high-bandwidth memory for AI data centers, leaving less for phones.&lt;/p&gt;

&lt;p&gt;The two reports differ on how to state the size of that move. Beebom describes global memory prices spiking 300% in three months, while LatestLY reports memory chip costs up more than 300% year over year. Both point the same direction, but the periods are not the same.&lt;/p&gt;

&lt;p&gt;Nothing's chief executive Carl Pei gave a forward number. He said "memory module costs will go up by 5x by the end of 2026."&lt;/p&gt;

&lt;p&gt;Xiaomi India's chief business officer Sandeep Singh Arora expects no relief this year. "The chip and memory shortage will persist into the second half of 2026, particularly affecting the festive season with further price increases," he said.&lt;/p&gt;

&lt;p&gt;IDC and Omdia both project component prices staying high into 2027 and 2028.&lt;/p&gt;

&lt;h2&gt;
  
  
  The budget segment is the casualty
&lt;/h2&gt;

&lt;p&gt;The most important number in these reports is not the 21%. It is what happened underneath it.&lt;/p&gt;

&lt;p&gt;Counterpoint recorded a 45% fall in shipments of phones under Rs 15,000 in the second quarter of 2026. That is the segment where a Rs 2,000 increase decides whether someone buys at all.&lt;/p&gt;

&lt;p&gt;The market is expected to shrink 13% to 16% in 2026 as a result. Refurbished phone sales are forecast to grow 16% over the same period, which tells you where those buyers went.&lt;/p&gt;

&lt;h2&gt;
  
  
  What this means for developers
&lt;/h2&gt;

&lt;p&gt;Expect your Indian install base to get older, not newer. When new budget phones stop selling and refurbished ones grow 16%, the practical result is that the devices in circulation stay in service longer. Check your analytics for the actual spread of Android versions and RAM sizes before you raise a minimum SDK level or drop a device tier.&lt;/p&gt;

&lt;p&gt;Test on the low end again. A 45% collapse in sub-Rs 15,000 shipments means the phones already out there are the ones you must run on. If your test matrix quietly drifted toward current flagships, it is now measuring a market that is shrinking rather than the one you serve.&lt;/p&gt;

&lt;p&gt;Memory footprint is the thing to optimize. Manufacturers responding to these costs have two options: raise prices or cut specifications, and cutting RAM is the usual choice. An app that needs a lot of memory will be the one the system kills first on a 4GB device.&lt;/p&gt;

&lt;p&gt;Budget your own test hardware differently. Device labs are bought at retail, so the same increases hit your procurement. Buying the cheap handsets now is cheaper than buying them next year. Both the &lt;a href="https://techaiwire.com/articles/iqoo-z11-india-launch-price-specs/" rel="noopener noreferrer"&gt;iQOO Z11 at Rs 34,999&lt;/a&gt; and the &lt;a href="https://techaiwire.com/articles/vivo-t5-india-launch-september-2-specs/" rel="noopener noreferrer"&gt;vivo T5 with its 7,050mAh battery&lt;/a&gt; launched before this latest wave landed.&lt;/p&gt;

&lt;p&gt;Watch the festive quarter for the real signal. Arora named it specifically, and India's biggest buying season is the honest test of whether these prices hold or whether brands absorb them to move units.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was first published on &lt;a href="https://techaiwire.com/articles/india-smartphone-price-rise-21-percent-memory-costs/" rel="noopener noreferrer"&gt;Tech AI Wire&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Also available in
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://techaiwire.com/de/articles/india-smartphone-price-rise-21-percent-memory-costs/" rel="noopener noreferrer"&gt;Deutsch&lt;/a&gt; · &lt;a href="https://techaiwire.com/ja/articles/india-smartphone-price-rise-21-percent-memory-costs/" rel="noopener noreferrer"&gt;日本語&lt;/a&gt; · &lt;a href="https://techaiwire.com/fr/articles/india-smartphone-price-rise-21-percent-memory-costs/" rel="noopener noreferrer"&gt;Français&lt;/a&gt; · &lt;a href="https://techaiwire.com/es/articles/india-smartphone-price-rise-21-percent-memory-costs/" rel="noopener noreferrer"&gt;Español&lt;/a&gt; · &lt;a href="https://techaiwire.com/pt/articles/india-smartphone-price-rise-21-percent-memory-costs/" rel="noopener noreferrer"&gt;Português&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Related on Tech AI Wire
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://techaiwire.com/articles/iqoo-z11-india-launch-price-specs/" rel="noopener noreferrer"&gt;iQOO Z11 launches in India at ₹34,999 with a different chip&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://techaiwire.com/articles/vivo-t5-india-launch-september-2-specs/" rel="noopener noreferrer"&gt;vivo T5 arrives September 2 with a 7,050mAh battery and 144Hz screen&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Sources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://gadgets.beebom.com/guides/india-smartphone-price-hike-roundup" rel="noopener noreferrer"&gt;India Smartphone Price Hike Tracker: List of Phones with Revised Prices&lt;/a&gt; - Beebom&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://www.latestly.com/technology/india-smartphone-prices-soar-21-in-2026-know-why-your-next-phone-may-cost-more-7596940.html" rel="noopener noreferrer"&gt;India Smartphone Prices Soar 21% in 2026&lt;/a&gt; - LatestLY&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://www.gizmochina.com/2026/05/03/smartphone-price-hike-india-2026-oneplus-nothing-xiaomi/" rel="noopener noreferrer"&gt;Smartphone Prices Just Skyrocketed in India: Here's What Got Expensive&lt;/a&gt; - GizmoChina&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>smartphones</category>
      <category>india</category>
      <category>pricing</category>
    </item>
    <item>
      <title>ZLUDA adds cuFFT support for AMD GPUs via hipFFT</title>
      <dc:creator>techaiwire</dc:creator>
      <pubDate>Sun, 27 Sep 2026 17:45:18 +0000</pubDate>
      <link>https://dev.to/techaiwire/zluda-adds-cufft-support-for-amd-gpus-via-hipfft-4he9</link>
      <guid>https://dev.to/techaiwire/zluda-adds-cufft-support-for-amd-gpus-via-hipfft-4he9</guid>
      <description>&lt;p&gt;A new pull request for ZLUDA, the open-source layer that runs NVIDIA CUDA software on AMD graphics cards, adds support for cuFFT. That is NVIDIA's library for fast Fourier transforms, a type of math used to pull frequency information out of a signal. The change merged into the project on September 22, 2026. &lt;a href="https://www.phoronix.com/news/ZLUDA-cuFFT-APIs-hipFFT" rel="noopener noreferrer"&gt;Phoronix&lt;/a&gt; reports it lets Folding@Home's distributed-computing client run CUDA-based work on AMD Radeon GPUs with no changes to the software itself.&lt;/p&gt;

&lt;p&gt;A Fourier transform turns a signal, such as an image or a stretch of audio, into a list of the frequencies it contains. Scientific software, some machine-learning pipelines, and Folding@Home's protein-folding client all lean on cuFFT for that math. Until now, that code path only ran on NVIDIA hardware.&lt;/p&gt;

&lt;h2&gt;
  
  
  How the translation works
&lt;/h2&gt;

&lt;p&gt;ZLUDA catches the calls a program makes to NVIDIA's CUDA libraries and reroutes them to matching AMD tools instead. For cuFFT, the &lt;a href="https://github.com/vosen/ZLUDA/pull/672" rel="noopener noreferrer"&gt;merged pull request&lt;/a&gt; forwards those calls to hipFFT, AMD's own FFT library.&lt;/p&gt;

&lt;p&gt;One detail needed extra care. CUDA identifies each FFT plan with a 32-bit number, called a handle. hipFFT instead uses a raw memory pointer for the same job. Truncating or reinterpreting that pointer directly could crash the program or quietly return wrong results. So the pull request builds a synchronized registry that maps CUDA's numeric handles to hipFFT's pointers instead. hipFFT itself loads at runtime, with separate setup code for Windows and Linux.&lt;/p&gt;

&lt;p&gt;The port covers only the cuFFT functions that have a direct hipFFT match, not the whole library. The pull request lists what was tested before the merge:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Area tested&lt;/th&gt;
&lt;th&gt;Result&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Handle lifecycle management&lt;/td&gt;
&lt;td&gt;Passed&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Workspace configuration&lt;/td&gt;
&lt;td&gt;Passed&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;64-bit transform planning&lt;/td&gt;
&lt;td&gt;Passed&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;3D real-to-complex transforms&lt;/td&gt;
&lt;td&gt;Passed&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Folding@Home Core24 and Core27 work units&lt;/td&gt;
&lt;td&gt;Ran successfully&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  What still needs work
&lt;/h2&gt;

&lt;p&gt;ZLUDA maintainer vosen flagged three issues while reviewing the change, according to the pull request. Handle IDs could in theory overflow. A global lock could serialize FFT operations more than needed. And some error codes coming back from hipFFT are not yet mapped to the matching CUDA error, a gap the review marked medium-to-high severity.&lt;/p&gt;

&lt;p&gt;Testing is also uneven across platforms. Windows builds and AMD hardware tests both passed, and the code compiles cleanly on Linux. But the pull request's author, AmosKito1, wrote that they had "limited Linux testing capacity." The Linux path has seen less real-world use than the Windows one so far.&lt;/p&gt;

&lt;h2&gt;
  
  
  What this means for developers
&lt;/h2&gt;

&lt;p&gt;If your software calls cuFFT and you want to try it on AMD hardware through ZLUDA, check first that every function you use has a direct hipFFT match. The port does not cover the full API yet. Expect the Windows path to be better tested than Linux for now. Hold off on anything long-running or safety-critical until the handle-overflow and error-mapping gaps that vosen flagged get closed.&lt;/p&gt;

&lt;p&gt;Folding@Home users get the clearest benefit today. Their AMD cards can now pick up CUDA work units that need cuFFT, work that previously went only to NVIDIA GPUs. Anyone maintaining GPU-accelerated scientific or signal-processing code built on cuFFT now has a second hardware target to test against, without rewriting for a native AMD library.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was first published on &lt;a href="https://techaiwire.com/articles/zluda-cufft-amd-gpus-hipfft/" rel="noopener noreferrer"&gt;Tech AI Wire&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Also available in
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://techaiwire.com/de/articles/zluda-cufft-amd-gpus-hipfft/" rel="noopener noreferrer"&gt;Deutsch&lt;/a&gt; · &lt;a href="https://techaiwire.com/ja/articles/zluda-cufft-amd-gpus-hipfft/" rel="noopener noreferrer"&gt;日本語&lt;/a&gt; · &lt;a href="https://techaiwire.com/fr/articles/zluda-cufft-amd-gpus-hipfft/" rel="noopener noreferrer"&gt;Français&lt;/a&gt; · &lt;a href="https://techaiwire.com/es/articles/zluda-cufft-amd-gpus-hipfft/" rel="noopener noreferrer"&gt;Español&lt;/a&gt; · &lt;a href="https://techaiwire.com/pt/articles/zluda-cufft-amd-gpus-hipfft/" rel="noopener noreferrer"&gt;Português&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Sources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://www.phoronix.com/news/ZLUDA-cuFFT-APIs-hipFFT" rel="noopener noreferrer"&gt;ZLUDA Now Implements Some NVIDIA cuFFT APIs With hipFFT&lt;/a&gt; - Phoronix&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://github.com/vosen/ZLUDA/pull/672" rel="noopener noreferrer"&gt;Implement core cuFFT APIs with hipFFT (#672)&lt;/a&gt; - GitHub (vosen/ZLUDA)&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>nvidia</category>
      <category>hardware</category>
      <category>opensource</category>
    </item>
    <item>
      <title>SynthID's image watermark carries a 64-bit ID field</title>
      <dc:creator>techaiwire</dc:creator>
      <pubDate>Sun, 27 Sep 2026 17:42:41 +0000</pubDate>
      <link>https://dev.to/techaiwire/synthids-image-watermark-carries-a-64-bit-id-field-43p5</link>
      <guid>https://dev.to/techaiwire/synthids-image-watermark-carries-a-64-bit-id-field-43p5</guid>
      <description>&lt;p&gt;An essay published on brand.io on September 21, 2026, argues that AI content-watermarking systems have grown from simple "this was AI-generated" labels into something closer to tracking infrastructure. Its author calls the result a "spymark" rather than a watermark. The claim rests on one technical detail from Google DeepMind's own research paper on SynthID-Image. Each image's watermark payload is 136 bits long. Of those, 64 bits are described as a database ID. The other 72 bits handle error correction.&lt;/p&gt;

&lt;p&gt;Watermarking means quietly hiding information inside a file, such as a picture, an audio clip, or a block of text. A person cannot notice it, but a matching detector can read it back out. &lt;a href="https://ai.google.dev/responsible/docs/safeguards/synthid" rel="noopener noreferrer"&gt;SynthID&lt;/a&gt;, Google's watermarking system, is built into several of its image- and text-generation products.&lt;/p&gt;

&lt;h2&gt;
  
  
  What the paper describes versus what Google says it does
&lt;/h2&gt;

&lt;p&gt;The &lt;a href="https://arxiv.org/abs/2510.09263" rel="noopener noreferrer"&gt;SynthID-Image paper&lt;/a&gt; describes a 136-bit payload embedded into 512-by-512-pixel images: 64 bits for a database ID, plus 72 bits of error correction. The brand.io essay calls these "secret hidden signals imperceptible to humans." A 64-bit field is large enough to give a separate number to every image SynthID has ever watermarked. That size is why the essay treats the field as evidence the system could identify single images, not just flag that a picture is AI-made.&lt;/p&gt;

&lt;p&gt;Google's own public documentation describes something narrower. It says SynthID works by using "a pseudorandom function to augment model logits" as content is generated. That signal is applied "in a way that helps you determine if the text was generated by your model." It is a single yes-or-no signal, not an identifier tied to one person or one request. The documentation adds that models sharing a tokenizer also share one watermark and one detector. The same watermark covers every output from that model, not a unique one per user. Google's own material does not mention a database-ID field.&lt;/p&gt;

&lt;p&gt;The essay is careful about this gap. It presents the 64-bit field as a documented technical capability in the research paper, not as proof that Google or anyone else uses it to track specific people today. It says it found no public evidence that anyone does.&lt;/p&gt;

&lt;h2&gt;
  
  
  Other systems the essay names
&lt;/h2&gt;

&lt;p&gt;The essay makes the same argument about text and audio watermarks. It says SynthID's text version steers word choices during generation to create "a detectable statistical pattern" tied to the model. It adds that OpenAI has built a similar provenance signal into its own image and video output. For audio, it points to Audiowerk, an open-source watermarking tool dating to 2018. The essay says Audiowerk can "hide 128-bit payloads in audio and protect them with secret AES key." It also compares the idea to printer tracking dots. Many color laser printers have stamped this near-invisible pattern on pages since the 1980s. It encodes a printer's serial number plus the date and time of printing.&lt;/p&gt;

&lt;h2&gt;
  
  
  What this means for developers
&lt;/h2&gt;

&lt;p&gt;If you build on SynthID or a similar watermarking tool, read the underlying research paper before you tell your own users what the system does and does not record. A payload's technical capacity and a company's stated policy on using that capacity are two different things. This story shows they can diverge without either side lying: the field exists in the specification, and the company says it does not use the field for tracking.&lt;/p&gt;

&lt;p&gt;If you generate images, audio, or text at scale, check the watermarking library's specification for any identifier fields before you adopt it. Then write down, in plain language for your own users, what the watermark can and cannot be used to determine.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was first published on &lt;a href="https://techaiwire.com/articles/synthid-watermark-64-bit-id-field/" rel="noopener noreferrer"&gt;Tech AI Wire&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Also available in
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://techaiwire.com/de/articles/synthid-watermark-64-bit-id-field/" rel="noopener noreferrer"&gt;Deutsch&lt;/a&gt; · &lt;a href="https://techaiwire.com/ja/articles/synthid-watermark-64-bit-id-field/" rel="noopener noreferrer"&gt;日本語&lt;/a&gt; · &lt;a href="https://techaiwire.com/fr/articles/synthid-watermark-64-bit-id-field/" rel="noopener noreferrer"&gt;Français&lt;/a&gt; · &lt;a href="https://techaiwire.com/es/articles/synthid-watermark-64-bit-id-field/" rel="noopener noreferrer"&gt;Español&lt;/a&gt; · &lt;a href="https://techaiwire.com/pt/articles/synthid-watermark-64-bit-id-field/" rel="noopener noreferrer"&gt;Português&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Sources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://brand.io/article/spymarks/" rel="noopener noreferrer"&gt;Spymarks, Not Watermarks&lt;/a&gt; - brand.io&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://ai.google.dev/responsible/docs/safeguards/synthid" rel="noopener noreferrer"&gt;SynthID | Responsible Generative AI Toolkit&lt;/a&gt; - Google AI for Developers&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>privacy</category>
      <category>google</category>
      <category>aisafety</category>
    </item>
    <item>
      <title>Claude Opus 5.5 cuts output price to $20 per million</title>
      <dc:creator>techaiwire</dc:creator>
      <pubDate>Sun, 27 Sep 2026 17:40:04 +0000</pubDate>
      <link>https://dev.to/techaiwire/claude-opus-55-cuts-output-price-to-20-per-million-3nag</link>
      <guid>https://dev.to/techaiwire/claude-opus-55-cuts-output-price-to-20-per-million-3nag</guid>
      <description>&lt;p&gt;Anthropic released Claude Opus 5.5 on September 22, 2026. The model costs $4 per million input tokens and $20 per million output tokens. Anthropic's newsroom says it "performs at the level of Claude Fable 5.1 on most work and costs 40% less to run than Opus 5." For teams that run coding agents for hours, output tokens are the line on the bill that grows, so the price is the news.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://techcrunch.com/2026/09/22/anthropic-releases-opus-5-5-with-lower-prices-and-fable-level-performance/" rel="noopener noreferrer"&gt;TechCrunch reported&lt;/a&gt; that the $20 output price is down from $25 on the previous version. TechCrunch also said the model runs faster and needs less compute to do it.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Opus 5.5 costs
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Item&lt;/th&gt;
&lt;th&gt;Price per million tokens&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Input&lt;/td&gt;
&lt;td&gt;$4&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Output&lt;/td&gt;
&lt;td&gt;$20&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Cache write, 5 minutes&lt;/td&gt;
&lt;td&gt;$5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Cache write, 1 hour&lt;/td&gt;
&lt;td&gt;$8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Cache read&lt;/td&gt;
&lt;td&gt;$0.20&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Prompt caching stores part of a request so it is not sent and billed in full every time. A cache read here costs $0.20 per million tokens. The Batch API takes 50% off both input and output, in exchange for slower replies.&lt;/p&gt;

&lt;h2&gt;
  
  
  What the model card says
&lt;/h2&gt;

&lt;p&gt;Anthropic's &lt;a href="https://platform.claude.com/docs/en/models/opus-5-5/overview" rel="noopener noreferrer"&gt;platform documentation&lt;/a&gt; gives the model identifier as &lt;code&gt;claude-opus-5-5&lt;/code&gt;. On Amazon Bedrock it is &lt;code&gt;anthropic.claude-opus-5-5&lt;/code&gt;. The model is available through the Claude API, Amazon Bedrock, Google Cloud, Microsoft Foundry, and the Claude Platform on AWS.&lt;/p&gt;

&lt;p&gt;The context window holds 1 million tokens. That is everything the model can read and write in one conversation. A single synchronous reply can reach 128,000 tokens. Through the Batch API, with a beta header, that ceiling rises to 300,000 tokens.&lt;/p&gt;

&lt;p&gt;The documentation lists a knowledge cutoff of June 2026. It also says the model will not retire sooner than September 22, 2027. That second date matters to anyone who pins a model identifier in production code.&lt;/p&gt;

&lt;h2&gt;
  
  
  Four changes that can break working code
&lt;/h2&gt;

&lt;p&gt;The documentation lists four differences from Opus 5 that are not backward compatible.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Extended thinking is always on and cannot be turned off. Thinking is the model working a problem through before it answers.&lt;/li&gt;
&lt;li&gt;Forced tool use now returns an error instead of being accepted.&lt;/li&gt;
&lt;li&gt;Thinking blocks are tied to the model and the conversation that produced them.&lt;/li&gt;
&lt;li&gt;The earlier &lt;code&gt;computer_20251124&lt;/code&gt; tool version is no longer accepted.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The default effort setting is medium. On Claude Fable 5.1 it is high. Effort controls how hard the model works on a reply, so an unchanged prompt can behave differently.&lt;/p&gt;

&lt;h2&gt;
  
  
  What this means for developers
&lt;/h2&gt;

&lt;p&gt;Read those four changes before you swap a model identifier in a running service. The always-on thinking is the trap. Code that passes a flag to disable thinking, or that moves thinking blocks between models, has to change first. A price cut is not worth an outage.&lt;/p&gt;

&lt;p&gt;Re-run your own evaluations rather than trusting the comparison with Fable 5.1. Anthropic's claim covers most work, and your workload is not most work. TechCrunch reported the model outpaced Fable on many benchmarks for informal task completion, and placed it near Mythos on biology and cybersecurity. Those are broad categories, not your test suite.&lt;/p&gt;

&lt;p&gt;Check the effort default if you are moving across from Fable 5.1. Going from high to medium changes cost and answer quality together, which makes a regression easy to misread.&lt;/p&gt;

&lt;p&gt;If repeated context dominates your bill, read the cache rows before the token rows. Anthropic made a similar move on &lt;a href="https://techaiwire.com/articles/claude-fable-5-1-mythos-5-1-cache-price-cut/" rel="noopener noreferrer"&gt;cache pricing for Claude Fable 5.1&lt;/a&gt; earlier this month. Teams that send the same long system prompt on every call feel a cache change more than a token change.&lt;/p&gt;

&lt;p&gt;One reason to wait exists. TechCrunch reported that Sonnet 5.5 and Haiku 5.5 are due in the coming weeks. Most production traffic does not need the largest model, so a cheaper tier may fit your workload better within the month.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was first published on &lt;a href="https://techaiwire.com/articles/claude-opus-5-5-price-cut-adaptive-thinking/" rel="noopener noreferrer"&gt;Tech AI Wire&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Also available in
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://techaiwire.com/de/articles/claude-opus-5-5-price-cut-adaptive-thinking/" rel="noopener noreferrer"&gt;Deutsch&lt;/a&gt; · &lt;a href="https://techaiwire.com/ja/articles/claude-opus-5-5-price-cut-adaptive-thinking/" rel="noopener noreferrer"&gt;日本語&lt;/a&gt; · &lt;a href="https://techaiwire.com/fr/articles/claude-opus-5-5-price-cut-adaptive-thinking/" rel="noopener noreferrer"&gt;Français&lt;/a&gt; · &lt;a href="https://techaiwire.com/es/articles/claude-opus-5-5-price-cut-adaptive-thinking/" rel="noopener noreferrer"&gt;Español&lt;/a&gt; · &lt;a href="https://techaiwire.com/pt/articles/claude-opus-5-5-price-cut-adaptive-thinking/" rel="noopener noreferrer"&gt;Português&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Related on Tech AI Wire
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://techaiwire.com/articles/claude-fable-5-1-mythos-5-1-cache-price-cut/" rel="noopener noreferrer"&gt;Claude Fable 5.1 cuts cache reads 75% and keeps token prices flat&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Sources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://techcrunch.com/2026/09/22/anthropic-releases-opus-5-5-with-lower-prices-and-fable-level-performance/" rel="noopener noreferrer"&gt;Anthropic releases Opus 5.5 with lower prices and Fable-level performance&lt;/a&gt; - TechCrunch&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://platform.claude.com/docs/en/models/opus-5-5/overview" rel="noopener noreferrer"&gt;Claude Opus 5.5 overview&lt;/a&gt; - Claude Platform Docs&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://www.anthropic.com/news" rel="noopener noreferrer"&gt;Anthropic newsroom&lt;/a&gt; - Anthropic&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>anthropic</category>
      <category>llm</category>
      <category>pricing</category>
      <category>api</category>
    </item>
    <item>
      <title>Git 2.56 adds history drop and delete-merged</title>
      <dc:creator>techaiwire</dc:creator>
      <pubDate>Sun, 27 Sep 2026 17:37:27 +0000</pubDate>
      <link>https://dev.to/techaiwire/git-256-adds-history-drop-and-delete-merged-5469</link>
      <guid>https://dev.to/techaiwire/git-256-adds-history-drop-and-delete-merged-5469</guid>
      <description>&lt;p&gt;Git 2.56 is in release candidate form and is expected at the end of September 2026. &lt;a href="https://lwn.net/SubscriberLink/1094575/2385e98583715c2b/" rel="noopener noreferrer"&gt;LWN.net reported&lt;/a&gt; that the release carries more than 700 non-merge commits. Most of them are plumbing, but a handful of new commands change what developers can do without reaching for an interactive rebase.&lt;/p&gt;

&lt;p&gt;LWN calls 2.56 "a solid release" and says the project is "holding back much of its more significant work for the future." That future is Git 3.0.&lt;/p&gt;

&lt;h2&gt;
  
  
  The new commands
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Command or option&lt;/th&gt;
&lt;th&gt;What it does&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;git history drop&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Removes named commits from a branch by replaying the ones after them&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;git repo info&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Prints repository paths, both absolute and relative&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;git add --resolved&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Stages only the merge paths whose conflicts you fixed&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;git branch --delete-merged&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Deletes local branches already merged into their remote tracking branch&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;git bisect --reset-when-found&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Restores the original state once bisect finds the commit&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;git replay --linearize&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Drops merge commits while replaying history&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;git refs&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Creates, deletes, updates and renames references directly&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  What history drop does, and where it stops
&lt;/h2&gt;

&lt;p&gt;&lt;code&gt;git history drop&lt;/code&gt; removes a commit you name from a branch. It works by replaying every commit that came after it. That is the job people currently do with an interactive rebase, typed carefully, one line at a time.&lt;/p&gt;

&lt;p&gt;There is a limit worth knowing before you plan around it. Git's release notes say the command still refuses to work if the history contains merge commits. Many real branches contain merges, so the command suits a linear feature branch rather than a long-lived shared one.&lt;/p&gt;

&lt;p&gt;&lt;code&gt;git replay --linearize&lt;/code&gt; approaches the same ground from the other side. It drops merge commits as it replays, which flattens a tangled history into a straight line.&lt;/p&gt;

&lt;h2&gt;
  
  
  Smaller changes you will notice
&lt;/h2&gt;

&lt;p&gt;&lt;code&gt;git add --resolved&lt;/code&gt; is aimed at a common mid-merge mess. During a conflicted merge you often fix two files and leave other edits in the working tree. The new option stages only the paths whose conflicts you resolved, and leaves your other local changes alone.&lt;/p&gt;

&lt;p&gt;&lt;code&gt;git branch --delete-merged&lt;/code&gt; clears out local branches that were already merged into the branch they track. Git also prints a clearer message when one of those branches is in use for a bisection.&lt;/p&gt;

&lt;p&gt;The Git project's release notes list several quieter fixes. Git now spots typos in commands such as &lt;code&gt;git push origin/main&lt;/code&gt;. A new &lt;code&gt;fetch.followRemoteHEAD&lt;/code&gt; setting controls how a fetch treats the remote's default branch. Asking any command for help now exits with code 0 instead of 129, which stops scripts from reading a help request as a failure. Configuration commands retry when they collide, which reduces lock errors when two commands write config at once.&lt;/p&gt;

&lt;p&gt;Underneath, &lt;code&gt;git cat-file --batch&lt;/code&gt; formats output faster, and &lt;code&gt;git log --follow&lt;/code&gt; handles non-linear history better than before.&lt;/p&gt;

&lt;h2&gt;
  
  
  What this means for developers
&lt;/h2&gt;

&lt;p&gt;Try &lt;code&gt;git history drop&lt;/code&gt; on a copy of a branch before you trust it on a real one. The merge-commit restriction is the part that decides whether it fits your workflow at all. Run &lt;code&gt;git log --merges&lt;/code&gt; on the range you want to edit: if that prints anything, the command will refuse.&lt;/p&gt;

&lt;p&gt;&lt;code&gt;git branch --delete-merged&lt;/code&gt; is the one to wire into habit. Most developers accumulate dozens of stale local branches and clean them up with a shell pipeline copied from a blog post years ago. A built-in option is safer, because it checks the remote tracking branch rather than matching names.&lt;/p&gt;

&lt;p&gt;The exit-code change deserves a scan of your own tooling. Any script that treated 129 as the signal for a help request will now see 0. That is the correct behavior, but it is a behavior change, and it will fail quietly rather than loudly.&lt;/p&gt;

&lt;p&gt;Nothing here breaks an existing repository. The changes that will are in the next release: &lt;a href="https://techaiwire.com/articles/git-3-0-sha-256-rust-reftable/" rel="noopener noreferrer"&gt;Git 3.0 switches new repositories to SHA-256 and reftable&lt;/a&gt;, and makes Rust a required build dependency. Git's own breaking-changes document still gives 3.0 no release date. Treat 2.56 as the last quiet stop before that one.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was first published on &lt;a href="https://techaiwire.com/articles/git-2-56-history-drop-delete-merged/" rel="noopener noreferrer"&gt;Tech AI Wire&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Also available in
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://techaiwire.com/de/articles/git-2-56-history-drop-delete-merged/" rel="noopener noreferrer"&gt;Deutsch&lt;/a&gt; · &lt;a href="https://techaiwire.com/ja/articles/git-2-56-history-drop-delete-merged/" rel="noopener noreferrer"&gt;日本語&lt;/a&gt; · &lt;a href="https://techaiwire.com/fr/articles/git-2-56-history-drop-delete-merged/" rel="noopener noreferrer"&gt;Français&lt;/a&gt; · &lt;a href="https://techaiwire.com/es/articles/git-2-56-history-drop-delete-merged/" rel="noopener noreferrer"&gt;Español&lt;/a&gt; · &lt;a href="https://techaiwire.com/pt/articles/git-2-56-history-drop-delete-merged/" rel="noopener noreferrer"&gt;Português&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Related on Tech AI Wire
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://techaiwire.com/articles/git-3-0-sha-256-rust-reftable/" rel="noopener noreferrer"&gt;Git 3.0 will default to SHA-256 and require Rust&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Sources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://lwn.net/SubscriberLink/1094575/2385e98583715c2b/" rel="noopener noreferrer"&gt;Looking forward to Git 2.56 - and 3.0&lt;/a&gt; - LWN.net&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.56.0.adoc" rel="noopener noreferrer"&gt;Git 2.56 release notes&lt;/a&gt; - Git project&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>opensource</category>
      <category>infrastructure</category>
      <category>git</category>
    </item>
    <item>
      <title>Meta's Muse agent exported 6.8 GB of its own filesystem</title>
      <dc:creator>techaiwire</dc:creator>
      <pubDate>Sun, 27 Sep 2026 17:34:50 +0000</pubDate>
      <link>https://dev.to/techaiwire/metas-muse-agent-exported-68-gb-of-its-own-filesystem-59f4</link>
      <guid>https://dev.to/techaiwire/metas-muse-agent-exported-68-gb-of-its-own-filesystem-59f4</guid>
      <description>&lt;p&gt;A researcher asked Meta's Muse agent to archive the files it could see and send them to Google Drive. It did. Peter James &lt;a href="https://mouse.dev/blog/muse-runtime-export/" rel="noopener noreferrer"&gt;published the result&lt;/a&gt; on September 22, 2026: a 2.7 GB compressed archive that unpacked to 6.8 GB of the agent's own runtime environment. The question it raises is not whether Muse broke a rule, but what a personal agent counts as "its files" when you ask.&lt;/p&gt;

&lt;p&gt;"I asked Muse to archive the files it could see and send them to my Google Drive. It did," James wrote.&lt;/p&gt;

&lt;h2&gt;
  
  
  What was in the archive
&lt;/h2&gt;

&lt;p&gt;By James's account the export held Ubuntu system files, internal Meta documentation, integration code, app templates, memory files, agent logs, and SSH key files. An SSH key is a credential that grants access to a remote machine without a password.&lt;/p&gt;

&lt;p&gt;The files also name things Meta has not announced. James reports 113 sub-agent records and roughly 68 skill directories. A skill is a packaged set of instructions for one job. The directories cover Google Workspace, Meta's own social apps, Outlook, travel, shopping, health, and home devices.&lt;/p&gt;

&lt;p&gt;Configuration files listed integrations described as in the pipeline: Slack, Dropbox, Polymarket, Canva, and Klaviyo. The runtime files call the product "Hatch", which James describes as Meta's internal name for Muse.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Meta says the sandbox does
&lt;/h2&gt;

&lt;p&gt;Meta published its own account of how it isolates Muse. The &lt;a href="https://research.meta.ai/blog/security-and-safety-for-ai-agents-our-approach-with-muse" rel="noopener noreferrer"&gt;Meta AI Research post&lt;/a&gt; says the agent runs in a dedicated cloud virtual machine, inside a &lt;code&gt;systemd-nspawn&lt;/code&gt; container. A container is a walled-off slice of one machine.&lt;/p&gt;

&lt;p&gt;Meta writes that "root inside the runtime cell is mapped to an unprivileged host user so runtime cell root is not host root." In plain terms: even full control inside the agent's box is not control of the machine hosting it.&lt;/p&gt;

&lt;p&gt;Meta also describes a separate component called Sentinel. It runs outside the agent's box and is the only thing allowed to approve actions such as sending an email or making a purchase. Meta says credentials are never exposed to the agent at all. Muse instead receives surrogate tokens, which a service named &lt;code&gt;authd&lt;/code&gt; swaps for real credentials at the network boundary.&lt;/p&gt;

&lt;p&gt;For web browsing, Meta says the agent sees only accessibility tree snapshots rather than the raw page, and cannot run JavaScript. An accessibility tree is the simplified description of a page that screen readers use.&lt;/p&gt;

&lt;h2&gt;
  
  
  The two accounts sit awkwardly together
&lt;/h2&gt;

&lt;p&gt;These claims are in tension, and neither source resolves it. Meta says credentials are never exposed to the agent. James reports SSH key files inside the archive the agent produced. Neither account says whose keys those are, or what they unlock, so the gap between the two statements is not settled by the published material.&lt;/p&gt;

&lt;p&gt;James says Meta marked his bug bounty report "Not Applicable" and did not state grounds. Meta's post says the program pays up to $300,000 for vulnerability reports. Meta has not published a response to this specific export.&lt;/p&gt;

&lt;h2&gt;
  
  
  What this means for developers
&lt;/h2&gt;

&lt;p&gt;Treat an agent's own runtime as part of its output surface. The sandbox held: nothing here shows the host being compromised. What leaked was the contents of the box, because a user asked the thing inside the box to describe itself. Permission systems that gate actions, as Sentinel does, do not gate disclosure.&lt;/p&gt;

&lt;p&gt;If you ship an agent, assume its filesystem is readable by its user and build accordingly. Keep internal documentation, unreleased connector names, and any key material out of the image the agent runs on. A surrogate-token design like Meta's protects the user's credentials, and does nothing for secrets baked into the image itself.&lt;/p&gt;

&lt;p&gt;For anyone evaluating Muse, this follows &lt;a href="https://techaiwire.com/articles/meta-muse-mac-agent-file-access/" rel="noopener noreferrer"&gt;the file access that arrived with its Mac release&lt;/a&gt; four days earlier. The useful test before you grant an agent your email and cards is simple: ask it to export everything it can see, then read what comes back.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was first published on &lt;a href="https://techaiwire.com/articles/meta-muse-agent-exported-own-filesystem/" rel="noopener noreferrer"&gt;Tech AI Wire&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Also available in
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://techaiwire.com/de/articles/meta-muse-agent-exported-own-filesystem/" rel="noopener noreferrer"&gt;Deutsch&lt;/a&gt; · &lt;a href="https://techaiwire.com/ja/articles/meta-muse-agent-exported-own-filesystem/" rel="noopener noreferrer"&gt;日本語&lt;/a&gt; · &lt;a href="https://techaiwire.com/fr/articles/meta-muse-agent-exported-own-filesystem/" rel="noopener noreferrer"&gt;Français&lt;/a&gt; · &lt;a href="https://techaiwire.com/es/articles/meta-muse-agent-exported-own-filesystem/" rel="noopener noreferrer"&gt;Español&lt;/a&gt; · &lt;a href="https://techaiwire.com/pt/articles/meta-muse-agent-exported-own-filesystem/" rel="noopener noreferrer"&gt;Português&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Related on Tech AI Wire
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://techaiwire.com/articles/meta-muse-mac-agent-file-access/" rel="noopener noreferrer"&gt;Meta's Muse agent lands on the Mac with file access&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Sources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://mouse.dev/blog/muse-runtime-export/" rel="noopener noreferrer"&gt;I asked Meta's Muse for its filesystem and it sent me 6.8GB&lt;/a&gt; - mouse.dev&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://research.meta.ai/blog/security-and-safety-for-ai-agents-our-approach-with-muse" rel="noopener noreferrer"&gt;Security and safety for AI agents: our approach with Muse&lt;/a&gt; - Meta AI Research&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>meta</category>
      <category>aiagents</category>
      <category>security</category>
    </item>
    <item>
      <title>GPT-6 Astra breaks an Enigma message unsolved since 2005</title>
      <dc:creator>techaiwire</dc:creator>
      <pubDate>Sun, 27 Sep 2026 17:32:12 +0000</pubDate>
      <link>https://dev.to/techaiwire/gpt-6-astra-breaks-an-enigma-message-unsolved-since-2005-2ne4</link>
      <guid>https://dev.to/techaiwire/gpt-6-astra-breaks-an-enigma-message-unsolved-since-2005-2ne4</guid>
      <description>&lt;p&gt;OpenAI's GPT-6 Astra has recovered the settings behind an 82-letter German Army Enigma message sent on July 10, 1941. The message, known by the indicator MVUEH, had sat unbroken on a public research archive for 21 years. The interesting part for developers is not the history. It is that the model wrote and ran its own cryptanalysis software to get there.&lt;/p&gt;

&lt;p&gt;Enigma was the cipher machine the German military used in the Second World War. Its settings changed daily, and breaking a message means recovering those settings.&lt;/p&gt;

&lt;h2&gt;
  
  
  What the model actually did
&lt;/h2&gt;

&lt;p&gt;The &lt;a href="https://www.cryptocellar.org/bgac/the-mvueh-break.html" rel="noopener noreferrer"&gt;CryptoCellar account of the break&lt;/a&gt; describes the sequence. GPT-6 Astra read through the unbroken messages held on the site and picked MVUEH as the most promising target. It then noticed that the plaintext looked connected to a different message, Nr. 173, indicator SIPVX, which researchers had already solved.&lt;/p&gt;

&lt;p&gt;From there the model wrote software. It built an Enigma simulator in Python and in C++, plus an implementation of the Bombe. The Bombe was the electromechanical machine built at Bletchley Park to search Enigma settings. The model then ran that search.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://www.schneier.com/blog/archives/2026/09/gpt-6-astra-breaks-an-old-enigma-message.html" rel="noopener noreferrer"&gt;Bruce Schneier's summary&lt;/a&gt; describes the result as "a thorough break with the ROSENOW crib". A crib is a guess at a piece of the original text. If you know some words the message almost certainly contains, you can test settings far faster.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where the crib came from
&lt;/h2&gt;

&lt;p&gt;That crib is the reason to read the autonomy claim carefully. The repeated place name ROSENOW ROSENOW came from SIPVX, the related message that human researchers broke in 2017. Schneier's write-up says the model "did it entirely on its own", and in the same breath names its reliance on that crib.&lt;/p&gt;

&lt;p&gt;Both things are true. The model chose the target, spotted the link between the two messages, wrote the tooling, and ran the search without being told how. It did so standing on an existing human break of a sibling message.&lt;/p&gt;

&lt;p&gt;Schneier's post adds one more caveat. The team is "still analysing the GPT-6 Astra logs to see exactly how it executed the break". The full method is not yet public.&lt;/p&gt;

&lt;h2&gt;
  
  
  The verification
&lt;/h2&gt;

&lt;p&gt;Frode Weierud, the cryptanalyst who runs the CryptoCellar archive, checked the result. CryptoCellar's account says he confirmed that the model "had found the correct key and plaintext", and calls the achievement "simply amazing".&lt;/p&gt;

&lt;p&gt;The recovered key was not the expected one. CryptoCellar reports a wheel order of 253, where 512 was the order otherwise recorded for that day. The wheel order is which rotors sit in which slots inside the machine. The recovered plaintext is nearly identical to SIPVX, with differences the account puts down to encipherment errors made at the time.&lt;/p&gt;

&lt;p&gt;CryptoCellar also explains why the message resisted for so long. The ciphertext as transcribed contains errors, and the message involves a rare turnover of the left-hand wheel. Both break the assumptions a straightforward search depends on.&lt;/p&gt;

&lt;h2&gt;
  
  
  What this means for developers
&lt;/h2&gt;

&lt;p&gt;The transferable result here is a workflow, not a cipher. The model surveyed a problem set, picked the tractable instance, wrote a correct simulator in two languages, wrote a search program against it, and ran it. That is ordinary engineering work, done end to end, on a problem with a verifiable answer.&lt;/p&gt;

&lt;p&gt;Note which conditions made it work. The answer was checkable, a related solved case existed to supply a crib, and the search space was bounded by physical machine constraints. Where your own problem has those three properties, this pattern is worth trying. Where it does not, a model cannot tell you it has failed.&lt;/p&gt;

&lt;p&gt;The verification step is the part not to copy loosely. A named human expert confirmed the key before anyone published the claim. That is how this result stayed a result, rather than joining the pile of plausible-looking machine output nobody checked. CryptoCellar's account says the two days of work would take a human researcher weeks or months, which raises the value of fast expert review rather than lowering it.&lt;/p&gt;

&lt;p&gt;The security reading is narrower than some coverage suggests. This was a 1941 cipher with a tiny keyspace by modern standards. It says nothing about the strength of anything you are shipping. It does follow &lt;a href="https://techaiwire.com/articles/gpt-6-astra-critical-cyber-threshold/" rel="noopener noreferrer"&gt;OpenAI rating Astra its first Critical cyber model&lt;/a&gt; five days earlier, which is the more concrete signal for anyone tracking this capability.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was first published on &lt;a href="https://techaiwire.com/articles/gpt-6-astra-enigma-mvueh-break/" rel="noopener noreferrer"&gt;Tech AI Wire&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Also available in
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://techaiwire.com/de/articles/gpt-6-astra-enigma-mvueh-break/" rel="noopener noreferrer"&gt;Deutsch&lt;/a&gt; · &lt;a href="https://techaiwire.com/ja/articles/gpt-6-astra-enigma-mvueh-break/" rel="noopener noreferrer"&gt;日本語&lt;/a&gt; · &lt;a href="https://techaiwire.com/fr/articles/gpt-6-astra-enigma-mvueh-break/" rel="noopener noreferrer"&gt;Français&lt;/a&gt; · &lt;a href="https://techaiwire.com/es/articles/gpt-6-astra-enigma-mvueh-break/" rel="noopener noreferrer"&gt;Español&lt;/a&gt; · &lt;a href="https://techaiwire.com/pt/articles/gpt-6-astra-enigma-mvueh-break/" rel="noopener noreferrer"&gt;Português&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Related on Tech AI Wire
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://techaiwire.com/articles/gpt-6-astra-critical-cyber-threshold/" rel="noopener noreferrer"&gt;GPT-6 Astra is OpenAI's first Critical cyber model&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Sources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://www.cryptocellar.org/bgac/the-mvueh-break.html" rel="noopener noreferrer"&gt;The MVUEH break&lt;/a&gt; - CryptoCellar&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://www.schneier.com/blog/archives/2026/09/gpt-6-astra-breaks-an-old-enigma-message.html" rel="noopener noreferrer"&gt;GPT-6 Astra Breaks an Old Enigma Message&lt;/a&gt; - Schneier on Security&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>openai</category>
      <category>aicoding</category>
      <category>security</category>
    </item>
    <item>
      <title>Python documentation is now available in German</title>
      <dc:creator>techaiwire</dc:creator>
      <pubDate>Sun, 27 Sep 2026 17:29:36 +0000</pubDate>
      <link>https://dev.to/techaiwire/python-documentation-is-now-available-in-german-436l</link>
      <guid>https://dev.to/techaiwire/python-documentation-is-now-available-in-german-436l</guid>
      <description>&lt;p&gt;The official Python documentation now has a German edition. The Python project announced it on September 26, 2026, and the pages live at docs.python.org/de/3/. It matters because German speakers can now learn the language from its own reference, not from third-party books or blog posts.&lt;/p&gt;

&lt;p&gt;The announcement came from Stan Ulbrych on the &lt;a href="https://blog.python.org/2026/09/python-docs-in-german/" rel="noopener noreferrer"&gt;Python Insider blog&lt;/a&gt;. "We're excited to announce that the Python documentation is now available in German (Deutsch)!" he wrote. He credited the community volunteers who did the translation work.&lt;/p&gt;

&lt;h2&gt;
  
  
  What is translated so far
&lt;/h2&gt;

&lt;p&gt;The German edition is complete where it counts first, and thin everywhere else. The project's translation dashboard at translations.python.org tracks two numbers for each language.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Measure&lt;/th&gt;
&lt;th&gt;German progress&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Core documentation&lt;/td&gt;
&lt;td&gt;100%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Core progress in the last 30 days&lt;/td&gt;
&lt;td&gt;23.79%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Full documentation&lt;/td&gt;
&lt;td&gt;9.17%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Full progress in the last 30 days&lt;/td&gt;
&lt;td&gt;5.87%&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;So roughly a quarter of the core set was finished in the final month before launch. The full documentation is a far bigger body of text. It includes the standard library reference, which describes every built-in module in detail.&lt;/p&gt;

&lt;p&gt;The German site offers several Python versions. Its version menu lists Python 3.14.7 as the current stable release. It also offers 3.15, which is in pre-release, and 3.16, which is still in development.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why a language appears only when its core is done
&lt;/h2&gt;

&lt;p&gt;Python's rules for translations come from PEP 545, a Python Enhancement Proposal. A PEP is the formal design document the project uses to decide how things work.&lt;/p&gt;

&lt;p&gt;PEP 545 sets a bar before a language appears in the documentation's language menu. Three parts must be 100% translated: the page on reporting bugs, the tutorial, and the reference for built-in functions. That is why a new language can go live while most of its pages are still in English. The pieces a beginner reads first are finished; the long tail comes later.&lt;/p&gt;

&lt;p&gt;The same PEP fixes the web address pattern, docs.python.org/LANGUAGE/VERSION/. It also requires one named coordinator per language. For German, the Python Developer's Guide names Swen Bachmann as that coordinator. The translation files live in his GitHub repository, python-docs-de, which shows 361 commits.&lt;/p&gt;

&lt;h2&gt;
  
  
  How the translation pipeline works
&lt;/h2&gt;

&lt;p&gt;Translators never edit the documentation pages directly. According to the Developer's Guide, they work in gettext PO files. Gettext is a common toolkit for translating software. A PO file lists each English sentence next to a slot for its translation.&lt;/p&gt;

&lt;p&gt;Sphinx, the tool that builds Python's documentation, generates those files from the English source. When translators finish, build scripts pull the files in and publish them to docs.python.org automatically. The German team manages its work through Transifex, a web platform for translation projects.&lt;/p&gt;

&lt;p&gt;Contributors must first accept a documentation contribution agreement. Under PEP 545, that offers their work under the CC0 license, a public-domain dedication. German joins 27 active translation projects, which include French, Spanish, Japanese, Russian, Hungarian and both forms of Chinese.&lt;/p&gt;

&lt;h2&gt;
  
  
  What this means for developers
&lt;/h2&gt;

&lt;p&gt;If you teach Python to German speakers, point them at docs.python.org/de/3/ for the tutorial and the built-in functions reference now. Those parts are fully translated. For the standard library reference, expect most pages to still read in English, since the full set is at 9.17%.&lt;/p&gt;

&lt;p&gt;Check the version in any link you share. The German site offers several versions, from 2.6 up to the 3.16 development docs. A link to /de/3/ follows the current stable release, while a link with a version number stays fixed. Use the fixed form in course material you do not plan to update.&lt;/p&gt;

&lt;p&gt;If you write German and know Python, this is one of the easier ways to contribute to the project. You translate PO entries through Transifex, and the Developer's Guide explains the setup. The 9.17% figure shows how much of the library reference still needs hands.&lt;/p&gt;

&lt;p&gt;Keep your terms consistent. The Developer's Guide asks translators to respect technical naming, so names like &lt;code&gt;dict&lt;/code&gt; or &lt;code&gt;asyncio&lt;/code&gt; stay as they are. Only the prose around them changes.&lt;/p&gt;

&lt;p&gt;Last, watch the dashboard if your team works in another language. The same 100% core rule decides when that edition appears in the language menu.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was first published on &lt;a href="https://techaiwire.com/articles/python-documentation-german-translation/" rel="noopener noreferrer"&gt;Tech AI Wire&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Also available in
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://techaiwire.com/de/articles/python-documentation-german-translation/" rel="noopener noreferrer"&gt;Deutsch&lt;/a&gt; · &lt;a href="https://techaiwire.com/ja/articles/python-documentation-german-translation/" rel="noopener noreferrer"&gt;日本語&lt;/a&gt; · &lt;a href="https://techaiwire.com/fr/articles/python-documentation-german-translation/" rel="noopener noreferrer"&gt;Français&lt;/a&gt; · &lt;a href="https://techaiwire.com/es/articles/python-documentation-german-translation/" rel="noopener noreferrer"&gt;Español&lt;/a&gt; · &lt;a href="https://techaiwire.com/pt/articles/python-documentation-german-translation/" rel="noopener noreferrer"&gt;Português&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Sources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://blog.python.org/2026/09/python-docs-in-german/" rel="noopener noreferrer"&gt;The Python documentation is now available in German&lt;/a&gt; - Python Insider&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://translations.python.org/" rel="noopener noreferrer"&gt;Python documentation translations dashboard&lt;/a&gt; - Python translations dashboard&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://peps.python.org/pep-0545/" rel="noopener noreferrer"&gt;PEP 545 - Python Documentation Translations&lt;/a&gt; - Python Enhancement Proposals&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://devguide.python.org/documentation/translations/translating/" rel="noopener noreferrer"&gt;Translating - Python Developer's Guide&lt;/a&gt; - Python Developer's Guide&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>python</category>
      <category>opensource</category>
      <category>documentation</category>
    </item>
    <item>
      <title>DRBD 9 edges toward mainline Linux with 7 prep patches</title>
      <dc:creator>techaiwire</dc:creator>
      <pubDate>Sun, 27 Sep 2026 17:26:59 +0000</pubDate>
      <link>https://dev.to/techaiwire/drbd-9-edges-toward-mainline-linux-with-7-prep-patches-4kja</link>
      <guid>https://dev.to/techaiwire/drbd-9-edges-toward-mainline-linux-with-7-prep-patches-4kja</guid>
      <description>&lt;p&gt;Christoph Böhmwalder posted a 7-patch series to the Linux kernel mailing lists on September 23, 2026. It is titled "drbd: preparation for DRBD 9". The series reshapes the kernel's old DRBD code so that the much newer DRBD 9 can follow it into mainline. That matters to anyone running replicated storage on Linux, because the version shipped inside the kernel is still on the older 8.4 branch.&lt;/p&gt;

&lt;p&gt;DRBD stands for Distributed Replicated Block Device. It copies a disk, block by block, to one or more other machines over the network. If one server dies, another holds an identical copy of the data. &lt;a href="https://linbit.com/drbd/" rel="noopener noreferrer"&gt;LINBIT&lt;/a&gt;, the company behind it, says the project has been maintained for more than two decades.&lt;/p&gt;

&lt;h2&gt;
  
  
  What the 7 patches change
&lt;/h2&gt;

&lt;p&gt;The cover letter describes the approach in one line. "Each patch moves a piece of the in-tree DRBD 8.4 code to the form it has in the out-of-tree DRBD 9 code," Böhmwalder wrote.&lt;/p&gt;

&lt;p&gt;"In-tree" means code that lives in the official kernel source. "Out-of-tree" means code maintained separately and built as an add-on module. DRBD 9 has only ever been out-of-tree.&lt;/p&gt;

&lt;p&gt;The &lt;a href="https://marc.info/?l=linux-kernel&amp;amp;m=179017280175669&amp;amp;w=2" rel="noopener noreferrer"&gt;cover letter&lt;/a&gt; lists these changes:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Higher ceilings for fast networks: socket buffers up to 128 MiB, and a maximum resync rate of 8 GiB/s.&lt;/li&gt;
&lt;li&gt;The file &lt;code&gt;drbd_worker.c&lt;/code&gt; is renamed to &lt;code&gt;drbd_sender.c&lt;/code&gt;, matching DRBD 9's layout.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;drbd_interval&lt;/code&gt; data structure's bitfields are replaced.&lt;/li&gt;
&lt;li&gt;The table of network packet names moves to a new location.&lt;/li&gt;
&lt;li&gt;Log messages gain rate limiting per object, so one failing device cannot flood the kernel log.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The series went to both the linux-kernel and linux-block lists. The cover letter stresses that nothing changes for current users: "Defaults are unchanged, all existing configurations remain valid."&lt;/p&gt;

&lt;h2&gt;
  
  
  Why DRBD 9 is worth the effort
&lt;/h2&gt;

&lt;p&gt;LINBIT explained the goal in an April 27, 2026 blog post by Michael Troutman. The kernel carries DRBD 8.4.11, which the post calls stagnant. Active development happens on DRBD 9.3, outside the kernel.&lt;/p&gt;

&lt;p&gt;The gap between the two is large.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Capability&lt;/th&gt;
&lt;th&gt;DRBD 8.4 (in the kernel)&lt;/th&gt;
&lt;th&gt;DRBD 9 (out-of-tree)&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Nodes per volume&lt;/td&gt;
&lt;td&gt;2, for failover&lt;/td&gt;
&lt;td&gt;Up to 31 peers&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Split-brain protection&lt;/td&gt;
&lt;td&gt;Relies on fencing&lt;/td&gt;
&lt;td&gt;Built-in quorum for 3 or more nodes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Failed-node handling&lt;/td&gt;
&lt;td&gt;Manual STONITH or fencing setup&lt;/td&gt;
&lt;td&gt;Automatic&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Split brain is the failure where two machines both believe they hold the live copy and start writing different data. Quorum prevents it by letting a node write only while it can see a majority of the cluster. STONITH, short for "shoot the other node in the head", is the older fix: power off a suspect node before it can do damage. DRBD 9 also adds safeguards for syncing a node that rejoins the cluster.&lt;/p&gt;

&lt;p&gt;LINBIT's post named Linux 7.2 as its target for the DRBD 9.3 patches. This week's series is described as preparation, so the full DRBD 9 code is a later, separate submission.&lt;/p&gt;

&lt;h2&gt;
  
  
  What this means for developers
&lt;/h2&gt;

&lt;p&gt;If you run DRBD today, check which one you have. You may already load LINBIT's out-of-tree DRBD 9 module rather than the kernel's 8.4 driver. &lt;code&gt;cat /proc/drbd&lt;/code&gt; prints the loaded version. This series changes nothing for either group yet, and the cover letter promises existing configurations stay valid.&lt;/p&gt;

&lt;p&gt;If you rely on the in-kernel 8.4 driver, the upstream work is a reason to plan a test of DRBD 9 now. Once it lands, the in-kernel driver will gain multi-peer volumes and quorum. Those change how a cluster must be configured and fenced. Trying them on a staging cluster first beats discovering the differences after a distribution kernel upgrade.&lt;/p&gt;

&lt;p&gt;If you build storage on fast networks, note the new limits. A resync ceiling of 8 GiB/s and 128 MiB socket buffers leave room for fast data-center links. LINBIT's site notes DRBD can replicate over TCP/IP or RDMA, the low-latency transport used on InfiniBand and RoCE networks. The defaults stay the same, so you still have to raise them yourself.&lt;/p&gt;

&lt;p&gt;Watch the linux-block list for the next round. Review comments on these 7 patches will show how quickly maintainers accept a large, long-running out-of-tree driver. That answer decides when a stock kernel can replace a separately packaged DRBD module.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was first published on &lt;a href="https://techaiwire.com/articles/drbd-9-preparation-patches-linux-kernel/" rel="noopener noreferrer"&gt;Tech AI Wire&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Also available in
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://techaiwire.com/de/articles/drbd-9-preparation-patches-linux-kernel/" rel="noopener noreferrer"&gt;Deutsch&lt;/a&gt; · &lt;a href="https://techaiwire.com/ja/articles/drbd-9-preparation-patches-linux-kernel/" rel="noopener noreferrer"&gt;日本語&lt;/a&gt; · &lt;a href="https://techaiwire.com/fr/articles/drbd-9-preparation-patches-linux-kernel/" rel="noopener noreferrer"&gt;Français&lt;/a&gt; · &lt;a href="https://techaiwire.com/es/articles/drbd-9-preparation-patches-linux-kernel/" rel="noopener noreferrer"&gt;Español&lt;/a&gt; · &lt;a href="https://techaiwire.com/pt/articles/drbd-9-preparation-patches-linux-kernel/" rel="noopener noreferrer"&gt;Português&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Sources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://marc.info/?l=linux-kernel&amp;amp;m=179017280175669&amp;amp;w=2" rel="noopener noreferrer"&gt;[PATCH 0/7] drbd: preparation for DRBD 9&lt;/a&gt; - linux-kernel mailing list&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://linbit.com/blog/working-to-put-drbd-9-in-the-mainline-linux-kernel/" rel="noopener noreferrer"&gt;Working to Put DRBD 9 in the Mainline Linux Kernel&lt;/a&gt; - LINBIT&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://linbit.com/drbd/" rel="noopener noreferrer"&gt;DRBD&lt;/a&gt; - LINBIT&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>linux</category>
      <category>opensource</category>
      <category>infrastructure</category>
    </item>
  </channel>
</rss>
