Connect with us

Tech & AI

Cloudflare fixes Containers cross-tenant flaw exposing customer data

Published

on

Cloudflare fixes Containers cross-tenant flaw exposing customer data

Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers’ containers on the same physical host.

Cloudflare Containers is a service available on the Workers Paid plan that lets developers run containerized applications on Cloudflare’s infrastructure, alongside Cloudflare Workers.

Developers and companies building applications on Cloudflare typically use it, including those running backend services, processing jobs, and code execution environments.

The flaw was reported through HackerOne on September 4 by Oren Yomtov, a security researcher at technology company Accomplish.

Advertisement

Exploiting it would let an attacker read other customers’ files, including directory listings, SQLite databases, Chromium profiles, .env files, and credential files.

According to Cloudflare’s disclosure, the issue was in a shared storage pool configured to skip zeroing reused 64 KiB blocks.

“When the thin volume backing a container’s root disk was deleted, its physical blocks were returned to a pool that served workloads belonging to multiple customer accounts,” Cloudflare explains.

By writing only 4 KiB to an unused region of a new container’s disk, the researchers could cause a reused 64 KiB physical block to be allocated. Without the zeroing operation, only the 4 KiB write would overwrite the block, leaving in a readable state the remaining 60 KiB that may contain data from a previous customer.

Advertisement

They found residual material on 18 of 24 container placements and across 20 of 22 underlying nodes tested, including directory structures, database pages, and structurally complete SQLite databases.

“The vulnerability would potentially have allowed for a customer with a Workers Paid account to recover residual data from storage blocks previously used by other customers’ Containers on the same underlying host,” Cloudflare says.

“A successful exploitation would have crossed the tenant-isolation boundary and could disclose filesystem metadata, directory structures, database pages, and application data.”

An attacker would not have control over the victim or host, nor would they be able to read an actively attached disk.

Advertisement

Risk evaluation and real exposure

Cloudflare says the researchers only used scripts that performed checks and returned aggregate counts, not actual disk contents, so no real customer data was exposed in this evaluation.

The researchers also did not demonstrate any way to change another customer’s data or disrupt their workloads on Cloudflare’s service.

Cloudflare removed the setting that caused the skipped block zeroing, retired existing container disks, and cleared cached snapshots that may contain old mappings, finishing all mitigation actions by September 19, 2026.

After examining logs, telemetry, and historical data, the company found no evidence that customer data was exposed via the method described by Accomplish.

Advertisement

Cloudflare applied the fixes to its infrastructure automatically, and customers need to take no action to address the risk.


article image

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech & AI

Boox Announces the Picco, Its Smallest E-Reader Ever (2026)

Published

on

While smartphones won’t stop getting bigger, e-readers seem to be getting smaller. Boox has been at the forefront with one of the most popular small e-readers, the Boox Palma, and now it is adding an even smaller model.

Boox announced the Picco, with preorders opening today. Its screen is just under 4 inches (3.97 to be exact), making it about the size of a playing card. It’s even smaller than the Xteink X4 Pro I tested earlier this year, which has a 4.3-inch screen (but just slightly larger than the 3.7-inch Xteink X3), and considerably smaller than the upcoming Boox Palma 3’s 6.19-inch screen. I liked the size of the Xteink in my hand, but navigating the interface and getting books were challenging, so I’m excited to see another option in that smaller size from a maker with more accessible ebooks (though still not as convenient as a Kindle or Kobo with their built-in stores).

The Picco will cost $100 and is expected to ship in November. I’ll be testing it soon, but in the meantime, here are the details if you’ve been eyeing a tiny e-reader.

An E-Reader for Productivity

Boox Announces the Picco Its Smallest EReader Ever

Courtesy of Boox

The Boox Picco has a monochrome screen with a resolution of 235 pixels per inch and an adjustable front light that switches between warm- and cool-toned lighting. The microSD card slot supports up to 2 TB of flash memory storage (a 16 GB card is included). There are both a touchscreen and physical page-turning controls, thanks to the buttons on the side of the device. The case has a magnetic ring so you can attach it to the back of a smartphone, though I’ll have to see how well it fits when I test it, as I had mixed results attaching an Xteink to my phone due to both fit and magnet strength.

Advertisement
Image may contain Electronics and Remote Control

Courtesy of Boox

Boox says the Picco will have a streamlined operating system focused on reading and digital utility tools. It’s also the first in what Boox calls its Tiles lineup, which is how you’ll access ebooks on this device. You can also use web and USB-C file transfers (the Picco has Wi-Fi and Bluetooth connectivity) to get ebooks onto the Picco. The Picco also has the Pomodoro, Todo, and Countdown apps, so you can use it as both an e-reader and a productivity gadget—handy, and a bigger motivation to keep it attached to the back of your phone even when you aren’t reading.

I’m intrigued to see it in action. Boox’s most popular e-reader could become the Picco over the Palma 3, but we’ll have to wait for both devices to become available to see which is the better buy. Stay tuned for my reviews of both when they come out.


Power up with unlimited access to WIRED. Get best-in-class reporting and exclusive subscriber content that’s too important to ignore. Subscribe Today.

Source link

Advertisement
Continue Reading

Tech & AI

Discord Is Testing A Lightweight Mode To Free Up Resources While Gaming

Published

on

But a Chromium-based design means it can only be so efficient.

Discord is working on a new mode for its social platform that it says might be less resource-intensive. Screenshots of an option called Game Mode began circulating on social media over the weekend. The description shown for the Game Mode toggle states that it will “Reduce Discord’s CPU and GPU usage while a game is running.” By making the chat platform less resource-intensive, concurrently running software should be able to run more smoothly.

Today, the company confirmed on X that this experimental mode will begin rolling out to its users next week. The brief official announcement about Game Mode added that Discord is “aiming to add more resource-saving features over time.”

Discord is based on the Electron web app framework, which uses Javascript and Chromium for creating software. The open-source Chromium, which is the basis for Google’s Chrome and several other browsers, is not known as the most efficient tool for web development. A feature like Game Mode could offer some performance improvements, especially while also running a beefy AAA game on the same machine, but there may only be so far that Discord will be able to streamline on its current architecture.

Advertisement

Source link

Advertisement
Continue Reading

Tech & AI

Meta-Led Anti-Terrorism Group Faces Mass Resignation of Expert Advisers

Published

on

Six of the nine independent experts on the advisory board of the Global Internet Forum to Counter Terrorism—a consortium run by several of the biggest US tech companies—resigned on Monday, according to a letter seen by WIRED and interviews with three of the people.

The tensions between the independent advisory committee and the GIFCT date back to an email the counterterrorism and free speech experts received in July from Meta’s Nell McCarthy, a vice president overseeing content policy. For years, the group had advised the GIFCT on how to prevent platforms from becoming havens for the radical organizations and individuals blamed for some of the world’s worst mass violence.

But McCarthy wrote that while the consortium welcomed the experts’ insights on violent trends, it no longer desired their scrutiny on the effectiveness of Big Tech’s efforts to curtail violence. Meta and other leaders wanted to “refresh” the 6-year-old independent advisory committee the experts sat on, she wrote. Meta currently serves as chair of GIFCT’s operating board, giving it outsized influence over policy changes, though other companies on the panel must ultimately approve.

New additions to the rotating advisory committee had previously been elected by current members; under the plan laid out in July, they would instead be picked by tech companies. The committee would be barred from weighing in on key topics such as the consortium’s performance and making recommendations together as a group. Its role as a watchdog would be neutered, advisers believed.

Advertisement

In their resignation letter, the departing members of the committee wrote that their appeals against the plan had been “ignored” and that, in turn, they had “lost confidence in the GIFCT’s ability to deliver effectively on its founding mission” to prevent terrorists from exploiting online services. “We all know that a body that cannot scrutinise, take a position, or evaluate is not an advisory body at all,” the letter stated. “It is decoration and accountability theatre.”

Meta deferred comment on the resignations to the GIFCT. An unsigned statement sent to WIRED by a GIFCT spokesperson on behalf of the consortium’s leadership and the Meta-chaired operating board says the proposed changes have been “informed by several rounds of feedback” and are not yet final. They came out of discussions on “how to more effectively engage civil society and governments for substantive input” as “multi-stakeholderism is a core principle” for the GIFCT.

The consortium has about 35 members; other long-time board members include Microsoft and YouTube. A small staff alerts members to violent content, helps them exchange threat intelligence, and commissions research on countering extremism. While the coordination has helped some platforms combat problematic content, critics believe the group isn’t living up to its potential.

A WIRED investigation in 2024 uncovered several issues with GIFCT, including Meta delaying TikTok’s membership bid and poor relations between the companies at the helm and the unpaid independent advisory body. It also revealed failures in the tip-sharing database the consortium oversees to coordinate takedowns of problematic content.

Advertisement

The dismantling of the advisory group threatens to deteriorate the organization’s work further at a time when balancing free expression and online safety has become more challenging. Generative AI tools have simplified content creation but imposed limited guardrails.

Extremist content, including some that is now AI-generated, that promotes organizations such as Islamic State remains a persistent issue. Newer nihilistic collectives have turned to AI-supported scams such as sexploitation to coerce young victims into carrying out violence and abuse. Several AI chatbots have been accused of facilitating violence.

“A Shame”

The experts who resigned include university researchers and representatives of civil society organizations. They had agreed with McCarthy on the need for changes to improve the results of the decade-old anti-terrorism consortium. But they believe the proposal, which could be finalized soon, amounts to a step backward.

“There won’t be critical voices raising concerns about what GIFCT is doing or is not doing,” one of the departing experts says. “It may seem politically convenient for them to abolish the independent advisory committee, but they are going to regret it in the longer term.”

Advertisement

Source link

Continue Reading

Tech & AI

SpaceX’s Latest Starship Mission Reached Low-Earth Orbit

Published

on

The successful mission also deployed 26 of SpaceX’s latest Starlink satellites.

For its 14th flight, SpaceX’s Starship powered by its Super Heavy megarocket has entered low-Earth orbit for the first time. SpaceX kicked off this major undertaking early Monday morning but had to deal with some hiccups on the way, including losing one of its six Raptor engines. Ultimately, SpaceX decided to push on with the mission and successfully reached orbit albeit with some compromise.

SpaceX originally planned to have Starship orbit Earth six times over a span of nearly 10 hours for the Flight 14 mission. With one of the engines offline, the plan changed to only spend approximately three hours in orbit before reentering the Earth’s atmosphere and landing in the Pacific Ocean. As part of the same mission, SpaceX managed to deploy 26 of its Starlink V3 satellites into orbit. SpaceX said that its Starlink team has made contact with all newly-deployed 26 satellites in orbit, which will eventually be used to improve Internet speeds for customers. While previous Starship missions also carried several V3 satellites, they only remained in suborbital space and served as test flights to see if the new satellites would connect to the existing Starlink constellation.

While Starship’s flight 14 marked a major milestone of reaching orbit, the mission also served as a test of the reusability of its Super Heavy rocket. After providing the necessary boost to Starship, Super Heavy landed in the Gulf of Mexico, where it will eventually be retrieved, but not by a launch tower‘s “chopsticks” as previously demonstrated.

Advertisement

Source link

Advertisement
Continue Reading

Tech & AI

Jet Megatextures Demo For ESP32-S3

Published

on

Mipmapping is a good way to add a lot more detail to a 3D scene without overburdening the rendering hardware with detail that won’t be seen by the user. This level-of-detail rendering technique was demonstrated on the N64 console hardware a few years ago by [James Lambert] with [Michael Biggins], also known as [PhonicUK], now demonstrating it on the ESP32-S3 using his own Jet rendering engine.

Although level-of-detail rendering really speeds things up, it does also require far larger texture sizes, with [James]’s N64 demo taking up 40 MB of a 64 MB cartridge. To fit it on an ESP32-S3 with 16 MB of PSRAM and no SD card expansion or such the textures were further compressed to use 8-bit indexing, resulting in a mere 5.01 MB of textures.

There’s a demonstration video over on the associated Reddit thread, which shows the camera moving through the scene. Even if not as exciting as the Wipeout port by [Michael] that we previously covered, it does make clear that even without a proper 3D GPU the ESP32-S3 is already a pretty capable gaming machine that can go toe-to-toe with some 1990s consoles.

Advertisement

Source link

Advertisement
Continue Reading

Tech & AI

These Extremists Are Running for Election in November

Published

on

There are five weeks left until the midterm elections, and extremism is on the ballot in much of the US. A WIRED review of candidates running for statewide and federal positions in November, along with exclusive data on candidates running for state-level positions, reveals hundreds of Republican candidates who openly express virulently hateful ideologies, share racist content online, have close ties to white supremacist and antisemitic figures, and are members of far-right groups online. President Donald Trump and his administration have openly embraced, endorsed and defended many of these candidates.

At a local level, over 500 candidates running for state legislator positions in November are members of far-right groups on Facebook that promote militias, gun rights, and Christian nationalism, according to data collected by the Institute for Research and Education on Human Rights and shared with WIRED.

While many extremist candidates—such as groyper James Fishback and antisemitic influencer Dan Bilzerian— didn’t make it through GOP primaries, many made it to the general election, and a number of them are expected to win.

“The candidates are taking a page out of the Trump administration’s playbook,” Luke Baumgartner, a former research fellow at George Washington University’s Program on Extremism, tells WIRED. Baumgartner claims that many of the candidates running in November have been inspired by those in the White House. “In essence, the executive branch has handed them a permission slip to say and do what would have been unthinkable during the George W. Bush, McCain, or [Mitt] Romney eras of the GOP,” he says.

Advertisement

Extremist rhetoric has led to real world political threats. In 2025, terrorism and targeted violence incidents rose 19 percent compared to 2024, according to researchers at the University of Maryland; the US Capitol Police reported an increase in “threat assessment cases” against members of Congress for the third year in a row, with a 58 percent increase from 2024; and the US Marshals Service documented threats against almost 400 judges, a roughly 5 percent increase from the previous year.

Here are five races involving candidates who have shared extremist ideologies or have close ties to extremist figures, that WIRED is watching ahead of the November midterms.

The Texas Railroad Commissioner Race

MANSFIELD TEXAS  APRIL 15 Tarrant County Republican Party Chair Bo French speaks during a rally on Tuesday April 15 2025...

Photo-Illustration: WIRED Staff; Getty Images

Bo French, the GOP candidate for Texas Railroad Commissioner, is so extreme that Republican strategist Karl Rove has said he would vote for a Democrat rather than supporting a “bigot.”

Source link

Advertisement
Continue Reading

Tech & AI

Detachable mop heads and top-tier cleaning make the affordable Roborock Qrevo 2 Pro a dream for mixed floors

Published

on

Why you can trust TechRadar


We spend hours testing every product or service we review, so you can be sure you’re buying the best. Find out more about how we test.

Roborock Qvero 2 Pro: 30-second review

The Qrevo 2 Pro is the latest robot vacuum and mop combo cleaner from Roborock and includes detachable mop plates to help ensure it doesn’t get carpets wet while cleaning.

Cleaning performance is a match for some of the most expensive options on the market with its mopping being as good as I have ever tested making it a fantastic pick for the price.

Advertisement

Source link

Continue Reading

Tech & AI

New StandBy faces revealed for iPhone Duo

Published

on

The forthcoming iPhone Duo has more features than Apple has revealed, including a whole series of faces for its StandBy mode. Here’s what to eventually look for.

While pre-orders for iPhone Duo don’t start until October 16, and the Xcode betas still don’t show developers everything, one has found many new options coming to iOS 27 for this device.

Developer pdfu reports that the Xcode 27.1 simulator is lacking Rushmore, an app that is for displaying the new StandBy faces. But despite that, they have managed to get certain of the new faces running.

These working ones are variants on familiar clock and calendar faces as used on the iPhone‘s current StandBy mode. But code references describe several more options.

Just because something is referenced in code, it doesn’t necessarily mean that it will launch immediately. But those code references show five more faces:

  • Home Camera: up to nine camera views
  • Home Module
  • Flow
  • Fade
  • Snoopy

There are no details for Home Modular, Flow, or Fade. But the code for Flow also includes the term ResponsiveArt, which suggests that it will at least be an animated face.

Face editor

The iPhone Duo will also feature a revised editor for customizing these StandBy faces. It’s very similar to the existing one on iPhone and is perhaps more like the Apple Watch face editor.

Advertisement

Users can swipe left and right to adjust, for instance, the style of an analog clock, its numerals, light mode and dark mode, plus the color of the face and the hands.

Some of these clock faces also have room for two widgets. Then some more are digital instead of analog and there pdfu has found code references for five layouts:

  • StandBy
  • Stacked
  • Top
  • Middle
  • Bottom

The presumption is that all but the StandBy one may actually be intended for when the iPhone is opened like a book.

Developer pdfu has a strong track record for examining beta code. They confirmed that the iPhone Duo would use Touch ID, for instance, and most recently uncovered that Siri could be replaced by Claude or ChatGPT.

Advertisement

Source link

Continue Reading

Tech & AI

JadePuffer agentic AI attacks target Azure, destroy cloud resources

Published

on

JadePuffer agentic AI attacks target Azure, destroy cloud resources

The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components.

The malware emerged in July, with researchers at cloud security company Sysdig highlighting that it uses AI agents to automate the entire attack chain, from reconnaissance, credential theft, and lateral movement to persistence and data encryption.

Shortly after, the company noted that JadePuffer expanded its focus to AI assets, training datasets, and vector databases, using a tool called EncForge.

Microsoft Security Research observed two JadePuffer attacks in June that mapped cloud resources, retrieved storage account keys, and deleted Azure Storage accounts.

Advertisement

The destructive stage lasted seven minutes and targeted more than 100 storage accounts, as well as Key Vaults, Function Apps, Virtual Machines, and App Services.

Although the threat actor was able to delete most of the targeted Azure Storage accounts, some remained unaffected because of Azure resource locks and storage account-level protections.

Microsoft tracks the JadePuffer threat actor as Storm-3168 and says it used two compromised service principals – security identities that enable applications, hosted services, and automated tools to authenticate to Azure and access assigned resources.

Both service principals belonged to the same tenant. One was used for reconnaissance and resource discovery, while the other “performed discovery, destructive operations, and credential collection.”

Advertisement
Timeline of observed attacks
Timeline of observed attacks
Source: Microsoft

The attacker removed backup and recovery protections (Azure Site Recovery locks), indicating an effort to make restoration more difficult.

This operational pattern could further support ransomware extortion, although Microsoft did not report anything about financial demands and didn’t confirm data theft in the observed cases.

According to the researchers, attempts to delete Azure SQL databases failed because the attacker used an unsupported API version. Attempts to remove recovery protection locks also failed.

“The parallel targeting of Azure SQL databases and storage accounts suggests an effort to broaden the destructive impact across different data services rather than concentrating on a single resource type,” Microsoft said.

Roughly half an hour after the wipe attempts, Storm-3168 returned to perform more than 30 requests for storage account keys, most of which succeeded.

Advertisement

Microsoft could not determine exactly how the initial access occurred, but noted that credentials for one service principal appeared in a public GitHub issue before the attacks.

The researchers recommend several mitigation steps and guidance for system administrators, including activating cloud workload protections, checking for secrets in public repositories, and evaluating Azure RBAC permissions against least-privilege principles.


article image

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Source link

Advertisement
Continue Reading

Tech & AI

Xiaomi And Motorola Launched Phones At Snapdragon Summit. Here’s Why I’m Excited For Each One

Published

on





Snapdragon Summit in Maui, Hawaii, has come and during the show, Qualcomm (who paid for my travel and accommodations) announced two new top tier phone processors. They are the Snapdragon 8 Elite Gen 6 and the Snapdragon 8 Elite Extreme Gen 6. The former is the successor to last year’s flagship while the latter is a new even more premium tier of performance.

Both chips run off of two 5GHz prime cores and six 4GHz performance cores built on a 2nm process. The key differences between the two include Matrix cores included in the Extreme’s GPU, additional video processing (8K/60fps) on the Extreme, and more. For the average consumer, you probably won’t notice a ton of differences between the two in day-to-day tasks, but when it comes to gaming, AI (agentic AI was a key theme at the conference), and sustained performance, that’s when you’ll notice the difference.

According to Qualcomm, the reason for the two premium tiers stems from phone maker demand. Consumers have been vying for more premium options in the smartphone space, and these chips are designed to address that need. Speaking of phones, there were two major phone announcements at Snapdragon Summit. The Xiaomi 18 Pro and Pro Max will run the Elite and Extreme processors respectively. The Motorola Signature 27 will also run the Extreme chip, and both of those phones are exciting for different reasons.

Advertisement

Motorola Signature 27 brings Motorola back into flagship territory

Motorola’s Signature series of smartphones have typically been reserved for overseas sales only, with no presence in the U.S. That looks to change with the Signature 27, which will get a North American release. The Signature 27 is peak Motorola flagship material — Snapdragon 8 Elite Extreme Gen 6, a six-antenna design, a 200-megapixel telephoto lens, and Bang & Olufsen audio, which was recently announced.

Those specs all sound great, but it’s mostly just great to see a Motorola flagship on U.S. shores again. Motorola has been doing very well with its flip phones and midrange candybar phones, but it’s been a while since a real flagship came to the States, so that alone is worth celebrating. That’s especially true in light of OnePlus’s exit from the U.S. market — there’s another premium flagship taking its place, and it looks like a real beast. Stay tuned to SlashGear for more news about the Motorola Signature coming — hopefully — soon.

Advertisement

Xiaomi 18 Pro and 18 Pro Max split the difference

Xiaomi is a phone that will not come to the U.S., though it will likely be relatively easy to import if you so choose. The 18 Pro series brings a boatload of great specifications to the table, and it also represents the diversity that Qualcomm was talking about. Both phones have similar specifications and capabilities, and they also bring a couple of neat features to the lineup as well.

The first is the rear-facing screen. Picture an iPhone 18 Pro, and replace the camera island with a rear facing screen. You can use this for taking selfies with the main cameras, but Xiaomi will also bring some apps and functionality to the rear screen as well. The options we could play with were limited to things like answering calls, playing music, and some AI-generated animals, which were admittedly pretty cute, but not terribly functional.

Advertisement

The other cool thing, and honestly the thing that excites me the most, is the privacy display. This works basically the same as the Samsung Galaxy S26 Ultra’s display with pixels that turn off, and software that runs the whole thing. Xiaomi re-did the subpixels a bit, which is supposed to give better color even with the privacy display on, and it was not terribly noticeable, but it’ll take more experimentation to determine. But I mainly like the idea that someone else beyond Samsung is making this feature. Hopefully it’s only a matter of time before it catches on with more phone makers.



Advertisement

Source link

Continue Reading

Trending

Copyright © 2025