Posted on

Modders do what AMD can’t (or won’t) by adding FSR 4 support to more games

  • AMD’s FSR 4 can now be used in more games that don’t have an official implementation, thanks to the Optiscaler mod
  • It isn’t compatible with all games, as FSR 4 reportedly doesn’t support Vulkan yet
  • Players may run into trouble using the mod in anti-cheat games

The reception to AMD’s Radeon RX 9070 series GPU launch was mixed considering the inflated prices, and lack of availability for some. However, if you were fortunate enough to land one at MSRP, a new and improved mod may make life a little easier regarding AMD‘s new upscaling method and its compatibility in games.

As reported by VideoCardz, modders have managed to implement AMD FSR 4 support in numerous titles that already have DLSS or XeSS (Nvidia and Intel’s similar technologies, respectively). This is all thanks to a mod known as Optiscaler on GitHub from cdozdil, which has previously been used to enable other older versions of upscaling methods in titles that don’t have official support.

It’s an important mod for Radeon RX 9070 and RX 9070 XT users to take advantage of since so far, there are only a few titles that have official FSR 4 implementation from game developers. FSR 4 significantly enhances visual quality, particularly with its performance mode – which is arguably a game changer as previous FSR models suffered from ghosting issues that caused a blurry image or trail left behind by in-game UI or character models when in motion.

As well as super-resolution (Xe Super Sampling for Intel’s XeSS), frame generation can also be injected in unsupported games – this is similar to Nukem (on GitHub) which uses DLSS’ Frame Generation in games to implement FSR 3’s frame generation.

While it certainly isn’t as well polished as official support (it’s currently an experimental addition), it could be enough to hold users over for the time being. It’s worth noting that not all games are supported on Optiscaler as of now, which is supposedly because FSR 4 doesn’t support Vulkan (a graphics API used for rendering in plenty of games) yet.

There’s no guarantee that certain titles will even get official FSR 4 implementation – it took CD Projekt Red several months to add FSR 3 to Cyberpunk 2077 (likely because of its partnership with Nvidia), so don’t expect it to happen overnight with FSR 4 – especially with other titles that share a similar agreement with Nvidia.

The AMD Radeon Graphics badge displayed over an RGB gaming keyboard.

(Image credit: Ralf Liebhold / Shutterstock)

Modding capabilities as such should be allowed on anti-cheat games

While mods like this are great for RDNA 4 users and those who can’t use frame generation (mostly owners of Nvidia RTX 3000 series and older GPUs), the only major downside is that it doesn’t seem to work with games that use anti-cheating tools.

{ window.reliablePageLoad.then(() => { var componentContainer = document.querySelector(“#slice-container-newsletterForm-articleInbodyContent-ybjdo6imnFozpiad7eqc4F”); if (componentContainer) { var data = {“layout”:”inbodyContent”,”header”:”Get daily insight, inspiration and deals in your inbox”,”tagline”:”Sign up for breaking news, reviews, opinion, top tech deals, and more.”,”formFooterText”:”By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.”,”successMessage”:{“body”:”Thank you for signing up. You will receive a confirmation email shortly.”},”failureMessage”:”There was a problem. Please refresh the page and try again.”,”method”:”POST”,”inputs”:[{“type”:”hidden”,”name”:”NAME”},{“type”:”email”,”name”:”MAIL”,”placeholder”:”Your Email Address”,”required”:true},{“type”:”hidden”,”name”:”NEWSLETTER_CODE”,”value”:”XTR-D”},{“type”:”hidden”,”name”:”LANG”,”value”:”EN”},{“type”:”hidden”,”name”:”SOURCE”,”value”:”60″},{“type”:”hidden”,”name”:”COUNTRY”},{“type”:”checkbox”,”name”:”CONTACT_OTHER_BRANDS”,”label”:{“text”:”Contact me with news and offers from other Future brands”}},{“type”:”checkbox”,”name”:”CONTACT_PARTNERS”,”label”:{“text”:”Receive email from us on behalf of our trusted partners or sponsors”}},{“type”:”submit”,”value”:”Sign me up”,”required”:true}],”endpoint”:”https://newsletter-subscribe.futureplc.com/v2/submission/submit”,”analytics”:[{“analyticsType”:”widgetViewed”}],”ariaLabels”:{}}; var triggerHydrate = function() { window.sliceComponents.newsletterForm.hydrate(data, componentContainer); } if (window.lazyObserveElement) { window.lazyObserveElement(componentContainer, triggerHydrate); } else { triggerHydrate(); } } }).catch(err => console.error(‘%c FTE ‘,’background: #9306F9; color: #ffffff’,’Hydration Script has failed for newsletterForm-articleInbodyContent-ybjdo6imnFozpiad7eqc4F Slice’, err)); }).catch(err => console.error(‘%c FTE ‘,’background: #9306F9; color: #ffffff’,’Externals script failed to load’, err)); ]]>

Sign up for breaking news, reviews, opinion, top tech deals, and more.

Titles like Elden Ring, Warhammer 40,000: Space Marine 2, and The Finals, use anti-cheat software which is used to prevent cheating online. While I won’t argue against these measures (even though they can ruin performance in some games), they make mods like Optiscaler effectively useless, as users could be banned if they are using it.. Now, I haven’t seen cases of this myself without players genuinely cheating, but it doesn’t mean it’s impossible either.

I’ve shared the same frustrations when it comes to games that don’t support ultrawide resolutions and aspect ratios – those games usually require modification, as evident in Street Fighter 6 which cannot be played at 21:9 or 32:9 aspect ratios unless you use RE Framework by Praydog on GitHub, but Capcom views modding as cheating.

It’s a very similar scenario in this case – gamers spend hard-earned money to acquire new hardware, and if you can’t even use upscaling methods like FSR 4 in a large number of titles, mods like Optiscaler are the only way. So, with those anti-cheat measurements, maybe dial it down a little…Please?

You may also like…

Source

Posted on

AMD RX 9070 GPU spec and benchmark rumors cast fresh doubt on power usage and performance – but I wouldn’t worry about the latter

  • AMD’s RX 9070 GPUs have witnessed spillage around their specs and possible performance levels
  • Power-wise the RX 9070 XT looks a bit hungrier than expected, but the vanilla 9070 is pitched at a more comfortable level
  • The benchmarks paint a shakier picture of performance than previous leaks – but there are good reasons not to worry here, thankfully

AMD’s RX 9070 GPUs will soon be officially revealed – in a week there’s a big press event dedicated to these cards – but ahead of that, we’ve just been treated to some purported leaked specs and benchmarks.

In terms of the specs, VideoCardz comes with news that Hoang Anh Phu, a regular leaker on X, posted some details of the RX 9070 models (although that post has since been deleted).

Salt firmly clutched in hand, then, we can consider the revelations apparently made in a recent AMD press briefing.

We’re told the RX 9070 XT will run with 64 Compute Units (4,096 Stream Processors) and a boost clock of 2970MHz, all as previously rumored, with a power usage (TBP or Total Board Power) of 304W.

As for the vanilla RX 9070, that supposedly has 56 Compute Units (3,584 Stream Processors) and a boost clock of 2520MHz, with a 220W power consumption.

Meanwhile, both of these inbound RDNA 4 graphics cards from AMD have had benchmarks leaked, giving us a rough idea of where their performance may lie (scoop up even more salt here, though).

Wccftech noticed the benchmarks highlighted by Benchleaks (on X) which show that the RX 9070 XT scored 179,178 in the OpenCL test from Geekbench, and 177,395 points in Vulkan (both of these are graphics tests).

{ window.reliablePageLoad.then(() => { var componentContainer = document.querySelector(“#slice-container-newsletterForm-articleInbodyContent-t2jgsf7N7Boy3QNgFJGf37”); if (componentContainer) { var data = {“layout”:”inbodyContent”,”header”:”Get daily insight, inspiration and deals in your inbox”,”tagline”:”Sign up for breaking news, reviews, opinion, top tech deals, and more.”,”formFooterText”:”By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.”,”successMessage”:{“body”:”Thank you for signing up. You will receive a confirmation email shortly.”},”failureMessage”:”There was a problem. Please refresh the page and try again.”,”method”:”POST”,”inputs”:[{“type”:”hidden”,”name”:”NAME”},{“type”:”email”,”name”:”MAIL”,”placeholder”:”Your Email Address”,”required”:true},{“type”:”hidden”,”name”:”NEWSLETTER_CODE”,”value”:”XTR-D”},{“type”:”hidden”,”name”:”LANG”,”value”:”EN”},{“type”:”hidden”,”name”:”SOURCE”,”value”:”60″},{“type”:”hidden”,”name”:”COUNTRY”},{“type”:”checkbox”,”name”:”CONTACT_OTHER_BRANDS”,”label”:{“text”:”Contact me with news and offers from other Future brands”}},{“type”:”checkbox”,”name”:”CONTACT_PARTNERS”,”label”:{“text”:”Receive email from us on behalf of our trusted partners or sponsors”}},{“type”:”submit”,”value”:”Sign me up”,”required”:true}],”endpoint”:”https://newsletter-subscribe.futureplc.com/v2/submission/submit”,”analytics”:[{“analyticsType”:”widgetViewed”}],”ariaLabels”:{}}; var triggerHydrate = function() { window.sliceComponents.newsletterForm.hydrate(data, componentContainer); } if (window.lazyObserveElement) { window.lazyObserveElement(componentContainer, triggerHydrate); } else { triggerHydrate(); } } }).catch(err => console.error(‘%c FTE ‘,’background: #9306F9; color: #ffffff’,’Hydration Script has failed for newsletterForm-articleInbodyContent-t2jgsf7N7Boy3QNgFJGf37 Slice’, err)); }).catch(err => console.error(‘%c FTE ‘,’background: #9306F9; color: #ffffff’,’Externals script failed to load’, err)); ]]>

Sign up for breaking news, reviews, opinion, top tech deals, and more.

In those same tests, the vanilla RX 9070 GPU managed to attain 140,842 points in OpenCL, while it hit 158,520 in Vulkan.

Those are just numbers, obviously, and only useful if we compare them to existing results for other GPUs, as Wccftech does. The tech site found that the RX 9070 XT is about 6% faster than the RX 7900 XT in OpenCL, and a touch slower (4% off the pace) in Vulkan compared to that same current-gen graphics card.

The RX 9070 (non-XT) on the other hand is about even with the 7800 XT in OpenCL and about 6% slower than this GPU in the Vulkan test (where it’s only a smidge faster than the 7700 XT, in fact).

female PC gamer playing on a desktop

(Image credit: Gorodenkoff / Shutterstock)

Analysis: Reasons to be doubtful (and cheerful)

At this point you might be thinking: huh, weren’t these RDNA 4 GPUs supposed to be faster than this based on previous rumors? Well, yes, they were. In fact past chatter has suggested that AMD was aiming to get the RX 9070 XT to be slightly faster than the RTX 4080 (Founders Edition model from Nvidia).

Now, if the RX 9070 XT is not much faster than the RX 7900 XT as is indicated here, that current-gen AMD GPU is considerably off the pace of a vanilla RTX 4080, so this latest leak is disappointingly slow compared to what we’ve been primed to expect.

However, this is just a few Geekbench runs, and as I always say when it comes to gauging gaming graphics cards, this is not nearly the best way to judge performance. Synthetic benchmarks aren’t ideal full-stop, and Geekbench is low on the ladder of these metrics to boot.

Other leaked performance estimations (including 3DMark results, and a glimpse of the vanilla 9070 flexing its muscles in Call of Duty: Black Ops 6) suggest a beefier GPU than what we’re seeing here, that’s for sure. And AMD is certainly putting expectations firmly on the table with its new naming scheme – the RTX 9070 models are clearly intended to square up to Nvidia’s RTX 5070 offerings.

So in short, I really wouldn’t worry about these fresh benchmarks, and I’d be surprised if they weren’t proven to be out of line eventually.

The indicated power usage figures are interesting, certainly. Previously we’ve seen suggestions that the RX 9070 XT could demand up to 330W of power, although that’s for top-end boards, with the entry-level (and reference) graphics cards expected to pitch in at 260W. This leak claiming 304W for the reference board is a bit higher than expected, then (while top-end GPUs going very heavy with the power is something that’s already been rumored, and not really a surprise, of course).

The RX 9070, on the other hand, sounds like it’s in a theoretically much more comfortable spot for a lot of gaming PCs out there, being rated at 220W.

All these rumors will be cleared up soon enough, because as noted, AMD’s official launch event is now imminent, where we’ll find out the hefty-sized missing piece from the next-gen Radeon puzzle – those MSRPs.

Because after all, whatever performance comes out at relative to Nvidia’s new mid-range graphics cards, the right price tag can still make RDNA 4 a potent rival, or perhaps even a force to blow away Blackwell. (Okay, so the latter is doubtless wishful thinking, but come on AMD – let’s have a pricing surprise of a good nature in the GPU world for once, eh?).

You might also like…

Source

Posted on

OpenAI says it has evidence DeepSeek used ChatGPT to train its AI

Chinese startup DeepSeek stunned the world with its sophisticated DeepSeek R1 reasoning model, which is as good as ChatGPT o1. That’s not a surprising achievement; it’s only a matter of time before other AI models can replicate what OpenAI has done in terms of AI reasoning. Also, OpenAI will soon make o3 available, the successor to o1.

What really shocked the markets was DeepSeek’s research, which showed that the company was able to train R1 to achieve the same capabilities at a fraction of the cost of training o1.

Because of US sanctions, DeepSeek didn’t have access to the latest NVIDIA GPUs that AI firms like OpenAI use to train high-end AI models. It turned to software optimizations to compensate for what it lacked in hardware to create an AI model that could match ChatGPT o1.

But it turns out software optimization isn’t everything DeepSeek might have done to train its AI. OpenAI claims it has evidence that DeepSeek distilled ChatGPT to train the DeepSeek AI models.

Tech. Entertainment. Science. Your inbox.

Sign up for the most interesting tech & entertainment news out there.

By signing up, I agree to the Terms of Use and have reviewed the Privacy Notice.

If that’s true, the practice violates OpenAI’s terms of service for ChatGPT. Ironically, if OpenAI’s claim is true, it’ll make the company experience what many creators felt when they discovered OpenAI may have trained its ChatGPT models using copyrighted materials without consent.

OpenAI told The Financial Times it found evidence that DeepSeek used the US models to train DeepSeek AI.

OpenAI found evidence of “distillation,” which it believes came from DeepSeek. Distillation is a process where AI firms use an already trained large AI model to train smaller models. The “student” models will match similar results to the “teacher” AI in specific tasks.

Some early DeepSeek testers were surprised to see the AI identify itself as ChatGPT in early responses, which prompted speculation that DeepSeek AI might have been trained with ChatGPT chats.

OpenAI claims that DeepSeek might have distilled ChatGPT make sense, but it’s unclear whether the US AI firm can prove the IP theft beyond doubt. Even if it can provide conclusive evidence that DeepSeek used ChatGPT to train its AIs, there’s probably little OpenAI can do. After all, DeepSeek R1 is already out in the wild.

DeepSeek made its models available open-source, which means anyone can install them on computers. The DeepSeek app is topping the App Store, and it’s available in the Google Play store. Unless DeepSeek is banned in the US, the app won’t go away anytime soon.

The FT says that OpenAI and Microsoft investigated accounts believed to belong to DeepSeeka last year. They were using OpenAI’s API for ChatGPT access. OpenAI blocked access, suspecting they may rely on distillation to train other models.

DeepSeek has not commented on these allegations. The company is seen as a hero in China after the release of DeepSeek R1, which wiped nearly $1 billion from the US market.

On the other hand, it’s not just Chinese AI companies like DeepSeek that might rely on the distillation of ChatGPT and other frontier AIs to train better AI models. The FT notes that it’s common practice for AI labs in China and the US to use outputs from bigger companies.

OpenAI and others have already trained AI using humans to teach the models how to produce responses that sound more conversational. This is an expensive process, so smaller firms will distill established models to train smaller ones. In such a case, a company like DeepSeek would have gotten the human feedback step for free.

I said earlier that DeepSeek’s use of distillation to train R1 is something others could benefit from, Apple included. I wasn’t referring to stealing AI work done by others but to using advanced, proprietary models to train smaller models that Apple might need for its on-device Apple Intelligence approach.

If OpenAI has strong evidence that DeepSeek used ChatGPT to train its AI models, we could be looking at the second good reason to ban DeepSeek in the US and elsewhere. The first is that DeepSeek collects plenty of user data and sends it all to China.

A ban is a process that will take time. And, again, even if all of this is successful, DeepSeek will still have strong AI models on its hands, which it can use to create next-gen AI of its own.

Meanwhile, OpenAI still has to deal with allegations that it used copyrighted content without consent to create ChatGPT.

Source

Posted on

Intel is taking the budget GPU market by storm

  • Intel’s upcoming Arc B570 GPU is only 12% slower than B580 according to early benchmark
  • The Arc B580 will start at $249 while the B570 will start at $219
  • Intel has taken a great leap in its GPU and gaming focus

While Nvidia and AMD‘s new GPUs may have taken the spotlight over recent weeks with a slew of big new reveals, notably Team Green’s RTX 5000 series at CES 2025, Intel is slowly becoming a dark horse within the budget GPU market – and PC gamers with tight budgets should pay attention.

According to an early test result spotted in the Geekbench 6 database (initially highlighted by Wccftech), the Intel Arc B570 is only 12% slower – perfect, since it’s also 12% cheaper than the Arc B580, which we noted offers fierce competition in terms of performance against its affordable rivals in our Intel Arc B580 review. This was made evident with the B570’s 86,718 score compared to the B580’s 98,343 in the OpenCL API benchmark.

Whilst there are multiple different benchmark results for the B580 (with the same expected for the B570 once it hits full release), Wccftech states most range between 95,000 and 100,000 points, suggesting slower performance on its lower-spec counterpart.

Considering the price of the Arc B580 ($249 / £249 / AU$439) and the Arc B570 ($219 / £219 / around AU$350), PC gamers on a budget will have a variety of competent options for 1080p gaming this generation. With Team Blue’s XeSS upscaling method gradually improving, Intel could claim pole position to become the budget GPU king if it can compete with Nvidia’s DLSS and AMD’s FSR.

A pair of Intel Arc Alchemist chips in front of a dark purple background

(Image credit: Intel)

Is it time to take Intel’s GPU and gaming efforts seriously?

Nvidia has consistently ruled over the years, while Intel has focused on providing stronger processors for PC builds and AMD has historically been a plucky underdog in both markets. The tide is now turning within the budget GPU space, and it’s safe to say that Team Blue is now one to take seriously.

Besides the upcoming Arc B580 and B570, Intel’s new Lunar Lake processors have been shown to benefit handheld gaming PCs as well – the MSI Claw 8 AI+ is powered by the Ultra Core 7 258V processor, which will reportedly allow gamers to play games like Cyberpunk 2077 on higher settings using ray tracing.

There’s still a long way to go for Intel to catch up to AMD and Nvidia in terms of providing high-end GPU hardware, but it’s already off to a great start – I hope its next lineup of GPUs showcases a big step forward in performance.

{ window.reliablePageLoad.then(() => { var componentContainer = document.querySelector(“#slice-container-newsletterForm-articleInbodyContent-VvpZPG6mx83Sat9irGuqDG”); if (componentContainer) { var data = {“layout”:”inbodyContent”,”header”:”Get daily insight, inspiration and deals in your inbox”,”tagline”:”Sign up for breaking news, reviews, opinion, top tech deals, and more.”,”formFooterText”:”By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.”,”successMessage”:{“body”:”Thank you for signing up. You will receive a confirmation email shortly.”},”failureMessage”:”There was a problem. Please refresh the page and try again.”,”method”:”POST”,”inputs”:[{“type”:”hidden”,”name”:”NAME”},{“type”:”email”,”name”:”MAIL”,”placeholder”:”Your Email Address”,”required”:true},{“type”:”hidden”,”name”:”NEWSLETTER_CODE”,”value”:”XTR-D”},{“type”:”hidden”,”name”:”LANG”,”value”:”EN”},{“type”:”hidden”,”name”:”SOURCE”,”value”:”60″},{“type”:”hidden”,”name”:”COUNTRY”},{“type”:”checkbox”,”name”:”CONTACT_OTHER_BRANDS”,”label”:{“text”:”Contact me with news and offers from other Future brands”}},{“type”:”checkbox”,”name”:”CONTACT_PARTNERS”,”label”:{“text”:”Receive email from us on behalf of our trusted partners or sponsors”}},{“type”:”submit”,”value”:”Sign me up”,”required”:true}],”endpoint”:”https://newsletter-subscribe.futureplc.com/v2/submission/submit”,”analytics”:[{“analyticsType”:”widgetViewed”}],”ariaLabels”:{}}; var triggerHydrate = function() { window.sliceComponents.newsletterForm.hydrate(data, componentContainer); } if (window.lazyObserveElement) { window.lazyObserveElement(componentContainer, triggerHydrate); } else { triggerHydrate(); } } }).catch(err => console.error(‘%c FTE ‘,’background: #9306F9; color: #ffffff’,’Hydration Script has failed for newsletterForm-articleInbodyContent-VvpZPG6mx83Sat9irGuqDG Slice’, err)); }).catch(err => console.error(‘%c FTE ‘,’background: #9306F9; color: #ffffff’,’Externals script failed to load’, err)); ]]>

Sign up for breaking news, reviews, opinion, top tech deals, and more.

You may also like…

Source

Posted on

Microsoft just added DeepSeek R1 to Azure AI Foundry and GitHub

When it comes to artificial intelligence, Microsoft refuses to be left behind. On Wednesday, the Redmond company announced that the R1 model from DeepSeek is now available on Azure AI Foundry and GitHub. This surprisingly sudden move comes despite the fact that OpenAI claims DeepSeek built AI models using its data without permission.

“As part of Azure AI Foundry, DeepSeek R1 is accessible on a trusted, scalable, and enterprise-ready platform, enabling businesses to seamlessly integrate advanced AI while meeting SLAs, security, and responsible AI commitments—all backed by Microsoft’s reliability and innovation,” Microsoft CVP Asha Sharma said in a blog post.

Sharma also repeated DeepSeek’s pitch for R1, explaining that its power and low cost will give more users access to state-of-the-art AI without heavy investment.

Of course, Microsoft understands the concerns raised about DeepSeek during its rapid rise to prominence in recent weeks, including the sheer amount of data the Chinese company collects. According to Microsoft, the model “has undergone rigorous red teaming and safety evaluations, including automated assessments of model behavior and extensive security reviews to mitigate potential risks.” Plus, Azure AI has tools like content filtering and the ability to test applications before deployment to protect developers and end users.

Tech. Entertainment. Science. Your inbox.

Sign up for the most interesting tech & entertainment news out there.

By signing up, I agree to the Terms of Use and have reviewed the Privacy Notice.

If you want to test out DeepSeek R1 through Azure AI Foundry, you will need an Azure account. Once you’re signed in, search for “DeepSeek R1” in the model catalog. After opening the model card, click “Deploy” to obtain the inference API, the key, and access to the playground. You can try out your prompts in the playground to try out R1.

You can also “explore additional resources and step-by-step guides to integrate DeepSeek R1 seamlessly into your applications” on GitHub. Microsoft says Copilot+ PC owners will soon be able to run distilled versions of DeepSeek R1 locally as well.

Source

Posted on

US Treasury incident a clear warning on supply chain security in 2025

A major state-sponsored cyber incident that targeted the United States Department of the Treasury in the weeks prior to Christmas 2024 appears to have begun as the result of a compromise at a third-party tech support supplier, serving as a warning on the precarious security and vulnerable nature of technology supply chains for IT firms and their customers alike.

The cyber attack was allegedly the work of an undisclosed China-backed advanced persistent threat (APT) actor and, according to The Washington Post, it targeted among other things the Office of Foreign Assets Control (OFAC), a department of the Treasury that administers and enforces foreign sanctions against individuals, organisations and countries.

Due to its involvement in sanctions and enforcement actions against malicious cyber actors – it has played a key role in multinational operations against financially motivated ransomware gangs – OFAC presents a very obvious target for threat actors.

In a letter to senators Sherrod Brown and Tim Scott, who sit on the Committee on Banking, Housing and Urban Affairs – a copy of which has been reviewed by Computer Weekly – Treasury assistant secretary for management, Aditi Hardikar, confirmed the department was notified by a third-party software services provider that it had been compromised on 8 December 2024.

The organisation in question, BeyondTrust, said the APT gained access to a key that it was using to secure a cloud-based remote tech support service.

“With access to the stolen key, the threat actor was able override the service’s security, remotely access certain Treasury DO user workstations, and access certain unclassified documents maintained by those users,” wrote Hardikar.

“Treasury has been working with the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), the Intelligence Community, and third-party forensic investigators to fully characterise the incident and determine its overall impact.

“Based on available indicators, the incident has been attributed to a China state-sponsored APT  actor. The compromised BeyondTrust service has been taken offline and at this time there is no evidence indicating the threat actor has continued access to Treasury information,” wrote Hardikar.

The Chinese authorities have denied the Americans’ allegations, with a spokesperson for Beijing’s embassy in Washington DC describing them as “irrational” and part of a “smear campaign”.

BeyondTrust vulnerabilities

The tech firm at the centre of the incident, BeyondTrust, is a US-based supplier with roots dating back to the mid-1980s. It specialises in privileged identity management and privileged access management (PIM/PAM), privileged remoter access and vulnerability management services. It claims more than 20,000 customers in 100 countries, including the likes of tech firms such as Axians and ServiceNow.

It is also particularly well-used in the public sector, with multiple customers in local government, healthcare and utilities, including a number of NHS bodies in the UK.

In a statement posted to its website, BeyondTrust said it identified an incident impacting a “limited number” of Remote Support SaaS customers that arose through the compromise of an application programming interface (API) key. It revoked the key immediately on concluding a root cause analysis into a remote support SaaS technical issue on 5 December 2024, and began notifying affected users, including the Treasury.

It has since identified two specific vulnerabilities within the Remote Support and Privileged Remote Access product lines – one of critical severity and one of medium severity. These have been assigned designations CVE-2024-12356 and CVE-2024-12686 respectively. Both have been patched for both cloud-hosted and on-prem versions as of 18 December 2024.

According to BeyondTrust, the issues are both command injection vulnerabilities that, successfully exploited, enable an unauthenticated remote attacker to execute operating system commands in the context of the site user.

A BeyondTrust spokesperson told Computer Weekly: “BeyondTrust previously identified and took measures to address a security incident in early December 2024 that involved the Remote Support product. BeyondTrust notified the limited number of customers who were involved, and it has been working to support those customers since then. No other BeyondTrust products were involved. Law enforcement was notified and BeyondTrust has been supporting the investigative efforts.”

Security supply chain still a big issue in 2025

With this incident, BeyondTrust unfortunately becomes the latest in a long-line of cyber security specialists to find themselves making headlines after the compromise of products and solutions designed to keep end-users safe.

Avishai Avivi, CISO at SafeBreach, a supplier of breach and attack simulation tools, explained how the breach likely unfolded. “BeyondTrust, unironically, provides a secure method for IT support personnel to provide remote support to end users,” he said. “This method involves establishing a trusted connection between the support person and the end-user.

“This trusted connection punches through traditional perimeter security controls and gives the support person full access and control over the end-user workstation. Once inside, the support person can send documents back over that secure channel or masquerade as the end-user and send the same documents directly.

“The security controls protecting the US Treasury network have no way of knowing something nefarious is happening, as the trusted connection is, well, trusted.

“Was there something that the US Treasury could have done to prevent this? The sad answer appears to be yes. Again, referring to the technical information BeyondTrust provided, the system administrators at the US Treasury, or the vendor likely to provide support services, failed to configure trusted locations from which the support agents could connect. We refer to this as IP whitelisting [allowlisting].

“This failure is a critical risk with any such service [and] the same issue led to notable breaches in 2023 and 2024. This oversight is why we urge all service vendors, especially trusted ICT vendors, to follow the CISA Secure-by-Default guidance.”

Source

Posted on

Leaked Nvidia RTX 5090 laptop GPU benchmarks are weird

  • Nvidia’s RTX 5090 laptop GPU shows inconsistent Geekbench 6 performance scores
  • Fails to score higher than the RTX 4080 or 4090 laptop GPUs in Vulkan
  • It hasn’t launched yet, and there aren’t any official drivers available

CES 2025 finally gave us a look at Nvidia’s new RTX 5000 series of graphics cards, and the flagship RTX 5090 GPU’s performance capabilities compared to the last generation’s RTX 4090 – but early benchmarks for its laptop GPU don’t look very promising.

This comes from BenchLeaks on X, which claims to have leaked Geekbench 6 results of Nvidia‘s RTX 5090 laptop GPU using Vulkan (graphics API used in plenty of games), with its highest score of 114,821. Tom’s Hardware highlighted this as the fourth benchmark among five different tests, with the lowest score sitting at 51,831 and the final test scoring 77,989.

Each benchmark score points towards wildly inconsistent performance for Team Green’s flagship laptop GPU, which failed to score higher than the RTX 4080’s 145,067 and the RTX 4090’s 167,655 Geekbench scores in Vulkan (both of which are for the laptop versions of those GPUs). While these results might be cause for concern, it’s far too early to draw any conclusions.

Nvidia geforce 4070

(Image credit: Nvidia)

Should we be worried about these early benchmarks?

While these tests are almost certainly not great to see, it’s absolutely not a reason to panic. Aside from the fact that these benchmarks are not official, but are claimed to be leaked, the RTX 5000 series hasn’t even officially launched yet (the RTX 5090 will be available at the end of the month), which means the necessary drivers and optimizations have not been made yet.

It’s also important to note that in-game benchmarks are what matter most – while Geekbench 6 can be accurate for measuring the performance capabilities of a GPU, scores are never going to be the same as each test will often vary drastically or closely. Despite the inconsistent scores here, we should wait to see how the RTX 5090 laptop GPU fares across multiple games once Nvidia makes the necessary adjustments and official drivers have been released.

We should be getting both the desktop RTX 5090, alongside gaming laptops with the mobile version, in for review, so make sure you check out our full reviews when they are live for reliable and independent verdicts on just how good (or not) these new GPUs from Nvidia really are.

You may also like…

{ window.reliablePageLoad.then(() => { var componentContainer = document.querySelector(“#slice-container-newsletterForm-articleInbodyContent-ck4ufNKYg8pJpSq6jzS44J”); if (componentContainer) { var data = {“layout”:”inbodyContent”,”header”:”Get daily insight, inspiration and deals in your inbox”,”tagline”:”Sign up for breaking news, reviews, opinion, top tech deals, and more.”,”formFooterText”:”By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.”,”successMessage”:{“body”:”Thank you for signing up. You will receive a confirmation email shortly.”},”failureMessage”:”There was a problem. Please refresh the page and try again.”,”method”:”POST”,”inputs”:[{“type”:”hidden”,”name”:”NAME”},{“type”:”email”,”name”:”MAIL”,”placeholder”:”Your Email Address”,”required”:true},{“type”:”hidden”,”name”:”NEWSLETTER_CODE”,”value”:”XTR-D”},{“type”:”hidden”,”name”:”LANG”,”value”:”EN”},{“type”:”hidden”,”name”:”SOURCE”,”value”:”60″},{“type”:”hidden”,”name”:”COUNTRY”},{“type”:”checkbox”,”name”:”CONTACT_OTHER_BRANDS”,”label”:{“text”:”Contact me with news and offers from other Future brands”}},{“type”:”checkbox”,”name”:”CONTACT_PARTNERS”,”label”:{“text”:”Receive email from us on behalf of our trusted partners or sponsors”}},{“type”:”submit”,”value”:”Sign me up”,”required”:true}],”endpoint”:”https://newsletter-subscribe.futureplc.com/v2/submission/submit”,”analytics”:[{“analyticsType”:”widgetViewed”}],”ariaLabels”:{}}; var triggerHydrate = function() { window.sliceComponents.newsletterForm.hydrate(data, componentContainer); } if (window.lazyObserveElement) { window.lazyObserveElement(componentContainer, triggerHydrate); } else { triggerHydrate(); } } }).catch(err => console.error(‘%c FTE ‘,’background: #9306F9; color: #ffffff’,’Hydration Script has failed for newsletterForm-articleInbodyContent-ck4ufNKYg8pJpSq6jzS44J Slice’, err)); }).catch(err => console.error(‘%c FTE ‘,’background: #9306F9; color: #ffffff’,’Externals script failed to load’, err)); ]]>

Sign up for breaking news, reviews, opinion, top tech deals, and more.

Source

Posted on

From front to back: tech vice-president Dan Lake on Notonthehighstreet.com’s tech strategy

The big news from online marketplace Notonthehighstreet.com (NOTHS) in the build-up to peak trading is its new partnership with delivery platform Deliveroo, announced in September.

NOTHS is one of the early wave of non-food-specific retail businesses partnering with Deliveroo to add speedy fulfilment options to their offering. Screwfix led the charge in 2023, and others such as B&Q, Ann Summers, Wilko, and The Perfume Shop have followed suit in 2024, opening up rapid delivery via the Deliveroo app to London consumers who need their items pronto.

Launching with 15 brands under the umbrella of NOTHS, the partnership enables Deliveroo customers to order personalised gifts on-demand for the first time – via the presence of luxury jewellery and accessories retailer and NOTHS partner Hurley Burley on the app – as well as access to goods from a variety of small non-food businesses.

Paul Wilkinson, Deliveroo product director, paid compliment to his company’s integrations team on a LinkedIn post in October, saying their work means consumers have up-to-date product and availability information “at their fingertips” from launch.

“These use a new dedicated API [application programming interface] that we have designed from the ground up for grocery and retail partners, and it has taken a whole village of amazing people to build and ship this,” he wrote.

Contrastingly, the direct tech integration with NOTHS is non-existent at present, according to Dan Lake, vice-president for technology at the online marketplace. The hardware and software integrations are through the NOTHS brand partners, with a NOTHS logo accompanying brand pages on the Deliveroo app to signify the connection.

“It’s an obvious brand partnership that is beneficial to the business,” Lake says of the Deliveroo tie-up, which he says generates “unprompted NOTHS brand awareness”.

“We’ve not invested anything from a tech point of view, but if it goes very well and we want to scale across the UK, there will be some tech investment needed. This approach buys us time to make our platform easier for integrating into third parties.”

And therein lies the crux of the technology challenge NOTHS faces right now. So much of the focus for the business in its 18 years of operating, since being founded by Holly Tucker in 2006, has been on the consumer experience and its front-end capabilities.

But in the past two years, since Lake’s arrival from high-flying fitness brand and retailer Gymshark, simplifying behind the scenes and exploring where a “buy, not build” approach to technology might be more appropriate has been the name of the game.

Front to back

“We’ve underinvested in the back end,” Lake says. “In the two years I’ve been here, we’ve gone through a lot of change and been purposeful. It’s about going back to what the company was about in the first place –shouting about and supporting small businesses in the UK.”

From a tech perspective, he says, it has been important to articulate NOTHS’s definition of customer is a “dual definition” – encompassing the end consumer, but also the small brands selling through the platform.

“It sounds obvious – and it is obvious internally – but it can get missed on how we decide what we’re going to focus on and invest into,” he says.

Lake’s senior leadership position reports directly to CEO Leanne Rothwell, and he has the responsibility of looking after tech products across the organisation. He acknowledges he joined NOTHS “primarily for the tech challenge”, identifying it as a reverse job to what he faced at Gymshark, where he was engineering director.

When Gymshark went through its exponential growth period, which resulted in its 2020 unicorn status as a £1bn-valued privately-owned business, it needed to internally build out tech to support its core Shopify foundations. At NOTHS, there’s a need to more comprehensively work with tech partners and stop relying on building everything in house.

“At NOTHS, we’re trying to end up in the same space but from the opposite end,” Lake says, adding that the business is looking to buy more tech rather than build it in house. “My view is we should only invest in or own things that are strategically important to us or we would have operational challenges without – we have too much stuff that falls into the commoditised bracket.”

In what might be welcome news for the retail technology ecosystem, NOTHS is now looking for products on the market – where there is commoditisation. Albeit, there is not a bottomless pit for investment.

Lake talks of the need for products within a retail organisation’s tech stack to contribute to strategic and operational performance. With so much built in house, NOTHS finds itself with components that are no longer contributing to either and are “holding us back” – it’s a typical retail legacy system tale of entanglement.

“Everything is owned and maintained, so my focus is on identifying what’s now been commoditised and what have other people done a better job of building – and we can then think about what we can chop away at. After all, we’re not a tier one tech company.”

Fundamental shift

NOTHS has already started its journey of modernisation under Lake’s stewardship. The marketplace has migrated promotional capabilities to a third-party engine platform – Talon One.

“Although pretty simplistic in approach compared to most businesses, it represents the first time we’ve gone out and bought a capability and integrated it in a composable MACH tech way,” Lake says.

“It’s a fundamental shift in thinking internally for the engineering and product teams. We deprecated and removed the old promo engine which – surprise, surprise – we had built. It did one thing and we had the age-old problem that you never come back to it – you go on to the next priority and it becomes a problem for people.”

This change will support in the running of campaigns, but is also set to be a capability utilised as NOTHS explores its options around building a loyalty proposition. “This takes a number of things the tech team shouldn’t need to be involved in off their plate, so we can focus in the investments we want to make,” Lake adds.

With e-commerce stack technology, “the most commoditised” area of retail tech, according to Lake, there’s lots of focus on what to bring in to the NOTHS business in this area: “We’re headless already, but some better decisions probably could have been made – you should own the user experience as it can contribute to strategic differentiation.

“What we hadn’t done in the move to headless was consider the service or integration layers just under that, so we built a load of microservices, some with thin veneers into the monolithic platform. We hadn’t thought about how to take off parts we shouldn’t really own which can be a distraction and they take time with maintenance on bugs.”

NOTHS is using Contentstack from a headless content management system point of view, but a stream of work currently well under way with Kin + Carta and Valtech is focused on better optimising the digital experience.

Lake says the NOTHS search and discovery process starts with its brand partners putting product data in – and this is an area where improvements are sought.

“For trade reasons, we focused on very outer edge of search and discovery and how results had ranked and reranked – and we’re using Google Vertex AI,” he adds. “Search went live last year and there have been marked improvements there. We’re doing tests on browse currently.

“We have circa 450,000 products on the platform, and surfacing the most relevant of those is a big challenge and we have built a load of tech that doesn’t really lean into surfacing the most relevant thing.”

That is being addressed using Google Vertex, and the work with Kin + Carta involves improving data quality and product information management processes so NOTHS can “augment the effects of the AI”.

In terms of AI strategy, a lot will depend on finding the most suitable partners. “A lot of the third-party companies we might buy into will be bringing AI to us because they are integrating it into their products – and that’s great,” Lake says.

“That’s the benefit you find yourself in as a D2C or online business. You can see the pressure on fellow CTOs working for SaaS businesses because there is a race to market – and there will be a number of misses, but we can benefit from that.”

Lake admits NOTHS was looking at how to use AI for search and discovery, “but then Google Vertex came along”. He predicts this type of situation will continue to happen for a while as the AI hype and focus continues.

“Once we have solved some problems and operational issues – and removed friction for partners and internally – we can think about how to utilise AI for something that is really interesting,” he says.

Lake describes his team as a “lean” 40-45 people covering tech and product, and says his leadership style follows a “teach-a-man-to-fish mentality”.

“It’s no good me steaming in and saying, ‘Cut that out, remove this, and go and buy this’, as it won’t build the sustainability in the approach we need,” he says, adding that the team is realising this new working method is aimed at making their lives easier as much as it is part of a method for driving the business forward.

The team covers IT infrastructure, cyber security, and support, with delivery managers, and an engineering team overseeing online, back and front-end, and mobile work across iOS and Android. There are members of the team focused on data analytics and data science, and those looking after platform infrastructure and product management.

“Good people get bought into the culture,” Lake adds.

It is their job to ensure the tech serves the five to six million customers NOTHS has in the UK, but under Lake’s leadership, they are also increasingly focused on making the lives of circa 5,000 marketplace sellers – some of which have started their journeys with Deliveroo this autumn – easier and more fruitful.

Source

Posted on

I’ve never taken Intel’s GPU competition seriously, but the Arc B580 has left me no choice

  • Intel’s Battlemage Arc B580 GPU just scored higher than the RTX 4060 in Vulkan testing
  • AMD’s RX 7600 loses to both Nvidia and Intel GPUs in Vulkan tests
  • The new GPU will launch on December 13, for $249 / £249 / around AU$439

It’s easy to place AMD and Nvidia as leaders within the GPU market, with the latter’s RTX 4000 series currently dominating over the RX 7000 series – but Intel is about to shake things up, with the Arc B580 defeating both the RTX 4060 and RX 7600 GPUs in Vulkan benchmark tests.

According to Tom’s Hardware (based on public benchmark tests), the Intel Arc B580 loses out to Nvidia’s RTX 4060 in OpenCL API (which is irrelevant for gaming) but successfully defeats Team Green’s GPU with a 6% lead in Vulkan (one of the APIs used for most games).

The Battlemage GPU is priced at $249 / £249 / around AU$439 which is cheaper than the RTX 4060 at MSRP ($299 / £289 / AU$545), and it’s purported to be the faster GPU (especially equipped with 12GB of VRAM). If there’s anything to take from this, it’s that Intel is suddenly in pole position to reignite the budget GPU market and take the lead – though doing so will depend on AMD and Nvidia’s CES 2025 reveals.

The Intel Arc logo against a blue and purple backdrop

(Image credit: Intel)

Say goodbye to 8GB GPUs with Intel…

Team Red has already made it clear that its focus has shifted from high-end GPUs to mid-range options, with a strong emphasis on AI upscaling going forward with FSR 4 (much like Nvidia’s continuing focus on AI for DLSS 3’s successor). With this in mind, I’m optimistic about what both have to offer at CES in January when it comes to budget options.

The Intel Arc B580 will feature 12GB of VRAM, while the cheaper B570 will utilize 10GB of VRAM – 8GB of VRAM is nowhere near enough to tackle games today, and it’s great to see that Intel abandoning this long-standing staple of affordable GPUs. More and more triple-A titles are demanding more VRAM for consistent performance and after Apple’s move away from 8GB of unified memory (shared RAM between the CPU and GPU) for Macs, I’m expecting Nvidia and AMD to follow suit.

Spotted by VideoCardz, XeSS Frame Generation has been leaked and is now available for Intel GPU owners to use via Nexus Mods – AI upscaling has been the talk of the town for PC gaming for improved frame rates and image quality, and now that Team Blue has joined the party, there is room for competition in the budget GPUs arena.

You might also like…

{ window.reliablePageLoad.then(() => { var componentContainer = document.querySelector(“#slice-container-newsletterForm-articleInbodyContent-k9f3g8H8RCwAPYgRmn35nZ”); if (componentContainer) { var data = {“layout”:”inbodyContent”,”header”:”Get daily insight, inspiration and deals in your inbox”,”tagline”:”Sign up for breaking news, reviews, opinion, top tech deals, and more.”,”formFooterText”:”By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.”,”successMessage”:{“body”:”Thank you for signing up. You will receive a confirmation email shortly.”},”failureMessage”:”There was a problem. Please refresh the page and try again.”,”method”:”POST”,”inputs”:[{“type”:”hidden”,”name”:”NAME”},{“type”:”email”,”name”:”MAIL”,”placeholder”:”Your Email Address”,”required”:true},{“type”:”hidden”,”name”:”NEWSLETTER_CODE”,”value”:”XTR-D”},{“type”:”hidden”,”name”:”LANG”,”value”:”EN”},{“type”:”hidden”,”name”:”SOURCE”,”value”:”60″},{“type”:”hidden”,”name”:”COUNTRY”},{“type”:”checkbox”,”name”:”CONTACT_OTHER_BRANDS”,”label”:{“text”:”Contact me with news and offers from other Future brands”}},{“type”:”checkbox”,”name”:”CONTACT_PARTNERS”,”label”:{“text”:”Receive email from us on behalf of our trusted partners or sponsors”}},{“type”:”submit”,”value”:”Sign me up”,”required”:true}],”endpoint”:”https://newsletter-subscribe.futureplc.com/v2/submission/submit”,”analytics”:[{“analyticsType”:”widgetViewed”}],”ariaLabels”:{}}; var triggerHydrate = function() { window.sliceComponents.newsletterForm.hydrate(data, componentContainer); } if (window.lazyObserveElement) { window.lazyObserveElement(componentContainer, triggerHydrate); } else { triggerHydrate(); } } }).catch(err => console.error(‘%c FTE ‘,’background: #9306F9; color: #ffffff’,’Hydration Script has failed for newsletterForm-articleInbodyContent-k9f3g8H8RCwAPYgRmn35nZ Slice’, err)); }).catch(err => console.error(‘%c FTE ‘,’background: #9306F9; color: #ffffff’,’Externals script failed to load’, err)); ]]>

Sign up for breaking news, reviews, opinion, top tech deals, and more.

Source

Posted on

TfL cyber attack cost over £30m to date

The September 2024 cyber attack that forced Transport for London (TfL) to suspend multiple services across the capital has cost it more than £30m to date, it has emerged.

In a financial update to its board, TfL said that previous forecasts of an operating surplus of £61m had now been slashed to £23m, largely due to the financial impact of the security incident. It currently has an operating deficit of £37m, which is £122m lower than initially budgeted for.

The organisation revealed that it has spent £5m on incident response, investigation and remedial cyber security measures in the past three months.

The incident began on 1 September when defenders detected suspicious activity on TfL’s network. Likely fearing ransomware, the IT security teams limited and shut off several systems to ensure the impact was minimised.

Fortunately, the impact of the incident on London’s bus, Tube and other services was limited, but multiple other services were affected. Most prominently, passengers were left unable to access their account logins for contactless and Oyster payment services, APIs used by third parties including Citymapper went offline, and the Dial-a-Ride service for disabled people had to be briefly suspended.

Although initially TfL said that it did not believe passenger data had been affected,, it later found that data on 5,000 people was accessed, including names, contact details and in some cases bank account data. All of these people have been contacted and the incident has been referred to the Information Commissioner’s Office (ICO). Subsequently, the National Crime Agency (NCA) arrested and later bailed a 17-year-old boy on suspicion of offences under the Computer Misuse Act.

In the report, TfL commissioner Andrew Lord thanked the thousands of TfL employees who have “really pulled together” in recent weeks to address the disruption and maintain key services, and passengers for their patience.

Lord added that TfL had received wide praise and recognition for its response, but said that the consequences of the incident will continue for some months to come. He promised a full review of the incident in due course, although stressed that publicly available information will remain limited as it relates to an ongoing criminal case.

More services restored

In recent days, TfL has been able to restart a number of services that were disrupted during the cyber attack, including the contactless.tfl.gov.uk service.

This means passengers who use pay-as-you-go with a contactless credit or debit card, or on their smartphones, are now able to see their full journey history again.

Additionally, it means that TfL can also once again provide photocards for Zip cards for five to 17 year-olds, 60+ London Oyster, and 18+ Student Oyster. It has already dispatched over 30,000 Zip passes, 40,000 new student passes and 13,000 pensioners’ passes since reopening applications.

TfL said that it was encouraging parents and guardians to apply for updated Zip photocards as a matter of urgency – expired 5-10 and 11-15 Zips are being accepted on TfL and surface rail services in London at present, but this concession will end on New Year’s Eve.

The organisation warned customers would still see some residual delays when contacting customer services, particularly with regard to refunds for overpayments for concessionary cardholders affected by the cyber attack.

Shashi Verma, chief technology officer at TfL, said: “We’re pleased that customers can now access their contactless journey history again, meaning that all TfL fares services impacted by the recent cyber incident are now reinstated. We apologise for any inconvenience that this incident has caused our customers,” said TfL CTO Shashi Verma.

“We are now able to process contactless and Oyster refunds for those requiring them, though customers should anticipate there may be some delays due to the expected backlog. We have also contacted all new photocard customers who were impacted by not being able to apply for their new photocard. I want to also personally thank our engineers and customer services teams who have worked hard during this incident to support customers and restore services.”

SonicWall EMEA executive vice-president, Spencer Starkey, commented: “Due to [its] importance, safeguarding critical national infrastructure [CNI] is vital to maintain order and prevent potential disasters caused by threats such as cyber attacks.

“Ensuring the cyber security of critical national infrastructure requires a comprehensive and ongoing effort. The ramifications of an attack and ensuing outage on CNI can be disastrous and it’s important to place the utmost amount of time, money and efforts on securing them.

“In a divisive landscape, we’re seeing a continued geo-migration of threats, and governments are under constant cyber threat. These cyber attacks raise concerns about a country’s own national security, critical national infrastructure as well as the safety of sensitive information.

“Protecting government networks relies on constant communication and cooperation, working together with the private sector and imposing strict punishments, to deter future attacks,” he added.

Source