02 SEP 2026 · 15:01 MDT · HPC CONTROL-PLANE ALERT: Active exploitation of end-of-life Proxmox VE 7 and a confirmed Virtualizor update-channel compromise require exposure review, MFA, supported versions, signed-update validation and incident hunting. Proposed guidance requires environment-specific validation. Read the evidence →

AI · HPC · DATA CENTER AFFAIRS

The compute field, without the mythology.

Confirmed benchmark systems are separated from reported deals, planned capacity and unverified speculation. Performance classes are not interchangeable: TOP500 HPL, mixed-precision AI throughput, model quality, tokens per second, power and usable production capacity measure different things.

CONFIRMEDREPORTED / PLANNEDSPECULATIVE · NOT RANKED AS FACTUPDATED · 02 SEPTEMBER 2026 · 15:01 MDTNEXT UPDATE · 01 SEP 2026 · 06:00 MDT

INFOGRAPHIC 01 // TOP500 JUNE 2026

Confirmed HPL leaders

June 2026 list rechecked August 31. HPL EFlop/s; not a live utilization feed or an AI-model ranking.

1 · LineShine
2.198 EFlop/s
2 · El Capitan
1.809
3 · Frontier
1.353
4 · Aurora
1.012
5 · JUPITER
1.000

LineShine debuted at No. 1 in Shenzhen. El Capitan, Frontier, Aurora and JUPITER Booster occupy Nos. 2–5. These are published HPL results—not a ranking of generative-AI service quality. Official TOP500 list

INFOGRAPHIC 02 // REPORTED CAPACITY · CARRY-FORWARD

Planned and contracted compute

Source dates: August 26 and August 4. Financial claims below were carried forward, not independently reverified today; no new commissioning evidence is asserted.

460 MWAnthropic/Nscale West Virginia capacity reported by Reuters; Anthropic declined comment.
$45B / 6 yearsReported rental arrangement; future Vera Rubin deployment, not a live TOP500 result.
$1.09TAggregate uncommenced Big Tech lease commitments compiled from filings; not current installed capacity.

Nscale report · Lease analysis

SPECULATIVE CLUSTER REGISTER

What we can discuss—but not promote to fact

  • Stealth/internal clusters: public GPU-count claims without owner filings, facility evidence or reproducible benchmark remain unranked.
  • Announced campuses: power reservations and financing do not prove energized racks.
  • Model-linked compute: model performance cannot reliably back-calculate cluster size.

Evidence rule: corroborated plans remain plans. Promote operational status only with dated owner/operator evidence of commissioning; label measured benchmark results separately. Two reports repeating a capacity claim do not establish energized compute.

INFOGRAPHIC 03 // AI MODEL SIGNAL

Released, previewed and dependency-changing models

OpenAI GPT‑5.6 SolOfficial August 6 update verified August 31. Product availability is not an independent benchmark ranking. Unverified throughput claims omitted.
Claude Opus 5Official July 24 release verified August 31. Vendor coding and knowledge-work claims require workload-specific evaluation.
Tencent preview · REPORTEDAugust 28 reporting carried forward; release details and independent evaluation were not reverified in this collection.
Unconfirmed model watchNo sourced public-release confirmation available for the previous Gemini watch item. Excluded from the confirmed model field.
Provider dependency · WATCHPrior August 29 reporting retained as historical context; no fresh status verification in this collection. Test portability and policy continuity.
Evaluation ruleTrack model card, license, context, tool authority, retention, cyber capability, price and independent task results—not vendor leaderboard claims alone.

OpenAI GPT‑5.6 · Claude Opus 5 · Tencent report

INFOGRAPHIC 05 // AI MALWARE EVIDENCE WINDOW

Research samples are not a prevalence measure

405 samplesUnit 42 AI-associated research set; mixed categories.
12 endpoint-observedSeen on Cortex XDR-protected endpoints; not 12 confirmed autonomous campaigns.
2024–2025 telemetryEndpoint: Dec 2024–Jun 2025. Network: Jun 2024–Jun 2025. Not an August 2026 attack rate.

Vendor-specific observations cannot establish global prevalence. Unit 42 source · Reviewed 02 SEPTEMBER 2026 · 15:01 MDT. Model capability, observed malicious use and authorization remain separate evaluation questions.

HPC THREAT LENS · PREVENTIVE ARCHITECTURE

Protect the orchestration layer, not only the accelerators.

SEV 2 HIGH · ORANGECONFIDENCE · HIGHSTATUS · DOCUMENTED ARCHITECTURE RISK
IDENTITYFederation, service accounts, SSH keys, tokens and privileged operator paths.
CONTROL PLANESchedulers, APIs, bastions, cluster management and provisioning.
SOFTWARE SUPPLYContainers, modules, compilers, firmware and research dependencies.
DATA + MODELSParallel storage, checkpoints, weights, training data and intellectual property.
FABRICSlingshot/InfiniBand-class east-west visibility and segmentation.
PHYSICAL DEPENDENCYPower, cooling, BMS/OT, water, spares and vendor concentration.

PROPOSED MITIGATION — REQUIRES ENVIRONMENT-SPECIFIC VALIDATION: Isolate management planes, use short-lived identities, restrict job privileges, monitor storage egress and test recovery.

Carry-forward architecture focus (reviewed August 30): SchedMD says slurmrestd is not designed for direct internet exposure. Put authentication and TLS at the trusted boundary; use short-lived tokens and connection limits. This is documented guidance, not a newly disclosed Slurm exploit. SchedMD source

August 31 advisory focus: NVIDIA OpenShell/NemoClaw component-specific fixes now appear in the brief. Vendor-confirmed flaws are distinct from observed exploitation. Review workload isolation as well as scheduler controls.

Read the current threat brief and proposed mitigations →

INFOGRAPHIC 04 // ENERGY PLANNING · HISTORICAL ESTIMATE VS FORECAST

Data-center electricity demand: two different evidence types

2024 · ESTIMATE
415 TWh
2030 · FORECAST
945 TWh

Global annual data-center electricity consumption; common scale, not a cluster ranking. The 2030 number is IEA’s Base Case projection, not measured demand or a 2026 nowcast. Source: IEA, Energy and AI (2025), CC BY 4.0. Values restated; graphic created for this dashboard. Reviewed 30 August 2026, 15:06 MDT.

Read the planning limits

Energy availability, commissioning, cooling, network readiness and workload acceptance are separate gates. Do not convert MW reservations or dollars of leases into a confirmed GPU count. Treat unverified campuses as reported or speculative until dated operational evidence is available.

INFOGRAPHIC 06 // BIG TECH · ANNOUNCED AUGUST 31

NVIDIA + MediaTek: roadmap, not installed capacity

CLOUD INFRASTRUCTUREMediaTek to adopt NVLink Fusion for custom XPU integration.
LOCAL AIContinued collaboration on RTX Spark and DGX Spark PC chips.
AUTOMOTIVEContinued development of software-defined vehicle platforms.

Confirmed announcement / future delivery unverified: NVIDIA reports a $3.5 billion convertible-bond investment in MediaTek. These announcements establish neither commissioned cluster capacity nor measured model performance. NVIDIA · August 31. Reviewed 02 SEPTEMBER 2026 · 15:01 MDT.

INFOGRAPHIC 07 // TRUSTED MODEL PATH

Agent trust is a chain, not a model name

1 · DISCOVERInventory every endpoint, owner and advertised model.
2 · AUTHENTICATEVerify service identity, certificate and provider authorization.
3 · CONSTRAINScope secrets, egress, tools and command approval.
4 · OBSERVELog model ID, endpoint, tool calls and resulting actions.
5 · RECOVERRevoke tokens, isolate agents and reproduce decisions.

SANS observed third parties reaching a honeypot endpoint while expecting models it did not host. This is evidence of endpoint-provenance risk, not compromise of any named model vendor. SANS ISC · September 1. Reviewed 02 SEPTEMBER 2026 · 15:01 MDT.

INFOGRAPHIC 08 // HUMAN-TO-TERMINAL TRUST CHAIN

TerminalFix: where verification becomes execution

1 · LURECompromised page presents a fake CAPTCHA.
2 · COPY/PASTEUser is instructed to run terminal content.
3 · STAGEDownloaded components use sideloading and persistence.
4 · TUNNELOutbound encrypted connectivity creates attacker reach.
5 · RESPONDIsolate, preserve evidence, revoke sessions and rotate secrets.

This diagram summarizes Microsoft-observed behavior without reproducing commands, payloads or live indicators. It is not an AI-model flaw, but coding-agent and operator workflows share the same control lesson: untrusted text must not gain command authority. Microsoft Security. Reviewed 02 SEPTEMBER 2026 · 15:01 MDT.