AI Is Driving Up Tech Prices, Plus 3 More Stories
Artificial intelligence is making some of the ordinary technology around it more expensive, and the reason is sitting several layers below the chatbot. The immediate problem is a memory chip shortage being driven in large part by the AI boom: the same manufacturers that make high-bandwidth memory for data centers also make the DRAM and storage chips that go into laptops, phones, game consoles, TVs and cars.
AI’s memory appetite is showing up in the price of everyday tech
The Financial Times reported this weekend that DRAM prices have risen roughly fivefold over the past year as chipmakers shift capacity toward the much more profitable memory used by AI systems. Apple, Microsoft, Nintendo and other manufacturers have already raised prices or adjusted products as component costs move through the supply chain.
This isn’t simply “AI uses a lot of chips.” The particular bottleneck is memory. AI accelerators depend heavily on high-bandwidth memory, or HBM, which is built to move huge amounts of data to and from processors very quickly. At the same time, AI servers consume large quantities of more conventional DRAM and NAND flash storage. There are only so many factories, production lines and advanced manufacturing processes available, so allocating more of them to high-margin server products leaves less capacity for the parts that go into ordinary electronics.
TrendForce said in July that conventional DRAM contract prices were still expected to rise another 13% to 18% in the third quarter, even after prices had already reached record levels. The research firm specifically said PC and smartphone makers were reaching the limit of what they could afford. Consumer Reports followed the problem into actual products this week, finding the cost pressure showing up in everything from laptops and streaming devices to televisions and automobiles.
So, yes, the billion-dollar AI data center being built three states away can eventually affect what your next office laptop costs. The connection is indirect, but it is real.
I wouldn’t turn this into a panic-buying recommendation. Memory markets are famously cyclical, and “buy every laptop now because RAM will never get cheaper again” is the sort of sentence that ages badly. But if a business already knows it needs to replace several computers over the next year, the old assumption that comparable hardware will naturally get cheaper may not hold. Extending the useful life of a machine with a sensible repair or upgrade, considering a well-supported previous-generation model, and budgeting more realistically for replacements all make more sense than they did when memory was reliably sliding down the cost curve.
Business IT goes well beyond the website
Your business also depends on workstations, cloud accounts, browsers, Wi-Fi, remote access, collaboration tools, and all the other technology that quietly becomes infrastructure. Raymond Tec works across that whole stack, whether the problem lives on a server, on a desk, or somewhere in between.
Magento and Adobe Commerce stores face an unpatched zero-day
If you run Magento Open Source or Adobe Commerce, the second story is considerably less philosophical: you need to look at this now.
Security firm Sansec disclosed an actively exploited vulnerability it has named StyleSmuggler on September 5. It gives an unauthenticated attacker remote code execution on the store’s server, and there is no official Adobe patch yet. Sansec reproduced the complete attack chain on clean Magento Open Source 2.4.7, 2.4.8 and 2.4.9 installations. Its first known victim was running 2.4.6-p15 with the July and August security patches installed and Magento’s own patch-status check reporting clean.
In other words, this is one of those unpleasant moments when “fully patched” and “safe from this vulnerability” are two different things.
The mechanism is worth understanding because it is stranger than somebody uploading a PHP file through an obviously broken form. StyleSmuggler first poisons a file Magento writes itself, such as a failure report, by getting malicious PHP into the template system’s styles properties. Then the attacker causes Magento to process the poisoned file while rendering its normal “Payment Transaction Failed Reminder” email. Nobody has to click the email. Nobody even has to receive it. The malicious code runs on the server while Magento is building the message.
Successful attacks can install a persistent backdoor disguised as a Linux kernel worker process. Sansec says exploitation began late September 4 and that it published before its investigation was complete because stores were already being compromised.
Until Adobe publishes a fix, Sansec recommends temporarily disabling GraphQL for stores that don’t need it and aren’t protected by Sansec’s own virtual-patching product. Administrators should also check for the published indicators of compromise rather than assuming an up-to-date version means the store wasn’t hit. Adobe’s next scheduled security release is September 8, but Sansec says it does not yet know whether that release will contain a StyleSmuggler fix.
If compromise indicators are present, this stops being a “patch when available” job and becomes an incident-response job. Preserve evidence, remove the persistence, invalidate sessions, rotate credentials and payment/integration secrets that the store could access, and verify the environment is actually clean before declaring victory.
Compromised website help
Sometimes maintenance starts after the damage is done. Raymond Tec can investigate compromised sites, clean up access, recover what can be recovered, and patch the original problem — then help make the next incident considerably less exciting.
Trezor’s shipping breach got much larger because old data wasn’t actually deleted
Hardware-wallet maker Trezor says another roughly 67,000 U.S. customers were exposed in the breach at its shipping provider, ShipMonk. The interesting part isn’t that somebody broke into a cryptocurrency wallet. Trezor says its systems, devices and wallet backups were not compromised.
The problem is the shipping data.
The newly identified records cover orders from November 2019 through August 2021 and include names, email addresses, phone numbers, shipping addresses and order numbers. That brings the known impact of the ShipMonk incident to more than 80,000 Trezor customers. Trezor says it had repeatedly asked ShipMonk to delete the older data and received written assurances that it had been removed in accordance with its contract and retention policy.
Apparently, it hadn’t.
That makes this more useful than another generic “third party caused a breach” story. A retention policy only reduces risk if the data actually disappears. A contract saying a fulfillment provider will delete customer records after 90 days is good governance. Verifying that the provider really did it is better governance.
For the affected customers, the risk is unusually specific. A scammer may know not only your name and phone number, but that a hardware wallet was shipped to your home. Trezor is warning about fake emails, calls, physical letters and potential physical-security risks. A message that references the approximate date of your real order can sound convincing without having anything to do with Trezor’s actual systems.
The rule here is simple: a breach notice is never a reason to type your wallet recovery seed into a website, hand it to somebody on the phone, or “verify” it for a support representative. If Trezor emailed you about this incident, treat future Trezor-themed contact with considerably more suspicion and verify it through a channel you navigate to independently.
Technical discovery & auditing
The public page doesn’t tell you much about the machinery behind it. Raymond Tec audits inherited and long-running projects to uncover the plugins, integrations, data, dependencies, and old decisions that determine what the next change will really involve.
A German startup just put a rocket into orbit from continental Europe
I’ll end with something that does not involve changing a password, disabling an API, or figuring out why your laptop costs more.
German startup Isar Aerospace successfully sent its Spectrum rocket into orbit from Andøya Spaceport in northern Norway on Saturday. Reuters reports it was the first commercial orbital flight from continental Europe. The uncrewed rocket carried five small satellites and an in-flight experiment.
This is Spectrum’s second flight. The first, in March 2025, lasted about 30 seconds before the rocket fell into the sea. That sounds like a disaster if you’re judging it like an airline flight. It makes more sense as a development test: the first vehicle proved it could ignite, lift off and provide flight data; the next one reached orbit.
The larger reason Europe cares is access. Satellites support communications, weather forecasting, mapping, navigation, scientific work and national security. Europe has spent years dealing with launcher delays and the loss of access to Russia’s Soyuz rockets, while many European payloads have depended on U.S. launch providers. A commercially operated launcher that can put smaller payloads into orbit from Europe doesn’t replace SpaceX or Ariane overnight, but it gives satellite operators another route to space.
And after a week of stories about AI agents escaping test boundaries, hacked ecommerce stores and enormous databases that were supposed to have been deleted, “rocket went up and successfully stayed up” is a perfectly acceptable way to finish Sunday morning.
Still in a reading mood? The Raymond Tec News archive covers security, AI, small-business technology, policy, and the places technology collides with ordinary life — without requiring a computer-science degree to get through it.
Sources / Further Reading
- Financial Times: “RAMageddon” hits consumer electronics as AI drains chip supply
- TrendForce: AI server demand continues to support memory prices in Q3 2026
- Consumer Reports: AI demand for RAM is driving up prices for cars and tech
- Sansec: StyleSmuggler Magento and Adobe Commerce zero-day under active attack
- The Block: Trezor says ShipMonk breach affected another 67,000 customers
- Reuters: German rocket reaches space as Europe enters satellite launch race
- ESA: Spectrum’s first test flight and development background
