securitylab_nJuly 9, 2026🇷🇺Translated from Russian

Scientists Consider Replacing Leap Seconds with a Century-Scale 'Extra Hour' to Protect Global Digital Infrastructure from Negative Leap Second Risks

Global timekeeping authorities are preparing a landmark decision that could fundamentally change how the world manages civil time. Instead of continuing to insert occasional leap seconds, they are considering a system that would allow an extra hour to accumulate over hundreds of years before any major correction is needed. The goal is not to lengthen the day but to permanently remove the recurring one-second adjustments that have long destabilized computer systems and may become even more dangerous as Earth's rotation speeds up.

The leap second was first introduced in 1972 to keep Coordinated Universal Time (UTC) aligned with the planet's irregular rotation. While atomic clocks maintain exceptional stability, Earth's spin varies due to internal geological processes, ocean currents, atmospheric conditions, and other factors. When the difference between atomic time and astronomical time grows too large, specialists add a single extra second to the calendar year.

For ordinary users the adjustment is barely noticeable. For digital infrastructure, however, it creates serious problems. Computer systems rely on precise sequencing of events, and an abruptly inserted second has already triggered outages at Meta, Reddit, and Cloudflare. It has also disrupted airline operations and interfered with high-frequency stock trading. As networks and financial platforms operate at ever-higher speeds, their tolerance for non-standard time changes continues to shrink.

Many developers have therefore adopted a workaround known as leap-second smearing, in which the extra second is gradually distributed over a longer interval rather than inserted all at once. While this approach reduces immediate crashes, it creates a new inconsistency: different systems begin operating under slightly different time rules.

No leap seconds have been added since 2016 because Earth's rotation has begun to accelerate. Scientists are now discussing the opposite scenario: if the planet starts to outpace atomic time, the first-ever negative leap second may be required. Removing a second from UTC has never been attempted, and experts have no data on how today's infrastructure would respond.

The risk of a negative leap second prompted the General Conference on Weights and Measures in 2022 to accelerate a review of UTC rules, originally targeting 2035 as the deadline. Updated assessments now indicate that waiting that long could be risky, with the probability of needing a negative leap second before 2035 estimated at approximately 30 percent.

The new proposal under discussion would replace the current one-second corrections with a much larger allowable deviation—potentially an entire hour—between atomic time and Earth's position. This change would push the next major adjustment centuries into the future, effectively ending the era of leap seconds for practical purposes. If approved, the revised rules could come into force as early as 2027.

The International Bureau of Weights and Measures considers the issue urgent. Even a 10 percent chance of a negative leap second is viewed as unacceptable for global digital systems. By removing the most disruptive element before it can trigger unpredictable large-scale failures, authorities hope to safeguard servers, exchanges, aviation networks, and telecommunications infrastructure.

The reform would not completely sever the connection between civil time and Earth's rotation, but it would make that link far more flexible. UTC would continue to rely primarily on atomic clocks, while any accumulated difference with astronomical time would be allowed to grow over decades or centuries. Although humanity may eventually have to address an entire hour of divergence, computer systems would no longer need to prepare for sudden one-second jumps that cause more damage than they appear to.

Related articles

HabrOther

MEPhI Opens 2026 Admissions for Online Cybersecurity Master's Program with Yandex Practicum

The National Research Nuclear University MEPhI, in partnership with Yandex Practicum, is accepting applications for its online master's program in Cybersecurity for the 2026 intake. The two-year program leads to a state diploma in Information Security under code 10.04.01 and a professional retraining certificate from Yandex Practicum. Students can choose from four specialized tracks covering AppSec, DevSecOps, network security, and AI security. Admission is fully online and includes document submission via Gosuslugi, an entrance exam, and a motivation letter requiring at least 80 points. The program runs entirely remotely with evening and weekend classes, allowing students to combine studies with work while accessing student benefits and an educational loan at a subsidized 3% rate.

安全客Other

360 Group Launches NanoWork Enterprise AI Platform with Built-in Security and Opens Nationwide Channel Partner Recruitment

On July 28 at the Beijing National Convention Center, 360 Group founder Zhou Hongyi officially unveiled NanoWork, a next-generation enterprise intelligent agent work platform. The platform is designed to bridge the gap between powerful AI models and real-world business tasks by enabling multi-agent collaboration, on-demand model scheduling, and 24/7 cloud operation across diverse scenarios. NanoWork was developed through extensive real-world testing involving 100,000 intelligent agents, coverage of 630 positions over 150 days, consumption of 350 trillion tokens, and collection of 56,000 feedback items. A core emphasis is placed on native security features drawn from 360 Group's two decades of cybersecurity experience to prevent errors that could lead to actual data loss or permission breaches. The company is now actively recruiting city-level channel partners across China to help deploy the solution in local industries and activate existing customer bases with AI capabilities.

AntiMalwareOther

Google Enables Document Backup to Drive in Stable Play Services 26.26 Release

Google has rolled out automatic document backup from Android devices to Google Drive in the stable version of Google Play Services 26.26. The feature, which the company prepared for nearly a year, adds a new Documents option in Settings on Pixel phones under Accounts and backup. It remains disabled by default to avoid uploading the Downloads folder without user consent. Once enabled, supported files including PDF, DOC, PPT, XLS, ZIP and even APK files are copied to a new Android backups folder on Drive, with separate subfolders created for each device. The backup consumes storage quota and offers no automatic two-way sync, requiring manual cleanup when disabled. Traces of the capability first appeared in August 2025, followed by an official mention in February 2026 and beta testing before the current stable deployment.

HabrOther

Bridging Manual and Automated Testing: InfoWatch Engineer Outlines Unified Quality Process

InfoWatch senior test engineer Mikhail Shalepo has published a detailed article describing how his team built a reproducible process that links manual and automated testing into a single quality system. The approach addresses the growing complexity of server-side products that undergo quarterly releases and require extensive matrix testing across multiple operating systems and installation scenarios. Shalepo explains that the regulation focuses on decision points rather than prescribing exact test volumes, ensuring that choices about automation candidates, smoke-test gates, failure ownership, and manual compensation are documented and visible to the entire team. The framework divides work into two main blocks—feature development and pre-release regression—each containing preparation, execution, and completion stages. Key outputs include linked artifacts in TMS Scale, explicit Definition of Done criteria, and traceable coverage data that prevents reliance on individual knowledge. The article also shares practical lessons, including why separate mind maps and tables failed to stay current and how the team now integrates automation status directly with test cases.