Kategorie
Kiteworks urges 6-hour server shutdown over potential zero-day attacks
ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw
Elementor WordPress flaw lets attackers create admin accounts
AI tools help hacker break in for $25 per target
It’s cheap to set yourself up as a hacker these days using AI. Someone attacked 105 online retailers over a period of five days, compromising 27 of them — all for an average of $25 per attack, according to research by Israeli security company Gambit.
But the attacks have been going on for much longer. Whoever is responsible used open-source AI harnesses to mount the attack. Gambit has identified three of these: Strix for vulnerability search, Cairn for autonomous end-to-end exploitation, and Hermes to orchestrate the campaign. The attacks have proved to be highly lucrative, with 600,000 active credit card details taken from just two businesses, the installation of card skimmer scripts at five more, and some level of access to an unspecified number of major companies.
It has been a highly efficient attack, most access taking just a few hours and at a minimal cost. OpenRouter was used for AI model access. The capture of the account balance on August 25 showed the attacker spent just $7,005 over a four-week period. This worked out at roughly $25 per attack, with costs ranging from $3.13 for the cheapest target to $79.31 for the most expensive.
Gambit has contacted all the companies concerned, but warned that the intensity of the attacks shows how AI is transforming cyber criminals’ activities by providing a level of sophistication that humans would find more challenging to muster. We are already seeing a new level of incursions to businesses and can expect to see more in the future.
This article first appeared on CSO.
OpenAI wants you to use AI — but not to train its AI
Here’s an interesting concept: an AI company that fires people for using AI. It sounds like a strange way to run a company but there’s a real reason behind it.
OpenAI has been hiring contractors who have been tasked with reading ChatGPT users’ prompts to help improve responses by providing some real human input.
Unfortunately for OpenAI, it found many of them were using AI to train the AI, so not providing a human touch at all, according to a report in 404 Media. The company has subsequently fired many of the contractors, although 404 Media didn’t reveal the number.
None of them can say they weren’t warned, however. The terms for the contractors are set out in their working conditions. “Do not use AI detection tools, or AI yourself. Do not use GPTZero or any other AI detection tool. They are not reliable. Reviewers may not use AI either, including Grammarly and AI translation, to review, write feedback, or write comments.”
Despite this stark warning, many of the contractors turned to AI to assist in the work. OpenAI is very keen to avoid “model collapse,” a phenomenon in which AI models trained on text written by previous generations of AI models perform worse than their predecessors. It’s a form of digital inbreeding that industry observers have previously warned about, and which could have a deleterious impact on business.
One contractor told 404 Media that it was a common practise. “It’s pretty much the one thing that will get you kicked off ASAP. In a group of thousands, there are tons that have been caught.”
It will be hard to ascertain just how widespread the practise is as OpenAI declined to comment on the situation.
CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks
Microsoft’s new Copilot ‘super app’ unifies chat, code, agents
Microsoft’s Copilot “super app” has arrived, two months after CEO Satya Nadella confirmed it was in development. It combines conversational Chat, the autonomous Cowork agent, a redesigned coding environment named Code, and Autopilot, the persistent agent formerly known as Scout, into a single Copilot experience.
The idea is to make those capabilities look less like separate tools and more like different ways of getting work done through a unified experience. The end goal is to enable users to describe what they want to accomplish without choosing a mode themselves, and with Copilot routing the task to Chat, Cowork, Code or another capability, Microsoft said.
The individual pieces of this experience are not entirely new, and build on launches and consolidation moves that Microsoft has made over the past several months.
Nadella first described the unified Copilot architecture during an earnings call in July. He said it would bring chat, agents, and business workflows into a single AI workspace while separating the orchestration layer, context, and memory from any one AI model. Microsoft subsequently began unifying its consumer and Microsoft 365 Copilot apps ahead of the broader overhaul.
But Microsoft laid much of the groundwork in the period after its November 2025 Ignite conference, with the launch of Cowork for delegated multistep work, Scout for persistent agentic tasks, and natural-language app-building capabilities that have now evolved into Code.
The broader change goes beyond bringing those Copilot experiences together. With Friday’s updates, Microsoft is also adding components and infrastructure aimed at turning Copilot from an AI assistant embedded across Microsoft 365 into a broader orchestration layer for enterprise work.
These include Fabric IQ and Work IQ for enterprise context, Copilot Managed Runtime for running AI-built applications, a unified plugin registry for connecting capabilities, and usage-based billing and FinOps controls for managing agentic workloads and AI spending.
More enterprise context could boost productivityThe inclusion of Fabric IQ in Chat and Cowork, along with Work IQ’s access to data and workflows in Dynamics 365 and Power Platform, will make Copilot more effective for enterprise tasks by giving it a broader understanding of an organization’s data and workflows, potentially reducing hallucinations and improving productivity, said Abhishek Satapathy, principal analyst at Avasant.
“The practical shift is from AI that knows information to AI that can connect what happened, why it happened and what needs to happen next. For example, a business insight can increasingly become the starting point for analysis and follow-up action rather than requiring the user to manually move that context between reports, documents, conversations and business systems,” said Satapathy. “This is particularly relevant for analysts, managers and operations teams working across functions.”
Fabric IQ’s integration with Chat and Cowork is now generally available. Microsoft plans to integrate it with Code soon through its Frontier program. Work IQ will enter public preview over the next month, it said.
Redesigned Code expands the scope of software creationProductivity is also the focus of Microsoft’s redesigned Code environment.
It “broadens the audience for software creation” by addressing the middle ground between traditional development and simple automation, bringing more use cases into the scope of what business users can build, including those that may be too narrow for a formal development project but too complex for basic automation, Satapathy said.
That means more internal applications, dashboards and workflow tools can potentially be built without going through a traditional development project, while developers can use the same environment to accelerate application creation and focus on more complex engineering and production requirements, he added.
Alongside Code, Microsoft is introducing Copilot Managed Runtime, a governed hosting environment for applications built with Code, Cowork, and Copilot Studio. The runtime allows those applications to run within an organization’s Microsoft 365 environment while giving IT control over security, governance and access to live data, Microsoft said.
For enterprise developers and IT teams, the runtime could provide a common production layer for AI-created applications, helping enterprises move applications from experimentation and prototyping into production without having to create a separate operating model for each one, Satapathy said.
It could also help IT teams and CIOs curb shadow IT and application sprawl, said Manoj Chandra Jha, principal analyst at Nord-IQ Research. In its governed environment, IT departments can manage applications and agents created by employees consistently for security, identity, policies, lifecycle management, observability, and deployment.
The new Copilot Managed Runtime is currently in public preview and will also be accessible inside the redesigned Code experience, Microsoft said. That experience will roll out to Microsoft’s Frontier program at the end of the month, with broad availability in the coming weeks, it added.
New FinOps tools could help CIOs judge business valueBeyond productivity, faster scaling of AI applications and curbing application sprawl, Microsoft is also giving enterprises more tools to manage the cost of agentic AI by expanding its cost-management capabilities in Agent 365 to include Code and Copilot Managed Runtime.
These capabilities will allow administrators to manage AI spending policies at scale, control access to model families and route credit requests through existing approval workflows, while giving visibility into the outcomes generated by agentic workloads to decide where to sustain, expand or optimize usage, the company said.
End users will also be able to view their credit usage, remaining balances and usage history directly in Copilot, helping them manage their AI usage, it added.
For Bhupendra Chopra, chief revenue officer at IT consulting firm Kanerika, the expanded FinOps capabilities will be critical for CIOs, particularly for understanding if agentic workloads and automation are delivering sufficient business value and if they need to be reworked.
“These capabilities can reveal correction rates for agents. If employees regularly have to undo an agent’s work, that can indicate stale context, poor business rules or an unreliable data foundation before it shows up as a larger operational problem,” Chopra said.
“These capabilities can reveal another insight: whether the time supposedly saved by automation actually translates into a measurable business outcome. Enterprises can automate 20 minutes of work but simply spend that time elsewhere, meaning the productivity gain only matters when it produces a measurable result,” he added.
Usage-based billing extendedAlongside these FinOps capabilities, Microsoft is also extending usage-based billing to more of the capabilities being brought together under Copilot. The model is not new to the platform, having been introduced for Cowork when the agent became generally available in June.
While Cowork, Code and Autopilot, along with new long-running agentic capabilities and frontier models, will use usage-based billing, Chat and Copilot across Microsoft 365 will remain covered by the user subscription license, the company said.
That distinction could require CIOs to think about AI spending differently from traditional productivity software, Satapathy said.
Instead of budgeting primarily around the number of users with Copilot licenses, CIOs may need to consider what work is being delegated to agents, how much that work consumes and what business value it produces, he added.
“Two employees with the same Copilot license, for instance, could generate very different AI costs depending on whether one uses Copilot for assistance while the other delegates longer-running work to agents,” he further said.
However, that might still be some way off, with several of the key capabilities still in preview or yet to roll out.
Home, the new starting point in Copilot where Chat and Cowork come together, will begin rolling out through Microsoft’s Frontier program in the coming weeks, while Autopilot is expanding to private preview at the end of the month, Microsoft said.
Adobe’s next platform for Creative Cloud? Your AI assistant
Adobe is preparing for a future where users increasingly interact with its software through AI assistants, rather than always going directly to its applications.
That’s the idea behind its expanded integration with Anthropic’s Claude, as well as the first connector for Google’s Gemini, announced Thursday.
The updated Claude integration adds new ways for users to interact with Creative Cloud applications via text prompts, with 80 “tools” available across applications such as Acrobat Photoshop, Premiere, Express, and Lightroom. That’s up from the initial 50 at launch in April.
The Adobe plugin lets users take actions across various Creative Cloud apps, such as retouching images or resizing videos for social media posts. The latest additions include the ability to convert PDFs to different file formats.
In addition, Adobe has introduced interactive editor tools available in Claude. These offer greater control over Express and Acrobat files, Adobe said.
In Acrobat, it’s possible to edit text, for instance, reorder pages, or add comments and highlights. For Express, this means the ability to select and customize fonts, colors, and more.
The integrations could broaden access to Adobe’s software among workers “who never fully learned how to use Adobe’s tools,” said Keith Kirkpatrick, research director at The Futurum Group.
The ability to control elements of Creative Cloud apps via prompts “removes the learning curve, and can potentially help speed up the time it takes to go from an idea to a mostly finished output,” said Kirkpatrick.
Professional designers, meanwhile, will be “freed up to work on finishing ideas, rather than the spending valuable time doing the initial ideation and refinement,” he said. “It should also help them focus on only the highest-value work, instead of the routine or mundane projects.”
Adobe bets on AI assistantsThe Claude connector is part of a wider Adobe strategy to make Creative Cloud applications available within leading AI assistant tools. This includes similar integrations with OpenAI’s ChatGPT, Salesforce’s Slackbot, and, as of this week, Google’s Gemini.
AI usage by a range of workers is one the rise, even if regular adoption is still limited. Around 15% of US employees use AI daily in their role, according to a Gallup poll from May this year, while 30% use it a few times a week or more.
Gartner predicts that spending on enterprise AI assistants will rise from $17 billion in 2025 to $71bn in 2030, while knowledge workers are forecast to spend more time interacting with these tools in their daily work than with any other application over the next three years.
For Deepti Pradeep, Adobe’s senior director of agentic AI, the emergence of AI assistants creates another way for customers to access Adobe’s tools, rather than a replacement for its own applications.
“I think you will find a mix of all types of users; people who are in LLMs doing their tasks, and people who want to have more control and creativity as they’re going deep in our flagship apps,” she said.
“Our belief is that we want to be wherever the user is, whether they’re in the flagship apps ‘in the zone’ doing their thing, or whether they’re outside and they want to accomplish the task. So I don’t think it’s ‘this’ or ‘that’ — I think it’s everything. And we just want to be valuable in every moment that the user is in.”
Going forward, Adobe also plans to extend the interactive editor controls available now available for Acrobat and Express to a wider range of apps such as Photoshop. However, the emphasis will be on more streamlined interfaces, with more complex functionality remaining in the core application.
“With image editing there’s so much one can do, and we have very comprehensive products where we possibly can’t bring all that [to AI assistants such as Claude],” said Pradeep.
“So we’re trying to figure out what’s the right level that makes sense for the user in that given context. We want to ensure that we’re bringing relevant, value-added things. What we don’t want to do is over-engineer it.”
width="829" height="364" sizes="auto, (max-width: 829px) 100vw, 829px">Adobe for Claude includes new interactive editing tools for Acrobat and Express.
Adobe
Liz Miller, VP and Principal Analyst at Constellation Research, said there’s a lot of “buzz” from software vendors about the “start of an age where you never need to log into an application’s interface,” she said. This is exemplified by Salesforce CTO Parker Harris’s comments that customers may not need to log in to the CRM app at all in the future to get work done.
For some workers that may be accurate, said Miller, and the ability to access Adobe apps via third-party AI assistants “will 100% change the space and place they choose to work.”
But, just as access via mobile didn’t kill off Photoshop, “working in Claude will be a new way to work in, with, and through, Creative Cloud,” said Miller. “This is more about the future styles of work than it is about a SaaSpocalypse. Adobe is rightly identifying a new work surface and empowering creators to work where they choose.”
Miller said she already sees demand for Adobe’s integrations in third-party apps, “especially from non-creative, more technical users where updating a technical document that exists as a PDF was once a time-consuming task.
“A prompt-based update leveraging Acrobat and Express integrations with Claude fits within that individual’s workflow,” Miller said.
Adobe doesn’t provide daily or weekly usage statistics around the use of the existing Claude integration. It’s still early days in terms of uptake, the company said, though there is strong repeat use among early adopters and positive qualitative user feedback.
Do AI assistants threaten Adobe?Some have questioned whether wider use of enterprise AI assistants could negatively impact software vendors such as Adobe, which announced a $25 billion share buyback program in April amid investor concerns about the threat AI poses to its business.
Miller said that making Creative Cloud apps available across tools such as Claude could be beneficial for Adobe, widening the reach of its own products.
“This could be an interesting opportunity since Claude is not replacing Adobe’s capabilities or applications in this scenario,” she said. “In fact, it more closely connects Adobe applications to work being done using Claude.”
Kirkpatrick sees the integrations as a way to make Adobe’s creative tools available to a wider audience of office workers.
“I view Claude and Gemini as an easy-to-use front door, which expands the reach of the platform to users that might ordinarily not ever really use Adobe products,” he said.
‘Freemium’ modelThere are three levels of access to the Adobe plugin for Claude.
Guest users require no authentication but can use only a smaller subset of Adobe tools, while those that log in to an Adobe account can access all functionality but with certain restrictions on usage. Paid Creative Cloud users effectively have unlimited access to available Adobe tools in Claude.
“The actual functionality for guest users, where Adobe doesn’t have basic user identification data, is still limited, which ensures that there’s a reason to further engage with Adobe and its products,” said Kirkpatrick.
Accessing Creative Cloud apps doesn’t require any additional fees or draw on any Adobe AI credits. Adobe declined to comment on future plans to monetize the integration.
For Gemini users, free and paid users can access Creative Cloud tools, but there’s no guest access.
Kirkpatrick describes Adobe’s approaches as a form of freemium model, with more functionality unlocked as users take steps such as signing up for a free Adobe ID or purchasing Creative Cloud or Firefly subscriptions.
This chimes with Adobe’s wider strategy for driving adoption of its own AI tools, with CEO Shantanu Narayen stating during a recent earnings call that attracting new users matters more than “short-term relief” around pricing.
“In a world where new tools and technology come on the market frequently, driving adoption through ease-of-use and then backing that with enterprise-grade security, IP-rights management, and scalability, Adobe’s freemium model appears to be the right play,” said Kirkpatrick.
Google is set to launch a small AI data center into space
On October 1, Google’s first test satellite for Project Suncatcher is set to be launched. This is the next step in the company’s plan to build AI data centers in Earth’s orbit, according to The New York Times. The idea is, among other things, to harness solar energy in space instead of building ever-larger data centers on Earth.
The first satellite, MVP, is about the size of a refrigerator and was built by the satellite company Planet Labs. On board are four of Google’s TPU accelerators, which will be used to run Gemini in space.
MVP is equipped with solar panels that generate about one kilowatt. This, combined with cooling limitations, means the TPU chips can only run for 15 minutes at a time during testing.
Google plans additional launches in 2027. The goal is a network of AI satellites that communicate with each other via high-speed laser links. However, Google expects it will take several years before Project Suncatcher can be developed into an actual product.
Data centers on Earth:
iOS 27: Why you should learn to love Impersonation Risk Detection
I once had a friend who gave $1,000 to an online fraudster who claimed to be a tax assessor. My own father (bless his soul) once managed to hand over several hundred pounds to a lawyer from Africa promising to send him funds.
We know it happens.
We know people impersonate trusted entities to trick us into giving them our money. It’s a scam, one that’s taking place at every level of digital existence.
Apple is here to help.
Yet another great feature new to iOS 27, Apple’s new scam-prevention tool is a welcome intervention, giving individuals and businesses another line of defense against social engineering scams. While it’s not perfect, it is here, and every Apple user — particularly those working in or managing regulated industries, or any business at all that feels it may be a target for scams, fraud, or socially-engineered crimes — should take a look. According to most security reports, that effectively includes all of us.
What is Impersonation Risk Detection?On its support site, Apple explains several hypothetical attack scenarios the feature is designed to protect against, such as when an attacker convincingly poses as a government agency or some other trusted entity to trick you into making a payment or changing account or login details.
These things are very hard for traditional security protection to spot, in part because you are choosing to take the action — security can’t tell you’ve been tricked. Apple’s new system works to bridge the gap. It looks at information it knows about your device and your Apple Account and tries to spot when you’re being scammed, delivering its own risk assessment.
While Impersonation Risk Detection is a new system-level tool, it does require user consent to permit supported apps to ask the operating system for a risk assessment if the user does something that could be in response to a scam.
That assessment takes the form of a risk level that helps the app decide what to do next. This will usually trigger additional security steps on the part of that third-party app, including a request for identification, a delay in a transaction, or a warning to let you know you might be being scammed.
Supported apps may request one of these risk assessments when you do things like make a payment or change security settings for your account. Apple tells us these assessments come in the form of one of three levels: Unknown, Medium, or High, with High meaning significant signs of suspicious activity have been detected. It is important to note that while Apple raises these flags, it’s the app that makes the decision on what to do next. Apple’s part ends once it raises the warning.
The settings for the feature also let you take a look at which apps have requested a risk assessment, and why. At least, it will once the feature is activated and has been running for a while. You’ll find a list of requesters in Recent Activity, while the Reasons for Access will show you what actions prompted the request.
Who sees what?If you do choose to share information with developers, they will only get the scam warning signals generated using information about your device and Apple Account. Apple, however, will learn the type of action you attempted in the app, and may also learn relevant details such as the number of calls or emails you’ve made.
This is what Apple says it checks:
- On the device, Apple analyzes interaction patterns, timing, context, and basic sensor data to generate the risk level.
- Apple never analyzes the content of your Photos, Messages, or Mail.
- Apple learns the type of action you attempted in the app only when the app requests the risk assessment.
- Apps receive only the risk level, not the data.
Because the tool requires that some of your information is shared, Apple has left Impersonation Risk Detection off by default. Here’s how to enable it or just take a look:
- Open Settings > Privacy & Security.
- Scroll down the pane to find the Impersonation Risk Detection section, which sits beneath the App Advertising item.
- Tap this, and on the next page you’ll find a toggle to share information with developers of apps that support the feature.
- Toggle this to on for the protection to kick in. Apple warns it may take four hours to come into effect.
Once approved, compatible apps can request Apple’s Impersonation Risk Detection signals to see if your device or account shows signs that you’re being scammed. And hopefully you — or my dad — won’t get fooled again.
Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSky, LinkedIn, or Mastodon.
Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions
OpenAI is preparing a $500 ChatGPT Pro Max plan with faster Codex
With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance
Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
Meta floats project to lay first petabit submarine fiberoptic cable
The 7,000 km (4,350 mile) cable, called Petal, will connect the US and France. Meta is partnering with NEC and Sumitomo Electric Industries to build it, and working with French telecommunications company Orange to coordinate the landing of the cable on the French coast.
Petal will have more than double the capacity of today’s fastest transoceanic cables. Last November, AWS laid plans for a 320 Tbit/s cable between the US and Ireland, while a cable connecting Australia and the US, announced in January this year, will deliver 400 terabits per second.
The need for greater data connectivity has prompted a boom in subsea cable deployment, but their existence is making some US lawmakers rather twitchy, as they are fearful of the security implications. There have been calls for the big service providers to provide details of all the cables they have in place. The concerns are warranted given the number of incidents involving subsea cables.
This article first appeared on Network World.
Microsoft plans to deprecate Windows Deployment Services
Google plans Gemini 4 release before year-end
Google’s Gemini 4 AI model is in the early days of post-training, the phase in which a base AI model is refined to behave reliably, and should be released “much earlier” than the end of this year, Google DeepMind head Koray Kavukcuoglu told The Information at its AI Agenda Live Summit. Some Google observers have speculated that this could be as early as October.
Kavukcuoglu recently replaced DeepMind founder Demis Hassabis as head of the Google business unit.
The launch of Gemini 4 may lay to rest concerns about the delayed release of Gemini 3.5 Pro, which Google was originally expected to announce at its May 2026 developer conference.
While less capable models in the Gemini 3 family have been frequently updated, Gemini 3 Pro has only been updated once since its November 2025 released. In contrast, OpenAI — spurred on by Sam Altman’s “Code Red” memo — has released three updates to its frontier AI model since then: GPT 5.5 Pro, GPT 5.6 Astro, and GPT 6 Astro. Anthropic, too, has updated its most powerful Claude model several times.
Google has not been entirely idle in the AI arena, concentrating its efforts on updating less powerful, more affordable Gemini versions. In July, it announced three Gemini Flash models, aimed at more routine AI tasks, but the company remained silent about its high-end alternative.
Rydox marketplace admin pleads guilty, faces 22 years in prison
The SOC Doesn't Need to Start Over with Every Alert
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- …
- následující ›
- poslední »



