Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

New Manic Android malware can exfiltrate data through nearby devices

Bleeping Computer - 1 min 43 sek zpět
A new Android malware named Manic targeting users in multiple European countries has a fallback data exfiltration mechanism that uses nearby infected devices. [...]
Kategorie: Hacking & Security

The Pixel 11 paradox

Computerworld.com [Hacking News] - 43 min 45 sek zpět

After a week of using Google’s new Pixel 11 phones, two seemingly at-odds realities are crystal clear in my mind:

  1. These are truly fantastic devices that build off the many successes of the previous-gen Pixel 10 models and push the products forward in some subtle-seeming but significant ways.
  2. Tech reviewers are gonna have an absolute field day with these things and tear ’em apart for being so similar to their predecessors — despite the fact that, by most measures, that probably won’t matter and is arguably on some levels even a good thing.

Interestingly enough, these two realities manage to exist harmoniously — because they’re both very much accurate and very much true.

The real question, then, becomes what all of that means for you as a productivity-minded, tech-dependent professional — and if these shiny new Pixels are advisable for you to think about buying.

The answer, believe it or not, is actually quite simple.

[Got a Pixel? Any Pixel? Check out my free Pixel Academy e-course to find all sorts of advanced intelligence lurking within your current phone!]

Google Pixel 11 perspective

First things first, let me tell you a little bit about my past week’s adventures.

Last Wednesday — the same day Google awkwardly launched its latest-gen Pixel 11, Pixel 11 Pro, and Pixel 11 Pro Fold (gesundheit!) phones in an elaborate evening event several hours after an extensive blog-based announcement — I received a box of loaner review units for all those shiny new models.

I’ve spent the past year or so living with my own personal Pixel 10 Pro, and I’ve personally owned and used almost all of the flagship-caliber Pixels (in one form or another) before that. Even with the iterations I haven’t personally owned, like last year’s Pixel 10 Pro Fold, I’ve spent plenty of time toting ’em around and getting to know ’em — and I’ve taken detours to explore most flagship-level Android gadget releases from other manufacturers along the way as well.

The Pixel 11 Pro in its Olive color atop my personal Pixel 10 Pro in Obsidian.

JR Raphael, Foundry

So when I moved myself into these latest Pixels and started carrying ’em in place of my now-standard 10 Pro device, I have all the perspective in the world to tell you that:

  1. These devices are all positively delightful to use. They’re beautifully designed, sleek as can be, and a joy to carry and rely on.
  2. That’s in part due to the hardware, which has gotten impressively polished (and also just plain purty) over the years, but it’s more because of the software and the uniquely pristine and bloat-free approach Google takes to its Android operating system. It’s a night-and-day contrast to the experience you see from Samsung and other Android device-makers, and the impact is extremely noticeable both in what the phones are like to use and in the lack of in-your-face ads and legitimate privacy worries that other Android approaches unfortunately include.
  3. They’re also advantageous as a result of the genuinely useful and thoughtful touches Google adds into its native Android apps — like all of the smart Pixel Phone app features that let you avoid annoying hold times, skip over maddening phone mazes, intelligently screen calls and dodge spammy and scammy interruptions, and even enjoy clearer audio quality from regular ol’ audio conversations.

And that’s to say nothing, of course, of the Pixel’s unmatched software support policy. The Pixel is the only Android device where timely and reliable software updates — both major Android releases and the many smaller rollouts that now accompany those throughout the year — are an unambiguous part of the core product promise. With any Pixel phone, you’ll receive every software update within days of its release. No other device-maker even comes close to matching that guarantee, and for anyone who cares at all about maintaining optimal privacy and security practices on your phone over time, that’s a distinction you simply can’t ignore.

So that’s the first part of the Pixel 11 paradox — and that’s why these latest Pixels are all incredibly easy to recommend as the best all-around Android experiences available today and the only sensible suggestions for a top-tier Android purchase in 2026.

But there’s another half of the story, and it’s equally important.

The Pixel 11 upgrade uncertainty

Plain and simple, the most striking thing about these latest Pixels is how similar they are to their previous-gen Pixel 10 equivalents.

Now, don’t get me wrong: On paper, these latest Pixels are packin’ plenty of pertinent improvements. They’ve got new extra-efficient processors, brighter and supposedly more scratch-resistant displays, faster charging speeds, some new and improved camera components, and a thinner camera bar on the back. The Fold model is also ever-so-slightly thinner and lighter than its predecessor, by 0.7mm when folded (0.02″ — roughly half the thickness of a US dime) and 19g (roughly two-thirds of an ounce — the equivalent weight of three #2 pencils).

Speaking of the Fold, the 11 Pro Fold model is a true treat to use, and I still love its more familiar-phone-like form compared to the shorter and squatter, square-ish shape Samsung is now adopting ahead of Apple’s expected move in that same direction. The Pixel Fold’s dimensions allow you to feel like you’re using a regular phone most of the time, without much compromise or awkwardly limited screen space, and then enjoy that glorious tablet-like screen on the inside whenever you feel like unfolding it.

The Pixel 11 Pro Fold in my hand, with the 10 Pro Fold behind it.

JR Raphael, Foundry

Again: All of this works. Across the board, the Pixel 11 phones couldn’t possibly be pleasant to hold, carry, and use. They’re fast, their photos are second to none, and they sport a couple of truly interesting new software features that you might actually appreciate — like a new Magic Capture camera mode that lets you tap one button to record a video and automatically get full-resolution photos of the most meaningful moments from within it and an enhanced Android voice typing system that works like Wispr Flow and makes dictation easier and more accurate than ever.

There’s also a new HiLight LED system on the Pro models’ backs that’s intriguing in theory but almost shockingly limited in implementation. Quite literally, all it does at the moment is light up when you’re talking to Gemini hands-free and light up with a custom color when one of your favorite contacts is calling.

The Pixel 11 Pro’s HiLight LED, visible here at the right side of the camera bar, lights up for Gemini — and not much more.

JR Raphael, Foundry

It’s a great idea and return to the simple effectiveness of notification lights from Android’s past, but it’s embarrassingly half-baked in its execution. You can set up something similar but much less limited and more useful with a few minutes of crafty configuring on any Android device.

Oh, and these latest Pixels also pack a handful of new whizbang AI additions that you probably won’t notice or ever do much with.

So as you can see, in and of themselves and in the big picture, the Pixel 11 phones all stand out and are exceptional. But when you start looking at them compared to last year’s models or even the Pixel 9 devices before that — well, things get a little more complicated.

In a week of using the different Pixel 11 phones, I couldn’t immediately detect or appreciate the presence of any of the aforementioned year-to-year improvements compared to the experience of using last year’s Pixel 10 models. The camera performance is still incredible, but looking at photos taken with the Pixel 11 Pro and Pixel 10 Pro (or any other 11-to-10 Pixel-to-Pixel comparison), the actual visible differences are subtle enough (and the previous model’s photos strong enough) that I suspect few people will spend much time thinking about them. As far as the processor goes, the phones feel zippy and as fast as can be right now, for sure — but, once more, I’d struggle to say they’re noticeably any faster, in real-world terms, than the models that came before them. And as far as the Fold is concerned, the form differences from last year’s device are so subtle that I think most people will be hard-pressed to be aware of the evolution.

The same photo taken seconds apart on the Pixel 11 Pro (left) and 10 Pro (right).

JR Raphael, Foundry

The Magic Capture mode is nice, meanwhile, but I’m not sure it’s a reason in and of itself for most folks to buy a new device if they’re already using a recent previous-gen Pixel — and it may well make its way to older Pixels eventually. The enhanced Android voice typing system might be a reason to upgrade — but (a) it’ll almost certainly come to the rest of the Android ecosystem before long, and (b) in the meantime, you can get almost the exact same experience in just a slightly less native-feeling and convenient way by installing Wispr Flow.

That aside, we can’t overlook two downgrades in the Pixel 11, compared to the 10 models: First, the Pixel 11 eliminates the thermometer that’s been present on the past few Pixel Pro models — something that was originally launched before it was ready but that evolved into a genuinely useful element. I can’t even count the number of times my wife or I have relied on it for taking a quick temperature when someone’s under the weather and a standalone thermometer can’t be found or is acting up and giving us a different reading every time we try it.

Second, and perhaps even more significant, the Pixel 11 Pro models start with 12GB of RAM and only bump back up to 16GB — the standard level of memory for all Pro models last year — if you opt for the pricier 512GB storage version. The reason for this change is seemingly an industry-wide issue that’s out of Google’s control, of course, but it’s still something you’re faced with as a potential purchaser of these products. (I’d be surprised if anyone detected an immediate discernible difference in experience as a result of this change, but it stands to reason that the limitation could adversely affect you at some point down the line — particularly if you’re doing a lot of multitasking or other resource-intensive work.) The Pixel 11 Pro Fold, meanwhile, maintains its 16GB RAM level but includes a $100 price hike from last year’s version.

So while the Pixel 11 phones are great phones in and of themselves, they aren’t exactly great upgrades if you’ve already got a Pixel 10 or arguably even a Pixel 9 equivalent in your person-paw. And because of that, most reviewers are gonna look at ’em and say, “Meh. These aren’t exciting.”

Here’s a little secret, though: Particularly for professionals, “exciting” isn’t everything. An exceptional all-around experience and the knowledge that your device will remain optimally up-to-date as far as security, privacy, and performance are concerned — for a full seven years, with these products — means more. And in a weird way, having these phones not feel like must-buy upgrades over the past couple models is actually an indication that those previous years’ products are doing their jobs well.

If you’re on an older-gen Pixel or thinking about making the leap to the land of Pixels for the first time, you can’t go wrong with any of Google’s new Pixel 11 options. They may not be exciting, exactly, compared to what came before ’em — but in an era where almost everything new is all about AI gimmicks for the sake of AI (and often at the expense of accuracy and quality), avoiding excitement and sticking to a setup that simply works well might be the smartest move you can make.

Don’t let yourself miss an ounce of Pixel magic. Sign up for my free Pixel Academy e-course and discover tons of hidden features and time-saving tricks for whatever Pixel you’re using right now!

Kategorie: Hacking & Security

Critical Zimbra RCE flaw now actively exploited in attacks

Bleeping Computer - 56 min 1 sek zpět
CERT Polska, the Polish Computer Emergency Response Team (CERT), warned that attackers have begun exploiting a critical vulnerability in Zimbra Collaboration Suite (ZCS). [...]
Kategorie: Hacking & Security

40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets

The Hacker News - 2 hodiny 1 min zpět
A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 products. According to the Socket Threat Research team, the extensions are part of a broader set of 77 browser add-ons that share source code and infrastructure overlaps. The campaign, dubbed Offside Wallet Theft Factory, is believed to Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Microsoft says August Windows updates may cause gaming issues

Bleeping Computer - 3 hodiny 52 min zpět
Microsoft is investigating a potential issue with the August 2026 updates that may prevent some games from launching or cause them to crash on affected Windows 11 systems. [...]
Kategorie: Hacking & Security

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

The Hacker News - 4 hodiny 39 min zpět
Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been described as a case of unrestricted upload of a file with a dangerous type. "The flaw lives in the Forms module's File Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

When AI explains its decision, humans may stop thinking independently

Computerworld.com [Hacking News] - 9 hodin 40 min zpět

AI is known to be confidently wrong, and now it’s influencing humans to be that way, too.

In a new study, researchers tested AI’s influence on humans reviewing innovation proposals, and found that AI recommender tools were persuasive enough to convince the evaluators to reject decisions made by independent human experts, thus causing them to pass on promising innovations. Similarly, they went along with AI approval of ideas that the human experts found sub-par.

Interestingly, reviewers were also more inclined to defer to an incorrect AI decision when the model explained itself. Narrative explanations degraded human judgment, rather than enhancing it. People did better when they weren’t given a reason for the AI’s decision.

“Our findings reveal that LLM explanations do not necessarily improve decision-making,” the researchers, associated with Harvard Business School, MIT, and the University of Washington explained in their findings. “Effective human-AI collaboration requires designs that preserve rather than supplant independent human judgment.”

AI rationale can undermine human judgment

Every enterprise screens proposed projects before pursuing them, but there is always uncertainty, and the risk of trade-offs like false positives (going forward with projects that ultimately fail) or false negatives (rejecting ideas that might have succeeded). For an example of the former, the researchers point to Google Glass or Amazon’s Fire Phone; for the latter, Xerox terminating early Ethernet and PostScript projects.

Because they have limited time and only basic information to go on, decision-makers are increasingly turning to LLMs that use predictive algorithms to generate recommendations and rationales based on context.

The researchers set out to explore AI’s role in what they called “early-stage innovation screening.” They judged how human evaluators were influenced by LLM recommendations, both with and without explanations from the model on how and why it reached its decision.

Their experiment asked 228 experienced evaluators to assess nearly 50 submissions to an MIT challenge. They tested three different scenarios: human-only proposals with no AI assistance; LLM evaluations with a written rationale for the decision; and black-box AI pass-fail recommendations with no accompanying explanation.

Evaluators’ decisions were then compared to those made by four human experts. Those decisions were considered the ‘correct’ baseline. They were judged on whether they outright complied with the LLM’s recommendations, overrode them, or productively overrode them, meaning they independently verified persuasive model outputs before making a decision.

Their decisions were classified as correct (agreeing with human experts’ positive/negative decisions), false positive (supporting submissions that experts would reject), and false negative (rejecting submissions experts would move forward with).

Overall, the evaluators accepted LLM recommendations 67% of the time. They agreed with both black-box and narrative LLM decisions roughly 75% of the time, but only agreed with human decisions 54% of the time.

Seemingly counterintuitively, black-box recommendations improved the quality of decisions (aligning them with human experts) but recommendations with narratives did not. When given an LLM recommendation to reject a submission and an accompanying reason why, evaluators disproportionately agreed, which reduced false positives, but “substantially” increased false negatives.

The researchers posit that this is because narrative explanations “suppress” productive overrides; LLMs provide a convincing argument that is easy to accept, essentially discouraging independent human verification. This contradicts a common assumption that LLM explanations augment human decision-making.

The researchers pointed out that people are cognitively predisposed to weigh negative information more heavily than positive information; the phenomenon is known as ‘negativity bias.’

“Rejection is an active, eliminative decision that feels more consequential and accountable than preserving optionality,” they wrote. It also maintains the status quo, avoids risk and bias, and requires no resource commitment.

LLM explanations provide “ready-made justifications” for going along with rejection decisions without independently verifying them; humans effectively offload their thinking to AI, researchers explained. Evaluators often rely on surface cues such as fluency, coherence, and seeming credibility. LLMs are particularly well-suited to exploit this because they are linguistically fluent and expert-like, creating an “illusion of explanatory depth.”

Thus, “individuals tend to overestimate their understanding of a decision despite limited insight into its reasoning,” the researchers wrote.

Finding a balance in recommendation systems

The researchers pointed out that their findings have “clear implications” for enterprises designing AI-assisted evaluation systems.

Enterprises should be cautious with LLM explanations in high-stakes decision-making, they advised. AI recommendations should not be taken at face value; they should always be tested before any associated deployment. This helps improve accuracy and encourages human reviewers to detect errors and learn how models operate, or potentially can even increase human-AI agreement.

In decision contexts such as quality control, compliance screening, or fraud detection, LLM explanations could support conservative human decision-making, the researchers noted. On the other hand, in tasks like early-stage screening, LLM narratives could undermine performance by “discouraging independent judgment and suppressing productive human override.” In this context, simpler or more opaque recommendations may preserve human discretion and verification.

Future design of explanation systems should factor in the nature of the task and the potential cost of errors made by AI, the researchers advised. Enterprises could experiment with models that support contrasting narratives (reasons to reject an idea alongside reasons to accept it) or uncertainty disclosures based on a fixed threshold, rather than on purely binary decisions. Systems could also be structured to invite human disagreement.

The researchers also noted that there is opportunity to test whether narrative explanations have different impacts at later stages of decision-making, when evaluators have fewer options, more information, and increased incentive to verify outputs and think the problem through.

Ultimately, the researchers emphasized, “organizations should treat AI explanations not as universally beneficial transparency tools, but as behavioral interventions whose effects depend on how evaluators process information under uncertainty.”

This article originally appeared on CIO.com.

Kategorie: Hacking & Security

OpenAI confirms ChatGPT is down as logins and signups fail

Bleeping Computer - 10 hodin 22 min zpět
ChatGPT is experiencing a major outage, and users are unable to sign in, create accounts, or load chats, including previous conversations. [...]
Kategorie: Hacking & Security

OpenAI ‘temporarily slows’ scaling efforts, also promises zero data retention for select frontier model customers

Computerworld.com [Hacking News] - 10 hodin 35 min zpět

OpenAI this week announced multiple moves designed to counter negative perceptions of its security and privacy, saying it had slowed its pace of scaling, implemented a two-week pause in reinforcement learning, and will be offering zero data retention for “eligible API customers.”

In its first announcement, issued Tuesday, OpenAI said it “temporarily” slowed the pace of its scaling, in addition to pausing reinforcement learning training. 

Those efforts occurred while OpenAI hardened and red-teamed its research environment and expanded monitoring, it said, adding, “our largest planned frontier RL run remains on hold while we conduct smaller-scale training and evaluations to assess model behavior, validate our safeguards, and establish more evidence of alignment before proceeding.”

OpenAI’s statement said the company will “now require stronger evidence of aligned behavior throughout all of training, building on research and evaluations already underway. Keeping increasingly capable systems aligned is a challenge the whole field will need to address.”

It also highlighted other recent efforts to improve its procedures, including workload isolation, network isolation and “continuous security testing.”

However, the company noted that its newly proposed monitoring will generate overhead costs of “roughly 20% of the inference compute being monitored, though the cost varies substantially across training and evaluation workloads.” It promised to share more details about this system in a forthcoming blog post.

Analysts and consultants said that the moves were likely announced to position OpenAI better for an imminent IPO

Carmi Levy, an independent technology analyst, viewed the statements as “a slickly conceived move to win PR points as safety concerns around agentic AI continue to mount. It signals that the company is doing something, even if that something is woefully inadequate. In the absence of explicit regulations forcing vendors like OpenAI to permanently prioritize safety above all other factors, a two-week pause is little more than window dressing designed to deflect criticism.”

Jason Andersen, principal analyst at Moor Insights & Strategy, agreed, saying that he thought that “this is a little bit of pragmatic theater as they move into an IPO.” But he suggested that there also may be more going on. Enterprises will continue to spend on AI aggressively, and “it will be pedal to the metal until they get sued.” Then they’ll back away.

However, he said, “the only way that these [large AI] companies are going to be successful post-IPO, the only way to scale, is to get much deeper into enterprises. And the only way to do that is to alleviate fear and risk.”

Zero data retention?

In Wednesday’s announcement, OpenAI didn’t say what constitutes eligibility for the zero data retention program, only that it would start in September, when the company would share details in a “technical white paper.”

But Andersen said that this move has to be viewed in the context of today’s complicated vendor relationships. 

Much of OpenAI’s revenue is not direct from the enterprise, but through partners like Microsoft and AWS, he pointed out. “So let’s say I use a tool like Amazon Kiro, which can use OpenAPI via API to build my app without my knowledge of the model. It sounds like Amazon is the customer and you are Amazon’s customer. If you are an enterprise and want this [zero data retention] protection, you must provide your own API key to Kiro. The enterprise just becomes the direct customer and now gets the lockbox access. AWS no longer has access and loses out on revenue/margins.”

Consultant Brian Levine, executive director of FormerGov, added that the data retention promise is also complicated by how processes tend to function.

“OpenAI says it can now monitor for abuse across interactions without any staff ever reading the underlying content,” he said. “That is a strong technical promise, because watching for misuse and not being able to see the data have historically pulled in opposite directions. And the proof is a white paper that is still weeks away.”

In addition, he noted, “Zero is never quite zero because CSAM-flagged content is still retained for legal reporting.”

Flavio Villanustre, CISO for the LexisNexis Risk Solutions Group, saw the move somewhat differently, suggesting that it was designed to soften possible legislation.

“It is likely that they are seeing the writing on the walls about upcoming regulations that could have a significant impact on them, and this could be their attempt at showing a desire to self-regulate to avoid a more draconian legislation in the future,” Villanustre said. 

Still, Mike Wilkes, enterprise CISO at Aikido Security, observed, “sincerity is not the same thing as permanence. In the old Norse/Scandinavian image of a giant sea monster waiting beneath the surface, you might call this ‘Pause the Kraken.’ The real question is what conditions have to be met before OpenAI decides to release it again.”

Added Justin St-Maurice, technical counselor at Info-Tech Research Group, OpenAI seems to want credit for doing the bare minimum of what a major AI firm should have always done.

“If a carmaker announced that it was going to take basic safety testing more seriously before production, it wouldn’t be to fanfare. Frankly, it would be embarrassing that something so fundamental needed clarifying to a skeptical public,” he said. “The question for me is why this needs to be an announcement now, and whether they hold the line once a competitor ships something that makes a pause expensive.”

Thus, he advised, “stop treating these announcements as diligence. Ask for the evidence of what you’re actually getting, not what you’ve been promised. If a vendor can pause development for security reasons, and the way you found out was through a blog post, then you should be asking what your contract requires them to disclose to you.”

Kategorie: Hacking & Security

Rogue ransomware affiliate poses as recovery firm to steal payments

Bleeping Computer - 19 Srpen, 2026 - 22:59
A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]
Kategorie: Hacking & Security

Rogue ransomware affiliate poses as data recovery firm to steal payments

Bleeping Computer - 19 Srpen, 2026 - 22:59
A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]
Kategorie: Hacking & Security

Sakura Internet hack exposes data of up to 1.36 million accounts

Bleeping Computer - 19 Srpen, 2026 - 22:53
Japanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system, where customer contract and membership information is stored. [...]
Kategorie: Hacking & Security

Healthtech firm CareCloud data breach impacts 3.7 million patients

Bleeping Computer - 19 Srpen, 2026 - 22:07
U.S. healthcare IT company CareCloud disclosed that the data breach incident it suffered earlier this year has impacted more than 3.7 million individuals. [...]
Kategorie: Hacking & Security

Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second

The Hacker News - 19 Srpen, 2026 - 21:02
Cybersecurity researchers have disclosed details of a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker in the production environment at up to 12 bits per second, 360 times the rate of an earlier attack demonstrated in 2021. The end-to-end experiment used an attacker Worker and a victim Worker controlled by the researchers, Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Hackers compromise 14,500 Dahua web cameras in 35-day campaign

Bleeping Computer - 19 Srpen, 2026 - 20:09
In a large-scale campaign that researchers dubbed CameraSwarm, hackers compromised more than 14,500 Dahua IP cameras mostly in Ukraine and Russia. [...]
Kategorie: Hacking & Security

OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior

The Hacker News - 19 Srpen, 2026 - 20:06
OpenAI on Tuesday revealed that it paused reinforcement learning (RL) training for its latest artificial intelligence (AI) models for two weeks while it shored up additional defenses and increased the scope of its monitoring to avert another Hugging Face-like incident. "As models become more capable, the risks associated with developing and testing them internally also grow," the AI company Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

US warns of AI-powered attacks on Siemens PLCs in critical infrastructure

Bleeping Computer - 19 Srpen, 2026 - 19:50
U.S. cybersecurity agencies warn that threat actors are using AI-generated scripts to exploit Siemens S7 Series programmable logic controllers (PLCs) in U.S. critical infrastructure. [...]
Kategorie: Hacking & Security

The Google Pixel 11 Pro XL: A smarter phone for getting things done

Computerworld.com [Hacking News] - 19 Srpen, 2026 - 18:01

The new Google Pixel 11 Pro XL doesn’t dramatically reinvent the company’s flagship smartphone formula. From a hardware perspective, this year’s model represents an incremental update. But after spending time with Google’s latest full-featured Pixel, I’ve found that some of its most meaningful improvements for business users aren’t necessarily the things that stand out on a spec sheet or benchmark chart.

Starting at $1,299 with 256GB of storage, the Pixel 11 Pro XL features a 6.8-in. Super Actua LTPO OLED display, Google’s new Tensor G6 processor, a 5115mAh battery and an updated triple-camera system. Google also pledges seven years of operating system, Android security and Pixel Drop updates.

The hardware is very good, but Google’s deeper integration of Gemini with Android and other thoughtful software features are what make this device more interesting.

Tensor G6 performance: The numbers don’t tell the whole story

Google’s Tensor processors have never been benchmark chart-toppers, and the Tensor G6 doesn’t change that. In Geekbench 6, the Pixel 11 Pro XL scored 2,736 single-core and 7,399 multi-core numbers. That’s a healthy improvement over the Pixel 10 Pro XL’s 2,326 and 6,413, respectively, but well behind devices like Samsung’s Galaxy S26 Ultra (at 3,683 and 11,243) powered by Qualcomm’s latest SoCs.

Dave Altavilla

In 3DMark Wild Life, the Pixel 11 Pro XL scored 13,761, essentially neck-and-neck with Apple’s iPhone 16e at 13,627, though still far behind current gen flagships like the Galaxy S26 Ultra at 31,036.

There’s an important disconnect, however, between those numbers and actually using the phone. The Pixel 11 Pro XL feels fast and responsive in everyday use, whether moving between email and messaging apps, browsing complex websites or multitasking. Google claims the Tensor G6 delivers 25% faster web browsing and 15% faster application launches, while its TPU offers 50% more compute and up to 3.5X faster on-device AI processing.

For business and mainstream users, benchmark performance is less relevant unless you’re also a mobile gamer. Opening and switching between apps especially feels more responsive than other Android phones I’ve used as daily drivers. Add Google’s latest software efficiency and AI features, and the Pixel 11 Pro XL feels much more capable than the benchmark numbers suggest.

Rambler is AI with an everyday, practical purpose

Rambler may be the best example of Google’s efforts to minimize friction. Google has long offered excellent speech-to-text input, but Rambler takes voice input further. Instead of requiring carefully structured dictation, the Gemini-powered feature understands natural speech, including pauses and filler words, and turns it into cleaner written text.

Google Rambler with Gemini AI Assist listens to you before generating text.

Dave Altavilla

In practice, it’s a significant improvement and allows me to make fewer dictation mistakes, whether writing emails or texting. Being able to speak naturally and have the phone turn those thoughts into clean, well-crafted text is genuinely useful, and auto punctuation also seems improved. This is the kind of AI functionality I want from a business-focused device: technology that removes friction and makes me more efficient, rather than shoehorning in AI just for AI’s sake.

Gemini Intelligence also extends contextual assistance across more than 40 apps. Google can surface flight information when you’re discussing a trip, suggest adding events to Calendar or locations to Maps, and pull relevant information into Wallet.

The Pixel 11 also expands Google’s Live Translation capabilities to real-time translation and dubbing of video and audio using on-device generative AI models enabled by the Tensor G6. These features could be especially useful for international business and personal travel.

HiLight is a good idea that needs more flexibility Pixel 11 Pro XL HiLight alerts that Gemini is active.

Dave Altavilla

HiLight is a new software feature and integrated RGB LED array on the rear camera bar that provides visual feedback when Gemini is active and displays different colors for incoming calls from selected contacts.

The concept has real potential for business users. Put your phone face-down during a meeting and you could know whether something important requires attention without repeatedly picking up the device to check. Unfortunately, Google doesn’t expose enough configurability yet. I’d like to associate colors or patterns with an important email, Teams or Slack message, Calendar alert or priority contact. Google says message notifications from favorite contacts are coming, but the hardware appears capable of much more.

Excellent display and cameras, with better battery life

Dave Altavilla

The Pixel 11 Pro XL’s 6.8-in., 1-120Hz LTPO OLED Super Actua display is excellent, with peak brightness now reaching 3,600 nits. It’s easily one of the nicest phone screens on the market, with plenty of punch in daylight and accurate, vibrant colors. Its speaker system remains strong as well, while the Pixel 11’s industrial design is an attractive evolution of Google’s familiar camera-bar aesthetic.

As we’ve come to expect from Pixel phones, the camera system is also excellent, with a 50MP main sensor, 48MP ultrawide and 48MP 5X telephoto camera. Shots are crisp, with especially good low-light performance and telephoto capability. The Pixel’s color science has always been a bit drab for my taste, while others on my team call it more “accurate” versus the often more saturated rendering of Samsung Galaxy devices.

Pixel 11 Pro XL Creator Suite video settings.

Dave Altavilla

New software features include Camera Looks, Magic Capture and Creator Suite. Camera Looks provides more control over how Pixel devices process photos at capture, while Magic Capture uses AI to analyze hundreds of frames to catch fleeting moments. Creator Suite offers perhaps more practical utility for professionals, with an integrated teleprompter and project organization tools for producing video and social content on the fly.

Battery life appears improved as well. My observations are anecdotal currently, with specific benchmark testing still to come, but the Pixel 11 Pro XL seems appreciably more efficient than the previous generation. It’s not a groundbreaking leap, but battery life is solid and competitive with premium Android flagships like Samsung’s Galaxy S26 family. Some Chinese phone makers are operating in another class these days, with much larger silicon anode batteries and extremely fast charging, but that’s a different segment of the market in my opinion.

In my day-to-day use, which is admittedly heavy, the Pixel 11 Pro XL reliably gets me through a full, long day, though I typically need to top it off again the following day on my Pixelsnap charger.

Regardless, the Pixel 11 Pro XL’s 5115mAh battery can reach a 75% charge in roughly 30 minutes with a compatible 45W charger, while Pixelsnap Qi2.2 wireless charging tops out at 25W. So, at least there are well-rounded power options here.

Security and long-term support matter

The new Tensor G6 works alongside Google’s new Titan M3 security coprocessor and Trusted Execution Environment, with post-quantum cryptography extending into the device’s secure boot process. The Pixel 11 Pro XL also includes anti-phishing, anti-malware and scam protections.

Combined with seven years of OS and security updates, Pixel devices remain a compelling Android platform for organizations that intend to keep phones in service fleets for several years.

Pixel 11 Pro XL: Incremental hardware, better overall experience

Dave Altavilla

The new Google Pixel 11 Pro XL doesn’t deliver a major generational hardware upgrade. Its conventional benchmark performance trails the fastest flagship phones, physical changes are modest, and most Pixel 10 Pro XL owners will likely have little reason to rush out and upgrade.

That said, Google’s differentiation with its Pixel series increasingly comes from the intersection of Android, its Tensor silicon, Gemini AI and the company’s broader services ecosystem. Rambler demonstrates particularly well why that approach makes a difference. The feature obviously doesn’t require massive horsepower, but this type of on-device AI can make a measurable difference in how efficiently someone uses a smartphone throughout their workday.

For business users coming from an older Pixel or another Android device, the Pixel 11 Pro XL is a polished, secure and highly capable productivity, creation and consumption device with an excellent display, great cameras, solid battery life and increasingly useful AI features.

The bottom line is that this is an evolutionary Pixel launch. But Google’s software and AI integration make the overall experience more compelling than hardware specifications alone would suggest.

Kategorie: Hacking & Security

US charges Iranian hackers over $3.4 billion intellectual property theft

Bleeping Computer - 19 Srpen, 2026 - 17:56
The U.S. has charged 17 Iranians, alleged members of a hacking-for-hire company called Mabna Institute, involved in years-long operations that stole data from American organizations. [...]
Kategorie: Hacking & Security

Apple’s EU App Store truce: What changed — and who’s still angry?

Computerworld.com [Hacking News] - 19 Srpen, 2026 - 17:43

Apple has changed its App Store fee structure in the EU in a move to further satisfy the requirements of the Digital Markets Act (DMA). While critics continue to argue the changes don’t go far enough, the European Commission welcomed the changes made and plans to monitor how they’re implemented.

The new fee structure

Specifically, Apple introduced a less complex system than it had offered before, with a lower, but universal, 5% Core Technology fee applied on digital transactions in apps distributed outside the App Store. Apple changed its commission structure and eliminated some fees, including initial acquisition and store services fees. It has also expanded the scope of eligibility to operate alternative app marketplaces. The new changes go into effect Oct. 1, and include (verbatim from Apple’s statement):

  • For App Store apps using Apple In-App Purchase, the commission will be 26%. For the vast majority of developers, including those in the App Store Small Business Program, Mini Apps Partner Program, or Video Partner Program, and for auto-renewing subscriptions after their first year, it will be 15%.
  • For App Store apps using alternative payment processing, the commission will be 20%. Developers in the programs mentioned above will pay a reduced rate of 10%.
  • For App Store apps that link out of the app to complete purchases, the commission will be 15%. Developers in the programs mentioned above will pay a reduced rate of 10%.
  • For apps distributed via alternative app marketplaces or the web, Apple will charge a 5% Core Technology Commission.
What else has changed

There are additional improvements to what Apple was offering before, Developers, for instance, can now offer Apple In-App Purchase alongside alternative payment options. Also:

  • Apple has agreed to a set of child safety measures, including that apps in the Kids category will not include links to external websites to complete transactions.
  • Apps that do use alternative payment systems must require parental approval for the purchase.

In what I consider a major win for most customers, Apple also seems to have convinced Europe of the need to require every alternatively distributed app to go through the company’s Notarization service. This provides a baseline review of an app aimed at ensuring basic functionality and protection from serious threats; that’s important, as it implies that Apple customers can be a little more certain, if not completely confident, that apps purchased outside of the App Store aren’t packed with secret malware or payment scams. While Notarization isn’t able to fully ensure against that, it helps.

Who actually benefits?

Put the changes together and I think large developers will find themselves paying Apple less for the privilege of selling apps on its platform, while for the vast majority of developers a 15% charge remains. Epic, in contrast, charges developers 12%, but arguably offers a much more limited infrastructure as it does not make devices, operating systems, or any of the supporting services that make a good customer experience on the platform. 

The fact that Apple has worked with the EU to reach these new terms, which to a great extent do seem to deliver much of what was required under the DMA in relatively straightforward fashion, should sound like a win to critics of the App Store business. Apple has made it possible to use alternative payment systems and app stores and seems to have coalesced around the 15% fee as a base charge for the vast majority of developers with a much clearer and more straightforward approach. The company would likely argue that while doing this, it has striven to protect its business and its customers — and it can argue it should be able to generate revenue from an app’s distribution on its platform.

The fire and the fury

That’s not how Apple’s fiercest competitors see things. The Coalition for App Fairness, a group that includes competitors Spotify and Epic, put it this way: “Apple’s new terms defeat the purpose of the DMA by keeping fees high and blocking true competition.” 

Meanwhile, Epic CEO Tim Sweeney wrote, “Apple has launched a new junk fee structure in EU, mirroring the terms in Brazil and Japan. They’re still unlawfully charging for linked-out transactions (clearly prohibited by DMA) and add prohibitions and friction to herd kids into high-junk-fee Apple payments.”

The tone of both statements suggests that if the EU finds itself satisfied that Apple has brought itself into compliance with the DMA, some of its competitors might challenge that decision in the courts. They’ll have to if they want to avoid becoming bit-part players in Apple’s history, which is what an EU-approved settlement would reduce them to

Where do we go from here?

Apple, on the other hand, will likely continue to say some of its competitors want to compete on its platforms while paying nothing. If this continues, regulators will eventually need to define what they see as a viable revenue model (and why). At the same time, the tone of Apple’s latest statement suggests the new deal already matches regulatory expectation. If so, then it’s all over bar the shouting, and if the new détente holds, it’s reasonable to expect Apple will introduce this new business arrangement elsewhere over time as it firmly closes the door on its Epic struggle.

You can follow me on social media! Join me on BlueSkyLinkedInMastodon and subscribe to my newsletter for news and analysis.

Kategorie: Hacking & Security
Syndikovat obsah