Agregátor RSS

Takhle měkce Starship ještě nepřistál. Dnes to byl učebnicový let a raketa se na hladině pohupovala jako hračka

Živě.cz - 2 hodiny 23 min zpět
Oživeno 02:00 | Takhle měkce Starship ještě nepřistál, divili se moderátoři. A skutečně, dnes v noci to bylo na jedničku. Starship měkce dopadl do vod, převrátil se s velkým šplouchnutím, ale poté vždycky následovala ohnivá exploze zbytků paliva – vždyť je to to samé, jako by se převrátil vysoký ...
Kategorie: IT News

Pope's official prayer app commits cardinal sin, leaks 700K+ users' info

The Register - Anti-Virus - 4 hodiny 5 min zpět
Click To Pray, a prayer app endorsed by the Pope with hundreds of thousands of users worldwide, has leaked people’s names and email addresses for months - or longer - according to an ethical hacker who said she found and reported the security vulnerability six months ago to no avail. This app needs to take a vow of silence when it comes to your personal information. The app, available in seven languages and on iOS, Android, and clicktopray.org, is the official app of the Pope's Worldwide Prayer Network. It connects users across the globe to pray for the Holy Father’s intentions, and as of July 2026, it has 719,517 registered accounts. It’s also very leaky, according to security sleuth BobDaHacker, who says she spotted and disclosed the vulnerability to the Pope’s Worldwide Prayer Network on January 3. “The vulnerability is still live,” the hacker said in a Friday blog. “Nobody has ever responded. I guess my email wasn't in their prayers." The Reg readers likely remember BobDaHacker for her previous research exposing a free-food flaw in McDonald's ordering system and open controls on Chinese robot manufacturer Pudu Robotics. This latest security hole stems from an Insecure Direct Object Reference (IDOR) bug in the prayer app. This is a very common and easy-to-exploit type of flaw that occurs when a website or an app blindly accepts user-provided input to view or modify resources without checking to see if the user is actually authorized to retrieve the data. “You ask for your own data, the server gives it to you,” BobDaHacker explains. “You ask for someone else's data, the server gives you that too. Thou shalt not authorize, apparently.” When you sign up for a Click To Pray account, the app assigns you a sequential numeric user ID. As BobDaHacker uncovered, the API endpoint GET https://api[.]clicktopray.org/user/users/{id} will return user data for any account - not just your own account - so long as you supply a valid, five-digit user ID. It doesn’t perform any authorization check or ownership validation. “Just increment the number and get someone else's data,” she wrote. This data includes users’ email addresses, first and last names, country, dates of birth, and whether the account has been deleted, and the API exposes all 719,517 accounts on the prayer site. “With sequential user IDs and no rate limiting, an attacker could enumerate every single account on the platform,” the hacker explained. “One GET request per user. for i in range(1, 719518): scrape(). That's it. That's the exploit.” As BobDaHacker points out, many of these users are likely older individuals, not all that tech savvy, and very trusting of anything Vatican related, making these exposed accounts a “phishing goldmine.” “Imagine getting an email that says ‘The Holy Father requests your urgent attention’ with a Vatican-looking link,” she wrote. “Grandma is clicking that. Every time.” And then it gets even worse. The signup endpoint, POST https://api.clicktopray.org/user/users/sign-up, returns the account's validation_hash directly in the response body, and that value is the same UUID used in the email verification link. This means someone could sign up using any email address and verify the account before the confirmation message reached the inbox. Plus, BobDaHacker’s email client flagged the real verification email with a warning that it had failed the domain’s authentication requirements and might have been spoofed or improperly forwarded. “So not only is the API leaking 700,000 email addresses that could be used for phishing, but the real emails from Click To Pray already look like phishing,” the hacker noted. “An attacker wouldn't even need to try hard. They could send a pixel-perfect phishing email and it would have the same level of email authentication as the real thing: none. God works in mysterious ways.” The Register reached out to the Pope's Worldwide Prayer Network and did not receive any response. BobDaHacker says she’s still praying for one, too.®
Kategorie: Viry a Červi

Událo se v týdnu 30/2026

AbcLinuxu [články] - 4 hodiny 23 min zpět
Ucelený přehled článků, zpráviček a diskusí za minulých 7 dní.
Kategorie: GNU/Linux & BSD

Scientists Are Designing CRISPR Gene Editors With AI

Singularity HUB - 24 Červenec, 2026 - 23:47

To make CRISPR better at its job, researchers are turning to algorithms like DeepMind’s AlphaFold.

Gene editing is like a molecular meet cute. When protein “scissors” dock onto the intended gene, even a tiny slip—no more than the width of a hydrogen atom—can ruin the connection, and the protein may latch onto similar DNA sequences nearby. In a rom-com, a missed connection means heartbreak; in gene therapy, it can trigger dangerous off-target effects.

Now, AI is playing matchmaker.

In one recent study, researchers used AI to engineer more faithful gene-editing scissors with higher fidelity than previous versions. In another, AI designed scissors from scratch. Although the synthetic proteins are markedly different than their natural counterparts, they successfully edited genes in cells from multiple species.

The studies expand protein design. “The ability to customize the molecular geometry of genome editors will drive progress towards safer and more efficient therapies,” wrote Hoi Yee Chu and Alan Wong at the University of Hong Kong, who were not involved in either study.

Scientists still need to test the new molecular scissors inside the body. Meanwhile, they’ll continue searching for natural gene editors they can both employ and use to train AI.

Long Road to Precision

There’s no doubt CRISPR has transformed biology.

From blood disorders to inherited blindness and high cholesterol, the gene editor has gone from academic curiosity to a therapeutic powerhouse in just over a decade. Researchers and doctors are also using it to engineer immune cells that recognize and attack once untreatable cancers.

But it’s not all roses: CRISPR doesn’t always edit the right gene.

The gene editor’s protein scissors, called nucleases, are steered to a DNA sequence by a fragment of guide RNA. Once the arrive, the scissors cut the DNA and change the genome.

CRISPR was first used to inactivate target genes. A more sophisticated version, called base editing, can handle single DNA letter swaps. Yet precision is still a hurdle. Early CRISPR was even branded “genetic vandalism” for straying away from its intended target and making unpredictable genome-wide changes. Another problem is called bystander editing. This is when the tool alters neighboring DNA letters that weren’t supposed to be changed. Even a handful of unintended edits could undermine treatment.

Making CRISPR more precise is something of a holy grail. But nucleases are intricate molecular machines, and even small changes to a few critical building blocks can cripple them. To improve the proteins, studies have subtly altered existing nucleases and screened variants to surface versions that have better specificity without sacrificing activity, a tradeoff that has long plagued the field.

Both approaches are tedious and slow. And because they begin with natural enzymes, they explore only a tiny fraction of the protein designs that might actually work.

“What remains unclear is which amino-acid residues [protein building blocks] in Cas9 can be further engineered to maximize fidelity—that is, to ensure that the enzyme cleaves the genome at the correct site and makes the intended edit,” wrote Chu and Wong.

AI Intuition

A Chinese team turned to Google DeepMind’s AlphaFold 3 to open the black box. AlphaFold predicts not only protein shapes but also how proteins interact with DNA, drugs, and other biomolecules.

Most researchers use AlphaFold to CRISPR and its target DNA, revealing potential hotspots for engineering. This team took a different approach. Rather than focusing on a single protein-DNA structure, they used the AI to calculate the likelihood that specific parts of of CRISPRs protein scissors would interact with various DNA sequences.

They first mapped changes to the genome after base editing in human kidney cells and then compared thousands of off-target and on-target changes. To make sense of the data, they developed ContactSeek, an AI that pinpointed protein areas more often associated with mistaken targeting. These would be prime candidates for redesign.

They then used ContactSeek to improve a base editor that switches the DNA letter A to G. With only two changes, the new editor outperformed several existing high-fidelity editors. They also generated more selective CRISPR variants—those that used a different pair of protein scissors—without sacrificing editing efficiency.

Traditional methods often rely on individual trial-and-error experiments. But ContactSeek extracts patterns from thousands of predicted interactions, revealing contact regions that might be hard to detect from single tests. But like other AI models, ContactSeek’s predictions are only as good as the data used to train it. The tool could be further improved with more data and by adding complementary AI tools, such as RoseTTAFoldNA.

In a separate study, CRISPR pioneer Jennifer Doudna and colleagues asked AI to dream up entirely new nucleases. They focused on compact proteins that gave rise to Cas12, the proteins scissors often used in base editing. Instead of tweaking existing proteins, however, they fed an AI model the proteins’ 3D structure, and asked it to redesign them. The AI spooled out thousands of synthetic candidates.

But it didn’t give any hints about which might work, and testing each would be impractical.

Instead, the team trained a second AI on which parts of the proteins interact with each other and which with DNA. Eventually, the second model learned what sections could be changed and homed in on a handful of promising designs. They differed from their natural counterpart sequences by roughly 30 percent, far more than previous AI-designed CRISPR nucleases.

Despite being somewhat alien, several edited genes in bacterial, plant, and human cells. A few even outperformed their natural counterparts in terms of efficiency. Like ContactSeek’s designs, the synthetic nucleases must next prove themselves in the body. Researchers want to make sure they don’t trigger an immune attack and can edit enough cells to treat disease.

Neither study directly addressed bystander editing, another headache in the field. But the tools can work with each other. One fine-tunes nature’s gene editors; the other creates brand new designs. It’s early, but AI is beginning to help design the next generation of gene editing tools.

The post Scientists Are Designing CRISPR Gene Editors With AI appeared first on SingularityHub.

Kategorie: Transhumanismus

Europol flags 4,340 'horrific' URLs linked to The Com

The Register - Anti-Virus - 24 Červenec, 2026 - 22:20
Europol and its partners' investigators flagged 4,340 “horrific” URLs for removal over several weeks in June and July as part of an ongoing crackdown on The Com (short for community), a loosely knit network of online groups whose young members participate in a range of illicit activities. These range from hacking, swatting, and digital extortion to real-life shootings, stabbings, and other physical violence. Europol’s recent Referral Action Days, aimed at disrupting The Com’s online ecosystem and stopping the spread of its propaganda, is part of the larger Project Compass operation. Project Compass began in 2025, and its partner law-enforcement agencies span the US, UK, and EU member states. Investigators from Belgium, Finland, Hungary, Ireland, Luxembourg, the Netherlands, Portugal, Spain, and Sweden participated in the Referral Action Days during June and July. Various groups linked to The Com post content online to recruit members and groom young victims using social media, gaming platforms, and messaging apps. “The more extreme and harmful the content a user or group can produce or extort, the higher their status within the online community,” according to Europol. “These acts are often livestreamed on social media platforms, where online bystanders cheer them on, and later saved and disseminated.” The URLs flagged for removal during this latest push to disrupt The Com’s recruiting activities included “violent videos and images depicting self-harm, suicide, child sexual abuse material (CSAM), animal cruelty, and violent attacks,” the international cops said. This, the European cops say, includes so-called blood walls, which are paintings made with blood that display the extorter’s alias and group affiliation, and cut-signs, where the victims are forced to carve the extorter’s name into their bodies. It also includes videos of street attacks and arson, plus manuals on how to commit these violent attacks, along with instructions on grooming and extorting vulnerable minors, and conducting doxxing and swatting. Europol says its European Counter Terrorism Centre has received “hundreds” of requests from member states and others over the past two years to help investigate crimes linked to The Com. It describes the online network as a “global threat, particularly concerning minors as both victims and perpetrators.” Last year, both the UK and US issued similar warnings about a subset of The Com that recruits children and teens for contract shootings, kidnappings, and other real-life violent crimes. In July 2025, the FBI said that In Real Life (IRL) Com had become increasingly brazen in its swat-for-hire and violence-as-a-service solicitations. The FBI's alert followed a similar notice from the UK National Crime Agency about a "deeply concerning" trend of The Com recruiting teenage boys to commit a range of criminal acts, from cyber fraud and ransomware to child sexual abuse.®
Kategorie: Viry a Červi

OnTrac notifies customers of data breach after network hack

Bleeping Computer - 24 Červenec, 2026 - 21:55
OnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers. [...]
Kategorie: Hacking & Security

Hermes AI agent used to automate attack on Thai Finance Ministry

Bleeping Computer - 24 Červenec, 2026 - 21:09
A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]
Kategorie: Hacking & Security

As White House monitors latest OpenAI incident, Congress eyes an AI ‘kill switch’ for DHS

Computerworld.com [Hacking News] - 24 Červenec, 2026 - 20:37

The White House is monitoring developments after OpenAI revealed earlier this week that one of the company’s AI systems went beyond its intended parameters during a security test and managed to hack into the infrastructure of the AI platform Hugging Face. According to Reuters, presidential technology advisor Michael Kratsios has been briefed on the incident.

The OpenAI model escape also prompted a group of Republican and Democratic members of the House of Representatives to introduce two new bills. One, called the AI Kill Switch Act, would give the US Department of Homeland Security (DHS) the authority to order companies to shut down AI models deemed to pose a risk to human life or the US economy.

The other measure would require developers of the most advanced AI models to undergo independent security reviews before the systems are put into use.

Kategorie: Hacking & Security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Bleeping Computer - 24 Červenec, 2026 - 19:50
Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]
Kategorie: Hacking & Security

Jedna obrazovka na řídítkách stačí. Bosch posílá data z e-biku přímo do cyklopočítačů Garmin

Živě.cz - 24 Červenec, 2026 - 17:45
Bosch zpřístupňuje živá data ze svého chytrého systému zařízením třetích stran. Jako první je využijí kompatibilní cyklopočítače Garmin Edge, které zobrazí výkon jezdce, kadenci, stav baterie, dojezd i další údaje bez nutnosti dalšího displeje.
Kategorie: IT News

Microsoft blames massive Microsoft 365 outage on maintenance bug

Bleeping Computer - 24 Červenec, 2026 - 17:41
Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]
Kategorie: Hacking & Security

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

The Hacker News - 24 Červenec, 2026 - 17:12
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware. "BlueNoroff has operationalised trust abuse by combining compromised industry contacts, social engineering, walletRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

The Hacker News - 24 Červenec, 2026 - 16:15
Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. They codenamed the flaw Certighost. Because Domain Controller accounts carry directory replication rights, the resulting Kerberos credential can retrieve the krbtgt secret through DCSync. Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Chick-fil-A data breach affects more than 13,000 customers

Bleeping Computer - 24 Červenec, 2026 - 16:04
Chick-fil-A has confirmed that over 13,000 customers had their accounts breached in a wave of credential stuffing attacks targeting its website and mobile app between June 17 and June 19. [...]
Kategorie: Hacking & Security

Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack

Bleeping Computer - 24 Červenec, 2026 - 16:01
Slopsquatting, phantom squatting, and HalluSquatting all exploit the same late-binding attack pattern, where AI coding agents trust hallucinated package, repo, or domain names. ActiveState explains how pre-fetch verification and governed dependency management can help stop these attacks before malicious code enters the pipeline. [...]
Kategorie: Hacking & Security

Rusové chtějí přimontovat těžký kanón Armat pro raketové křižníky na kolečka

Živě.cz - 24 Červenec, 2026 - 15:45
Ruská invaze na Ukrajinu přináší smršť technologických inovací včetně poněkud neobvyklých řešení. Jedním takovým je i ruské námořní dělo v úpravě pro použití na souši a instalované na návěsu. Strojírenský závod Arsenal ze Petrohradu vyrábí pro ruskou flotilu lodní kanóny AK-100, AK-130, AK-726 a ...
Kategorie: IT News

Kubernetes Storage Flaws Expose a Dangerous Security Blind Spot

LinuxSecurity.com - 24 Červenec, 2026 - 15:17
Two newly fixed storage bugs in Kubernetes showed more than just a problem with path traversal. They found a common security flaw in the cloud: powerful parts often think that requests accepted by a higher system are safe to run. This is a simple lesson for the platform and security teams: RBAC can accept a request without showing that its parameters will stay within a certain filesystem boundary. This is clear from a new study from SentinelLabs into flaws in the Kubernetes CSI drivers for NF...
Kategorie: Hacking & Security

Europol flags 4,340 URLs for removal in 'The Com' crackdown

Bleeping Computer - 24 Červenec, 2026 - 14:56
Europol has flagged 4,340 URLs for removal during a multi-week operation targeting online content linked to "The Com," a loosely organized network of nihilistic violent extremist groups. [...]
Kategorie: Hacking & Security
Syndikovat obsah