Agregátor RSS

Jamf in the age of agentic IT: An interview with CEO Beth Tschida

Computerworld.com [Hacking News] - 24 Září, 2026 - 17:50

Jamf was a pioneer in Apple device management when it began in 2002. The company was ahead of its time: its founders could see that Apple had a future in the enterprise, but not many others saw it. Jamf now runs 35.2 million devices from 78,000 organizations. And it’s still looking to the future.

I spoke with Jamf CEO Beth Tschida, who joined me for a chat directly after her keynote speech at JNUC, Jamf’s big event for Mac admins, on September 23. 

The AI-driven ecosystem

Tschida wasn’t there to rehash Jamf’s past for relevance in the present, but to share the company’s deep commitment to being where its customers are going to go. That means artificial intelligence, which in Jamf’s case involves weaving AI across its ecosystem of products, from setup to tech support, security, and beyond.

It’s not a new vision — you could argue that some early signs of its intention were visible when the company acquired ZecOps in 2022 — but time moves forward and the company has coalesced around a firm philosophy of how to use AI, where to use AI, and how AI should be deployed in a human-centric way for the benefit of its customers.

“AI runs better on Apple, and Apple runs better on Jamf,” Tschida told me. The next piece to that statement is to consider how AI can be effectively managed by IT, she added. “You have to be able to see it. You have to be able to govern it, and then you want to be able to harness it.”

This points directly to shadow AI, one of the big-picture problems IT has with AI at the moment as employees feed confidential data to the cloud-based AI models. Jamf’s response has been to create new frameworks IT can use to monitor use of AI across their managed fleets. These tools let IT identify use, manage use, or even stop use altogether.

“How can we look at that, see it, govern it, and harness it in the ways that AI is providing that opportunity, right at the endpoint?” Tschida said. 

Precision modeling

The other component is pricing. Even when data is legitimately shared to AI, the cost of inferencing is high and getting higher. Jamf now offers tools to let IT monitor this use and the cost of it, enabling management to suggest lower cost or on-prem AI solutions for tasks where appropriate. After all, why would you pay for Fable when you can get your Apple device to help write that letter?

Tschida explained that part of Jamf’s response to AI costs is the inclusion of granular model controls, which let admins assign different teams access to different models, the idea being to prevent what she called “overmodeling” — the use of expensive high-reasoning models for tasks that lightweight models can handle.

“You have to understand what the need is. You must lay it out there in a governed way. Human in the loop and then you harness it,” she said.

The Mac advantage

But the Jamf vision doesn’t end with AI management; it extends to making active use of the tech. In this case the company has introduced AI-powered tech support for routine problems to free up staff time. There are two strands to this approach: More obviously, easy to access tech support should reduce time spent on routine problem solving, but another compelling aspect of this evolution is the move toward proactive device health.

Traditionally, IT has been reactive: a user experiences slowness, they eventually file a ticket, and IT fixes it. But many users simply “endure” suboptimal performance without ever reporting it, Tschida explained. “A lot of times, users don’t even raise a ticket. They just endure.”

That was then, but the future looks different. “We believe that we now have the right telemetry to look at device health,” Tschida said. “You’re really moving ahead of problems. Users don’t even raise a ticket… you can help them optimize it without them knowing it.”

With over 35 million devices now managed using Jamf, the origin story of the company seems further ahead of its time now than ever. Apple’s enterprise product marketing lead, Jeremy Butcher, appeared at one point during Tschida’s keynote to talk about where Apple now is in the enterprise. He pointed to data that Macs generate 55% fewer help tickets than Windows systems. He confirmed that the MacBook Neo has accelerated enterprise growth for the platform, and pointed out that more Apple devices are purchased in enterprise than any other brand.

With so much energy behind Apple’s platforms, what has Tschida been seeing?

“We know that Anthropic and other companies, they tend to deploy for Mac first. The developers are mostly running Macs. That’s what they prefer to be on, and they’re at the forefront of agentic AI.”

The thing about the growing enterprise Apple ecosystem is that no single company can build the perfect set of solutions for every enterprise. Part of Jamf’s response to this has been the creation of platform APIs, which customers and partners can use to extend the platform to meet their needs. “I love a good API because it allows you to run a road map way faster,” Tschida said.

Former Jamf CEO Dean Hager used to say, “When Apple innovates, Jamf celebrates.” 

His successor echoes his point, with a focus on what Jamf can do for its customers. “Our job is to make sure that Apple runs better with Jamf,” she said. “We’re scaling it, we’re securing it, and we’re making sure that you can… first see it, and govern it, and then harness what you can get from it in a way that’s helpful for our customers.”

Local intelligence, global scale

A second aspect to governance is around sovereign, private, and/or on-premises AI. I asked Tschida what her customers are saying. “There will be some that look at the benefit if you can run at least some of your workflows locally,” she said. “There’s a tokenomics piece of it. There’s a privacy piece of it. There’s a sovereignty piece of it.”

Whatever the motivation, for Jamf the question remains, “How can you determine what we can do and help you do, locally on device, and build that so you can run it at scale? That’s where we’re focused.”

I walked away from the interview feeling a vision for Apple in the enterprise in which IT is augmented by smart tech infrastructure: Macs that request support before users know they need it, systems that self-identify bottlenecks or wasted resources such as over-generous token consumption and let IT take steps. A more intelligent enterprise infrastructure, equipped with real-time awareness, self-reliant with little to no cloud exposure.

For Apple, Jamf, and certainly for the Mac, that seems like several giant steps since the foundation of Jamf in 2002. AI in IT is an accelerant, and Jamf is working with it. “We are doing our best to run at the speed of AI,” said Tschida. 

Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSky, LinkedIn, or Mastodon.

Kategorie: Hacking & Security

Hraní zdarma výměnou za reklamu? Microsoft si patentuje technologii, která vás nenaštve

Živě.cz - 24 Září, 2026 - 17:45
Reklamy ve hrách, zejména těch mobilních, už bohužel patří ke koloritu dnešní doby. Obtěžování reklamou může současně motivovat k zaplacení plné verze bez reklam, ale co kdyby ty reklamy byly nějak lépe vymyšlené, aby nepůsobily jen negativně? Microsoft si před pár dny podal patentovou přihlášku, ...
Kategorie: IT News

Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

The Hacker News - 24 Září, 2026 - 17:27
The "third-party[.]com" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users. "third-party[.]com has been a generic documentation placeholder for years, the same role example.com plays," Manifold Security's Head of Research, Ax Sharma, said. "Unlike 'example[.]com,' third-party[.]com Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Recenze hry The Alighieri Circle: Dante's Bloodline. Večerní procházka peklem. Nic víc, nic míň

Živě.cz - 24 Září, 2026 - 17:15
Blíží se říjen a s ním i tradiční hororová sezóna. Studio One O One Games se svým husí kůži nahánějícím příběhem přišlo o něco dřív. I když mělo skvělý nápad o pokračování pokrevní linie italského básníka, jeho provedení je přinejlepším průměrné.
Kategorie: IT News

Someone went shopping in ASUS's eShop – for customer data

The Register - Anti-Virus - 24 Září, 2026 - 17:13
Asus has warned eShop customers that an intruder got into part of its online store and may have helped themselves to contact details and order records. The PC maker disclosed the incident in an email sent to customers, first reported by KitGuru, in which it said had identified "unauthorized access to part of the Asus eShop environment," although exactly when that access occurred remains unclear. "Our investigation indicates that certain customer order information, including contact details and order records, may have been accessed," the company said. There is at least some good news for anyone who has handed Asus their card details. The company said no payment card, bank account, or other financial information was involved in the breach. Asus also said it isn't currently aware of the compromised information being misused or of any affected customers suffering harm. The company said it took steps to contain the incident after discovering the unauthorized access, launched an investigation, and introduced additional measures to secure the affected systems. That investigation remains ongoing, but Asus said it had found no evidence of continued unauthorized access. What Asus hasn't said is how many customers are caught up in the mess, when the intrusion began, how long the attacker had access, which countries are affected, or how whoever was behind the break-in managed to get into the eShop environment in the first place. The details that did escape, however, could give scammers a decent head start. Asus warned that the stolen details could give scammers enough to make phishing emails, texts, and phone calls about its products or customers' orders look rather more convincing. Asus told customers to keep an eye out for unexpected messages mentioning previous purchases, though it reckons the risk of anyone actually misusing the data remains low. This isn't the PC maker's first recent brush with data thieves. In December, Asus confirmed that one of its suppliers had been hacked after the Everest ransomware gang claimed to have pinched 1 TB of data from itself, ArcSoft, and Qualcomm. The company said the haul included some camera source code used in its phones, but maintained that its own systems and customer data were untouched. The Register asked Asus for more details about the latest breach, including how many customers were affected and when and how the intrusion occurred, but has not yet received a response. Asus is yet to comment publicly on the incident, and there is no mention of the breach on its eShop. So it's the usual post-breach drill: beware unexpected emails, texts, and calls. Except this time, whoever's behind them may have the receipts. ®
Kategorie: Viry a Červi

Gemini hacknulo tři skutečné firmy. Někdo mu při testu omylem otevřel dveře na internet

Živě.cz - 24 Září, 2026 - 16:45
Google potvrdil neobvyklý bezpečnostní incident z letošního května. Modely Gemini při testování svých hackerských schopností získaly přístup do systémů tří skutečných společností. Nikdo modelu nezadal, aby napadal firmy. Kvůli chybě v testovacím prostředí je považoval za součást cvičení. Jakmile ...
Kategorie: IT News

Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

The Hacker News - 24 Září, 2026 - 16:29
An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a previously undocumented information stealer called Psychedelic. "When a visitor interacts with the page, the lure copies a Windows Installer command to the clipboard and instructs the visitor to paste it into the Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

FedRAMP VDR & VER: Daily Scans Are Only the Beginning

Bleeping Computer - 24 Září, 2026 - 16:02
FedRAMP's new VDR and VER requirements make vulnerability management more continuous, with faster scanning, tighter remediation deadlines, and stronger evidence requirements. Anecdotes explains why the December 7 deadline is just the beginning of a broader shift toward continuous, automated compliance validation. [...]
Kategorie: Hacking & Security

Autonomní vůz Waymo vjel mezi stánky na farmářském trhu. Nikdo nevěděl, jak ho zastavit

Živě.cz - 24 Září, 2026 - 16:02
Autonomní vůz Waymo vjel v Denveru mezi stánky na farmářském trhu • Lidé si nevěděli rady, jak vlastně auto bez řidiče zastavit nebo přesměrovat • Město Denver nyní řeší komunikaci s bezpilotními vozidly v krizových situacích
Kategorie: IT News

Hackers now exploit critical Roundcube flaw in code injection attacks

Bleeping Computer - 24 Září, 2026 - 15:27
A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security. [...]
Kategorie: Hacking & Security

Five years later, you can finally buy Google Beam

Computerworld.com [Hacking News] - 24 Září, 2026 - 15:26

It’s been five years since Google first offered a glimpse of Project Starline, a three-dimensional videoconferencing platform billed at the time as as a “magic window” that enables realistic and immersive calls.

On Wednesday, Google announced that Google Beam — as the software element of the product is now called — is generally available for purchase, built into HP’s Dimension video meeting hardware. The Dimension hardware reportedly costs around $25,000 per unit; Google did not provide details for costs related to hardware or additional software licenses. The combined products will be sold in six countries at first: Canada, France, Germany, Japan, UK, and US.

Google has also partnered with co-working space provider Industrious to make Beam available to try at its locations across the US, including Atlanta, Chicago, New York City, and Palo Alto.

Beam “offers the potential for immersive, 3D engagement, without the challenge of wearables,” said Irwin Lazar, principal analyst at Metrigy.

“This is one of those ‘you have to try it’ experiences to understand the value proposition,” said Avi Greengart, president and founder of Techsponential. “It really does feel like you’re talking to someone a half a world away, with all your micro-expressions and nonverbal cues intact.

“This doesn’t just save you travel time and budget, it enables closer collaboration throughout a project or working relationship that provides different value than occasional live visits, which you may still need.”

Google began developing the Beam technology several years before it was unveiled amidst the COVID-19 pandemic and shift to remote working as offices were shuttered. It combines AI-generated 3D images of participants with spatial audio to create the sense of being in the same room.

The hardware has evolved considerably since then, with Google and HP shrinking the original large video booth into a smaller system that more closely resembles a conventional videoconferencing setup.

The 65-inch Dimension display renders meeting participants in their full size, and includes the cameras, 12-microphone array, and LED lighting required for the Beam software. Google Meet and Zoom video meeting apps are supported.

While Beam currently enables one-to-one meetings, Google recently highlighted its efforts to enable group calls, too. This is currently at an experimental stage.

Google claimed that an internal study showed 50% of Google staffers who used Beam felt more connected, resulting in a 21% drop in the need for follow-up meetings.

Select customers were granted early access last year, ahead of today’s full launch. One of them, management consulting firm Bain, uses Beam to interview job candidates remotely, reporting that it helps interviewers pick up on nuances of body language and eye contact without needing to meet in person. This also saved on travel costs, the company said in a promotional video.

It remains to be seen whether the technology will gain a wider audience. The price tag will “present somewhat of a barrier to adoption,” said Lazar. He expects early adopters will target specific use cases such as “executive meetings, hiring interviews, product demos, and high-stakes engagement.”

Greentgart described Beam as a “network-effect system,” as the technology is required on both ends of a Beam call. “That makes the expansion of Google Beam on HP Dimension to more locations crucial,” he said. “I expect that some companies will try it at a conference center before investing in endpoints inside their own companies.”

Kategorie: Hacking & Security

Microsoft adds pay-as-you-go pricing for extra OneDrive storage

Computerworld.com [Hacking News] - 24 Září, 2026 - 15:16

Microsoft has added a “pay-as-you-go” option for OneDrive storage, providing an additional way for Microsoft 365 commercial customers to buy extra cloud storage capacity for users.

Previously, increasing storage capacity for OneDrive users meant purchasing capacity “packs” for individual accounts, available in 100GB, 500GB, and 1TB through 6TB sizes.

With the new consumption-based billing, Microsoft 365 admins can select which users’ accounts are eligible for additional capacity, with any usage above the licensed storage quota then automatically billed.  

The new billing option is currently in public preview for Microsoft 365 business customers, ahead of general availability starting November.

Pay-as-you-go billing is turned off by default: Admins can set it up via the Microsoft 365 admin center, with options to set budget limits and alerts. The existing overall 25TB per-user limit for OneDrive remains in place.

Additional OneDrive storage costs $0.20/GB/month. Microsoft does not publish the pricing for the OneDrive capacity “packs.”

The OneDrive update follows a similar move with SharePoint, with a public preview of pay-as-you-go pricing for extra storage starting June, ahead of wider availability for GCC, GCC High, and DoD customers in November.

Microsoft will host a OneDrive + Copilot digital event on Oct 20 with updates on AI features coming to the cloud storage application.

Kategorie: Hacking & Security

UiPath’s new tool could unlock a much bigger wave of automated business processes

Computerworld.com [Hacking News] - 24 Září, 2026 - 15:10

A decade ago, UiPath built its business on watching people work, recording keystrokes and clicks to automate tasks employees already did by hand. This week, amid an industry consumed by autonomous agents, the company’s newest product suggests that same instinct still has a place.

UiPath used its Fusion conference in Las Vegas to launch Cartographer, a tool for building what the company calls a Map of Work: a living, governed record of the informal, undocumented knowledge that keeps enterprise processes running, the exceptions, workarounds, and judgment calls that never make it into an official workflow document.

Existing automation tools capture the click-by-click steps of a task. Cartographer works at the process level instead, documenting how work actually gets done versus how it’s designed to run. From the main stage, CEO Daniel Dines described this information as a missing manual enterprises need before trusting agents with real work. “A process map tells you how work is designed to run,” he said. “UiPath Cartographer is the key to uncovering the operational knowledge of how that work actually runs.”

Even with Cartographer, the first drafts of a Map of Work “will be incomplete for sure,” Dines admitted on stage.

That missing knowledge has kept enterprises’ most complex, exception-heavy processes out of automation’s reach, said Mark Geene, UiPath’s group senior vice president of agentic solutions. He characterized Cartographer as the next stage in a five-year push to extend the automation platform into messier enterprise areas. Capturing that knowledge, if it works, opens the door to automating processes once too undocumented and judgment-dependent to hand over to machines at all.

How well it will work is a different question. Analysts and customers on the ground described a tool that’s promising on paper, but whose real test comes later, in whether enterprises do the disciplined work of capturing and maintaining what Cartographer helps them uncover.

What’s different

That capture process has a real limit, said Amy Loomis, a research director at IDC, one that depends on whether people actually share what they know. “That step will only be as strong as the tribal knowledge of teams and the ability to capture it accurately,” she said.

Pairing deterministic guardrails with the inherently unpredictable behavior of large language models (LLMs) differentiates UiPath’s approach, Loomis said. She pointed to the spectrum of options UiPath will offer: prebuilt maps ready out of the box at one end, a curated Process Atlas in the middle, and Cartographer itself handling processes requiring full customization. A human “cartographer” role, an existing business analyst repositioned to own a Map of Work, is the other new piece, she said.

Getting a full picture of a process has been a persistent problem, one that often doesn’t surface until well after a bot is live, said Andrea Simpson, IT manager of automation at USI Insurance Services. “So much knowledge is in a person’s head, and it can be hard to get it out of our subject matter experts,” she said.

Knowledge management — a problem enterprises have been dealing with since the cold war — is the pain point UiPath aims to ease. But there are limits. Some knowledge will likely stay out of reach, Simpson said.

USI is an early adopter of Maestro, UiPath’s orchestration tool, to automate its marketing processes, tying together producer meetings, carrier submissions, and client communication. But the biggest hole is what happens off the record: a phone call, a conversation at someone’s desk. “We wouldn’t want that automated,” she said. “We want to keep that human.” That knowledge never touches a company system until a producer chooses to report it.

On-the-job training for agents

Perfection won’t be required to get started. “The goal isn’t to understand all the rules and processes from all the years you’ve been doing a process,” said UiPath’s Geene. “The goal is to capture enough information to get agents executing the process. The key is to get live early.”

Typically, once an LLM is built and deployed, “their brains freeze,” said Doug Marcey, CTO of Coronis Health, a healthcare revenue-cycle-management company that has used UiPath for about a year and a half. Cartographer’s promise, he said, is closer to on-the-job training for agents, gaining institutional knowledge the way a new hire gradually would, with each new exception routed through a “Decision Ledger” for a human owner to approve before feeding back into the map. That trail matters as much as the automation itself in a regulated industry. “The difficulty in healthcare is that compliance is all about vibes,” Marcey said. “The Decision Ledger would be very helpful for us.”

Coronis’s denial-management work shows what captured judgment can do. Agents draw on claims data, orchestration coordinates the workflow, and generative AI drafts appeal letters, a combination that’s made it financially viable to contest denials on smaller claims that previously would have been written off, Marcey said. Another UiPath healthcare customer was losing money on tens of millions of denied claims because generating an appeal could take 45 to 75 minutes, so it often wouldn’t happen despite a 50%-to-60% overturn rate on filed appeals, Geene said. With agents built on a Cartographer-style Map of Work, that process now takes four to five minutes.

The human factor

UiPath’s human cartographer role suggests the tool is meant to reshape jobs, not eliminate them. “This isn’t about replacing people,” said IDC’s Loomis.

At USI, much of a business analyst’s time today goes into repetitive work, translating what a stakeholder describes into documentation a developer can build from, work Simpson is eager to hand off. “It’s going to save so much time,” she said. “It’ll grow my team’s knowledge and improve the outcome of our processes.”

How it all shakes out will come down to people, as with any tech-driven transformation. “The hard problem is the change management at the organizational level,” said Marcey of Coronis Health.

And the accountability will remain with humans as well. “We can’t go to clients and say, ‘Hey, the bots screwed up,’” Marcey said.

This article first appeared on CIO.

Kategorie: Hacking & Security

Google to critical infra orgs: Our AI scanners won't be evil, promise

The Register - Anti-Virus - 24 Září, 2026 - 15:00
Google has jumped on the AI-defense-for-critical-systems train with its Scan for Good initiative, and says that its threat-hunting models have already autonomously uncovered critical security issues at hospitals, a municipality, a public rail operator, and major technology providers. So don't fear these bots. The initiative, announced on Thursday, uses Google’s Gemini 3.8 Flash Cyber, a version of the model tuned for software bug hunting and remediation, and Wiz’s Red Agent - this is the Google-owned cloud security shop’s pentesting AI agent. The AI systems will uncover public exposures and attack paths across public services, critical infrastructure, and nonprofits, and then hand these off for verification and remediation to human security researchers. “The program has been active over the past several months, and with this official launch, we are scaling it globally,” Gal Nagli, head of offensive security at Wiz, told The Register. “There is no set end date.” It's similar to OpenAI’s Daybreak for Frontline Defenders initiative, announced earlier this month. This program will distribute $1 billion in credits to subsidize access to OpenAI services and training for resource-strapped cyber defenders, including those protecting water and energy systems, community banks, local governments, nonprofits, and open-source projects. And like OpenAI’s new program, the Wiz and Google DeepMind partnership follows disclosures that Google’s AI agents also escaped their sandboxes and hacked other companies’ websites - as did agents developed by OpenAI, Anthropic, and Meta, and those are just the ones we know about. It also comes as existential dread about AI killing all of humanity reaches a fever pitch. AI for good (not evil) Scan for Good aims to put offensive security agents and Gemini 3.8 Flash Cyber to good, not evil, use. When authorized, either explicitly by organizations that apply for an assessment or under applicable bug bounty programs and vulnerability disclosure policies, the AIs will examine publicly facing websites, APIs, and applications for exposures, and then work with organizations to find and fix these. Every potential finding will be reviewed and validated by a human, and Wiz assures that “humans will remain responsible for confirming impact and making disclosure decisions.” When the bots and humans do identify a serious issue, the humans will contact the affected organization and work with them to remediate the security holes. Google’s AI systems have already helped critical organizations and tech providers find serious, internet-facing risks, including a critical GitHub Actions workflow vulnerability in one of Snowflake’s public repositories. In this bug-hunting expedition, conducted through Snowflake’s HackerOne vulnerability disclosure program, Wiz’s Red Agent autonomously identified a script injection vulnerability in snowflakedb/snowflake-connector-net. The flaw allowed an unauthenticated user to execute arbitrary commands within a GitHub Actions runner by opening a GitHub issue with a specially crafted title. Wiz disclosed the issue on June 23, and Snowflake fixed it on the same day, rotated the affected credential, and verified through detailed audit logs that Wiz was the only actor during the exposure window. Real-world examples The Google-owned biz provided several other examples of its AI for good, and said all of these were autonomously discovered by the models before Wiz validated them, but “only far enough to confirm real-world impact.” At that point, they privately notified the affected organization about the issue and helped it remediate the vulnerability. Some of these include: An exposed administrator key enabled read, write, and delete access to 8.8 million files in a “nationally significant archive” belonging to an unnamed Middle Eastern country. Assigning the correct set of permissions fixed the flaw. A public hospital with missing access controls exposed staff contact information and gave anyone online control of a hospital-wide mobile alert channel. A private hospital’s public appointment-booking site used an unsafe upload method that would have allowed attackers to take control of a hospital server and obtain patient identifiers, clinical information, and consent signatures. A municipality’s public data service exposed sensitive personal, health, and financial information belonging to about 5,000 elderly residents. Wiz confirmed the risk without collecting a bulk dataset. A public rail operator had a leaky production database that exposed active administrator sessions. This could have allowed criminals to take control of routes, schedules, service announcements, and administrator accounts - essentially disrupting the entire transportation system. Wiz helped the operator secure the system. The US Cybersecurity and Infrastructure Security Agency (CISA) also gave Scan for Good its stamp of approval, and Wiz told us the American cyber-defense agency provided guidance on the initiative. “At a time of evolving threats, defensive vulnerability discovery helps strengthen the nation’s digital infrastructure,” CISA acting director Nick Andersen said in a statement. ®
Kategorie: Viry a Červi

Porušil zlaté pravidlo vývojářů. Samsung poslal aktualizaci před svátky a zkazil Korejcům jídlo

Živě.cz - 24 Září, 2026 - 14:45
Samsung v Koreji vypustil špatnou aktualizaci SmartThings firmwaru pro prémiové chytré ledničky s dotykovým displejem, které tak přišly o svou nejdůležitější funkci – chlazení potravin uvnitř. Navíc těsně před důležitým třídenním korejským svátkem Chuseok, který je spojený s mnoha tradicemi včetně ...
Kategorie: IT News

Windows 11 KB5124010 update released with 46 changes and fixes

Bleeping Computer - 24 Září, 2026 - 14:16
Microsoft released the KB5124010 September 2026 non-security preview update for Windows 11 24H2 and 25H2, with 46 changes including Bluetooth improvements and the ability to remap the Copilot key. [...]
Kategorie: Hacking & Security

Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls

The Hacker News - 24 Září, 2026 - 14:05
The logistics sector has become the target of a new malicious cyber campaign that distributes an Android spyware codenamed Corp MDM. According to Have I Been Squatted, the campaign uses fake Google Play pages branded as CEVA and TKW Logistics to distribute an Android Package Kit (APK) file that's dressed up as a system service. The delivered app has the package name "com.corp.mdm" Corp MDM Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Apple Music Hall: V bývalé londýnské elektrárně vyrostlo koncertní studio budoucnosti

Živě.cz - 24 Září, 2026 - 13:45
Apple Music Hall v Londýně není jen místem pro koncerty. Vystoupení lze přímo v sále zaznamenat, smíchat v prostorovém zvuku, natočit několika kamerami a živě přenášet divákům po celém světě.
Kategorie: IT News

There's a new way to break RSA that's faster than anything we've seen before

Ars Technica - 24 Září, 2026 - 13:15

The world has known for decades that the RSA cryptosystem’s days are numbered. Once quantum computing becomes practical (estimates for that range from 3 to 20 or more years), the foundational security it provides will crumble. New research has revealed a novel method that uses classical computing to reduce the current RSA security level to an unacceptably low threshold.

The practical risk is limited, but still significant. Applying the attack against the deprecated use of 1024-bit keys took a handful of months on an academic CPU cluster, significantly less than the current estimates for 1024-bit factoring that would require resources that only nations or companies with massive resources could achieve. Widely used RSA implementations are also safe.

Nonetheless, the research has taken cryptographers by surprise because it introduces signature forgery, a new way to break RSA keys without factoring. Equally important, this novel method reduces the required computing resources by orders of magnitude.

Read full article

Comments

Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore

The Hacker News - 24 Září, 2026 - 13:00
AI coding agents are changing how quickly developers can build and ship software as well as how quickly credentials can become exposed. According to GitGuardian’s 2026 State of Secrets Sprawl Report, commits identified as AI-assisted are leaking secrets at approximately twice the rate of human-written ones. Most of the fastest-growing categories of leaked credentials are now connected to AI [email protected]
Kategorie: Hacking & Security
Syndikovat obsah