Agregátor RSS
Most administrators do not think about BIND, browser engines, or cloud kernels until one of them fails.
Linux packet metadata could keep pointing to network headers after the underlying packet had been rebuilt without them.
A Linux eBPF security flaw could cause the kernel to approve a program using an incorrect understanding of the values it would process.
Vyzkoušeli jsme nejnovější Apple iPhone 18 Pro a toto jsou naše první dojmy • Pocitově dospěl, zlepšil fotoaparát a Face ID • Změny dávají smysl, ale musíte je cíleně hledat
A security researcher has released working exploit code for four Linux kernel flaws that each let a local user gain root, the highest level of access on a machine.
Kernel maintainers have fixed all four over the past few weeks, so a system running an up-to-date kernel is not affected. But the exploit code is now public, and any machine still running an older kernel should be updated.
The flawsSwati Khandelwalhttp://www.blogger.com/profile/ [email protected]
LLM, neboli velké jazykové modely, jsou pro mnohé synonymum dnešního AI. Vy se zeptáte, AI chvíli přemýšlí a vypíše odpověď. Jsou natrénované pomocí zpětné vazby od lidských hodnotitelů, a proto komunikují jako lidé. Nově se prosazují agenti, kteří se místo vás mohou ptát jiných agentů, průběžně s ...
Microsoft fixed hundreds of security flaws in its September Patch Tuesday software updates — but it also introduced some annoying bugs. Now it has fixed some of them with a series of out-of-band updates.
Excel 2016 users were among the victims, as Patch Tuesday update caused certain paste operations to fail. A hotfix in update 5002665 partly fixes the problem, but if operations still fail then users will have to resort to using Excel’s “Paste special” command instead.
Users of Remote Desktop Services had found some instability in the application where RDP connections failed or where servers were left hanging at “Please wait for the Remote Desktop Configuration”. The issue was resolved with update KB5129194.
Another issue that users were facing after the update was a problem with some Credential Guard-protected machine accounts. Some users discovered that they had lost some security within Active Directory which meant that some devices were not recognized. The solution involves temporarily preventing Machine Identity Isolation enforcement before installing a fix. Microsoft said that it would be introducing a permanent solution in a future update.
Another issue raised by the September update affected applications that use HCS-managed virtual machines. In some cases, Plan9 users found that they were not able to access folders shared from the Windows host.
Applications that depended on these shared folders sometimes displayed an error indicating that no Plan9 drive shares were mounted. Microsoft said that Claude Cowork and the Windows Subsystem for Linux (WSL) were two of the applications affected, while Hyper-V virtual machines that did not have the Plan9 feature were not affected.
Microsoft also fixed an issue with USB Audio Class 1.0 devices. Some users found that no sound was coming from their audio devices after the Patch Tuesday update, and volume controls were unresponsive. Now restored sound, so affected users can once again make and take Teams calls.
In addition to these fixes from the September update, there was also an issue for some users where they were incorrectly informed that Microsoft Defender had been switched off. This has now been resolved.
Talk about your competitor getting through the door. Security researchers used Anthropic's Claude to help hack into OpenAI employees’ ChatGPT accounts. A trio of bug hunters researching frontier AI labs’ security weaknesses chained two vulnerabilities to take over multiple OpenAI employees’ ChatGPT accounts, then used that access to demonstrate they could reach an internal OpenAI repository by opening a harmless pull request. The entire timeline, from initial discovery to accessing OpenAI’s repo, took less than 72 hours and earned the researchers a $6,500 reward from OpenAI’s bug bounty program on Bugcrowd. “Until two months ago, any user or OpenAI employee logging into OpenAI’s own help forum (community.openai.com) could have had their ChatGPT and Codex accounts taken over,” Hacktron researchers Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini said in a writeup about their research. “Since people can connect various services to Codex and ChatGPT, the scope of what we could theoretically access was huge, including GitHub, Slack and emails.” And, in a poetic twist, they used rival AI giant Anthropic’s Claude models to develop the exploit. Claude has shown a propensity to hack organizations without human guidance, as have OpenAI's models. The team gained initial entry on July 25 via OpenAI’s community forum. The forum runs on Discourse, which typically uses FastImage to perform image checks. However, since FastImage didn’t support HEIF files in the affected setup, HEIF images uploaded to Discourse passed through ImageMagick, which used libheif to process them before converting them to another image format. “That exposed the underlying libheif parser directly to attacker-controlled files,” the researchers wrote. Using Claude Opus 4.8, the trio found a heap buffer overflow flaw in the libheif library and attempted to use that model to develop a remote code execution (RCE) attack, but this didn’t work on Discourse’s default configuration. But then, Anthropic released Claude Opus 5. The bug hunters used the newer model to generate an exploit script, and achieved RCE on OpenAI’s instance. The trio “immediately” reported the vulnerability to OpenAI. “We then took over an OpenAI employee’s account, whose Codex was connected to OpenAI’s Github organization,” they wrote. “To demonstrate impact without actually accessing any internal code, we sent a prompt to this employee’s Codex account to open a PR for us in OpenAI’s internal monorepo. Then we stopped any further testing.” Neither OpenAI nor Anthropic responded to The Register’s requests for comment. OpenAI fixed the flaw within about 14 hours of the report’s submission, marked the issue as resolved, and paid the Hacktron team a $6,500 bounty. “To clarify the scope of that award: testing against the Discourse-hosted community.openai.com was explicitly excluded from our bug bounty program,” OpenAI said in a comment shared by Hacktron. “The award recognizes the OpenAI-side finding, not the actions against Discourse.” Discourse also issued a fix that added image-processing sandboxing, and published a security advisory GHSA-vhm9-85gw-x335 with patching and rebuild guidance. The entire hack took a few days for an AI agent and a few hours of human work. “Work that once required a well-resourced team and months of effort can now be compressed into days,” the researchers said. “Security assumptions must catch up with attacker capabilities.” ®
Fugleramme, v překladu 'ptačí rámeček', je open-source projekt postavený na Raspberry Pi, který pomocí lokální umělé inteligence BirdNET-Go rozpoznává ptačí druhy podle jejich zpěvu a na displeji následně zobrazuje koláž tvořenou odpovídajícími ilustracemi. Databáze obsahuje přes 800 ručně vybraných historických přírodovědných ilustrací více než 400 druhů ptáků.
Projekt je navržen pro Raspberry Pi s mikrofonem a e-ink displejem, lze ho však snadno přizpůsobit (Raspberry Pi je například možné použít jen pro připojení panelu a samotný software může běžet třeba na NASu, domácím serveru nebo starém notebooku. E-ink displej není nutný, koláž si lze zobrazit také prostřednictvím webového rozhraní). Zdrojový kód projektu je dostupný na GitHubu pod licencí MIT.
WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without anyone clicking Install.
The security firm pwn.ai, whose researchers reported the flaw, calls the attack chain Click2Shell. On its own the flaw only Swati Khandelwalhttp://www.blogger.com/profile/ [email protected]
North Korea's employment scams work both ways. As well as placing fraudulent IT workers inside Western companies, regime-backed cybercriminals have posed as recruiters to infect more than 30,000 devices and steal over $10 million, according to an international advisory. Law enforcement and cybersecurity agencies from Australia, Germany, Japan, and the US issued an update on the campaign on Thursday. They said the attackers had compromised more than 7,000 cryptocurrency wallets and stolen funds that ultimately supported the North Korean regime. The agencies track the activity collectively as WaterPlum. Its operators target web designers, engineers, and cryptocurrency and Web3 specialists with bogus recruitment approaches. During the supposed interview process, victims are instructed to download files presented as coding assignments or other recruitment tests. Opening them backdoors the applicants' computers and installs malware. Once inside, the attackers deploy remote access trojans (RATs) and information stealers, giving them persistent access to credentials and other sensitive data long after the fake interview ends. In some cases, the compromised machines may later provide a route into corporate systems when the jobseekers secure legitimate employment. WaterPlum operators use that access to steal intellectual property, credentials, clipboard contents, keystrokes, cryptocurrency wallet data, and identity documents that can support further impersonation. "Stolen IDs can be used by North Korean IT workers to impersonate victims and generate foreign currency," the advisory [PDF] said. "Stolen credentials may be leveraged to exfiltrate crypto assets, personal data, trade secrets, etc., from victims' employers, clients, or contracting parties. The actors can also use stolen sensitive information for extortion." The agencies attributed at least $10.71 million in thefts to these tactics, with the proceeds funneled to Pyongyang. The recruiter campaign complements North Korea's better-known tactic of placing its own IT workers in technology roles at Western and allied companies. The scheme has been extensively documented and has generated revenue for North Korea for years. Researchers estimate that roughly 100,000 North Korean IT workers are employed or seeking work worldwide. Some are supported by accomplices operating laptop farms, which make remote workers appear to be based in the country where they were hired. The workers collect salaries from companies in countries that impose heavy sanctions on North Korea, with much of the money surrendered to the state. The sprawling IT worker fraud is thought to net Kim Jong Un's regime upwards of $500 million a year. The scale of the operation means some applicants inevitably succeed, although employers are becoming more familiar with signs of fraudulent North Korean candidates. Applicants often submit impressive resumes claiming prestigious educational backgrounds, extensive work experience, and language skills that may not withstand scrutiny during an interview. Other warning signs include repeated refusals to meet in person, suspicious interruptions to video feeds, voices in the background, and requests for payment in cryptocurrency. Fraudulent workers may also use AI face-swapping software, which can produce visual artifacts during video calls and prompt them to disable their cameras shortly after an interview or meeting begins. The agencies recommend that any organization suspecting it has engaged a fraudulent North Korean IT worker launch a full forensic investigation and assume that credentials and other sensitive data have been compromised. ®
I do pětistovky koupíte dobré periferie k počítači. • S Logitechem soupeří i privátní značka od Alzy. • Víte, že existují opravdu tiché myši?
Scammers impersonating law enforcement or government officials have cost victims more than $1.6 billion since January 2025, the FBI reports. The FBI’s Internet Crime Complaint Center (IC3) received close to 61,000 complaints of this type between January 2025 and July 2026, putting the average per-complaint loss at more than $26,000. The most common type of scam is one involving criminals convincing targets to pay a sum of money to remove charges the fraudsters claim were filed against them. Typically contacting targets via unsolicited phone calls, the scammers usually claim that the target has committed or is connected to a crime, and threaten consequences such as arrest and prison time if a payment is not made. Accounting for roughly 11 percent of the complaints is a different type of scam, which involves alleging victims did not fulfill their assigned jury duty or missed a court date, then threatening them with a fine or arrest unless they pay. Of these 6,833 complaints, scammers caused losses amounting to nearly $36 million. A more profitable variant involves a more targeted approach. Scammers will complete some due diligence on a target, such as ascertaining their profession, and tailor the scam to their job. The IC3 has seen cases in which scammers contact medical practitioners, for example, claiming their medical license is expiring or that it was used in the commission of a crime. Payment is then demanded either under the guise of renewing the license or as part of an extortion attempt to "protect their professional reputation." Victims reported 3,322 instances of this kind of targeted scam, with total losses exceeding $37 million. A far less common tactic, deployed in 496 of the total complaints, saw scammers claim that documents such as driver's licenses or passports had expired and demand payment to renew them. Despite accounting for a minority of cases, criminals still netted $348,000 using this method. Finally, and arguably the most elaborate tactic the IC3 outlined, was the targeting of Americans from different ethnic communities, foreign nationals, and international students in the US. The nature of the targeting was not the aspect the criminals invested the most effort in. The general procedure was also similar to the other examples: Scammers impersonate foreign law enforcement or US-based foreign diplomatic officials, threatening to cancel the victim’s home-country passport or have them extradited. However, these scams sometimes involve video calls. The criminals are known to don a country’s law enforcement uniform, or in some cases even take the calls in movie-style sets they create to mimic real government facilities. The IC3 said that it received 1,809 complaints of this kind of targeted scam during the 19-month reporting period, with total losses exceeding $140 million. It means nearly 10 percent of the overall losses stemmed from one scam that accounted for less than 3 percent of the total complaints. Law enforcement impersonation scams are common across the world, although they may take different shapes from country to country. In the Netherlands, for example, police received more than 7,200 reports of fake police officer scams in the first half of 2026 alone, although the criminals behind them don’t hide behind a phone or keyboard. Scams in the Netherlands see fraudsters approach victims at their homes, usually targeting the elderly population, offering to safeguard their valuables while posing as a trusted authority. In reality, the criminals simply steal the jewelry, money, bank cards, and other valuables they are entrusted to protect. Cases like these have surged across the country in recent years, and aspiring crooks as young as 14 have tried to cash in on the trend. Police have invested more in public awareness campaigns as a result. The FBI reminded the public that neither it nor any other law enforcement agency will call an individual and demand payment or request personal or sensitive information. Citizens should remember to ask for credentials and make attempts to independently verify the identity of the caller, such as calling the relevant office using publicly available details and asking for the caller by name. The IC3 recently reported its most damaging year for internet scams. It released 2025’s data in April, covering all types of cybercrime, pegging total losses at $20.87 billion – the first time it has reported annual losses exceeding the $20 billion threshold. ®
The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records. [...]
Apple přistoupil na výrazně vyšší ceny paměťových čipů od Samsungu • Výrobci čipů upřednostňují paměti pro serverová datová centra a umělou inteligenci • Zdražení komponent nevyhnutelně zasáhne trh s iPhony i konkurenčními Androidy
The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan.
The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity has been codenamed Operation Ravie Lakshmananhttp://www.blogger.com/profile/ [email protected]
An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel. [...]
Microsoft 365 users are being tricked into handing over access to their accounts by a new phishing kit, GhostCode, that exploits a weakness in a legitimate device authorization flow. Researchers in eSentire’s threat response unit identified the campaign in late August 2026.
The kit abuses Microsoft’s OAuth 2.0 device authorization grant flow, a legitimate mechanism designed to enable authentication from IoT devices, smart TVs, printers, or other devices that cannot easily support a conventional browser-based login. The technique, known as device-code phishing, has been seen in other attacks before. As part of the flow, the device displays a code for the user to enters in a browser on another device to complete authentication.
GhostCode poses as one such device, gets Microsoft’s OAuth to generate a device code and then convinces the victim to enter it on Microsoft’s authentication page. The victim then signs in and completes multifactor authentication as normal — but the authentication is for the attacker-controlled device, allowing them to obtain the resulting authentication tokens. These tokens are then used to register attacker-controlled devices, obtain additional credentials and establish persistence in the victim’s Microsoft environment.
In the campaign observed by eSentire, the attack involved a social-engineering setup where attackers pose as procurement officers through a web contact form before moving conversations to an NDA-themed HTML file. Opening the file took the victim to the device-code phishing page.
Stolen tokens allow persistence
GhostCode’s post-authentication activity is focused on turning the stolen access into persistence inside the Microsoft environment. Once access was granted, eSentire recorded nine successful API calls over a 78-second period, involving Microsoft Intune Enrollment, the Device Registration Service, Azure Active Directory and Microsoft Graph.
Three devices were registered during that time, at 28, 53 and 77 seconds after authentication, a sequence eSentire said was automated.
The third device was also successfully enrolled into Intune, Microsoft’s cloud-based device management service. eSentire noted that Intune enrollment survived token revocation: The attacker-created device remained in the tenant until it iwas explicitly removed.
The attackers also obtained a Primary Refresh Token (PRT), which eSentire called “one of the most powerful” credentials in a Microsoft identity environment.
“Obtaining a PRT via device code abuse gives the threat actors essentially SSO-equivalent access to the victim’s entire M365 environment for the PRT’s lifetime — including any service not explicitly protected by a Conditional Access policy requiring a compliant device,” eSentire said, adding that the token persists 14 days by default.
The attackers also employed multiple evasion techniques, including padding and obfuscating the HTML code in their lure, encrypting redirects, checking for bots, and using Cloudflare Turnstile to keep security tools away from the phishing page.
What defenders can do
To defend against attacks like this, eSentire’s researchers recommend restricting Microsoft’s device-code authentication flow through Conditional Access and disabling it for users who do not need it. It also advises monitoring the Device Registration Service for multiple device registrations from a single non-interactive session, and looking for activity involving the user agent python-requests following device-code authentication.
Auditing Entra ID for devices matching GhostCode’s naming pattern and correlating successful device-code authentication with subsequent Python-based requests, should be able to catch an attack in progress, the company said. It shared a list of indicators of comprise related to the campaign to aid detection.
GhostCode adds to a growing number of attacks abusing device-code phishing to target Microsoft’s OAuth authentication flow. Recent examples include attacks using the “EvilTokens” phishing-as-a-service (PhaaS) kit, a campaign reported by KnowBe4 in February 2026, and activity observed in December 2026 involving multiple clusters, including both financially motivated and state-sponsored actors.
John Ternus’ Apple threw a curveball at OpenAI with Siri Recap on Apple Watch, accelerating a conversation about privacy and data protection in an AI-augmented digital era. It’s a move that may yet contribute to finding a balance between scary surveillance and digital convenience.
Think of it this way: Apple operates on such a big scale that it must have expected the feature to face regulatory and legal investigation. We know Apple has tried to stay on the right side of existing data protection and privacy laws by ensuring that its system doesn’t keep personal data, audio recordings, or transcripts, but one thing it doesn’t do is achieve consent from everyone who may be exposed to the feature. That’s a big no-no in some places, and it’s logical to think Apple expects some pushback to that.
Apple thought it through
From where I sit, it looks like Apple has thought about this. You only need to look to Apple Worldwide Marketing VP Greg Joswiak’s recent comments on the matter to see this, as he very swiftly tried to position Recap as little more than the digital equivalent of notebook and pen, or a smartphone set to record. The difference is that using the latter still technically requires consent in some places, while using a pen and paper does not.
But if Apple has thought about it and anticipates oversight, then there are benefits to be had. Apple is not the only company seeking to use ambient data monitoring and AI tech to create new product families. Meta, OpenAI, and others also seem to be exploring ambient monitoring with AI, possibly with less of a commitment to privacy.
While it’s true as a general rule that your rights in a public place are weaker, they are not nonexistent, and both Apple and OpenAI must expect to face regulatory pushback on what they make.
This could be why Apple has accelerated regulatory conversation concerning such tools by introducing Siri Recap. The argument is that by forcing legislatures to make decisions on such matters, Apple is effectively throwing a punch at competitors who must also work within the law. (Though with data encryption such a huge piece of the privacy jigsaw, it’s fair to say that some nations may yet mess things up.)
Because it isn’t just about Apple
It makes sense for international lawmakers to create a harmonized framework of legislation to govern such products, particularly as they clamber headlong into so many different layers of protected personal existence. Apple’s decision to create this product at this time means regulators will now have to decide where to draw the line.
We can surmise where Apple thinks that line will be on the basis of what Joswiak said and the actions the company has taken with a variety of guardrails to maintain privacy and data security. The idea it seems to be moving toward is that by stripping out the stuff we want kept private, it has effectively built the digital equivalent of writing a few notes in your book with a pen while a conversation takes place.
If Apple’s argument prevails, then those will become the regulatory-approved principles to define what other companies must do with their devices in this space. Including Meta and OpenAI.
Caught in a trap
That’s going to be fine for some entities, but companies that want to build businesses on your data will be disadvantaged by those decisions. Apple’s approach is that by defining the space, it also knows precisely what it must do to compete within it. That’s going to make for a far more equal playing field as AI hardware reaches the market.
A second outcome Apple may also be looking at is that by challenging regulators to sit down and declare what data and privacy rights consumers should enjoy in an AI digital age, it also identifies terms of reference to inform how its future AR glasses handle and process external video. Right now, it’s plausible to imagine a similar arrangement in which actual video is never stored, just classified and summarized like audio in Siri Recap.
And, of course, one final potential outcome might be that if Apple manages to convince the EU that its system provides an appropriate balance between consumer privacy and security and third-party product design, then it may forge a path through the impasse that currently stops Apple Intelligence from working in the EU. This could be a blueprint of the intermediary architecture Apple originally proposed to the EU when it first introduced Apple Intelligence. We’ll have to see if Europe accepts that.
Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSky, LinkedIn, or Mastodon.
Unicode Consortium, nezisková organizace koordinující rozvoj standardu Unicode, oznámila vydání Unicode 18.0. Přidáno bylo
13 007 nových znaků. Celkově jich je 172 808. Přibylo 9 nových Emoji.
|