Agregátor RSS

Spuštění Intel 14A nebylo urychleno na první kvartál 2027, jde o starý údaj

CD-R server - 18 Září, 2026 - 00:00
Řada zdrojů v posledních dnech přišla se zprávou, že Intel urychlil spuštění rizikové výroby na procesu Intel 14A a ta začne již v prvním kvartálu příštího roku. Jde však o omyl, plány se nemění…
Kategorie: IT News

New RatHat Android malware uses AI to automate device control

Bleeping Computer - 17 Září, 2026 - 23:50
A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices. [...]
Kategorie: Hacking & Security

Německý kancléř chce deanonymizovat Internet

AbcLinuxu [zprávičky] - 17 Září, 2026 - 23:16
Německý kancléř Friedrich Merz (CDU) se během debaty s finalisty studentské vědecké soutěže Jugend forscht vyjádřil pro konec anonymity na internetu a vyslovil názor, že pro uživatele Internetu by měla platit podobná právní odpovědnost jako pro novináře tradičních médií. Na dotaz studenta, jak by se tedy povinnost uvádět pravé jméno slučovala s prací investigativních novinářů nebo ochranou jejich zdrojů, Merz neodpověděl, ve své reakci však prohlásil 'nechoďte na mě se svobodou slova' a že 'liberální demokracie musí být schopna chránit své občany před nepravdivými informacemi, osobními útoky a diskriminací'. Video z akce.
Kategorie: GNU/Linux & BSD

Linux Security Researcher Uses AI to Find Four Python Code-Execution Flaws

LinuxSecurity.com - 17 Září, 2026 - 23:15
Security researcher Sai Teja Erukude disclosed four alarming Python security flaws between June and August 2026 after combining specialized AI models with automated scanning and manual code review.
Kategorie: Hacking & Security

CISA Warns of Active Attacks on a Critical Cisco ISE Flaw

LinuxSecurity.com - 17 Září, 2026 - 23:00
Attackers are exploiting a critical Cisco ISE flaw that can open the product’s web management interface without a valid login. Cisco disclosed CVE-2026-76460 on September 16 and traced the problem to the way an ISE API handles authentication. A remote attacker does not need credentials or help from a user. A crafted request is enough to reach the vulnerable interface.
Kategorie: Hacking & Security

How a PowerPC Guest Could Trigger a KVM Use-After-Free

LinuxSecurity.com - 17 Září, 2026 - 22:45
A PowerPC KVM use-after-free could leave the Linux host kernel accessing a nested-guest object after another virtual CPU caused that object to be removed and freed. The upstream Linux correction adds a missing reference that keeps the object alive while KVM invalidates cached address translations.
Kategorie: Hacking & Security

Red Hat Quay Build Workflow Could Expose Registry Credentials

LinuxSecurity.com - 17 Září, 2026 - 22:00
As of September 17, Red Hat had documented a flaw in a Red Hat Quay build workflow that could expose container registry credentials to code retrieved from a mutable GitHub Action branch. Tracked as CVE-2026-85469, the issue created a software supply chain risk in the workflow used to publish Quay builder images.
Kategorie: Hacking & Security

Researchers find way to listen in on headphones from afar

The Register - Anti-Virus - 17 Září, 2026 - 21:36
Researchers based in China have devised a way to eavesdrop on signals handled by analog components in devices such as headphones, landline handsets, and smart devices by injecting electromagnetic (EM) signals. The technique, referred to as InjectEave, is not simply listening in on a low-frequency analog signal. It's an EM side-channel attack that overcomes one of the longstanding barriers to exploiting EM leakage: the faintness of RF signals in devices like headphones makes it difficult for adversarial listeners to separate signal from noise. Many different RF side-channel attacks have been explored, such as reading screen display emissions to reconstruct on-screen text or detecting the RF signals emitted by keys on a keyboard. But these techniques often prove impractical for passive EM capture because of the low signal-to-noise ratio. InjectEave trades passive signal capture for active signal manipulation. By transmitting a signal in the 0-9 MHz range – specifics have been withheld – an attacker can potentially modulate an otherwise difficult-to-detect audio signal so it can be captured by nearby equipment. "Our new project, InjectEave, shows that RF [radio frequency] signals can induce information leakage from everyday headphones, allowing an attacker to recover headphone audio from up to 30 meters away, including through walls," said Yan Long, assistant professor at The Hong Kong University of Science and Technology (HKUST) in Guangzhou, in an email to The Register. "We have verified the new vulnerability on multiple commercial devices including devices from Sony, HP, Philips, etc." Long and HKUST co-authors Haoran Yan, Ziyu Shao, and Shuhao Zhang, along with Qinhong Jiang of The Hong Kong Polytechnic University, describe their work in a paper [PDF] titled "Injected and Leaked: Actively Inducing Side-Channel Leakage Using Electromagnetic Injection and Hardware Nonlinearity," which was presented at USENIX Security 2026. The attack targets non-linear components found in computer systems, such as amplifiers, analog-to-digital converters, power converters, and switching MOSFETs. The interplay of the injected signals, the hardware, and the target audio signals essentially modulates the target signal so that it leaks and is detectable by the adversary. Conducting an InjectEave attack requires commodity RF equipment: a USRP B210 software-defined radio; antennas for injection and reception; a Siglent SSA3075X Plus spectrum analyzer; a laptop for controlling the SDR; and optionally an RF power amplifier to increase attack range. The researchers tested the technique with 11 off-the-shelf devices. One obvious application would be espionage, allowing an attacker to listen in on conversations carried over headphones or a landline phone. It could also be used to infer personal activities in households with smart fans or lamps through the monitoring and analysis of control signals and power consumption. Tested devices include: Sony ZX110AP (2014, wired headphones); Apple Earbuds (2016, wired earbuds); UGreen MAX2, Philips TAH2020, HP H231R (2024, 2025, 2023 wireless headphones); Flyingvoice P23GW (2023, VoIP landline); OIDIRE ODI-MF10A and Xiaomi BPLDS10DM (2023, 2025 smart fans); and JINGZAO JDO-06 and Xiaomi 1S (2024, 2019 smart lamps). "Our tests show that injection-induced side-channel attacks could eavesdrop on the majority of these devices from over 2m away and through walls, with a maximum distance of 30m for recovering intelligible headphone audio," the researchers state in their paper, noting that their tests indicate these scenarios are plausible in the wild. For the devices listed by the researchers, the maximum demonstrated attack range was generally between 1 and 6 meters, although they separately demonstrated headphone eavesdropping at up to 30 meters using an RF amplifier. Even so, the researchers documented various scenarios where eavesdropping could be done through hotel room walls and using attack hardware concealed in a nearby suitcase or within office furniture. The researchers note that non-linear components are common in computer systems and that any device with parts that handle signal stepping (e.g. power converters) may be vulnerable to InjectEave. "InjectEave is immune to digital defenses such as encryption, masking, and randomization, because the leakage comes from the analog path," the researchers conclude. "Hardware-aware mitigations such as twisted-pair wiring, shielding, and filtering can lower the energy that the injected carrier couples into the device, reducing the exposure. These mitigations raise the bar, but they do not guarantee immunity." ®
Kategorie: Viry a Červi

OpenAI details more cases of AI agents taking unauthorized actions

Bleeping Computer - 17 Září, 2026 - 20:55
OpenAI has presented new examples of what they call "AI model misalignment" from the past six months, including unauthorized file uploads, following self-generated instructions, hiding mistakes, and leveraging exposed API keys. [...]
Kategorie: Hacking & Security

LLMs respond differently to harmful prompts when AI watermarking is used

Ars Technica - 17 Září, 2026 - 20:33

In response to a new European Union law, AI platforms are implementing new schemes for watermarking the content they generate. Anthropic recently disclosed its future Claude models will use SynthID-Text, an approach Google created and released as open source. It uses a secret key that subtly changes the process a model uses for choosing the next word in a sentence. Whereas a top next word choice might be “cloudy,” the key might change it to “overcast.” Anyone who knows the key can determine if it was generated by the platform using it.

New research shows that SynthID-Text can change not just word selection but also the tools a model invokes and the chances it will adhere to or disregard safety guardrails it has been trained to follow. The threat can become greater in the face of an adversarial prompt, in which an attacker attempts to cause a model to carry out a harmful action, such as revealing a password or other sensitive information. Instructions that normally wouldn’t be followed will, in some cases, be performed once the watermarking is deployed. The finding underscores the need for developers to thoroughly test how their LLMs and agents behave when watermarking is in place.

Changing safety behavior

“As compared to the same models without watermarking, it is definitely going to change their behavior, especially when we place it under adversarial conditions, or we make these models call tools when they’re powering an agent,” Andrea Siposova, an AI security researcher at Lasso Security, told Ars. “Watermarking is made to not be perceptible to a reader, but we know that when we are changing anything about what the model is generating, it is going to cause some tradeoffs, it’s going to show up somewhere.”

Read full article

Comments

Pět důvodů, proč si nekupovat chytré hodinky. A dva důležité, proč ano

Živě.cz - 17 Září, 2026 - 20:15
Chytré hodinky jsou vhodným doplňkem k mobilu • Jenže mají i spoustu nevýhod, o kterých byste měli vědět • Na závěr přidáme dva důvody, proč má jejich koupě smysl
Kategorie: IT News

Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

The Hacker News - 17 Září, 2026 - 20:08
A critical vulnerability in Check Point's Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network. The Security Management Server is the system that controls firewall policy and administrator access. Check Point has released a fix through its LivePatch update channel and says it has no indication that the flaw Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

China's Salt Typhoon backdoors Latin American orgs with new snooping malware

The Register - Anti-Virus - 17 Září, 2026 - 20:00
China’s Salt Typhoon gang has developed a new backdoor and dropped it in networks belonging to high-profile organizations in several countries across Central and South America since at least August 2025, according to researchers. The PRC-backed espionage crew shifted its focus to Latin America a month prior, and from mid-2025 into 2026, the vast majority - 90 percent - of Salt Typhoon’s targets were located in that region, ESET, which tracks the group as FamousSparrow, said in a Thursday report. Salt Typhoon is the cyber-spy gang that hacked telecommunications and government agencies to gain stealthy, long-term access to victim organizations going back as far as 2019. These hacks, however, weren’t discovered until late 2023. In August 2025, ESET’s malware hunters found the group’s new backdoor, called SparroWocky, deployed against government agencies in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. While targeting entities in these countries “represents a rare occurrence among the China-aligned APT groups,” ESET believes the focus likely reflects China’s reaction to recent US President Donald Trump’s initiatives in the region, malware researchers Alexandre Côté Cyr and Romain Dumont said. “Donald Trump’s second presidential term has brought about an aggressive reaffirmation of US interests in Latin America, which threatens various long-term investments that China has cultivated throughout the continent in the last decade, in domains such as energy, mining, and telecommunications,” they wrote. “We suspect that FamousSparrow’s activities are intended to help China better monitor and anticipate the reaction of local governments to current US pressures.” SparroWocky is a modular C++ backdoor that appeared soon after the Beijing snoops started focusing on Latin America. The new backdoor integrates open source tools and uses techniques designed to evade antivirus and other security software. The name comes from Lewis Carroll’s Jabberwocky poem - the researchers found the first stanza in several collected samples. (’Twas brillig, and the slithy toves/Did gyre and gimble in the wabe:/All mimsy were the borogoves,/And the mome raths outgrabe.) ESET based its analysis on a malware sample compiled on November 17, and said it contained the following open source projects: Mbed TLS, a C library it uses to establish a secure communication channel with its command-and-control (C2) server. MinHook, a Windows API hooking library that hides the start address of newly created threads from security products. COFF Loader (or a similar project) to enable dynamic loading and execution of in-memory plugins in the form of COFF objects. Plus, the backdoor incorporates a variant of the SilentMoonwalk technique to spoof the call stacks originating from MinHook routines, and thus escape the watchful eyes of monitoring tools, along with a custom API-hashing algorithm to dynamically resolve Windows API functions. The gang deploys the backdoor in its usual way: a trident loader scheme consisting of a legitimate executable, a malicious DLL, and a file containing the encrypted malware. The loader resides in the malicious DLL and executes via DLL side-loading. After establishing communication with its C2 server, the backdoor starts receiving commands handled by a custom class named WinHandler (derived from a ServerHandler custom class), according to the runtime type information in the malware. The nearly 30 commands include scooping up system details and sending them to the C2, starting and/or terminating a new session and removing persistence, stealing and deleting files, taking periodic screenshots, collecting session IDs and usernames of enumerated remote sessions on the system via WTSEnumerateSessionsW, and spawning new SparrowWocky instances. It uses TLS encryption to communicate with its C2 servers, connecting directly to their IP addresses, generally on port 443, although ESET also spotted the malware using port 8080 in some cases. The malware researchers also published a full indicators-of-compromise list and samples in ESET’s GitHub repository, so give those a read, too. ®
Kategorie: Viry a Červi

30 nejlepších filmů a seriálů o sériových vrazích. Psychopati, kteří děsí i baví

Živě.cz - 17 Září, 2026 - 19:45
Mrazivé pohledy do mysli vrahů i těch, kteří je pronásledují. Seriály a filmy o sériových vrazích fascinují tím, jak balancují mezi hororem, detektivkou a psychologickým dramatem. Vybrali jsme tituly, které ukážou, že největší hrůza se často skrývá tam, kde ji nejméně čekáte.
Kategorie: IT News

ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories

The Hacker News - 17 Září, 2026 - 19:32
Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them. This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold like a monthly subscription. Some attacks use new tricks. Others just reuse what was already lying around. Both work often enough. So the threat landscape is not getting cleaner. It is just Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Brevo supply-chain attack injected ClickFix scripts on customer sites

Bleeping Computer - 17 Září, 2026 - 19:11
Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware. [...]
Kategorie: Hacking & Security

Balíčky z Číny zdraží od listopadu 2026. Češi si zřejmě připlatí 50 Kč za každou položku v objednávce

Živě.cz - 17 Září, 2026 - 18:45
Červencovým paušálním clem ve výši 3 eur za položku to nekončí. • Nejpozději od listopadu se bude hradit ještě manipulační poplatek. • Za každou položku odeslanou ze zemí mimo EU se prý zaplatí další 2 eura.
Kategorie: IT News

FUJITSU-MONAKA CPU a Fujitsu MONAKA Server

AbcLinuxu [zprávičky] - 17 Září, 2026 - 17:56
Společnost Fujitsu představila FUJITSU-MONAKA CPU a Fujitsu MONAKA Server. Navrženo, vyvinuto a vyrobeno v Japonsku. Pro suverénní AI infrastrukturu.
Kategorie: GNU/Linux & BSD

Googlebooky jsou za rohem. Google vyrazí proti Windows a macOS s upraveným Androidem

Živě.cz - 17 Září, 2026 - 17:45
Google oznámil, že již 21. září v 15:00 našeho času spustí předobjednávky Googlebooků. Firma s nimi chce vstoupit do třídy prémiových notebooků, které nabídnou vyšší výkon, lepší výbavu a nové softwarové funkce oproti dosavadním Chromebookům. Běží také na jiném operačním systému. Zatímco ...
Kategorie: IT News

Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

The Hacker News - 17 Září, 2026 - 17:37
Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a security announcement on September 15. The escape runs with the rights of the host account that runs the virtual machine. The flaw, CVE-2026-77179, is rated Critical, affects versions Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Syndikovat obsah