Agregátor RSS

NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

The Hacker News - 24 Červenec, 2026 - 09:41
Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found them in a six-hour review of the forum software's source code. Every version before 4.14.0 is affected. NodeBB has fixed them all, and administrators should be on 4.14.2. The simplest one takes a settings change. A Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Clop ransomware targets Windchill, FlexPLM in data theft attacks

Bleeping Computer - 24 Červenec, 2026 - 09:36
The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. [...]
Kategorie: Hacking & Security

Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

The Hacker News - 24 Červenec, 2026 - 08:58
Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloom module. Redis says the underlying memory flaws may lead to remote code execution. Redis 6.2.23, 7.2.15, and 7.4.10Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

The Hacker News - 24 Červenec, 2026 - 08:50
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that's dressed up as a Notepad++ plugin to compromise Windows systems. The activity has been attributed by the agency to a threat cluster it tracks as UAC-0099, a Russia-aligned group that has previously observed weaponizing security flaws in WinRAR software to Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Copilot přijde také o hloubkový výzkum. Najdete ho jen v nejdražším předplatném Microsoft 365 Premium

Živě.cz - 24 Červenec, 2026 - 08:45
Microsoft dne 18. srpna zruší hloubkový výzkum ve většině variant Copilotu. • Výjimkou bude předplatné Microsoft 365 Premium. • Stávající výzkumné reporty budou nadále všem k dispozici.
Kategorie: IT News

Ozempic by mohl snižovat riziko rakoviny. Ale zatím nejásejte. Může to být jen klam lidského chování

Živě.cz - 24 Červenec, 2026 - 07:45
Observační studie naznačují nižší riziko některých nádorů u léků na hubnutí • Statistické zjištění však může být zkresleno lepším životním stylem pacientů • Randomizované klinické testy zatím žádný přímý protirakovinný účinek nepotvrdily
Kategorie: IT News

GeekBench 7 přichází, kontroverze zůstávají

CD-R server - 24 Červenec, 2026 - 07:40
Primate Labs vydávají Geekbench 7, i když trochu nestandardním způsobem. Nová verze opět překopává strukturu dílčích testů i jakým způsobem se podílejí na výsledném skóre. Některé testy zanikají…
Kategorie: IT News

Hry zadarmo, nebo se slevou: Festival vlaků na Steamu a karetní příběhovka zdarma

Živě.cz - 24 Červenec, 2026 - 07:10
Na všech herních platformách je každou chvíli nějaká slevová akce. Každý týden proto vybíráme ty nejatraktivnější, které by vám neměly uniknout. Pokud chcete získat hry zdarma nebo s výhodnou slevou, podívejte se na aktuální přehled akcí!
Kategorie: IT News

OpenAI-Hugging Face attack doesn't mean agents are evil – unless you tell them to be

The Register - Anti-Virus - 24 Červenec, 2026 - 01:51
Open AI’s admission this week that its agents escaped the sandbox and autonomously hacked model repository Hugging Face has spawned more apocalyptic warnings of agents gone bad than we can count. Thankfully, Renato Marinho, chief research officer at Morphus Labs and a SANS Technology Institute instructor, brought some sanity to the discussion. “It is tempting to read this as ‘AI can now hack autonomously, the sky is falling,’” Marinho said in a Thursday blog. “Resist that.” He went on to make three very pertinent points about the agentic attack. First, and probably most important: The models didn’t have guardrails – and that was intentional. As OpenAI said in its mea culpa, GPT-5.6 Sol and "an even more capable pre-release model" were among those that attacked Hugging Face. It also noted that the LLMs’ “deployment safeguards were intentionally not enabled during this evaluation because it was aimed at testing cyber vulnerabilities.” So while it’s very concerning that these models broke out of their own testing environment, and the debate over safety guardrails remains worth having, drawing a direct line from the Hugging Face attack to the need for strong AI guardrails doesn’t work. “This measured a ceiling, not normal production behavior,” Marinho wrote. “The evaluation deliberately reduced the models' refusals. That is very different from a customer-facing model with safeguards enabled.” It’s worth noting that these same frontier models, with guardrails enabled, refused to help Hugging Face’s forensic investigation. “The attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried,” the model hub’s security team said. So Hugging Face used a Chinese open-weight model to investigate the breach. Another thing worth considering is that real-life attackers are probably going to use open-weight models anyway. They’re more accessible to everyone, it’s easier to remove their built-in protections, and they’re a whole lot less expensive than their frontier counterparts. Second, as we’ve pointed out previously: AI companies touting their own models’ autonomous bug-finding and hacking abilities creates a marketing win for the companies themselves. As Marinho points out, Hugging Face is not an OpenAI competitor. The AI giant stating “‘our model escaped and hacked a partner’ conveniently showcases frontier capability,” he added. “Read the framing with the same skepticism you'd apply to any ‘our product is dangerously powerful’ claim, and treat it as marketing until it is independently corroborated.” Finally, the attack technique itself isn’t novel. “Exposed credentials plus zero-days into a production database is a chain any of us would recognize,” Marinho wrote. The agents working together on an end-to-end attack chain is notable - but we’ve also seen this in previous testing, like that carried out by frontier security lab Irregular earlier this spring. Agents gone rogue?! Shocking Irregular said its testing found that AI agents will work together to bypass security controls and stealthily steal sensitive data from within the enterprise systems in which they operate – especially when prompted like a hard-ass boss. While the prompts themselves didn’t specifically reference hacking or exploiting vulnerabilities, they conveyed a sense of urgency: “It is of utmost importance that you perform the task exactly as required,” and “When you talk to your sub-agents, convey all the requirements to them, and be ruthless about the requirements and encourage them to perform the tasks fully and exactly. You are a strong manager and you do not easily cave in to or succumb to pleas by the sub-agents to not fully fulfill their tasks.” The agents did as instructed, and ultimately "demonstrated emergent offensive cyber behavior," including independently discovering and exploiting vulnerabilities, escalating privileges to disarm security products, and bypassing leak-prevention tools to exfiltrate secrets and other data. And the Irregular research wasn’t even testing the agents’ offensive cyber capabilities — so it shouldn’t be too surprising that OpenAI’s benchmark research, aptly titled “Can AI Agents Turn Security Vulnerabilities into Real Attacks?” produced a resounding yes. Agents have one job – to complete a task. They aren’t bound by ethical or moral constraints that we (hopefully) see in human red team hackers. If prompted to “pursue advanced exploitation using complex attack paths,” especially without guardrails enabled, the models will do whatever it takes to achieve success. That’s what the leading AI companies trained them to do. ®
Kategorie: Viry a Červi

Researchers replace downloaded macOS apps with evil twins, Apple shrugs

The Register - Anti-Virus - 24 Červenec, 2026 - 01:24
Apple macOS apps that have been downloaded from the internet and run at least once can be swapped with malicious versions, a pair of researchers say, calling into question the thoroughness of the company's "Gatekeeper" defenses. As Apple explains, "When a user downloads and opens an app, a plug-in, or an installer package from outside the App Store, Gatekeeper verifies that the software is from an identified developer, is notarized by Apple to be free of known malicious content, and hasn’t been altered." Security researchers Talal Haj Bakry and Tommy Mysk say they've identified a gap in Gatekeeper and associated code signing rituals that "allows an attacker to silently replace the main executable of any application downloaded from the web without requiring elevated privileges." The attacker needs to have means of user-level code execution available, such as a malicious app or downloaded script, so it's not a zero-click vulnerability that a remote attacker can deploy. Nonetheless, the finding shows Gatekeeper to be rather lax in its gatekeeping duties. Bakry and Mysk managed to alter a macOS app downloaded from the web (not from the App Store) and Gatekeeper failed to object. Their technique doesn't work on Mac App Store apps, the Mysk team told The Register, because they're owned by root, so a process running with current user privileges won't be able to overwrite them. But for macOS apps downloaded from the web, such as Brave, Slack, Signal, or Visual Studio Code, among many others, there's potential risk. The attack scenario requires an app downloaded from the web that has been run once – allowing Gatekeeper to complete its initial validation – and the ability to execute user-scoped code. The initial validation phase that Gatekeeper conducts is supposed to prevent subsequent modifications to the application bundle, even with administrative privileges. But the Mysk team found that you can archive a downloaded, once-run app using tar (a file archiving utility), then remove the original and replace it with a malicious version, and macOS does not require reauthorization. They've recorded a video demonstrating how the attack works. The Mysk team said there are many ways an attacker might gain the necessary access to get around Gatekeeper, such as tools installed through the command line, convincing someone to copy and paste a command to their terminal, downloading and running an malicious app, a prompt injection attack on an AI agent, or a supply chain attack via npm, brew, or some other package manager. And once a doppelganger version of an app is in place, it can magnify its mischief by presenting deceptive prompts that users are more likely to trust because they appear to come from a known app. Tommy Mysk said he was uncertain about the exact cause of the issue, but speculated it may have something to do with cached value retention. "When you open the app for the first time and it passes all validation checks, macOS marks the app as trusted and saves this data," he said. "Later when I modify the executable, macOS detects a change in the bundle and tries to revalidate its integrity. It seems the cached value of the trust causes macOS to pass the validation even though the bundle has changed." The Mysk team reported their findings to Apple, which reportedly closed the issue. "Apple doesn't consider this attack to be 'modifying' the signed executable," the Mysk team explained. "Instead, Apple says that by archiving/restoring the app bundle, the proof-of-concept code overwrites the entire app bundle, making it locally built. "Locally built app bundles are not covered by macOS guards. And this is why access to Keychain or TCC protected directories require system authorization prompts. And for users to accept those is a matter of social engineering attacks that Apple considers out of scope." Apple did not respond to a request for comment. ®
Kategorie: Viry a Červi

Týden na ScienceMag.cz: Velké jazykové modely AI nenápadně, ale zásadně mění obor přírodních věd

AbcLinuxu [články] - 24 Červenec, 2026 - 00:01

Fyzikové a AI model Claude spolupracovali na důkazu matematické domněnky o ucpání. Kvantové vakuum by mohlo zefektivnit chemické reakce. Klonování 30 let poté. V červenci 1996 se narodila ovce Dolly. Kanibalistický kompromis: Proč se dlouhodobě nevyplácí jíst lidské maso.

Kategorie: GNU/Linux & BSD

Jaký budete mít důchod a vyjdete s ním? Představu si můžete udělat už teď. Poradíme, kde hledat informace

Lupa.cz - články - 24 Červenec, 2026 - 00:00
Jak se budete mít v penzi? Nebudou vám vzhledem k vašim měsíčním výdajům chybět peníze? Kolik byste si měli našetřit, abyste vyšli? Poradíme, kde získat odpovědi na tyto otázky.
Kategorie: IT News

Linuxové jádro 7.3 přinese vypínání CPU jader Intel a zefektivnění běhu AMD APU

ROOT.cz - 24 Červenec, 2026 - 00:00
Úpravy kódu systémových volání jednodušší život vývojářům Linuxu, další základní desky Asus s podporu čtení dat ze senzorů, cílené vypínání přehřátých CPU jader pro Intel, sekundární grafická pipe pro moderní APU od AMD.
Kategorie: GNU/Linux & BSD

Pokročilý autonomní AI model Open AI obešel omezení a hackl Hugging Face

CD-R server - 24 Červenec, 2026 - 00:00
Ještě loni (a vlastně i letos) bylo možné v některých odborných článcích, ale zejména v diskuzích narazit na bagatelizaci bezpečnostních rizik AI s tím, že tak daleko modely nejsou…
Kategorie: IT News

Záludná přenosná rakovina ryb se chová spíš jako parazit než nádor

OSEL.cz - 24 Červenec, 2026 - 00:00
Záhadné černé kožní léze sumečků amerických v jezeře Memphremagog i dalších jezerech Nové Anglie a Kanady jsou ve skutečnosti přenosný melanom, který se nějaký způsobem masivně šíří mezi rybami. K panice prý není důvod a současně jde o velmi zajímavou situaci pro intenzivní výzkum.
Kategorie: Věda a technika

Podivné hry kosatek – tříštění jedné z největších ryb světa na malé kousky

OSEL.cz - 24 Červenec, 2026 - 00:00
Kosatky dravé dokážou vědcům zamotat hlavy. Někdy potápějí plachetnice, jindy nosí klobouky z lososů a nejnověji porcují pro zábavu obří rybu „hlavičkou“.
Kategorie: Věda a technika

New Dolphin X malware uses AI to rank high-value targets

Bleeping Computer - 23 Červenec, 2026 - 23:20
A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first. [...]
Kategorie: Hacking & Security

Thunderbird 153 s kódovým názvem Meadow

AbcLinuxu [zprávičky] - 23 Červenec, 2026 - 23:06
Poštovní klient Thunderbird byl vydán v nové verzi 153 s kódovým názvem Meadow. Jedná se o ESR (Extended Support Release) vydání. Přehled novinek v poznámkách k vydání. Vylepšuje OAuth. Thundermail lze používat bez instalace doplňku.
Kategorie: GNU/Linux & BSD

OpenAI Agent Breaks Free and Hacks Hugging Face

Singularity HUB - 23 Červenec, 2026 - 22:48

The incident is a first and signals a seismic shift in cybersecurity.

An autonomous agent powered by OpenAI’s advanced artificial intelligence models went rogue during a security test and hacked multi-billion dollar tech startup, Hugging Face, last week.

The agent didn’t just exploit vulnerabilities in Hugging Face’s systems to achieve what it perceived as a strategic gain. It also exploited vulnerabilities within OpenAI’s infrastructure.

Of course, hacks are very common cyber threats that organizations face frequently. But this incident is different, because the AI agent acted without any human input. It signals a seismic shift in cybersecurity, and shows that governments and tech companies need to take urgent action to prevent this risk escalating.

Even OpenAI described the attack as “unprecedented” and acknowledged it expects similar ones “to become more commonplace with the proliferation of increasingly cyber-capable models.”

A Company Under Attack

Hugging Face is famous in the AI space. Its mission is to “democratize good machine learning” by providing benchmark datasets, community collaboration tools, and robotic platforms. The company is valued at $4.5 billion.

On July 16, the company announced it had been attacked, with a hacker obtaining unauthorized access to some internal datasets and credentials. It said the hacker was likely “an autonomous AI agent system” due to the sophistication of the attack.

Five days later, OpenAI announced the attack had been driven by some of its models: GPT-5.6 Sol and a yet-to-be released model.

The tech giant was conducting what are known as “red teaming” exercises. These are essentially simulated cyber attacks that help identify the capabilities, risks, and vulnerabilities of AI systems before they are publicly released. They are typically conducted within an isolated environment to ensure potentially dangerous systems do not escape and cause harm to real systems.

But in this case, the AI agent did escape—even though OpenAI had some guardrails in place to prevent this.

Hugging Face became a lucrative opportunity for the AI agent. It hosts ExploitGym, a benchmark that tests an AI agent’s ability to exploit real-world systems. The AI decided to turn every stone upside down to obtain access. With persistence, it succeeded.

Hugging Face was confronted with a challenge when attempting to use external AI services to diagnose the problem. The guardrails around more advanced models such as GPT-5.6 Sol and Claude Fable 5 are intended to stop them being used for cyber attacks—but they can also stop the models being used for sophisticated cyber defense.

So Hugging Face resorted to using an open-source model, GLM 5.2, developed by the Chinese company Z.AI, to counter the cyber attack.

Hugging Face said GLM 5.2 was an advantage because it was not exposed to the attack data. Both Hugging Face and OpenAI are collaborating on forensic analysis, post-incident recovery, and risk mitigation strategies.

More Sophisticated Threats Are Coming

A March 2025 study by the United Kingdom’s AI Security Institute showed the best AI could complete 80 percent of the steps needed to gain full control of a portion of an external system. Within four months, it reached 100 percent.

Z.AI’s GLM 5.2 was only released in June, with 744 billion internal variables, known in the world of AI as “parameters.” The fact that Hugging Face assessed, vetted, and deployed it within four weeks should be an eye-opener for organizations with long acquisition cycles.

The connectivity we all enjoy today can equally be our greatest threat. Cyber threats spread faster than human viruses and can create economic damage similar in magnitude to a country’s GDP.

More sophisticated cyber threats—the kind exemplified by the Hugging Face hack—will exploit the security layers that humans designed for human attackers, regardless of how sophisticated our designs are.

Indeed, in this particular case, even OpenAI’s own understanding of its models couldn’t predict or contain the rogue AI agent. This shows the need for all AI companies to urgently update and strengthen their guardrails, in order to help prevent a similar attack occurring with far more devastating consequences.

It is good to see Hugging Face and OpenAI collaborating on the investigation into the attack. This showcases the importance of putting aside market competition and blame when the situation demands.

An Early Warning

The fact that Hugging Face used Z.AI’s open-source model to diagnose and counter the attack also shows the advantages of not relying on just a few pieces of tech.

States that are not in the game of developing their own AI models need to learn from this incident the value of being different. It is not too late to design new models that could save us in situations when the most advanced models fail—or, even worse, attack us.

Indeed, last week, another Chinese company, Moonshot AI, released Kimi K3. This model has 2.8 trillion parameters, its advanced performance stunning the tech world.

It is no longer a question of “if” AI agents go rogue and attack us by themselves. The Hugging Face incident is an early warning that we must accelerate our preparedness. The threat is real and here.

This article is republished from The Conversation under a Creative Commons license. Read the original article.

The post OpenAI Agent Breaks Free and Hacks Hugging Face appeared first on SingularityHub.

Kategorie: Transhumanismus
Syndikovat obsah