Agregátor RSS

LLMs respond differently to harmful prompts when AI watermarking is used

Ars Technica - 17 Září, 2026 - 20:33

In response to a new European Union law, AI platforms are implementing new schemes for watermarking the content they generate. Anthropic recently disclosed its future Claude models will use SynthID-Text, an approach Google created and released as open source. It uses a secret key that subtly changes the process a model uses for choosing the next word in a sentence. Whereas a top next word choice might be “cloudy,” the key might change it to “overcast.” Anyone who knows the key can determine if it was generated by the platform using it.

New research shows that SynthID-Text can change not just word selection but also the tools a model invokes and the chances it will adhere to or disregard safety guardrails it has been trained to follow. The threat can become greater in the face of an adversarial prompt, in which an attacker attempts to cause a model to carry out a harmful action, such as revealing a password or other sensitive information. Instructions that normally wouldn’t be followed will, in some cases, be performed once the watermarking is deployed. The finding underscores the need for developers to thoroughly test how their LLMs and agents behave when watermarking is in place.

Changing safety behavior

“As compared to the same models without watermarking, it is definitely going to change their behavior, especially when we place it under adversarial conditions, or we make these models call tools when they’re powering an agent,” Andrea Siposova, an AI security researcher at Lasso Security, told Ars. “Watermarking is made to not be perceptible to a reader, but we know that when we are changing anything about what the model is generating, it is going to cause some tradeoffs, it’s going to show up somewhere.”

Read full article

Comments

Pět důvodů, proč si nekupovat chytré hodinky. A dva důležité, proč ano

Živě.cz - 17 Září, 2026 - 20:15
Chytré hodinky jsou vhodným doplňkem k mobilu • Jenže mají i spoustu nevýhod, o kterých byste měli vědět • Na závěr přidáme dva důvody, proč má jejich koupě smysl
Kategorie: IT News

Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

The Hacker News - 17 Září, 2026 - 20:08
A critical vulnerability in Check Point's Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network. The Security Management Server is the system that controls firewall policy and administrator access. Check Point has released a fix through its LivePatch update channel and says it has no indication that the flaw Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

China's Salt Typhoon backdoors Latin American orgs with new snooping malware

The Register - Anti-Virus - 17 Září, 2026 - 20:00
China’s Salt Typhoon gang has developed a new backdoor and dropped it in networks belonging to high-profile organizations in several countries across Central and South America since at least August 2025, according to researchers. The PRC-backed espionage crew shifted its focus to Latin America a month prior, and from mid-2025 into 2026, the vast majority - 90 percent - of Salt Typhoon’s targets were located in that region, ESET, which tracks the group as FamousSparrow, said in a Thursday report. Salt Typhoon is the cyber-spy gang that hacked telecommunications and government agencies to gain stealthy, long-term access to victim organizations going back as far as 2019. These hacks, however, weren’t discovered until late 2023. In August 2025, ESET’s malware hunters found the group’s new backdoor, called SparroWocky, deployed against government agencies in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. While targeting entities in these countries “represents a rare occurrence among the China-aligned APT groups,” ESET believes the focus likely reflects China’s reaction to recent US President Donald Trump’s initiatives in the region, malware researchers Alexandre Côté Cyr and Romain Dumont said. “Donald Trump’s second presidential term has brought about an aggressive reaffirmation of US interests in Latin America, which threatens various long-term investments that China has cultivated throughout the continent in the last decade, in domains such as energy, mining, and telecommunications,” they wrote. “We suspect that FamousSparrow’s activities are intended to help China better monitor and anticipate the reaction of local governments to current US pressures.” SparroWocky is a modular C++ backdoor that appeared soon after the Beijing snoops started focusing on Latin America. The new backdoor integrates open source tools and uses techniques designed to evade antivirus and other security software. The name comes from Lewis Carroll’s Jabberwocky poem - the researchers found the first stanza in several collected samples. (’Twas brillig, and the slithy toves/Did gyre and gimble in the wabe:/All mimsy were the borogoves,/And the mome raths outgrabe.) ESET based its analysis on a malware sample compiled on November 17, and said it contained the following open source projects: Mbed TLS, a C library it uses to establish a secure communication channel with its command-and-control (C2) server. MinHook, a Windows API hooking library that hides the start address of newly created threads from security products. COFF Loader (or a similar project) to enable dynamic loading and execution of in-memory plugins in the form of COFF objects. Plus, the backdoor incorporates a variant of the SilentMoonwalk technique to spoof the call stacks originating from MinHook routines, and thus escape the watchful eyes of monitoring tools, along with a custom API-hashing algorithm to dynamically resolve Windows API functions. The gang deploys the backdoor in its usual way: a trident loader scheme consisting of a legitimate executable, a malicious DLL, and a file containing the encrypted malware. The loader resides in the malicious DLL and executes via DLL side-loading. After establishing communication with its C2 server, the backdoor starts receiving commands handled by a custom class named WinHandler (derived from a ServerHandler custom class), according to the runtime type information in the malware. The nearly 30 commands include scooping up system details and sending them to the C2, starting and/or terminating a new session and removing persistence, stealing and deleting files, taking periodic screenshots, collecting session IDs and usernames of enumerated remote sessions on the system via WTSEnumerateSessionsW, and spawning new SparrowWocky instances. It uses TLS encryption to communicate with its C2 servers, connecting directly to their IP addresses, generally on port 443, although ESET also spotted the malware using port 8080 in some cases. The malware researchers also published a full indicators-of-compromise list and samples in ESET’s GitHub repository, so give those a read, too. ®
Kategorie: Viry a Červi

30 nejlepších filmů a seriálů o sériových vrazích. Psychopati, kteří děsí i baví

Živě.cz - 17 Září, 2026 - 19:45
Mrazivé pohledy do mysli vrahů i těch, kteří je pronásledují. Seriály a filmy o sériových vrazích fascinují tím, jak balancují mezi hororem, detektivkou a psychologickým dramatem. Vybrali jsme tituly, které ukážou, že největší hrůza se často skrývá tam, kde ji nejméně čekáte.
Kategorie: IT News

ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories

The Hacker News - 17 Září, 2026 - 19:32
Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them. This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold like a monthly subscription. Some attacks use new tricks. Others just reuse what was already lying around. Both work often enough. So the threat landscape is not getting cleaner. It is just Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Brevo supply-chain attack injected ClickFix scripts on customer sites

Bleeping Computer - 17 Září, 2026 - 19:11
Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware. [...]
Kategorie: Hacking & Security

Balíčky z Číny zdraží od listopadu 2026. Češi si zřejmě připlatí 50 Kč za každou položku v objednávce

Živě.cz - 17 Září, 2026 - 18:45
Červencovým paušálním clem ve výši 3 eur za položku to nekončí. • Nejpozději od listopadu se bude hradit ještě manipulační poplatek. • Za každou položku odeslanou ze zemí mimo EU se prý zaplatí další 2 eura.
Kategorie: IT News

FUJITSU-MONAKA CPU a Fujitsu MONAKA Server

AbcLinuxu [zprávičky] - 17 Září, 2026 - 17:56
Společnost Fujitsu představila FUJITSU-MONAKA CPU a Fujitsu MONAKA Server. Navrženo, vyvinuto a vyrobeno v Japonsku. Pro suverénní AI infrastrukturu.
Kategorie: GNU/Linux & BSD

Googlebooky jsou za rohem. Google vyrazí proti Windows a macOS s upraveným Androidem

Živě.cz - 17 Září, 2026 - 17:45
Google oznámil, že již 21. září v 15:00 našeho času spustí předobjednávky Googlebooků. Firma s nimi chce vstoupit do třídy prémiových notebooků, které nabídnou vyšší výkon, lepší výbavu a nové softwarové funkce oproti dosavadním Chromebookům. Běží také na jiném operačním systému. Zatímco ...
Kategorie: IT News

Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

The Hacker News - 17 Září, 2026 - 17:37
Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a security announcement on September 15. The escape runs with the rights of the host account that runs the virtual machine. The flaw, CVE-2026-77179, is rated Critical, affects versions Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

London property manager breach may have exposed bank details and lockbox codes

The Register - Anti-Virus - 17 Září, 2026 - 17:30
London property management biz City Relay has warned customers that intruders may have stolen financial data, passwords, and codes used to access keys after compromising its Metabase Cloud instance. City Relay, marketing itself as "London's most trusted property management company," told landlords via email - seen by The Reg - that attackers accessed the third-party provided cloud twice "as a result of a vulnerability in the platform that we were unaware of." The message to customers stated: "Personal data was extracted from the platform." The potentially compromised data on the platform includes names, email and physical addresses, telephone numbers, financial information, property access details, and account passwords. City Relay said the exposed financial data included bank account numbers, sort codes, IBANs, SWIFT references, and account names and addresses. Attackers may also have obtained data about property amenities and access, including the locations of stored keys and codes for lockboxes containing them. Dray Agha, senior manager of security operations at Huntress, explained that Metabase connects to customers' databases, so the information exposed in an attack depends on the access each customer granted it. "A company linking Metabase to a general analytics database will only expose harmless user metrics," he said. "A company that connects it directly to their core transactional database risks exposing highly sensitive financial records and credentials." Agha said that if the exposed passwords and financial details were stored in readable form, that would point to inadequate data protection practices. "Sensitive financial details should also be encrypted or tokenized when held in a database. Keeping this information readable creates a massive risk if a connected reporting tool is ever compromised." The Register understands that City Relay sent the emails to current landlords and former users of its services. One source claimed City Relay learned of the intrusion on September 8 and notified affected customers on September 14. "As property access and key-storage information was potentially included, we immediately took precautionary action to update the relevant access and key-storage codes," the emails stated. "This work has now been completed. The previously exposed codes can no longer be used and we have no evidence of any unauthorised property access arising from the incident." Beyond the immediate physical security risks, City Relay urged customers to check their bank accounts for suspicious transactions, watch for phishing and other scams, and change any reused passwords on other accounts. The company told us it had found no evidence that the exposed data had been misused. It is continuing to investigate alongside cybersecurity specialists and "the relevant authorities" to establish the attack's full scope. City Relay's website says it has hundreds of "partners" – landlords who outsource management of their property portfolios – and that it manages, or has managed, thousands of London properties. The company has not said how many customers were affected in London or Paris, where it also operates. The Register asked City Relay for more information. City Relay did not identify the vulnerability used in the attack. Metabase disclosed a zero-day SQL injection flaw on August 6, saying attackers compromised fewer than 3 percent of its customers before fixes were automatically deployed, but it has not confirmed that the City Relay incident was part of that campaign. Known victims included laptop maker Framework and workflow automation platform n8n. ®
Kategorie: Viry a Červi

Předprodej notebooků Googlebook spuštěn v pondělí 21. září

AbcLinuxu [zprávičky] - 17 Září, 2026 - 16:45
Předprodej v květnu představených notebooků Googlebook, nástupců notebooků Chromebook, bude spuštěn v pondělí 21. září.
Kategorie: GNU/Linux & BSD

Anthropic tries to make Claude stickier with launch of Docs and Slides

Computerworld.com [Hacking News] - 17 Září, 2026 - 16:28

Anthropic is equipping its Claude AI assistant for more productivity work with the launch of Claude Docs and Slides.

While it’s already possible to create documents such as Microsoft Word and Google Docs files from Claude chats, the latest update, announced Wednesday, brings a rich-text editor directly into Claude.

Users ask the AI assistant to draft a document or slides via the chat interface, and Claude will ask clarifying questions before starting work. It will also leave comments to explain its choices.

Claude Docs files are then stored in the Artifacts tab and can be exported as Word, PDF, Google Docs, or markdown files. Documents can be shared with colleagues for real-time collaboration.

Anthropic

“Strategically, this signals Claude moving from an AI assistant into an agentic platform meant for full lifecycle of knowledge work,” said Arun Chandrasekaran, Distinguished VP analyst at Gartner.

He anticipates early user demand around “recurring, template-driven work,” such as status reports, board decks, and data-to-story reports.

“The likely near-term outcome isn’t wholesale replacement of alternative digital workplace tools, but it positions Anthropic as an entry point for workflows historically created in third-party tools,” said Chandrasekaran.

Claude Docs usage counts towards a customer’s Claude usage limits, and larger requests such as drafting a document with several sources takes up more of the limit. There are currently feature limitations, with no version history, access levels, or external sharing on Team and Enterprise pans. It’s also unavailable for customers that use “customer-managed encryption keys (CMEK), zero data retention (ZDR), or a HIPAA-ready configuration,” according to Claude’s support site.

Claude Docs and Slides are available in beta now on paid plans, rolling out to Pro and Max plans first. The feature is turned off by default for enterprise plans.

Anthropic

All of the major AI model providers are seeking ways to make their products stickier within customer organizations, said Jack Gold, principal analyst at J. Gold Associates. Some have targeted coding agents, while others, particularly Microsoft and Google, have AI assistants and agents that are connected into existing office productivity tools.

Microsoft’s Copilot is embedded across its Office suite, for instance, although users can also create documents directly from the Microsoft 365 Copilot chat interface.


“Microsoft and Google are bringing AI deeper into established productivity environments, while Anthropic is bringing more of the productivity environment into AI,” said Maria Bell, senior research analyst at FDM CCS Insight. “Over time, the competition may increasingly be over which becomes the primary interface through which knowledge workers get work done.”

Early findings of FDM CCS Insight’s ‘2026 Employee Workplace Technology Survey’ show that show that around half of employees that use generative AI at work do so to create or edit reports and documents.

It’s unlikely that native document editing features in Claude will result in a large-scale move from Microsoft or Google’s productivity suites, analysts say.

The updates to Claude this week have the potential to help users get more done, said Gold, “but it’s unclear how many users that already have productivity suites in place will choose to move to other tools,” even if they prefer Claude for its AI capabilities.

“The fundamental question is, if I am used to certain tools and they work for me, am I willing to change for the promise of working better? Not sure that will be a winning strategy,” he said.

“Microsoft and Google are deeply embedded in how people already work, and users have spent years becoming comfortable with their products and workflows,” said Bell.

“They are also increasingly bringing access to powerful AI models directly into those familiar environments. Anthropic therefore must do more than match document-creation features; it has to offer an experience compelling enough for users to build new habits around Claude,” she said.

As well as Anthropic’s Claude, it has long been rumored that OpenAI plans to build its own native productivity tools in ChatGPT that would bring it into more direct competition with Microsoft and other incumbent office software vendors.

Anthropic also announced that users can now invoke Claude Design in an ordinary chat. Claude Design, which generates visual outputs such as slides and prototypes, was previously available as a separate tool within the Claude app.  

In addition, Claude Cowork — which can perform multiple-stage tasks — and the regular Claude chat interface have now been combined, with Claude determining how to handle a request. This removes the need for users to decide which tool to use for a particular task, according to Anthropic. It’s not clear exactly how Anthropic decides where to route a request, however. Cowork queries are generally more token-intensive than the core chat interface.

“Claude can now figure out what a task needs, so what Cowork and Design can do is available from any conversation, with the context, skills, and connectors you already have,” the company said in a blog post.

The new Claude experience will roll out gradually, starting with Pro and Max customers. Anthropic said it will alert Claude Enterprise customers before any changes are made to their account.

Claude Enterprise costs $20 per user each month alongside consumption-based pricing.

Kategorie: Hacking & Security

Těhotná želvuška, hojící se rána a divoké bitvy pestřenek. Nikon vyhlásil nejlepší videa z mikroskopů za rok 2026

Živě.cz - 17 Září, 2026 - 16:13
Nikon každý rok vybírá ty nejkrásnější fotografie z optických mikroskopů. Mezinárodní soutěž Small World, do které přispívají vědecké týmy z celého světa, se bez přestávky koná už od roku 1975 a od sezóny 2011 ji doplnila i druhá kategorie Small World in Motion. Jak už název napovídá, tentokrát ...
Kategorie: IT News

Will Apple enter the server business?

Computerworld.com [Hacking News] - 17 Září, 2026 - 16:09

In a world of speculation, this week’s most interesting rumor says Apple may plan to enter the server business once again, with powerful systems running its own Apple Silicon chips.

It’s hard to dismiss the claims, particularly as Apple is already in the server business, with its Texas factory manufacturing servers for its Private Cloud Compute (PCC) cloud intelligence system. While those servers are only used internally —or externally if installed at third-party data centers for use with Apple’s ecosystem of products — they are still servers.

Apple is already in the server business

It’s also a business Apple has been in before. Many years ago, around 2002, I visited Apple in Paris, where the company demonstrated its Xserve and Xserve RAID systems. These were particularly aimed at the video and music industries and became quite widely used in those sectors. Apple discontinued Xserve in 2011, because the product sat outside its broad consumer-focused strategy.

Things were different then. You see, today’s Apple has billions of users. It has a fast-growing reach into enterprise tech — SAP recently updated its fleet of 60,000 Macs to macOS 27 on the very day the OS shipped, and there are hundreds of thousands of Macs in use at businesses worldwide. Apple has hundreds of millions of iPhones in active use across business. Apple even has the silicon to power these things.

The Apple Silicon advantage

You can’t ignore the computational advantage of Apple Silicon. The first leaked benchmarks for the M5 Ultra chip used in the new Mac Studio are incredibly impressive, with multi-core performance at an astonishing 52,516. That’s amazing performance from a Mac that costs an estimated 8 cents an hour to run at full capacity. 

Now imagine that price/performance ratio stashed in a server.

You don’t even need to imagine it, because MacStadium, AWS, and others already use Macs in server farms, with great success. MacStadium CTO Chris Chapman once told me that Apple Silicon is so power efficient his data centers would tell him the Macs he had racked with them were not using enough power for the space. (Data centers sell space by the square foot and calculate energy costs within that calculation.)

Making cloud cheaper and more secure

The computational performance per watt is an advantage to any user, but the cost benefits rack up pretty fast when you have a thousand machines racked up on the data farm. Apple even has a server operating system waiting in the wings — or did until it stopped offering macOS Server four years ago. 

Apple’s existing server production is focused on Private Cloud Compute. That system is impressive, (a) because Apple has opened it up to security experts to confirm it is secure, and (b) because it delivers data and privacy security equal to what its end-user platforms provide. 

But, as data centers blossom across Terra Firma, there’s a growing recognition of the need for sovereign AI, on-premises AI, and private AI. Think of it this way: We already know Macs can run some of the world’s most powerful LLMs very, very well. What’s wrong with introducing Apple Silicon-based servers to do the same thing? These things could even offer companies access to their own white-label private builds of Apple Intelligence, though I consider that unlikely. 

Why the speculation makes sense, and why it doesn’t

So, I see lots of reasons why speculation that Apple may re-enter the server market makes sense — though it may not be in a huge hurry, as the original claim is that these servers will run M8 Ultra chips. (Mark Gurman thinks it may be an M7 Ultra). 

Of course, speculation and conversation don’t always become fact. Merely because Apple is talking about servers again doesn’t mean it will advance those plans. 

Former Apple business-focused product marketing executive Todd Dailey doubts these plans. He says Apple is far more focused on consumer markets than enterprise. 

He also points out that if it were to offer servers, the company would need to consider providing same-day tech support and more flexibility around OS upgrades, adding that the business may not be big enough to justify the cost of implementing the plan. 

That doesn’t mean Apple isn’t considering it, just that once you bounce the idea through a few real-world weeds there may be obstacles to making it happen.

Is it time for iCloud Ultra?

I do think there are signs Apple is taking enterprise markets more seriously. I also think that as PCC deployment expands, it makes sense for Apple’s server teams to build a product road map for the future of PCC servers like any other Apple product, even if they are only used to support its own server-side AI.  

But I also think that if the company were to go ahead to make this happen, the solution would be aimed at developers and businesses seeking a uniquely private way to deploy sophisticated AI outside of the thrall of the frontier models, chipping a little more business away from those over-leveraged entities as it does. 

The thing is, if that’s the case, then is it servers Apple is thinking of building, or server farms offering hosted services for a price? An iCloud Ultra service for developers and enterprise users may perhaps make more sense. I guess we’ll have to wait and see.

Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSky, LinkedIn, or Mastodon.

Kategorie: Hacking & Security

Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords

The Hacker News - 17 Září, 2026 - 16:03
The Iran-linked "hacktivist" persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE. "HEAVYGRAM offers builtin commands supporting remote command execution, system, network and process information discovery, data and Telegram session files exfiltration, screenshot capture, DLL sideloading, Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

What Recent AI-Powered Attacks Mean for Your Identity Security

Bleeping Computer - 17 Září, 2026 - 16:01
AI is making credential theft faster and easier to scale, giving attackers more opportunities to abuse valid identities. Specops explains why identity security must go beyond successful authentication by verifying that both the user and the device requesting access can be trusted. [...]
Kategorie: Hacking & Security

Windows 11 24H2 Home and Pro reach end of support in October

Bleeping Computer - 17 Září, 2026 - 15:09
Microsoft reminded customers this week that devices running Windows 11 24H2 Home and Pro editions will stop receiving updates next month. [...]
Kategorie: Hacking & Security
Syndikovat obsah