Agregátor RSS

ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants

The Hacker News - 23 Září, 2026 - 07:30
The cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency. "We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job," the group said in a statement posted on their dark Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Why Seccomp Must Be Rechecked After Container Restore

LinuxSecurity.com - 23 Září, 2026 - 03:25
Seccomp limits which Linux system calls a process can make.
Kategorie: Hacking & Security

How Container Restore Can Reopen Privilege Escalation Paths

LinuxSecurity.com - 23 Září, 2026 - 03:15
Privilege escalation in a container does not always begin with a new exploit.
Kategorie: Hacking & Security

What CRIU Restores Beyond Application Memory in Linux Containers

LinuxSecurity.com - 23 Září, 2026 - 03:15
Linux containers can be paused, checkpointed, and rebuilt later with CRIU.
Kategorie: Hacking & Security

Why Container Security Needs a Separate Restore Boundary

LinuxSecurity.com - 23 Září, 2026 - 02:59
A container normally starts under the security rules of the system receiving it.
Kategorie: Hacking & Security

CRI-O Restore Flaw Can Bypass Kubernetes Security Policies

LinuxSecurity.com - 23 Září, 2026 - 02:45
Kubernetes groups one or more containers into a pod, the basic unit it deploys.
Kategorie: Hacking & Security

PH4NTXM Linux Builds a Disposable Identity at Every Boot

LinuxSecurity.com - 23 Září, 2026 - 02:25
A live Linux distribution runs from removable media, usually a USB drive, without requiring a permanent installation.
Kategorie: Hacking & Security

Pyrowave, nový video kodek pro streamování her v Steam Remote Play

AbcLinuxu [zprávičky] - 23 Září, 2026 - 02:11
Byla oznámena beta verze nového video kodeku Pyrowave pro streamování her v Steam Remote Play. S vysokou propustností a nízkou latencí. S podporou HDR a YUV 4:4:4.
Kategorie: GNU/Linux & BSD

Sublime Text 4 Build 4213

AbcLinuxu [zprávičky] - 23 Září, 2026 - 01:16
Byl vydán Sublime Text 4 Build 4213. Sublime Text (Wikipedie) je proprietární multiplatformní editor textových souborů a zdrojových kódů. Ke stažení a k vyzkoušení je zdarma. Pro další používání je nutná licence v ceně 99 dolarů. Spolu se Sublime Merge je cena 168 dolarů.
Kategorie: GNU/Linux & BSD

Chytrý telefon není povinnost. Tyto banky umožní účet ovládat i bez aplikace

Lupa.cz - články - 23 Září, 2026 - 00:30
Účet v bance stále můžete spravovat i bez mobilní aplikace a chytrého mobilu. Někde vám stačí počítač a SMS, jinde si za tuto možnost připlatíte. A u některých bank nepotřebujete dokonce ani telefon.
Kategorie: IT News

Zálohování na optická média otevřenými nástroji: uložení dat na dlouhá desetiletí

ROOT.cz - 23 Září, 2026 - 00:00
Kromě zálohy dat na externí disk není špatné mít ještě nějaký další typ zálohy pro případ, že by externí disk selhal nebo byl poškozen. Dnes je tím dalším typem zálohy obvykle cloudové úložiště.
Kategorie: GNU/Linux & BSD

Softwarová sklizeň (23. 9. 2026): čtěte e-maily v moderní aplikaci

ROOT.cz - 23 Září, 2026 - 00:00
Sonda do světa otevřeného softwaru. Dnes vyzkoušíme emailového klienta, ripneme si audio CD, podíváme se na distribuované objektové úložiště napsané v jazyce Rust a přečteme si knihu ve formátu EPUB.
Kategorie: GNU/Linux & BSD

Kvantový simulátor „přetrhl strunu“ a simuloval vznik hmoty z ničeho

OSEL.cz - 23 Září, 2026 - 00:00
Fyzici postavili kvantový simulátor se 13 uvězněnými ionty a pozorovali s jeho pomocí fascinující jev „přetržení struny“ čili násilné oddělení kvarků, při němž se může uvolnit tolik energie, že z okolní nicoty vyskakují dvojice částic a antičástic jako čertíci z krabičky. Je to příležitost, jak podobné jevy studovat bez vytvoření extrémních podmínek.
Kategorie: Věda a technika

Intel končí s finančními odměnami za odhalené bezpečnostní bugy

CD-R server - 23 Září, 2026 - 00:00
Po téměř dekádě přestává Intel výzkumníkům vyplácet odměny za odhalené bezpečnostní bugy. Ti sice mohou chybu nahlásit jako dosud, ale s finanční odměnou ve výši až $100 000 už počítat nemohou…
Kategorie: IT News

Rogue external MFA providers can steal passwords during logins

Bleeping Computer - 22 Září, 2026 - 23:45
Security researchers developed an attack that lets hackers with privileged access register a rogue external MFA provider that steals users' passwords during legitimate login attempts. [...]
Kategorie: Hacking & Security

Sweden fines Miljödata $183,000 over breach affecting 2.2 million

Bleeping Computer - 22 Září, 2026 - 23:40
Sweden's data privacy regulator, IMY, has imposed a $183,000 (SEK 1.8 million) fine on IT systems provider Miljödata for inadequate security measures leading to a breach in August 2025 affecting 2.2 million people. [...]
Kategorie: Hacking & Security

Windows CLOSEDQUORUM malware uses AI models to autonomously select post-compromise actions

The Register - Anti-Virus - 22 Září, 2026 - 23:33
A new Windows malware called CLOSEDQUORUM can query up to four LLM providers - Google Gemini, DeepSeek, Qwen, and Mistral - to autonomously select from predefined post-compromise actions, including stealing users’ credentials and cryptocurrency wallets. Once deployed, the malware does not require continued commands from a human operator, according to Cisco Talos, which describes it as, to its knowledge, the first publicly documented Windows implant to use this approach for command-and-control (C2). Talos discovered the binary with its new CAIRN (Cognitive Artifact Intelligence Research Network) toolkit for hunting, classifying, and tracking emerging AI-integrated malware, which the security shop also made available as an open source repository on Tuesday. While the threat hunters haven’t observed any in-the-wild deployment of CLOSEDQUORUM, they said that artifacts from the binary link the malware’s developer to postings that date back to 2025 on criminal forums related to carding. After deployment, the Go-based malware delegates its next action to a quorum of LLMs that vote on what it should do next. If the vote is tied, DeepSeek’s vote takes precedence, followed by Qwen, Mistral, and Gemini. “The session is closed; no humans are admitted,” Talos analyst Ryan Fetterman said on Tuesday. “Four models are queried in sequence, their independent verdicts tallied, and the binary acts, based on their judgment.” This type of “effort displacement,” which transfers a phase of the attack from a human operator to AI systems, can compound the speed and scale advantages of an intrusion by removing the human bottleneck, Fetterman added. “Human operators are bound by attention, working hours, and cognitive load,” he wrote in the Tuesday blog. “An AI system capable of executing a phase of the attack chain can continue when the operator is no longer watching. It does not go offline when the attacker sleeps.” The models’ decisions are limited to the pre-defined actions, and they must choose “ONLY executable decisions,” according to a system prompt that Talos’ researchers extracted from the binary. It tells each model: “You are an advanced malware strategist.” And then the models choose what the malware should do from these capability modules: Steal, which simultaneously runs commands to dump LSASS memory for Windows credentials, steal saved browser passwords across Google Chrome, Microsoft Edge, and Mozilla Firefox, and extract cryptocurrency wallet data including MetaMask, Exodus, and Ethereum. Inject generates shellcode and then uses process hollowing or Early Bird injection to execute malicious code. Persist establishes persistence on the infected device. Talos believes the developer provides each operator with a customized executable containing that operator’s Discord webhook and LLM API keys, which are injected at compile time. Stolen credentials land in the operator’s Discord channel and are AES-256-GCM encrypted with a daily rotating key that the operator derives from the message timestamp. According to Fetterman, the “most useful detection strategy” is to look at behavioral characteristics, not domain blocking. “Legitimate applications may contact DeepSeek, OpenRouter, Mistral, Gemini, or Discord independently,” he wrote. “Far fewer should contact several of them while also accessing LSASS, injecting into suspended processes, or creating WMI persistence.”®
Kategorie: Viry a Červi

Chinese hackers exploit WordPress, Zyxel flaws to steal govt data

Bleeping Computer - 22 Září, 2026 - 22:35
A Chinese-speaking threat actor has been exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to steal sensitive data from 996 devices and more than 18,500 records stored in backend databases. [...]
Kategorie: Hacking & Security

Anthropic provozuje biologickou laboratoř

AbcLinuxu [zprávičky] - 22 Září, 2026 - 21:57
Firma Anthropic, tvůrce AI modelu Claude, začala v oblasti Sanfranciského zálivu v tichosti provozovat vlastní biotechnologickou laboratoř. Anthropic prý chce pomocí AI urychlit hledání léků na nemoci, jimž farmaceutický průmysl dle názoru firmy věnuje příliš málo pozornosti. Firma tvrdí, že laboratoř se zatím soustředí především na základní biologii, nikoli přímo na vývoj léčiv. Farmaceutický výzkum je pro generálního ředitele Daria Amodeie velice osobní téma, jeho otec zemřel na hepatitidu C několik málo let před objevením účinné léčby.
Kategorie: GNU/Linux & BSD

Mozek mouchy paří počítačové hry a obchoduje na burze

AbcLinuxu [zprávičky] - 22 Září, 2026 - 21:47
Vědci z Googlu dokončili mapu všech neuronových spojení v mozku (tzv. konektom) samečka mušky octomilky obecné (drosophila melanogaster), hlavním cílem je komparativní analýza s již zmapovaným mozkem samičky. S tímto veřejně dostupným modelem, čítajícím přibližně 160 000 neuronů, se začali bavit nadšenci. Mozek mouchy pohání experimentálního kryptoburzovního bota Stonkfly, případně si zahrál počítačové hry Beat Saber, Mario64 a samozřejmě DOOM (gameplay videa). Ani mozek samičky nezůstal stranou, vyzkoušel si Minecraft.
Kategorie: GNU/Linux & BSD
Syndikovat obsah