Agregátor RSS
ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
The cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency.
"We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job," the group said in a statement posted on their dark Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Why Seccomp Must Be Rechecked After Container Restore
Seccomp limits which Linux system calls a process can make.
Kategorie: Hacking & Security
How Container Restore Can Reopen Privilege Escalation Paths
Privilege escalation in a container does not always begin with a new exploit.
Kategorie: Hacking & Security
What CRIU Restores Beyond Application Memory in Linux Containers
Linux containers can be paused, checkpointed, and rebuilt later with CRIU.
Kategorie: Hacking & Security
Why Container Security Needs a Separate Restore Boundary
A container normally starts under the security rules of the system receiving it.
Kategorie: Hacking & Security
CRI-O Restore Flaw Can Bypass Kubernetes Security Policies
Kubernetes groups one or more containers into a pod, the basic unit it deploys.
Kategorie: Hacking & Security
PH4NTXM Linux Builds a Disposable Identity at Every Boot
A live Linux distribution runs from removable media, usually a USB drive, without requiring a permanent installation.
Kategorie: Hacking & Security
Pyrowave, nový video kodek pro streamování her v Steam Remote Play
Byla oznámena beta verze nového video kodeku Pyrowave pro streamování her v Steam Remote Play. S vysokou propustností a nízkou latencí. S podporou HDR a YUV 4:4:4.
Kategorie: GNU/Linux & BSD
Sublime Text 4 Build 4213
Byl vydán Sublime Text 4 Build 4213. Sublime Text (Wikipedie) je proprietární multiplatformní editor textových souborů a zdrojových kódů. Ke stažení a k vyzkoušení je zdarma. Pro další používání je nutná licence v ceně 99 dolarů. Spolu se Sublime Merge je cena 168 dolarů.
Kategorie: GNU/Linux & BSD
Chytrý telefon není povinnost. Tyto banky umožní účet ovládat i bez aplikace
Účet v bance stále můžete spravovat i bez mobilní aplikace a chytrého mobilu. Někde vám stačí počítač a SMS, jinde si za tuto možnost připlatíte. A u některých bank nepotřebujete dokonce ani telefon.
Kategorie: IT News
Zálohování na optická média otevřenými nástroji: uložení dat na dlouhá desetiletí
Kromě zálohy dat na externí disk není špatné mít ještě nějaký další typ zálohy pro případ, že by externí disk selhal nebo byl poškozen. Dnes je tím dalším typem zálohy obvykle cloudové úložiště.
Kategorie: GNU/Linux & BSD
Softwarová sklizeň (23. 9. 2026): čtěte e-maily v moderní aplikaci
Sonda do světa otevřeného softwaru. Dnes vyzkoušíme emailového klienta, ripneme si audio CD, podíváme se na distribuované objektové úložiště napsané v jazyce Rust a přečteme si knihu ve formátu EPUB.
Kategorie: GNU/Linux & BSD
Kvantový simulátor „přetrhl strunu“ a simuloval vznik hmoty z ničeho
Fyzici postavili kvantový simulátor se 13 uvězněnými ionty a pozorovali s jeho pomocí fascinující jev „přetržení struny“ čili násilné oddělení kvarků, při němž se může uvolnit tolik energie, že z okolní nicoty vyskakují dvojice částic a antičástic jako čertíci z krabičky. Je to příležitost, jak podobné jevy studovat bez vytvoření extrémních podmínek.
Kategorie: Věda a technika
Intel končí s finančními odměnami za odhalené bezpečnostní bugy
Po téměř dekádě přestává Intel výzkumníkům vyplácet odměny za odhalené bezpečnostní bugy. Ti sice mohou chybu nahlásit jako dosud, ale s finanční odměnou ve výši až $100 000 už počítat nemohou…
Kategorie: IT News
Rogue external MFA providers can steal passwords during logins
Security researchers developed an attack that lets hackers with privileged access register a rogue external MFA provider that steals users' passwords during legitimate login attempts. [...]
Kategorie: Hacking & Security
Sweden fines Miljödata $183,000 over breach affecting 2.2 million
Sweden's data privacy regulator, IMY, has imposed a $183,000 (SEK 1.8 million) fine on IT systems provider Miljödata for inadequate security measures leading to a breach in August 2025 affecting 2.2 million people. [...]
Kategorie: Hacking & Security
Windows CLOSEDQUORUM malware uses AI models to autonomously select post-compromise actions
A new Windows malware called CLOSEDQUORUM can query up to four LLM providers - Google Gemini, DeepSeek, Qwen, and Mistral - to autonomously select from predefined post-compromise actions, including stealing users’ credentials and cryptocurrency wallets. Once deployed, the malware does not require continued commands from a human operator, according to Cisco Talos, which describes it as, to its knowledge, the first publicly documented Windows implant to use this approach for command-and-control (C2). Talos discovered the binary with its new CAIRN (Cognitive Artifact Intelligence Research Network) toolkit for hunting, classifying, and tracking emerging AI-integrated malware, which the security shop also made available as an open source repository on Tuesday. While the threat hunters haven’t observed any in-the-wild deployment of CLOSEDQUORUM, they said that artifacts from the binary link the malware’s developer to postings that date back to 2025 on criminal forums related to carding. After deployment, the Go-based malware delegates its next action to a quorum of LLMs that vote on what it should do next. If the vote is tied, DeepSeek’s vote takes precedence, followed by Qwen, Mistral, and Gemini. “The session is closed; no humans are admitted,” Talos analyst Ryan Fetterman said on Tuesday. “Four models are queried in sequence, their independent verdicts tallied, and the binary acts, based on their judgment.” This type of “effort displacement,” which transfers a phase of the attack from a human operator to AI systems, can compound the speed and scale advantages of an intrusion by removing the human bottleneck, Fetterman added. “Human operators are bound by attention, working hours, and cognitive load,” he wrote in the Tuesday blog. “An AI system capable of executing a phase of the attack chain can continue when the operator is no longer watching. It does not go offline when the attacker sleeps.” The models’ decisions are limited to the pre-defined actions, and they must choose “ONLY executable decisions,” according to a system prompt that Talos’ researchers extracted from the binary. It tells each model: “You are an advanced malware strategist.” And then the models choose what the malware should do from these capability modules: Steal, which simultaneously runs commands to dump LSASS memory for Windows credentials, steal saved browser passwords across Google Chrome, Microsoft Edge, and Mozilla Firefox, and extract cryptocurrency wallet data including MetaMask, Exodus, and Ethereum. Inject generates shellcode and then uses process hollowing or Early Bird injection to execute malicious code. Persist establishes persistence on the infected device. Talos believes the developer provides each operator with a customized executable containing that operator’s Discord webhook and LLM API keys, which are injected at compile time. Stolen credentials land in the operator’s Discord channel and are AES-256-GCM encrypted with a daily rotating key that the operator derives from the message timestamp. According to Fetterman, the “most useful detection strategy” is to look at behavioral characteristics, not domain blocking. “Legitimate applications may contact DeepSeek, OpenRouter, Mistral, Gemini, or Discord independently,” he wrote. “Far fewer should contact several of them while also accessing LSASS, injecting into suspended processes, or creating WMI persistence.”®
Kategorie: Viry a Červi
Chinese hackers exploit WordPress, Zyxel flaws to steal govt data
A Chinese-speaking threat actor has been exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to steal sensitive data from 996 devices and more than 18,500 records stored in backend databases. [...]
Kategorie: Hacking & Security
Anthropic provozuje biologickou laboratoř
Firma Anthropic, tvůrce AI modelu Claude, začala v oblasti Sanfranciského zálivu v tichosti provozovat vlastní biotechnologickou laboratoř. Anthropic prý chce pomocí AI urychlit hledání léků na nemoci, jimž farmaceutický průmysl dle názoru firmy věnuje příliš málo pozornosti. Firma tvrdí, že laboratoř se zatím soustředí především na základní biologii, nikoli přímo na vývoj léčiv. Farmaceutický výzkum je pro generálního ředitele Daria Amodeie velice osobní téma, jeho otec zemřel na hepatitidu C několik málo let před objevením účinné léčby.
Kategorie: GNU/Linux & BSD
Mozek mouchy paří počítačové hry a obchoduje na burze
Vědci z Googlu dokončili mapu všech neuronových spojení v mozku (tzv. konektom) samečka mušky octomilky obecné (drosophila melanogaster), hlavním cílem je komparativní analýza s již zmapovaným mozkem samičky. S tímto veřejně dostupným modelem, čítajícím přibližně 160 000 neuronů, se začali bavit nadšenci. Mozek mouchy pohání experimentálního kryptoburzovního bota Stonkfly, případně si zahrál počítačové hry Beat Saber, Mario64 a samozřejmě DOOM (gameplay videa). Ani mozek samičky nezůstal stranou, vyzkoušel si Minecraft.
Kategorie: GNU/Linux & BSD
- « první
- ‹ předchozí
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- …
- následující ›
- poslední »



