Agregátor RSS

Trezor: 347,000 users targeted in phishing attacks after Brevo breach

Bleeping Computer - 11 Září, 2026 - 09:55
Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link. [...]
Kategorie: Hacking & Security

Apple zdražil starší iPhony. Někteří prodejci je ale stále nabízí za původní ceny

Živě.cz - 11 Září, 2026 - 09:45
Apple společně s novými iPhony zdražil i ty starší • U základních modelů řad iPhone 16 a iPhone 17 je cenový nárust tři tisíce • U doprodejů iPhonů Air za staré ceny můžete výrazně ušetřit
Kategorie: IT News

Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

The Hacker News - 11 Září, 2026 - 09:31
Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz said in a report. Wiz saw the attacks between August 15 and September 8. JFrog had fixed both flaws before then, so only servers that had not been updated were open to them. Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

The Hacker News - 11 Září, 2026 - 09:14
A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital said in research published Thursday. The attack started with a crafted link and ended with the attacker able to do anything the logged-in user could do. Tencent, which owns Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Conti ransomware gang member sentenced to 4 years in prison

Bleeping Computer - 11 Září, 2026 - 08:48
A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022. [...]
Kategorie: Hacking & Security

PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws

The Hacker News - 11 Září, 2026 - 08:46
PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download. "These are Regular Maintenance Releases (MR) that Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Slevy až 40 % na vysavače Roborock. K vlajkovému modelu Saros 20 dostanete příslušenství za další čtyři tisíce

Živě.cz - 11 Září, 2026 - 08:45
Roborock zlevnil robotické vysavače až o 40 %. • Nejvyšší model Saros 20 je za 25 899 Kč, v ceně je i bohaté příslušenství. • Má vysoký výkon, dosáhne do rohů, je nízký a přejede i vysoké prahy.
Kategorie: IT News

Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

The Hacker News - 11 Září, 2026 - 08:19
Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypassRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Takhle v noci nepulzuje ani Praha. Vytvořili jsme unikátní časosběrnou animaci veřejné dopravy v Brně

Živě.cz - 11 Září, 2026 - 07:45
Brno zveřejnilo sedmidenní archiv poloh všech vozidel, která operují v systému jihomoravské veřejné hromadné dopravy IDS JMK. Programátoři si mohou stáhnout surová data ve formátu Apache Parquet z městského datového portálu a brněnští dataři se na sociálních sítích zároveň pochlubili skvělou ...
Kategorie: IT News

Podíl Intelu na Amazonu stoupl na 21,3 %. Patrně jen dočasně

CD-R server - 11 Září, 2026 - 07:40
Některá média zaujal pozitivní posun podílu Intelu v prodejích procesorů na Amazonu. Cenová historie však ukazuje, že jde o důsledek krátkodobé akce, která již skončila…
Kategorie: IT News

Hry zadarmo, nebo se slevou: Výprodej série Call of Duty a vojenská arkáda zdarma

Živě.cz - 11 Září, 2026 - 07:10
Na všech herních platformách je každou chvíli nějaká slevová akce. Každý týden proto vybíráme ty nejatraktivnější, které by vám neměly uniknout. Pokud chcete získat hry zdarma nebo s výhodnou slevou, podívejte se na aktuální přehled akcí!
Kategorie: IT News

Švýcarsko testuje přechod z Microsoft 365 na FOSS

AbcLinuxu [zprávičky] - 11 Září, 2026 - 04:35
Švýcarsko testuje přechod z Microsoft 365 na FOSS, konkrétně balík openDesk (Wikipedie) od německé státní společnosti ZenDiS (Wikipedie), s cílem posílit digitální suverenitu.
Kategorie: GNU/Linux & BSD

LibreOffice Conference 2026

AbcLinuxu [zprávičky] - 11 Září, 2026 - 04:25
V italském městě Pordenone probíhá LibreOffice Conference 2026. Zúčastnit se lze i online.
Kategorie: GNU/Linux & BSD

Automattic CEO Matt Mullenweg is out: Does this mean long-term viability, or liability, for WordPress customers?

Computerworld.com [Hacking News] - 11 Září, 2026 - 02:52

Automattic CEO Matt Mullenweg has been abruptly put on a paid leave of absence from the company by its board of directors, despite his objections. But enterprise IT executives who rely on WordPress may find the shift doesn’t mean much as long as Mullenweg fully controls WordPress.org, which handles all of the product’s patches and updates.

“The part of WordPress that actually keeps enterprise IT up at night isn’t Automattic’s org chart. It’s WordPress.org, the plugin and theme directory every WordPress site pulls its security updates from, and the WordPress trademark,” said Frank Dickson, principal analyst at Dickson Research. “Mullenweg owns and controls both personally, outside of Automattic, and nothing about this week’s vote touches that. He also remains a director on Automattic’s board. The company changed who runs its hosting business without changing who controls the distribution pipeline millions of those hosted sites still depend on.”

For IT leaders who rely on WordPress, it’s important to differentiate what is currently known about the change and what is speculation. A statement emailed to Computerworld from Automattic merely said: “Matt Mullenweg is currently on leave from Automattic. Mark Davies, Automattic’s CFO, will lead the company as interim CEO. The Board has full confidence in Mark’s leadership and in the team’s ability to execute against the company’s priorities.” 

However, messages from Mullenweg to Automattic employees made it clear that the move was one that he strongly opposed. He posted on his X account, “the next step in this playbook is to restart the smear attacks, so get ready for some National Enquirer rumors or hit pieces.”

He added: “I appreciate the hundreds of colleagues who have already expressed public and private support, and are organizing in solidarity. It’s a big help to counter the ‘Matt is an idiot and shouldn’t run an ice cream stand’ allegations. Also, whatever you can say about me, I’m direct and probably overcommunicate, which I’m going to continue doing through this mess folks have made.”

He also posted separately that he is looking to hire, but that applicants cannot be current Automattic employees. “I really need some great sysadmin and security researchers to hire really quick, no one from @automattic. I’m on the board there and fully support Mark Davies in his interim CEO role. But I think it’s probably good if I move some of my stuff currently hosted there, elsewhere.”

Next steps unclear

What is unclear are likely next steps. Is the leave permanent or temporary? And if temporary, how temporary? Is the board negotiating with Mullenweg, and might those negotiations involve whether Mullenweg continues to control WordPress.org? Neither Automattic nor Mullenweg provided clarification.

Melody Brue, analyst-in-residence at Moor Insights & Strategy, who has closely tracked WordPress for years, said that the apparent speed of Mullenweg’s removal as Automattic CEO suggests that the board was trying to sidestep something serious.

“It has to be some exposure or risk that was severe enough that speed outweighed any optics or fairness. Boards don’t generally move that abruptly,” she said. The appointment of the CFO as interim CEO “definitely shows some stabilization and possibly some legal compliance cleanup. What it doesn’t say is renewed product investment.”

IT worried about instability

But the longstanding worries among CIOs about WordPress were not primarily about the perceived lack of continued investment. It was the concern that Mullenweg has a tendency to react strongly to a situation, apparently without many thoughts of the consequences

Nothing better illustrated this than Mullenweg’s personal war with WordPress hosting provider WP Engine that resulted in a series of legal rulings in WP Engine’s favor. 

WP Engine litigation is still ongoing, and that may have played a role in the board’s actions. 

Part of that lawsuit is at the heart of enterprise IT concerns: Mullenweg had denied WP Engine access to WordPress.org resources, including patches, plugins and security updates for the software. 

The IT fear is that Mullenweg could unilaterally take similar actions against any customer, even an enterprise. 

“I would still treat this as vendor risk, because WordPress.org is still controlled by Matt, separate from Automattic,” Brue said. “The question is, who actually controls the plugins that these IT leaders rely on? It’s still a structural risk. Look at whether the patches flow through one person. For now, they still do. Is that pipeline protected by independent governance, oversight? That is what matters for enterprise IT.”

Flavio Villanustre, CISO at the LexisNexis Risk Solutions Group, agreed. 

“Most of the concerns from enterprises about using WordPress come from the fragmented ecosystem and the inconsistent security controls and support of modules and extensions, which have led to significant vulnerabilities in the past,” Villanustre said. “The change of CEO in their parent company won’t directly affect this, especially because Matt Mullenweg will continue as the WordPress[.org] leader anyway.”

Dickson also agreed, noting that the question of who sits in the CEO seat at Automattic was not the issue.

“The enterprise IT concern was never really about Automattic’s management bench. It was about one person holding unilateral, unaccountable control over a piece of critical open-source infrastructure,” he said. “In 2024, Mullenweg used exactly that control to cut WP Engine’s customers off from plugin and theme updates overnight, with no board sign-off and no customer input, purely as leverage in a business dispute. This week’s vote proves a board can restrain him inside Automattic. It says nothing about what restrains him at WordPress.org, because the honest answer is still nothing.”

In fact, rather than reducing those IT worries, Dickson argued that this move could worsen them. 

“If anything, this should sharpen the concern rather than settle it. A board just decided it couldn’t function with him running a corporate entity with ordinary fiduciary obligations,” he pointed out. “That same person still holds sole authority over the update pipeline for software that runs over 40% of the web. Risk teams that were nervous about concentration risk in WordPress now have a fresh, concrete data point: the concentration is real, and untouched by whatever just happened at Automattic’s board table.”

This change could help

Mike Wilkes, enterprise CISO at Aikido Security, interpreted the events differently, and suggested that it might indeed make WordPress look more attractive to enterprise IT.

“This could ultimately make WordPress more attractive to enterprise buyers, but only if it becomes the beginning of stronger institutional governance rather than simply a change in personalities,” he said. “CIOs don’t particularly care about palace intrigue until that intrigue can affect software updates, supply-chain dependencies or business continuity. The WP Engine conflict demonstrated that governance risk can become operational risk surprisingly quickly. The ongoing litigation underscores that this is not merely historical baggage.”

Wilkes pointed out that the next few steps taken by the board and by Mullenweg will likely be far more informative than any analysis of the board’s CEO change.

“I wouldn’t tell a CIO that yesterday’s announcement makes WordPress either safer or riskier today. I would tell them to watch what happens next,” he said. “If Automattic uses this moment to create clearer separation between corporate interests, WordPress.org infrastructure, and community governance, it could reduce one of the ecosystem’s most persistent concentration risks. If the same authority simply migrates to different individuals without structural reform, enterprise concerns haven’t really changed. In cybersecurity terms, replacing the administrator isn’t the same thing as eliminating the single point of failure.”

Dylan Forde, owner of Harmonic Design in Oakville, Ontario, Canada, and a WordPress developer for more than ten years, applauded the CEO change. 

“It is my opinion that the removal of Mr. Mullenweg is a good thing for both the WordPress community and open source,” he said. “He has been divisive for a long time, with many grievances that I overall understand, but I oppose his responses to. It sucks to build something used by millions of people and businesses around the world, all profiting off your work while giving nothing back. But cutting off and targeting individuals is not the answer. Open source is supposed to work for everyone, and my assumption is that anyone whose core business relies on WordPress will be sleeping easier now.”

Kategorie: Hacking & Security

[remote] CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22, 10.0 < 10.10, 11.0 < 11.3 - RCE

The Exploit Database - 11 Září, 2026 - 02:00
CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22, 10.0 < 10.10, 11.0 < 11.3 - RCE

Latest Anthropic horror story chills with tales of kamikaze drone swarms and bioweapons research

The Register - Anti-Virus - 11 Září, 2026 - 00:38
In the latest installment of "my AI model is more dangerous than yours," Anthropic on Thursday warned that cybercriminals and state-sponsored hackers alike are using its Claude models to automate cyberattacks, build kamikaze drone swarms, conduct mass surveillance operations, and try to develop an even more dangerous version of a deadly mosquito-borne virus. The baddies have come a long way since November, when an earlier Anthropic report documented Chinese spies using Claude to automate digital intrusions and steal sensitive data at a handful of critical organizations. Now everyone from ShinyHunters to Russian freelancers is getting in on the illicit model usage. This is not to say that Anthropic – nor any other frontier AI lab – plans to slow down its model development or testing initiatives, or take responsibility when its AI commits crimes. It does, however, “hope that the findings in this report will help other developers recognize similar patterns on their own platforms, give governments and civil society a clearer view of how emerging threats take shape, and strengthen collective defenses.” The model maker’s latest very lengthy report on AI misuse covers activity Anthropic disrupted between December 2025 and August 2026 across seven “harm areas” where miscreants used – or attempted to use – Claude Haiku, Sonnet, and Opus models for evil. These span cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation. Anthropic also noted that its most powerful Claude Fable or Mythos-class models weren’t used, except in one distillation case. Even without those most advanced systems, the case studies in the report highlight some pretty bad behavior. Autonomous cyberattacks For example, a Russian espionage crew that Anthropic tracks as GTG-20006 – the state-sponsored cyber espionage arm of Russia’s Foreign Intelligence Service (SVR), also known as Midnight Blizzard, APT29, or Cozy Bear – increased the speed of its attacks by using AI to automate the entire kill chain. Anthropic identified more than 20 organizations targeted in these attacks, including embassies, think tanks, defense-industrial companies, and government, defense, and intelligence agencies across Ukraine, Europe, the Middle East, Asia, and North Africa. “We observed GTG-20006 operate through customized AI-driven workflows that automated much of their operations from development, infrastructure acquisition, phishing, persistence through command and control, to data exfiltration,” Anthropic said. Meanwhile, “multiple clusters” linked to the data-theft-and-extortion gang ShinyHunters used Claude to scale their smash-and-grab operations. One affiliate that specializes in supply-chain attacks breached a software-as-a-service provider, and used that foothold to steal data from about 200 of the SaaS company’s customer organizations. “It then conducted a session-store dump containing over 2,100 Azure AD token sets spanning more than 40 corporate tenants in about 34 hours,” according to the report. “AI agents performed nearly all of the work.” Biological misuse Moving on to a serious health-and-safety risk that looks even scarier when given an AI boost: Anthropic’s report documents five cases of users in “unsupported regions” using Claude to support biological weapons development. In one, a scientist attempted to use Claude to help write a grant application for research related to chikungunya virus, a mosquito-borne virus that can cause severe disease and death. The research focused on the virus’ transmissibility and immune evasion properties, which Anthropic admits could be used to help develop better vaccines. Or “it could also be used to make the pathogen more dangerous,” the report authors said, noting that the military research institute where the research would be performed gave them “cause of concern.” In May, Anthropic discovered a user outside the US using Claude in their research on adaptations of highly pathogenic avian influenza – bird flu. “Unlike other influenza variants, H5 viruses (of which this avian virus is one) often show striking brain involvement in cats, foxes, ferrets, and some human cases,” the report says. “A pandemic variant with such properties would be especially concerning due to its potential to increase disease severity, confuse diagnosis, and hinder treatment.” Weapons development Since its November report, Anthropic has identified new categories for Claude misuse that violate its terms of service. One of these involves users outside the US using Claude to develop software for conventional weapons – firearms, missiles, armed drones, bombs, and other munitions, plus targeting and control systems that operate them. In its new report, the model maker shares details on six cases: three in China, two in Russia, and one in Yemen. In Yemen, a weapons development program used Claude instead of human software engineers to develop guidance, navigation, and control (GNC) software that steers and stabilizes a flying vehicle. “Our safeguards blocked many of their requests, but not all of them,” Anthropic says. The same team used Claude to try to develop guided weapons. While Anthropic says it has no evidence that the actors produced an operational device, it says they did test-fire a guided rocket. “We banned accounts associated with the actors and shared threat information with public- and private-sector partners to mitigate risks posed by the actors,” the report says. “Nevertheless, we have evidence that the actors had already built an offline simulation toolkit that does not rely on Claude or other engineering computing environments.” In China, someone used Claude to draft a Chinese-language specification for an anti-torpedo fire control system, and then benchmark their system against specific US anti-torpedo and anti-submarine programs. Anthropic assesses that the user was associated with a Chinese defense industry manufacturer aiming to produce a weapons specification and acquisition proposal for the People's Liberation Army Navy. According to the report: The actor used Claude to write the acquisition proposal, refining it over many drafts. After each draft, the actor instructed Claude to role-play a hostile expert reviewer to critique the proposal, then used that feedback to sharpen the next version. In parallel, the actor used Claude to build pieces of the anti-torpedo weapons system’s fire control software and a test matrix to validate them. Anthropic uncovered this during an internal investigation into suspected weapons development and banned the account. In yet another case, Anthropic identified a likely Russian “freelance team” attempting to build a full-stack autonomous first-person-view (FPV) kamikaze drone swarm. They used Claude to write and test the code, building the drones’ core software system. Anthropic also banned these accounts. ®
Kategorie: Viry a Červi

Komerční banka mění ceny a podmínky. Spustí podporu okamžitých SEPA plateb, ale jen pro příjem

Lupa.cz - články - 11 Září, 2026 - 00:00
Komerční banka od listopadu mění ceny a podmínky svých služeb. Sníží hranici, od které účtuje příplatek za zpracování hotovosti, zavede poplatek za nevyzvednutý objednaný výběr a umožní příjem okamžitých SEPA plateb. Změny se týkají i karet, inkasa nebo firemních účtů.
Kategorie: IT News

Kybertest vás naučí rozpoznat typické online podvody. Sám však obsahuje několik chyb

Lupa.cz - články - 11 Září, 2026 - 00:00
S nadšením jsme se do Kybertestu pustili a nedopadlo to dobře: na 100 % jsme jej neudělali. Při příliš pečlivé kontrole totiž můžete paradoxně přijít o body. V jedné z úloh je chybně uveden název České pošty a sporná je i url adresa fiktivní banky. Nepřesnosti jsme našli také v doprovodných textech.
Kategorie: IT News

Nezávislost, kontinuita a obava o data: Švýcarsko na cestě od Microsoftu

ROOT.cz - 11 Září, 2026 - 00:00
Digitální suverenita, snížení či eliminace závislosti na jednom dodavateli, který navíc neručí za dodržování GDPR a snahy o finanční úspory, to vše spojuje všechny snahy o přechod k otevřeným alternativám.
Kategorie: GNU/Linux & BSD

Chystá se nová GeForce RTX 5070, místo GPU GB205 ponese ořezané větší GB203

CD-R server - 11 Září, 2026 - 00:00
Nvidii patrně na skladě leží defektní čipy GB203 v množství větším než v malém, a tak hledá řešení, jak je udat. Tím by nakonec měla být nová verze GeForce RTX 5070…
Kategorie: IT News
Syndikovat obsah