Agregátor RSS

Microsoft disrupts AI-assisted platform that compromised 12,000 accounts

Ars Technica - 22 Září, 2026 - 21:45

Microsoft said Tuesday that it led an industry-wide disruption of a subscription-based scam platform that used an AI chatbot to compromise 12,000 Microsoft accounts over a few-month span.

Named EvilTokens, the platform was introduced over a Telegram channel in February and charged an initial $1,500 fee and a recurring $500 charge each month after that. EvilTokens provided a single service for streamlining most steps required to compromise email accounts in large numbers. From there, the platform helped customers analyze inboxes, select targets that would provide the biggest potential payouts, and draft follow-up emails that provided realistic ruses for tricking company employees into transferring funds to attacker-controlled accounts.

Minutes, not days

“While EvilTokens helped cybercriminals access email accounts, at the center of the service was an AI-style chatbot that could analyze a victim’s inbox and help criminals identify trusted relationships, payment authorizations, and sensitive responsibilities, as well as other circumstances where fraud was most likely to succeed,” Microsoft said. “The platform could even recommend fraud strategies, including drafting messages that impersonated trusted contacts to help criminals trick victims into taking action.”

Read full article

Comments

ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

Bleeping Computer - 22 Září, 2026 - 21:13
The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants. [...]
Kategorie: Hacking & Security

Three-Year-Old Boy’s Metastatic Cancer Disappears After Two Shots of Experimental Cell Therapy

Singularity HUB - 22 Září, 2026 - 20:41

The boy, whose liver cancer had spread to his lungs, suffered no dangerous side effects and remained cancer-free a year later.

At just three years of age, the boy had already been through the medical ringer.

A tumor roughly the size of a large orange had invaded his liver and spread to his lungs. Multiple surgeries and rounds of chemotherapy temporarily cleared the cancer. But it rapidly came back.

With few options left, his parents enrolled him in an experimental CAR T cell therapy trial. The approach, which involves genetically reprogramming immune cells, has transformed the treatment of stubborn blood cancers. But when it comes to solid tumors, including liver cancer, CAR T has fallen frustratingly short.

The trial, run by Baylor College of Medicine in Texas and collaborators, is testing CAR T cells specifically engineered to hunt down and destroy cancer hidden in organs. The cells carry genes that help them grow and persist and a “kill switch” to rein them in. They’ve shown promise in mice, but treating a toddler, already weakened by grueling interventions, was a gamble.

It paid off. After two infusions of CAR T cells made from the boy’s own immune cells, his cancer disappeared. A biomarker associated with liver cancer plummeted, and he experienced no dangerous side effects. A year later, he remained cancer-free. The story of his recovery was published this month in the New England Journal of Medicine.

Although it’s just a single clinical case, the results show “a durable complete response in a chemotherapy-resistant solid tumor can be achieved entirely in the outpatient setting without systemic toxicity,” study author David Steffin at Texas Children’s said in a press release.

If the benefits hold up in other patients—including those with larger or faster-growing tumors—the approach could help banish several types of solid tumors that have so far evaded treatment. The trial is actively recruiting participants between one and 21 years old, with an initial goal of testing up to 30 people. If successful, it could change the course of many lives.

Broader Aim

Solid cancer has long been CAR T’s nemesis.

The treatment reprograms a patient’s immune cells to recognize and attack cancer cells. In current FDA-approved therapies, doctors extract T cells from a patient’s blood and genetically equip them with “hooks” that latch onto targets, known as antigens, on the surfaces of certain cancer cells.

A brief round of chemotherapy then depletes the patient’s existing immune cells, making room for the enhanced ones. Once infused back into the body, CAR T cells find and kill their targets.

Scientists have steadily refined the technology. Some are developing ways to manufacture CAR T cells directly inside the body, potentially slashing time and cost. Others are pursuing a broader goal: Solid cancers. These account for roughly 85 percent of cancer diagnoses, but they’re notorious for slipping past first-generation CAR T cells.

Part of the reason they’re so evasive is solid cancers often carry multiple types of antigens. Targeting just one can leave behind residual cancer cells that eventually regrow. And unlike cancerous blood cells, which freely roam our bloodstream, solid tumors are buried inside organs and surrounded by healthy tissue. CAR T cells have to tunnel through this physical barrier.

Tumors also pump out a menagerie of chemicals that reshape their local environment. Some spur their expansion; others protect them from immune cell attacks—including CAR T—by depriving the cells of signals and nutrients they need to survive.

With their new CAR T cells, the Baylor team tackled several of these shifty maneuvers at once.

Gen 2.0

Finding the right antigen was the first hurdle. Previous work showed glypican-3, or GPC3, fit the bill. This antigen coats several types of cancer cells—including the boy’s hepatoblastoma—spurring them to grow out of control. But the protein is hardly present in healthy cells, making it an appealing target.

GPC3-targeting treatments have already had some success. Two clinical trials using antibodies found that inhibiting the protein is relatively safe in patients with an advanced form of liver cancer. But the antibodies struggled to reach deeper, hidden cancer cells, and the patients didn’t completely recover.

CAR T cells, in contrast, can move through dense tissues. In mouse models of liver and lung cancer, GPC3 CAR Ts safely slashed their cancer burden, while a small clinical trial in people with liver cancer backed up those safety findings.

To give their CAR T cells a better chance in the cancer chemical wasteland, the team added two more functions to the original GPC3 CAR T recipe. One genetic alteration equipped them to make IL-15 and IL-21, molecules that help the cells survive and expand. The second added a “kill switch” for safety in case the cells expand out of control. Once activated by a drug, they self-destruct without harming nearby tissues.

All these upgrades resulted in a therapy that gave the toddler and his family hope. His tumors—both the original hepatoblastoma and ones that had spread to his lungs—tested positive for GPC3.

He received two CAR T infusions made from his own cells, eight weeks apart. Neither infusion required a hospital stay. After the first dose, the liver tumor shrank, suggesting a partial response. After the second, imaging showed tumors in both organs disappeared and stayed away at least a year.

“This marks a durable, 12-month disease-free status,” wrote the team.

The cells worked fast and stuck around. By four weeks, they had already infiltrated his liver, and signs of the engineered cells remained detectable in his blood nine months after treatment. Despite the risk of side effects, such as neurotoxicity or a potentially deadly runaway immune activation, the boy never experienced serious toxicity from the treatment.

But results in one child aren’t enough to know whether the cells will work for others. And his case may be unusual. CAR T cells naturally swarm the liver and lungs after infusion into the bloodstream, which might have been especially helpful. More follow-ups will also be needed to track long-term risks, such as the engineered cells expanding out of control. If that happens, can the built-in kill switch rein them in?

Still, the results are a proof of concept for a strategy that could overcome some solid tumor defenses. Given liver cancer is the third leading cause of cancer-related deaths around the world, the therapy could make a substantial impact. A related trial using similarly engineered cells is also underway.

The post Three-Year-Old Boy’s Metastatic Cancer Disappears After Two Shots of Experimental Cell Therapy appeared first on SingularityHub.

Kategorie: Transhumanismus

Trump v OSN přejmenoval umělou inteligenci. Zbavil ji fake jména AI, dal jí už obsazené

Živě.cz - 22 Září, 2026 - 20:35
Americký prezident Donald Trump dnes na Valném shromáždění OSN oznámil, že přejmenovává umělou inteligenci. Místo AI, tedy artificial intelligence, se má nově používat zkratka SI. Písmeno S v ní znamená „super“. Podle Trumpa slovo „umělá“ působí, jako by technologie byla falešná. „Od této chvíle ...
Kategorie: IT News

Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

The Hacker News - 22 Září, 2026 - 20:29
Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server's web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server that controls firewall policies for the Check Point Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

New ClosedQuorum Windows malware uses AI for attack decisions

Bleeping Computer - 22 Září, 2026 - 20:04
A new Windows malware named ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously determine the actions to take during post-compromise stages of an attack. [...]
Kategorie: Hacking & Security

WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

The Hacker News - 22 Září, 2026 - 20:03
WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders. On some servers, that can go further, allowing the attacker to run their own code. The fix shipped on September 22 in WordPress 7.1.2, with fixes for every branch the project still supports, back to 4.7, and WordPress is telling site owners Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials

The Hacker News - 22 Září, 2026 - 19:58
Cybersecurity researchers have disclosed details of a malicious npm package named "tw-pkgprobe-7731" that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data. The package, named "tw-pkgprobe-7731," was first uploaded to the npm registry in mid-August 2026 by an npm account named "twdepprobe7731." Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

ShinyHunters claims FBI hack: 'This is NOT financially motivated'

The Register - Anti-Virus - 22 Září, 2026 - 19:24
ShinyHunters claims it hacked the FBI and stole more than 2 TB of employee data - and this time it’s personal. The gang wants the Feds to correct the record on how it operates. “This is NOT financially motivated,” a Shiny spokesperson told The Register. “We want the FBI to correct or retract their statements they made, which included substantial false allegations.” The FBI did not immediately respond to The Register’s request for comment. According to a ShinyHunters spokesperson, the extortion group exploited an Oracle PeopleSoft zero-day vulnerability on the FBI jobs webpage, which it says allowed remote code execution (RCE) on the servers. The group then defaced the website, replacing it with a “This site has been seized by ShinyHunters” banner and image shared with The Register. At press time, the site says it is “currently down for maintenance but will be back up soon!” ShinyHunters also claims it moved laterally from the compromised site onto the FBI’s managed servers on AWS GovCloud, and downloaded about 2 TB to 3 TB of data belonging to current, former, and prospective FBI employees. “We hold data on all FBI employees and applicants,” the spokesperson told us. ShinyHunters claims the compromised FBI services include human resources, MedLink, and Criminal Justice Information Services. Neither Oracle nor AWS immediately responded to our inquiries, including whether Oracle is aware of a PeopleSoft preauth RCE zero-day, and whether AWS has any insight into the alleged data theft. We will update this story if we receive any response. Unlike most of the group’s smash-and-grab operations that involve a multimillion-dollar ransom demand to not leak the stolen files, ShinyHunters said it isn't seeking an extortion payment from the FBI. Instead, it wants the federal cops to retract statements made about ShinyHunters in a May 15 bulletin, shortly after the gang broke into ed-tech giant Instructure's Canvas platform and claimed to have stolen data tied to hundreds of millions of students, teachers, and staff. The FBI said ShinyHunters uses “harassment strategies, sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting.” The security alert also said that extortionists “may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist.” Shiny claims none of this is true. “I have been doing my very best to combat these allegations,” they told us. “And this is the best way to do it.” ®
Kategorie: Viry a Červi

Reducing shadow IT visibility gaps with Wazuh

Bleeping Computer - 22 Září, 2026 - 19:17
Shadow IT can leave security teams unaware of unmanaged endpoints, unauthorized software, and other assets that fall outside existing monitoring. Wazuh explains how endpoint inventory, agentless monitoring, and centralized analysis can help organizations identify and reduce these visibility gaps. [...]
Kategorie: Hacking & Security

Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises

The Hacker News - 22 Září, 2026 - 19:03
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack chain." The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the efforts of Health-ISAC, alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The ShadowserverRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Review: M5 Ultra Mac Studio: Pure, unadulterated power

Computerworld.com [Hacking News] - 22 Září, 2026 - 18:56

I’m old enough to remember when Macs were friendly little machines. While a little underpowered and equipped with some platform-unique foibles, they were really good at some things, highly secure, and had the best user interface of any PC. 

That was then; this is now. And while the platform is still unique, still highly secure, and still has the best user interface, Apple’s all-new Mac Studio is a beast of a machine. It’s incredibly powerful and would crackle with energy if it weren’t so energy efficient. 

TL;DR review

No matter what pro workflow you follow, the M5 Ultra Mac Studio is more than you need.

Longer review

Apple hasn’t changed the design of the Mac Studio.

It’s 7.7-inch square, 3.7-inch high aluminum box with two USB-C and one SDXC port on the front, and an array of ports — four Thunderbolt 5, two USB A, 10Gb Ethernet, HDMI, and headphone — at rear. It brings Wi-Fi 7 and Bluetooth 6, supports up to eight displays with up to 6K resolution at 60Hz, or four Studio Display XDR units. 

Basically, this one box can power a bank of displays, and for those using it in a live video production environment, Apple has also introduced generator locking (a.k.a. genlock) over USB-C, which lets the on-display image synchronize precisely with a pro video camera for the most precise editing and playback you’ll find. 

Pros and cons

Pros

  • Massive CPU/GPU power capable of handling the most demanding 3D and AI tasks.
  • Neural accelerators and unified memory make it ideal for training and running large LLMs on-premises privately.
  • Doubled read/write performance over the previous generation via a new storage controller and fast NAND.
  • Inclusion of four ProRes accelerators (handling up to 33 streams of 8K) and genlock over USB-C for precise sync.
  • High performance at low wattage; runs quiet and cool compared to high-end PC alternatives.
  • Features Thunderbolt 5, Wi-Fi 7, and Bluetooth 6.
  • Works exceptionally well as a headless AI or rendering server.

Cons

  • Extremely high retail price ($12,299 for the top spec).
  • Neither the RAM nor the SSD can be upgraded or replaced by the user.
  • No keyboard or mouse included, which feels odd for a five-figure machine.

For my review, Apple loaned me a top-of-the-line M5 Ultra Mac Studio equipped with a 36-core CPU and 80-core GPU. It has 256GB memory, 4TB storage, and carries a retail price of $12,299. At that price and with those specifications, it is of little surprise that this is such a great computer.

It’s also intended for some of the most demanding 3D and AI tasks you’ll find out there, rather than for people who spend their time writing about tech — though this machine can open multiple tabs in Chrome without stuttering, so unleashes real productivity boosts even at my level. 

Apple Let’s get one thing out the way

That’s not to say some pro users lack reservations about it. Many are frustrated that neither the RAM nor SSD are user serviceable, while the lack of a keyboard and mouse in the box chimes oddly in a computer that costs five figures.

In Apple’s defense, in these pro markets most users probably already own better keyboards and mice than you’d find in the box, while the massive performance benefits you’ll find with the M5 Ultra chip are in part realized because RAM in Macs is built to be part of the processor itself.

That SOC design boosts efficiency, cuts heat dissipation, and makes for great performance at low wattage relative to other machines. Changing the way memory is installed on the chip would compromise Apple’s silicon architecture, which Apple doesn’t want to do. 

It’s all about the architecture

The Mac is powered by a quad-die chip built using Apple’s UltraFusion process. Inside is an engineering marvel. The 80-core GPU brings neural accelerators, making these Macs truly phenomenal machines for building, developing, training, or running AI models. Apple’s unified memory tech is a godsend for tasks like these as it scales to handle… well, most anything you throw at it. Efficiently. 

Apple’s coupled chip speed with performance across the system. That means an advanced storage controller, superfast NAND, and really fast, next-gen SSDs for twice the read/write performance of the last model. This basically means the chip can grab big dollops of data and very swiftly push them around the system all the way from storage to display. Then there’s the rest of the advanced tech to consider, including the inclusion of four ProRes accelerators, which means my test Mac can deal with up to an incredible 33 streams of 8K ProRes video. 

This is a machine that can happily handle massive multi-camera editing, racing through dozens of high-res angles at once to field the perfect shot. Think live sports, concerts, and movie shoots. Not only this, but all those streams are at normal res, no conversion required — no sitting around waiting for low-quality proxy files. 

Apple A bicycle for several minds

I’m thinking a full-flight video rendering data server in an 8-inch box that consumes perhaps 10 cents an hour at peak power (c. 480 watts). I’m also thinking of it as an on-premises AI system for me, the family, or any enterprise. 

Compared to the previous equivalent mode, the M3 Ultra, Apple says the chip brings up to 4.3x faster AI performance, up to 1.8x faster GPU performance, and up to 1.3x faster CPU performance. It’s also almost ten times faster than the M1 Ultra for AI.

None of this is accidental. All of it is designed. This whole creation is architectural; it leans heavily into Apple’s software and hardware integration, which now also extends to the design of the processor itself. Making the RAM user-serviceable would limit the performance of the machine, which at this price and in this sector of the market seems a little counterintuitive.

Sure, you can build yourself something pretty powerful using a Ryzen 9 chip that consumes 900 watts at peak and runs hot. Or you can put Apple’s silver box on your desk and barely hear a thing as it crunches through ‘god tier’ AI models your Ryzen can’t handle without additional GPU’s. All the same, if you want to configure your own memory you do have a choice — it’s just not a Mac. 

Choice is nice

I know what I’d choose. Based on a weekend of using the Studio, I’ve found what it does is beyond most of the feeble tests mere mortals like me can cook up, so I thought you might want some benchmarks:

Geekbench 7

  • Single-core CPU: 3,771
  • Multi-core CPU: 52,350
  • GPU (Metal): 360,019
  • GPU (OpenCL): 214,466

Cinebench

  • CPU (Multi-thread): 18,052
  • GPU: 141,480

Putting these numbers into context, Apple explains what these numbers mean when compared to the M1 Ultra Mac Studio: 

  • 2.4x faster project builds in Xcode
  • 4.7x faster render performance in Redshift
  • 9.8x faster time to first token performance in LM Studio
  • 15.4x faster CopyCat ML training in Foundry Nuke
Storage is fast, really fast

Of course, with these machines built to work with and manipulate huge files, one roadblock to performance will be storage, right? Not on this Mac. Apple says it has deployed a new storage controller tech in the computers, which works with the speediest NAND memory it could find to deliver twice the read and write performance we got from the last generation of this system. 

This gives it plenty of horsepower for flinging files about, with Blackmagic’s Disk Speed test giving me exceptional results: 13,941MB/s write and 11,350MB/s read speeds. These speeds are indeed double the performance of the previous generation. 

It also means this Mac Studio can handle data transfers faster than almost anything out there, making it happy to handle multiple streams of uncompressed 8K RAW video, heavy compositing workloads and, of course, AI development, machine learning, or running your own on-premises AI models. Install the models you want to use and use them to your heart’s content. Run it headless if you like. I did.

Apple Headless, no hanging

I know a lot of you will end up wanting to run some kind of headless setup using this Mac. You’ll have it working furiously as your domestic or business AI server, chewing through your data, vibe coding opportunistic app creations, rendering video off your main Mac, and more. In my own little experiment, I found myself typing sentences for this review (this sentence, actually) on a Mac mini using a keyboard on a MacBook that happens to have the Mac Studio in its active window over vnc, and nothing ran slow. It means that if you run this Mac headless, it’s no slouch.

Better yet, once you have the Mac set to run as a headless unit, you’ll be able to download LM Studio, install your choice of AI, and chat to your heart’s content. Your AI running privately and securely for you on your device, and — one more thing — it’s fast and responsive. What’s not to like? I used it to design and develop a capability test to put the Mac through its paces.

Apple’s focus on AI is strategic, of course. Apple knows its hardware has pretty much occupied the AI development space, to the extent that almost any LLM you use was probably at least in part made on a Mac. AI is up there with CAD and medical imaging among the most demanding tasks you can do on any PC, let alone a Mac. And these Macs can handle all those tasks. I did want to try stringing four of these Macs together to run as an AI cluster, but at $12,000+ each that wasn’t going to happen.

Buying advice

Most of us don’t need this Mac. We probably never will — which is why cost is not the point here. This Mac is about performance, full stop, and that shows at every layer: a faster processor, blistering SSD storage, unified memory that scales to the task, and a storage controller fast enough to leave most other PCs gasping in the dust. From the software to the silicon, it feels like Apple’s engineers raided every high-end tech they had and crammed it inside this good-looking silver box. 

The real question isn’t whether this Mac is impressive — it obviously is — but if it’s impressive enough to justify an upgrade if you already own the previous model. Things get a little more nuanced if that is the case. The M5 Ultra is a genuine step up: the processor gains are significant, and the storage speed increase alone will matter to plenty of pro workflows. But last year’s Mac Studio was already so far ahead of most computers that “significantly better than the best thing available” doesn’t automatically mean “worth $12,000+ to replace.”

My take: if you’re still on an older computer and need the extra processing power or storage throughput for demanding work, this machine delivers in spades. If you bought last year’s M3 Ultra model and it’s handling your workload fine, there’s no urgency. You’re not falling behind, you’re just not on the bleeding edge. All the same, I so wish AI-driven price inflation hadn’t pushed these systems quite so high in price.

Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSkyLinkedIn, or Mastodon.

Kategorie: Hacking & Security

IT mistake erases 11 years of viewing history for hospitals’ maternity records

Ars Technica - 22 Září, 2026 - 18:55

A “human error” in the IT department led to Nottingham University Hospitals NHS Trust (NUH) losing data from maternity records over an 11-year span.

The data loss occurred on August 18, the English hospitals announced in a blog post on Monday spotted by The Register. The blog said the problem is “the result of human error” during routine technical work while “creating a copy of a radiotherapy database for reporting purposes.”

The post reads:

Read full article

Comments

AI pokořila 80 let starou nacistickou šifru. Naprogramovala si virtuální Enigmu a použila historické souvislosti

Živě.cz - 22 Září, 2026 - 18:45
Využití AI při řešení prachem zapadlých záhad má pokračování. Díky modelu GPT-6 Astra od OpenAI se podařilo rozluštit zprávu, jejíž obsah zůstával tajemstvím více než 80 let. Šlo o německý radiogram šifrovaný legendárním strojem Enigma. Zpráva označená jako MVUEH byla odeslána 10. července 1941 a v ...
Kategorie: IT News

Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

The Hacker News - 22 Září, 2026 - 18:41
A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

NightmareEclipse's latest zero-day leaves Microsoft Defender stuck in the past

The Register - Anti-Virus - 22 Září, 2026 - 18:36
Serial Microsoft zero-day leaker NightmareEclipse has found another way to mess with Windows Defender, this time by stopping the antivirus from updating itself. The security researcher, also known as Abdelhamid Naceri, released a proof-of-concept dubbed “BigDiskBuster” that is designed to prevent Microsoft Defender Antivirus from installing platform and security intelligence updates. “Made a funny tool, completely denies defender from updating so you're stuck with your current version if the tool is running in the background,” NightmareEclipse said. The researcher describes BigDiskBuster as similar to their earlier “UnDefend” tool and claims it works on all supported versions of Windows, although they admit the current PoC is “a bit buggy and needs some rewritting [sic].” That compatibility claim has not been independently verified. The trick doesn't disable Defender. Instead, the PoC waits for an update to start, then tries to fill up the drive so there isn't enough space for it to finish. The code does this by creating hidden temporary files sized to consume the drive's free space, spinning up additional threads as needed to claim more. Once it detects that the Defender update has failed, it closes the files and returns the space. BigDiskBuster also opens Microsoft's Malicious Software Removal Tool executable, MRT.exe, in a way that restricts other processes' access to the file while the handle remains open. The result, according to NightmareEclipse, is that Defender stays stuck on its current platform and security intelligence versions as long as the tool keeps interfering with updates. A screenshot published alongside the PoC shows Windows Security reporting that a protection definition update failed with error 0x80070643. That's a generic installation error, however, and isn't evidence on its own that BigDiskBuster is at work. Leaving Defender stuck on old security intelligence is obviously less than ideal. The antivirus may still be running, but preventing it from receiving Microsoft's latest threat definitions could leave it less able to identify newly detected malware. The steady stream of bugs from NightmareEclipse comes amid a very public spat between the researcher and Microsoft over the company's vulnerability disclosure process. The researcher began dumping Windows zero-days and proof-of-concept code in April, claiming Microsoft had mistreated them and cut off their access to its vulnerability reporting system. Redmond wasn't exactly thrilled. In May, Microsoft criticized NightmareEclipse for releasing vulnerabilities without giving it a chance to fix them first, saying none of the initial bugs had been reported through its official channels. The company also invoked its Digital Crimes Unit, saying it would pursue cases against people engaged in malicious activity or enabling cybercrime – language widely interpreted as a threat of legal action against the researcher. That went down about as well as you'd expect with the security community. Microsoft subsequently walked back the rhetoric, saying it had “no intention to pursue action against individuals conducting or publishing security research.” By then, however, NightmareEclipse's earlier GitHub account had also been taken down, along with access to Microsoft's vulnerability reporting portal. The peace offering didn't end the feud. NightmareEclipse continued releasing Windows exploits, including RoguePlanet in June, LegacyHive in July, ShieldBreak in August, and ShieldCrash in September. Several of the researcher's earlier zero-days have since been patched by Microsoft, while some were exploited in the wild after their public release. BigDiskBuster is a rather different beast. Rather than providing an obvious route to SYSTEM privileges, it interferes with one of the basic things antivirus software needs: updating itself. There’s currently no indication that BigDiskBuster has been used in real-world attacks, and NightmareEclipse's claim that it works across all supported Windows versions remains unverified. Redmond has not responded to The Register's questions. In the meantime, its Nightmare apparently shows no sign of ending.®
Kategorie: Viry a Červi

Check Point warns of Management Server zero-day exploited in attacks

Bleeping Computer - 22 Září, 2026 - 18:32
Check Point Software released emergency hotfixes to address a critical Security Management Server vulnerability that could let attackers run arbitrary scripts. [...]
Kategorie: Hacking & Security

Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates

The Hacker News - 22 Září, 2026 - 18:14
A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19. The tool, called BigDiskBuster, has no patch, no CVE, and no Microsoft advisory. Its author, Abdelhamid Naceri, is a former Microsoft security researcher whose earlier Defender exploits were used in Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Z.ai says sorry for slurping up your code, open sources ZCode

The Register - Anti-Virus - 22 Září, 2026 - 17:59
Chinese AI giant Z.ai has apologized after developers caught it pulling a Grok, packaging up and uploading user workspaces to cloud storage. In a case that’s highly reminiscent of the issues over which Elon Musk’s xAI was scrutinized in July, Z.ai’s code-generation harness wing, ZCode, was found packaging and git-encrypting entire user workspaces, including complete project histories, and shipping them off to Alibaba Cloud. Worse still, the private key used to decrypt the data was only held by the server under Z.ai’s control, meaning users could not access the files ZCode had uploaded, nor delete them. Ferstar, the researcher who first highlighted the issue, claimed there was no option for users to disable the behavior in their settings, and there was no disclosure of the practice in ZCode’s privacy policy. They said the core problem lay with the tool’s Repository Index functionality, which triggered the uploading of files after Repo Wiki generated pages in the cloud. ZCode released a statement on Monday apologizing for the “security issues” and confirming the data it uploaded had never been used to train its models. “We sincerely thank the community developers who previously identified issues in ZCode. Going forward, we will establish an ongoing product security vulnerability reporting and response process,” it Xeeted. “We welcome developers to continue reviewing ZCode and reporting potential issues, and we will provide rewards based on the severity of the issues reported.” ZCode said it tasked the China Academy of Information and Communications Technology (CAICT) and Beijing security company NSFOCUS to probe its product following the implemented changes. The company claimed the two outside assessments concluded that all the previously uploaded data has now been deleted and said the Repo Wiki feature was removed. ZCode also open sourced the entire project on GitHub, “placing the code under community scrutiny and making ZCode more open and transparent.” “Once again, we sincerely apologize and welcome continued scrutiny from the community. The full security assessment report will be released soon.” Ferstar confirmed the open sourced code showed no signs of the Repo Wiki still being implemented, but criticized the company for wiping commit records and the source code ZCode used to upload files pre-patch. For the uninitiated, Z.ai, formerly known internationally as Zhipu, is among the world’s AI heavyweights and one of the most heavily backed LLM-focused companies in China. It is the first AI company in the post-Gen AI era to launch and subsequently IPO on the Hong Kong Stock Exchange. Other Chinese AI giants are publicly traded, such as Alibaba and Baidu, but these were all established well before the AI era began. Z.ai is a startup with its roots in academic research. It spun out of Tsinghua University’s Knowledge Engineering Group research lab in 2019 and now develops AI models that it claims compete with the best in the West. Last month, the company claimed that its latest model, GLM-5.3, is as good as the most advanced equivalents developed by Anthropic and OpenAI at hunting for security vulnerabilities. Z.ai has also previously claimed the accolade of developing the first advanced model entirely on Chinese (Huawei) hardware. Meanwhile, the likes of Anthropic and OpenAI have reportedly expressed concern over the capabilities of models from Z.AI and Moonshot, while the US government mulls restricting access. ®
Kategorie: Viry a Červi

Jak dobře vybrat projektor. Vždy zkontrolujte rozlišení a nečekejte, že přenosné modely nahradí kino

Živě.cz - 22 Září, 2026 - 17:45
Projektor dokáže proměnit obyčejný obývák v domácí kino s několikametrovým obrazem. Než jej ale pořídíte, promyslete si zatemnění, umístění i ozvučení. Vysvětlíme, které parametry hlídat, co znamená podpora 4K a co můžete čekat od malých přenosných modelů.
Kategorie: IT News
Syndikovat obsah