Agregátor RSS

Serial Microsoft 0-day hunter drops yet another Defender exploit

The Register - Anti-Virus - 9 Září, 2026 - 19:23
Zero-day researcher Nightmare Eclipse, aka MSNightmare, published yet another Microsoft Defender proof-of-concept exploit for a zero-day dubbed ShieldCrash, which they claim will allow attackers to bypass the earlier ShieldBreak patch and read files as SYSTEM. “I might rework this later into a full SYSTEM PoC but for now I'm dropping this skeleton PoC because I'm feeling a bit lazy,” the prolific Microsoft bug hunter and thorn in Redmond's side said in their latest zero-day exploit's README. As is usual with Nightmare’s zero-day cadence, they published ShieldCrash shortly after Microsoft released its latest Patch Tuesday security updates. According to Nightmare, this exploit works on Windows systems that have already applied the September patches. ShieldCrash purports to be a bypass of an earlier Defender privilege escalation zero-day, ShieldBreak (CVE-2026-69414), that allowed attackers to bypass another patch for another Nightmare Eclipse zero-day RoguePlanet (CVE-2026-50656). Redmond patched ShieldBreak last week, and RoguePlanet in July. Both allowed attackers to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems. The latest bypass, ShieldCrash, allows arbitrary file reads as SYSTEM - but not arbitrary writes or a full SYSTEM shell, according to the researcher. Microsoft did not immediately respond to The Register’s questions, including when it planned to patch ShieldCrash. We will update this story when we hear back. While the serial bug hunter typically finds and publishes Microsoft exploits - ShieldCrash is Nightmare’s 11th Microsoft zero-day, and they have made clear that with Redmond, their vendetta is personal - they recently branched out into other security vendors’ software. Last week, they released a zero-day bug called FalconFlank that affects CrowdStrike’s Falcon endpoint security platform. This one still has a Windows twist: the privilege escalation bug abuses the Microsoft Office malicious macros remediation feature in CrowdStrike Falcon. Security sleuth Kevin Beaumont confirmed the FalconFlank exploit works, along with several others Nightmare released over the past couple of weeks. These include HardBreacher, a now-patched elevation of privileges bug in Kaspersky’s endpoint antivirus product, and PrettyPrague, an elevation of privileges vuln in Gen Digital’s Avast antivirus software. ®
Kategorie: Viry a Červi

US says Chinese firms extracted billions of tokens from frontier AI models

Bleeping Computer - 9 Září, 2026 - 18:48
U.S. cybersecurity and intelligence agencies say that six Chinese AI companies conducted industrial-scale distillation attacks on American frontier AI models since at least late 2024. [...]
Kategorie: Hacking & Security

ChatGPT teď obrázky kreslí lépe a mnohem rychleji. Mrkněte na novou galerii s Ježíšem, zrzkou i kočkopsem

Živě.cz - 9 Září, 2026 - 18:45
GPT-Image 2.5 je nejlepší obrazový generátor na světě. • Je rychlejší a přesnější než starší modely a má i nové funkce. • Vyzkoušeli jsme jej na desítkách promptů pro generování i úpravy.
Kategorie: IT News

No, AI is not killing jobs for everyone, studies say

Computerworld.com [Hacking News] - 9 Září, 2026 - 18:43

A slew of recent studies indicate that AI isn’t dramatically displacing workers. At the same time, there were no indicators that the fast-moving technology is creating a lot of jobs, even as AI skills remain in high demand.

Stanford University researchers in an August study found that any AI-related job declines were concentrated among young workers aged 22–25. But for older and more experienced workers that wasn’t the case.

“Claims of economy-wide AI-driven job losses are not visible in payroll data through June 2026,” the researchers said, citing ADP payroll information. Stanford partnered with ADP to conduct the research.

The decline for young workers is more often related to the automation of some work tasks by AI, as opposed to its use to complement work. In contrast, AI is more often used by experienced workers to augment what they do. 

According to the Stanford report, workers between 22 and 25 and employed in jobs highly exposed to disruption by AI are falling behind their older counterparts. Their employment levels in June were about 19% below the same age group in less-exposed occupations. That’s compared to where they would be if both groups had kept pace with each other.

“Experienced workers show no comparable gap,” the researchers said, adding that “this is consistent with recent reports of a worsening job market for entry-level workers.”

Employment of younger workers in AI-exposed jobs fell about 11% from late 2022, while the same age group in less-exposed jobs actually grew about 10%. “For older age groups, we find much less marked differences in employment growth across AI exposure quintiles,” the researchers said.

Stanford, which created a lab last year to study AI’s impact amid heightened fears of the technology’s economic effects, said its numbers were based on available indicators.

AI’s adverse impact on young workers has been well documented, with many of them laid off in the initial wave of AI automation. AI has also suppressed wages for entry-level workers.

AI was cited for 116,175 job cuts in 2026, but that number is declining. The technology  was blamed for 3,462 cuts in August, according to data from Challenger, Gray and Christmas.

It’s the “lowest monthly total since December 2025 when 142 cuts were attributed to AI,” the company wrote in a blog entry. The research firm also noted aggressive hiring plans for companies in 2027.

AI is adding value to companies in different ways, and humans are an important part of that process, said Michael Chui, a senior fellow at QuantumBlack, AI at McKinsey. “The night shift is real now,” he said. “People are sending off their agents to write code and checking in the morning.”

MIT late last year established an AI labor index to determine how agents are affecting the workforce. The school’s Project Iceberg looks at how the coordination and interaction with agentic AI changes how work is done.

Despite the disruptions, demand for AI-related talent continues to rise, tech industry consortium CompTIA said last week. About 320,000 job listings in August required AI-related capabilities, a 4.5% increase from July.

AI-related hiring is outperforming the broader tech market, with demand for AI skills up 96% year-over-year, said Kye Mitchell, head of Experis North America, which is part of ManpowerGroup.

“We’re seeing real growth…in marketing management and project management roles, suggesting employers are looking beyond the people building AI to the people applying it,” Mitchell said.

More broadly, the US economy added 162,000 jobs in August, according to US Department of Labor figures released last week. CompTIA noted that tech employment across all sectors rose by 86,000 workers in August.

But within the tech sector, 14,700 positions were cut, CompTIA said.

Kategorie: Hacking & Security

Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

The Hacker News - 9 Září, 2026 - 18:34
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo,
Kategorie: Hacking & Security

Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

The Hacker News - 9 Září, 2026 - 18:34
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo, Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Pracovní stanice Thelio Mira AI od System76

AbcLinuxu [zprávičky] - 9 Září, 2026 - 17:51
Společnost System76 představila pracovní stanici Thelio Mira AI s předinstalovaným Pop!_OS s prostředím COSMIC nebo Ubuntu. Nakonfigurovat lze až s 16jádrovým CPU AMD Ryzen 9 9950X, 192 GB DDR5 RAM, dvěma GPU NVIDIA RTX Pro 6000 a 192 GB GPU pamětí.
Kategorie: GNU/Linux & BSD

Jen si lehnete a necháte se podjíždět. Robotický masážní válec je můj osobní hit veletrhu IFA

Živě.cz - 9 Září, 2026 - 17:45
Mám rád to bezcílné toulání mezi stánky neznámých firem, když už mám na veletrhu splněné „povinné zastávky“. Letos mě na berlínské IFA zaujal produkt čínsko-hongkongského startupu RheoFit a jedním dechem musím dodat, že to je značně individuální záležitost, která není pro ...
Kategorie: IT News

Veradigm warns of patient data breach after ransomware gang claims attack

Bleeping Computer - 9 Září, 2026 - 17:31
Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data. [...]
Kategorie: Hacking & Security

DigitalOcean sponzorem Omarchy, 3 miliony dolarů

AbcLinuxu [zprávičky] - 9 Září, 2026 - 17:05
DigitalOcean je sponzorem nadace Omacom Foundation stojící za linuxovou distribucí Omarchy. Přislíbená částka je 3 miliony dolarů, tj. 1 milion dolarů ročně po dobu tří let.
Kategorie: GNU/Linux & BSD

LG má velký reputační problém. Aféra se špehujícími televizory ale ukazuje, proč mohou být levné

Živě.cz - 9 Září, 2026 - 16:45
LG má v posledních dnech problém kvůli zjištěním amerického kanálu Gamers Nexus. Ten ukázal nejen bezpečnostní slabiny, přes které lze napadený televizor využít k odposlechu, ale hlavně rozsah běžného sběru diváckých dat. A ten není specialitou LG. Skutečně nás televizory sledují? Lze to vypnout? A ...
Kategorie: IT News

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

The Hacker News - 9 Září, 2026 - 16:23
Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others.  Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide range of data from compromised systems. This can include credential, session tokens, and API
Kategorie: Hacking & Security

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

The Hacker News - 9 Září, 2026 - 16:23
Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others.  Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide range of data from compromised systems. This can include credential, session tokens, and APIRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

MFA's Weakest Link: Account Recovery Is the New Attack Path

Bleeping Computer - 9 Září, 2026 - 16:01
MFA makes account takeover harder, but attackers are increasingly targeting the recovery processes used to reset passwords and authentication methods. Specops explains why stronger identity verification at the service desk is critical to preventing social engineering attacks from turning account recovery into account takeover. [...]
Kategorie: Hacking & Security

Nejlepší strategické hry z univerza Star Wars. Ovládněte bojiště, planety nebo rovnou celou galaxii

Živě.cz - 9 Září, 2026 - 15:45
Pro určitou sortu hráčů není uspokojivějšího pocitu než komandovat celá vojska či rovnou civilizace a sledovat, jak se jim daří, případně jak hynou za bzučení blasterových výbojů. Pojďme si připomenout, kde všude už jsme v historii značky podobnou možnost dostali.
Kategorie: IT News

Siri AI Recaps? Even if Apple builds it responsibly, others might not

Computerworld.com [Hacking News] - 9 Září, 2026 - 15:05

Late-breaking reports suggest Apple has built a new Siri AI ‘Recaps’ feature that summarizes your day for you. The idea sounds great until you recognize that this summary will also include overheard conversations. 

Suspending the huge red flag of concern over privacy and data protection for a moment or two, why would this be useful and who is it for?

How it’s supposed to work

First, it is being described as an Apple Watch feature that will only be available on the latest models: Apple Watch Series 12 and Apple Watch Ultra 4, as these allegedly include secure audio processing hardware. Reading between the lines, that suggests the devices will be able to listen to and process audio on device, which implies that the information won’t need to leave your smartwatch, not even to your iPhone.

The report also says the feature doesn’t make a transcript, nor does it store the audio; it instead gathers key datapoints from what is said to include in the summary, deleting all the remaining information in the process. You can have the feature working all day, on-demand, or only in specific locations. The idea seems to be to provide some kind of actionable summary of events and key conversations that take place during the day. I imagine the subtext is to digitize as much as possible of your daily existence as Apple thinks you will be comfortable with to create the kind of datapoints contextual AI requires if it is going to help with your life.

The case for it

That sounds fine, up to a point — the idea that a digital assistant will be able to recognize key events, moments, and requirements to remind us of them, act on them, or suggest next steps concerning them is certainly a notion that’s gained currency in tech circles. They see it as augmenting human achievement, enabling people to become more productive, more efficient, and capable of doing more with less effort. At least, that’s part of the argument.

What is wrong with that (other than concerns over privacy or a desire not to have one’s entire waking life transformed into a series of datapoints that can be measured, tested, or surveyed by entities outside of our control), right? If you have nothing to hide, you have nothing to fear, at least, not until times change and what didn’t need to be hidden in the past becomes something that must be shrouded in future.

Apple’s privacy defense

Apple, of course, has its strong privacy story to lean into as it introduces this surveillance-as-a-service solution; it’s an argument that says it recognizes how this tech can be abused, and wants to deploy it correctly. It will point to that record as it promises its system doesn’t gather data, doesn’t collect it, and doesn’t keep any form of transcript on or off the device. The company should be commended for building a system that works this way, recognizing as it does that the best way to protect confidential information is not to gather it in the first place.

The warning

But what Apple has also done with this new speculated upon — and as-yet-unconfirmed product — is to show us what these tools can already do. Much of this is already visible; take recent news that LG smart TVs constantly collect and upload user data as an illustration of the seemingly egregious ways in which such tech is used. (LG denies the claim.) What Apple shows us is that with AI in the picture, all your waking moments can be collated, curated, analyzed, digitized and rendered into actionable data. Apple may not be doing that, but others will not be equally cautious, so we owe Apple a debt for warning us of what’s at stake.

Though we don’t know whether Apple will actually introduce this new service, the source of the claims is one of the strongest in the industry. What we do know is that the technology required to build systems like this exists, along with AI systems capable of sourcing, sharing, and sifting through that information. What we don’t yet know is how to remove ourselves from the data stack.

Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSky, LinkedIn, or Mastodon.

Kategorie: Hacking & Security

Nekradou vám heslo, kradou váš souhlas. Přihlašovací obrazovka byla přitom pravá

Zive.cz - bezpečnost - 9 Září, 2026 - 14:45
Dostanete zprávu. Píše organizátor konference, novinář nebo někdo, kdo se za ně vydává, a v textu je odkaz na nějaký dokument, sdílení souborů nebo něco jiného, uvěřitelného. Kliknete, na stránce se ukáže klasická přihlašovací obrazovka Googlu nebo Microsoftu, která se dnes ukazuje na každém druhém ...
Kategorie: Hacking & Security

Nekradou vám heslo, kradou váš souhlas. Přihlašovací obrazovka byla přitom pravá

Živě.cz - 9 Září, 2026 - 14:45
Dostanete zprávu. Píše organizátor konference, novinář nebo někdo, kdo se za ně vydává, a v textu je odkaz na nějaký dokument, sdílení souborů nebo něco jiného, uvěřitelného. Kliknete, na stránce se ukáže klasická přihlašovací obrazovka Googlu nebo Microsoftu, která se dnes ukazuje na každém druhém ...
Kategorie: IT News

WeChat worm could pwn a friend before they even answered the call

The Register - Anti-Virus - 9 Září, 2026 - 14:45
Tencent has patched up a zero-click vulnerability that security researchers used to create a worm capable of spreading through calls on WeChat. With more than 1.4 billion monthly active users, WeChat is among the most popular apps in the world. According to researchers at Calif, its VoIP stack contained a memory corruption bug that could enable a trusted contact to take control of a user's account simply by calling them. Calif called the flaw WeWorm, describing it as the first zero-click worm capable of spreading through WeChat calls on both iOS and Android. Calif released a demo of the vulnerability in action this week, and although Tencent has pushed fixes to address the attack on August 21, the team that found it is still withholding key details. In Calif's demonstration, the exploit took control of a victim's WeChat account within seconds, without the recipient answering the call. The compromised account then called another contact and repeated the process without user interaction. Declining the call stopped infection, but answering it or allowing it to continue ringing did not. An attacker could also try again when the recipient was away from the phone, the researchers said. "Exploitation takes only seconds, and gives us full control of the WeChat account," Calif said. "We can read and send messages, make calls, and act on the victim's behalf." The exploit requires the attacker to be on the victim's friends list. Calif argued that this offered limited protection because a compromised account could be used to target its trusted contacts. Calif said the WeWorm exploit could be chained with other vulnerabilities to compromise an entire device rather than only a WeChat account. It did not disclose the full attack chain. "Chained with other Android and iOS bugs we've reported and are helping fix, it can lead to full control of the device," the researchers said. "[Attackers] could exploit another app, gain root access using techniques like those in OEMpocalypse, take over the victim's WeChat app, and use it to attack you." Calif said it used AI to find the vulnerability and develop its first remote code execution (RCE) exploit in about two days. Tencent later confirmed the researchers' findings. The researchers said they published their high-level findings to highlight how AI could make such capabilities available beyond "well-funded, sophisticated actors." Calif plans to present the full analysis of WeWorm "at an upcoming conference." Ryan Fedasiuk, an adjunct assistant professor in Georgetown University's Security Studies Program, described the discovery of WeWorm as "an extremely serious incident." He called on the US and China to maintain open communication and share information as AI increases the potential scale and severity of cyber threats. ® Updated to add on September 10: Tencent told us: "We were notified of a potential security issue by researchers at Calif through Tencent's official Security Response Center. We investigated the report and have implemented a fix. The fix was deployed on our servers and is now live for all users — no app update or any other action is required. "We have no evidence that the issue was exploited or that any user was affected. Protecting our users is our highest priority, and we're grateful to the researchers for bringing this to our attention and working with us."
Kategorie: Viry a Červi
Syndikovat obsah