Agregátor RSS

Sběrnice SIO pro počítače Atari a problematika externích paměťových médií

ROOT.cz - 23 Červenec, 2026 - 00:00
Na sběrnici SIO se připojovala i externí paměťová média. Většina z nich představuje dosti fascinující propojení analogové a digitální techniky. Dnes se zaměříme na magnetická média, především na kazetové magnetofony.
Kategorie: GNU/Linux & BSD

AMD ukázala layout Zen 6 / Venice, 256jádrového Epycu

CD-R server - 23 Červenec, 2026 - 00:00
AMD před akcí Advancing AI zveřejnila layout serverové varianty Zen 6 a zapůjčila přítomným redaktorům odvíčkované vzorky na hraní, respektive nafocení. A tak se můžeme podívat…
Kategorie: IT News

Létající mikrovlnka Morfius X-rotor na jedné misi zneškodní i 50 dronů

OSEL.cz - 23 Červenec, 2026 - 00:00
Lockheed Martin představil jako jeden z trháků letošního Farnborough Airshow 2026 protidronový dron Morfius X-rotor. Je vybavený mikrovlnnou hlavicí, se kterou dokáže během jediného operačního letu usmažit přes 50 dronů protivníka. Stanou se mikrovlnné drony účinnou zbraní proti hejnům dronů?
Kategorie: Věda a technika

Archeologické muzeum na Naxu, achájské pokračování

OSEL.cz - 23 Červenec, 2026 - 00:00
Památky achájské (mykénské) kultury na Naxu. Napřed tuctové pro kontext, pak ale i velice zvláštní, jaké jinde neuvidíme.
Kategorie: Věda a technika

Upbound says hack caused $13 million in fraudulent Acima leases

Bleeping Computer - 22 Červenec, 2026 - 23:43
The Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases. [...]
Kategorie: Hacking & Security

South Korea discloses data breach impacting diplomats worldwide

Bleeping Computer - 22 Červenec, 2026 - 22:06
South Korea disclosed that hackers breached the National Diplomatic Academy's online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats. [...]
Kategorie: Hacking & Security

GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier

The Hacker News - 22 Červenec, 2026 - 20:37
Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from $20,000-$30,000+ to a fixed $10,000, while its permanent invite-only VIP tier will pay $30,000 or more. Reports filed before that date, including those already in GitHub's growing triage queue, will retain the previous payout terms. GitHub said the Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs

The Hacker News - 22 Červenec, 2026 - 20:07
Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target environment. The high-severity flaw, tracked as CVE-2026-8933 (CVSS score: 7.8), impacts default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. The disclosure comes as Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Galaxy Unpacked July 2026

AbcLinuxu [zprávičky] - 22 Červenec, 2026 - 19:50
Samsung na akci Galaxy Unpacked July 2026 (YouTube) představil své nové telefony Galaxy Z Fold8 Ultra, Fold8 a Flip8, hodinky Galaxy Watch Ultra2 a Watch9 a chytré brýle ve spolupráci s Gentle Monster a Warby Parker.
Kategorie: GNU/Linux & BSD

Garmin má chytrý náramek bez displeje. CIRQA vydrží na jedno nabití deset dní a nevyžaduje předplatné

Živě.cz - 22 Červenec, 2026 - 19:45
Garmin CIRQA je chytrý náramek bez displeje pro diskrétní sledování zdraví • Zařízení nabízí pokročilé fitness funkce i desetidenní výdrž baterie bez předplatného • Prodej na českém trhu odstartuje 24. července s doporučenou cenou 4990 Kč
Kategorie: IT News

Own nothing, upgrade everything: Apple’s new Klarna deal

Computerworld.com [Hacking News] - 22 Červenec, 2026 - 19:01

Just in time for the iPhone’s 20th anniversary, Apple is moving closer to becoming a service company. It is set to launch its new deal with Klarna next week and when it does, Apple enthusiasts in the US will effectively be able to subscribe to their favorite Apple hardware, with the cost spread across up to three years.

This matters because when combined with Apple One and Apple’s Creator Studio subscriptions, the Klarna arrangement brings Apple closer to offering a full subscription model for hardware, software, and services. The only thing you don’t get under the new arrangement is AppleCare, for which you’ll allegedly need to pay extra.

Moving closer to hardware-as-a-service

Apple has slowly been transitioning toward hardware-as-a-service for almost a decade. Back then, Forrester analyst Frank Gillet predicted the company would eventually offer bundles of services and products for a monthly, all-in, fee. 

This isn’t quite where we are yet; you still need at least three subscriptions to get close. But, after the better part of a decade, Apple has moved much nearer to the hardware-as-a-service idea.

There are some products reportedly excluded from the arrangement, including MacBook Neo, Apple Watch SE, the entry-level iPad, and iPhone 16. Clearly, Apple sees those products as sufficiently affordable. 

Easy payments for RAM-ageddon

The new Klarna arrangement comes as Apple is forced to increase product prices as AI-driven memory price inflation becomes widely felt across every economy. In theory, I assume, Apple hopes to make its products available to cash-strapped consumers who need new hardware, while also navigating a time of deep economic tumult and uncertainty. It’s thought the company has previously rejected these plans to protect normal hardware sales, but normality is a kingdom we no longer seem to possess. Interesting times. Probable inflation incoming.

“Apple Upgrade lands at precisely the moment Apple needs it,” IDC analyst Francisco Jeronimo wrote in a note seen by Computerworld. “Having just pushed Mac and iPad prices up on the back of the memory shortage, with iPhone increases widely expected in September — as well as the new iPhone foldable expected at $2,500 — Apple’s real risk is that rising prices even further can impact the upgrade cycle.” 

New age, new shopping habits

The introduction of the scheme gives consumers a way to purchase the company’s popular high-end devices when they are introduced — no doubt,at higher cost — this fall. Plus, of course, if it’s good enough for GM, it’s good enough for Apple.

It’s all about attitude, too. From Apple’s perspective, it has done plenty of the groundwork required to convince its customers that subscription payments for things you value are no bad thing. 

Reluctance to embrace “Access Not Ownership’”purchasing models has dropped dramatically since Apple — and CEO Tim Cook — first began banging the drum for services income. Apple’s services stream has now become its second-biggest revenue driver after the iPhone. It has over 1 billion paid subscriptions, and an active hardware installed base of more than 2.5 billion devices globally.

A combination of changed customer habits and external threat means the stars are now aligned for hardware-as-a-service models. “Reframing a device as a low monthly payment protects that [upgrade] cadence and allows Apple to start marketing their products as device-as-a-service to consumers, which no other vendor was ever able to do,” Jeronimo wrote to me. 

There is a one-more-thing aspect to this: the products are effectively being leased, a new approach that will give Apple a stronger grip on EOL devices, helping it grab more of them for refurbishment, resale, and recycling. Over time, this will give the company a much stronger grip on the lucrative second-user market that exists around Apple equipment, even while for almost every consumer product we find the life we want is something we can rent, but probably can’t afford to own.

Managing future risk

The other solid reason to take a partnership approach is risk management. Apple had intended to develop its own buy-now, pay-later scheme via Apple Pay Later, but abandoned that plan as it became riskier with rising bank rates. “Also, by backing the program with Klarna rather than reviving the in-house subscription plan it shelved in 2024, Apple captures the demand upside without taking the credit risk onto its own balance sheet,” Jeronimo said.

You can follow me on social media! Join me on BlueSky,  LinkedInMastodon and subscribe to The Core.

Kategorie: Hacking & Security

Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack

Bleeping Computer - 22 Červenec, 2026 - 18:59
Swiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers. [...]
Kategorie: Hacking & Security

Linux kernel team publishes 432 CVEs in two days

The Register - Anti-Virus - 22 Červenec, 2026 - 18:58
If you're responsible for Linux security, someone just dumped a pile of work onto your desk: 432 Linux kernel CVEs were published across Sunday and Monday this week. Linux watchers at nixCraft pointed out the volume on Monday morning, and it didn’t take long for seasoned sysadmins to start expressing concerns. Jan Schaumann, chief information security architect at Akamai Technologies, took to the OSS-SEC mailing list Tuesday to express concerns over the sheer volume of Linux kernel CVEs published in recent days. Aside from noting that the CVE system isn’t the best way to track security changes, Schaumann also wondered in his post whether there was any good way to deal with so many kernel security issues. “This onslaught really shows it's not feasible to attempt to prioritize individual kernel changes,” Schaumann said. “You might attempt to process this large set of changes by pointing an LLM at the intake and asking it to prioritize them,” he suggested, “but if it spits out a dozen today and another 25 the next, you haven't won much.” Schaumann also suggested waiting to see which ones emerge as serious issues and focusing on those in the weeks to come, or updating one’s entire fleet of Linux machines on a weekly basis. “I sure would like to be able to do [that], but reality keeps getting in my way,” Schaumann said. “I'm not sure what to do here going forward.” In an email to The Register, Schaumann said that individually reviewing vulnerabilities for patching was already difficult enough before things rose to this level, and that automation may be the only option - but it's not a great one. "Automated, regular, and frequent updates that pull in all changes within a given time window of tolerance seem to me the only reasonable approach, but that is very difficult for many large organizations," Schaumann explained. Those orgs often rely on lengthy QA processes, slow and staged development cycles, and may even have contractual requirements for long-term support that make an automated approach an impossible one. The nixCraft team speculated on social media that AI bug reports are a likely reason for all those kernel CVEs, which wouldn’t be without precedent - Linus Torvalds himself said in May that the Linux kernel security mailing list had become “almost entirely unmanageable” due to AI-assisted bug hunting. Nonetheless, Torvalds has described AI as a useful tool for Linux development while still noting it can be a drag for maintainers, both from a workload standpoint and the fact "it keeps finding embarrassing bugs." On that note, it's worth understanding what a Linux kernel CVE actually means - many of the vulnerabilities included in the Sunday-to-Monday batch are small in scope, but they're vulnerabilities nonetheless. As senior Linux maintainer Greg Kroah-Hartman noted in a February blog post, the Linux kernel CVE team follows the CVE Program's definition of a vulnerability: a weakness in a product that can negatively affect a system's confidentiality, integrity, or availability. “At the level that the Linux kernel runs, almost any type of bug that can affect a running system can be classified as a vulnerability,” Kroah-Hartman noted. The kernel team looks at every bugfix that is added to stable kernel releases, he added, and if it fixes an issue that meets that CVE criteria, a CVE is assigned. AI-assisted bug hunting has increased the volume of reports reaching Linux kernel maintainers. We reached out to the Linux kernel team, but didn’t hear back. Kroah-Hartman did tell The Register earlier this year that AI bug reports had become worthwhile in recent months, and he predicted they're likely to keep adding to his workload. Unfortunately for Linux sysadmins, the position in which they find themselves in this current mess isn’t one that’s readily solved. CVEs might be a messy way to track and prioritize security updates, especially when hundreds of them are published over a short period, but without something better, it falls to IT and security teams to determine which vulnerabilities affect their systems and which kernel updates they need to deploy. Hope you’ve got the coffee machine filled up: The onslaught is unlikely to ease if other recent patch cycles are any indication. ®
Kategorie: Viry a Červi

Vyhledávání ve Windows 11 si už nevyláme zuby na překlepech. Zkuste si ho v nové aktualizaci

Živě.cz - 22 Červenec, 2026 - 17:45
Aktualizace KB5101684 vyšla pro Windows 11 24H2/25H2 v kanále Release Preview. • Vyhledávání si lépe poradí s překlepy a neúplnými názvy aplikací. • Průzkumník se učí používat jednotky MB a GB.
Kategorie: IT News

How enterprise GenAI can amplify ransomware risk — and how to contain it

Bleeping Computer - 22 Červenec, 2026 - 17:30
Enterprise AI can accelerate ransomware attacks when AI assistants and agents inherit excessive permissions or compromised identities. Acronis explains how identity controls, governance, and least-privilege access help reduce AI-enabled ransomware risk while supporting secure AI adoption. [...]
Kategorie: Hacking & Security

Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

The Hacker News - 22 Červenec, 2026 - 17:01
Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, which, if exploited, could facilitate a silent hijack of a user's WhatsApp data. The shortcoming has been codenamed HermeticReader by Guardio Labs. It's officially tracked as CVE-2026-48294 (CVSS score: 7.4), with the vulnerability Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Vyšla hra Scarlet Deer Inn

AbcLinuxu [zprávičky] - 22 Červenec, 2026 - 16:16
Po pěti letech vývoje vyšla česká počítačová hra Scarlet Deer Inn (ProtonDB). Scarlet Deer Inn je vyšívaná temná středověká pohádka. Zatímco život ve zdánlivě obyčejné vesnici se točí kolem běžných povinností a sousedských drbů, v podzemí se skrývají zlověstná tajemství.
Kategorie: GNU/Linux & BSD

New InfraTrust report reveals infrastructure flaws admins should patch first

Bleeping Computer - 22 Červenec, 2026 - 16:15
Eclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities affecting infrastructure, firmware, networking, and edge devices. [...]
Kategorie: Hacking & Security
Syndikovat obsah