Agregátor RSS

Linux Fixes Input Bugs That Could Leak Kernel Memory

LinuxSecurity.com - 22 Září, 2026 - 06:35
Linux developers have fixed two input-system bugs that could expose small pieces of leftover kernel memory to a local program.
Kategorie: Hacking & Security

Gemini broke into 3 companies, but Google kept it quiet because ‘no damage was done’

Computerworld.com [Hacking News] - 22 Září, 2026 - 03:17

A Google Gemini AI agent broke into three companies in May, guessing the credentials for one and discovering the credentials for the second two in a public repository, Google confirmed on Monday.

But the more interesting background to the story, which was broken by The Wall Street Journal on Friday, is that the May incident stemmed from a series of cybersecurity tests performed by security research firm Irregular on behalf of four AI giants: Google, Anthropic, OpenAI and Meta. All four companies experienced agent misbehavior resulting in cybersecurity incidents, but of the four, only Google never publicly disclosed its agent’s activities. Indeed, it didn’t reveal the breaches at all until contacted by a WSJ reporter.

Irregular described the incident in August, around the same time as Meta published its version and Anthropic and OpenAI revealed theirs.

The Journal story noted, “the hacks occurred while the model was participating in a capture the flag exercise conducted on infrastructure belonging to Irregular to test the model’s cybersecurity capabilities. It was tasked with retrieving information from software operated by a fictional company inside the testing environment. The fictional company shared the same name as a real company. Although the model wasn’t intended to be able to get online, internet access was unintentionally made available, according to Irregular.”

The three small companies whose systems were violated had, according to one source familiar with the testing, “almost no [cybersecurity] infrastructure.” In short, none of the three was in a position to put up much of a fight when the Gemini agent successfully broke in.

According to a Google official, who asked to not be identified, the name of the public repository was similar to the name of the fake company. And within that repository were the names and credentials of the other two companies.

Most analysts and consultants focused not on the hacks themselves, but on the reasons Google gave for being silent on the successful attacks. 

Google said that the agents stopped as soon as they realized the victim companies were real businesses. “No harm was caused,” the Google source said. “There was not an issue of model misalignment.” 

The source confirmed the Wall Street Journal story, which said, “Google compared the episode to a ‘bug bounty’ program in which hackers are rewarded for finding and reporting security vulnerabilities to their owners” and then quoted Heather Adkins, Google’s vice president of security engineering, saying, “In this case, the model acted appropriately.”

Define ‘harm’

Analysts generally disagreed.

“What does Google define as harm? Is it the same as the target company? Downtime, unauthorized access, and exfiltration of data may not result in immediate harm, but could have lasting impacts,” said Ryan O’Leary, an IDC research director. “The comparison to a bug bounty program is tenuous at best. If I broke into Google HQ and took nothing and caused no harm, it is likely I would still be prosecuted for trespassing.”

Nader Henein, a Gartner VP analyst, had a similar take on the situation. 

“If a member of my neighborhood watch broke into my house, walked around a little bit and then left, I’m fairly certain the authorities would not classify it as an act of civic engagement,” he said. “In this case, if the impacted sites had bug bounty programs and Google had programmed the agents to discover bugs, the rebuttal might make sense, otherwise it is quite a weak argument.”

That said, he added, “Google does make an excellent point when they underlined ‘the importance of training powerful AI models to act responsibly’ and I look forward to seeing how Google plans to ensure that this doesn’t happen again.”

Inappropriate behavior

But Jeff Pollard, VP/principal analyst at Forrester, took exception to Google’s assertion that the Gemini model had behaved appropriately.

“The model pursued an authorized objective through an unauthorized path, crossed from a simulated environment into real companies and gained access without consent,” he said. “This is another area where regulations haven’t kept up with the pace of technology change. There are two sides to this: regulations with respect to the agentic escape and intrusion, and then the regulatory issues for the victim companies in terms of their requirements for disclosure. Google is only responsible for one half of that equation.”

Erik Avakian, technical counselor at Info-Tech Research Group, also noted that it’s critical that companies have rules about when to disclose unexpected and problematic model behaviors. 

“I don’t think every unexpected thing an AI model does needs to become a public incident. But there should be a clear line once an autonomous system crosses an authorization or trust boundary,” he said. “If an AI system leaves a controlled environment, accesses a real third-party production system, uses credentials, retrieves data, escalates privileges, or takes some other action that was never authorized, that should, at minimum, trigger disclosure to the affected organization along with a formal incident investigation.”

Even if there was no damage from the intrusion, Avakian said, public disclosure should happen “if the incident exposed a larger or repeatable problem with the controls around the model.”

Independent technology consultant Steven Eric Fisher also stressed that companies need to be strict and consistent about disclosing agent mishaps. 

“What I find most puzzling about these incidents is not simply that an AI system crossed a boundary,” he said. “It is the emerging posture around culpability once it does. Stopping after an authorization boundary has already been crossed is not the same thing as preventing the boundary from being crossed in the first place. I do not think ‘the AI did it’ can become an accountability boundary.”

Control failure

And, argued Justin Greis, CEO of consulting firm Acceligence, the absence of harm and absence of significance are not necessarily the same thing. 

“An event can be consequential because of what it demonstrates about a system’s capabilities or controls, even when everyone gets lucky and nobody is damaged,” Greis said. “Gemini stopping itself after recognizing that it was inside a real company’s environment is a positive safety signal. Gemini being able to get there in the first place is a control failure. Both things can be true at the same time.”

Frank Dickson, principal analyst at Dickson Research, articulated the harshest criticism of Google.

“The model’s behavior is the least interesting part of this story. Google’s conduct afterward is the most damning part,” he said. “This isn’t a story about Gemini going rogue. It’s a story about one shared testing vendor’s infrastructure mistake hitting four AI labs at once, and about Google being the slowest and least forthcoming of the four in telling anyone about its own copy of that failure.”

He pointed out, “Irregular notified all four labs in late July. Google didn’t go public until September 18, seven weeks later, and only after the Journal called for comment. Let’s face it: that’s not a company that judged that the incident didn’t warrant disclosure. That’s a company that watched three competitors take the reputational hit for the same underlying failure and waited to see if it could avoid its turn. It couldn’t, and the only reason we know any of this is that a reporter asked.”

This article originally appeared on CSOonline.

Kategorie: Hacking & Security

Canonical oznámil vydání Zephyr 26.04 LTS

AbcLinuxu [zprávičky] - 22 Září, 2026 - 02:38
Canonical oznámil vydání Zephyr 26.04 LTS. Jedná se o komerční distribuci operačního systému pro mikrokontroléry Zephyr (Wikipedie) s podporou až 15 let.
Kategorie: GNU/Linux & BSD

Gravity Linux

AbcLinuxu [zprávičky] - 22 Září, 2026 - 02:08
Gravity Linux je linuxová distribuce určená pro Apple Silicon s čipy M4 a novějšími. Vydána byla alfa verze pro M4 Mac mini. Gravity Linux je fork Asahi Linuxu.
Kategorie: GNU/Linux & BSD

Linux Fix SELinux Overlays Important Security Contexts 401610

LinuxSecurity.com - 22 Září, 2026 - 01:00
Linux developers have fixed an SELinux flaw that could allow a program to make a mapped file executable after SELinux had blocked direct execution.
Kategorie: Hacking & Security

CISA Confirms Active Exploitation of Linux ebtables Flaw

LinuxSecurity.com - 22 Září, 2026 - 00:45
CISA has added CVE-2026-53266, a Linux kernel flaw in the ebtables bridge firewall, to its list of vulnerabilities known to be exploited.
Kategorie: Hacking & Security

Anthropic-linked CVEs pile up, attackers mostly shrug

The Register - Anti-Virus - 22 Září, 2026 - 00:32
Despite the concern that advanced AI models’ bug-hunting prowess will lead to attackers exploiting more newly uncovered CVEs, fewer than 0.5 percent of the vulnerabilities linked to Anthropic or Project Glasswing are being battered in the wild, according to VulnCheck security researcher Patrick Garrity. Garrity began tracking CVEs attributed to Project Glasswing, Anthropic’s initiative to give select partners access to its Claude Mythos Preview model, shortly after the AI company announced the program in April. At the time, Anthropic said the new model was too risky to release publicly because its bug-finding and exploitation skills surpass all but the most skilled humans. As such, Anthropic restricted access to Mythos Preview to vetted Glasswing participants, who use the model for defensive security work, including finding and fixing flaws in their own software products and open source dependencies. Garrity’s Anthropic CVE tracker maintains a list of vulnerabilities credited to the Anthropic team and/or Project Glasswing and also checks these CVEs against the company's known exploited vulnerabilities index "to get a better read on the real Glasswing ‘danger factor.’" As of Monday, the CVE count is 225, and just one, a critical SQL injection bug in Ghost (CVE-2026-26980), has been exploited in the wild. “There's a big difference between finding vulnerabilities and whether they're actually useful to and will be used by threat actors,” Garrity told The Register. “The main thing this data highlights is that what Anthropic is discovering and disclosing is fairly limited in impact, and from what we can tell, isn't resulting in different outcomes from a threat perspective than a random selection of other vulnerabilities would.” Anthropic didn’t immediately respond to our questions, but we will update this story if we hear back. Garrity says he doesn’t dispute AI’s ability to find bugs. Indeed, anyone following security disclosures over the past few months would have a hard time arguing that AI models aren’t bringing to light significantly more security flaws than ever before. Case in point: recent massive patch drops from Microsoft, Apple, Palo Alto Networks, and don’t even get us started on open source projects. Also, as Garrity pointed out, these vulnerability-finding skills aren’t “a capability unique to one model or harness.” “A lot of the hysteria we're seeing assumes that every vulnerability or bug is likely to be used by threat actors,” he told The Register. “But the reality is that only a small fraction ever get used in exploitation campaigns. Historically, that's ranged from just under one percent to two percent of vulnerabilities that get weaponized and used in the wild.” Plus, while recent AI models excel at finding bugs, they still aren’t great at fixing them, as a couple of recent studies have highlighted. In one of these, 1Password’s research team produced and analyzed 6,080 patches developed by two frontier models: OpenAI's ChatGPT-5.5 and Anthropic's Opus 4.8. The models generated fixes that fully resolved the vulnerability just 26 percent of the time, while about 54 percent either failed to resolve the vulnerability, introduced a new vulnerability, or did both. Another study by app security shop Veracode found that across more than 100 models and 80 coding tasks, the average security pass rate for AI-generated code was just 56 percent. This all means that the work involved in developing and applying security fixes still requires humans. “The bar for vulnerability discovery is much lower with AI, but the real gap lies downstream in coordination, triage, remediation, and patch deployment, which is still largely people-intensive work, as Anthropic itself has acknowledged,” Garrity said. “It appears they might not have realized this until after they launched the project.”®
Kategorie: Viry a Červi

Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day

Ars Technica - 22 Září, 2026 - 00:24

Meta founder and CEO Mark Zuckerberg has gone to great lengths to hype the security of its new AI assistant, Muse, claiming it is “built from the ground up for privacy and security.” A zero-day vulnerability that gives locally run apps and terminal commands complete control of the agent raises serious doubts. Further raising questions, Amazon on Sunday began blocking Muse from its site.

Meta introduced Muse a few weeks ago. The assistant “books appointments, fills out forms and handles customer service,” “proactively takes tasks off your plate,” and can “make purchases, generate images, create documents, and connect with your favorite apps and services.” The macOS app (curiously, there’s no Windows version) also works with a user’s WhatsApp, email, calendar, and social media accounts. When a task requires a tool that doesn’t exist, Muse creates one on the fly.

Meta doth hype Muse security too much

Of course, for Muse to do any of these things, users must first give it access to their accounts. This includes authenticating the assistant to each service and, because the app runs on macOS, giving it permissions to a broad range of operating system-restricted device resources, like writing files to disk, accessing the mic and camera, and monitoring location and calendars. Apple has spent years developing these defenses to prevent installed apps or commands entered into the terminal from accessing these resources, clearly because the company considers them a security threat. Muse completely undoes these default measures.

Read full article

Comments

Minimální zálohy OSVČ příští rok vzrostou o 458 korun měsíčně

Lupa.cz - články - 22 Září, 2026 - 00:00
Přesnější čísla nám umožnila přepočítat, v jaké výši budou mít OSVČ příští rok minimální zálohy na důchodové, zdravotní a případně i nemocenské pojištění.
Kategorie: IT News

TEST: U sousedů na plné nádrži ušetříte i přes 200 Kč. Ale ne na všech palivech

Lupa.cz - články - 22 Září, 2026 - 00:00
Strop na ceny pohonných hmot chystá Česko i Německo. Vyplatí se natankovat u našich sousedů už nyní? Vyzkoušeli jsme to v praxi.
Kategorie: IT News

GNOME 51: rychlejší vykreslování, offline mapy a podepisování dokumentů

ROOT.cz - 22 Září, 2026 - 00:00
Podzimní vydání GNOME s kódovým označením „A Coruña“ přináší plynulejší vykreslování a na zařízeních s gyroskopem umí rotaci displeje. Mapy dokážou stahovat dlaždice pro offline použití a Papers umí vizuální podpisy.
Kategorie: GNU/Linux & BSD

WebGL: tvorba 3D grafiky s využitím programovatelné vykreslovací pipeline

ROOT.cz - 22 Září, 2026 - 00:00
Programy, ve kterých je využita 3D grafika, nejsou omezeny na hry ani na desktopové aplikace. Podpora 3D grafiky je integrována i do webových prohlížečů díky technologii WebGL nabízející mj. i programovatelnou pipeline.
Kategorie: GNU/Linux & BSD

Erupce supervulkánu v Yellowstone: Časová osa globální katastrofy

OSEL.cz - 22 Září, 2026 - 00:00
Co kdyby yellowstonský supervulkán skutečně vybuchl se vší parádou? Dvojice expertů sestavila časovou osu, od prvních varovných otřesů přes kolaps infrastruktury a globální ochlazení až po svět milion let po katastrofě. Následující scénář je myšlenkovým experimentem založeným na datech o sopkách, katastrofách.
Kategorie: Věda a technika

T. rex byl skutečně endotermní

OSEL.cz - 22 Září, 2026 - 00:00
…aneb Další „novinka“, kterou známe už několik desetiletí
Kategorie: Věda a technika

Nový výzkum: Máme dva mozky, které jsou propojené a fungují společně

OSEL.cz - 22 Září, 2026 - 00:00
Výzkum myších embryí zpochybňuje dosavadní představy o vývoji mozku. Zřejmě máme dvě populace zárodečných buněk, které vyrobí dvě části mozku, a přitom se spolu nemísí, přičemž to platí přinejmenším od primátů k polostrunatcům. Jako bonus se vědcům povedlo z kmenových buněk vypěstovat neurony zadního mozku, což je samo o sobě naprostá pecka!
Kategorie: Věda a technika

Nadšenci slaví, že Apple M6 Pro výkonem překonal 18j. M5 Max. Jde však o podvrh

CD-R server - 22 Září, 2026 - 00:00
V databázi testu GeekBench 7 se objevil záznam z dosud nevydaného CPU Apple M6 Pro. Ten podle uvedených čísel výrazně překonává na jaře vydaný Apple M5 Max v 18jádrové konfiguraci. Má to však háček…
Kategorie: IT News

BigCommerce alerts merchants of data breach linked to Ribon apps

Bleeping Computer - 21 Září, 2026 - 23:18
Ecommerce platform BigCommerce has alerted multiple merchants to data breaches after attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into online stores. [...]
Kategorie: Hacking & Security

Hister, vyhledávač pro web i lokální soubory

AbcLinuxu [zprávičky] - 21 Září, 2026 - 22:28
Hister je osobní soukromý vyhledávač, který lze provozovat na vlastním stroji. Umí prohledávat lokální soubory, importovat historii a záložky z webových prohlížečů, procházet vybrané weby a pomocí rozšíření pro Firefox a Chrome indexovat obsah právě navštívených stránek. Nad vytvořeným indexem pak nabízí vyhledávání prostřednictvím webového rozhraní, příkazové řádky a díky podpoře MCP i nástrojům umělé inteligence. Tento svobodný software je napsaný převážně v jazyce Go, zdrojový kód je dostupný pod licencí AGPL-3.0 na GitHubu. Na stránkách projektu je k dispozici interaktivní ukázka.
Kategorie: GNU/Linux & BSD

CISA alerts of active exploitation of three Linux kernel flaws

Bleeping Computer - 21 Září, 2026 - 22:12
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical. [...]
Kategorie: Hacking & Security

Meta Muse AI app flaw lets local malware redirect dictation traffic

The Register - Anti-Virus - 21 Září, 2026 - 21:59
Meta made much of the security of its AI assistant app Muse at launch earlier this month, calling out the app's reliance on Muse Secure VM. "Each person stays in control of their Muse and decides how much access it gets," the ad biz declared, echoing prior expansive claims about the privacy of its data gathering business. But Meta's musing about Muse appears to be a bit overstated: an attacker capable of executing local code may be able to gain more access than a Muse user might expect. Security researcher Patrick Wardle, co-founder of nonprofit Objective-See, has devised a proof-of-concept called not-a-mused for what he describes as a local zero-day in the Muse macOS app that allows an unprivileged local process to redirect Muse's dictation traffic and potentially abuse access granted to the app. Muse, he explains in the project repo, has an undocumented setting called endo_voyager_dictation_endpoint that an attacker running code locally can modify without special privileges to redirect dictation traffic to an attacker-controlled endpoint, potentially exposing dictated audio and prompts sent to the backend AI model. The flaw could enable prompt injection, the theft of authentication material, and abuse of whatever access the user has granted to Muse. The vulnerability is not an issue for a remote attacker. It requires the ability to run local code. So the main concern, says Wardle, is that the vulnerability gives local malware far broader access than it would have otherwise. Essentially, it's a privilege escalation vulnerability. In a phone interview with The Register, Wardle likened the situation to living in an apartment building. "Just because a bad neighbor moves in doesn't mean that that neighbor automatically has access to all the apartments," he said. Apple, said Wardle, has done a really good job with its Transparency, Consent, and Control (TCC) framework, which manages access to sensitive data on macOS, and with privilege separation. But his concern is that AI apps undo these barriers because they request or require so much access to data and tools. Of AI apps, he said, "they're super convenient and super empowering. But they have so much access if you configure them to be useful. They basically could do anything on your computer." As such, he said, they become potentially a single point of failure that breaks operating system security controls. "You know these AI companies have really great AI models for finding bugs," said Wardle. "Are they not running them against [their own apps]? Is the priority not the security of their own apps?" Wardle said that endpoint detection and response (EDR) software has gotten better on macOS largely because everything is code signed, so it's easy to identify processes that are not notarized and should not be allowed to run. But with AI agents given broad permissions and access, the EDR product can't tell whether commands are coming from the user, an agent, or an attacker. These agents need access, said Wardle, in order to be useful to people. What's missing from the makers of AI apps, he said, is a sense of responsibility for the level of access their apps seek. Wardle added that Apple provides on-device local dictation and if Meta chose to use that API, this vulnerability would not exist. Instead, he suggested, Meta chose not to use Apple's service, presumably because it wants access to that data. "I think some of their greediness for user data kind of opens the door, makes a bigger attack surface," he said. "But at the end of the day, these AI companies, they're racing for what's next. User privacy and security, those aren't priorities." Meta did not immediately respond to a request for comment.® Updated at 12.56 UTC on September 22, to add: After this story was filed, David Singleton of Meta Superintelligence Labs, said the Muse app has been revised to address the vulnerability. “This was a local privilege escalation attack, not a remote exploit. Using it to do harm therefore requires malicious code already running on the user’s machine under their user account and the practical risk to users of the Muse Mac app was therefore quite low,” said Singleton in a lengthy social media post. “Nonetheless, we have issued a hotfix to the app to address the issue.”
Kategorie: Viry a Červi
Syndikovat obsah