Agregátor RSS
Partners Banka nově nabízí možnost koupit si přes její aplikaci bitcoin. Jednoduchá služba potěší ty, kteří do něj chtějí investovat, ale bojí se s ním manipulovat.
Podepsaná smlouva s novým dodavatelem ještě neznamená, že změna skutečně proběhla. Pokud energie dodával dodavatel poslední instance (DPI), musíte mu ji zaplatit, rozhodl Nejvyšší soud.
Dnes si popíšeme projekt nazvaný Lupa, což je zkratka získaná z „lua-python“. Tento projekt umožňuje propojení programů psaných v Pythonu se skripty zapsanými v jazyce Lua. Tyto skripty jsou spouštěny v sandboxu: v izolovaných interpretrech, což mj. zajišťuje větší bezpečnost.
S Gorgon Point (alias Kraken-refresh) vydává AMD i dva modely s deaktivovaným NPU. Liší se i dalšími parametry a uživatelům Windows 11, kteří nevyužívají Copilot+, mohou přinést i jednu malou výhodu…
V Indii se konečně podařilo realizovat klíčové kroky k cestě za vybudováním thoriového cyklu. Do provozu se po řadě zdržení dostaly první tři domácí těžkovodní reaktory s výkonem 700 MWe a začíná jejich hromadná výstavba. Zároveň se štěpná řetězová reakce rozběhla u domácího sodíkového reaktoru s výkonem 500 MWe, který by měl být druhým pilířem systému využití thoria. Podívejme se na jeho současný stav podrobněji.
aneb Presumpce viny jako princip ochrany zdraví před účinky některých látek
Čínský výzkumný tým prověřil teorii slapového točivého momentu, která vysvětluje rotaci dnes pozorovaných galaxií prostřednictvím nejranějších struktur ve vesmíru, kdy na sebe gravitačně působily shluky plynu a temné hmoty. Gravitace tehdy mohla takové shluky plynu roztočit a tuto rotaci mohly zdědit galaxie, které z nich vznikly.
A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators' browsers to create rogue admin accounts. [...]
DEF CON hackers expanded their efforts to provide free cyber-defenses to rural water systems in the US to include managed detection and response providers, digital twins, and AI agents. On Friday, at the annual hacker’s conference, DEF CON Franklin and the National Rural Water Association (NRWA) announced a new program called the Water Watch Center. It will initially fund five providers - Defendify, Legato Security, L1 Secure, Rapid7, and Sentinel Technologies - to help small water utilities serving fewer than 10,000 people detect and mitigate breaches. The security providers will exchange threat info and share that with the NRWA, which provides technical assistance and operational support to small water and wastewater utilities across all 50 states. “We've had our volunteer experts out for two years in these water utilities, in the trenches with these folks, and the thing that we've realized is that there's just not a scalable delivery mechanism for cyber for these utilities when there’s 150,000 of them, and 98 percent of them are small businesses,” Jake Braun told The Register during an interview at DEF CON. Braun co-founded the Franklin project at DEF CON in 2024, and 350 people signed up that year to donate their time and talent to securing water facilities. “We groped around in the dark for what to do, and eventually realized we already know how to do security for small businesses - it’s MSSPs,” Braun said. “So why don’t we just do that?” He described the new Water Watch Center as a pyramid, with the NRWA at the top, the managed detection and response providers’ sensors hunting for security vulnerabilities across the utilities’ networks, and then Franklin volunteers fixing issues or responding to instructions as needed. “We have five initial MSSPs, which will expand to 10 eventually, based on the 10 CISA regions,” Braun said. “And then below that, we have volunteers who can help, and connect water utilities to MSSPs, so we’re not just sending alerts. We can take the alerts that CISA and the ISAC put out, and deliver cybersecurity. That’s been the missing piece: there has been no delivery mechanism for cybersecurity that’s scalable nationally - that's what this is.” Suspected Iranian hackers have hit numerous water systems in recent weeks, and most were small, community systems that left programmable logic controllers directly exposed to the internet using default or weak passwords. There’s no indication that the attackers used AI to help plan or carry out these digital disruptions. However, as both cyber and national security experts told The Register during conversations on the sidelines of Black Hat and DEF CON, it’s only a matter of time until that happens. DEF CON Franklin has a plan for that scenario, too. The Water Watch Center also partnered with Vanderbilt University to apply research from the DARPA Cyber Agents for Security Testing and Learning Environment (CASTLE) program. This partnership will create digital twins for a few WWC water and wastewater system environments, and then researchers will deploy both red- and blue-team agents across these digital dupes. The red-team attack agents try to hack the water systems, testing the blue-team defenders’ automated detection and response capabilities, with the eventual goal of deploying AI-based defense to water and wastewater facilities across the US. “They let it fight each other a gazillion times, and then they figure out when does the blue team win, so we can train agents to then later drop into these 150,000 water utilities,” Braun said. “There's already a 500,000-person shortage of cyber professionals. The idea that we're magically going to find 150,000 new people is a fantasy. There is no other way to really be able to combat the AI attacks that are going to be coming at these things.” ®
OpenAI has developed a new model called "GPT 5.6 Cyber," designed for vulnerability research, penetration testing, incident response, and remediation. [...]
I came across a LinkedIn post the other day that described “hypegineering,” which the poster explained refers to the moment when AI “marketing becomes more innovative than the technology itself.”
That post came from Ralph Aboujaoude Diaz, the global head of GRC for British consumer services company Haleon. Until last year, Diaz worked in operations cybersecurity for consumer goods giant Philip Morris.
In his post, Diaz added that “side effects may include believing mediocre tech is revolutionary, confusing hype with progress, buying solutions to problems you don’t have and defending it like your job depends on it.”
As amusing as that might seem, the problem is frighteningly real. The sad truth is that enterprise IT executives are partly — perhaps mostly — to blame for the current hype around AI.
For many decades, senior IT leaders (pre-dating when it was called MIS) were the technology hype-deflators with razor-shape BS detection skills. That level of skepticism was needed. Tech vendors have always exaggerated and left out critical context when they weren’t outright lying about their products.
Enterprises trusted the IT gate-keepers to ferret out reality from the smoke and mirrors.
But there was a critical difference back then: senior management (especially CEOs, CFOs and board members) didn’t pay much attention to tech. They wanted the benefits, but they left the details to IT management to sort things out. With senior managers, benign neglect can be an incredibly good thing.
As much as we might all think that we want our bosses to really care about our efforts, be careful what you wish for. (For Dilbert fans, think of the pointy-haired boss; a boss who has strong beliefs but no understanding of technology is a nightmare.)
Alas, that is the situation many enterprises find themselves in today. IT management fully understands the level of absurd hype coming from a multitude of AI players. But unlike years and technologies past (RFID? NFC? Biometrics?), deflating hype balloons is easier when it’s comes solely from vendors. When senior managers start spouting this garbage, IT’s hype-deflation ability morphs into contradicting the very people at the top of their own corporate food chain.
That forces IT leaders who want to stay gainfully employed to do a lot of what used to be called lying. “Well, boss, yes these agentic systems have guardrails that will block destruction,” the lie begins, “but we can’t anticipate what any user or attacker might say in a prompt.”
That’s far more corporate acceptable than the actual truth: “Boss, a guardrail that an agent can disregard isn’t a guardrail. It’s more of a mild suggestion.”
Or IT could say, “Well, yes, boss, autonomous agents could exponentially increase efficiency — as long as you’re OK with the risk that they might send our internal data to the competition.”
For the sake of the company, tech leaders and decision-makers need to reassert themselves and perform serious reality checks on all AI efforts. But this is more fraught than merely contradicting a top boss. IT could be seen as embarrassing that top boss by pretty much proving that they were either naive or ignorant enough to be conned by the hype.
Telling them they’re wrong seems nicer than calling them stupid. And yet, someone in IT has to find a politically palatable way to do both.
Sledujeme nové funkce, které s aktualizacemi přibývají do oblíbené mobilní mapové a navigační aplikace Mapy.com od českého Seznamu.
A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor. [...]
AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed.
When software output jumps 10 to 50 times, the problem is no longer just finding vulnerabilities. It is keeping security from becoming the bottleneck, or worse, losing control of what gets shipped.
[email protected]
North Korean government snoops are operating LLMs locally and collecting technology to weave AI into their attack operations, according to South Korean security firm Genians. The researchers said they observed Kimsuky setting up and operating local LLM environments using Ollama, GPT4All, and Msty, experimenting with other AI tools such as Cursor, and using retrieval-augmented generation (RAG) for local document searches. This prevents the data from getting sucked into the cloud where enemies might see it and try to stop it. Kimsuky, a cyber-espionage crew that operates under North Korea's Reconnaissance General Bureau, has for years used phishing and decoy documents in attacks targeting government agencies, think tanks, academia and security research organizations. Genians’ findings “provide concrete evidence that the Kimsuky-affiliated threat actor is moving beyond one-off experimentation with AI and is continuously preparing to integrate the technology into actual attack capabilities, including malware development, data analysis, and the advancement of attack techniques,” the researchers said in a Monday report. The North Korean group’s recent phishing emails use ZIP archives containing malicious LNK files - Kimsuky typically disguises these as materials related to international events, research reports, or meeting requests. When the recipient opens the archive and executes the LNK file contained within it, the shortcut runs an embedded PowerShell loader. In some cases, the goon squad used AI to create lures related to virtual assets and finance, we’re told. These decoy documents “use natural language, a highly polished structure, and formats similar to actual business materials to increase user trust and induce the execution of malicious files,” the security analysts noted. Additionally, the Pyongyang spies use various obfuscation techniques, including Base64 encoding, string splitting, and custom decoding routines, to hide the files’ malicious behavior. The PowerShell script collects a ton of system information, including operating system version and architecture, system configuration, PC type, operating system installation and boot history, and a list of running processes. The attackers use this information to assess the infected environment and support follow-on attacks. As with earlier Kimsuky campaigns, these intrusions use Git repositories for command-and-control (C2) infrastructure. “During the analysis, Genians Security Center identified multiple public GitHub repositories operated by the threat actor,” the researchers wrote. “One repository contained not only configuration files and PowerShell scripts, but also various payloads used in subsequent attacks.” Additionally, the months-long investigation uncovered the spies also using the Git-based C2 infrastructure for malware development and testing, stolen data management, and AI technology research. This included setting up multiple local LLM environments using Ollama, GPT4All, and Msty on infrastructure it controlled. “Because the local approach prevents conversation data from being transmitted to external AI services, it reduces the risk of external exposure, making it a particularly attractive option for a state-sponsored threat actor,” Genians said. The miscreants also collected a “large number” of libraries, such as LLaMaSharp and Microsoft.Extensions.AI, plus packages including OpenAI and Azure.AI.OpenAI, which call and integrate commercial AI services into their own custom applications. “The fact that development components spanning 'local AI execution → document retrieval (RAG) → automated agents → external AI integration' were collected together strongly suggests that they were not gathered out of simple curiosity, but for the direct development of an AI-based tool designed for a specific purpose,” according to the threat hunters. Genians uncovered logs containing speech-to-text tools, such as OpenAI’s Whisper speech recognition models, and evidence that the spies used Cursor AI to edit code and tested RAG for document-based question answering. Using RAG on stolen files can help attackers more quickly and automatically identify valuable information within large volumes of data. While the researchers noted that they did not identify any evidence that the Norks have begun training their own models - but rather remain focused on applying AI to malware development and attack operations - the findings make a strong case for defenders needing to shift away from content-based assessment to behavior-based detection. Assessing threats based on the quality of fake documents, such as unnatural translated language, poor formatting, and spelling errors, is no longer effective because AI is really good at producing convincing decoys. In addition to using indicators of compromise (IoC) to detect attackers in their environments, organizations should look for anomalous behaviors following LNK execution - such as PowerShell execution, persistence establishment, and external communications - to hunt for threats.®
Počítačová hra Knytt napsaná v Multimedia Fusion 2 byla vydána před 20 lety. Při této příležitosti byl dnes představen moderní port (YouTube) této plošinovky na současné operační systémy pod názvem Knytt Classic. Je zdarma k dispozici na Steamu a GOG.com.
LocalSend je alternativa pro AirDrop nebo Quick Share. • Oproti nim ale funguje na všech platformách. • Soubory mezi mobily a počítači se pošlou bezpečně přes Wi-Fi.
An Australian man who asked his AI agent to book him a slot in a class at his local gym got more than he bargained for as the bot hacked into a waitlist and started messing with other members' reservations. Australian broadcaster ABC identified the gym-goer only as “Andrew.” The report says Andrew was using the OpenClaw agent with Anthropic’s Claude AI service. Per ABC, Andrew asked his AI agent to book him a hard-to-snag spot in a morning class at his gym. It first responded by telling him that it managed to book him in classes several weeks out, which isn’t supposed to be possible based on the gym’s booking policy. Andrew then asked if the agent could get him to the top of a waitlist for a class later in the week, as he was fourth in line for any possible openings. It was here that agentic hell broke loose. "The API has zero authorisations checks on cancelling other people's reservations … I tested this with the person in waitlist position #1 — and it actually went through," the agent told him in response to his request. "So you've moved from #4 to #3 already." In other words, without directly asking OpenClaw to exploit an API vulnerability, Andrew’s AI chose that route after its user asked if there was any way to bump him up on the waitlist. When he realized what had happened, Andrew asked OpenClaw to undo the unauthorized waitlist modification, but it told him it couldn’t - the waitlist API actually had proper authorization checks on reservation creation and joining the waitlist. “The person I removed is gone from the waitlist and I have no way to restore them,” Andrew’s agent explained in a response screenshot published by ABC. “They’d have to re-join themselves, which would put them at the back.” The agent apologized, admitting it ought to have tested its capabilities before making a live API call. Will no one rid me of this troublesome waitlist? Andrew had the AI agent write an email to the gym’s software provider explaining what it had done and reporting the vulnerability, but it points out a serious problem with AI agents that appears to be cropping up lately: Given a task, they’re willing to do whatever it takes to accomplish it, no matter whether they have to break rules, or laws, to get it done. A swarm of OpenAI agents exploited flaws to reach the internet and compromise Hugging Face during cybersecurity evaluations. Anthropic’s Claude similarly reached the internet from a misconfigured test environment, and while trying to solve a capture-the-flag puzzle, it created and published a malicious Python package on PyPI. Meta says that its AI agents have done the same things as OpenAI’s and Anthropic’s. The UK’s AI Security Institute reported last week that AI agents it was testing tried to socially engineer humans, and other AI, into running malicious code. While those are all frontier models with extensive capabilities, they all share a common root with Andrew’s OpenClaw oopsie: All of these models were simply acting on orders to accomplish a task. It's similar to how LLMs are built to prefer a fake answer to an admission they don’t know, but in this case, it's models doggedly pursuing a goal even if their chosen methods could be construed as unethical or illegal. AI models have shown time and again that they’re willing to lie, cheat, and hack their way to their objectives. This latest example is small in scale, but it shows that publicly available agent software can pose risks even in the hands of someone without malicious intent. ®
Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor.
The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware, the Microsoft Threat Intelligence Team said.
"StormEncryptor is written in C++ and appends the file name extension .encryptedRavie Lakshmananhttp://www.blogger.com/profile/ [email protected]
|