Agregátor RSS

Licensing costs driving 90 percent of VMware users to explore options: Survey

Ars Technica - 6 Říjen, 2026 - 14:00

VMware customers face multiple obstacles as they rethink their virtualization strategy to reduce dependence on VMware.

Today, Rimini Street published its “2026 IT Virtualization Survey – What’s Next for VMware Users.” The survey examined 300 organizations worldwide that use VMware.

Notably, Rimini sells third-party support for VMware and other software, including Oracle and SAP. That means there’s an incentive for Rimini to portray VMware users as experiencing obstacles. However, the survey was also conducted by a third-party research company, Unisphere Research, and the results align with other recent reports about VMware customers.

Read full article

Comments

LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings

The Hacker News - 6 Říjen, 2026 - 13:57
A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown. There is no warning first, of the kind either program shows before it runs a macro. The attack works only when the program's Java support is enabled. So far, it has only been shown as a proof of concept, and there are no reports of its use in Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Asos app delivers a data leak threat instead of fast fashion

The Register - Anti-Virus - 6 Říjen, 2026 - 13:51
Asos customers have reported receiving a rogue app notification claiming the online clothing retailer's Snowflake instance has been compromised and threatening to leak data. The notification included a link to a Telegram channel named "Xuanye Wen Gateway" and addressed Asos's data protection officer and IT team. "Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it," it says. The notification does not, by itself, establish that the sender accessed Asos's Snowflake instance or sensitive customer data. How the message was sent remains unclear. Asos's share price fell by around 12 percent following reports of the notification, although it has recovered slightly since. Several hours after publication, an Asos spokesperson confirmed the attack and claimed it had limited impact, telling The Register, "Basic personal information including name and contact details may have been accessed. We do not believe that payment-card information or account passwords, were impacted. Our website and app are operating as normal, with no current disruption to any aspects of our operations." The spox added, "The Company has cyber security insurance with a large global provider, including business continuity insurance. It is too early to quantify any potential impact on trading." Snowflake did not immediately return a request for comment. Customers of Snowflake, a cloud platform for storing and analyzing data, were targeted in a major data theft campaign in 2024, including Ticketmaster, Santander, AT&T, and dozens of others. Connor Riley Moucka, 26, of Kitchener, Ontario, later pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and conspiracy charges over a hacking spree that compromised more than 165 organizations, exposed billions of customer records, and brought in about $2.5 million in ransom payments. Snowflake subsequently introduced controls allowing administrators to require multi-factor authentication. A Snowflake spokesperson said: "At this time, we can report that we have found no compromise of the Snowflake platform. We take customer privacy and security very seriously. The investigation is ongoing and we will provide further updates as soon as more information becomes available." ® Updated October 9 0900 UTC to add: Snowflake said in a statement: “We are aware of ASOS’s notification to their customers regarding this incident. We can confirm this issue did not in any way result from a vulnerability, weakness, flaw, or misconfiguration with the Snowflake service, platform, or internal environments, and was not caused by Snowflake. No remediation is required for Snowflake customers. We continue to encourage adherence to our security best practices at https://docs.snowflake.com/en/guides-overview-secure.” Updated October 8 1400 UTC to add: Asos now says it was a social engineering compromise: "We discovered that an unauthorized party gained access to an ASOS employee account by impersonating a trusted contact to obtain log in credentials. Those credentials were then used to access information on certain third-party platforms used by ASOS." Updated Oct 6 at 1742 UTC: To add Asos' confirmation of the attack and comment. Updated October 7 0845 UTC: To add Snowflake's statement.
Kategorie: Viry a Červi

Denmark's ID register spills more people's details than the country has residents

The Register - Anti-Virus - 6 Říjen, 2026 - 13:46
An unauthorized party abused a private Danish company's legitimate access to the country's Central Population Register (CPR), exposing names, addresses, identification numbers, and other personal information about approximately 8.8 million people. The CPR administration said in a statement [PDF] that it became aware on October 2 of irregular activity during September and established the scale of the breach over the weekend. In a TV interview last night, digitization minister Christina Egelund said it was too soon to say whether the country would issue all-new CPR numbers, one of the solutions proposed following the breach. Danish cybersecurity specialist Jan Kaastrup told TV 2 that treating CPR numbers as secrets was a "broken" approach and argued that a number alone should not be accepted as proof of identity. "We live in a digitalized society, and therefore we should have much better identification systems," he said. Egelund described the company whose access was abused as "small." Private businesses can obtain CPR data under section 38(1) of the Danish Civil Registration System Act, subject to restrictions set out in the ministry's access terms [PDF]. Eligible recipients include companies, foundations, other legal entities, and individuals conducting business. However, access concerns a defined group of people identified individually in advance, and recipients must be legally entitled to process the information under the GDPR and Danish data protection law. The Register asked the ministry why such broad access was given. CPR numbers underpin access to public services and many everyday transactions in Denmark, which has a population of around 6 million people. The database includes the information of over 55,000 people living in Greenland who also use CPR numbers for healthcare, tax services, and banking. The ministry said the register contains approximately 11 million records, including people who have died or moved abroad, which explains why the affected total exceeds Denmark's current population. The ministry also noted that names and addresses of persons who chose to register with name and address protection were not exposed. The CPR administration blocked the unnamed company's access and said it was working with specialists and relevant authorities to establish what happened. It has notified the Danish Data Protection Agency, and police are investigating. ®
Kategorie: Viry a Červi

Zájemci o bezpečnější mobil mají smůlu. Pixel 11 nekupujte, varují experti a mluví o podrazu Googlu

Zive.cz - bezpečnost - 6 Říjen, 2026 - 13:45
** Pixelu 11 hrozí, že bude po 10 letech prvním mobilem od Googlu bez GrapheneOS** Google drží výrobce v šachu přísnými pravidly proti necertifikovanému Androidu ** Motorola zákaz zřejmě obejde, komerční úspěch ale zaručený nemá
Kategorie: Hacking & Security

Zájemci o bezpečnější mobil mají smůlu. Pixel 11 nekupujte, varují experti a mluví o podrazu Googlu

Živě.cz - 6 Říjen, 2026 - 13:45
Pixelu 11 hrozí, že bude po 10 letech prvním mobilem od Googlu bez GrapheneO • S • Google drží výrobce v šachu přísnými pravidly proti necertifikovanému Androidu • Motorola zákaz zřejmě obejde, komerční úspěch ale zaručený nemá
Kategorie: IT News

How to build a ‘safe-to-fail’ culture for IT teams — and why you should

Computerworld.com [Hacking News] - 6 Říjen, 2026 - 13:37

Companies continue to invest in AI, automation, developer tools, and other new technologies. But they may not get the results they expect if IT workers don’t have the time, resources, or freedom to learn how to use them.

IT workers may be afraid to try new tools if they think a failed experiment could hurt their performance reviews. They may also be unsure which tools and data they can use or how to test new technology without creating security problems or disrupting the business.

A safe-to-fail culture can help remove those barriers. It gives IT workers room to try new ideas while limiting the risks to the company. Although employees still have to follow rules, they’re given the time, approved tools, and secure environments they need to test new ideas. Even if the company decides not to adopt a new technology, it can still learn from the experience.

“To me, a safe-to-fail culture is not a safe-to-be-careless culture,” said Michael Morris, global head of platform and talent at Randstad Digital. “It means designing experiments so that a failure is contained, reversible, and useful.”

1. Make experimentation part of the job

“Fear of failure is a major barrier, especially when people believe every experiment will be measured against short-term productivity,” said Daniel Burrus, founder and CEO at Burrus Research. “Leaders need to separate experimentation from day-to-day performance reviews and give teams permission to test ideas without career risk.”

One way IT leaders can encourage experimentation is to set aside time for employees to do it during the workday. If it becomes one more task added to an already busy schedule, workers may put it off or have to do it on their own time.

Typeform, an AI engagement platform vendor, gives employees time during the workday to try AI and other new technologies, said Aleks Bass, the company’s chief product and technology officer. Each employee also receives $1,000 for training, certifications, specialized tools, or other resources that can help them in their job.

That flexibility is important, because employees in different roles may need different tools and training, she said. Typeform provides some tools to everyone, while the individual budget lets workers try other tools the company hasn’t yet approved for wider use.

“So if we’re telling people that we want them to experiment with AI … but we’re saying, ‘Oh, do that in your own time, with your own money, or your own personal accounts,’ then you haven’t really created that safe environment to experiment,” Bass said.

Morris from Randstad Digital said each experiment should focus on a specific business problem and have a clear goal. For example, rather than simply telling employees to learn AI, managers could ask them to find out whether it can speed up writing test cases, improve technical documents, or automate routine support tasks.

“The key word is ‘disciplined,’” he said. “Every pilot should have a business owner, a clear hypothesis, a measurable outcome, a time limit, and an explicit decision at the end: scale it, revise it, or stop it.”

Leaders also need to recognize what employees learn, not just what they successfully deploy, Morris said.

“Small, disciplined pilots expose integration, security, quality, and adoption problems while they are still inexpensive to fix,” he said. “They also reveal where AI performs well and where human judgment is still required. That allows leaders to redesign the process around the technology rather than simply bolt a new tool onto an old workflow.”

One barrier to experimentation is the stigma attached to stopping a project, said Jeremy Koppen, chief information security officer at Equifax.

“To change this, my leadership team and I actively commend our people for shutting down projects that no longer make sense,” he said. “When we go out of our way to appreciate a team for bringing that to our attention, it shifts the dynamic. People know we value their transparency, and they quickly realize they just freed up their talent to do work that actually matters.”

2. Replace uncertainty with clear boundaries

IT workers may also avoid trying new tools because they aren’t sure what the company allows or how much risk it is willing to accept, said Dom Profico, CTO at digital consultancy Bridgenext.

Creating a safe-to-fail culture starts with training employees and ensuring they know what they can and can’t do, he said. As new AI tools emerge, employees need to understand the company’s rules and whether a new tool can do something its existing technology can’t.

Those conversations can keep companies from chasing every new “shiny penny” while still encouraging employees to share ideas that could be useful, Profico said.

Organizations should clearly explain the security and operational rules employees need to follow and put safeguards in place to keep mistakes from affecting customers or users, he said. Knowing those protections are in place may make employees more comfortable trying new things.

Companies can’t eliminate every risk, Profico said. If they want employees to try new ideas, they have to give them some freedom, accept that things may go wrong, and apply company policies consistently.

“If you want to run an innovative organization, you’ve got to really give a little bit more freedom and accept some of that risk,” he said.

Ravi Soin, CIO and CISO at Smartsheet, described the approach as creating a culture of “yes, but safely.”

IT leaders have to let workers know which systems they can access, how they can use company data, and when they need to involve IT or security, according to Soin.

“Within those boundaries, people should be able to try new technologies without having to go back to IT or security for permission every time,” he said.

For example, Smartsheet lets employees in different departments pursue citizen-development projects in preapproved sandboxes.

“If someone in sales wants to use Claude Code for a customer demo, they can do so in a pre-approved sandbox with DLP [data loss prevention] and access controls already configured,” Soin said. “So instead of waiting on a security review, they can start the same day.”

3. Limit the potential damage

The safeguards should depend on how much damage a mistake could cause, said Arthur Hu, Lenovo’s global CIO and CTO of its Solutions & Services Group. An employee testing an AI coding tool, for example, doesn’t need as much oversight as an AI agent working in a critical customer system.

“This starts with analyzing the potential blast radius of a project — meaning the scope of the potential impact to systems and users — and designing the controls accordingly, where a human needs to stay in the loop, what the audit trail needs to look like, and how quickly you can regain control,” he said.

Randstad’s Morris recommended testing new technologies in stages. Employees could start with approved tools and synthetic or nonsensitive data in a sandbox, then move to a test environment and, finally, a small pilot. Access should be limited to what employees need, and the company should monitor and review the pilot and have a plan to stop it or reverse any changes if something goes wrong.

“Security should be a design constraint from the beginning, not a veto that appears at the end,” Morris said. “Only after the team meets agreed performance and security thresholds should the capability reach production.”

Typeform employees can test tools that haven’t been approved for companywide use in sandboxes with mock company and customer data, Bass said. This lets them see whether a tool could help them without putting customers or the company’s platform at risk.

4. Turn experiments into business results

Testing technology early can uncover problems before a company makes a large investment in it, Lenovo’s Hu said. It can also show whether employees trust the technology and whether it fits into the way they work.

“We built a governed AI sandbox on top of our enterprise AI OS. Teams can pull in a new model, tool, or agent framework, stand up a working prototype, and find out whether it earns its place, all without going near production,” he said.

“Things that prove out move onto the enterprise platform and inherit our security, reliability, and compliance controls by default,” he added.

Typeform took a different approach when it put a small team in charge of developing Research Flow, a product that uses an AI interviewer to collect detailed customer feedback. The company gave the team access to AI tools, set clear goals, and allowed employees to try new ways of working. The team could also earn bonuses for reaching each of three goals, Bass said.

The team, which started work in December, was asked to build a working prototype by the end of February. Without AI tools, the project would normally have taken nine months to a year, Bass said. The company believed the bonuses were worth it because finishing the product faster meant it could bring it to market quicker and begin generating revenue sooner.

“At the beginning, I have to be honest, I don’t think the team believed that they could do it,” Bass said. But by early January, the team thought the goals were within reach. They ultimately achieved all three and received the bonuses, she said.

Related:

Kategorie: Hacking & Security

Wikimedia: Rogue OpenAI agents behind unauthorized Wikipedia edits

Bleeping Computer - 6 Říjen, 2026 - 13:31
The Wikimedia Foundation says rogue OpenAI agents made unauthorized Wikipedia edits and may have been partially responsible for a May outage. [...]
Kategorie: Hacking & Security

Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies

The Hacker News - 6 Říjen, 2026 - 13:26
The Wikimedia Foundation, which hosts Wikipedia, has confirmed that it has discovered activity by rogue OpenAI agents on its platforms, including unsuccessful efforts to compromise Etherpad, a public note-taking tool, and edit Wikipedia pages. "The unauthorized bot activities included edits to our wikis, some unsuccessful attempts to exploit a public note-taking tool we host, and heavy traffic,Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Klient, e-mailový klient pro GNOME s nativní podporou Proton Mailu, PGP a spamfiltrem řízeným AI

AbcLinuxu [zprávičky] - 6 Říjen, 2026 - 13:13
Klient je e-mailový klient pro GNOME s nativní podporou Proton Mailu, PGP a spamfiltrem řízeným AI. Napsaný je v Go s GTK4 a libadwaita. Připojuje se přímo k Proton Mailu (bez Proton Bridge), ke Gmailu, k Seznam.cz a k libovolné schránce IMAP/SMTP. Každou novou zprávu nejdřív posoudí spamfiltr a teprve potom ji ukáže a ohlásí. Rozhraní je česky a anglicky.
Kategorie: GNU/Linux & BSD

Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers

The Hacker News - 6 Říjen, 2026 - 13:02
In 2024, MCP (Model Context Protocol) set out to become the USB-C of AI: one standard for connecting models, agents, and IDEs to tools and data. The protocol delivered. Thousands of developers built servers, and enterprises plugged them into agent workflows. The ecosystem around it fell short. Earlier this year, our team at OX Security,  traced critical vulnerabilities in Anthropic's MCP [email protected]
Kategorie: Hacking & Security

V současné krizi dobrá nabídka. Notebook za 13 tisíc má dost výkonu, 16 GB RAM a 16" displej

Živě.cz - 6 Říjen, 2026 - 12:45
Asus Vivobook 16 zlevnil na 13 290 Kč, v létě stál o deset tisíc víc. • Láká na velký 16" displej, jádra Zen 5, infrakameru a 16 GB RAM. • Má i několik omezení a háčků, jenže to dnes všechny levné notebooky.
Kategorie: IT News

Chytrá tapeta vyrábí elektřinu ze vzdušné vlhkosti. Může napájet domácí senzory i další elektroniku

Živě.cz - 6 Říjen, 2026 - 11:45
Nová papírová tapeta vyrábí elektrickou energii z běžné vzdušné vlhkosti • Speciální papírový systém pohlcuje vodu a napájí drobné senzory • Zkombinované moduly zároveň dokážou účinně snížit vlhkost v místnosti
Kategorie: IT News

Legacy sign-on service comes back to bite school software provider Bromcom

The Register - Anti-Virus - 6 Říjen, 2026 - 11:30
UK education software provider Bromcom has notified customers of a personal data breach affecting its single sign-on (SSO) technology. In a September 24 EduGeek post, an account named Bromcom_Alastair said an unauthorized third party had accessed and retrieved email addresses and limited information associated with affected SSO registrations. The incident involved legacy SSO registration functionality in Bromcom's Communication Server environment. The company confirmed in an FAQ it found no evidence that its school Management Information System (MIS), used to manage student data, attendance, behaviour, and administration, was compromised. Bromcom said it was working with external forensic specialists to determine the nature and scope of the data involved. The company identified the incident on September 6 after reports of SSO access problems and has since withdrawn the legacy functionality from production. The service held email addresses associated with SSO registrations, the provider used, such as Microsoft or Google, registration and last sign-in dates where recorded, and internal user and registration reference numbers. Bromcom said the affected component did not hold account passwords or authentication tokens. The legacy SSO registration functionality had remained in production after being superseded because "it was still being called by an internal system," the supplier said. The incident did not enable access to Microsoft or Google accounts, whose authentication services are separate from the affected component said Bromcom. The Register has asked Bromcom to comment further. Bromcom provides information management software used in schools and the wider education sector in the UK. It offers tools for budgeting, timetabling, HR, and benchmarking. Bromcom's software is used by more than 5,000 schools and 390 multi-academy trusts (organizations that run multiple schools). Recent customer wins include Newport City Council, the Ministry of Defence, Warwickshire County Council, and the Northern Ireland Education Authority. ® Updated to add at 0834 UTC, October 6 A spokesperson for Bromcom said: "We recently identified, contained and began investigating an IT incident. Our investigation is ongoing to determine the nature and scope of any data involved, and we have already taken steps to resolve any disruption. We are liaising with the relevant schools and trusts, as well as the appropriate authorities."
Kategorie: Viry a Červi

Nikkei discloses breaches of employees’ Microsoft, Google email accounts

Bleeping Computer - 6 Říjen, 2026 - 11:25
Over the weekend, Japanese publishing giant Nikkei disclosed that unknown attackers recently breached two employee email accounts and used one to send thousands of phishing emails. [...]
Kategorie: Hacking & Security

Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports

The Hacker News - 6 Říjen, 2026 - 11:21
Google has stopped accepting product vulnerability reports through its bug bounty program for its open-source software. The change, in effect since October 1, means researchers can no longer submit security flaws in the code of projects such as Go, Angular, and Protocol Buffers there for a reward. Reports about supply chain compromises are still accepted, and reports filed before October 1 are Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Freckle je první mobil pro děti, který je nepřiková k displeji. Místo toho budou objevovat okolí

Živě.cz - 6 Říjen, 2026 - 11:15
Smartphony nejsou pro děti nejvhodnějším společníkem na cesty • Freckle Phone je naopak navržený přímo pro ně, bez sociálních sítí a dalších pastí • Místo toho pomůže dětem objevovat okolí a spojí je s kamarády
Kategorie: IT News

SQLDoom, hra Doom v SQL databázi CedarDB

AbcLinuxu [zprávičky] - 6 Říjen, 2026 - 10:47
Hra Doom nově běží také v SQL databázi CedarDB. Představen byl SQLDoom. Vyzkoušet lze online demo. Zdrojové kódy jsou k dispozici na GitHubu.
Kategorie: GNU/Linux & BSD

Poskládal si PC ve stylu steampunku. Unikátní počítač je plný trubek a dřeva

Živě.cz - 6 Říjen, 2026 - 10:45
Není to nejvýkonnější počítač na světě, ale nikdo jiný takový nemá. Uživatel Old-Mate-Fetus se na Redditu pochlubil vlastnoručně poskládanou sestavou, kde tradiční komponenty propojil s těmi vlastními. Mix mědi, mosazi a dřeva trochu připomíná nějaký steampunkový výtvor jak z knih Julese Verna. ...
Kategorie: IT News

Engineer sentenced for locking over 3,000 devices on employer network

Bleeping Computer - 6 Říjen, 2026 - 10:19
A former core infrastructure engineer at an industrial company headquartered in New Jersey was sentenced to 32 months in prison for locking thousands of devices on his employer's network in a ransomware-style attack. [...]
Kategorie: Hacking & Security
Syndikovat obsah