Agregátor RSS

Tahle loď instaluje největší větrné turbíny na světě. Uprostřed moře vysune hevery, zvedne jeřáb a přeroste Eiffelovku

Živě.cz - 10 Srpen, 2026 - 17:45
Jsou lodě malé, jsou lodě letadlové, no a pak je tu Voltaire. Podivné stvoření patří belgické společnosti Jan De Nul a používá se při stavbě větrných farem. Loď v posledních letech pracuje na konstrukci největšího systému Dogger Bank Wind Farm v Severním moři. Voltaire je tzv. Jack-Up ...
Kategorie: IT News

Apple’s real memory problem isn’t cost, it’s supply

Computerworld.com [Hacking News] - 10 Srpen, 2026 - 17:37

Apple continues work to get White House go-ahead to source memory from Chinese supplier CXMT, which the US government has placed restrictions on.

For Apple, the issue comes down to simple math. With the cost of making iPhones up 38% because of eye-watering memory price increases — up almost 7-fold since the beginning of 2025 — it makes sense to make pragmatic choices when it comes to sourcing supply, particularly when other computer companies (including HP and Acer) already obtain memory from CXMT.

US resistance to the plan is that because of the way Apple packages memory on chip, the use of that memory might partly contravene the technology transfer restrictions the US has in place. Note: use of off-the-shelf components is fine.

Apple has been lobbying to use memory from the supplier only on devices made and sold in China and would likely argue this is reasonable given that both HP and Acer already use CXMT memory in products sold outside the US. 

Why it’s really about supply

The iPhone maker’s dilemma isn’t just about memory price, it’s also about ensuring it has enough component supply to satisfy demand for its products. This is plausibly a bigger challenge for the company, which is already warning of constrained supply because of lack of available memory. Samsung, Micron, and SK Hynix have allegedly already sold through all their DRAM production for 2027, which only sharpens Apple’s case to secure alternate sources.

With that in mind, it matters that China consumes around 20% of all Apple hardware sold globally. All the company needs is the go-ahead to use RAM from CXMT in those Chinese-made, China-sold devices.

That alone would effectively grow its usable memory supply by the same amount, because the non-restricted memory it currently has to use in Chinese-market products could be freed up for devices sold elsewhere, with CXMT covering the China-sold units instead.

With demand for its products accelerating —even amid a broad industry downturn — Apple really wants to make sure it has enough of the component to meet demand. Those powerful, on-premises 1.5TB RAM-equipped M7 Ultra Mac Studio AI clusters won’t exist unless it’s possible to find memory to put inside them.

The timeline challenge

The proposed arrangement with CXMT might not be a quick fix. Recent reporting indicated the company has already reached its production capacity for 2026, though it is working to double capacity by 2028. Apple has already tested memory chips from the company across products including iPhones and MacBooks.

While Apple this year has applied steep price increases across all its products (except for iPhones), it is now expected to increase the cost of the current iPhone 17 models perhaps as soon as this week. 

Market reports already warn that Apple will raise prices on its soon-to-debut iPhone 18 Pro and iPhone Ultra devices next month, and we expect availability to be constrained, once again as a result of RAM shortages. Even if Apple gets the go-ahead to work with CXMT to close the gap, the positive impact of that arrangement is unlikely to kick in before next year.

Enjoy the pain

Elsewhere, big memory manufacturers, including SK Hynix, have announced plans to invest in new DRAM manufacturing capacity. But this will not be operational until 2029, at the earliest.

This suggests constrained product availability and higher prices for the coming months — and the only way Apple, or anyone else, will be able to limit the impact of those price increases across the entire electronics industry will be if they can obtain additional stocks of memory from vendors outside the big three. If they cannot, you can kiss the age of abundance goodbye.

You can follow me on social media! Join me on BlueSky,  LinkedInMastodon and subscribe to The Core.

Kategorie: Hacking & Security

⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors

The Hacker News - 10 Srpen, 2026 - 17:00
A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default. That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit paths are so short you wonder what was supposed to stop them in the first place. That’s only part of it. Here’s Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Chcete-li se podívat na předpověď počasí ve Windows 11, radši si kupte výkonnější počítač

Živě.cz - 10 Srpen, 2026 - 16:45
Aplikace Počasí ve Windows 11 spotřebovává vyšší stovky megabajtů paměti. • Konkurenční nativní aplikace od Applu v macOS se spokojí s málem. • Počasí je další příklad neefektivity webu přestrojeného do aplikace pro Windows.
Kategorie: IT News

CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs

Bleeping Computer - 10 Srpen, 2026 - 16:34
CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. [...]
Kategorie: Hacking & Security

When Credentials Are No Longer Enough: Device Trust in the AI Era

Bleeping Computer - 10 Srpen, 2026 - 16:01
AI is making phishing, credential theft, and social engineering faster and more efficient, while traditional trust signals such as passwords, MFA, IP reputation, and geolocation become easier to bypass. Specops explains why organizations are increasingly adding device trust to their Zero Trust strategies. [...]
Kategorie: Hacking & Security

Meta představila nový model umělé inteligence Muse Glimmer

AbcLinuxu [zprávičky] - 10 Srpen, 2026 - 16:00
Americká technologická společnost Meta Platforms představila nový model umělé inteligence (AI) Muse Glimmer. Model je menší než přední modely AI od konkurence a má běžet přímo na počítačích uživatelů. Meta model zpřístupní jako open source, tedy otevřený software. Nový model je navržen tak, aby zvládal takzvané agentní úkoly na počítačích se spotřebitelskou grafickou kartou. Klade si tak za cíl uspokojit poptávku po systémech AI, které běží přímo na zařízeních uživatelů.
Kategorie: GNU/Linux & BSD

CopyKat Finds 122 Linux Kernel Objects That Can Amplify Memory Corruption

LinuxSecurity.com - 10 Srpen, 2026 - 15:54
Modern Linux kernel hardening has made many traditional exploit techniques harder to use, but new research from IBM Research Europe and Vrije Universiteit Amsterdam suggests attackers may have a much larger set of alternatives than defenders realized.
Kategorie: Hacking & Security

Za tragický pád letadla ATR v Brazílii mohla námraza i posádka. Závěrečná zpráva odhalila šlendrián aerolinek

Živě.cz - 10 Srpen, 2026 - 15:45
Letadlo se zřítilo kvůli nefunkčnímu systému proti námraze a chybám posádky • Odmrazovací systém nefungoval a piloti ignorovali hlášení o poklesu rychlosti • Aerolinky dlouhodobě zanedbávaly údržbu a poruchy se nezapisovaly do deníku
Kategorie: IT News

Attackers pick Levi's pockets in social engineering attack

The Register - Anti-Virus - 10 Srpen, 2026 - 15:36
Levi Strauss is investigating a data breach after attackers used social engineering to access three employees' work computers. In a regulatory filing, the jeans maker said the intruders accessed and exfiltrated what it described only as "certain corporate information." Levi's said it spotted the intrusion, kicked off its incident response procedures, brought in outside cybersecurity experts, and managed to cut off the unauthorized access. Its investigation remains ongoing. There is some good news for anyone worried that their trouser-buying habits might now be circulating on the dark web: Levi's said its preliminary investigation indicates that no consumer data was affected. The company also said the attack caused no disruption to its operations and, based on what it knows so far, isn't expected to have a material impact on its business. Affected parties and regulators will be notified where required. While Levi's isn't sharing much else about the incident, Reuters reports that the company was also among more than 200 targeted over the past five weeks by ransom-seeking hackers using decidedly old-school social engineering techniques. Google researchers have been tracking several crews involved in the wider campaign, which it believes may sit under an umbrella group dubbed UNC6671. The attackers have been phoning employees on their personal mobiles while posing as colleagues or IT support staff, then directing them to spoofed login pages designed to harvest credentials and multi-factor authentication codes. Their targets have included financial and legal firms handling the sort of information that can make for particularly effective extortion fodder, although Google says the attackers have previously gone after organizations across manufacturing, healthcare, insurance, technology, and hospitality too. There's no confirmation that UNC6671 was behind the successful Levi's intrusion, nor has the denim dealer said exactly what was stolen or whether anyone tried to extort it. For now, Levi's appears to have contained the breach before its attackers could get any deeper into its pockets. ®
Kategorie: Viry a Červi

Wetherspoons bars smart glasses from filming customers

The Register - Anti-Virus - 10 Srpen, 2026 - 15:20
Wetherspoons has stopped short of banning Meta-style smart glasses from its pubs, but told The Register that customers should switch off their cameras and refrain from filming. "Like many hospitality companies, Wetherspoon has CCTV cameras for security reasons, but their use is strictly controlled by data legislation," a spokesperson said. "Apart from that, the general code that applies in our pubs, and most pubs, is that you can't film customers or employees without their permission. "Meta glasses seem to breach this code, and common sense, by enabling surreptitious surveillance, so our instinct is to say turn off the cameras. This is akin to our efforts to stop audible playing of videos in our pubs, which also invades people's space." The Register asked whether customers who refused to stop recording would be ejected, but Wetherspoons declined to elaborate. Wetherspoons' statement suggests that recording, rather than merely wearing the glasses during a wallet-friendly session, would attract the attention of security staff. The policy is therefore less strict than those adopted by venues and events that have banned recording glasses outright over privacy concerns. DEF CON, which concluded last week, was the latest in a series of organizations to issue outright bans on Meta-style recording glasses, even for those who use them with prescription lenses. Conference organizers told delegates to pack "non-violating eyewear" if they needed them. Monopoly Events, which runs UK Comic Cons among other events, recently imposed a ban after talent agencies and guests raised concerns about privacy and the effect of covert recording on personal interactions. Scottish ferry operator CalMac also temporarily suspended unplanned visits to ships' bridges after a passenger made crew members feel uncomfortable during a crossing in June. Restaurateur Jeremy King, who owns London's Arlington, The Park, and Simpson's in the Strand, has said the glasses should not be worn in his establishments. Similarly, private members' club Soho House does not allow recording inside its venues, a policy that extends to Meta-style glasses. Brighton's Yellow Book Bar called the glasses "creepy and intrusive" when announcing its ban, and theatre companies ATG Entertainment and Trafalgar Entertainment do not permit them either. Meta's smart glasses have become shorthand for the wider category of camera-equipped eyewear. Google unveiled Glass in 2012 but failed to turn it into a mainstream consumer product. Meta and EssilorLuxottica launched their first Ray-Ban Stories glasses in 2021, followed by the second-generation Ray-Ban Meta range in 2023 and an expansion into Oakley-branded models. Meta's glasses have become the most prominent products in the category, prompting other tech companies to work on rivals. The next-gen eyewear has proven especially popular among social media users, allowing them to record high-res, hands-free, and first-person footage with ease. Unlike Google Glass, however, the wearables are largely indistinguishable from their analog counterparts, which makes their recording capabilities all the more problematic. The camera in Meta's specs is small and embedded neatly inside the glasses' frame. The company routinely highlights that each pair is fitted with a recording light, which activates when the user begins shooting video, and that if this light is covered up, then recording immediately stops. The feature has done little to appease those who feel the cameras are an invasion of privacy. UK law does not generally prevent individuals from filming in public, although pubs are private premises and may set their own rules. Smart glasses make those rules harder to enforce because recording is far less conspicuous than when someone points a smartphone at the scene. Researchers have shown that Meta's glasses can be paired with apps that can dox passersby in seconds. Others have worked up projects that inform Android users of nearby glasses-wearers using Bluetooth signals. Meta faces a UK data protection probe concerning the cross-border data flows of its glasses' footage after Kenyan reviewer teams reported seeing footage from wearers' more intimate moments. ®
Kategorie: Viry a Červi

Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development

The Hacker News - 10 Srpen, 2026 - 15:19
North Korea's state hackers are no longer content to type prompts into public chatbots. One of the country's main espionage groups has begun running artificial intelligence (AI) offline on its own servers, connecting document-search tools to files in its possession, and collecting the software parts needed to build AI into its malware. South Korean security firm Genians says it uncovered the Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Member of The Com sent to prison for blackmail, sextortion

Bleeping Computer - 10 Srpen, 2026 - 14:56
A member of "The Com," a loose-knit online cybercrime collective that targets children and teenagers, has been sentenced to two years in prison for blackmail and sextortion offenses against nearly 120 victims worldwide. [...]
Kategorie: Hacking & Security

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

The Hacker News - 10 Srpen, 2026 - 14:25
Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on. Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had exposed, abused a cloud-synced passkey system from malware already on the victim's machine, and used a Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Cyber vulnerability sweep picks up Royal Navy drones sending data to China

The Register - Anti-Virus - 10 Srpen, 2026 - 14:25
Cameras aboard Royal Navy drone boats were found phoning home to an IP address in China during a routine cyber vulnerability assessment. The UK Ministry of Defence confirmed the discovery, describing it as "an issue affecting a Kraken Unmanned Surface Vessel sub-system used by the Royal Navy." The Register understands that the data consisted of a "heartbeat" signalling that the camera was online and functioning normally. Even so, an unexpected transmission from military equipment to an IP address in China will rattle nerves. We contacted unmanned surface vessel supplier Kraken for more information, but have yet to receive a reply. An MoD spokesperson told The Reg: "A thorough investigation found no evidence of MoD data or systems being accessed, compromised or transmitted externally." "Our assurance and testing processes are designed to identify and address potential vulnerabilities early, and we continue to undertake routine security activity across our systems and equipment." According to reports, the talkative components were cameras sourced by Kraken from a third-party supplier. The incident raises questions about supply chains, audits, and cybersecurity in the British armed forces. The spokesperson said: "The first duty of government is national security, and we take the security of our equipment, networks, and data extremely seriously." Concerns about China-linked cyber activity have risen sharply in recent years. In April, the National Cyber Security Centre issued a security advisory regarding covert networks, built from compromised routers and other edge devices. Beijing is also rarely far from the headlines when spying and covert operations are involved. In January, a China-linked group was accused of spying on the phones of aides to UK prime ministers. An unexpected connection from military hardware to China is therefore concerning, even if it carried little more than an "I'm alive!" heartbeat. The incident also demonstrates why every component in a defense supply chain needs testing rather than relying on a supplier's assurances. ®
Kategorie: Viry a Červi

Linux Vulnerability Prioritization with Threat Intelligence Insight

LinuxSecurity.com - 10 Srpen, 2026 - 14:13
A Linux vulnerability scan can create almost as many questions as it answers. The scan may identify dozens of affected packages, several CVEs marked High or Critical, and a mix of fixes that are available now or still working through a distribution's update process.
Kategorie: Hacking & Security

LexisNexis shuts down services after suspicious activity on servers

Bleeping Computer - 10 Srpen, 2026 - 14:11
LexisNexis took its Diligence, Metabase API, and Newsdesk services offline as part of its response to unusual activity on servers hosted and managed by an unnamed third-party vendor. [...]
Kategorie: Hacking & Security

Valve notifies Steam hardware customers of a data breach

Bleeping Computer - 10 Srpen, 2026 - 13:47
Video game publisher and digital distribution giant Valve is notifying Steam hardware customers in Europe that hackers stole their data after hacking its shipping partner, CEVA Logistics. [...]
Kategorie: Hacking & Security
Syndikovat obsah