Agregátor RSS

AMD kupuje Taalas, výrobce „AI modelů v křemíku“, 50× rychlejších než Blackwell

CD-R server - 7 Srpen, 2026 - 10:00
AMD oznámila akvizici společnosti Taalas, která se specializuje na vývoj a výrobu inferenčních čipů integrujících AI model přímo do křemíku. Umožňuje to dosáhnout až 200× lepšího poměru cena / výkon…
Kategorie: IT News

Nintendo Switch 2 po prvním roce. Smysluplný upgrade s jediným důležitým nedostatkem

Živě.cz - 7 Srpen, 2026 - 09:45
První rok nejnovější konzole Nintenda je za námi a nikdo nemůže pochybovat, že je Switch 2 masivní úspěch. Nejrychleji prodávaná konzole v historii, několik vysoce hodnocených exkluzivit, podpora od vydavatelů třetích stran… ale i nejedna kontroverze a rozhodnutí, nad kterými jen kroutím hlavou.
Kategorie: IT News

TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

The Hacker News - 7 Srpen, 2026 - 08:50
A new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, indicating the group has been compromising internet-facing infrastructure for years before training their sights on the software supply chain. "The connection is supported by overlapping domains, malware deployment paths, staging techniques, backend infrastructure, Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Výborný notebook za 18 tisíc. Lenovo má jemný a jasný OLED, dostatek výkonu a tříletou záruku

Živě.cz - 7 Srpen, 2026 - 08:45
Lenovo IdeaPad Slim 5 zlevnilo na 17 938 Kč, obvykle stojí 20 tisíc. • Nabízí procesor od AMD, 16 GB RAM, výborný OLED a hodně konektorů. • Pro kancelářskou práci má dost výkonu a vydrží celý den.
Kategorie: IT News

Bójka na Mallorce naměřila rekordní teplotu Středozemního moře 33,02 °C

Živě.cz - 7 Srpen, 2026 - 07:45
Meteorologická bóje poblíž ostrůvku Dragonera jihozápadně od Mallorky pravděpodobně naměřila rekordní teplotu ve Středozemním moři. Ve středu 5. srpna odpoledne zaznamenala 33,02 °C. Aktuální a historické záznamy španělských bójek si můžete prohlédnout třeba v tamní mapové aplikaci PORTUS, kterou ...
Kategorie: IT News

CXMT odmítla požadavky Applu, nenechá si diktovat ceny

CD-R server - 7 Srpen, 2026 - 07:40
Apple narazil při vyjednávání o cenách a dodávkách pamětí pro iPhone 18. Když se šest týdnů před vydáním nové generace pokusil přesvědčit čínskou CXMT k objednávkám za nižší ceny, byl usměrněn…
Kategorie: IT News

Hry zadarmo, nebo se slevou: Baldur's Gate 3 na konzolích nikdy nebylo levnější a čtyři PC hry zdarma

Živě.cz - 7 Srpen, 2026 - 07:10
Na všech herních platformách je každou chvíli nějaká slevová akce. Každý týden proto vybíráme ty nejatraktivnější, které by vám neměly uniknout. Pokud chcete získat hry zdarma nebo s výhodnou slevou, podívejte se na aktuální přehled akcí!
Kategorie: IT News

China launches mysterious probe into security of Palo Alto Networks' products

The Register - Anti-Virus - 7 Srpen, 2026 - 06:24
China’s Cyberspace Administration (CAC) has conducted a review of Palo Alto Networks’ products. The regulator’s announcement of its review says it’s needed “to ensure the safe and stable operation of critical information infrastructure, prevent cybersecurity risks and vulnerabilities, and safeguard national security.” And that’s all Beijing has to say on the matter. A Palo Alto spokesperson provided The Register with the following statement: "We maintain the highest standards of business conduct and security practices and ethics across our global operations. At this time, there is no impact to our ability to support customers or deliver our products and services in the region." This matter has echoes of China’s 2023 investigation into the security of products from memory-maker Micron, which the CAC announced out of the blue. Micron had previously fought intellectual property and antitrust cases in China, but the company and Chinese authorities did not explicitly link those matters to the security probe. The CAC published its findings weeks after announcing the probe and decided Micron’s products represented an unacceptable security risk for critical infrastructure operators – effectively banning sales of Micron products to such entities – but didn’t offer a detailed explanation for its decision. The memory-maker eventually stopped selling its datacenter and server products in China, a decision that cost it billions of annual revenue – but created new opportunities for China’s own memory-makers, which are largely prohibited from selling to American companies. China is home to several security companies whose product portfolios overlap with Palo Alto’s. Huawei and H3C, for example, have plenty to offer local buyers. Palo Alto doesn’t reveal revenue earned from individual countries, so it’s hard to know what a potential ban could cost the company. China has for years accused Western tech companies of assisting US surveillance and offensive hacking activities. The Register would not be surprised at all if Beijing reuses that reasoning in its findings about Palo Alto products. Western governments level the same accusations at Huawei and ZTE. Beijing’s ban on Micron didn’t noticeably impact the company’s reputation elsewhere. Indeed, the AI boom has brought Micron such great riches that past dents to its bottom line are now almost irrelevant. ®
Kategorie: Viry a Červi

Cloudflare wants to provide the operating system for the AI-first enterprise

Computerworld.com [Hacking News] - 7 Srpen, 2026 - 02:31

Traditional operating systems (OS) were built to manage hardware, files, apps, and users on a device, but Cloudflare says the agentic AI era requires a whole new format.

The company this week announced Cloudflare OS, which connects AI agents, enterprise data and context, internal systems, and workflows together in one secure workspace. It is open source and browser-based, sparing companies the need to build all-new infrastructure.

The OS is launching alongside several other new security, identity, spending, and user insight tools that Cloudflare has built for the AI-based workplace.

“Cloudflare OS isn’t a traditional desktop OS,” said Rita Kozlov, VP of product at Cloudflare. “It reimagines the workplace computing environment for AI.”

Open source OS runs in a browser

Cloudflare OS serves as a secure, AI-equipped workspace that is plugged into internal company systems. Available now through Cloudflare’s open source repository, it is accessible directly in a browser, and runs inside an enterprise’s Cloudflare account.

“It is a browser-based workspace that begins with a conversation,” Kozlov explained. Users can ask an agent to research, create slides, spreadsheets, and documents, build full-stack apps, or automate workflows without the need for a terminal. Those outputs are then shareable, but kept in isolated databases with access controls.

Enterprises will soon be able to access the OS directly through Cloudflare or via a “select group” of partners that will build tailored offerings on Cloudflare’s architecture, the company says. Because it is open source, organizational processes, internal system connections, and context aren’t locked into a vendor product or AI model provider. Customers can use whatever models they choose.

Cloudflare OS is built on Cloudflare Workers, Dynamic Workers, Durable Objects, and Access, the company’s zero trust network access (ZTNA) tool that verifies every user and request. Agents start with zero permissions by default and are only granted access to tools required for a specific task. Organizations configure their own Access policies, models, branding, skills, and integrations, Kozlov explained.

Governed connectors known as gatekeepers give admins control over what AI can see, what it can change, and when the system needs human sign-off. They can also control budgets, set rate limits, and delegate tasks to different models.

“Because agents act on people’s behalf and produce work others can access and modify, they require a new security model,” Kozlov said. Thus, Cloudflare OS tracks the resources an agent requires so the right access controls follow its work when it is shared.

Cloudflare initially built the OS for internal use, and employees “across every team” use it daily. Kozlov estimated that, over the last 30 days, internal users have used it to create more than 4,000 apps, automations, and tools. Over that same period, she claimed, the company’s sales team saved an estimated 10,000 hours by automating previously manual tasks like territory planning and proposal creation.

“We open sourced Cloudflare OS so any organization can build ‘Your Company OS,’” Kozlov said. Open source is critical because “you cannot put your company into software you do not own. Organizations need to be able to inspect the platform, customize it, connect their own systems, and make it their own,” she explained.

A more cohesive bundle

Cloudflare deserves credit for packaging Cloudflare OS as an operating system, noted tech analyst Carmi Levy.

“This very much is not Windows, macOS, or Linux, and it isn’t an operating system by its common definition,” he said. “But Cloudflare’s use of this terminology implies familiarity to enterprise IT buyers.”

This makes for an easier discussion as enterprises struggle to understand how to best incorporate AI-related platforms and workflows into infrastructure that wasn’t initially designed for it.

Microsoft has marketed the combination of its Azure, Entra, Fabric, Windows, and Microsoft 365 offerings as an operating system of sorts, but hasn’t pulled all the pieces into a common brand, Levy said. And Google’s Gemini, Workspace, Vertex AI, and Cloud Run are “circling similar territory.”

But, he noted, Cloudflare OS is “more cohesively bundled” and infrastructure-focused, offering a single pane of glass platform for buyers worried about stitching together otherwise disparate AI-aware networking pieces. The company recognizes that AI introduces new architectural realities such as inference and model routing “over and above” traditional OS core competencies.

“While competing offerings generally leave the infrastructure heavy lifting to enterprise decision-makers, Cloudflare is marketing itself as a single-source vendor, which potentially frees IT planners from having to integrate all the AI pieces on their own,” Levy said.

An infrastructure-first, application-agnostic approach means Cloudflare OS can coexist with whatever AI applications already exist in an enterprise, he said. It will “play nice” with OpenAI, Anthropic, Google, Microsoft, Meta, or open source layers, allowing employees to begin working in familiar workflows after sign-in.

“Its open-source architecture also minimizes the potential for vendor lock-in as enterprises gradually figure out how to evolve their stacks to align with new AI-era realities,” Levy said.

Managing identities and budgets for both humans and AI

As AI agents emerge across the enterprise, tracking their use can be challenging, causing problems from both a security and a spend standpoint. Along with Cloudflare OS, the company has launched a way to address this issue with its new Identity-Aware AI Gateway, now in beta.

Also integrated with Access, the offering gives admins visibility into what users (both human and AI) are requesting from AI models. It allows security teams to set up custom domains in front of their gateways and replace shared API keys by integrating with their identity provider, like Okta or Entra, and ZTNA infrastructure, Cloudflare explained.

Every request is tied to Access-verified identities, and enterprises can filter each user’s logs, analytics, and spend. IT teams can track redundancies, limit usage rates, and apply filters that strip out employee names, passwords, and other sensitive data before requests go to outside model providers.

A companion feature, AI Spend, tracks every user’s behavior over time to create a baseline of normal AI usage. When spending deviates from that pattern, the system alerts the IT team.

A new tab, User Insights, tracks cost and identifies over-spend caused by activities such as low cache-hit rates or oversized context windows. The capability scores sessions and compares them against account history using a 95th percentile session cost over the previous 30 days, Cloudflare product managers Ming Lu, Kenny Johnson, and Ayush Kumar explain in a blog post. Anything above 2x an account’s 95th percentile is a “strong candidate for anomalous behavior.”

For instance, one Cloudflare customer had an employee who left a rogue AI session running, generating a $30K bill. “User Insights helped them identify the problem and shut off access before the problem was further exacerbated,” Kozlov said.

Cloudflare is also building prompt classification functionality that sorts requests into categories such as coding or writing. This can help enterprises understand what AI is being used for.

“Once business traffic is separated from everything else, personal use becomes visible,” the project managers explained. “From the outside, someone running a side hustle on company time and someone quietly moving data out through a model look the same. Telling them apart is central to catching insider risk.”

Looking at the bigger picture

Identity-Aware AI Gateway and AI Spend address the visibility problem that has dogged so many recent AI deployments where enterprises failed to monitor usage, Levy noted. Projects “crashed and burned” as users unwittingly blew through token allocations.

These platforms provide single-point visibility into what is being used, how it’s being used, and where the potential lies for raising the productivity bar, he said. They overlay with existing models; in doing so, they enhance security with more precise control over resource allocations, and via automated anonymization protocols that prevent inadvertent sharing of sensitive data.

Ultimately, he said, vendors who free IT from having to independently assemble the pieces of their own AI implementations, and who assist them with answers to AI-specific questions, “will gain advantage over vendors that aren’t looking at the bigger picture.

This article originally appeared on CIO.com.

Kategorie: Hacking & Security

How the famed USENIX Security conf is managing a flood of papers in the AI era

The Register - Anti-Virus - 7 Srpen, 2026 - 01:40
The 35th USENIX Security Symposium (USS), which takes place next week in Baltimore, Maryland, hit an all-time high for paper submissions. While some of that increase has been aided by the availability of AI tools, those managing the conference say abuses were minimal due to defensive measures. But they're also trying not to look too closely in order to preserve trust within the security research community. "This year's conference has received ~3,030 valid submissions (~1,280 in Cycle 1 and ~1,750 in Cycle 2)," explained Ben Stock, tenured faculty at the CISPA Helmholtz Center for Information Security and USS program co-chair, in an email to The Register. "This is up from the previous year, which had ~2,400 submissions in total." Stock said that the entire security community has seen growth of this sort and pointed to the Network and Distributed System Security Symposium (NDSS), which saw its paper submission count jump from 694 in 2024 to 1,311 in 2025 and 1,481 this year. "So, I would not call the growth unprecedented, even though the number of submissions has reached a high point compared to previous years," he said. "This is something we had expected and scaled our Program Committee (PC) accordingly." Sussing out unacceptable uses of AI A paper published in April, "More Versus Better: Artificial Intelligence, Incentives, and the Emerging Crisis in Peer Review," found that since the release of ChatGPT in 2022, submission volume at major academic journals has increased 42 percent. In the USENIX Security '26 transparency report, issued in January between the first and second paper submission cycles, Stock and fellow co-chair Elissa Redmiles, assistant professor of computer science at Georgetown University, detail how they've developed tools and policies to account for the possibility of AI usage, both for paper submissions and in paper reviews. "The proliferation of readily-available LLMs to aid in writing and developing code is not unknown to the community," their report says. "However, we see an alarming trend of AI usage in key areas of the scientific process. Therefore, we took actions against two types of identifiable actions which violate the scientific process in our minds: non-existing (possibly hallucinated) references and usage of AI in the review process." After identifying and rejecting a paper that contained nonexistent references, the report explains, the conference organizers developed tooling "to extract references from the submitted PDFs, query well-known sources such as DBLP and arXiv, and manually confirm invalid references." The org rejected papers containing three or more hallucinated references, a policy that impacted 21 of the 1,181 first round submissions (1.78 percent). "We have rejected papers for the repeated presence of nonexistent references," said Stock. "We cannot say with certainty that these were AI-hallucinated, but nevertheless considered these papers to be problematic and thus rejected them." The report notes that more than 100 additional papers contained at least one reference that reviewers could not confirm. Aware that some of these might simply be false positives due to name spelling differences or missing citations, conference officials opted not to investigate these in order not to further burden staff. Conference organizers draw the line at using AI for bibliography preparation. "We believe that it is critical to halt this trend that threatens scientific integrity before it grows further," the report states. However, limited use of AI to polish human-written text is expected, and that extends to those reviewing submitted papers, up to a point. "We have not set a dedicated AI policy, but have made it clear to our PC members that usage of [AI] services to write reviews is not permitted, in particular also because this violates confidentiality," said Stock. "We have detected a tiny number of cases where we have reached sufficient confidence that AI was used and took appropriate actions, including removal of the members from the PC and allowing affected authors to resubmit." Under that policy, USS asked five of 496 reviewers to cease participation. "We have not seen evidence that leads us to believe that AI generated submissions have become a significant challenge for the security community," said Stock. "This does not mean that AI hasn't been used in parts of these submissions, though." ®
Kategorie: Viry a Červi

OpenAI rolls out a major ChatGPT upgrade, even if you don’t pay for it

Bleeping Computer - 7 Srpen, 2026 - 00:48
OpenAI is rolling out a more reliable version of ChatGPT GPT-5.6 Sol for Plus and Pro users, while Free users are getting unlimited text chats with GPT-5.6 Luna. [...]
Kategorie: Hacking & Security

ClickFix attack pushes macOS infostealer for crypto theft attacks

Bleeping Computer - 7 Srpen, 2026 - 00:37
A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials. [...]
Kategorie: Hacking & Security

Týden na ScienceMag.cz: Vylepšený test nenašel žádný rozdíl mezi vodíkem a antivodíkem

AbcLinuxu [články] - 7 Srpen, 2026 - 00:01

Umělá inteligence generuje kompletní recepty elektrolytů pro baterie. Superzemě jsou běžnější, než se myslelo. ČR bude rozvíjet další lokality pro výstavbu malých modulárních reaktorů. Objev nového exoměsíce přináší nové výzvy pro kosmickou terminologii.

Kategorie: GNU/Linux & BSD

SVJ ignorovalo vlhkost a plíseň, výbor na stížnosti nereagoval. Majitelce může hradit ztrátu z nájmu, rozhodl soud

Lupa.cz - články - 7 Srpen, 2026 - 00:00
SVJ vědělo, že vady společných částí domu způsobují v bytě vlhkost a plíseň, přesto opravu řádně neprojednalo a řešení roky odkládalo. Podle Nejvyššího soudu tak může odpovídat nejen za opravu, ale i za ušlé nájemné.
Kategorie: IT News

EndeavourOS na Raspberry Pi 4B 4 GB: doladění systému k použitelnosti

ROOT.cz - 7 Srpen, 2026 - 00:00
Přestože EndeavourOS Linux oficiálně podporuje Raspberry Pi 4B, po instalaci počítač každých několik sekund na několik sekund tuhnul. Musel jsem provést množství změn, aby byl počítač vůbec použitelný.
Kategorie: GNU/Linux & BSD

Microsoft chce, aby na Xbox Helix běhaly všechny hry, které kdy vyšly pro Xbox

CD-R server - 7 Srpen, 2026 - 00:00
Microsoft začal prosazovat strategii v podobě maximální herní kompatibility nadcházejícího Xbox Helix. Měly by na něm fungovat tituly napsané pro Xbox 360, Xbox One, Xbox One S / Xbox One X i novinky…
Kategorie: IT News

Početné týmy mravenců jsou skvělé v řešení hlavolamů

OSEL.cz - 7 Srpen, 2026 - 00:00
Terénní experimenty s ekologicky nesmírně úspěšnými mravenci Paratrechina longicornis ukazují, že jsou v řešení hlavolamů lepší než agenti umělých inteligencí, vycvičení na fyzikálních a matematických modelech. Také vyšlo najevo, že početnější mravenčí týmy vyřeší složitější hlavolamy v porovnání s malými týmy.
Kategorie: Věda a technika

Why Do Some People Never Get Cancer? The Answer May Be in Their Blood

Singularity HUB - 6 Srpen, 2026 - 22:48

Researchers will hunt for antibodies in the blood of people who lived past 100, drank heavily, or smoked—but avoided cancer.

Jeanne Calment was over 122 years old when she passed away. The oldest person in history, she smoked for nearly a century, but never developed cancer.

Why does cancer grow, spread, and become deadly in some people but not others? Even twins, who share similar genes and lifestyles can differ widely in cancer risk. Many factors likely contribute, but a bold new study, called ATLAS, is investigating an unexpected player: autoantibodies.

These immune-system proteins roam our bodies, but instead of attacking pathogens, they mistakenly target healthy cells and tissues. They’re best known for their role in autoimmune diseases, but early evidence suggests they also fine-tune the immune system’s response to cancer. Some appear to weaken immune surveillance, allowing tumors to sprout and flourish. Others may boost anti-cancer immunity by tagging cancer cells for destruction.

Whether they’re friend or foe is far from clear. ATLAS researchers aim to find out by analyzing blood samples from diverse groups of people, including centenarians and people who have escaped cancer despite carrying high-risk gene variants or exposure to risk factors like smoking.

The project hopes to discover why some people are naturally resistant to cancer, which could lead to early diagnostic tests, new therapeutic targets, and more effective treatments. ATLAS may “uncover fundamental principles” of antibody immunity in cancer, wrote the team.

Immune Mayhem

Since the late 19th century, scientists have suspected the immune system helps keep cancer in check. The idea has since spawned powerful treatments. In CAR T cell therapy, for example, a patient’s own immune T cells are genetically enhanced to better recognize and destroy tumors to cure previously untreatable blood cancers. A similar strategy in macrophages, immune cells that tunnel into tumors and literally engulf them, is now entering early clinical trials.

Far less attention has been given to antibodies. These proteins normally fight pathogens, like viruses. But sometimes they go rogue, taking the form of autoantibodies that attack healthy proteins, DNA, and other molecules. Even healthy people carry a diverse collection of autoantibodies, but most bind only weakly and don’t seem to trigger biological effects.

For decades, these proteins were used mainly to diagnose autoimmune diseases such as rheumatoid arthritis, as they often appear years before symptoms emerge. But more recently, scientists have begun uncovering their broader impact on the immune system. Autoantibodies that attack cytokines, a type of immune signaling molecule, were implicated in roughly 20 percent of Covid-19 deaths, largely because they disabled antiviral defense.

Scientists have since linked them to worse outcomes in several other life-threatening viral diseases, increasing some people’s vulnerability as if they were immunocompromised. Beyond infections, they also neutralize cytokines that protect against inflammatory bowel disease.

Cytokines orchestrate many immune system activities, including inflammation, allergies, autoimmunity—and cancer. Although there’s still little direct evidence that autoantibodies themselves drive or prevent tumors, scientists have found many can recognize cancer-related proteins and are developing methods to detect them as an early sign of cancer.

If autoantibodies can reshape cytokine activity during viral infections, could they also determine who develops, or resists, cancer?

“These discoveries establish that autoantibodies can function as powerful, naturally occurring immune modifiers raising the possibility that similar antibodies may alter antitumor immunity,” wrote the ATLAS team.

Charting the Landscape

Because antibodies linger long after diseases have gone, they preserve a molecular record of a person’s immune history. Rather than focusing on a handful of candidates, ATLAS is going fishing: The study will chart the body’s entire antibody repertoire, including autoantibodies, seeking signatures linked to cancer susceptibility or resistance.

The team will first scan blood samples for autoantibodies. They’ll also catalog conventional antibodies, making note of the ones that directly recognize and attack cancers. All this data will go into a comprehensive cancer antibody atlas, giving researchers a resource to explore how different antibodies shape cancer.

To start, the team will study what they call “remarkable groups of people” whose immune systems may hold unusual clues. Among them are healthy centenarians. Although cancer risk usually skyrockets with age as DNA mutations accumulate, these individuals have somehow avoided the disease. Others have remained cancer-free despite smoking, heavy drinking, or carrying cancer-related gene variants such as the BRCA mutations for breast cancer. The team will also study pairs of identical twins where only one sibling developed cancer, allowing them to compare antibody signatures in people with nearly identical genetic blueprints.

Finally, the team plans to track people with cancer before, during, and after immunotherapy, to paint a picture of how immune responses evolve over the course of the treatment.

Ultimately, they expect to find three broad classes of antibodies: those that help or hinder cancers and those that appear largely neutral. Each could prove valuable.

Autoantibodies that blunt anti-cancer immunity could become drug targets. Scientists might make synthetic “decoy” antibodies to block them—in a way, fighting fire with fire. The findings could also inspire next-generation immunotherapies.

On the other hand, autoantibodies that help the immune system recognize cancers could become therapies themselves or complement existing therapies, such as checkpoint inhibitors, which boost the body’s immune response to cancer. These are much less toxic than chemotherapy, but only 20 percent of patients respond, perhaps because of immune differences.

Even seemingly neutral autoantibodies may be useful cancer biomarkers. Because antibody tests are already well-established, fast, and inexpensive, associated neutral antibodies could aid early detection, monitor whether treatments are working, or warn when a cancer is likely to return.

But correlation isn’t causation.

Some antibodies may merely record a person’s immune history rather than actively influencing cancer. To tease the two apart, the team plans to test promising candidates in cultured human cells and mice, to see whether they alter cancer growth or spread. Those experiments could reveal previously hidden molecular communications between the immune system and cancer and deepen our understanding of the deadly disease.

“We should be able to come up with a biomarker to predict who is likely to avoid cancer, [and] who is likely to develop cancer,” said ATLAS team member, Xin Lu at the University of Oxford. “Potentially we could come up with therapeutic, preventative agents [that are] antibody-based. And that would be fantastic.”

The post Why Do Some People Never Get Cancer? The Answer May Be in Their Blood appeared first on SingularityHub.

Kategorie: Transhumanismus

Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group

Bleeping Computer - 6 Srpen, 2026 - 22:07
A recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile threat actors. [...]
Kategorie: Hacking & Security

AI struggles to patch vulns without adult supervision

The Register - Anti-Virus - 6 Srpen, 2026 - 21:04
AI models may not be that good at fixing security flaws. Researchers at 1Password's Off-by-1 Labs analyzed security patches generated by two frontier models - ChatGPT 5.5 at "medium" effort and Claude Opus 4.8 at "high" effort - and found that autonomous patches cleanly fixed vulnerabilities only about a quarter of the time, while most of the remainder failed to fully remediate the flaw or introduced other problems. Keith Hoodlet, director of security research at 1Password, argues in a blog post that the results show LLM-driven security remediation still needs human review. "Across six recently disclosed CVEs, we produced 6,080 patches using two frontier, cyber-capable reasoning models," Hoodlet said. "The average success rate for generating a patch that fully resolved the vulnerability (without materially changing application behavior) was just 26.0 percent." Of the AI-generated patches, 20.1 percent fixed the original issue but altered application behavior (eg, changing "allow list" logic to "deny list" logic). Some 2.3 percent of the patches fixed the issue while introducing new security issues. 49.3 percent of the patches failed to fix at least one existing exploit path. And 2.2 percent both failed to fix the vulnerability while introducing a new exploit path. And among the patches in the first two categories (successful, clean; successful, changes app behavior), the researchers rated more than a third of the results fragile, meaning that while the adjusted code may have guarded against a particular vulnerability (eg, escaping particular input characters), the repair job didn't address the underlying problem. In their research paper [PDF], authors Axel Mierczuk, Spencer Michaels, and Keith Hoodlet propose the acronym FLAWED to represent automated LLM patches: Fix-Like Artifacts With Embedded Defects. Based on the generated patches, they conclude, "[T]he expected value of a fully LLM-generated, non-human-reviewed patch is a net-negative by a considerable margin." The value of LLM-generated patches depends upon initial patching guidance. The research team says that while both human developers and LLMs typically require some initial guidance to tackle a vulnerability, LLMs are more likely to be derailed when given incorrect advice. When LLMs get correct guidance, their fix-success rate hits 65.0 percent compared to 50.4 percent when they get no guidance. And incorrect guidance dooms LLMs, dropping their fix-success rate down to about 15.2 percent. Human devs, the authors argue, have a good chance of catching misleading information as they reason through vulnerable code. The authors have released a patch evaluation harness under the name FLAWED that organizations can use to evaluate the effectiveness of their security fixes. It's clear from the paper why AI-generated patches might be appealing – considered in isolation, they're inexpensive relative to human software engineers. The average successful, clean patch cost just $6.74 (a figure that includes the cost of failed attempts). Nonetheless, the authors argue that the cost-benefit analysis needs to assess how much expert supervision will be required to make LLM-assisted patching useful. "Based on our manual review of a representative sample of patches generated during our research, we suspect that, in a large number of cases, the cognitive load imposed by reviewing a mountain of mostly-incorrect, similar-yet-subtly-different LLM-generated vulnerability patches will likely result in engineers spending more effort than would be necessary to understand and patch vulnerabilities themselves using standard LLM-assisted coding techniques that keep the human operator in the driver’s seat," the authors conclude. "The alternative, cognitive surrender to a process with a success rate of only about 1 in 4 poses significant long-term risks for any organization considering autonomous, LLM-driven patching." ®
Kategorie: Viry a Červi
Syndikovat obsah