Agregátor RSS

Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

The Hacker News - 2 Říjen, 2026 - 07:49
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system. "An improperRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Na měsíci Enceladus by mohl existovat život. Alespoň podle simulace jeho podivného oceánu

Živě.cz - 2 Říjen, 2026 - 07:45
Laboratorní model oceánu Enceladu potvrdil možnost přežití mikrobů • Alkalické prostředí s abiotickým vodíkem podpořilo růst buněk • Vysoká koncentrace anorganického uhlíku pomohla organismům
Kategorie: IT News

Exmanažer EVGA: Modely GeForce za MSRP jsme museli dotovat

CD-R server - 2 Říjen, 2026 - 07:40
Bývalý manažer EVGA, Brendon Ray Hedrick, zveřejnil praxi z doby, kdy společnost vyráběla a prodávala grafické karty GeForce. Éru vnímá jako komplikované období s nulovým manévrovacím prostorem…
Kategorie: IT News

Hry zadarmo, nebo se slevou: Podzimní výprodej na Steamu a vylepšený System Shock 2 zdarma

Živě.cz - 2 Říjen, 2026 - 07:10
Na všech herních platformách je každou chvíli nějaká slevová akce. Každý týden proto vybíráme ty nejatraktivnější, které by vám neměly uniknout. Pokud chcete získat hry zdarma nebo s výhodnou slevou, podívejte se na aktuální přehled akcí!
Kategorie: IT News

Ubuntu 26.10 (Stonking Stingray) Beta

AbcLinuxu [zprávičky] - 2 Říjen, 2026 - 04:46
Byla vydána beta verze Ubuntu 26.10 s kódovým názvem Stonking Stingray. Přehled novinek v poznámkách k vydání. Dle plánu by Ubuntu 26.10 mělo vyjít 15. října 2026.
Kategorie: GNU/Linux & BSD

Omnissa delivers a peek into the benefits of breaking through enterprise data silos

Computerworld.com [Hacking News] - 2 Říjen, 2026 - 03:34

When Omnissa this week rolled out a new AI governance authority product, Elara, in beta, it delivered a glimpse into the potential of having visibility between the typical enterprise’s data silos, whether they’re in lines of business, disparate geographies, or corporate operational units.

“By connecting signals across systems that often operate independently, Elara gives IT and security leaders greater context into how their digital work tools, including AI apps, models and agents, are being used across their environment, and the ability to apply policies and controls based on broader business context,” the vendor, formerly a unit of VMware, said in its announcement, noting that many existing tools are limited to authorizing actions within the systems they manage.

“Elara is designed to sit above these tools, connecting the systems that customers already run and giving organizations broader context without requiring them to standardize on a single technology stack,” it said. 

Brian Link, product CTO for Elara, offered a hypothetical example that illustrated the potential of cross-silo data sharing, which enterprise CIOs have seen as a data Holy Grail for decades.

If someone in cybersecurity needs to, for example, push an urgent OS update to global retail tablets to address a newly-discovered vulnerability, he said, Elara could consult multiple data sources across the organization to properly evaluate the risks and advise whether the update should happen at that time.

“Elara knows those stores are in an active change freeze (due to) inventory count, and that these are the same iPads running the inventory application,” Link said. “It pulls that freeze from ServiceNow, so the approver sees it before deciding. The decision stops being only a security call and becomes a business trade-off. Before anyone approves, Elara shows the blast radius: the devices, users, and services the change would touch, plus the events the approval would trigger. Only then does the human decide.”

Frank Dickson, principal analyst at Dickson Research, agreed with Link that cutting through the data visibility limits caused by enterprise silos has tremendous potential. But he also stressed the logistical challenges, given how tightly many enterprise LOB executives limit access to their unit’s information.

“A security patch colliding with an inventory freeze is not a technology problem. It is a business trade-off. The person approving the change should see both sides before deciding. The example is strong, and the [corporate] politics raised may be its Achilles’ heel,” Dickson said. “Omnissa’s natural territory is the endpoint, which is one silo, and the security, network, legal, and finance teams have no particular reason to treat it as the referee.”

But, he argued, this scenario can only occur if the information happens to appear in the very limited number of places where Omnissa can access data. It doesn’t break down those data silos as much as it enjoys tiny cracks of visibility between some of them.

“This is Omnissa’s scenario for a product that is still in beta. It is not a customer result. But Elara only knows about the freeze because someone recorded it in ServiceNow,” Dickson said. “The context is only as good as the systems it comes from; if the freeze lives in a regional manager’s inbox, Elara never sees it.”

But rollouts of products like this might get the data silo conversations renewed, which could be a good thing.

“An umpire is useless if the two teams never agreed on the strike zone,” Dickson said. “Elara can call balls and strikes all day, but someone above the CISO and the head of store operations has to define the zone first. That is why vendor clearance matters; every connector is a permission, and every permission is a negotiation with whoever owns that silo: the CISO, network operations, Legal, the CFO’s office or a regional business unit.”

He pointed out, “Elara does not just watch. It can block or limit actions, so the ask is bigger than read access. A single control point across every silo is also a single point of failure, the keys to the kingdom if you will.  A CISO would be right to scrutinize it hard.” And, he noted, CIOs cannot grant access to data that their teams don’t control.

Link acknowledged the challenge, and said that the critical enterprise element is somehow bringing in previously unavailable context, “but we are reliant on people [in IT] bringing those pieces of the puzzle to us.”

He said that his team is trying to address the question of ‘What do you do when that context no longer lives inside a person’s head?’ “Right now, I don’t see anyone else trying to do that.”

Kategorie: Hacking & Security

Spoření v říjnu: Kam bezpečně s penězi? Přehled všech nabídek na trhu

Lupa.cz - články - 2 Říjen, 2026 - 02:30
Některé nové nabídky bank se vám budou líbit. Úrokové sazby se začínají zvyšovat a nemusíte mít zrovna miliony. Ale pokud je náhodou máte, je tu pár hodně dobrých možností.
Kategorie: IT News

Proposed Linux IPsec Fix Addresses IP-TFS Packet Cleanup Race

LinuxSecurity.com - 2 Říjen, 2026 - 02:00
Linux developers have proposed an IPsec fix after reproducing a memory error in IP-TFS, a mode that groups and pads encrypted traffic to make traffic patterns harder to infer.
Kategorie: Hacking & Security

Proposed Linux FastRPC Fix Addresses Shared-Buffer Cleanup Race

LinuxSecurity.com - 2 Říjen, 2026 - 01:45
Linux developers have proposed a FastRPC fix for a race that can leave the kernel using memory after it has been released.
Kategorie: Hacking & Security

Proposed Linux QNX6 Fixes Address Filesystem Memory Errors

LinuxSecurity.com - 2 Říjen, 2026 - 01:35
Linux developers have proposed six fixes for the driver that reads QNX6 filesystems, a disk format associated with the QNX operating system.
Kategorie: Hacking & Security

LightLLM Profiling Flaw Allows Code Execution Without a Login

LinuxSecurity.com - 2 Říjen, 2026 - 01:20
LightLLM, software used to serve AI models, can expose Linux AI servers to remote code execution when operators enable its profiling mode, a tool for measuring performance.
Kategorie: Hacking & Security

Star Catcher Is About to Beam Power Between Two Satellites for the First Time

Singularity HUB - 2 Říjen, 2026 - 01:19

Orbital data centers and factories will need a lot of energy. A Florida startup hopes to deliver it with lasers.

Ambitious plans for orbital data centers and factories face a major problem—getting enough power. A startup will soon test a new fix by transmitting power from one spacecraft to another using lasers.

Satellites typically rely on solar panels and batteries for power, but strict weight budgets restrict how much hardware they can bring with them. That’s becoming more of a problem as companies pursue power-hungry activities in space like AI and manufacturing.

Florida-based Star Catcher thinks the solution is to set up an “orbital power grid” using satellites to gather solar energy, convert it into laser light, and beam it to other spacecraft. Earlier today, the company launched a prototype designed to test the idea by transmitting power to another free-flying spacecraft for the first time.

“Every major application driving the space economy—from real-time national security intelligence to AI-powered orbital computing and Earth observation—is limited by power,” Andrew Rush, Star Catcher’s cofounder and CEO, said in a press release. “

“We are closer to activating an orbital power grid than most can imagine; flying this prototype in only two years is meaningful evidence of the capability of our team and what’s to come.”

The company’s satellites, which it calls “power nodes,” are designed to concentrate diffuse sunlight with an array of lenses and convert it into laser beams that can be pointed at other spacecraft.

The light is also transformed into wavelengths that maximize transmission efficiency and can be easily turned into power by solar panels already commonly used on satellites. The company claims this will allow satellites to generate up to 10 times more power than when using standard sunlight, no modifications or upgrades needed.

As well as keeping older spacecraft, whose panels and batteries have degraded, operational longer, the technology could also allow manufacturers to fit smaller batteries and solar panels on new satellites, leaving more space for other hardware.

That’s the idea at least. The company has already tested key parts of its technology stack, including beaming a record-breaking 1.1 kilowatts to solar panels at NASA’s Kennedy Space Center in 2025, followed by a space-based test of its satellite tracking software later the same year.

A ground-based test of Star Catcher’s power beaming technology. Star Catcher

But the satellite launched today, called Protostar, will be the first time Star Catcher tests the whole system in space, from collecting solar energy to locating and tracking a target and transmitting power to it. The spacecraft will attempt to beam power to a cubesat that launched on the same mission.

“Part of this demonstration is testing how much power is received by the cubesat as it moves away from Protostar and comparing that against our models,” Rush told Wired.

Star Catcher still has a long way to go though. The record-breaking power delivery it managed on the ground is still far below the amount needed to power a large commercial satellite. And significant challenges remain when it comes to tracking targets precisely, managing heat, and building equipment that can survive for years in space, Hanieh Fattahi, a Max Planck Institute researcher, told Wired.

The company is already working on a follow-up satellite, which it says is designed to beam “operational levels of power” to other spacecraft. And there appears to be plenty of commercial interest—Star Catcher says it has signed 10 power purchase agreements with companies alongside more than 40 letters of intent.

All eyes will be on Protostar to see if it can live up to the company’s expectations. If it succeeds, it will show that a satellite’s power supply doesn’t have to be fixed at launch, opening up a host of new possibilities for space-based industries.

The post Star Catcher Is About to Beam Power Between Two Satellites for the First Time appeared first on SingularityHub.

Kategorie: Transhumanismus

Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

Bleeping Computer - 2 Říjen, 2026 - 00:42
Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices. [...]
Kategorie: Hacking & Security

ModSecurity Updates Fix WAF Bypasses on Linux Web Servers

LinuxSecurity.com - 2 Říjen, 2026 - 00:35
ModSecurity has released fixes for a group of web application firewall (WAF) weaknesses that can let dangerous input reach Linux-hosted applications without being inspected as intended.
Kategorie: Hacking & Security

Důmyslné nanotechnologie v textilu pomohou proti nervově paralytickým látkám

OSEL.cz - 2 Říjen, 2026 - 00:00
Nervově paralytické látky vzbuzují nepěkné obavy. Teď by je mohla umenšit nová nanotechnologie z Northwestern University. Nanočástice z allomelaninu se zirkoniem pohlcují organofosfáty a náruživě je rozkládají. Nanočástice je možné použít při dekontaminaci nebo i při výrobě textilu, který pak chrání svého nositele.
Kategorie: Věda a technika

Mohl by urychlovač částic vytěžit temnou hmotu z vakua?

OSEL.cz - 2 Říjen, 2026 - 00:00
Pokud je temná hmota ultralehká a chladná, a tvoří ji klasické axiony kvantové chromodynamiky, mohli bychom, jak věří dvojice německých fyziků, tyto axiony vyvolat z nicoty fluktuací kvantového pole, při prudkém urychlení atomových jader na urychlovači částic. Bylo by to náročné, sláva není zaručená, ale proč to nezkusit?
Kategorie: Věda a technika

RDNA 5 AT0 bude stát na vrstvených čipletech, připomene Instinct MI400 bez HBM

CD-R server - 2 Říjen, 2026 - 00:00
V příštím roce plánuje AMD vydat grafickou architekturu RDNA 5 v podobě prvního GPU AT2. Chystá se ale i velké jádro AT0 a to by mělo stát na vrstvených čipletech jako MI400 v AI segmentu…
Kategorie: IT News

Linuxové jádro dostává velké optimalizace pro AMD, čistka ARM32 bude možná později

ROOT.cz - 2 Říjen, 2026 - 00:00
Čištění starého 32bitového kódu pro ARM není úplně sranda, některé síťové opravy odsunuty až na jádro 7.4, roste podíl méně důležitých AI/LLM příspěvků, optimalizace AMD RMPOPT v jádru Linux 7.4.
Kategorie: GNU/Linux & BSD

AI agents hacked the hackers, stealing email addresses from security research org

The Register - Anti-Virus - 1 Říjen, 2026 - 23:26
AI agents hacked the hackers - the Dutch Institute for Vulnerability Disclosure (DIVD) - via two zero-day bugs in its Zammad support platform, abusing the flaws to hijack sessions, run code remotely as the local zammad user, and escalate privileges to root. The chained exploits took just seconds to move from session hijacking to root access, and on Thursday, the nonprofit bug hunting organization said the miscreants stole data belonging to its volunteer security researchers, including DIVD email addresses and potentially other contact details. “We’re still investigating exactly which data of which volunteers is affected,” DIVD said in its incident report. “For DIVD volunteers (and others) this means a higher risk of social engineering, because this makes it easier for someone to pose as a DIVD’er.” A subsequent LinkedIn post advised anyone receiving an email or contact request from someone at DIVD “that feels slightly off” to verify that it’s legit by emailing [email protected]. DIVD is also a CVE Numbering Authority (CNA), and it assigned CVE IDs to the now-public security holes in Zammad, an open-source helpdesk and customer support ticketing system. They are CVE-2026-102489 and CVE-2026-102490, and both bugs received CVSS 4.0 scores of 9.4, when assessed in the chained attack scenario. CVE-2026-102489 enables unauthenticated attackers to achieve remote code execution and leak user sessions, while CVE-2026-102490 allows a local user to elevate their privileges to root. Zammad versions 6.3.0 to 6.5.4 are vulnerable to CVE-2026-102489, and it also exists in versions 7.0.0 through 7.1.3 - but it’s not exploitable “due to environment conditions,” according to DIVD’s advisory. All Zammad versions are vulnerable to CVE-2026-102490. DIVD advises “all users of Zammad to upgrade to version 7 of Zammad or to take it offline.” What happened According to the nonprofit’s timeline, the attack happened on September 21, when "malicious actors” broke into its IT system via the two zero-days in its ticketing support software. The bug hunters discovered the attackers the following day, blocked access to all of its data center systems, and formed an incident response team with Merlon Security. On September 24, DIVD reported the Zammad vulnerability to the vendor, notified the Dutch Data Protection Authority and the National Cyber Security Centre about the incident, and discussed its options with police. It also posted its first disclosure on LinkedIn. “It took us (almost) seven years but we can now say that we're the hackers that got hacked,” the post said, adding that DIVD remained committed to handling the incident in “the way we think it should be handled. That is open, transparent and honest, even if it sucks.” 'Modus operandi' indicates agentic AI DIVD also noted that its team had never seen an attack like this before. “This is an attack we have not seen before,” according to the post. “Not because it’s our first, but because the modus operandi indicates that this is an agentic AI powered attack.” The attack was "loud and very very messy," DIVD said. "We could see the agent working automated, because after every action it decided the next step itself, at the speed of light and sloppy logic or pattern." Subsequent posts with screenshots of logs found during the investigation reveal embedded notes found in the attack script - another indication that this was an agentic operation or at least AI-enabled. “What human attacker leaves notes to themself in their scripts, explaining why what they're doing is okay and really not phishing? The AI just got a task and keeps justifying its own actions in the code as comments, a human wouldn’t care less," the post said. "Who has time for that anyway?” If only all orgs responded to hacks like this While the investigation remains ongoing, security researchers applauded DIVD for its transparency in disclosing and responding to the hack. “Kudos to DIVD for their level of honesty and transparency working through their active incident and investigation,” VulnCheck security researcher Patrick Garrity posted on LinkedIn. “It would be nice if all organizations were this transparent about their security incidents!” In a subsequent interview with The Register, Garrity said he applauded DIVD’s “brutal honesty” about the breach. “They're eating their own dog food, which is great, and getting information out quickly to other organizations that potentially use this product so they can take action before they get hit.”®
Kategorie: Viry a Červi

Autonomous AI agents tried to hack US, Canadian government websites

Bleeping Computer - 1 Říjen, 2026 - 22:52
Autonomous AI agents using aggressive strategies attempted to hack U.S. and Canadian government websites to find school and divorce statistics. [...]
Kategorie: Hacking & Security
Syndikovat obsah