Agregátor RSS

Chrome kašle na design Windows 11. To stejné ale dělá Microsoft s Edgem

Živě.cz - 6 Srpen, 2026 - 16:45
Google z Chromu 151 odstranil experimentální předvolbu. • Aktivovala materiál Mica v záhlaví okna. • Microsoft na designový styl Windows 11 loni rezignoval také.
Kategorie: IT News

How AI Exposed a Browser Security Gap that Enterprises Cannot Ignore

Bleeping Computer - 6 Srpen, 2026 - 16:02
AI did not create a new browser security problem. It exposed one that enterprises have long been able to ignore. Skyhigh Security explains why browsers have become a critical control point for governing data movement, AI interactions, and modern work. [...]
Kategorie: Hacking & Security

NASA chce prozkoumat jeskyně pod povrchem Měsíce pomocí dronu napájeného laserem přes optické vlákno

Živě.cz - 6 Srpen, 2026 - 15:45
Projekt LUX vyvíjí dron k průzkumu temných měsíčních lávových tunelů • Dron bude napájen laserem přes tenké odvíjené optické vlákno • NASA vyčlenila finance na devítiměsíční studii proveditelnosti konceptu
Kategorie: IT News

Mak's Weekly Security Roundup: Critical Linux Security Updates Admins Should Know

LinuxSecurity.com - 6 Srpen, 2026 - 15:07
This week’s most important Linux security updates arrived through vendor advisories rather than major headline-making disclosures.
Kategorie: Hacking & Security

Alza má další variaci na Logitech MX Master. Nová myš už nabídne i kolečko se setrvačníkem

Živě.cz - 6 Srpen, 2026 - 14:45
Alza uvedla svou zatím nejlepší kancelářskou myš. • Eternico M505 je téměř klonem Logitech MX Master. • Láká na tichá tlačítka, hliníková kolečka a design.
Kategorie: IT News

Kubernetes Maintainers Expand CSI Path Traversal Fixes Beyond Original Vulnerabilities

LinuxSecurity.com - 6 Srpen, 2026 - 14:21
Kubernetes maintainers patched two path-traversal vulnerabilities in the NFS and SMB CSI drivers earlier this year. But repository histories show that the security work did not end with those fixes.
Kategorie: Hacking & Security

Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities

The Hacker News - 6 Srpen, 2026 - 14:16
Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network. Its August 3 scan counted 4,407 exposed Rockwell controllers worldwide, including 2,844 in the United States, but Forescout could not confirm any were compromised. That figure counts exposed Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

OpenAI’s ‘Rotten to the core’ defense is its weakest play yet

Computerworld.com [Hacking News] - 6 Srpen, 2026 - 14:07

Ancient Greek sophist Protagoras famously said, “There are two sides to every question.” But OpenAI’s latest attempt at reality distortion seems determined to narrow this dispute to just one. In its motion to reject Apple’s complaint, the company does not meaningfully acknowledge the criticisms levelled against it, preferring instead to recast the case as a grievance over talent retention and product-market failure.

The filing

In case you missed the news, OpenAI filed a motion to the court to dismiss Apple’s recent lawsuit against it. In that filing, OpenAI argued that, “Apple should not be permitted to use a baseless and pretextual lawsuit to make up for its shortcomings in the market for talent and retaining its employees, and its failures to integrate AI into its products.”

The company’s dismissal claims Apple’s case was, “plainly filed without adequate investigation and built on selectively excerpted communications and ordinary conduct stripped of context,” adding, in a turn of phrase borrowed from Apple’s own complaint, that it is “rotten to its core.”

The narratives can change

As ever with litigation, these are allegations and counter-allegations rather than findings of fact. The value of the filings is that they show how each side wants the court, and the public, to understand the same disputed events. At the moment, we don’t yet know how Apple will respond to OpenAI’s response; it follows that company’s failed attempt to woo public opinion earlier in the week when it deployed what some see as a “cookie jar” defense, arguing that Apple’s secrets only slipped out because the figurative jar lid was open.

OpenAI likely hopes for more success with its latest attempt to defend itself against Apple’s claims it engaged in a coordinated attempt to obtain trade secrets through questionable recruitment practices.

Central to the company’s counter-argument are its attempts to recharacterize some of Apple’s claims. For example, Apple alleges that one former staffer, Chang Liu, downloaded confidential files after leaving the company. OpenAI argues that Liu was instead attempting to help ex-colleagues who asked him for assistance. This is a useful example of the Protagorean frame: both companies are trying to extract different meanings from the same event.

What the truth might be

The courts will need to decide which version of events is closer to the truth. What is already clear is that OpenAI has been actively involved in recruiting Apple staff, including the services of former Chief Design Officer Jony Ive, as it develops a product that, to a layman like me, sounds likely to compete with Apple hardware. OpenAI says those recruitments reflect Apple’s failure to retain its staff; Apple argues its competitor is using exfiltrated confidential information to guide its hiring. The court will need to decide that story as well.

Ultimately, I don’t expect OpenAI’s efforts to have the court reject Apple’s lawsuit to succeed. Apple is asking for discovery precisely so it can test whether its reading of this distorted reality is supported by OpenAI’s internal procedures and the available facts. One of OpenAI’s arguments seems to be that Apple has not researched the matter thoroughly enough; Apple is quite literally requesting discovery to do just that.

What happens next?

I don’t know what discovery might turn up, but it does amuse me to think Apple could build its own large language model to boost the discovery process and identify communication conduits that might otherwise be obscured in the evidence initially available to it. How high, and in what direction, do OpenAI’s claimed recruitment practices go, and who is implicated in them? That’s something we might find out in the coming months.

OpenAI’s Protagorean defense extends a little further, of course, as the company also said it had “no use, need or desire for Apple’s trade secrets” because it is building “something entirely new.” This may surprise Apple, which has already alleged that OpenAI contacted its manufacturing partners and sought access to secret manufacturing processes Apple developed with them.

Once again, it will be up to the courts to decide whether those events took place, or if OpenAI’s defense has substance. Given that this dispute centers on product design and involves the AI company’s growing army of former Apple design and development staff, I find the denial hard to accept. But courts tend to make their own decisions, for good, or for ill. 

Fight or settle

What happens next? I think this attempt to reject the original litigation will fail, which means the case will enter the discovery process before one of two outcomes becomes more likely: A bitter public battle that lasts for years and might well end up in the Supreme Court, or an out-of-court settlement shaped by which side gains the most compelling evidence.

Like any war, there are really only two options: one side fights until the other can no longer continue, or both sides find a way to settle. The path to settlement may begin by recognizing that two stories can be applied to the same facts, and that the version closest to the truth often sits somewhere between them. I’m not a lawyer and I don’t have insider insight into the practicalities of the case, but based on what has been revealed so far, the most plausible combined story may be that Apple’s own vulnerabilities helped create an environment OpenAI chose to exploit. If so, Apple’s legal team will be searching hard for evidence of intent.

I expect they’ll find it.

You can follow me on social media! Join me on BlueSky,  LinkedInMastodon and subscribe to The Core.

Kategorie: Hacking & Security

IT department put sticky notes on the laptops to help employees log in

The Register - Anti-Virus - 6 Srpen, 2026 - 14:00
PWNED Welcome back to PWNED, the weekly column where we lovingly poke fun at other organizations' security screw-ups, in hopes the rest of us can learn a valuable lesson. This week’s story involves an IT department that ought to know better putting user credentials in the precisely wrong place. Have a story about someone leaving a gaping hole in their network? Share it with us at [email protected]. Anonymity is available upon request. Our terrifying tech tale comes courtesy of Marc Bishop, director of business growth at Wytlabs, a marketing and SEO company. In the course of his career, Bishop came across one firm where the people guarding the henhouse left the keys out where almost anyone could get them. Bishop’s client company was responsible on the surface. They had a strong password policy and even made users take security training. Then they moved offices, and that's when basic security hygiene went out the window. The company decided to take some old laptops and give them out to new users. To make life easy for the recipients, they put sticky notes – everyone’s favorite credential-sharing tool – on the laptops with the name of each employee and their initial login credentials on it. Let’s just stop for a moment to remark on how bad it is to put usernames and passwords on a piece of paper where the wrong person could see them. Even the IT department should not know your password, should someone in IT themselves turn rogue. So, even if the laptop stayed on a shelf in a closet that only the support staff had access to, having that sticky note would be bad. However, our situation is even worse because the laptops in question were stored in a conference room while the facilities team finished readying the office for the move. During that time, anyone who had access to the conference room could go in and get multiple user account credentials. And that's exactly what happened: A contractor entered the conference room and took pictures of the sticky notes. This non-employee later logged in remotely and accessed all kinds of proprietary data, including planning documents that were sitting on shared drives. What’s particularly shocking about this story is that the IT department was the cause of the information leak. People who work in tech and are charged with maintaining security should never put a password, even a temporary password, out in the open. Password security is paramount. If someone is starting with a new account, send the credentials through an encrypted channel - and preferably ensure only the intended recipient can view the temporary password. ®
Kategorie: Viry a Červi

CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps

The Hacker News - 6 Srpen, 2026 - 13:49
Coinspect has identified CryptoJS.lib.WordArray.random() as the weak random number generator behind the Ill Bloom wallet drains. Introduced in the JavaScript cryptography library 12 years ago, the function supplied weak entropy that affected wallet apps used to generate recovery phrases. Coinspect's on-chain analysis puts the measured theft across two sweeps since late May at a lower bound of Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses

The Hacker News - 6 Srpen, 2026 - 13:33
Cybersecurity researchers have disclosed a security issue with Apple's iCloud Private Relay tool that can expose a user's real IP address. Introduced with iOS 15, iCloud Private Relay employs a dual-hop architecture to ensure users' privacy by routing their Safari web traffic through two relays so that no single third-party, including Apple, can determine where the request is originating from Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory

The Hacker News - 6 Srpen, 2026 - 13:30
A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit. It abuses a standard feature built into almost every major AI assistant: pre-filled deep links. We observed production websites embedding hidden prompt injection payloads inside "Ask AI" buttons on marketing and competitor comparison pages. When a [email protected]
Kategorie: Hacking & Security

80 % čistoty, 2 % námahy. Stojan na kolo Gearrista automaticky vyčistí řetěz po každé jízdě

Živě.cz - 6 Srpen, 2026 - 12:45
Dánská značka Gearrista řeší problém, který má každý cyklista, který chce udržovat své kolo ve špičkovém stavu – čištění řetězu. Gearrista System je stojan, do kterého postavíte kolo po každé jízdě, a tlačítkem spustíte desetiminutový program na čištění řetězu a kazety. Žádná voda, žádná chemie, ...
Kategorie: IT News

Novou baterii pro elektromobily nabijete na 97 % za pouhých osm minut. Ale jen s megawattovým zdrojem

Živě.cz - 6 Srpen, 2026 - 11:45
Automobilka Hongqi otestovala baterii s rychlým dobíjením za 8 minut • Nová čínská baterie výrazně snižuje vnitřní odpor i celkové přehřívání • Prototyp vyžaduje zatím nedostupné megawattové nabíjecí stanice
Kategorie: IT News

Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access

The Hacker News - 6 Srpen, 2026 - 11:19
Attackers broke into an organization's Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an executable to disk. They fed Java source code to the database, let Oracle compile it into stored schema objects, and ran commands from inside the database engine. Huntress, which tracks the toolkit as khunt, Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model

The Hacker News - 6 Srpen, 2026 - 10:57
Security flaws in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel let untrusted or forged instructions reach an agent's tools with no check that a model turn had authorized them. In several of the attack paths, the model never ran at all, so system prompts, content filters, and model-level guardrails never got a chance to intervene. The affected products include Amazon Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Polohovací stůl tam, kde je málo místa. Tenhle má na šířku jen 88 cm a stojí jen 2100 Kč

Živě.cz - 6 Srpen, 2026 - 10:45
Elektricky polohovatelný stůl Di volio Barga stojí jen 2100 Kč. • Má i pracovní desku, fyzická tlačítka, displej a držák na sluchátka. • Díky šířce jen 88 cm se hodí i do menších prostor.
Kategorie: IT News

Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells

The Hacker News - 6 Srpen, 2026 - 10:05
Cybersecurity researchers have disclosed details of a "factory-shipped backdoor" implanted in at least 20 Chinese router models from Zbtlink. According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available from Zbtlink that span more than 2 years. The backdoors are designed such that they start automatically and attempt to beacon to Chinese Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Syndikovat obsah