Agregátor RSS

Lego má novou kosmickou ikonu. Série Icons se rozšířila o téměř půlmetrový Hubbleův dalekohled

Živě.cz - 5 Srpen, 2026 - 15:45
A teď už může mít Hubbla na stole úplně každý. Lego rozšířilo svoji sbírku Icons o novou legendu: 38 centimetrů dlouhou repliku Hubbleova vesmírného dalekohledu. Stavebnice se skládá z 1252 kostiček a stejně jako u ostatních zástupců technické sbírky nabízí hromadu detailů. Nechybí možnost ...
Kategorie: IT News

Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain

The Hacker News - 5 Srpen, 2026 - 15:41
Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer. The new dead drop resolver approach, observed in two trojanized npm packages "bianira-ui" and "fluid-type-ui," has been codenamed NullReceiver by Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

London cops handed victim's new address and number to her stalker, watchdog says

The Register - Anti-Virus - 5 Srpen, 2026 - 15:30
UPDATED The UK's data protection regulator has criticized London's Metropolitan Police Service (MPS) after its officers handed a victim's stalker details about her new phone number and home address, among other failures. The Information Commissioner's Office (ICO) today issued the MPS with an enforcement notice [PDF] and a reprimand over the two incidents, which occurred in 2024. Enforcement notices include specific steps offending organizations must take to meet their data protection duties under UK law, while reprimands serve as official warnings concerning breached data protection laws. The ICO outlined two major incidents that were caused by failures at the MPS, but added that they were not isolated and "reflected wider weaknesses in MPS policies, procedures, and assurance arrangements for handling sensitive personal information." The first involved a man subject to an interim Stalking Protection Order (SPO), which restricted him from contacting his victim. An MPS superintendent authorized an application for an interim SPO in January 2024 concerning a man who had been arrested the previous year on suspicion of harassment and malicious communications offences. The man was also, at the time, subject to bail conditions that included a prohibition on contacting the victim and their friends and family. As a result of the man's actions, the unnamed victim had to change her phone number and home address. Despite warnings that all personal information had to be redacted from the copy handed to the defendant, officers included unredacted witness statements and other documents. These exposed the new address and phone number of the victim, and those of her friends and family members. Within days, after the man fled the UK, breaching his bail conditions, the victim reported to the MPS that the defendant had contacted her on her new phone number. A full SPO was issued in May 2024, and the stalker was arrested in July upon re-entering the UK. He was later charged with stalking offenses and imprisoned following a guilty plea. The second incident was a classic CC-not-BCC email blunder, exposing the addresses of 18 people connected to the UK Parliament who had been targeted in a honeytrap operation by "a malicious actor." The MPS emailed those affected by the honeytrap scheme to update them about the date by which the suspect would have to answer bail, but forgot to use the BCC function, exposing the target's email addresses to one another. The MPS reported the breach that day, acknowledging that recipients might be able to deduce one another's identities from their email addresses, although three of the accounts had recently been deactivated. The MPS told the Information Commissioner that there was "no reported detriment" as a result of the breach and no official complaints made, although it was aware that "some" targets were "displeased" that their names had been shared. One MP raised the issue in the House of Commons. The ICO said that regarding the honeytrap scheme, the officer who sent the email had not completed data protection training for over four years at the time, and their line manager had not completed it for nearly four years also. The ICO found that data protection training completion rates were low across the force, and the MPS has committed to improving them. Jo Stones, group manager of civil and cyber investigations at the ICO, said: "People entrust the police with some of their most sensitive personal information, often at moments when they are vulnerable or at risk. They have the right to expect that information will be handled securely. "In these cases, the Metropolitan Police Service failed to put in place the safeguards needed to protect people's personal information. One breach exposed a stalking victim's new contact details to the person she needed protection from. Another revealed the identities of people connected to a highly sensitive investigation. "These incidents were foreseeable and preventable. Our action makes clear that organisations, particularly those in the public sector handling sensitive law enforcement information, must have effective training, monitoring and assurance in place. Policies and reminders are not enough if they are not followed, checked and enforced." The Met now has 12 months to improve compliance with its data protection training requirements, aiming for 100 percent completion and following up with staff who miss the deadline. It must also review every three months how officers send emails to multiple recipients, consider more secure alternatives, and report its progress on training completion to the ICO. Earlier this year, the ICO served the Met's commissioner with a separate enforcement notice over failures to meet duties under the Freedom of Information Act. It followed a previous notice issued two years earlier, with which the MPS complied. ® Updated to add at 1447 UTC: A Met spokesperson told The Reg: “We take all information breaches extremely seriously and ensure they are reported to the Information Commissioner’s Office (ICO) as soon as they become apparent. “We are aware that these incidents can have real consequences for victims and have apologised to those affected by these two cases. “While we are disappointed to have received this enforcement action, particularly given the improvements already made, we recognise that these breaches were not acceptable and fell short of the standards we expect. “The Met has taken significant steps to strengthen information disclosure processes, as acknowledged by the ICO, and remains committed to ensuring the right training and safeguards are in place to prevent similar breaches from happening again in the future.”
Kategorie: Viry a Červi

Super klávesnice do obýváku. Tahle bezdrátová za 419 Kč má touchpad, Bluetooth i české popisky

Živě.cz - 5 Srpen, 2026 - 14:45
Alzácká klávesnice Eternico K200S zlevnila o 30 % na 419 Kč. • Bezdrátově se připojí ke třem zařízením, má české popisky a touchpad. • Spíš než k počítači se hodí na klín nebo konferenční stolek k televizoru.
Kategorie: IT News

New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch

The Hacker News - 5 Srpen, 2026 - 13:43
A memory corruption flaw in the Linux kernel's Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distributions, and a public exploit ships with pre-built records for roughly 800 kernel builds. The vulnerability, tracked as CVE-2026-64531 (CVSS score: 7.8) and codenamed OVSwrap by its discoverer, was disclosed by security researcher Asim Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk

The Hacker News - 5 Srpen, 2026 - 13:43
Kali365 is turning a legitimate Microsoft login into a gateway to corporate data. The phishing kit targets US organizations with attacker-controlled device codes that victims approve on Microsoft's real authentication page. Once access and refresh tokens are issued, attackers may retain access to email, documents, and cloud resources, creating a direct path to data exposure, financial fraud, [email protected]
Kategorie: Hacking & Security

UK charities count the cost of Beacon CRM cyberattack

The Register - Anti-Virus - 5 Srpen, 2026 - 13:04
Beacon CRM has confirmed it was hit by a cyberattack that exposed data belonging to a growing list of UK charities. The company, which markets its software to charities and has more than 1,500 customers, said its investigation remains ongoing. However, it appears that a substantial amount of customer data was copied, and Beacon is warning users to assume everything they stored on the platform was downloaded. "Currently, our investigation has confirmed that copies of database backups were made and likely downloaded by the unauthorized third-party," it said on Tuesday. "We have evidence that shows a spike in activity during the incident timeline symptomatic of data leaving our systems. "It is highly unlikely we will be able to ascertain any more granular detail regarding exactly what data this was and to whom it relates so out of an abundance of caution, you may want to assume that all data that you store in Beacon, including attachment files, has been downloaded." Beacon also warned that although customer data is encrypted, "it is possible that the unauthorized third party responsible for this incident was able to decrypt it." Customers should therefore assume the copied information was readable. Beacon did not answer any of The Register's questions, instead offering a statement that echoed the wording of its public FAQ pages. It did not comment on whether extortion demands were made, nor how or when the attackers got in. Beacon's information page says early evidence points to compromised credentials being used to access its systems. One affected charity said the company became aware of the attack on July 29. Beacon also said anyone with a paid account or free trial created before July 27 should assume that all data stored in it was downloaded. While the incident response folk do their thing, customers have been urged to investigate how badly they were affected. Beacon also reset every user's password and imposed stronger requirements on replacements. Charities hit Because Beacon CRM is a product specifically engineered for the charity sector, the bulk of those confirmed to be affected are UK charities. Among the higher-profile victims is the Molly Rose Foundation, a persistent campaigner on the UK's Online Safety Act. It said Beacon informed it of the situation on August 3, five days after the CRM company became aware of the breach. The foundation confirmed that personal data belonging to supporters, donors, and service users was affected. That includes names, addresses, email addresses, phone numbers, genders, dates of birth, records of donations or payments made to the foundation, and other information supplied in connection with its services and activities. The Scottish Council for Voluntary Organisations (SCVO) did not identify individual victims, but said many Scottish charities use Beacon CRM. Other charities confirmed to be affected include: London-based homeless charity The Upper Room Chiswick House and Gardens Trust Victim Support (no victim data affected) Macmillan Cancer Support Jersey, per the Bailiwick Express Young person's charity Motiv8, according to Portsmouth News UK-Med PANS PANDAS UK, a children's charity for those with the PANS and PANDAS conditions, said that it was unsure whether its data had been affected, having abandoned Beacon earlier in the year. English National Ballet told The Register: "As one of Beacon CRM's customers, English National Ballet was informed on 3 August 2026 that an unauthorised third party had gained access to their system. "English National Ballet has not received confirmation that our data was directly affected, however as a precaution we have informed all contacts as soon as possible that their data could potentially have been accessed. ENB take data privacy extremely seriously. We are doing everything we can to reduce the risk of anything similar happening in the future." ®
Kategorie: Viry a Červi

Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup

The Hacker News - 5 Srpen, 2026 - 13:04
An unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in versions 1.22.1 through 1.27.0. No login, no repository write access. A public repository and crafted Org-mode markup are enough. The flaw is fixed in Gitea 1.27.1. The file-read flaw is tracked as CVE-2026-59774, rated Critical with a CVSS score of 9.8, and received its Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Ošklivé elektrické Ferrari je vyprodané. Internet prorokoval fiasko, šéfové tech firem z USA a Číny vytáhli peněženky

Živě.cz - 5 Srpen, 2026 - 12:45
Když se v květnu představilo první elektrické Ferrari všech dob, strhla se na internetu bouře všemožných názorů proč a jak je úplně špatně. Je elektrické, má tvary crossoveru, nikdo ho kupovat nebude, a když se zákazníci budou cukat, italská značka jim neprodá své výjimečnější modely se spalovacími ...
Kategorie: IT News

RawTherapee 5.13

AbcLinuxu [zprávičky] - 5 Srpen, 2026 - 12:44
Byla vydána nová verze 5.13 svobodného multiplatformního softwaru pro konverzi a zpracování digitálních fotografií primárně ve formátů RAW RawTherapee (Wikipedie). Vedle zdrojových kódů je k dispozici také balíček ve formátu AppImage. Stačí jej stáhnout, nastavit právo ke spuštění a spustit.
Kategorie: GNU/Linux & BSD

Leaked n8n API Tokens Exposed Live Instances to Credential Theft

The Hacker News - 5 Srpen, 2026 - 12:35
GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without exploiting a software vulnerability. We scanned public GitHub commits for exposed n8n API tokens and identified 4,576 unique credentials associated with 1,255 hostnames. Of the 896 [email protected]
Kategorie: Hacking & Security

EU vydala katastrofální předpověď dezertifikace kontinentu. Do roku 2040 bude ohrožené celé Polabí a jih Moravy

Živě.cz - 5 Srpen, 2026 - 12:13
Společné výzkumné centrum Evropské komise JRC před pár dny vydalo novou publikaci, ve které se vědci na základě přesnějších dat z družic programu Copernicus a nových modelů snaží lépe charakterizovat postupnou degradaci půdy v Evropě a riziko dezertifikace. Na první pohled by se mohlo zdát, že ...
Kategorie: IT News

6 things you should know about Google’s new selfie sign-in system

Computerworld.com [Hacking News] - 5 Srpen, 2026 - 11:45

Losing access to your Google account might just be the epitome of a modern-day nightmare.

Especially if you’re using Android and even more so if you’re invested in lots of different Google services on top of that, the amount of access and info connected to that one single sign-in is just staggering. Think about it: You’ve got everything from your Android apps and settings to potentially your email, your documents and spreadsheets, and all of your assorted files in Google Drive. And that’s to say nothing of all the images you might be backing up to Google Photos, the notes you might be storing in Google Keep, and even random things you might not think about like your browsing activity in Chrome or your location-related data in Maps.

It’s a lot, to say the least. And that’s precisely why it’s so important to think about your Google account security proactively and do everything you can to (a) make sure no one else ever gains access and, equally important, (b) make sure you never lose access to that all-encompassing sign-in.

At this point, you’re hopefully already doing smart stuff like using a unique and secure password and relying on two-factor authentication to add an extra layer of security beyond that — or maybe using a passkey for an alternate form of two-factor protection.

But even with all of those layers, the issue still remains of what happens if for any reason you aren’t able to get into your own Google account one day. And now, Google’s got a new option to help you make sure that nightmare never actually comes to pass.

Suffice it to say, it’s well worth your while to consider. But there are some important things you should know about it first.

[Get fresh Googley insight in your inbox with my free Android Intelligence newsletter. One new and useful tip every Friday!]

The ins and outs of Google selfie sign-in

The system of which we speak is an option to use a sophisticated selfie of yourself to sign into your Google account in an emergency — if all of your usual methods are for whatever reason not getting you through the gate. It happens more often than you’d think. And having multiple secure workarounds in such a scenario could be a massive lifesaver if it ever happens to you.

Depending on where you look, the option is called “selfie for sign-in,” “video verification,” or sometimes just “selfie video.” (Hey, this is Google we’re talking about here. Branding has never been a strength.) The system was announced in a random blog post a couple weeks back and has been slowly but surely showing up under the hood for accounts around the world ever since — but you’d never know it unless you happened to poke around in the exact area of your Google account settings where the option appears.

In my experience so far, it seems most average Android-owning animals are woefully unaware of its existence — and those who are aware of it are mostly perplexed by how exactly it works and if or when it’s advisable to use.

I’ve set it up on my own personal Google account, and I’ve explored every last nook and cranny. Here’s everything there is to know:

1. Selfie sign-in is super simple to set up

Seriously — it couldn’t be much easier. Just go to this page within the Google account settings site on a device with a camera (like, y’know, your phone or maybe an Android tablet).

Provided the feature is available on your account now, you’ll just click a couple o’ quick buttons to get the process started, then you’ll follow some simple prompts to stare into your camera longingly for a few moments.

Setting up a Google selfie sign-in is surprisingly swift ‘n’ simple.

JR Raphael, Foundry

The system will ask you to turn your head in specific directions. Then, it’ll take a handful of seconds to process and save your stunning turn on the virtual runway.

The process takes less than a minute to verify and save your selfie video.

JR Raphael, Foundry

And — well, that’s pretty much it.

2. Your selfie video is only for access to your Google account — not your phone or tablet

This is slightly confusing, since most modern Android devices offer the ability to use biometrics on the lock screen and show your face to unlock the phone itself — but the selfie sign-in system we’re speaking of here has nothing to do with any of that. It won’t unlock your device in any scenario or have any connection to any specific phone or tablet.

It’s connected purely to your Google account, and its sole purpose is acting as a mechanism to let you sign into that account — not to unlock or access any specific piece of hardware.

Speaking of which…

3. It’s only there as a last resort

Once you set up your selfie sign-in, odds are, you’ll never actually think about it again or have a reason to use it. Anytime you sign into your Google account, you’ll still use your standard password, passkey, and any two-factor authentication you’ve placed on the account.

The selfie path is there only in the event that all those regular methods are for some reason failing you. It’s unlikely, but it’s not impossible. And with your selfie video saved, if that situation ever arises, you’ll have an easy alternate way to prove your identity — by submitting a live on-the-fly selfie video and allowing Google to match it with your original saved one — so you can avoid getting locked out.

4. The selfie sign-in is designed to be both private and secure

When it comes to matching a saved selfie video and a new live one, Google requires different movements to verify validity and avoid any impersonation attempts.

Google says the data from your saved selfie video is always encrypted, too — not just in transport but also at rest, when it isn’t actively being used — which means no one else should ever be able to access it or do anything with it. You can always opt to delete a saved selfie video entirely, if you want, via that same Google account settings page.

And on that note…

5. You can prevent your selfie video from being used for any form of training

Lots of folks are understandably uneasy about the idea of their personal data — including their personal faces! — being used for any manner of machine learning these days. Google does ask for permission to do that and anonymously lean on your submission to help improve its facial recognition systems when you sign up for the selfie sign-in option, but critically, you can easily say no thanks.

When you’re in the midst of the selfie sign-in setup, look for the option to “Improve Google services.” It’ll appear at the bottom of the initial service agreement.

Keep that box unchecked, and your selfie video will never be used for any form of training or other purposes.

JR Raphael, Foundry

As long as you don’t check the box in that area, your selfie sign-in data will never be used for anything other than its primary intended purpose. And if you ever change your mind or are unsure of how you initially answered, you can also always revisit and revise that decision on that same Google account settings page.

The option to opt out of model training is always available on the selfie video settings screen.

JR Raphael, Foundry

6. Selfie sign-ins are (so far) only for individual Google accounts

With this initial rollout, Google’s selfie sign-in option is not available for accounts that are part of a Google Workspace team or organization. That kind of makes sense, since in any such situation, you could always turn to an admin for help if you were ever to lose account access, anyway.

This is something more intended for individual Google accounts, where you’re on your own and largely out of luck if you ever lose access. So whether you’re conducting business from an individual account or using an individual account alongside a Workspace-connected company sign-in, it’s something to consider for that part of your online identity.

The only other noteworthy asterisk is that selfie sign-ins won’t work with accounts where Advanced Protection is enabled. Advanced Protection is an extra-heightened form of Google account security created for people in the public eye or otherwise at an elevated risk of a targeted attack, and so it deliberately makes it much more difficult to get into an account in ways that go above and beyond what’s necessary for most ordinary organisms. If you have Advanced Protection on for your Google account, selfie sign-in won’t be available for you.

But for the rest of us, it’s a powerful new path that could prevent an unthinkable nightmare — and all you’ve gotta do is take two minutes to set it up now and then hopefully forget all about it.

Got Android? Check out my free Android Intelligence newsletter to get an exceptional new tip in your inbox every Friday.

Kategorie: Hacking & Security

Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data

The Hacker News - 5 Srpen, 2026 - 11:23
A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed. The "evil twin" extensions were uploaded to the repository between July 26 and August 1, 2026, according to Manifold Security. The packages have been removed from Open VSX as ofRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Ostuda Xboxu One může Microsoftu pomoci v další bitvě s PlayStationem. Převod disků do digitálu se rýsoval již před 13 lety

Živě.cz - 5 Srpen, 2026 - 10:45
Před 13 lety chtěl Microsoft zabránit bazarovému prodeji her. • Po velké kritice tuto technologii rychle zrušil. • Nyní ji ale vytáhne jako vítězný triumf.
Kategorie: IT News

Výrobci: GeForce RTX 5000 zdraží o 20-30 %, zastavili jsme dodávky levných karet

CD-R server - 5 Srpen, 2026 - 10:00
V kontextu zdražení grafických karet společnosti Nvidia vyšlo na povrch několik zajímavých informací. Zdražení bude spíš výraznější a výrobci jej využijí i k výhodnějšímu zpeněžení skladových zásob…
Kategorie: IT News

Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself

The Hacker News - 5 Srpen, 2026 - 09:53
An agent running Anthropic's Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project during a cyber evaluation by the UK's AI Security Institute. When a bystander publicly warned that the code was malicious, the agent denied it, force-pushed a rewritten branch history to erase the evidence, and posted from a second account it controlled to vouch forSwati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Syndikovat obsah