Agregátor RSS
Více než rok po promítání na karlovarském festivalu přichází do české distribuce jeden z nejbizarnějších animovaných titulů poslední doby, u něhož se dá však dokonale vypnout. Princezna Kosmolesba (Lesbian Space Princess) je totiž přesně tak střelená a ulítlá, jak slibuje už samotný název.
Multiple 'watermark removers' have surfaced days after Anthropic began watermarking text generated by Claude, including an open source project with over 4,500 GitHub stars and paid AI detection evasion services. None of the tools' claims about defeating the text watermark can be verified, as Anthropic has not released a detector. [...]
Byl by to řadový kyberbezpečnostní incident nevalného dosahu, jenže se stal na palubě letadla, což mu okamžitě přisoudilo řádově vyšší význam a pozornost od mezinárodních médií po FBI.
K incidentu došlo na letu 591 společnosti Delta Air Lines 10. srpna z Las Vegas do Atlanty (Boeing 757). Skupina ...
Byl by to řadový kyberbezpečnostní incident nevalného dosahu, jenže se stal na palubě letadla, což mu okamžitě přisoudilo řádově vyšší význam a pozornost od mezinárodních médií po FBI.
K incidentu došlo na letu 591 společnosti Delta Air Lines 10. srpna z Las Vegas do Atlanty (Boeing 757). Skupina ...
A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. [...]
Apple now has a long and storied history in wearables. The Apple Watch set expectations for the category, replacing Swiss watches on so many wrists on its journey to become the world’s most widely worn wearable AI device. But is Apple making the most of the technology it has now developed — and is there another opportunity waiting to be explored?
Apple seems to think there might be. Mark Gurman recently reported the company is exploring a wider family of wearables, including products such as fitness bands and rings. And while the latter certainly represents a viable opportunity, the fitness band market seems ripe for a good bit of Sherlocking.
Why is it ripe?
The technologies Apple already has
First, think of the technologies Apple can already bring to a fitness band product. The sensors, algorithms, and software the company has already developed would certainly make sense in wristband form when used with a paired iPhone to review the data the band collects. Apple’s sensors have a good reputation for accuracy and could deliver outstanding battery life. They could carry a smaller display to show limited amounts of information, such as time or distance travelled. And I expect the company’s product design teams could build a high-quality health and fitness band with very little effort, as some of the key technologies to support such a device have already been tried and tested on Apple Watch.
Privacy as a product
The second reason is competitive. Apple knows that in Europe under the Digital Markets Act it will eventually be forced to give third-party devices, including fitness bands, peer access to the kind of data it already uses in the Apple Watch. The company has suggested a protected system in which that information is shared (once it has been cleaned up to protect customer privacy), but EU regulators have not yet agreed – and perhaps never will.
The problem at the moment is that Apple doesn’t make a fitness band other than Apple Watch. And there are enough Apple customers who use third-party bands that the company might see an opportunity to bring its own versionto market as a fitness band that doesn’t erode privacy. Ironically, EU competition regulators have given Apple a reason to compete for a market it didn’t originally want to get into — to the likely detriment of incumbents in the fitness band space.
What customers want
The third reason is the nature of the market itself. Recent success by the likes of Fitbit Air, Cirqa, or Whoop show growing interest among consumers for screen-free, all-day trackers.
“Consumers want either minimalist, screenless trackers they can wear 24/7 or feature-rich sports watches with superior accuracy and multi-day battery life,” Jason Low, research director at Omdia said in a statement. “Premium and screenless devices are gaining ground, while basic watches and mid-tier smartwatches are being left behind.”
Apple leads the smartwatch side of the equation with a 46% global share, Omdia says, while Garmin (with 15%) posted the biggest share gain among non-Apple vendors. “Garmin’s market share gains highlight a clear trend: consumers are increasingly willing to pay premium prices for devices that deliver accurate, advanced training data and translate it into actionable insights,” Low said.
What Apple offers
Apple already has its own market-tested technology to provide accurate and advanced fitness monitoring if provided on a screenless device. As its business is not built on selling the data its devices gather, it can supplement those high-quality features with privacy promises some other vendors don’t match, while offering additional features and services through integration at a platform level. Add Siri AI to the mix and access to Apple Music and the device seems even more compelling.
Apple might be motivated to boost attachment rates to customers who will update iPhones, Macs and other Apple devices less frequently in response to recent price increases. The logic is that if customers can’t afford a new iPhone, they might invest in an Apple Watch, AirPods, or fitness band instead, becoming more deeply invested in Apple’s ecosystem as they do.
The potential returns seem promising: the fitness tracker market is expected to $generate 189 billion by 2032. That’s real money Apple already has the tech to take a grab at – and its years of work on colorful Apple Watch bands means it could offer its bands in a wide selection of designs at a price consumers will find they can afford.
You can follow me on social media! Join me on BlueSky, LinkedIn, Mastodon and subscribe to The Core.
With the launch today of the AI Collaborators feature in Workfront, Adobe aims to bring AI agents directly into the flow of work as permissioned team members that can be assigned tasks.
Three types of these ‘collaborators’ are now generally available in Workfront. A content reviewer agent automatically checks documents in the work management app against brand guidelines. A project coordinator tracks project progress and keeps stakeholders up to date.
Then there are “task agents” that let customers connect external AI agents to Workfront and assign them work.
The task agents are geared towards a variety of purposes — a social media manager that turns briefs into published posts, a performance analyst that reports on how campaigns are faring, or a content designer that creates visuals and layouts.
To set up a task agent, users provide a name and description of the agent’s purpose, then connect it to an agent platform, with Anthropic’s Claude, Microsoft’s Copilot Studio, and Writer currently highlighted as options.
Once it’s ready to go, users can assign work to the agent in a Workfront project just as they would a human user.
As the agent carries out its tasks, an auditable trail of actions is recorded via the Workfront “update stream.” That allows humans to review outputs, such as AI-generated copy, and approve or adapt the result as needed.
Only admins are permitted to create AI Collaborators within Workfront.
With the launch of AI Collaborators in Workfront, Adobe’s intention is to deploy AI agents where work actually occurs, said Brent Rudewick, vice president for strategy and product management for Adobe GenStudio and Workfront. That, in turn, can help customers shift AI investments from proof of concept to production.
“The challenge we were solving is: how do we bring an agent into the context of the workflow as an authorized, permissioned user?” said Rudewick. “That’s what an AI Collaborator is.”
In many cases, employees might already use their own AI agents — be that ChatGPT, Claude, Copilot, or other tools. But those agents are removed from important information relating to work tasks, said Rudewick.
“Workfront already has all that context because it’s got the previous briefs you’ve done, the previous content, and it understands the knowledge graph of how that stuff works,” he said. “You’re bringing that agent into a system that already has all of the context: it knows what it needs to go and do, instead of you having to tell it every time you go into one of those other surfaces.”
“This is a step in Adobe’s evolution of AI and automation capabilities,” said Jessica Liu, principal analyst at Forrester. “It follows in the direction of the overall technology market.”
Marketers are looking to automation to gain efficiency, she said, though effectiveness is “unfortunately more of an afterthought at the moment.”
Any automation benefits will depend on organizations having well-designed processes and workflows, Liu said. “Technology that can support marketers in those efforts is helpful, but only if marketers can help themselves first,” she said. “Specifically, they need to have processes and workflows that are diagnosed, scoped, designed, implemented, and optimized. It’s very difficult to automate a process or workflow that is broken or non-existent.”
At the same time, Adobe wants to make it easier for Workfront users to access the feature from third-party AI agent tools via a model context protocol (MCP) client. At launch, this enables users to take actions such as creating a campaign record, assigning work, approving content and more from ChatGPT, Claude, Copilot and others.
“We want to give choice to the customer,” said Rudewick. “If the enterprise has decided, ‘Hey, Claude is the predominant surface we’re going to use,’ we want them to be able to use that surface and not be blocked to get the value that they have in their application investment in Workfront.
“If you boil Workfront down to its most rudimentary sense, it’s a campaign, it’s a project, it’s a task, it’s an assignment, and it’s an approval — that’s really what Workfront is, so how do we expose that through whatever surface?”
The emergence of AI tools that can perform tasks on behalf of users has been viewed as a threat to software companies such as Adobe. But even as Adobe opens Workfront up to third-party AI platforms, Liu believes the company’s AI investments can help ensure customers remain in the Adobe app.
“For marketers who use many Adobe products, having Workfront AI Collaborators operate within Adobe’s ecosystem should be easier for data transfer, access management, and user interface and experience,” said Liu.
AI Collaborators are available at no additional cost to Workfront customers (Adobe does not publish Workfront prices). However, using the “task agent” AI Collaborator could incur additional costs for third-party agents that connect to Workfront.
Hra o trůny (Game of Thrones) patří k nejslavnějším seriálům HBO. V osmi sezónách nabídla boj mocných rodů o vládu nad Západozemím, politické intriky, války, zrady i fantasy. V roce 2022 na ni navázal Rod draka a svět George R. R. Martina se od té doby dále rozrůstá. Pokud vás podobné výpravné ...
Hardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping and logistics provider, was hacked [...]
Donald Trump is allowing government agencies to contract private cybersecurity companies to carry out operations against cyber-enabled transnational criminal organizations (CE-TCOs). The US President signed a memo on Wednesday confirming a strategy hinted at earlier this year, saying participating companies can support national operations against criminals, including cyber surveillance and technical disruptions of their networks. The latter, described as "Cyber Effects Operations," covers activities that cause "the manipulation, disruption, denial, degradation, or destruction of information systems, networks, physical or virtual infrastructure controlled by information systems, or information resident thereon." Although the memo establishes a distinction between cyber effects operations and cyber surveillance missions, it acknowledged that the latter will also inevitably involve some disruption or manipulation of systems in order to carry out the surveillance. Surveillance operations are designed for intel gathering, either to support further snooping or for later use in cyber effects operations, with the intent of remaining undetected. Trump described CE-TCOs as "any foreign group that conducts cyber-enabled crime against the United States Government, a United States person, or United States interests." Crucially, the definition excludes entities directly associated with, or operating wholly on behalf of, foreign governments. No stepping on TAO's toes, of course. Participating companies will undergo "rigorous vetting" and will be subject to "strict operational procedures," the memo adds. The operational procedures are to be drawn up within 60 days and codified by program executive directors working with the Homeland Security Council. Companies wishing to be called up for service will have to demonstrate that they have the technical capabilities to carry out the required operations, and be willing to prove this each year via annual evaluations. Program managers must ensure that the operational procedures open opportunities for highly resourced, large organizations, as well as "smaller, more agile companies" that may prove useful for "specialized or discrete tasks." The Justice Department will also play a role in authorizing operations, particularly those targeting US residents or raising domestic legal issues. Participating companies will also be prohibited from executing operations that could lead to "critical outcomes," which is shorthand for attacks that result in the loss of life or serious injury, or those that could be seen as an armed attack under international law. These companies will also be required to maintain a bond or escrow of at least $1 million, which shall be forfeited if they violate the terms of their contracts. Unleashing Trump's cyber army The White House published "President Trump's Cyber Strategy for America" document in March, which promised to "unleash the private sector by creating incentives to identify and disrupt adversary networks and scale our national capabilities." The document [PDF] also stated: "We will leverage the immense talents and ingenuity of our private sector research base. "We will establish a new level of relationship between the public and private sectors to defend America in peace and war." The announcement prompted legal eagles and think tanks to ponder the implications of such a move. Many wondered how the promise to mobilize the private sector would be put into practice. They did not then have the details contained in this week's memo, and some assumed participating companies would support operations against nation-states. This particular program, however, excludes entities acting directly on behalf of foreign governments. Writing for the Royal United Services Institute (RUSI) and citing reporting available at the time, cyber and tech research fellow Gareth Mott said that the US Computer Fraud and Abuse Act (CFAA) might need to be amended before American companies could legally offer such services. Experts from law firm Skadden, Arps, Slate, Meagher & Flom agreed, despite the US Cyber Strategy not mentioning any plans for legislative changes. They wrote: "Any attempt to more directly involve the private sector in offensive cyber actions will likely require further legal and regulatory changes before it can be meaningfully implemented. "Even if the administration were to issue new enforcement guidance redirecting prosecutions away from hack-back cases, the availability of civil penalties under the CFAA and its five-year statute of limitations would likely render such executive actions significantly less impactful. "Technology companies should consider closely monitoring developments to track how the administration plans to enact such incentives." However, Jenner & Block lawyers noted in an analysis published by Lawfare that a provision of the CFAA could limit participating companies' exposure. Title 18 of the US Code, § 1030(f), says the CFAA does not prohibit lawfully authorized investigative, protective, or intelligence activity by a US government agency or intelligence agency. Participating companies might therefore be protected when acting under government contracts and direction. However, no court has determined whether that exemption covers private companies carrying out such work. "No court has addressed whether this exception provides any protection for private-sector entities engaged to perform these activities on behalf of the US government and, if so, under what circumstances," the lawyers wrote. "At the very least, it is unlikely that a court would interpret this provision to extend to private companies engaged in independent offensive operations, without government direction or involvement." The last part is key: because the US government will draw up procedures and direct the companies' involvement, the work may fall within the CFAA exemption. Whichever way the US constructs its private sector play, it represents a significant shift in the country's cybersecurity policy, and perhaps that of other nations further down the line. As Mott points out, US allies will certainly be keeping tabs on the private sector program's success, and its take-up from the companies it looks to attract. ®
Afghan telecom providers and South Asian critical infrastructure organizations have emerged as the target of a new ongoing campaign that delivers a previously undocumented backdoor called PATCHCORD.
According to Acronis Threat Research Unit (TRU), the backdoor is a compiled C/C++ implant delivered by means of sector-specific lures, including fake VPN installers impersonating Afghan Telecom (Ravie Lakshmananhttp://www.blogger.com/profile/ [email protected]
Confidence in an organization's cyber recovery capabilities deserves scrutiny. If a ransomware attack disables the SaaS data tenanted in the Microsoft cloud ecosystem, the data the business depends on as its lifeblood, the pace at which operations resume rests on assumptions that often prove wrong. Anyone whose answer is "It's all good. Microsoft has my back on this one with its comprehensive native retention and recovery capabilities" is due a reality check. With agile business tools like M365 and Entra ID and solid backend infrastructure in the form of Azure, Microsoft brings a lot to the SaaS party. Both IT departments and MSPs need to be aware, however, that Redmond operates on the same shared responsibility model as other major SaaS providers. In the event of a cyberattack, the recovery burden splits between what the cloud provider handles and what falls to the subscriber alone. MSPs face the additional pressure of meeting stringent SLAs, working with clients’ preferred providers or tooling, and managing their own staffing and profitability accordingly. Microsoft ensures that its services keep running in the aftermath of a strike but does not promise to restore data to a specific known good point before the disaster. That gap always sat with the customer, and planning for it before problems hit beats improvising while picking up the pieces. "There's a common misconception about what Microsoft is responsible for, as distinct from the service they're providing," explains Brent Torre, GM of cyber resilience . Microsoft's native tools, he points out, address problems like short-term accidental deletion and aspects of data governance. They are not a backup solution and will not protect against ransomware or recover data. "Microsoft is clear that whether it's a SaaS application like Microsoft 365, a platform application like SQL Server, or even VMs running in Azure, the customer is always responsible for the information that's in that service, as well as devices, accounts and identities," he adds. "If you get compromised and the attacker starts deleting data, Microsoft has no responsibility for that." A world of pain The gap between availability and true cyber recovery is misunderstood, and it has widened into something of a chasm in recent years. There are three contributing factors to this gap. The first is the evolution of cyberattacks. Typical cyberattacks have pivoted from muscling past a defensive barrier to targeting human weakness, because strolling in through the front entrance with a stolen pass is easier than shimmying through a forced window. Identity has become the primary attack surface. Credential compromise, or identity-based initial access, removes the need to find a vulnerability to exploit and requires only an unwary employee. AI is now a staple weapon in the criminal arsenal, augmenting exploitation techniques such as phishing, social engineering, deceptive emails and spoofed websites, all convincingly used to trick users into typing passwords into a portal controlled by the aggressor. The technique can get more scientific than that. Automated AI-powered bots test millions of leaked username and password pairs across hundreds of different websites, exploiting the common habit of password reuse. Microsoft Entra ID, the vendor's cloud-based identity and access management service and the very tool designed to keep criminals out, is now a prime vector for attack and no match for stolen identity. Once an attacker compromises Entra ID with pilfered credentials, without setting off alarms, they have a free run at gathering data from mailboxes, OneDrive, SharePoint, Teams and other soft targets. The ransomware attack itself can then be launched with ease and at leisure. Another contributory factor is that the vogue for moving workloads to infrastructure and platform as a service (IaaS and PaaS) models shows no sign of abating. Organizations tend to retain some functions on-premises, put some in SaaS applications, and others in cloud environments, but are often guilty of not protecting and managing everything to the same level of quality. Data gets backed up in a variety of locations, yet whether it is all equally recoverable in the event of a breach is another chink in the armor that nobody understands. The 'as a service' model is popular, but it is the weak link when ransomware strikes. The third part of the problem is the emergence of multiple compliance requirements mandating cyber resilience along with correct backup and recovery procedures, for which many organizations are ill-prepared. Together, these pressures give criminals room to do enormous harm to data, business operations and compliance posture in the gap between attack and restoration of SaaS availability. Given that Microsoft's native retention and recovery capabilities are not designed to deliver true cyber resilience, restoring the business to how it was before the attack is something to plan for in advance. Time for independent backup protection "At Kaseya we regularly recommend that you keep a copy of your data, independent of the primary environment it's operating in," advises Torre. "This needs to be something immutable that you can recover from even if the Microsoft or Google or Salesforce ecosystem goes down." This kind of protection is best delivered as a dedicated cloud-to-cloud backup solution stored outside the main SaaS tenant, he argues, an approach increasingly written into cyber insurance and compliance requirements. By pulling copies of regularly targeted data from the Microsoft tenant for storage offsite in a third-party datacenter, organizations can be sure that if SaaS credentials are compromised, critical assets remain safe from attack. Restoration can then push what is needed directly back into the SaaS environment, even where the original tenant has been destroyed. "In fact some people find it faster to stand up a new shell and rebuild it than try to gain access back into a compromised tenant," notes Torre. "Whether you're an internal IT technician, working the night shift, or an MSP needing to live up to your SLAs and maintain profitability, you require a solution that's super straightforward and you need to be able to trust that the recovery will work. Both IT departments and MSPs should be looking out for a solution that's incredibly easy to use. Disaster recovery isn't the only job that they have." A good platform, he says, focuses not just on guaranteeing recovery but on keeping the hygiene of the cyber resilience estate at a high standard without endless human intervention. It should also make certain that Microsoft 365 and Entra ID are restored together in a single workflow, so identity and the data it grants access to come back online in the right order rather than in separate stages. Choosing the right platform Datto is a cybersecurity and data protection business owned by Kaseya. Datto SaaS Protection for Microsoft 365, Datto Backup for Microsoft Azure, and Datto Backup for Microsoft Entra ID are designed between them to close the gap between availability and recovery by storing protected copies of tenant data in the Datto Cloud, outside the Microsoft environment. In this way a compromised production tenant does not take the recovery point down with it. "With our M365 backup, we're protecting one million users worldwide," claims Torre. "A lot of organizations have built trust around our ability to protect and recover their data. We offer a trusted platform for recovery that focuses on ease of recovery, ease of deployment, not just for M365 but for Azure and Entra ID too." Both IT bosses and MSP players need to recognize that a ransomware attack, or other cyber crisis, is a matter of when rather than if. Recovery matters more than protection, because protection is certain to fail at some point, and traditional approaches to backing up data are no longer sufficient on their own. Anticipating disaster is not enough; the organization also needs to be set up to withstand it. That means being as certain as possible that the Microsoft environment can be recovered rapidly, down to the last scrap of data. This capability underpins modern business workflows and operations. Microsoft tracks more than 4,000 identity attacks every second and analyzes 38 million identity risk detections daily — no organization is off the target list. When an attack lands, the restoration clock is already ticking, and any delay in fully restoring IT operations and key environments to their pre-attack state can mean the difference between survival and collapse, with profit, regulatory standing and reputation all riding on the outcome. Securing data with purpose-built cyber resilience platforms that enable rapid, clean recovery is how organizations meet that test. MSPs looking to close the gap can start with the Datto MSP Buyer's Guide to Microsoft Entra ID Backup Sponsored by Datto.
Firma IBM uvedla svůj první mikropočítač Personal Computer před 45 lety, v srpnu 1981. Základní konfigurace modelu 5150 za 1 565 tehdejších dolarů obsahovala desktop s Intel 8088 a 16KB RAM, Color Graphics Adapter a klávesnici. Právě klávesnice Model F/XT vybavené kapacitními spínači, vlivné a s převodníkem dodnes použitelné, připomíná sběratelský web Admiral Shark's Keyboards.
Podle analytiků z Counterpointu už čínští výrobci DRAM a NAND pamětí prohánějí své korejské a americké rivaly. Zpráva ze začátku srpna ukazuje, že ChangXin Memory Technologies (CXMT) již patří 7 % trhu s čipy pro operační paměti, když zaznamenala 719% meziroční růst.
Konkurenti jsou v objemu ...
A Linux security tool can catch a system call and still record the wrong thing.
AI coding tools can introduce unvetted or hallucinated open source dependencies faster than traditional security reviews can keep pace. ActiveState explains why organizations should govern packages at the point of selection, before they enter the development pipeline. [...]
Linux Audit can tell defenders that a system call ran while leaving out the setting that explains what the call did.
V Rumunsku kvůli rekordnímu suchu na Dunaji odstavili celou jadernou elektrárnu • . • Vojenské odstřely koryta nepomohly a stát na srpen vyhlásil energetickou nouzi. • Chybějící elektřinu nahradí obnovitelné zdroje, uhelná elektrárna i dovoz ze zahraničí.
Cybersecurity researchers have disclosed details of a new macOS-oriented, Rust-based information stealer called AmnesiaStealer that's capable of hijacking Chromium web browsers to steal session data.
The multi-stage stealer is spread via a counterfeit GitHub download page titled "Download for macOS" and claims to be from a verified publisher. The page employs a ClickFix-style lure that Ravie Lakshmananhttp://www.blogger.com/profile/ [email protected]
A new White House memo signed by U.S. President Donald Trump instructs the National Coordination Center (NCC) to establish a program that would allow private security companies to apply for approval to hack foreign cybercrime organizations. [...]
|