Agregátor RSS

Klíčová slova „auto“ a „typeof“ v C23

ROOT.cz - 4 Srpen, 2026 - 00:00
Jedním z nejvíce konzervativních programovacích jazyků používaných v současnosti je klasické céčko. Součástí specifikace C23 je i rozšíření sémantiky klíčového slova „auto“.
Kategorie: GNU/Linux & BSD

Archeologické muzeum na Naxu, dokončení v antice

OSEL.cz - 4 Srpen, 2026 - 00:00
Napřed keramika zdobená v geometrickém stylu, pak archaické plastiky a po nich stavební dekorace, šperky a sklo z helénistické a římské doby. Skončíme velkou pozdně antickou mozaikou. To vše od 9. století před n. l. do konce antiky, snad až do 5. století n. l.
Kategorie: Věda a technika

Rezervoárový počítač v kapalině: Data zpracovávají kmitající částice

OSEL.cz - 4 Srpen, 2026 - 00:00
Představte si počítač, který tvoří soustava mikročástic v kapalině. Rezervoárový počítač s aktivními koloidními oscilátory z Kostnice je úplně jiný, než jste zvyklí. Funguje jako blackbox a stále plně nechápeme jak. Přesto umí pozoruhodné věci, včetně předpovídání chaotických časových řad nebo odhalování nepatrných anomálií v datech.
Kategorie: Věda a technika

Ryzen AI Max+ PRO 495 Gorgon Halo zachycen v Geekbench, výkon nápadně stoupl(?!)

CD-R server - 4 Srpen, 2026 - 00:00
Gorgon Halo alias Strix Halo-refresh se objevil v databázi nového testu GeekBench 7. Výkonnostní výsledky s posunem o 32 % se však zdají být až příliš dobré…
Kategorie: IT News

Google dev kit spurs first-ever agent-on-agent violence

The Register - Anti-Virus - 3 Srpen, 2026 - 22:30
In what they call the first-ever real-world agent-to-agent exploitation method, Pillar Security researchers say they discovered an exploit in the repository behind Google's Agent Development Kit for Python that could allow attackers to compromise supply chains. In other words, now we know that one AI agent can be used to control and compromise another one that has more privileges. The security snafu existed in google/adk-python, an open source Python toolkit with more than 90 million downloads used to build and deploy AI agents. Google has since fixed the underlying issue in the repository but deemed the exploit non-rewardable because it involved social engineering. Even so, it illustrates the risks of using AI agents in CI/CD workflows for triage, pull request (PR) reviews, and discussions. It also shows how one AI agent could attack another in a production environment, according to Pillar’s Dan Lisichkin, who found and reported the vulnerability. “Our world is changing quickly, and new attack surfaces are not yet reflected in threat models because these attacks never could exist in the first place in the ‘pre-agent’ world,” Lisichkin said in a technical write-up published on Monday. He will also discuss the findings during a poster talk at DEF CON's AI Village on Friday, August 7 at 1600 PDT. “CISOs and security practitioners should start considering these scenarios, threat-modeling them, and calculating worst-case implications and blast radius,” Lisichkin wrote. The issue stems from the way that the repo ran two classes of automated AI agents with different privilege levels that unintentionally share a trust boundary. One is a low-privilege, public-facing AI agent activated whenever a user opens a pull request (PR) or issue, and a second is a high-privilege, maintainer-only agent. Pillar’s team found that the low-privilege, public-facing agent could be manipulated via prompt injection into triggering a maintainer-only agent that can execute malicious actions. “Because workflows that explain how these agents work behind the scenes are also public, any person could have connected the dots that one agent should be able - at least theoretically - to 'call' the other,” Lisichkin told The Register. "When it comes to building the attack, you just need to know English to build the prompt injection (or just ask an AI to do it for you)." There is one caveat: an attacker would first likely need to make legitimate contributions to the repository to build trust among the maintainers before moving on to prompt injection. But assuming someone was willing to put in the time, here’s how the attack would play out. First, an external user - this would be the attacker - creates a new PR. Lisichkin calls this PR A, and it combines a real fix with malicious code, such as a modified package.json or malicious dependency. Then, a public-facing agent tied to a high-privilege collaborator personal access token (PAT) reads the attacker’s PR text and marks the PR for review. This level of trust - the collaborator PAT - allows the attacker-generated text to trigger a gated workflow. Once the PR A triage happens, the attacker opens a second PR - PR B - with the prompt injection, and the triage agent emits the trusted @gemini-cli handoff. This triggers the privileged-agent workflow and executes the malicious action. “Strung together, they manufacture a complete, believable ‘a human asked for a review, gemini ran it, gemini approved’ trail on the poisoned PR, none of which ever happened,” Lisichkin wrote. Google did not respond to The Register’s inquiries, but Lisichkin confirmed that the underlying issue was fixed. Still, his findings, Google said, “did not meet the bar” for a bug-bounty payout. “This report demonstrates exfiltration of a GitHub token with a 'pull-requests: write' permission, which enables tampering with a PR but still requires a maintainer to take an action to merge the malicious PR as PRs are not automatically merged after a bot review,” Google explained. “We don't reward vulnerability reports that require social engineering to enable a supply chain security compromise,” the rationale continued. “Nonetheless, we have taken an action to harden the repository so we will be recognizing this report with credit.” Lisichkin told us the research shows agent isolation is not enough. "Agents should have their own identity, which mandates what resources they are allowed to access and in what they are allowed to interact with these resources," he said. "In this case, if Google had just given a bot identity to the initial triaging agent, most of the attack could have been prevented. Security teams need to start modeling agent identity and agent resource access within their threat models."®
Kategorie: Viry a Červi

New DOUBLECUP ClickFix service hides malware in browser cache images

Bleeping Computer - 3 Srpen, 2026 - 22:01
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems. [...]
Kategorie: Hacking & Security

Fake Roblox Xeno script launcher pushes infostealer, RAT malware

Bleeping Computer - 3 Srpen, 2026 - 21:25
Fake Xeno Executor installers are infecting unsuspecting Roblox players with malware that provides remote access and steals sensitive information. [...]
Kategorie: Hacking & Security

18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

The Hacker News - 3 Srpen, 2026 - 20:43
Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments. One of the packages in question is "lib-mtop," an unscoped package with the same name as a private Alibaba package
Kategorie: Hacking & Security

18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

The Hacker News - 3 Srpen, 2026 - 20:43
Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments. One of the packages in question is "lib-mtop," an unscoped package with the same name as a private Alibaba package Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Aktivní AirTag v odbaveném zavazadle nepředstavuje žádný problém. Vztahuje se na něj totiž výjimka

Zive.cz - bezpečnost - 3 Srpen, 2026 - 20:15
** Zapnuté lokátory v odbavených kufrech nepředstavují žádné bezpečnostní riziko ** Knoflíková baterie bezpečně splňuje mezinárodní limity leteckých organizací ** Desítky aerolinek dnes tato data oficiálně využívají k dohledání ztracených kufrů
Kategorie: Hacking & Security

Aktivní AirTag v odbaveném zavazadle nepředstavuje žádný problém. Vztahuje se na něj totiž výjimka

Živě.cz - 3 Srpen, 2026 - 20:15
Zapnuté lokátory v odbavených kufrech nepředstavují žádné bezpečnostní riziko • Knoflíková baterie bezpečně splňuje mezinárodní limity leteckých organizací • Desítky aerolinek dnes tato data oficiálně využívají k dohledání ztracených kufrů
Kategorie: IT News

AI slop pollutes the CVE pipeline with fake vulns

The Register - Anti-Virus - 3 Srpen, 2026 - 19:19
Now AI is making fake vulnerabilities and polluting the ecosystem. A batch of critical- and high-rated SQLite CVEs that appeared in the NVD with CISA-supplied enrichment last week turned out to be technically bogus, according to security researchers, and their path into widely used databases exposes weaknesses in the CVE pipeline. Software supply chain security outfit JFrog reported last week that six supposed SQLite vulnerabilities published in a larger batch by a new, obscure GitHub repository were all complete garbage. Running the advisories through an AI checker suggested they were likely AI generated, JFrog said, and, upon testing, it found that none of the six SQLite reports, which carried CVSS scores ranging from 9.8 to 7.5, described a reproducible vulnerability. One, an alleged use-after-free vulnerability in the open source database that Red Hat initially assigned a maximum 10.0 CVSS score to before lowering it, relied on a function that didn't exist in the affected SQLite version. Another UAF vulnerability with a 9.1 CVSS score cited source lines that weren't even related to the supposed flaw. When JFrog tested the accompanying proof-of-concept, it executed a valid query with no memory leaks or errors. The other four SQLite CVEs from the repo that JFrog tested were similarly fake. The other 49 CVEs in the questionable GitHub repo claimed to be security vulnerabilities in the open-source RAW image processing library libraw and Arduino audio decoding library ESP32-audioI2S. While JFrog didn't test those as extensively, it said all are just as fake as the rest, aside from one which “contained a real bug wrapped in unverified CVE metadata.” A message posted to Openwall’s OSS-Security mailing list on Friday indicated that MITRE had rejected the whole repo’s worth of vaporous vulnerabilities, but the whole thing should serve as an important lesson, poster and Oracle Solaris engineer Alan Coopersmith pointed out. “MITRE and most other CNAs which assign CVEs for code they don't produce themselves operate on the honor system, and trust CVE requesters to have verified the information they provide,” Coopersmith noted in the OSS-Security post. “The CNA is often not in a position of being able to verify the report themselves.” As JFrog points out, the US National Institute of Standards and Technology (NIST), which manages the US National Vulnerability Database (NVD), used to provide a reliable backstop by manually reviewing and enriching CVE records after they entered the database. That process slowed dramatically in 2024 after a surge in vulnerability submissions, coupled with operational challenges, left the agency with a growing backlog of records it was unable to process. By late 2024, the backlog had grown to more than 17,000 unprocessed CVEs, despite NIST's plan to clear it by the end of fiscal year 2024 with contractor help. It continued to grow, reaching more than 27,000 by the end of 2025, according to a Department of Commerce Inspector General report published in May 2026. To make matters worse, the DoC IG concluded that NIST had been wasting money allocated to fixing the backlog due to a “lack of strategic planning and decisive action” that has led to the stack of unresolved issues continuing to grow. In other words, the pipeline has no mandatory checkpoint at which every claimed vulnerability must be independently reproduced. “Because no step in today's system actually requires a proof-of-concept or bug reproduction, a plausible-sounding fake advisory can slide right through the pipeline and end up in GitHub Security Advisories, downstream databases, and enterprise scanners,” JFrog said. “This incident demonstrates a systemic issue with automated vulnerability ingestion.” What that means for security professionals, aside from having to deal with polluted vulnerability databases, is that bad advisories could waste time better spent chasing real issues. Because reputable databases can ingest unverified records, JFrog recommended several checks before defenders act on a newly published CVE. First off, if the vendor hasn’t corroborated the issue (SQLite maintainers don’t list the fake CVEs, for instance) it’s probably not legitimate. A lack of commit hash or pull request in the reference fields of a repo is also indicative of AI slop, as is suspicious metadata (i.e., missing CPE product definitions). Lastly, if the code references don’t appear to match real functions or point to parts of the code that don’t involve the supposed issue, that’s a good sign it’s just an AI hallucination. JFrog reported its findings to the GitHub Security Advisory team, Red Hat, and NVD, all of whom the company told us have flagged or removed the CVEs. GitHub hasn't yet, JFrog told us. We reached out to GitHub to inquire why the repo is still up, but didn’t hear back. As for why someone might do this, JFrog speculates that it could be an attempt for someone to boost their research experience with fake reports, or to influence what automated CVE identification tools flag as actual vulnerabilities. In both cases, JFrog told us, that's just speculation. Either way, these 54 apparently bogus CVEs, JFrog security researcher Afek Berger said, are just one example of a problem they expect to see more often. "Generative AI has lowered the effort required to produce a plausible-looking advisory to close to zero, while the effort required to verify one, review the source code, build the affected version, reproduce the PoC, is unchanged," Berger told us in an email. "That asymmetry means that even well-resourced defenders and maintainers cannot manually validate every incoming report … this is a challenge the whole industry is facing in the AI era." ®
Kategorie: Viry a Červi

N-able warns of N-central auth bypass flaw exploited in attacks

Bleeping Computer - 3 Srpen, 2026 - 19:00
N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers. [...]
Kategorie: Hacking & Security

12 bezplatných editorů videa. Stáhnout si můžete jednoduchou střižnu i software, který používá Hollywood

Živě.cz - 3 Srpen, 2026 - 18:45
Potřebujete sestříhat video z dovolené či vytvořit klip? • Vybrali jsme dvanáct nejlepších bezplatných editorů videa • Nabídka čítá jednoduché, ale i komplexní programy
Kategorie: IT News

12 bezplatných editorů videa. Stáhnout si můžete jednoduchou střižnu i software, který používá Hollywood

Živě.cz - 3 Srpen, 2026 - 18:45
Potřebujete sestříhat video z dovolené či vytvořit klip? • Vybrali jsme dvanáct nejlepších bezplatných editorů videa • Nabídka čítá jednoduché, ale i komplexní programy
Kategorie: IT News

Anthropic’s AI models accidentally hacked three companies

Computerworld.com [Hacking News] - 3 Srpen, 2026 - 18:38

Anthropic has launched an investigation into what went wrong during a recent test of three models that left a trio of companies accidentally hacked.

The company was testing how well Claude Opus 4.7, Claude Mythos 5, and an internal test model could find hidden information about fictional companies in simulated networks. But because of a misunderstanding by one of Anthropic’s partners, the AI models gained access to the internet — and managed to find real companies with the same or similar names as the fictional ones.

As a result, three companies were actually hacked. Anthropic said it halted the tests on July 23, and the affected companies were notified four days later. So far, the company has received responses from two of the three companies, according to Reuters.

Anthropic is not alone when it comes to renegade models. An OpenAI agent recently went rogue and breached AI platform Hugging Bear and a customer of the cloud platform Modal Labs.

Kategorie: Hacking & Security

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

The Hacker News - 3 Srpen, 2026 - 18:24
Malware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim's screen. Unit 42 detailed three attack paths against Chrome's Google Password Manager cloud authenticator, which it calls Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key; the strongest targets the master key
Kategorie: Hacking & Security

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

The Hacker News - 3 Srpen, 2026 - 18:24
Malware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim's screen. Unit 42 detailed three attack paths against Chrome's Google Password Manager cloud authenticator, which it calls Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key; the strongest targets the master keySwati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

The Hacker News - 3 Srpen, 2026 - 18:15
The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. In a report published over the weekend, Resecurity said it observed the INC Ransomware accelerating its activity since the beginning of August 2026, listing multiple victims on its data leak site. Per
Kategorie: Hacking & Security
Syndikovat obsah