Agregátor RSS

Kritické zranitelnosti v produktech VMware: CVE-2026-59309, CVE-2026-59310 a CVE-2026-47876

AbcLinuxu [zprávičky] - 31 Červenec, 2026 - 19:26
Vládní CERT upozorňuje (𝕏) na kritické zranitelnosti v produktech VMware: CVE-2026-59309, CVE-2026-59310 a CVE-2026-47876. Zranitelnosti v VMware vCenter umožňují vzdálenému útočníkovi se síťovým přístupem obejít autentizaci a získat neoprávněný přístup k vCenter, případně zneužít directory traversal ke spuštění libovolného kódu na vCenter.
Kategorie: GNU/Linux & BSD

Apple’s Tim Cook era ends with a record $109B quarter

Computerworld.com [Hacking News] - 31 Červenec, 2026 - 18:52

Apple’s outgoing CEO, Tim Cook, bade an emotional farewell to analysts and shareholders on Thursday as the company announced a record June quarter. His successor, John Ternus, takes over at the beginning of September with the company seemingly in solid shape.

The results were impressive, though some worrying challenges were confirmed. Apple managed to set a new June quarter record, but acknowledged slowing services growth and an unexpected mishap in forecasting future demand. Mac sales jumped an absolutely astonishing 28.7%, as the MacBook Neo grabbed consumer imagination, and overall the company saw growth everywhere except the iPad.

Apple’s fiscal Q3 2026 results saw the company generate $109.4 billion in revenue, up 16% year-over-year for a net quarterly profit of $29.8 billion. Gross margin for the quarter was 50.1%, compared to 46.5% in the year-ago quarter (though two points of this was attributed to tariff returns). 

More specifically:

  • iPhone sales were up 21.7%, an unusually high number for what is traditionally a slower quarter.
  • Wearables increased 6.5%.
  • Services revenue increased 12%.
  • And the iPad declined 5.9%.
The Mac is out the bottle

Apple’s huge Mac quarter is a bellwether moment for the company. The platform is benefiting from both the iPhone halo and the MacBook Neo/MacBook Pro blessing. Apple confirmed MacBook Neo is drawing interest from education and enterprise clients, with Apple CFO Kevan Parekh noting that roughly half of the large US education Mac purchases during the quarter displaced Windows and Chromebook devices. 

Big business wins included a massive 20,000-unit iPhone deployment at Morgan Stanley as the company shifted from employee-owned to corporate-owned/managed devices. The only problem is that demand for both Macs and iPhones is greater than Apple originally anticipated; as a result, some systems could be in short supply moving forward.

Memory, components, and demand

Cook described the current memory pricing environment as a “100-year flood” that forced Apple to raise prices on iPads and Macs. Parekh explained that memory cost changes explain more than 100% of the sequential gross margin decline, with adjusted gross margin falling from 49.3% in March to 48.1% in June (excluding tariff refunds). They’re projected to decline further. 

Cook noted the DRAM market has only three primary suppliers, and Apple is evaluating options for additional supply flexibility.

The company also has a fresh problem on its hands, in that its iPhones and Macs are selling in much bigger quantities than Apple expected. And while the company managed to meet demand in the quarter, it might be constrained in the next. “It’s not a regular supply issue. It’s a demand forecast issue, to be candid,” Cook explained. “The iPhone and the Mac are both doing remarkably better than we thought they would do.… We continue to expect high levels of demand. However, with less flexibility in supply chain, we expect the impact from the supply constraints to increase significantly sequentially.

“We’re seeing some very significant constraints currently with limited flexibility in the supply chain to remedy it.”

Services grew, right?

Apple’s services revenue also grew, but not as much as many analysts had anticipated. Apple passed $30 billion for the first time in a June quarter, buoyed by all-time records in cloud and payment services, while the company’s paid subscription base surpassed 1.5 billion. 

At the same time, Apple confirmed headwinds to services income, principally around currency exchange impacts and volatile economies, softness in mobile gaming, and – confirming the punitive impact of regulation on this part of the Apple business model – App Store business model changes.

What no one yet can know is the extent to which Apple’s recently announced Klarna product leasing deal will contribute both to services income and to accelerated replacement cycles. With 1.5 billion people in its addressable market, it’s very possible that a substantial number of customers will decide to pay for their Apple products on a monthly basis. The result would be a stable, predictable income stream for the company.

What about AI?

Apple’s introduction of Siri AI is delayed in the EU and China due to regulatory hurdles, though the situation in China could soon change following recent reports of an AI support deal with Alibaba and Baidu

Goldman Sachs analyst Michael Ng asked about Siri AI plans and experience. Cook said the company remains “off the charts excited” about Siri AI, and the company continues to receive positive feedback, though he added some warnings about cost. 

Cook explained that to handle users who might want to use Siri AI extensively, the company plans an upgrade option through iCloud+, though it is too early to define the specifics. (Incoming CEO John Ternus said Apple is focused on its own approach to artificial intelligence, but continues to see “enormous opportunity” in the sector.)

What the analysts said

Discussing the results, Morgan Stanley analyst Erik Woodring pointed to decelerating services growth and memory costs nibbling at the edge of Apple’s margins. “Apple’s leverage over the supply chain appears to be in question,” he said, adding it’s not clear whether AI is serving as a measurable tailwind to products or services, with its future monetization impact still uncertain.

Bank of America analyst Wamsi Mohan noted that continued demand means supply constraints are the biggest inhibitor for the stock, since demand will be shunted into subsequent quarters. Wells Fargo also pointed to the longer range picture that despite supply challenges in the current quarter, Apple still has plenty of momentum going into Q1 2027.

Finally, Jeff Pu, of GF Securities, speculated that demand might also be impacted by an estimated $300 increase in the cost of the upcoming 18 Pro series of devices, though this may be partially mitigated by Apple’s new leasing deal.

Cook’s watch is almost over

This was Cook’s 19th and final earnings call as CEO, with his successor joining the call for the first time. Cook closed the meeting with this message: “As you know, this will be my final earnings call, and John will lead these calls going forward. The transition is going seamlessly, and I am beyond excited for John to step into his new role and lead Apple into its next era.”

Apple stock was down around 9% at mid-day Friday as investors consider the quarter’s record results.

You can follow me on social media! Join me on BlueSky,  LinkedInMastodon and subscribe to The Core.

Kategorie: Hacking & Security

CISA warns of cyberattacks disrupting U.S. water utilities

Bleeping Computer - 31 Červenec, 2026 - 18:49
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater systems sector. [...]
Kategorie: Hacking & Security

Hry na PlayStation budou vycházet jen digitálně. Už nikdy nebudete nic vlastnit (Podcast Živě)

Živě.cz - 31 Červenec, 2026 - 18:45
Reorganizace Xboxu pokračuje. O práci přišlo 1600 lidí a stejný počet bude následovat v dalších měsících. Divize se ztenčí o pět studií. Microsoft se chce dále soustředit na velké značky. Chystá pokračování The Elder Scrolls, Falloutu nebo Dooma. Jen si nejsme jistí, jestli po čistce bude mít tyto ...
Kategorie: IT News

Bezpečnostní chyba hardwarových kryptopeněženek Coldcard

AbcLinuxu [zprávičky] - 31 Červenec, 2026 - 18:39
Společnost Coinkite upozorňuje na bezpečnostní chybu svých hardwarových kryptopeněženek Coldcard. Jedná se o kritickou chybu v generování náhodných čísel (RNG). Místo hardwarového generátoru náhodných čísel (TRNG) byl omylem používán softwarový fallback (PRNG).
Kategorie: GNU/Linux & BSD

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

The Hacker News - 31 Červenec, 2026 - 18:39
Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka. According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted archive, which holds a Windows Shortcut (LNK). Executing the file triggers a multi-stage chain that
Kategorie: Hacking & Security

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

The Hacker News - 31 Červenec, 2026 - 18:39
Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka. According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted archive, which holds a Windows Shortcut (LNK). Executing the file triggers a multi-stage chain that Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Reporter’s notebook: In Dubai’s sun and sand, AI, server farms, and optimism bloom

Computerworld.com [Hacking News] - 31 Červenec, 2026 - 18:30

Walking around Dubai, it’s hard to believe a war is still going on in neighboring countries.

No missiles have struck the city, and it was clear during a recent visit that local residents are keeping to their routines. The biggest public worry, as it has been in many parts of the world, is the extreme heat. (The high today is around 106 degrees.)

Dubai, one of seven emirates in the United Arab Emirates (UAE), continues to emerge as a major global tech hub and is on the verge of becoming a major AI powerhouse. Each of the emirates has their own laws and traditions, with Dubai and Abu Dhabi — the UAE capitol — the most prominent.

Other nations recognize the region’s potential and Dubai’s position. The US, for instance, showed interest in currying favor with the UAE by sending a CIA spy to vet the emirate’s top AI firm, paving the way for future chip and AI deals. That outreach, highlighted in a report in The Wall Street Journal, was a hot topic in the local tech community.

These days, Dubai and Abu Dhabi hope to position themselves as hubs where people and companies go for AI. Its location makes it an excellent place to do business, with connections to Asia, Europe, and Africa.

Broadly speaking, the UAE wants to be something of a Switzerland for AI, or “a neutral AI corridor between East and West,” Mahmood Abdulla, a regional technology expert, explained in a 2025 LinkedIn entry.

Data center buildouts

While states like New York are putting a moratorium on the construction of data centers in the US, the UAE is moving in the opposite direction; an aggressive AI data center buildout has government backing.

Stargate UAE, a data center project that involves top tech firms such as OpenAI and Oracle, is being built in Abu Dhabi. The city has essentially planned out a business model designed to turn AI into hard cash with a focus on the energy resources that will play a major role in the effort.

The plan is to redirect Abu Dhabi’s vast energy resources — it has up to 100 billion barrels of known oil reserves — to data centers generating AI tokens. Those tokens can then be sold as compute resources to produce revenue.

With oil markets volatile because of ongoing conflicts and the worldwide rise of renewables, pushing energy use to AI data centers might be a more reliable form of revenue long term.

Will it work? That remains to be seen. But unlike the US backlash against data centers construction in many place, a ban here seems unlikely.

The entrepreneurial spirit

Technological innovations from entrepreneurs have been at the core of Dubai’s rapid growth in recent years as a global business center. Here, AI is already quietly woven into daily life, much as it is in China, where AI is already in factories, homes, and infrastructure.

One founder told me that naming his company to include “AI” is more of a US thing. UAE companies focus less on boasting about AI models and superintelligence; they tend to emphasize user experiences.

On a separate track, Dubai is already targeting the launch later this year of robotic air taxis flying from the airport into the city. (That’s ahead of New York City, where electric air taxis are still being tested.)

Still, Dubai is behind the US when it comes to autonomous ground transport. The first autonomous taxis hit Dubai streets just last year, and there are a limited number operating in tourist areas.

A complicating face tor for the area remains the Iran war. Dubai’s Internet City, a hub with buildings belonging to the likes of Microsoft, Oracle and IBM, largely emptied when the war started in late February. Foreign tech workers left, and property prices declined.

But the real estate market is booming as opportunistic investors buy low. Their bet: the US-Iran war won’t stop the UAE’s growth.

Money is flowing into the area in other ways. Heavy tax burdens in Western countries are pushing wealthy founders to move businesses to Dubai’s tax-free environments. And Dubai is opening the door to those with digital nomad and freelance visas. Although visas can cost thousands of dollars a year, lower rent and healthcare costs compared to the US can offset those costs.

Rivals are emerging, too

UAE’s economic rival, Saudi Arabia is also rising as a tech powerhouse. Riyadh has undertaken reforms at a rapid pace to become an attractive place to do business under its Vision 2030 program.

Saudi Arabia requires corporations to have regional headquarters in the country to win government contracts, a policy that challenges Dubai’s status as a regional business hub.

The UAE also relies heavily on immigrants and human labor, which can be both a plus as well as a challenge. There is no pathway for entrepreneurs or long-time tech workers to retire here, which can undermine worker motivations to stay.

Still, the attractive business environment, combined with local infrastructure and a skilled labor force, make this area appealing. As one founder told me, if the US doesn’t want its most skilled immigrants, the UAE will be happy to welcome them with open arms.

Kategorie: Hacking & Security

The most famous brand in physical security got pwned by ShinyHunters

The Register - Anti-Virus - 31 Červenec, 2026 - 18:27
A leading name in home and business physical security, Brinks Home, recently said it identified unauthorized access to a portion of its IT systems, an intrusion ShinyHunters claims it carried out to steal millions of records from the security provider's Salesforce instance. Brinks Home hasn’t named the intruder or identified the affected system, but said the responsible party has threatened to leak information it claims to have taken. “Brinks Home is working diligently to determine what information was involved and who may be affected,” the company statement said. “If the Company determines that personal information has been affected, it will notify those individuals as required and as appropriate.” An FAQ page for the incident said that Brinks Home products and services weren’t affected, as far as the company knows at this point, so alarms and other security tools should be working without issue. While Brinks may not have been very forthcoming with information, and lacks any sort of official way for media to communicate with it outside of sending a LinkedIn message it didn’t answer, the party that’s claimed responsibility has gone public with some details, and it’s none other than ShinyHunters with another claimed Salesforce breach. According to leak site monitoring outfit Ransomware.live, ShinyHunters claimed to have obtained more than 4.9 million Salesforce records from Brinks Home “containing some PII.” The group threatened this week to leak the data along with causing “several annoying digital problems” if Brinks Home didn’t reach out by Thursday, July 30, to negotiate a ransom payment. It’s not clear if Brinks Home has contacted ShinyHunters; Brinks Home didn’t respond to messages, and contacts The Register has for ShinyHunters appear to have changed, causing message and email rejections. ShinyHunters has been a prolific Salesforce intruder of late, with the group claiming earlier this year to have stolen data from around 100 high-profile companies’ Salesforce instances. Salesforce has previously warned that an unnamed known threat actor group was actively scanning for public-facing Salesforce instances and abusing misconfigured guest accounts to break in. Brinks Home is no longer part of the larger Brinks brand, with The Brinks Company telling us it sold the home security arm in 2010. Brinks Home’s parent company, Monitronics, has filed for bankruptcy twice since 2019; for customers’ sake, we hope its physical security services are better than its financial management and infosec. ®
Kategorie: Viry a Červi

Data center developer eyes disused newpaper printing plant

Computerworld.com [Hacking News] - 31 Červenec, 2026 - 18:16

As newspapers move online, the buildings that once housed their printing presses need new occupants.

The Minnesota Star Tribune has just sold its old printing plant on the edge of Minneapolis to the aptly named property developer Legacy Investing, which plans to create a new data center there. has found the ideal way to bring them back to life.

This is the second such move by Legacy. It has already bought a building in downtown Minneapolis that it has transformed into a data center for artificial intelligence and cloud computing.

These old buildings, already connected to power, are an attractive option for developers — especially with some grid operators threatening power cuts for new-build data centers during power shortages.

Legacy is taking a small-is-beautiful approach rather than replicating the massive data centers being built for Big Tech firms. Those are the size of small towns and consume huge volumes of water and hundreds of megawatts of power, while the capacity of Legacy’s downtown building is about 30 MW, and it expects the Star Tribune site to host around 20 MW of data center equipment.

The scaled-down approach may well be an attractive option for operators in the future.

This article first appeared on Network World.

Kategorie: Hacking & Security

DefCon security conference bans smart glasses with recording capabilities

Computerworld.com [Hacking News] - 31 Červenec, 2026 - 17:57

It’s a sign of the times: Security conference DefCon has added smart glasses to its list of banned audio- or video-recording devices.

The organizers have said that, with no consistent way to understand whether smart glasses are recording or not, they have taken the step to ban them in their entirety on the grounds that they erode trust and invade people’s privacy.

Putting corrective lenses in the smart glasses will be no excuse: DefCon insists that visitors bring a pair of glasses without the smarts instead.

The smart glasses ban has been added to DefCon’s already strict rules on photography, which among other things ask visitors not to take group shots and to use “portrait” mode (or a low F-stop for those with old-fashioned cameras) to focus on the foreground, so that people in the background appear blurred.

The smart glasses market has gone up a notch lately. Google and Samsung have both announced Gemini powered eyewear running on Android. Apple is looking to launch its new generation of smart glasses next June, citing privacy concerns as the reason for the delay.

It is not only tech conferences that are getting jumpy about smart glasses. CISOs are beginning to get wary about their impact on organizations and whether their data is secure.

This article first appeared on CSO.

Kategorie: Hacking & Security

Understanding Trust Boundaries in Linux Infrastructure

LinuxSecurity.com - 31 Červenec, 2026 - 17:46
Every time you SSH into a server, run sudo, install a package, or start a container, Linux decides whether to trust it. Most of those decisions happen so quickly that administrators rarely think about them—until one turns out to be wrong. Looking more closely raises an interesting question: why do such different security problems often fail in similar ways?
Kategorie: Hacking & Security

Které hry vyjdou v srpnu 2026: Rozšíření Mafie, strategické Star Wars a 16 dalších novinek

Živě.cz - 31 Červenec, 2026 - 17:45
Před podzimní sezónou se na srpen chystá jen několik očekávaných pecek. Vedle toho dojde i na řadu portů velkých titulů a v našich končinách určitě zarezonuje doplněk pro loňskou Mafii.
Kategorie: IT News

Anthropic and OpenAI are competing to see whose agents can go rogue harder

The Register - Anti-Virus - 31 Červenec, 2026 - 17:04
One company's inventive campaign for an unreleased product has become a contest between Anthropic and OpenAI to see which can shout the loudest about its own failures. Readers who tuned in earlier today saw the latest episode in the drama – or sitcom – as Anthropic tried to outdo OpenAI's appropriation of the Mythos marketing playbook and made itself the punchline. Since first teasing Mythos in April, Anthropic has marketed the model through fear – declaring its cybersecurity models too dangerous for public release and offering access only to a select few trusted organizations via Project Glasswing. To its credit, the strategy has paid off. Anthropic has closely associated the Mythos name with cybersecurity, which may explain why OpenAI appeared to borrow its competitor's proven PR strategy last week. OpenAI agents exploited a zero-day to escape their sandbox, leading to the autonomous cyberattack on Hugging Face. The episode duly secured sensational headlines playing on the long-held fear that AI will one day go rogue and take over the world. Anthropic responded this week by lathering on even more clown makeup, squandering an opportunity in the process. The Claude maker sent its models into a testing environment to capture a flag. Their prompts said they had no internet access, but because of what Anthropic called "a misunderstanding" with evaluation partner Irregular, the connection was live. Anthropic's models then followed OpenAI's script: they reached the public internet and attacked systems belonging to outside organizations. This time, three were affected rather than one, the company admitted. In one scenario, Mythos 5 persuaded developers to download a poisoned PyPI package. It was installed on 15 machines, including one at a cybersecurity company that routinely scans such packages for malware. In Anthropic's words: "When that company's scanner installed the package, Claude's hidden code executed. We believe the company's security scanner treated PyPI packages as safe to install, and as a result, Claude was able to exfiltrate the company’s credentials to a collection point it had set up. Claude then used these credentials to access further infrastructure from this company." Worse still, the first of the three incidents occurred in April. Anthropic discovered them only months later, during a retrospective manual review prompted by OpenAI's disclosure. Had it not gone looking, they might never have been discovered, let alone disclosed. There are some caveats. Opus 4.7, the oldest model tested, attacked production systems despite apparently recognizing what it was doing. Mythos 5 recognized that accessing the internet violated its instructions, then reasoned its way into continuing anyway. It was also responsible for publishing the poisoned PyPI package. Only an unnamed research model stopped itself from attacking external organizations. Anthropic also said the models were not running with the production safeguards and monitoring that would normally surround a deployment. Most damningly, Anthropic ran Mythos 5 – the model it had deemed too dangerous for public release – without safeguards in an environment that unexpectedly had internet access. Following OpenAI's admission that it failed so badly in its responsibility to control its technology, Anthropic could have easily spun the story in its favor. You don't have to be fictional tapdancing political PR antihero Malcolm Tucker to see how Anthropic could have used the episode to make its case as the safer, more trustworthy AI company. Instead, realizing its own marketing playbook was being used to help a competitor, it went head-to-head with OpenAI, willingly admitted that it made similar sandbox-based blunders, and disclosed that the results were even more calamitous. Three companies hacked, not just one. So, while the AI biz has attempted to eclipse OpenAI's "rogue agent" story with its own, what's left behind is a new reputation for irresponsible handling of technology. Failed superheroes The incident does not instill a great deal of trust in either Anthropic or OpenAi to safeguard the world from its AI. Dr Ilia Kolochenko, founder of ImmuniWeb and practising cybersecurity and data protection lawyer, likened the two companies to failed superheroes. "While making conclusions would be a bit premature at this point in time, the incidents certainly do not increase confidence in the AI vendor's ability to safely deploy AI, let alone to assure their customers that the so-called frontier models are safe to use," he told The Register. "It is akin to hiring a superhero to protect you but being afraid that the superhero may suddenly go rogue and kill you and your family. Nobody needs such a superhero." Likewise, security pro Jake Williams, VP at HunterStrategy and IANS faculty member, said: "I'm not going to mince words: the major AI labs are negligent in protecting the public from their agents. "We need government regulation now or at the very least a private cause of action with guaranteed punitive damages for agents damaging others." By trying to reclaim a marketing trope that served it well, Anthropic has invited scrutiny of its own safety record and accusations that it is chasing attention above all else. Other experts we spoke to shared the concern that both companies are mishandling their agents, with potentially greater consequences as the systems become more capable. The common thread is recklessness, which Anthropic and OpenAI seem oddly eager to advertise. ®
Kategorie: Viry a Červi

Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies

The Hacker News - 31 Červenec, 2026 - 16:45
Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators. Researchers named the operation Fuyao and attributed it to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China company founded in 2019. The same apps have a second job. When a box
Kategorie: Hacking & Security

Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies

The Hacker News - 31 Červenec, 2026 - 16:45
Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators. Researchers named the operation Fuyao and attributed it to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China company founded in 2019. The same apps have a second job. When a box Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Poslední show Tima Cooka. Apple má rekordní tržby a zisk. Šéf firmy potvrdil i jednání o čínských pamětech

Živě.cz - 31 Červenec, 2026 - 16:45
Apple zakončil třetí fiskální čtvrtletí roku 2026 tržbami ve výši 109,4 miliardy dolarů, čímž překonal loňské výsledky o 16 %. Čistý zisk vzrostl dokonce o 27 % na 29,8 miliardy dolarů. Jde o nejlepší výsledky za třetí kvartál v historii firmy. S výjimkou iPadů rostly všechny segmenty Applu. ...
Kategorie: IT News

ESET tracks rise in malicious AI skills and adaptable malware

Bleeping Computer - 31 Červenec, 2026 - 16:01
Attackers are adapting established techniques to AI platforms, emerging technologies, and changing user behavior. ESET's new threat report examines the rise of malicious AI skills, AI-assisted malware, ClickFix attacks, record quishing activity, and ransomware tools designed to disable security software. [...]
Kategorie: Hacking & Security

Charities remain locked out of CAF Bank online accounts

The Register - Anti-Virus - 31 Červenec, 2026 - 15:55
A week after suspending online banking, CAF Bank still has no timetable for restoring access to its 14,000 UK charity customers. The bank updated customers on Thursday about the outage, which has disrupted payments to staff and suppliers. Little had changed. In a message seen by The Register, CAF Bank said it was not yet able to restore the service safely. As it had earlier in the week, the bank said it detected attempted fraud on some accounts and acted quickly to stop it. Its investigation uncovered a previously unknown vulnerability in the connection between its systems and third-party software. CAF Bank said its technical team was working around the clock with suppliers and external experts on a fix. The Register understands that no timetable has been set for restoring online banking. Earlier this week, CAF Bank CEO Alison Taylor apologized for the disruption. "The core bank is not affected. We are acutely aware of the impact this has on our customers and want this to be fixed as soon as possible, but we cannot restore access to the online service until we are assured the issue is safely resolved," she said. Since The Register first reported the story earlier this week, the BBC has spoken to charities struggling to make essential payments, including payroll. Kevan Hodges, chief executive of Down's syndrome charity 21 Together, told the BBC the outage was "appalling." "People are concerned that wages won't get paid because of this, and that's just stressful when they have bills to pay. My team have wasted days trying to get through to [CAF Bank], but all in vain," he said. Bali Rodgers, chief executive of Safer Communities Alliance, told the BBC the grassroots organizations it represents were slowly losing trust in the bank. CAF Bank also came under fire last year after the introduction of a new banking platform left customers unable to log in or make transactions. The bank later apologized but has not disclosed how much it spent on the system. CAF Bank held £1.45 billion ($1.93 billion) in customer deposits at the end of its 2024/25 financial year. ®
Kategorie: Viry a Červi
Syndikovat obsah