Agregátor RSS

Český prodejce telefonů míří k pěti miliardám. Pomohl mu obchod s Googlem na několika trzích v Evropě

Živě.cz - 13 Srpen, 2026 - 08:45
Google dodal Vackovi růst, jaký na padajícím trhu s telefony skoro nikdo nemá • . • Pixely rostou i ve chvíli, kdy celý trh se smartphony kvůli drahým pamětím výrazně padá. • Do pěti nejsilnějších značek světa se Google zatím nedostal, tři čtvrtiny trhu drží jiní.
Kategorie: IT News

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

The Hacker News - 13 Srpen, 2026 - 08:09
Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which refers to a critical security feature bypass that stems from weak authentication. It was patched by Microsoft as part of its July 2026 Patch Tuesday updates. "The authentication Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Medúzy vyřadily z provozu největší jadernou elektrárnu v západní Evropě. Na plný výkon běží jediný reaktor

Živě.cz - 13 Srpen, 2026 - 07:45
Jaderná elektrárna Gravelines musela kvůli medúzám odstavit tři reaktory • Nápor rosolovitých mořských živočichů ucpal filtry na přívodu chlazení • Situaci ve francouzské jaderné energetice navíc komplikují vlny veder a sucha
Kategorie: IT News

Ceny nejlevnějších modelů GeForce RTX 5000 jsou již v průměru 64 % nad MSRP

CD-R server - 13 Srpen, 2026 - 07:40
Letní vlna zdražování ještě neskončila a reálné ceny GeForce i u nejlevnějších nabídek začínají v průměru na částkách bezmála dvě třetiny nad oficiální cenou stanovenou výrobcem…
Kategorie: IT News

Veřejný test eDokladů

AbcLinuxu [zprávičky] - 13 Srpen, 2026 - 06:01
Dle plánu dnes ve 13:00 proběhne veřejný test eDokladů. Jeho cílem je ověřit připravenost aplikace a související infrastruktury na vysokou souběžnou zátěž před podzimními komunálními volbami.
Kategorie: GNU/Linux & BSD

Chinese Loongson processors have leaky caches, researchers find

The Register - Anti-Virus - 13 Srpen, 2026 - 04:14
Researchers from Germany’s Helmholtz Center for Information Security have found processors made by China’s Loongson have leaky caches that attackers could use to seek specific data. Loongson has developed its own LoongArch instruction set architecture (ISA) that blends approaches used by MIPS and RISC-V. On a site called LoongLeakAttack.com, the researchers explain that they found the leaky cache using a fuzzer, then noticed that the LoongArch ISA manual mentions an instruction that leaves 32 bits of a memory register in an “uncertain” state. “Our analysis reveals that under certain circumstances, the ‘uncertain’ data originates from the L1 data cache,” the four researchers wrote. “Since this cache is not isolated between applications, LoongLeak can leak data from other applications and the operating system. Even worse, an attacker can prime the CPU’s internal state to target the leakage to a specific cache set.” In a paper [PDF] explaining their research, authors Lorenz Hetterich, Tristan Hornetz, Fabian Thomas, and Michael Schwarz share case studies that “include recovering full-disk AES keys from the kernel, partial root password hashes from user-space, and bypassing traditional software defenses such as ASLR and stack canaries, all within seconds.” In case that’s not scaring you enough, they also point out “LoongLeak can be exploited from unprivileged user space, containers, or virtual machines.” The flaw even means “LoongLeak can cross the virtual machine boundary and leak host data from inside a VM.” “As the leakage is architectural, it requires neither high-resolution timers nor traditional sidechannel amplification, and it grants the attacker precise control over cache set and line offset,” they add. And the cherry on top is that software mitigations aren’t possible. Users with chips that possess the flaw either need to replace them or make sure they don’t allow any private data to enter or remain in the L1 cache. Making that happen can require turning off one thread per core, effectively disabling hyperthreading. The news isn’t all bad, because Loongson fixed the flaw in an update to its model 3A6000 processor, and the mitigation of evicting cache data slows performance by just 1.4 percent in the worst case. The blast radius of this flaw is also likely to be limited, because Loongson chips are hardly used outside China. The company offers chips for PCs, servers, and appliances such as printers. China’s government promotes use of Loongson chips as part of its plan to reduce dependence on imported tech. Lenovo makes laptops that use Loongson chips but only sells them in China. The Register has discussed the company’s chips with other major PC-makers, who told us they would adopt Loongson product if users want them, or if doing so becomes necessary to participate in the Chinese hardware market. But we’ve not seen a non-Chinese company adopt the processors. China’s government, however, may be nervous about this research as it has instructed public sector buyers to buy local products. Perhaps some government agencies are running vulnerable devices? If that’s the case, Beijing has its work cut out spotting any attacks, because the researchers could find “no specific tools or methods to detect if LoongLeak is being exploited.” ®
Kategorie: Viry a Červi

Flutter 3.47 a Dart 3.13

AbcLinuxu [zprávičky] - 13 Srpen, 2026 - 04:12
Byla vydána nová verze 3.47 frameworku Flutter (Wikipedie) pro vývoj mobilních, webových i desktopových aplikací a nová verze 3.13 souvisejícího programovacího jazyka Dart (Wikipedie).
Kategorie: GNU/Linux & BSD

Made by Google 2026

AbcLinuxu [zprávičky] - 13 Srpen, 2026 - 04:02
Na akci Made by Google 2026 (YouTube) byla oficiálně představena jedenáctá generace telefonů Pixel s novým čipem Google Tensor G6 a hodinky Pixel Watch 5.
Kategorie: GNU/Linux & BSD

Manjaro 26.1 Bian-May

AbcLinuxu [zprávičky] - 13 Srpen, 2026 - 04:01
Byla vydána nová verze 26.1 linuxové distribuce Manjaro (Wikipedie). Její kódové jméno je Bian-May. Ke stažení je v edicích GNOME, KDE PLASMA a XFCE.
Kategorie: GNU/Linux & BSD

Lovable bolsters its AI software creation capacity, touts $400M funding round

Computerworld.com [Hacking News] - 13 Srpen, 2026 - 02:36

Lovable, the Swedish-based AI software creation platform company, today announced an acceleration of its product, infrastructure, and team development efforts — and a noteworthy round of Series C funding totaling $400 million.

The company said in its statement that it is looking to augment its platform, which it boasts is already used by almost two-thirds of Fortune 500 companies.

Headquartered in Stockholm, Lovable plans to grow its team to 450 people this year, hiring most heavily in machine learning, product, infrastructure, and security roles, and is looking to expand operations from its home base to include locations in London and three US cities: Boston, San Francisco, and New York City.

The planned growth is made possible by the latest infusion of venture capital, which follows a $330 million Series B funding round last December. Lovable now has a $13.3 billion valuation.

The Series C funding was led by Menlo Ventures and the Scaleup Europe Fund and includes US-based Regent. (Regent is the parent company of Foundry.)

Earlier this month, Lovable announced a partnership with Cerebras Systems, the chipmaker that builds processors the size of dinner plates (the Wafer-Scale Engine) and supercomputing systems built for AI inference and training. Cerebras systems are designed to keep an entire AI model’s weights on a single, super-sized WSE chip, rather than split across many GPUs, to avoid GPU memory bottlenecks.

That partnership calls for Lovable to run some of its latency-sensitive workloads on dedicated Cerebras capacity.

“Fast AI is more valuable than slow AI,” said Cerebras CEO and Cofounder Andrew Feldman said in a statement when the partnership was unveiled. “When AI responds in real-time, users do more with it, stay longer, and run higher value workloads. Software creation is one of the clearest examples of the importance of speed. Creators don’t want to wait.”

In its statement today, Lovable said that since its launch in November 2024, people have created more than 60 million projects with its tools, with Lovable-built apps seeing more than 900 million visits a month.

Computerworld is part of Foundry, which is owned by Regent.

Kategorie: Hacking & Security

"City-Forum" data-theft attacks target Salesforce, ServiceNow portals

Bleeping Computer - 13 Srpen, 2026 - 01:07
An ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals. [...]
Kategorie: Hacking & Security

Android malware combo takes out loans and relays victims' credit cards

Bleeping Computer - 13 Srpen, 2026 - 00:22
A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal live card data and send it to attackers in real time. [...]
Kategorie: Hacking & Security

Banky zavádí záchranné tlačítko, kterým stopnete krádež peněz z účtu

Lupa.cz - články - 13 Srpen, 2026 - 00:00
Banky postupně začínají zavádět bezpečnostní pojistky, které mohou zabránit vykradení účtu v případě napadení kyberútočníky. První dvě už v aplikaci mají speciální tlačítko.
Kategorie: IT News

Dlužník roky blokoval vlastní insolvenci. Za obstrukce dostal od soudu trest

Lupa.cz - články - 13 Srpen, 2026 - 00:00
Dlužník odmítal spolupracovat s insolvenční správkyní, nepředložil seznam majetku a závazků a řízení opakovaně brzdil námitkami podjatosti vůči správkyni i soudcům. Insolvenci tak na několik let prakticky paralyzoval. Nejvyšší soud potvrdil, že podobné zneužívání procesních práv může být trestným činem.
Kategorie: IT News

Podpora unifikované práce se zařízeními v operačním systému Atari: CIO (dokončení)

ROOT.cz - 13 Srpen, 2026 - 00:00
Na předchozí dvojici článků o subsystému CIO implementovaného ve všech osmibitových mikropočítačích Atari dnes navážeme. Ukážeme si, jakým způsobem je možné realizovat vlastní sofistikované zařízení, zaregistrovat toto zařízení pod vhodným písmenem a volat jeho operace z Atari BASICu.
Kategorie: GNU/Linux & BSD

Gelsingerova Fab 62 v Arizoně už nabrala čtyřleté zpoždění, Intel shání peníze

CD-R server - 13 Srpen, 2026 - 00:00
Intel oznámil veřejnou nabídku kmenových akcií v hodnotě 20 miliard dolarů na financování expanze výrobních kapacit. Zdá se, že důvodem je snaha o dokončení Fab 62, která měla stát již roku 2024…
Kategorie: IT News

Astronomové poprvé objevili 3 aktivní supermasivní černé díry v 1 galaxii

OSEL.cz - 13 Srpen, 2026 - 00:00
Galaxie J0148-4214, vzdálená od nás asi 12,5 miliard světelných let, obsahuje hned 3 supermasivní černé díry současně. Astronomové detekovali dvojici supermasivních černých děr o hmotnosti 80 milionů a 600 tisíc Slunci společně s třetí o hmotnosti 2 miliony Sluncí, s využitím detailní analýzy spektra záření galaxie.
Kategorie: Věda a technika

'Near-autonomous' AI agents attack Taiwan's nuclear safety agency

The Register - Anti-Virus - 12 Srpen, 2026 - 23:45
Suspected Chinese cyber operatives used publicly available AI tools to compromise Taiwanese government systems before expanding the attack to its nuclear safety agency, supply-chain vendors, and at least seven energy companies in what security researchers called a "near-autonomous attack." Over the first four days of July, AI agents compromised 85 government user accounts and extracted more than 2,500 personnel records, according to Dream, an Israeli cybersecurity firm. Researchers uncovered evidence of the attack in a 160 MB online archive containing 1,395 files documenting the operation. Dream, in research published on Wednesday, detailed the intrusions and said that the suspected Chinese hackers hit “government entities in Asia” - but declined to say which government had been attacked. A person familiar with the attack confirmed to The Register that Taiwan was the target. The Financial Times first reported on Dream’s research and identified Taiwan. While the security firm doesn’t attribute the agentic attack to the Chinese government or a specific hacking group, the operational documentation “points to a Chinese-language operator,” the researchers said. According to Dream, the attack framework, built on open source Hermes and OpenClaw AI agents, deployed up to eight sub-agents, each assigned to its own targets and attack techniques, across 12 “attack waves” between July 1 and July 4. First, the agents mapped the entire government ecosystem, extracting embedded URLs, API endpoints, OAuth client IDs, and Keycloak configuration objects from a single government portal. This portal allowed the agents to identify 21 connected government systems and every supported authentication flow. “On one target alone, it discovered 36+ API endpoints spanning account management, user data retrieval, file upload, and administrative functions - many completely unauthenticated,” the Dream threat researchers wrote. “Critically, it found that one of the systems exposed its entire user database without any authentication - thousands of employee records including names, departments, and SSO account IDs.” Multiple entry points After mapping the government’s attack surface, the agents found multiple entry points including three hidden API endpoints that accepted any request body and returned a valid authenticated session without requiring user credentials. Using employee usernames harvested from an unauthenticated API, the agents broke into a government department’s office automation portal, solving its CAPTCHAs with 100 percent accuracy. The agents also tested predictable password patterns based on each employee’s ID, and cracked 85 accounts across multiple password-spray rounds. Eighty-four of the 85 cracked accounts successfully authenticated to the department's internal information system, giving the attackers access to internal dashboards, equipment management interfaces, and personnel statistics pages. In total, the illicit access allowed the agents to exfiltrate a ton of government information, including more than 2,564 personnel records, a full JSON export of all department system users, seven SSO client secrets, six internal database credentials across MSSQL, Oracle, and Sybase, and internal network IP ranges. But wait, there's more And then, the agents pivoted to the Taiwanese government’s supply chain. “It expanded the operation to government IT supply chain vendors, a nuclear safety agency, a government email system, and 7+ energy sector companies - scanning them all in parallel for misconfigurations, exposed admin interfaces, and exploitable vulnerabilities,” the researchers wrote. Notably, the attack framework implemented what the AI tools called “learning cycles.” These are autonomous sessions where the models search vulnerability databases, GitHub repositories, and other security research for specific techniques, CVEs, and common weaknesses to exploit in the targeted government's infrastructure. Additionally, when the AI framework made a mistake, it “self-corrected,” according to Dream, catching errors and fixing them through its own verification process. This near-autonomous attack comes as frontier model makers OpenAI, Anthropic, and Meta all admitted that their agents went rogue, escaped from their training environments, and autonomously hacked other organizations and people. OpenAI technical staffer Michael Dalton, in a Black Hat briefing last week about the Hugging Face attack, said “AI orchestrated, fully automated offensive attacks are real now.” “In the near future, we should expect that threat actors will intentionally deploy, optimize, weaponize, and use offensive agent collectives in the manner that you have just described here,” he added. It appears that the future is now. ®
Kategorie: Viry a Červi

Terabytes of credentials leaked in massive supply-chain attack

Ars Technica - 12 Srpen, 2026 - 23:43

Terabytes worth of credentials, many belonging to the world’s biggest and most sensitive organizations, have been exposed in a supply-chain attack on LiteLLM, an open source tool that streamlines AI-driven software development. Microsoft, Amazon, Cisco, Samsung, and Salesforce are only a handful of the entities whose access secrets were exposed.

The revelation was posted on Tuesday and Wednesday by security firms CloudSEK and Hudson Rock. CloudSEK said it found cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys that could allow attackers to gain access to more than 2,500 organizations.

40 minutes is all it takes

The credentials were extracted during a 40-minute window in March while the victims used compromised versions of LiteLLM downloaded from the package’s official location in the Python Package Index repository. Hudson Rock said it made the discovery after analyzing a 195TB file that it obtained. Neither firm identified the source of the information.

Read full article

Comments

Researcher bypasses Microsoft Defender security patch, seizing control

Computerworld.com [Hacking News] - 12 Srpen, 2026 - 23:13

Just weeks after Microsoft patched a critical hole in Microsoft Defender, a cybersecurity researcher has posted an apparent bypass that provides system-level control to attackers once they gain any level of access. 

The researcher, who goes by the name Nightmare Eclipse, has been engaged in a long-running battle with Microsoft Security

Nightmare Eclipse has not provided the further details we requested, however Microsoft sent a brief statement, saying, “Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims,” and reiterating its commitment to investigating issues and supporting coordinated disclosure.

But the proof of concept (PoC) security bypass, ShieldBreak, described by Nightmare Eclipse in a series of public posts, potentially threatens to be more damaging than earlier bypasses. 

Like other recently reported vulnerabilities, ShieldBreak requires an attacker to first somehow gain system access, typically via a successful phishing scam. Once in, however, the attacker can gain full admin/root access.

But there is a troubling psychological component to ShieldBreak, in that it is a bypass for a recently posted security patch from Microsoft, noted Justin Greis, CEO of consulting firm Acceligence.  The problem is that CISOs who have already deployed that patch might feel protected when they are not.

“This one is concerning because the patch bypass directly calls the integrity of the remediation into question,” he said. “ShieldBreak appears to demonstrate that an attacker can bypass the fix Microsoft shipped for CVE-2026-50656 and ultimately obtain system-level privileges on the endpoint. That is an important distinction for enterprise defenders, because organizations may believe they have already remediated the underlying vulnerability. A successful patch bypass means the exposure can persist even after the normal vulnerability-management process says the system is protected.”

Greis added that such bypass can reduce overall trust in official patches. 

“When public proof of concept code can bypass it, the CISO’s question becomes ‘have we actually removed the exposure?’ rather than simply ‘have we deployed the patch?’,” he said. “From an architecture perspective, organizations should be very careful about allowing the same security product to become both the control being relied upon and the only source of evidence that the control is working.”

Flavio Villanustre, CISO for the LexisNexis Risk Solutions Group, said he was especially concerned about the timing of the PoC’s release, given that it seemed to be intended to put the most pressure on Microsoft, given its typical timing for security patches

“This vulnerability, if valid, would need a fix from Microsoft, but because those patches are usually only released on the second Tuesday of the month and the security researcher seems to have carefully timed the release of the PoC, we may have this exposure for another 4 weeks unless Microsoft deems this a very high severity risk, which is unlikely,” he pointed out.

Cybersecurity consultant Brian Levine, executive director of FormerGov, agreed that CISOs should not underestimate the damage potential if this PoC proves valid. 

“What makes it dangerous is what it does once they’re in: it turns an ordinary low-privilege account into full system control by abusing Defender itself, the security tool running at the highest privilege on the box,” he said. “An exploit that lives inside your antivirus is quiet, it’s trusted, and it can be used to blind or disable the very thing you’re counting on to catch the intruder. It’s not a worm, but it’s a near-ideal second stage for ransomware crews and anyone doing hands-on-keyboard intrusion.”

Levine suggested that CISOs not wait for a Microsoft fix, but immediately take an aggressive defensive stance.

“Assume it’s live and lean on defense in depth, because this is exactly the scenario where treating Defender as your only line fails you. Application allowlisting, such as WDAC or AppLocker in enforced mode, is the strongest hardening available and can stop the payload even if the race succeeds,” Levine said.

“Tighten local admin rights and least privilege so a foothold has less to escalate from. And give your hunters one very specific thing to watch for: an interactive shell or scripting host running as system whose parent process is Defender’s engine, MsMpEng.exe. That should never happen in a healthy environment and it’s a high-fidelity sign someone is running this.”

But he also suggested that CISOs not assume that the PoC necessarily works as advertised. 

“This is a single researcher’s proof of concept. It hasn’t been independently verified, and it’s coming from someone in the middle of a very public and very bitter fight with Microsoft, so perhaps some of the theater around it should be discounted,” Levine said. “But you can’t wave it away either. Patch bypasses are extremely common, and the claim that Microsoft’s fix for RoguePlanet didn’t fully close the door is entirely plausible. Defenders should treat it as credible until proven otherwise, not the reverse.”

Although Levine and other analysts were initially dubious, there are now indications that the PoC’s effectiveness has been independently verified. 

Cybersecurity and risk advisor Steven Eric Fisher, a former cybersecurity risk specialist at Walmart, said, “I’ve seen independent confirmation that ShieldBreak works, although its exploitation method differs materially from the original RoguePlanet exploit. RoguePlanet relied on a filesystem race condition, while ShieldBreak appears to use a different Defender/Cloud Filter API path,” Fisher said. “So while it is being characterized as a bypass of Microsoft’s CVE-2026-50656 fix, it is not simply a replay of the original exploit.”

He added that cybersecurity researcher Kevin Beaumont has already published Microsoft Defender Advanced Hunting detections for ShieldBreak that organizations can incorporate into monitoring while evaluating their exposure.

And Pieter Arntz, malware intelligence researcher at Malwarebytes, also said he has seen confirmation from a researcher he tracks, Will Dormann.

This article originally appeared on CSOonline. It has been updated with a statement from Microsoft and further confirmation of the exploit.

Kategorie: Hacking & Security
Syndikovat obsah