Agregátor RSS
Český prodejce telefonů míří k pěti miliardám. Pomohl mu obchod s Googlem na několika trzích v Evropě
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
Medúzy vyřadily z provozu největší jadernou elektrárnu v západní Evropě. Na plný výkon běží jediný reaktor
Ceny nejlevnějších modelů GeForce RTX 5000 jsou již v průměru 64 % nad MSRP
Veřejný test eDokladů
Chinese Loongson processors have leaky caches, researchers find
Flutter 3.47 a Dart 3.13
Made by Google 2026
Manjaro 26.1 Bian-May
Lovable bolsters its AI software creation capacity, touts $400M funding round
Lovable, the Swedish-based AI software creation platform company, today announced an acceleration of its product, infrastructure, and team development efforts — and a noteworthy round of Series C funding totaling $400 million.
The company said in its statement that it is looking to augment its platform, which it boasts is already used by almost two-thirds of Fortune 500 companies.
Headquartered in Stockholm, Lovable plans to grow its team to 450 people this year, hiring most heavily in machine learning, product, infrastructure, and security roles, and is looking to expand operations from its home base to include locations in London and three US cities: Boston, San Francisco, and New York City.
The planned growth is made possible by the latest infusion of venture capital, which follows a $330 million Series B funding round last December. Lovable now has a $13.3 billion valuation.
The Series C funding was led by Menlo Ventures and the Scaleup Europe Fund and includes US-based Regent. (Regent is the parent company of Foundry.)
Earlier this month, Lovable announced a partnership with Cerebras Systems, the chipmaker that builds processors the size of dinner plates (the Wafer-Scale Engine) and supercomputing systems built for AI inference and training. Cerebras systems are designed to keep an entire AI model’s weights on a single, super-sized WSE chip, rather than split across many GPUs, to avoid GPU memory bottlenecks.
That partnership calls for Lovable to run some of its latency-sensitive workloads on dedicated Cerebras capacity.
“Fast AI is more valuable than slow AI,” said Cerebras CEO and Cofounder Andrew Feldman said in a statement when the partnership was unveiled. “When AI responds in real-time, users do more with it, stay longer, and run higher value workloads. Software creation is one of the clearest examples of the importance of speed. Creators don’t want to wait.”
In its statement today, Lovable said that since its launch in November 2024, people have created more than 60 million projects with its tools, with Lovable-built apps seeing more than 900 million visits a month.
Computerworld is part of Foundry, which is owned by Regent.
"City-Forum" data-theft attacks target Salesforce, ServiceNow portals
Android malware combo takes out loans and relays victims' credit cards
Banky zavádí záchranné tlačítko, kterým stopnete krádež peněz z účtu
Dlužník roky blokoval vlastní insolvenci. Za obstrukce dostal od soudu trest
Podpora unifikované práce se zařízeními v operačním systému Atari: CIO (dokončení)
Gelsingerova Fab 62 v Arizoně už nabrala čtyřleté zpoždění, Intel shání peníze
Astronomové poprvé objevili 3 aktivní supermasivní černé díry v 1 galaxii
'Near-autonomous' AI agents attack Taiwan's nuclear safety agency
Terabytes of credentials leaked in massive supply-chain attack
Terabytes worth of credentials, many belonging to the world’s biggest and most sensitive organizations, have been exposed in a supply-chain attack on LiteLLM, an open source tool that streamlines AI-driven software development. Microsoft, Amazon, Cisco, Samsung, and Salesforce are only a handful of the entities whose access secrets were exposed.
The revelation was posted on Tuesday and Wednesday by security firms CloudSEK and Hudson Rock. CloudSEK said it found cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys that could allow attackers to gain access to more than 2,500 organizations.
40 minutes is all it takesThe credentials were extracted during a 40-minute window in March while the victims used compromised versions of LiteLLM downloaded from the package’s official location in the Python Package Index repository. Hudson Rock said it made the discovery after analyzing a 195TB file that it obtained. Neither firm identified the source of the information.
Researcher bypasses Microsoft Defender security patch, seizing control
Just weeks after Microsoft patched a critical hole in Microsoft Defender, a cybersecurity researcher has posted an apparent bypass that provides system-level control to attackers once they gain any level of access.
The researcher, who goes by the name Nightmare Eclipse, has been engaged in a long-running battle with Microsoft Security.
Nightmare Eclipse has not provided the further details we requested, however Microsoft sent a brief statement, saying, “Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims,” and reiterating its commitment to investigating issues and supporting coordinated disclosure.
But the proof of concept (PoC) security bypass, ShieldBreak, described by Nightmare Eclipse in a series of public posts, potentially threatens to be more damaging than earlier bypasses.
Like other recently reported vulnerabilities, ShieldBreak requires an attacker to first somehow gain system access, typically via a successful phishing scam. Once in, however, the attacker can gain full admin/root access.
But there is a troubling psychological component to ShieldBreak, in that it is a bypass for a recently posted security patch from Microsoft, noted Justin Greis, CEO of consulting firm Acceligence. The problem is that CISOs who have already deployed that patch might feel protected when they are not.
“This one is concerning because the patch bypass directly calls the integrity of the remediation into question,” he said. “ShieldBreak appears to demonstrate that an attacker can bypass the fix Microsoft shipped for CVE-2026-50656 and ultimately obtain system-level privileges on the endpoint. That is an important distinction for enterprise defenders, because organizations may believe they have already remediated the underlying vulnerability. A successful patch bypass means the exposure can persist even after the normal vulnerability-management process says the system is protected.”
Greis added that such bypass can reduce overall trust in official patches.
“When public proof of concept code can bypass it, the CISO’s question becomes ‘have we actually removed the exposure?’ rather than simply ‘have we deployed the patch?’,” he said. “From an architecture perspective, organizations should be very careful about allowing the same security product to become both the control being relied upon and the only source of evidence that the control is working.”
Flavio Villanustre, CISO for the LexisNexis Risk Solutions Group, said he was especially concerned about the timing of the PoC’s release, given that it seemed to be intended to put the most pressure on Microsoft, given its typical timing for security patches.
“This vulnerability, if valid, would need a fix from Microsoft, but because those patches are usually only released on the second Tuesday of the month and the security researcher seems to have carefully timed the release of the PoC, we may have this exposure for another 4 weeks unless Microsoft deems this a very high severity risk, which is unlikely,” he pointed out.
Cybersecurity consultant Brian Levine, executive director of FormerGov, agreed that CISOs should not underestimate the damage potential if this PoC proves valid.
“What makes it dangerous is what it does once they’re in: it turns an ordinary low-privilege account into full system control by abusing Defender itself, the security tool running at the highest privilege on the box,” he said. “An exploit that lives inside your antivirus is quiet, it’s trusted, and it can be used to blind or disable the very thing you’re counting on to catch the intruder. It’s not a worm, but it’s a near-ideal second stage for ransomware crews and anyone doing hands-on-keyboard intrusion.”
Levine suggested that CISOs not wait for a Microsoft fix, but immediately take an aggressive defensive stance.
“Assume it’s live and lean on defense in depth, because this is exactly the scenario where treating Defender as your only line fails you. Application allowlisting, such as WDAC or AppLocker in enforced mode, is the strongest hardening available and can stop the payload even if the race succeeds,” Levine said.
“Tighten local admin rights and least privilege so a foothold has less to escalate from. And give your hunters one very specific thing to watch for: an interactive shell or scripting host running as system whose parent process is Defender’s engine, MsMpEng.exe. That should never happen in a healthy environment and it’s a high-fidelity sign someone is running this.”
But he also suggested that CISOs not assume that the PoC necessarily works as advertised.
“This is a single researcher’s proof of concept. It hasn’t been independently verified, and it’s coming from someone in the middle of a very public and very bitter fight with Microsoft, so perhaps some of the theater around it should be discounted,” Levine said. “But you can’t wave it away either. Patch bypasses are extremely common, and the claim that Microsoft’s fix for RoguePlanet didn’t fully close the door is entirely plausible. Defenders should treat it as credible until proven otherwise, not the reverse.”
Although Levine and other analysts were initially dubious, there are now indications that the PoC’s effectiveness has been independently verified.
Cybersecurity and risk advisor Steven Eric Fisher, a former cybersecurity risk specialist at Walmart, said, “I’ve seen independent confirmation that ShieldBreak works, although its exploitation method differs materially from the original RoguePlanet exploit. RoguePlanet relied on a filesystem race condition, while ShieldBreak appears to use a different Defender/Cloud Filter API path,” Fisher said. “So while it is being characterized as a bypass of Microsoft’s CVE-2026-50656 fix, it is not simply a replay of the original exploit.”
He added that cybersecurity researcher Kevin Beaumont has already published Microsoft Defender Advanced Hunting detections for ShieldBreak that organizations can incorporate into monitoring while evaluating their exposure.
And Pieter Arntz, malware intelligence researcher at Malwarebytes, also said he has seen confirmation from a researcher he tracks, Will Dormann.
This article originally appeared on CSOonline. It has been updated with a statement from Microsoft and further confirmation of the exploit.
- « první
- ‹ předchozí
- …
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- …
- následující ›
- poslední »



