Agregátor RSS

Installed Is Not Remediated: How to Verify Linux Security Patches in Production

LinuxSecurity.com - 27 Červenec, 2026 - 18:22
There are several reasons why Linux has such a good reputation and has become such a good standard across the world. It is the power behind most internet servers and cloud infrastructures as well as billions of Android devices. It is stable, has consistently high-performance levels, and remains very flexible. You don’t have to deal with expensive licenses, can view and share code, and can customize any part of the interface to suit your demands. In an age of data breaches and continuous malwa...
Kategorie: Hacking & Security

Tech giants link hands to praise open AI models after OpenAI - Hugging Face attack

The Register - Anti-Virus - 27 Červenec, 2026 - 18:17
In the wake of OpenAI agents attacking Hugging Face, Nvidia has recruited a new posse of partners to promote open source models as the security solution the industry needs. The AI arms dealer announced the foundation, the Open Secure AI Alliance, in a blog post today, describing the mission of the group being “to ensure defenders everywhere have open, frontier tools they can trust and control.” Partners in the group are numerous, ranging from established tech giants like Microsoft, Red Hat, HPE, IBM, and Adobe to newer groups like Palantir, SpacexAI, Hugging Face, and The Linux Foundation. What all the founding members have in common, Nvidia said, is that they agree open source AI models are a fundamental part of modern cybersecurity, just like prior open source tech has been for the infosec space. “The United States and its partners now face a choice in AI security: whether the defenses that protect our infrastructure will sit inside a few opaque systems or be built on open models, harnesses and tools that any defender can study, adapt and deploy,” Nvidia said in the announcement. The claims in many ways echo the pleadings from tech industry heavyweights made in an open letter to US government regulators last week. That letter, signed by many of the same companies that are part of the founding OSAA cadre, essentially argues that regulators should ensure Anthropic, Google, and OpenAI don’t end up with total control of the US AI market, and that open-weight models should be given a seat at the table, too. The new alliance is arguing that, not only do open-weight models need to be allowed to proliferate in the US, but they also need to be considered a fundamental part of the security puzzle. For those unfamiliar with the Hugging Face incident, a group of autonomous OpenAI agents, operating in a sandbox and stripped of guardrails to test their full capability to solve cybersecurity puzzles, exploited a pair of zero-days to escape and gain access to the internet. For some reason, the bots thought the solution to the problems they were posed could be found in Hugging Face systems, so they broke in and accessed a bunch of private information and hijacked some credentials. When Hugging Face turned to closed-source US frontier AI lab bots to examine the incident and help figure out what happened, those tools declined to help because they thought the data Hugging Face was trying to examine was itself malicious. Hugging Face turned to Chinese-made GLM 5.2, hosted on its own infrastructure, to figure things out. “That incident showed a practical truth,” said Nvidia. “When defenders cannot inspect, adapt and run advanced AI on their own infrastructure, their ability to respond is constrained at exactly the moment speed matters most.” Only open-source AI models, which China leads development on, can fill that role, the OSAA argues, and it’s prepared to counter those who say open models are a threat: Just look at what happened last week and it's readily apparent that closed source models are dangerous too. The Alliance is pooling its efforts to give security pros access to essential open tools. Nvidia said that it’s participating by releasing its Object-Oriented Agent project on GitHub, HPE is contributing its SPIFFE/SPIRE zero-trust AI identity framework, Hugging Face has handed its Safetensors transparent AI model weight formatting to the PyTorch Foundation, and SpaceXAI has open-sourced Grok Build (though the reason behind that doesn’t appear to be entirely benevolent). In addition, IBM and Red Hat have released Lightwell, an automated open-source vulnerability remediation platform, while Microsoft has come out with MDASH, a multi-model agentic scanning harness to automate bug discovery and remediation. Those efforts, while not open source themselves, are still a sign that Alliance members “are building an open defense stack,” Nvidia said. The OSAA ended its announcement with another call for policymakers not simply ban open-source AI models, as doing so “would weaken defensive capacity and risk concentrating power, dependence, and vulnerability in a few closed providers,” the group said. Many providers, as we saw last week, are more concerned with protecting themselves than helping victims of autonomous cyber attacks respond quickly. Clement Delangue, cofounder and CEO of Hugging Face, said in a post on X that he spoke to OpenAI over the weekend about last week’s incident and asked the company to provide funding to support the development of better open-source AI cyber defenses. It’s not clear if the company plans to fulfill that request; it’s not a founding member of the Nvidia-led OSAA. Neither is Google or Anthropic, for that matter. We reached out to all three companies for their take on the new initiative, but didn’t hear back from any of them. ®
Kategorie: Viry a Červi

Krabix.cz, online 3D konfigurátor krabiček pro 3D tisk

AbcLinuxu [zprávičky] - 27 Červenec, 2026 - 18:12
Krabix.cz je online 3D konfigurátor krabiček pro 3D tisk s exportem do STL. Běží přímo v prohlížeči. Nic se neposílá na server.
Kategorie: GNU/Linux & BSD

Deset skrytých nastavení fotoaparátu iPhonu, díky kterým pořídíte výrazně lepší fotografie i videa

Živě.cz - 27 Červenec, 2026 - 17:45
Výchozí nastavení iPhonu zbytečně omezuje maximální kvalitu videí i fotografií • Správným nastavením funkcí fotoaparátu získáte větší kontrolu nad snímky • Pro profesionální tvorbu využijte formát ProRAW a externí ukládání dat
Kategorie: IT News

The best thing about Apple’s smart glasses: what Cupertino rejects

Computerworld.com [Hacking News] - 27 Červenec, 2026 - 17:41

Despite the temptation to enter what might become a $40 billion market, Apple has reportedly decided to delay the introduction of its smart glasses until 2027. The company apparently wants to figure out a better balance between privacy and convenience. 

If it gets that right, Apple might be able to bring to market glasses people can wear in public without making everyone around them wonder whether they, their children, their private conversations or even corporate data are being quietly recorded or filmed.

It’s a sensible move. During the first internet gold rush, many argued that trading privacy for convenience would be more than justified by the benefits. Years later, that bargain looks a great deal less attractive than it did.

We’ve seen this story

After all, since then we’ve seen the likes of Cambridge Analytica and the evolution of digital state surveillance (and state-adjacent surveillance “businesses” such as NSO). We’ve also seen the dubious rise of data brokers, creepy “personalized” ads that seem to follow private conversations around, and all the other parasites that breed in the murk when privacy is diluted.

None of these things is good. More people than ever now seem to understand that when privacy is removed, bad things happen — no matter what herds of fully paid-up lobbyists try to make people believe. Privacy erosion seems to be a great deal for ultra-wealthy corporations seeking to turn our lives into their profit. It is not such a great deal for the rest of us.

The next privacy frontier: Your face

This growing awareness matters as we prep for the next big thing in disruptive technology: AI-equipped wearable devices capable of contextual understanding and analysis of surroundings. These smart, sensor-packed devices will pick up so much information about us, from health biometrics to direction, even insight into what we look at, how long, and what that gazing does to our heart rate. (Think of how useful the latter data point might become for divorce lawyers and blackmail.)

In the next wave of wearables, the data gathered about you will comprise an even more accurate depiction of who you are than what your smartphone already generates. These systems don’t just pick up the raw data about you; because they are AI-equipped, they also gather information about what you do and why you’re doing it. That might be useful some of the time, but is the convenience worth turning your whole life into a data point that can be interrogated, hacked, stolen, or abused? I’m not certain it is.

Apple’s opportunity

Fortunately, I’m not the only one. Apple seems to be rethinking some of the scariest features built into its future (2027) Meta-competing glasses, possibly with the introduction of software fixes to mitigate some of the more egregious ways these devices might be used to disrupt privacy.

This is good business, of course. Not only has Apple fought hardest to protect user privacy, but it also knows that Meta — its main competitor in the smart glasses space — has what could easily be seen as a poor record for privacy protection. With Apple about to enter the fray with its first set of AI wearables since Vision Pro, it must find ways to distinguish its business from Meta’s.

Privacy is one major way to do so – and Apple might be motivated in part by Meta’s attempts to use Europe’s Digital Markets Act to undercut more customer privacy than Apple thinks it should without informed customer consent. If Meta wants that kind of info from an iPhone or Apple Watch, it will make the same play to get data from any other wearables Apple might create. 

What will Apple do?

Apple’s plan boils down to ensuring its devices don’t collect data they shouldn’t. Bloomberg’s Mark Gurman points to the surveillance threat of existing products: “Consumers remain uneasy around people wearing camera-equipped glasses, unsure whether they’re being recorded during conversations at work, restaurants or other public places,” he concedes.

I agree Apple will not want to introduce products that undermine its reputation for privacy, though I reject his opinion that fears about privacy and smart glasses are “probably unfounded.” History already shows these things only seem harmless until they’re not.

Gurman tells us Apple will put a light in the glasses so we can tell when a wearer is filming us, and a feature that disables filming if the light is broken or faulty. The company could also launch glasses with no camera at all, no third-party checking of footage, and on-device (rather than cloud-based) data analysis. He also posits that Apple could include a camera but “hard-code” limits on how it can be used, meaning it might pick up ambient data to feed contextual AI analysis, but not capture video or images. Others have considered a privacy beacon to prevent other devices filming the wearer.

We will likely learn how Apple plans to make smart glasses dumb enough to wear without becoming a privacy pariah at WWDC 2027. Gurman says the products are unlikely to ship until that fall.

You can follow me on social media! Join me on BlueSky,  LinkedInMastodon and subscribe to my daily, human-curated Apple-related news round-up, The Core. 

Kategorie: Hacking & Security

Coca-Cola confirms data theft in Fairlife ransomware attack

Bleeping Computer - 27 Červenec, 2026 - 17:39
The Coca-Cola Company has confirmed that hackers stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month. [...]
Kategorie: Hacking & Security

Ernst & Young data breach claimed by ShinyHunters extortion gang

Bleeping Computer - 27 Červenec, 2026 - 17:12
The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company's systems via a supply-chain attack. [...]
Kategorie: Hacking & Security

Databáze zařízení pro Home Assistant

AbcLinuxu [zprávičky] - 27 Červenec, 2026 - 17:08
Nadace Open Home Foundation spustila veřejnou preview verzi komunitní databáze zařízení pro Home Assistant. Má fungovat jako „Wikipedie pro chytrá zařízení".
Kategorie: GNU/Linux & BSD

A Practical Linux Log Correlation Playbook for Small Security Teams

LinuxSecurity.com - 27 Červenec, 2026 - 17:03
An administrator reports unusual outbound traffic from a Linux server after firewall logs show repeated connections to an unfamiliar external IP address. Nothing obvious appears in the authentication logs, the web server is running normally, and no high-severity endpoint alerts have fired.
Kategorie: Hacking & Security

Firefox 153 oddělí váš soukromý a pracovní život a po letech odmítání podporuje HDR

Živě.cz - 27 Červenec, 2026 - 16:45
Oživeno 27. 7. 2026 | Největším tématem Firefoxu 153 je HDR. Mozilla s implementací pořádně otálela, vždyť Chrome přehrávání videí s vysokým dynamickým rozsahem podporuje od ledna 2018. Edge funkci získal ještě o něco dřív. Firefox každopádně konečně umožňuje přehrávání HDR ve Windows. Musí být ...
Kategorie: IT News

How AI Is Shrinking Linux's Security Patch Window

LinuxSecurity.com - 27 Červenec, 2026 - 16:40
For decades, Linux defenders relied on a comfortable assumption: a public security patch did not imply an imminent vulnerability. While open-source openness made vulnerability fixes public to everyone on kernel.org or the Linux Kernel Mailing List (LKML), converting a raw commit into a weaponized exploit took a significant amount of manual effort. This delay, estimated in weeks or months, gave businesses enough time to assess exposure, organize testing windows, and push changes across product...
Kategorie: Hacking & Security

Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw

The Hacker News - 27 Červenec, 2026 - 16:40
Public exploit details released on July 27 show how an unauthenticated request can reach PHP's eval() function inside vBulletin and execute code on an unpatched forum server. The attack requires no account, administrative access, or interaction from another user. SSD Secure Disclosure lists vBulletin 6.2.1 and earlier, and 6.1.6 and earlier, as affected, but does not give a lower version Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More

The Hacker News - 27 Červenec, 2026 - 16:10
Monday starts with the usual promise that everything is under control. Then the logs wake up. This week, trusted tools crossed lines, old flaws found new work, exposed systems stayed exposed, and attackers kept hiding inside normal-looking services. Nothing looked strange at first. That helped. That is the mood. Here is the full recap. ⚡ Threat of the Week OpenAI Says Its AI Agent Went RogueRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Shadow AI agents are multiplying. Here's how to find and secure them.

Bleeping Computer - 27 Červenec, 2026 - 16:01
Shadow AI agents are rapidly spreading across enterprise platforms, often without IT or security visibility. Nudge Security explains how organizations can discover, assess, and govern AI agents before unmanaged permissions and autonomous actions create security risks. [...]
Kategorie: Hacking & Security

Elektromobil Chip připomíná golfový vozík. Umí jezdit bez řidiče a bude stát méně než Fabia

Živě.cz - 27 Červenec, 2026 - 15:45
Americký startup vyvinul elektrické vozidlo určené pro krátké městské cesty • Model s dojezdem přes 160 kilometrů dobijete z domácí zásuvky • Prázdné auto dokáže na dálku ovládat operátor a sám ho zaparkuje
Kategorie: IT News

Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update

The Register - Anti-Virus - 27 Červenec, 2026 - 15:45
Not content with broken Windows updates, Microsoft has disclosed two problems with Defender for Endpoint on Linux – one that could disable the security service after a reboot, and another that prevents updates on FIPS-enabled Red Hat Enterprise Linux 8 and 9. The more serious problem affected versions 101.26042.0000 through 101.26042.0009 across all supported Linux operating systems. After an upgrade or reinstall followed by a reboot, "the Defender service might be disabled on some devices," according to Microsoft. "If you use Defender for Servers (Plan 1 or 2) with Defender for Cloud and have the MDE [Microsoft Defender Endpoint] integration enabled, automatic updates for the MDE.Linux extension are enabled by default, which means your machines could have received an affected version automatically," it explained. "If an affected version was installed, the issue might impact active protection on rebooted devices until remediation steps are taken." Microsoft did not specify what caused Defender to become disabled, but anything that could knock out endpoint protection will give administrators sweaty palms. A separate problem affected RHEL 8 and 9 systems running in FIPS mode: the 101.26042.x update could fail to install, leaving devices on their previous version. FIPS refers to US Federal Information Processing Standards, which in this context impose requirements on the cryptography used by government and other regulated systems. Although Microsoft's alert did not mention an available update, its release notes direct users affected by the disabled-service bug to build 101.26042.0011. The separate FIPS installation problem is fixed in version 101.26052.0011 and later. Microsoft Defender for Endpoint on Linux protects server workloads on-premises and in the cloud. According to Microsoft, "it helps you prevent, detect, investigate, and respond to advanced threats with unified visibility through the Microsoft Defender portal." Other endpoint security platforms are available, but where an organization has gone all-in with Microsoft, the unified management offered by Defender for Endpoint on Linux can be difficult to resist. Microsoft has an unfortunate habit of shipping broken updates for its flagship operating system, Windows. An update that breaks software specifically designed to protect a device takes things to another level, particularly given the relentless rise in attacks and the need to both fend them off and monitor activity. Hence the appeal of unified visibility through the Microsoft Defender portal. However, an update that could leave Defender disabled after a reboot – while also refusing to install on some security-hardened systems – is less than ideal. ®
Kategorie: Viry a Červi

Nové widgety na stránce nového panelu Firefoxu

AbcLinuxu [zprávičky] - 27 Červenec, 2026 - 15:27
Na stránce nového panelu Firefoxu přibudou nové widgety. Například denně aktualizována interaktivní křížovka.
Kategorie: GNU/Linux & BSD

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

The Hacker News - 27 Červenec, 2026 - 15:05
n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation platform. Security Joes found the flaw while probing n8n's February fix for CVE-2026-27577 for another bypass. The affected ranges are <2.31.5 and >=2.32.0,<2.32.1. n8n fixed the flaw in versions 2.31.5 and Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Apple zdražuje předplatné. V Česku ale zvýšil ceny jen u hudební služby Music

Živě.cz - 27 Červenec, 2026 - 14:45
Apple minulý týden ve světě zvyšoval ceny předplatných. Ve vybraných zemích zdražil úložiště iCloud+ a superpředplatné One, které zahrnuje všechny jeho prémiové služby. Česko je ve skupině zemí, kde si uživatelé nově připlatí za hudební službu Music. Největší konkurent Spotify teď ve verzi pro ...
Kategorie: IT News

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

The Hacker News - 27 Červenec, 2026 - 14:37
Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs "secure document" lures to deliver legitimate remote monitoring and management (RMM) tools. "The victim was directed through compromised web infrastructure to a counterfeit Microsoft Store page claiming that Microsoft Teams had to be updated before the shared document could be opened," ZeroBEC said inRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Syndikovat obsah