Agregátor RSS

Linux Security Update Fixes 12 X.Org and Xwayland Flaws

LinuxSecurity.com - 8 Říjen, 2026 - 21:00
X.Org has issued fixes for 12 vulnerabilities in its display software.
Kategorie: Hacking & Security

Linux TCP Fast Open Use After Free Leaves a Packet Pointer Behind

LinuxSecurity.com - 8 Říjen, 2026 - 20:45
A bug in Linux’s TCP Fast Open code can leave it reading memory that has already been released.
Kategorie: Hacking & Security

Apache Jackrabbit Fixes Critical WebDAV Session Hijacking Flaw

LinuxSecurity.com - 8 Říjen, 2026 - 20:35
Apache disclosed a critical Apache Jackrabbit session hijacking flaw on Oct 7, 2026.
Kategorie: Hacking & Security

FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

The Hacker News - 8 Říjen, 2026 - 20:32
Hackers tied to a Chinese cybersecurity company stole email from government organizations, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia, the FBI and agencies in 6 other countries said on October 8. The company, Integrity Technology Group, has been sanctioned by the U.S. and the UK. The hackers scanned websites for flaws using a tool containing more Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

This Tool Turns Scientific Articles Into Agents That Answer Questions and Collaborate

Singularity HUB - 8 Říjen, 2026 - 20:24

The Paper2Agent system could make it easier to understand papers, reproduce results, and generate hypotheses.

For centuries, the humble scientific paper has been the way researchers share discoveries. These papers are highly formulaic. Each starts with an introduction laying out the problem, followed by hypotheses, results, and conclusions.

More recently, journals have asked authors to include code or datasets—like brain scans or gene activity—for others to inspect and reuse. Video and image summaries are now often welcome too.

But for the most part, papers haven’t changed much. They may tell an intriguing story—if you can get past all the jargon. And a PDF dozens of pages long makes it tough to reproduce results, often the first step in a new project. Human error can also leave out important pieces.

“For years, we have felt that static research papers are not the best way to represent scientific knowledge,” wrote James Zou at Stanford University. His team is about to shake things up. This month, they described Paper2Agent, a workflow that turns papers into interactive AI agents.

These aren’t your average chatbots. Each is trained on a paper’s text, figures, and data, and asked to reproduce its results, essentially running through the experiments in a virtual world. This gives them a deeper understanding of the work, turning them into virtual “authors” that can answer complex questions about it. They can also apply methods from one paper to a new dataset and even collaborate with other paper agents across disciplines.

There’s now “an opportunity to fundamentally reimagine what knowledge looks like,” Zou said in a press release. “Instead of having only passive artifacts, why don’t we convert each static record into an active embodiment of knowledge?”

Embarrassment of Riches

The volume of scientific publishing has skyrocketed in recent decades. Global scientific output topped three million papers in 2023, and the numbers are still climbing.

That much literature would overwhelm anyone. Yet reading papers to build up foundational knowledge is the first step in any scientific project. The challenge is even thornier when research crosses disciplines—say AI and protein science, or machine consciousness and neuroscience. In these cases, scientists must master multiple fields, but the connections they form often spark breakthroughs.

The sheer volume creates another headache: reproducibility. Scientists are a critical bunch. Before building on a previous paper’s conclusions, they often try to recreate the experiment to see if they get the same results.

It doesn’t always work. In the landmark 2015 Reproducibility Project, only 39 percent of psychology studies produced results consistent with their original findings. A 2026 analysis didn’t fare much better. And large language models may add a wrinkle in machine learning research, where the pipeline, from data collection to model selection and training, isn’t always well documented.

For Zou and team, turning papers into AI agents could help us tackle these problems.

‘Living’ Knowledge

To develop Paper2Agent, the team first ask it to scan all sections of a paper and then try to recreate its results. Along the way, it captures details that a reader might otherwise have to dig out, such as experimental setups and chemicals, and saves them in a digital vault called an MCP server.

Anthropic developed MCP to give AI systems access to tools, data, and workflows through a common interface. Scientists can then link a large language model of their choice to the server, query the agent in everyday language, or run new experiments using their own data while borrowing the paper’s methods.

In other words, Paper2Agent is like a translator between a human-written paper and a chatbot.

That might sound redundant. After all, it’s already possible to upload a paper to ChatGPT, Claude, or another chatbot and ask questions. The difference is in the training: A chatbot can summarize a paper’s results, but it doesn’t have a deeper understanding of how those results came to be or whether the underlying analysis holds up.

By trying to replicate results based on the paper, Paper2Agent’s AI gets a sort of hands-on experience, potentially making it less prone to hallucination. The agents can “provide much more in-depth insights to the readers,” Zou told Nature.

In one experiment, Paper2Agent created an agent based on a recent paper describing AlphaGenome, an AI model that predicts how changes in DNA letters affect their function. It took under an hour without human supervision.

When asked genetics questions requiring AlphaGenome analysis, the agent answered with near-perfect accuracy. It was also two to four times faster than Biomi and other “AI scientists” given access to the same paper, likely because it had a better grasp of AlphaGenome’s tools and capabilities.

The tool didn’t always work. When the team applied it to 110 papers spanning computational biology, machine learning, astrophysics, and other fields, it successfully converted 76 percent into working agents. But that failure is arguably a feature, not a bug. Papers that couldn’t be agentified often lacked sufficient code, data, or model files, or relied on broken scripts and unavailable datasets.

“Agentification can therefore serve as a practical diagnostic of computational reproducibility,” wrote Zou and study author Jiacheng Miao.

Digital Collaboration

Left alone, the agents began “talking” to each other.

In one test, Paper2Agent converted two studies on psoriasis into agents. Working with the AlphaGenome agent, the trio found a previously unknown genetic variant as a potential cause for the condition. An agent based on a paper about ADHD genetics similarly flagged a new mutation associated with increased risk. Another pair of agents identified a DNA letter variant linked to “bad” cholesterol, one that AlphaGenome had not pinpointed on its own.

These results showcase the power of collaboration in a world where papers aren’t isolated documents. “In the past, if there are two research groups that publish two different papers, those two research groups have to somehow find each other,” Zou said. Paper agents could make that matchmaking automatic, allowing findings from different studies to mesh—and produce new ideas—with far less human effort.

Paper2Agent is free to use, although installing and running it still needs some computer savvy scientists may not have. For trainees, it could become a shortcut that stunts their ability to critically evaluate a paper and spot flaws in the authors’ logic, instead taking an agent’s reply at face value.

Other questions remain. If agents become a new way of sharing scientific knowledge, who should be responsible for creating them? And can papers based primarily on wet-lab experiments, rather than code, also benefit?

Magdalena Skipper, editor-in-chief of Nature, which published the work, doesn’t expect conventional papers to disappear anytime soon. But she is optimistic that agentifying papers could alter the future of sharing scientific knowledge.

“There is a prospect that…there will be something genuinely influential that will change the way knowledge is disseminated, but importantly, the way that knowledge is interacted with,” she said.

The post This Tool Turns Scientific Articles Into Agents That Answer Questions and Collaborate appeared first on SingularityHub.

Kategorie: Transhumanismus

High-severity Nvidia bug could crash GPU monitoring on exposed servers

The Register - Anti-Virus - 8 Říjen, 2026 - 20:17
Researchers found thousands of GPU servers exposing Nvidia's DCGM Exporter to the internet, with hundreds potentially vulnerable to a high-severity flaw that could let unauthenticated attackers crash the GPU monitoring service and disrupt AI workloads. DCGM Exporters read telemetry from the GPUs on a host, including its hardware, utilization, memory usage, power consumption, and error events. Each GPU has its own unique ID, or UUID, and all of these metrics are exposed in plaintext over HTTP. This exposure provides would-be attackers with detailed information useful for reconnaissance, including mapping GPU infrastructure, identifying potentially vulnerable systems, and monitoring workload activity. Michael Katchinskiy, a researcher at datacenter security startup Lava, found and reported the bug in the GPU health and performance monitoring service. In September, the GPU giant Nvidia released a fix for the flaw, tracked as CVE-2026-47483, and gave it an 8.2 CVSS high-severity rating. “Once we realized how much these endpoints revealed, the next question was: How many of them are exposed to the internet?” Katchinskiy said in a Thursday blog. So the researchers started scanning the internet for exposed DCGM Exporters. And the scale of exposure proved “especially significant,” he wrote. Over the course of four scans between March and May, the threat hunters found about 2,100 GPU servers exposing DCGM Exporter metrics to the open internet. These included 12,000 GPU UUIDs. None of these required authentication. The hosts belonged to about 300 organizations, according to Katchinskiy, and nearly half - 5,274 of the exposed GPUs, or 44 percent of the total - were located in the US. These GPUs represented about $100 million in hardware, and included Nvidia Blackwell Ultra B300 GPUs, H200s, and H100s - used to run large-scale AI workloads - plus consumer RTX 5090 and 4090 systems. While investigating the exposed systems, the Lava team found that about 25 percent of the exposed DCGM hosts also revealed data from Go’s /debug/pprof/ built-in profiling tool. The profiler collects and exposes runtime performance data such as CPU and memory usage for running Go applications. This includes CPU usage, memory allocations, goroutine states, and blocking events. “With enough concurrent unauthenticated requests, the exporter could run out of memory and crash, cutting off visibility into GPU health and activity,” Katchinskiy wrote. The CPU and memory pressure could also affect AI training or inference workloads. Nvidia fixed the issue in version 4.8.2, and operators should upgrade to that version or later. In addition to GPU telemetry, Lava looked into Prometheus Node Exporter, which monitors server hardware and operating systems, and also exposes metrics over HTTP. The team found 12,096 public Node Exporter hosts exposing data on server models, operating systems, firmware versions, hostnames, storage paths and networking hardware commonly used in GPU clusters. This information reveals how environments are built and configured, which could also be used by attackers for reconnaissance, matching the system to known vulnerabilities. The publicly exposed monitoring services affected customer infrastructure across neocloud and GPU cloud providers including Nebius, Voltage Park, Lambda, Northern Data, and DigitalOcean. Lava reported all of this to the affected providers, and Katchinskiy says that these providers worked with customers to address the exposures. For operators: the security shop says Nvidia DCGM Exporter, Node Exporter and Prometheus services should not be directly reachable from the public internet and recommends restricting them to authorized monitoring infrastructure. “The findings highlight a growing security gap in AI infrastructure: companies are spending millions on GPUs while leaving critical systems exposed,” Katchinskiy wrote. “Those exposures can reveal how AI environments are built and, in some cases, allow attackers to disrupt them.” ®
Kategorie: Viry a Červi

ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories

The Hacker News - 8 Říjen, 2026 - 19:58
The crooks have trust problems of their own. One ransomware affiliate decided to keep the profits for himself. Elsewhere, an attacker left a server exposed, complete with tools and traces of an intrusion. Apparently, keeping things secure is a problem on both sides of the fence. The rest of the week isn't much more reassuring. Malicious code turned up in developer packages and extensions that Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

FakeGit malware campaign returns with 17,610 malicious GitHub repos

Bleeping Computer - 8 Říjen, 2026 - 19:10
More than 17,000 fake repositories on GitHub are distributing the SmartLoader malware after the FakeGit campaign reactivated earlier this month to push the StealC infostealer. [...]
Kategorie: Hacking & Security

Shai-Hulud worm makes jump to AI infrastructure with Tensorlake compromise

The Register - Anti-Virus - 8 Říjen, 2026 - 18:54
The credential-hijacking Shai-Hulud worm has struck again, this time burrowing its way into a popular AI agent platform SDK. Multiple security researchers reported Thursday that they had detected Shai-Hulud infection in a recent release of the npm package for version 0.5.144 of Tensorlake’s SDK. That package has somewhere in the neighborhood of 12,000 downloads per week, while its GitHub repository has more than a thousand stars, suggesting it’s quite popular and that the infection could pose a serious risk to anyone who installed the malicious version. Analysis of the malicious release suggests it shares code and techniques with the Shai-Hulud variant dubbed ChainDrop by researchers, which was used in August to compromise npm dependencies including keyv and flat-cache. Like other variants of Shai-Hulud, the worm is designed to steal credentials and self-propagate. This particular version, according to supply chain security firm SafeDep, is designed to steal everything from crypto wallets to browser passwords, GitHub Actions secrets, cloud credentials, service-account tokens, and whatever else it can get its hands on. It exfiltrates that data and keeps an open line to its C2 infrastructure to await further instructions. To make matters worse, this Shai-Hulud variant monitors certain stolen GitHub tokens and, if one is revoked, can trigger the deletion of the infected user's home directory under specific conditions, making removal tricky. Socket recommends rebuilding compromised systems from a trusted source before restoring access to secrets, while researchers warn that the malicious token monitor should be disabled before revoking affected credentials. Tensorlake, for those unfamiliar, is a cloud-native platform for running isolated AI agents and untrusted AI-authored code. The infected npm SDK is used to create and manage Tensorlake environments. Socket warns that the malicious SDK's installation script can execute on the developer's machine or build server, outside Tensorlake's sandbox protections, potentially compromising the host before any AI-generated code is run. “Teams may isolate an agent’s generated code while installing its SDK on a developer workstation, application server, or build runner with access to deployment credentials and other secrets,” Socket noted. “Code executed during that installation inherits the permissions of the installing process.” That may sound bad, but it’s worth noting the malicious version wasn’t up for long - according to security firm Socket, the infected version was published to npm earlier this morning, UTC, and was flagged by its engine 11 minutes after publication. Npm removed the version, and Tensorlake has pulled the package as well, updating the version to 0.5.145. Best check to be sure you haven't installed the malicious version if you're a Tensorlake user. ®
Kategorie: Viry a Červi

Jednou větou mi ChatGPT vytvořil hru. Zkuste nové interaktivní odpovědi

Živě.cz - 8 Říjen, 2026 - 18:45
OpenAI od včerejška zpřístupnilo v ChatGPT nový model GPT-6 a s ním i funkci Intelligent UI, díky kterým budou odpovědi pestřejší. Kde se to hodí, tam AI použije obrázky, grafy nebo interaktivní aplikace. „Naučili jsme GPT-6 vytvářet odpovědi pomocí textu, vizuálních prvků a interaktivních ...
Kategorie: IT News

Microsoft will let Copilot act on local files on Windows PCs

Computerworld.com [Hacking News] - 8 Říjen, 2026 - 18:02

Microsoft is giving Copilot greater control over Windows PCs, allowing the AI assistant to organize and make changes to local files, and run certain tasks using on-device AI models.

The changes were announced at Microsoft’s Hybrid Intelligence event, where it outlined plans to combine local and cloud AI processing to help customers reduce AI costs and retain more control over data.

Three new Copilot capabilities will be available to Copilot+ PC users “in the coming months,” Microsoft said.

One is the ability for Copilot to access local files and recent user activity, providing additional context for the AI assistant’s outputs.

Copilot will also be able to perform actions on a device, such as moving files and changing settings.

“It has the same level of the ability to control and change things that I do as a user, but always with permission,” said Jacob Andreou, Microsoft EVP, Copilot, during the event.

The capability sounds similar to Copilot Actions, an “experimental” feature that Microsoft announced last year in preview for Windows Insiders at the time.

Finally, there will be an option to run Copilot on local AI models for certain tasks, only accessing cloud servers “when needed,” Microsoft said.

“Copilot will still use the cloud for the hardest tasks,” said Andreou, “but for times when cost or privacy matter more, it can delegate down to local models that run directly on your computer.”

Microsoft’s hybrid model reflects market demand, noted Biswajeet Mahapatra, principal analyst at Forrester. “The demand we see is not for AI that runs exclusively on-device, but for AI that can intelligently decide which workloads should run locally and which belong in the cloud,” Mahapatra said. “Enterprises increasingly want both options available.”

In a demo, Andreou also showed how the ability to access and interact with local files will increase the usefulness of Autopilot (formerly called Scout), the long-running Copilot agent that can be set to work continuously in the background. (Autopilot is currently in private preview.) Autopilot can also run on locally hosted models, he added, helping reduce costs and avoid sending private data to the cloud.

Microsoft also announced more powerful hardware — including the Surface Laptop Ultra and Surface RTX Spark Dev Box — and more efficient AI models designed to run on devices.

“Most companies are still getting their heads around AI, token usage, which models to use, and where to run them,” said Tom Mainelli, group vice president, Device & Consumer Research, at IDC. “As these companies get more savvy and look to scale AI to more employees, the need to run AI locally — including Microsoft Copilot — will increase.” 

Current business laptops have some local AI capabilities and features, said Mainelli, but still largely rely on Copilot running in the cloud. This could change once more advanced hardware is broadly available, he said.

“As more systems ship with the right combination of CPU, GPU, NPU, and memory, and as local models continue to improve, I expect more AI jobs to run on the device,” said Mainelli.

For now, the installed base of enterprise PCs “remains highly mixed,” said Mahapatra.

“While Microsoft highlighted new AI-capable hardware, and noted that a growing share of business laptops are Copilot+ PCs, most enterprise fleets will take several years to refresh,” he said.

“The immediate opportunity is therefore concentrated among organizations already investing in AI PCs and high-performance devices. Many enterprises will continue to rely primarily on cloud-hosted AI while selectively adopting local AI capabilities as refresh cycles progress.”

Microsoft is also attempting to address security when running agents on-device. This includes the general availability launch of Microsoft Execution Containers (MXC) on Windows 11, which allows organizations to set up policies that define which files and networks agents can access. MXC is supported by a range of agent tools, including OpenAI’s Codex and OpenClaw, with Anthropic Claude Code, Box, Manus, and others to follow.

Added security measures should give business customers more confidence when enabling Copilot to access local files, said Mainelli. “That’s what Microsoft is bringing to the table: a level of security and traceability in these processes that should give companies confidence in using them,” he said. “Microsoft took major steps in telling that story today, and we’ll see how companies respond.”

Enterprises should manage agents on Windows devices “in the same way they approach any automation platform: trust should be based on controls, not on the AI itself,” said Mahapatra.

“Microsoft’s announcement is significant because it acknowledges that agents require a different security model than traditional applications,” he said. “Technologies such as Microsoft Execution Containers are designed to limit what agents can access, identify which agent took an action, and enforce policy-based controls.”

At the same, he warned against granting broad autonomous access to local files without appropriate governance. “Role-based access, read-only assistance, document summarization, search, and workflow support are likely to be adopted more quickly than autonomous file modification or business process execution,” Mahapatra said.

“As agents move from providing recommendations to taking actions, organizations will need stronger approval controls, monitoring, auditing, and human oversight. This is especially important for agents interacting with sensitive data, regulated processes, or systems of record.”

Kategorie: Hacking & Security

Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks

The Hacker News - 8 Říjen, 2026 - 17:45
Attackers behind a string of personal data leaks at Japanese organizations have abused APIs for mobile apps and targeted known software flaws, the JPCERT Coordination Center (JPCERT/CC) said. The Tokyo-based center, which takes incident reports, based its October 8, 2026 alert on those reports and other information. The alert names no attacker and no affected organization. JPCERT/Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Seznam se obejde bez hesla. Zavádí přístupové klíče

Živě.cz - 8 Říjen, 2026 - 17:45
Seznam je první velkou českou službou podporující passkeys. • Na západě jde o rozšířenou technologii nahrazující hesla. • U Seznamu si heslo ponecháte, ale při přihlášení jej nemusíte používat.
Kategorie: IT News

UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML

The Hacker News - 8 Říjen, 2026 - 17:26
The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN. According to TrendAI, the malware has been put to use in attacks targeting Ukrainian government personnel. The cybersecurity company is tracking the cluster under the name Earth Sirrush (previously SHADOW-EARTH-065). ASHVEIN, Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Cisco warns of critical flaws allowing Nexus switch takeover

Bleeping Computer - 8 Říjen, 2026 - 17:26
Cisco released security advisories for five critical vulnerabilities in its NX-OS data center network operating system that could be exploited to run arbitrary code with root privileges on Nexus switches. [...]
Kategorie: Hacking & Security

Fighting GenAI with GenAI: The New Email Security Landscape

The Register - Anti-Virus - 8 Říjen, 2026 - 17:00
The use of phishing emails as a means of stealing information or implanting damaging malware dates back to the mid-1990s. Although almost as old as the Internet, it remains the instrument of choice for threat actors wanting to pose as trusted organizations or individuals for the purposes of corporate infiltration. In fact its use is on the rise: according to the most recent figures from the Federal Bureau of Investigation (FBI), some 26 percent of all cybercrime complaints filed with them are now phishing-related. The bad news doesn’t stop there. Phishing is mutating in alarming new ways, raising all sorts of difficult questions for defenders and placing email security at a tricky inflection point. AI has for years been a useful tool in the hands of the cybercriminal. But the advent of Generative AI (GenAI) is proving a cyber game changer, transforming phishing from a widespread but easily identifiable nuisance into a lethal precision instrument. Aspiring phishers have historically been hindered by various constraints. Their attempts at chummy authenticity have often been undermined by easy-to-spot mistakes and amateurish formatting – blemishes that traditional email security is good at picking up. Personalised attacks have also been hard to launch at any kind of scale. GenAI sweeps all technical, linguistic, and operational restrictions aside by automating sophistication. Attackers no longer have to choose between individually targeted “spear phishing” which takes much effort to coordinate, and large-scale attacks that lack finesse. Now, with minimal expertise and at low cost, they can hit thousands of victims with minutely tailored phishes at the press of a button. Today’s Large Language Models (LLMs) generate polished and contextual text in any language, backing it with realistic brand graphics and convincing web addresses. At a stroke, Gen AI has democratized this type of crime, putting it in reach of anyone capable of the most elementary research. “Thanks to AI, the historic signals that exposed a phishing email – poor grammar, misspelt words – are now ironed out and replaced with perfect language,” notes Dave Baggett, SVP Cybersecurity with software developer Kaseya. “These emails can be highly targeted with the help of AI. You can create an email that pinpoints, say, a pharma company by using authentic terminology. It’s an incredibly powerful tool for the bad guys.” And let’s not forget that where this new AI-enabled phishing is successful, it is not just a single unwary employee whose data is at risk. Once past the perimeter, a bad actor can get to work burrowing into the cloud and SaaS platforms that now underpin global commerce and communications. All in all, it’s easy to understand how losses from phishing attacks have gone up 274 percent in the last couple of years, according to the FBI. This new email security landscape is an alarming development for corporate IT bosses, and also for MSPs who must be super wary on behalf of customers who don’t have the expertise to pick up attacks at this pitch of sophistication on their own. AI is for the good guys too It’s not all bad news on the email security front line. As threat actors have been perfecting their use of GenAI, defenders have been developing AI-driven counter solutions in parallel. Where old school protection relied on spotting the kind of anomalies that GenAI has now ironed out, newer solutions are geared more towards contextual analysis. They are not so much trying to spot clumsy typos and dodgy attachments as model an attacker’s intent before damage is done. Today defenders can use AI to analyze subtle patterns that are in tune with the layered structure of modern phishing campaigns. The aim is to determine whether a message aligns with expected behavioral patterns. This level of finesse is made necessary by the insidious nature of modern phishing which means that technically clean email messages, in other words ones that are free of malware-loaded attachments or booby-trapped links, can still contain malicious potential. Modern cybercriminals often bypass automated security filters by the simple means of exploiting human psychology and trusted infrastructure. Social engineering, supercharged by GenAI, can be a sharper sword than a malware payload. A phish will often seek to impersonate a boss or a colleague using a plain text email. Attackers can set GenAI to scour LinkedIn, looking for people who have just started new jobs. Green employees are more vulnerable to a phish that looks like an email from a new superior they haven’t got to know yet. Once trust is established, what will typically follow is a demand for, say, an urgent wire transfer, or a casual request for payroll details or passwords. Attackers can develop a relationship over multiple emails to “groom” the victim before striking. Traditional filters see nothing suspicious. Spotting this sort of attack demands a smarter grade of tool. “Since attackers are relying on manipulation of fallible individuals, security must now support them at the moment where wrong decisions can be made,” says Baggett. “Good email security will replace generic warnings with easily digestible context about why a message might be risky and advice about the need for further verification.” Where once an inbox was a passive delivery channel, says Baggett, it is now an active layer of risk mitigation, tooled up to stamp out a phishing attempt before it escalates into account compromise and devastating financial loss. A huge asymmetry The good guys are fighting back. But as Baggett points out, there remains a huge asymmetry between bad actor and defender: “Attackers can use LLMs, basically for free, to create perfect phishing templates,” he says. “On the other hand, if defenders took every inbound email and put it through a frontier LLM model, that’s about 100x too expensive. We just can’t use the same tools at the criminals.” One option for defenders is to use smaller, more specialized models, distilled from larger ones. A compact model could be tuned, for example, to the sentiment or meaning of each phrase in an email, and set to pick up a threatening tone or a favor being asked. Where chunky LLMs just cost too much, another choice might be to run a subset of the overall inbound mail through a big model: “Admins can be given a way to run particular mails through a frontier LLM,” says Baggett. “That model will have been trained to understand certain critical aspects of email security.” Better use could be made of pre-LLM tools such as computer vision, which can help process, analyze and understand visual data like digital images and videos. Other ancillary tools that could enrich the defensive mix include sender analysis to look into the origin and authenticity of an email message, and linked-content inspection that can examine an email in depth without triggering any embedded threats. There are some reasons to hope for a safer future as AI technology evolves. As inference becomes smarter and models get better, it should become possible to run a higher percentage of emails through a large scale LLM, believes Baggett. This, however, may not be achievable for some years. There’s also the possibility of using LLMs not just to spot potentially malicious emails but also to analyze the settings and admin controls of existing security tools. In this way, the knowledge required to use the tools to best effect becomes much less. “Security tools can be complex and feature hundreds of settings,” points out Baggett. “Some require expertise that our customers don’t have. There are a number of things we believe tools should be doing to help defenders, for example reduce alert fatigue.” The criminal fraternity may, of course, also find ways to harness better tools for new purposes. At the moment, most attacks are conceived and designed by humans. But ultimately, this job may be taken over by agentic models able to figure out new tactics for themselves. Machines may soon be able to plan and supervise attacks at scale. Great tools, available now Luckily defenders don’t have to sit back and be at the mercy of future developments. There are some great tools available today that help them even up the odds and cut the complexity from checking email. INKY Smart Insights, for example, uses GenAI to reduce a lengthy manual email investigation to a few seconds of automated triage. For the purposes of hard-pressed administrators it can turn a mess of technical email evidence into a plain-language verdict and enable the creation of cogent reports. Along with Kaseya Intelligence it can support decision-making across the broader security environment. “Smart Insights will identify problems and give a narrative explanation of its reasoning,” enthuses Baggett. “It will do that in a way that’s not overly technical, making the tool valuable to someone who doesn’t have expertise in email security.” The hard-pressed MSP, for example, can leverage Smart Insights to provide key information for their customers in an abbreviated and digestible format. In short, it allows them to enjoy the sophistication of LLMs but without adding hugely to their overheads. The war on GenAI-powered phishing is far from won. But so long as defenders can understand the potential of the smart tools at their disposal, they have a fighting chance of keeping the bad guys at bay and essential channels of communication safe. Find out more at Kaseya’s Cybersecurity Summit – details here Sponsored by Kaseya
Kategorie: Viry a Červi

Fast AI, slow rollback: the risk facing Apple IT teams

Computerworld.com [Hacking News] - 8 Říjen, 2026 - 16:58

There’s a big disconnect between the rate at which IT is deploying various kinds of AI-generated output and the speed with which it can roll those changes back when things go wrong, warns a new report from Fleet Device Management. It’s almost as if the rush to embrace AI has eclipsed the need to manage its deployment effectively.

The research, based on a survey of more than 250 enterprise IT practitioners managing Apple devices, is available in full via the company’s website and echoes similar concerns I’ve heard from others in the space. I spoke with Fleet founder and CEO Mike McNeil to get his take on the disconnect. 

What’s happening in the enterprise

First, some of the stats gathered in the survey:

  • 86% of respondents allow AI-written output to reach production devices following some review.
  • 61% used AI to author an MDM profile/configuration in the past month.
  • 62% used it to write scripts/code.
  • 69% can’t roll back a bad configuration within an hour; 43% need more than a day.
  • About a quarter (26%) can recover the same day but only with manual intervention.

McNeil stressed the challenge exposed by this data. “When one of those changes is wrong, 69% can’t undo it within an hour, and 43% need more than 24 hours,” he said. “So the exposure is real even without a count of incidents. The AI tool isn’t what gets pulled back. The configuration it produced is, and most teams do that by hand.”

The risk of moving too fast

He told me that just 7.6% of Fleet’s customers are exclusively Mac shops, confirming that most Fleet clients manage multiple platforms. It’s not a platform-specific challenge; McNeil sees this as a problem for all of them.

“I’d frame risk by two things: how much privilege the code runs with and how hard recovery is,” he explained, noting the risk of scripts running at root, which can take full control of the machine to the extent that reversion can’t undo what’s done. 

“Windows and Linux have the most scripting-heavy management, so they have the most room for script-level mistakes,” he said — but even iOS is at risk from a bad restriction or network profile, particularly when attempting to recover remotely.

He pointed out: “36% of respondents manage Apple devices through Intune, a Windows-first platform. Tooling built around one platform’s assumptions tends to be weakest at the edges of another’s.”

Why MDM is a high-risk tool

For Apple in the enterprise, the risk is inherent to device management and IT’s power to use MDM to deploy a potentially poorly crafted AI tool at scale. 

“MDM is one of the few trusted paths that can bypass the [macOS platform security] prompts, which is exactly why a bad or malicious MDM-delivered change is so consequential,” he warned. 

He continued: “Windows has a larger and older attack ecosystem, with more legacy surface area. Linux gives administrators the most freedom and the fewest guardrails. On every platform, the management channel is the high-value target, so the same controls apply — review, least privilege, a change record, and a fast revert.”

The risk is that poorly crafted AI-generated MDM profiles can set off a chain of problems that can take days to resolve, particularly in large-scale device deployments. The problem is that unless there’s a clear audit record, it’s harder to remediate errors.

“AI speeds up authoring, but review capacity stays the same,” McNeil said. “Without a gate, errors and anything malicious in a script reach production faster.”

Speed needs to be managed

Ultimately, while AI can accelerate a multitude of IT tasks, the speed of deployment must also be matched by robust review and strong rollback tools. “Speed is only an advantage if recovery keeps pace,” he said.

Fleet’s core argument is that IT needs to change how it approaches what it does. “Mac administration is an engineering discipline now, and these admins are further along than the industry thinks,” he said. “The infrastructure around them hasn’t caught up.”

How should IT approach this? McNeil suggests a succession of protections his own MDM system already supports through GitOps with YAML files, adding, “the pattern works with any tool that has an API.” 

  • Treat device configuration like application code. 
  • Profiles, scripts, and policies should live as files in a Git repository. 
  • A change arrives as a pull request, a second person reviews it, and automation applies it to devices. 
  • To undo it, you revert the commit. 

“One caveat: a revert fixes what the configuration says. It doesn’t undo a script that has already run. That’s an argument for preferring declarative configuration over imperative scripts where you can,” he advised.

Less clicking, more engineering

None of these cautions are arguments against use of AI in enterprise IT, of course. They are arguments to promote a more conscious management system around the use of it. All the same, as AI proliferates, the Fleet CEO does think IT pros must anticipate a change in their roles. “Less clicking, more engineering,” he said.

“As AI takes on more of the mechanics like creating configuration profiles, drafting scripts, and troubleshooting routine issues, admins can spend less time figuring out how to make a change and more time deciding what should change, how it affects the business and where human judgment is required,” he said.

Finally, I pointed to the ongoing dilemma between Apple and IT. Some people complain Apple doesn’t innovate in the enterprise fast enough, others say it innovates too fast. What does Fleet think?

“Keeping up with Apple’s release pace was the single most cited hardest part of the job, at 31%,” he told me. “Budget and headcount came last, at 5%. Admins aren’t complaining that Apple ships too little. They’re stretched by the yearly OS cycle, new frameworks, and deprecations.”

“My own view is that the direction is right,” he said. “Declarative Device Management and tighter platform security are good for enterprises. The pace is the issue, and it’s the main reason admins need automation and a safety net.”

Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSky, LinkedIn, or Mastodon.

Kategorie: Hacking & Security

Nejlepší katastrofické filmy. Když se svět hroutí a začíná boj o přežití

Živě.cz - 8 Říjen, 2026 - 16:45
Katastrofické filmy fascinují tím, jak křehký je svět, který považujeme za samozřejmý. Stačí výbuch, vlna, otřes a nudný život se mění v boj o přežití. Klasické hollywoodské spektákly, komorní evropská dramata, realistické rekonstrukce i apokalyptické vize ukazují zkázu v celé její podobě. Zároveň ...
Kategorie: IT News

Strands Decider, maličká obdoba modelu Jev

AbcLinuxu [zprávičky] - 8 Říjen, 2026 - 16:37
Strands Decider 2B je malý open-source model s 2 miliardami parametrů, určený k rychlé klasifikaci vstupů a rozhodování mezi možnostmi, generující odpovědi ve stylu modelu Jev. Strands dosáhl přibližně 72% shody s Jevem na veřejné testovací sadě JevBench (tento benchmark pochopitleně nepředstavuje přímé srovnání s modelem Jev). Zdrojové kódy jsou k dispozici na GitHubu pod licencí Apache-2.0, váhy modelu na Hugging Face.
Kategorie: GNU/Linux & BSD

Zemřela softwarová inženýrka Margaret Hamiltonová

AbcLinuxu [zprávičky] - 8 Říjen, 2026 - 16:30
Ve věku 90 let zemřela americká softwarová inženýrka Margaret Hamiltonová, která vedla tým, jenž vyvíjel letový software pro program Apollo amerického Národního úřadu pro letectví a vesmír (NASA).
Kategorie: GNU/Linux & BSD
Syndikovat obsah