Agregátor RSS
Samsungu se sice podařilo vyžehlit situaci ve výrobě pamětí, kde nespokojení zaměstnanci hrozili stávkou, pokud nedostanou víc z vysokých firemních zisků. Vyvolalo to ale nespokojenost ve výrobě čipů…
Who needs expensive frontier models to find software vulns? Cisco has just released two open-weight models that specialize in finding known bugs in existing codebases. The models, Antares-350M and Antares-1B, are part of Cisco’s new Antares family of security small language models (SLMs), and are now available on Hugging Face - but only to vetted users. “We’re making sure we’re gating that and appropriately granting access,” DJ Sampath, Cisco's senior vice president and general manager of AI software and platform, told The Register. The company is working with academic and nonprofit organizations, as well as smaller and public organizations’ security teams, to ensure they have access to the vulnerability-hunting models. Plus, because both are small models designed to run locally, “you also need the keys to the source code” to scan for and find vulnerabilities, Sampath said. “This means an attacker is going to be able to exploit an endpoint or a service that you have.” It also means that proprietary code never leaves the organization’s machines, compared to cloud-based LLMs that send code to the AI providers’ external servers for processing and analysis. This enables security analysis in environments with strict privacy or compliance requirements, according to the networking and security giant. And yes, it's named after the massive red super-giant star. “It's almost 1,000 times bigger than the sun, even though the sun dominates the sky, and that is the analogy that we're using here for vulnerability detection and localization,” Cisco VP and chief AI scientist Amin Karbasi told The Register. “The impact of vulnerabilities in your codebase is huge, but it might be only a single file or a few lines of code in a million lines of code.” A future, 3-billion-parameter model in the Antares family won’t be released to the public, Karbasi added. “We are completely gating the 3B model to make sure that we responsibly release it to communities that need it,” he said. Small yet mighty Cisco claims that its models perform as well as or better than dozens of larger models in its new benchmark test that measures how efficiently AI models identify security flaws in codebases. Antares-1B outperforms Google’s Gemini 3 Pro and is comparable to Z.ai's GLM-5.2, we’re told, while the yet-to-be-released Antares-3B does a better job at finding vulnerabilities than GLM-5.2 and OpenAI’s GPT-5.5. Plus, we’re told that the small models scan code much faster and at a fraction of the cost of larger, token-gobbling AI systems. “If you look at the performance, in terms of the time it takes to finish 500 repositories, Antares finishes the entire cohort of repositories in 15 minutes, whereas frontier models take five hours,” Karbasi said, adding that this translates to significantly less cost. “It takes like less than $1 whereas frontier models are above $100 into $150 of cost,” he added. The difference, Karbasi explained, is that Cisco took a “fundamentally different approach” to building Antares. “These models have been trained in a very different way,” he said. “Antares is inherently not a chatbot. It is an investigator. It is a search engine. It has to find a very specific thing that might be a needle in a haystack, and it goes and finds that.” This required training the model on several different ways to search for vulnerabilities “because one way of search may not actually be fruitful, then it has to change its strategy, do it another way, and then do it another way,” Karbasi said. “Because it is very nimble and it’s very small, it can actually do a lot of search at the same time, which is very different from bigger models.” Karbasi likened it to a bicycle on a busy London street: “You can go much faster than the biggest truck.” Or, to use Sampath’s favorite analogy for the benefits of using a small, security-focused model to find bugs in code: “Sometimes you don't need a private jet to go to a corner store, right?”®
Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched. [...]
AI models will do just about anything to complete the task you ask, including cheating to get there, according to new cybersecurity evaluations from the UK government's AI Security Institute (AISI). The group found that leading models often take shortcuts to achieve a particular result and then misrepresent how they obtained that result. And they won't always admit it when asked. "Every model we have tested for this behaviour attempted to cheat," AISI said in a blog post on Tuesday. "Models did not reliably report this behaviour when asked, and often did not reason about it in their chain-of-thought, suggesting that detecting cheating will likely require robust monitoring methods." Infractions included searching the internet for the answer, bypassing sandbox network restrictions, probing the evaluation harness, attacking a system other than the target, and guessing an answer. Cheating in this manner – employing a workaround or gaming a reward function to score better on a benchmark test, for example – has been widely documented by machine learning researchers. It doesn't necessarily imply malicious intent, AISI said, but it's nonetheless troublesome because it can produce misleading assessments of model capabilities. When AISI conducted evaluated five leading models, it found that all of them cheated. The results were as follows: GPT-5.4 cheated 67 times in 475 test runs (14.1 percent). GPT-5.5 cheated 54 times in 475 test runs (11.4 percent). GPT-5.6-Sol cheated 60 times in 475 test runs (12.6 percent). Claude 4.7 Opus cheated 43 times in 475 test runs (9.1 percent). Claude Mythos Preview cheated 37 times in 475 test runs (7.8 percent). Asking models whether they cheated or did anything wrong proved an unreliable auditing mechanism because the models didn't always admit wrongdoing. "In our experiments, models did not consistently acknowledge attempted cheating when asked, and described it as wrong less than 50 percent of the time," said AISI. Existing vetting methods, such as self-reporting and chain-of-thought logs, proved similarly dicey because models don't always report their chain-of-thought. And there were instances where a model would consider whether a proposed action amounted to cheating and then decided to take the action anyway. Given the absence of reliable model cheating detection methods, AISI warns that its current approach – manual review coupled with LLM monitoring – may not be sufficient to catch deception, particularly as models become more sophisticated. "A more fundamental fix would be to train the models not to cheat in the first place – but given this kind of behaviour was reported in frontier models more than a year ago, robustly aligning it away may not be easy," AISI concludes. ®
The Anubis ransomware gang has claimed responsibility for the cyberattack on Coca-Cola's Fairlife dairy subsidiary, threatening to publish allegedly stolen corporate data unless the company pays a ransom. [...]
Apple has moved to address a security flaw in its Hide My Email service that enabled users' real email addresses to be unmasked, effectively undermining the feature's privacy guarantees.
404 Media reported Tuesday that a fix for the issue was deployed by Apple on July 3, 2026, after more than a year, when it was disclosed to the company by Tyler Murphy, co-founder of EasyOptOuts.
Hide My Email
Apple has moved to address a security flaw in its Hide My Email service that enabled users' real email addresses to be unmasked, effectively undermining the feature's privacy guarantees.
404 Media reported Tuesday that a fix for the issue was deployed by Apple on July 3, 2026, after more than a year, when it was disclosed to the company by Tyler Murphy, co-founder of EasyOptOuts.
Hide My EmailRavie Lakshmananhttp://www.blogger.com/profile/ [email protected]
A US federal court has approved Anthropic’s $1.5 billion settlement in a class-action lawsuit in which authors accused the AI company of using their books without permission to train the AI model Claude. This is the largest such settlement to date in a US copyright case, according to Reuters.
The dispute is one of several legal cases in which copyright holders sued AI companies over how large language models (LLMs) were trained, and it is the first major AI-related copyright dispute in the US to be resolved through a settlement.
A judge had previously ruled that the actual training of AI models using books falls under the “fair use” doctrine in US copyright law. But Anthropic was found to have violated the law by storing more than 7 million pirated books in a central library, regardless of whether they were later used for AI training or not.
Byl vydán Mozilla Firefox 153.0. Přehled novinek v poznámkách k vydání a poznámkách k vydání pro vývojáře. Řešeny jsou rovněž bezpečnostní chyby. Nový Firefox 153 bude brzy k dispozici také na Flathubu a Snapcraftu.
Hackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent webshells and install malicious plugins on affected servers. [...]
As Apple gears up to anoint John Ternus the new company CEO in September (while current leader Tim Cook takes a seat on the board) the company appears to be firing on all cylinders ahead of the leadership transition.
What’s going well
Just look at the evidence:
- Apple is building market share across its entire product range; even memory-driven price inflation doesn’t seem to have dampened demand for its hardware yet.
- While Apple had to raise prices, the company’s MacBook Neo remains seriously popular. It’s sitting atop Amazon’s US best-selling chart, which currently includes six Macs in the top 10. The Neo has topped this chart since its introduction.
- Apple’s iPhone 17 series continues to sell well, with recent market data showing sustained growth. Both Counterpoint and IDC tell us that iPhone shipments continue to increase, even as other vendor shipments slide.
- IDC analyst Francisco Jeronimo recently estimated that Apple’s upcoming foldable iPhone Ultra could grab 29.4% of global folding smartphone sales this year, rising to 34.9% in 2027.
- The company’s new 27 series of operating systems is attracting a great response as beta testers report that it is already solid, stable, and performing well.
- The AI narrative has really changed, with analysts no longer quite so starry-eyed at the prospects for the big frontier AI firms. Apple’s edge-AI-enabling approach is winning converts.
What’s coming up
The company’s newly-filed lawsuit against OpenAI may or may not succeed, but it will certainly help consolidate recognition of the importance of Apple’s designs and intellectual property in whatever hardware emerges from the AI firm. It also means both Apple and OpenAI are already competing in hardware, even though neither company yet offers anything that directly challenges the other.
Apple has just set out its stall to brand-loyal fans in a big way and did so before OpenAI gets to woo the same set of customers with a wriggle of its Jony Ive-tinged talisman.
The stage is set for intense competition between the two. Though some say Apple’s needs to improve employee retention, if it does find proof of efforts to use recruitment to engage in industrial espionage, it’ll be easier to represent its own products as being the OG for new hardware.
If nothing else, it means consumers will forever be asking, “If OpenAI’s designers are so good, why did it need to poach them from Apple?” Doubt is a weapon.
Managing perception
It doesn’t matter how the case goes, because there fight is already affecting consumer psychology. It also means that as Ternus prepares to take his seat atop the rainbow-colored Apple throne, we can already size him up. “A man is measured by his enemies,” Joe Abercrombie wrote in “The Trouble With Peace.”
Given the proximity of the leadership transition, it’s highly probable that Ternus signed-off on the litigation; in doing so he — and Apple — tell us to expect more of the same.
Apple has, rightly or wrongly, decided that OpenAI will become its new existential bugbear, following in the footsteps of Microsoft Windows, Real Networks, Adobe Flash, Android, and Samsung, all of whom have been useful foils against which Apple has been able to build and maintain its identity.
Looking at that list, you’d be tempted to believe that nothing much is new. Apple has often defined itself by the enemies it sometimes keeps. What has been will be again, which in this case means even as OpenAI attempts to carve out an identity as a hardware manufacturer delivering solutions to compete with Apple and Google, Ternus’ team’s looks to drive a consensus-shaped wedge into the pro-LLM propaganda.
That blow comes as Apple finally gets its act together around AI, and as the company prepares for a future in which the world’s most-used wearable device also becomes the wearable way to woo Siri AI.
My kingdom come
Rising market share, powerful solutions, an increasingly recognized and respected approach to AI, and an ideological crusade — these details constitute Apple’s place today and are Tim Cook’s coronation gift to Ternus. He’s passing along a strong and hyper-profitable baton that screams of timeliness and relevance even as the company gets set, ready, to go with a year or two of new product designs, new product families, and a 20thanniversary iPhone.
This is Apple’s party. OpenAI’s name didn’t make the list.
You can follow me on social media! Join me on BlueSky, LinkedIn, Mastodon and subscribe to The Core.
German authorities say they have neutralized the main infrastructure supporting the Kratos phishing-as-a-service (PhaaS) kit following an operation supported by the US and Indonesia. Officers from Frankfurt am Main's Central Office for Combating Internet Crime (ZIT) and the Federal Criminal Police (BKA) described Kratos as one of the most widespread and dangerous PhaaS kits on the market. In Indonesia, authorities said they arrested the Kratos kit's alleged "developer and technical administrator." The announcement of Kratos's takedown did not mention whether any other individuals are being pursued. According to the ZIT and BKA, Kratos allowed low-skill cybercrims to harvest credentials, including passwords and session cookies, to bypass MFA by providing them with convincing Microsoft-themed phishing pages. Criminals using Kratos phishing pages targeted hundreds of thousands of victims across more than 30 countries, while the operation behind the kit allegedly earned more than €300,000 ($342,000) since 2024. More than 1,800 criminal enterprises are estimated to have used Kratos, which was responsible for around 15,000 phishing campaigns per month. "Each individual campaign had the potential to harm several thousand recipients worldwide," the German authorities said in a statement. The operation neutralized more than 200 servers, according to the ZIT and BKA, although the latter declined to explain how. Methods used in previous takedowns included handing legal warrants to infrastructure providers, such as Kratos's chosen hosting company, and working with ISPs to null-route or sinkhole traffic associated with suspect IP addresses. Dr Benjamin Krause, head of the ZIT at the Frankfurt am Main Public Prosecutor's Office, said, "Our approach of disruptive law enforcement works: In addition to the primary task of identifying and prosecuting the accused, we have once again succeeded in dismantling a criminal online service and thus contributing to greater cybersecurity." Carsten Meywirth, head of the cybercrime department at the BKA, added: "Anyone who steals login credentials online using fake websites shouldn't feel safe. The success against the Kratos phishing kit shows that even highly professional phishing infrastructures can be effectively combated. "This is pioneering work and a clear signal to other cyber actors – phishing will not go unpunished and will be consistently fought by the BKA." Many names, same focus German authorities referred to the PhaaS kit only as Kratos, although open source reporting has tied it to products previously sold under names such as SneakyLog and Sneaky 2FA. Similarly, the ZIT and BKA mentioned only fake Microsoft authentication pages among the templates offered by Kratos. Microsoft, meanwhile, reported earlier this year that SneakyLog had been used to generate phishing campaigns targeting US citizens with fake W-2 tax forms. As recently as July 16, security shops such as Heal Security reported that Kratos offered customers lures themed around various websites, including SharePoint, OneDrive, Microsoft Forms, Canva, Tilda, and more. KnowBe4 added Adobe lures to that list with its own investigation in February, which also raised uncertainty about when the kit first hit the market. Microsoft, which said Kratos was also known as SneakyLog, believes the latter entered the phishing kit market as of early 2025, although KnowBe4 said the first signs of Kratos only emerged in January 2026. Muddying the picture further, KnowBe4 did not mention SneakyLog or Sneaky 2FA as part of Kratos's past. The security shop said instead that it evolved from a previous life as a family of commercial trojans and infostealers. One thing that most open source reports agree on, however, is that the targets of the phishing kit's customers are based primarily in the US and Europe. Microsoft identified manufacturing, retail, and healthcare as the main target industries in the US, while in Europe, industrial organizations, law firms, polytechnic institutions, schools, SMBs, and others have all been attacked, according to ANY.RUN. ®
Hidden text on a web page was enough to make Kiro, AWS's agentic coding IDE, rewrite its own configuration file and run an attacker's code on a developer's machine, with no approval step able to stop it.
Intezer, in research with Kodem Security, found that a request as ordinary as asking Kiro to summarize a page could end in remote code execution. AWS has patched the issue, and no CVE has been
Hidden text on a web page was enough to make Kiro, AWS's agentic coding IDE, rewrite its own configuration file and run an attacker's code on a developer's machine, with no approval step able to stop it.
Intezer, in research with Kodem Security, found that a request as ordinary as asking Kiro to summarize a page could end in remote code execution. AWS has patched the issue and says it is Swati Khandelwalhttp://www.blogger.com/profile/ [email protected]
GNOME is officially shortening its standard vulnerability disclosure window from 90 days to 30 days, a change that impacts upstream maintainers, downstream Linux distributions, and system administrators in how they handle software vulnerabilities. The policy shift, announced by long-time security coordinator Michael Catanzaro, addresses modern software patching realities and a growing influx of automated submissions.
The company behind the disk space analyzer TreeSize has irked some users by no longer offering support or updates for perpetual licenses beyond their maintenance period unless customers subscribe. Further frustration has come from JAM Software's long-standing policy of not providing license keys or installers to TreeSize perpetual license holders after that support period ends.
Since 2025, JAM Software has been transitioning most TreeSize editions to subscription models. Today, it sells perpetual licenses only for personal use, which include 12 months of updates, support, and “downloads of older versions, and your license,” plus the option to extend the support period. TreeSize currently has "no plans to discontinue the sale of perpetual licenses for TreeSize Personal," product manager Hendrik Christ told Ars Technica.
As perpetual-license maintenance periods expire, customers are discovering that extending support now generally requires subscribing to software they already own the right to use. Read full article
Comments
Imagine logging into a production Linux server for routine maintenance and noticing background network activity connecting to an unfamiliar external IP address. Your endpoint protection agent is not popping up with an alert, there is no service failure, and on the surface, the system appears to be running normally.
Google's DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.5 Flash that's designed to discover, validate, and patch vulnerabilities quickly and efficiently.
According to the tech giant, the model will be exclusively available to governments and trusted partners via CodeMender as part of a limited-access pilot
|