Agregátor RSS

The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In

Bleeping Computer - 12 Srpen, 2026 - 16:01
Fake remote workers can exploit gaps between hiring checks, device delivery, and account access to enter organizations under false identities. Specops Software explains how document verification and biometric liveness checks can help organizations confirm that the person receiving access is the legitimate new hire. [...]
Kategorie: Hacking & Security

Sonda Escapade pořídila snímek Země a Měsíce. Je netradiční, ale ne první ze vzdálených končin Sluneční soustavy

Živě.cz - 12 Srpen, 2026 - 15:45
Sonda Escapade pořídila netradiční snímek noční Země v infračerveném tepelném záření • Fotografií Země ze vzdálenějších končin Sluneční soustavy bylo díky sondám pořízeno více
Kategorie: IT News

Exposed: Woeful security at UK criminal records office that led to sensitive data leak

The Register - Anti-Virus - 12 Srpen, 2026 - 15:40
The UK's criminal records office, ACRO, has escaped a fine and received a regulatory reprimand after security failings potentially exposed highly sensitive data belonging to nearly 11,000 people. ACRO disclosed the "cybersecurity incident" in April 2023, and said at the time that it had no evidence to suggest that any data was compromised. However, it has now emerged that attackers maintained persistent access to ACRO's website and content management system for more than seven months, and staged sensitive data for possible exfiltration. According to the Information Commissioner's Office (ICO), which reprimanded ACRO rather than imposing a financial penalty, the breach was uncovered in March 2023 only because ACRO was investigating a separate intrusion. The watchdog said that while investigating an SQL injection attack that compromised 15 sets of credentials, most belonging to ACRO staff, investigators found evidence of separate intrusions dating back to July 8, 2021. The incidents fell into three categories, the ICO said. Some did not affect personal data, while others exposed only a small number of account credentials. The most serious involved ACRO's website and its Kentico content management system. The intrusion began on August 5, 2022, and the attackers maintained persistent access, without being detected, until March 14, 2023. The ICO found that ACRO ran version 12.0.0 of Kentico CMS from September 2019 until March 2023 without applying the patches and hotfixes released during that period, leaving known vulnerabilities unresolved. The ICO blamed poor communication between ACRO and its managed service provider. The supplier did not learn that patching was its responsibility until February 2020 and continued to assume that it was not required to monitor actively for security updates. "The ambiguity around who was accountable for identifying necessary Kentico CMS patches created a gap where patches and hotfixes were missed, which ultimately left ACRO's website vulnerable," the ICO said. Further, ACRO did not have a documented policy that covered patching Kentico CMS, nor could it demonstrate how vulnerabilities were identified or prioritized. ACRO's Trend Micro antivirus generated alerts, but nobody appears to have been minding them. The records office told the ICO that, for reasons redacted from the postmortem, it was "unable to establish what business processes existed for the assessment or handling of security alerts at the relevant time." It also could not identify which roles were responsible for reviewing these alerts at the time, ultimately resulting in them going unread. ACRO's poor logging means that, despite an extensive investigation by a third-party cybersecurity outfit, it remains impossible to determine whether the affected data was exfiltrated. Investigators did establish that the attackers staged the data for possible exfiltration between February 15 and 16, 2023. The potentially exposed material included: Police Certificate Applications Subject Access Request (SAR) forms and International Child Protection Certificate forms Names Dates of birth Addresses National Insurance numbers Passport and driving licence details Bank account information Biometric data Highly sensitive criminal offence and special category information ACRO notified 84,048 people of the breach, although investigators later determined that data relating to no more than 10,920 individuals had potentially been staged for exfiltration. Of these, ACRO received 35 formal complaints citing personal distress and concern about the risk of identity theft and financial loss, according to the ICO's reprimand document [PDF]. "Complainants included those connected to Police Certificates, International Child Protection Certificates, and victims of domestic violence." The ICO also received six complaints citing similar concerns. ACRO's saving grace was its network segmentation, which prevented the attackers from straying beyond the CMS into other systems, the ICO noted. Since the attack was discovered, ACRO has made a number of improvements to its security, including decommissioning the compromised infrastructure (although not until June 2023), implementing a SIEM, improving visibility, monitoring, and network segmentation, hardening systems, and migrating to Salesforce Experience Cloud. Jonathan Balmforth, group manager of civil and cyber investigations at the ICO, said: "This case highlights how basic cyber security failings can create significant risks for thousands of people, particularly where organizations process large volumes of highly sensitive personal information. "Organizations must ensure there is clear accountability for identifying, assessing and applying security updates. They must also have effective monitoring in place so that warning signs of cyberattacks are identified, investigated and acted upon promptly. "The lessons from this incident are clear. Having the right policies, responsibilities and oversight arrangements in place is just as important as having the right technology. "We welcome the improvements ACRO has made since these incidents. We hope other organizations will use this case as an opportunity to review their own processes and responses to ensure personal information remains properly protected." ACRO welcomed the reprimand from the ICO and highlighted the steps it has taken since to bolster its security. A spokesperson told The Register: "Since the cybersecurity incident was identified in March 2023, we have worked hard to strengthen our systems and safeguards. "In particular, we immediately took the previous website offline and subsequently decommissioned it. We also took steps to protect customers, including making sure anyone potentially affected was informed at the earliest possible stage." They went on to say: "We accept the ICO's findings of the infringements. We are grateful for the recognition from the Information Commissioner of the multiple remedial steps ACRO has taken in light of this incident and are committed to maintaining high standards of data protection and information security in future." ®
Kategorie: Viry a Červi

Akira ransomware scum blocked victim's security tools – and broke their own encryptor

The Register - Anti-Virus - 12 Srpen, 2026 - 15:00
An Akira ransomware affiliate rebooted a victim’s computer into Safe Mode to kill its security tools – and in the process sabotaged their own malware when the limited-function startup mode also broke their encryptor. “Akira's encryptor is engineered for speed, relying on concurrent worker threads and heavy memory mapping rather than simple sequential read-and-write operations. That high-performance design is likely what caused it to break in Safe Mode,” Huntress security operations analyst James Northey told The Register. “Safe Mode loads a minimal driver set, which can restrict storage controllers and pagefile availability,” he added. “A heavy, multi-threaded encryptor strains that constrained environment far more than the lighter, streamed-I/O designs used by other ransomware families.” But the ending wasn't entirely happy for the victim. The attacker had already stolen credentials and data from file shares before Safe Mode prevented the ransomware from doing its job. Northey detailed the incident in a Wednesday blog and cautioned that this was more likely a memory-configuration issue, and shouldn't be taken as a practical defense to prevent Akira ransomware from locking up valuable files. “Ultimately this could be a case of winning the battle, but not the war,” Northey wrote. “It’s possible that a host with more physical memory or a larger page file might give akira.exe enough virtual memory to encrypt the endpoint in Safe Mode,” Northey added. “Akira’s developers or affiliates could retool the encryptor to reduce its memory demands or make its Safe Mode launch sequence more reliable, meaning that the same failure may not occur in a future intrusion.” Nonetheless, there's one big lesson here: For the love of all that is holy, turn on multi-factor authentication (MFA). Here’s a closer look at what happened, and how to prevent it from happening to you. How it started… In early August, Huntress responded to an incident that began, as most Akira intrusions do, with a SonicWall SSL VPN. On August 4, the VPN logged a credential-spray attack: a burst of failed logins using bad credentials that it denied. But then, seven minutes later, one of them succeeded when the attacker used a valid VPN account that wasn’t protected by MFA. Once they had gained access, the criminal accessed the domain controller via Remote Desktop Protocol (RDP) and queried Active Directory to hoover up detailed information about the network, users, groups, computers – essentially everything an attacker needs to know about who and what to target for lateral movement and mass encryption in a ransomware attack. “The enumeration was a full-property dump of every user and every computer in the domain,” Northey wrote. The Akira ransomware affiliate then moved to the application server to start collecting stolen data, downloading WinRAR and using that tool to archive mapped file shares before sending the stolen data to cloud storage using s5cmd, a fast S3 transfer utility. They also installed remote desktop software AnyDesk, configured to start with Windows, and abused this legitimate tool as a remote-access trojan, giving the attacker hands-on keyboard control. They also used it as a command-and-control channel to drop more malware, including the very cleverly named akira.exe ransomware binary – because no one would guess what that executable could be, right? Then came the Safe Mode reboot Here’s where things went sideways for the ransomware scumbag. About three hours into the intrusion, the attacker forced the computer to reboot into Safe Mode with Networking, a boot mode that only loads essential drivers and services, blocking most third-party software. Attackers, especially ransomware gangs, do this to disable endpoint detection and response products and other security tools that would otherwise detect and stop their malware from infecting victims’ machines. While some ransomware crews, including Snatch and AvosLocker, have abused Safe Mode for this purpose for years, Huntress has never seen Akira do it until now. In this case, the reboot stopped the Huntress agent and disabled Microsoft Defender's real-time protection, preventing Defender from quarantining the malicious file. “The attacker got their blind window,” Northey wrote. “What they didn't get was a clean detonation.” Thirteen seconds after the reboot, the computer started spewing memory errors. Safe Mode boots with constrained virtual memory, and it didn’t have sufficient memory to encrypt the endpoint. Essentially, Safe Mode not only acted as an EDR killer, but also borked the ransomware. In addition to the obvious recommendations – like make sure you receive alerts on bursts of failed VPN logins against multiple usernames from one source, and require MFA on every VPN account – Huntress suggests organizations keep an eye out for this Safe Mode play. Specifically, “alert on boot-configuration changes and Safe Mode boots: msconfig.exe / bcdedit activity, Kernel-Boot EID 27 with a SAFEBOOT load option, Kernel-General EID 12 BootMode=2, and third-party security services stopping (System EID 7036),” Northey wrote. Also, “watch for tooling being added to the Safe Mode minimal-service registry list.” ®
Kategorie: Viry a Červi

Posuňte práci s AI na vyšší level. Ukážeme, jak vytvořit vlastní Gem či GPT a k čemu je to dobré

Živě.cz - 12 Srpen, 2026 - 14:45
Neopakujte umělé inteligenci stále stejné pokyny. Vytvořte si vlastního asistenta, který bude pracovat podle vašich pravidel.
Kategorie: IT News

Hackers leverage new Microsoft SharePoint exploit in attacks

Bleeping Computer - 12 Srpen, 2026 - 14:25
Hackers have already begun using a proof-of-concept (PoC) exploit for a critical Microsoft SharePoint vulnerability, published by cybersecurity company Rapid7 on Tuesday. [...]
Kategorie: Hacking & Security

Bezpečnostní chyby v produktech od Intelu – 08/2026. Mikrokód 20260811

AbcLinuxu [zprávičky] - 12 Srpen, 2026 - 14:23
Intel vydal 42 upozornění na bezpečnostní chyby ve svých produktech. Současně vydal verzi 20260811 mikrokódů pro své procesory.
Kategorie: GNU/Linux & BSD

Apple’s response to RAM-ageddon? Lease, downgrade, refurbish, repair

Computerworld.com [Hacking News] - 12 Srpen, 2026 - 14:07

Apple is in the process of tweaking its business models to cope with the unyielding memory price and availability crisis. Its response is now emerging across multiple fronts.

Finance or lease

The company’s recently-introduced Apple Upgrade scheme in partnership with Klarna is a smart response to the reality that as devices inevitably become more expensive, consumers will shift from outright ownership to flexible lease and financing arrangements. With its partnership, Apple continues to generate revenue while also maximizing the likelihood customers will return the product at EOL, more about which later.

Samsung and Google have introduced similar schemes. “Financing models already dominant in India and Africa are now poised to reshape the US and European markets,” said CCS Insight in a presentation exploring the consequences of the memory shortage.

Downgrade

Apple has seen a lot of success with the iPhone 17 this year. That success wasn’t entirely because it’s such a good smartphone; it also reflects consumers making the decision to purchase lower-specced devices to stay within budget. Apple continues to see strong sales of its Pro range, which represents the power of its reach into more affluent consumer groups. It’s also important to note that at the moment, the iPhone 16e is the biggest-selling device on the US pre-paid market.

People still want the best, but are being more cautious in how they acquire it.

Refurbished

The trade in refurbished devices is fundamentally built on two things: A large installed base of originally-sold devices resilient enough to be refurbished in the first place and buy-back deals attractive enough to encourage consumers to trade those devices in at all. That’s why it matters that Apple recently increased the value of its trade-in scheme: you’ll get up to $480 for an iPhone 16 or up to $720 for an iPhone 16 Pro Max under Apple’s new deal. It’s also important because Apple has its own growing refurbished business in Apple Refurb, and also because devices that really have reached end-of-life can be broken up for parts, taking a little pain out of Apple’s ongoing component crisis.

In 2024, Apple shifted 15.9 million refurbished devices and accessories.

Delay and Repair

As prices rise, consumers will keep their devices longer and are far more willing to repair existing hardware than upgrade. It’s well-known that iPhones are the most durable smartphones and ship with extensive future system support, so these devices can be successfully used for five years — sometimes more. Apple offers its own service and support package to keep your devices in good shape, and its recent decision to extend AppleCare One support to new nations reflects consumer sentiment. Those who want Apple’s trusted support for up to three devices can now get it for just a few dollars each month.

Not just about iPhones

All these initiatives are important in their own right, of course, and while I’ve focused on iPhone here, Apple is implementing these changes and services across all its product lines. It knows that in the face of AI-flation, consumer habits will change. Demand for new devices — assuming Apple can even get enough components to make them — will fall. “Demand for refurbished models and financing will grow — fast,” said CCS.

The other transformation concerns price. The hyperinflation driven by decisions made by the effective cartel of the big three memory vendors (who could have continued to support the consumer memory industry while providing less support for data centers) is driving low-tier smartphone manufacturers to exit markets or raise prices. CCS expects smartphone prices to increase by 25%. Counterpoint says DRAM prices have risen 70% since 2025, while Gartner and others expect price inflation to remain into next year.

As Intel’s CEO said, “There’s no relief until 2028.”

Price increases leave a huge gap in the sub-$500 device market; that’s a vacuum the second-user market in refurbished smartphones will fill. As the value of that tier increases, it becomes a more strategically important market for both Apple and Samsung, who make the vast majority of smartphones. For both vendors, ongoing market changes mean the second-user market is becoming a primary channel for both companies; you can expect continued business pivots from both as they seek to capture business revenue.

Incoming structural challenges

Even there, there’s a structural challenge to overcome. That is that as memory prices surge, sales of new devices decline. Down the road, there will be fewer devices to trade in, meaning the supply of used devices will fall, creating a future supply-and-demand imbalance in the second-user market. I predict this could get quite bitter, with manufacturers grabbing larger chunks of available devices to the detriment of the small renew-and-refurbish retailers. CCS Insight expects the market for second-user smartphones to grow by 9% in 2026 as cost-and-supply challenges bite.

Making the circle

There is opportunity within the chaos. Apple has committed to building a circular manufacturing ecosystem by 2030, which is only four years away. 

We don’t know how far along the company is on that road, or the extent to which changing market conditions have undermined its attempt to reach that goal. But the company will have spent time developing new manufacturing and production processes to enable more extensive use of recycled and renewable raw materials in that attempt.

The signs are positive — the recently introduced MacBook Neo has a 90% recycled aluminium enclosure and 100% recycled cobalt battery. 

Distorted loop

There is a reality in which any slowdown in new device manufacturing — or, indeed, the cadence of new device introductions — gives Apple and its partners a little breathing space in which to develop and deploy new manufacturing process technologies. 

In that narrative, it does perhaps matter that under its new iPhone release schedule, there will be an 18-month gap between the launch of the best-selling iPhone 17 and the spring 2027 release of the iPhone 18. With a 20th anniversary iPhone and new iPhone Ultra range, along with some talk of a future flip phone, Apple may soon be in position to maintain the marketing buzz with new iPhones every six months while actually crafting an 18-month wait between major device improvements.

Doing so will likely reduce initial unit shipments while also flattening sales revenue for more predictable income. It also builds in extra time to retool the production lines for each device family.

Leading with the new

When it comes to the deployment of new circular manufacturing tech, that potential 18-month gap buys that most precious of resources, time. Which means that while memory price inflation has caused huge problems, raised prices and forced Apple to change business practices, it could also give the company an opportunity to introduce one of the most profound changes in manufacturing of the 21st Century: circular manufacturing. To some extent, this transition in the nature of Apple’s business is reflected at board level, as the company is itself transitioning to new leadership under incoming CEO John Ternus.

You can follow me on social media! Join me on BlueSky, LinkedIn, Mastodon and subscribe to The Core to keep pace with daily Apple news in one email.

Kategorie: Hacking & Security

OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning

The Hacker News - 12 Srpen, 2026 - 13:47
A newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API calls let researchers recover internal reasoning and secrets from session logs, including API keys and passwords. The weakness affected encrypted reasoning objects used by the providers' reasoning APIs, where a block created in one session could be replayed into another and, during testing, Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Enterprise Defenses Recovered at the Edge and Collapsed Inside

The Hacker News - 12 Srpen, 2026 - 13:41
Enterprise defenses are tuned to catch the attacks that make noise. This year's data shows attackers winning by making none. According to Picus Labs' new Blue Report 2026, which measured more than 338 million real attack simulations across actual client production environments in the first half of 2026, defenses are having one of their strongest years yet. Average prevention effectiveness [email protected]
Kategorie: Hacking & Security

Signal adds new security feature to thwart man-in-the-middle attacks

Bleeping Computer - 12 Srpen, 2026 - 13:21
​Signal has introduced Automatic Key Verification, a new security feature that gives users a new way to ensure their encrypted chats haven't been intercepted. [...]
Kategorie: Hacking & Security

Brit rail cops bring live facial recognition to the London Underground

The Register - Anti-Virus - 12 Srpen, 2026 - 13:19
British Transport Police is expanding its trial of live facial recognition (LFR) to the London Underground, despite concerns about privacy and mistaken identification. The force, which polices railways across England, Scotland, and Wales, will begin its Tube deployments at Victoria Underground station. The cameras will then rotate between Underground and Network Rail stations until the trial ends in November. The trial began at London Bridge railway station in February and is intended to assess how the technology performs in a railway setting. It follows deployments by the Metropolitan Police, which says it will start using face-scanning cameras in London's West End and Soho by the end of this year after a six-month pilot in the south London borough of Croydon. Live facial recognition scans faces within a camera's field of view and compares them with a police watchlist. A possible match generates an alert that an officer must review before deciding whether further action is warranted. According to the railway bobbies, the technology deployed relies on the NEC NeoFace M40 algorithm, which appears to be the same across several forces. "Expanding deployments into London Underground stations will help us assess the technology in a different transport environment while continuing to refine how it is used across the railway network," said the officer responsible for the project, chief superintendent Chris Casey. Critics describe the technology as dystopian and intrusive, and errors have already resulted in innocent people being mistaken for criminals and detained. Members of ethnic minorities appear to be more at risk of being mistaken for someone else by facial algorithms. "This is a disturbing and dystopian expansion of live facial recognition that will capture millions of innocent people's faces. Far from reserving this for exceptional cases, British police are now using live facial recognition routinely in the sort of pervasive way you might expect in China, but not in a democracy," says Silkie Carlo, director of civil liberties group Big Brother Watch. The London Underground network is estimated to handle more than 3.7 million passenger journeys a day on weekdays. A recent Opinium survey of 2,000 UK adults, commissioned by facial recognition biz Face Int, found that 69 percent believed the public should have a say in how the technology is used. It also found that 61 percent worried errors could get people into trouble for things they had not done, while 57 percent were concerned about how facial images were stored. Britain's railway fuzz says images of anyone who does not match the authorized watchlist are deleted immediately and permanently. Whether that remains the policy in future is another matter, of course. We asked the British Transport Police to comment regarding public concerns about the use of facial recognition technology. A spokesperson for the force referred to us to the comments made in the announcement by chief superintendent Casey, who said: "Our focus remains on protecting the public, preventing crime and bringing offenders to justice, while ensuring the technology is used lawfully, proportionately and transparently." ®
Kategorie: Viry a Červi

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

The Hacker News - 12 Srpen, 2026 - 13:13
Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation. The most severe of the flaws are listed below - CVE-2026-48362 (CVSS score: 10.0) - An operating system command injection vulnerability in ColdFusion that couldRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

AI policies work better when employees help write them

Computerworld.com [Hacking News] - 12 Srpen, 2026 - 13:00

It’s likely that many enterprises have created — or are at least considering — AI policies that clearly lay out approved AI tools and their uses, set up training programs for employees to help them use the tools in their jobs, and establish guardrails around those systems to avoid issues such as security vulnerabilities and data bias.

But how many of these policies have received the blessing of employees? It’s a key question, because many workers are highly wary of AI.

They worry that it will cost them their jobs, either by taking over their work or because companies will cut jobs and use the savings to fund investments in AI research and infrastructure. They worry about AI-powered performance tracking software impacting raises and promotions. They worry about AI screening of job applications for future roles.

Even employees who have embraced AI to assist their work have reason to worry. Many say that using generative AI tools saves them time, but the time savings are eroded by “botsitting” — having to check and recheck output, provide missing context, fix errors, and go through multiple iterations before the desired outcome is achieved. They may also have to wade through “workslop,” low-quality genAI output that hasn’t been properly vetted by co-workers.

Additionally, workers say that as AI makes them more productive, their workload keeps increasing. All of this can add up to “prompt fatigue” or “AI brain fry,” mental exhaustion that affects heavy genAI users, particularly when they bounce between multiple AI tools.

AI policies that don’t take these factors into account are apt to be problematic. Employees may even organize to protect themselves from AI in the workplace. Indeed, tech pros are increasingly interested in unionizing, driven in part by the incursion of AI.

It doesn’t have to come to that. Company leaders can proactively work with their employees to develop AI policies that take employee well-being into account. The result might be stronger AI adoption, better business outcomes, and a happier, more productive workforce.

The 2026 Tech Sentiment Report by technology career marketplace Dice found that professionals are generally not resisting AI itself, “but rather, they’re looking for clarity around how it will affect their jobs, careers, and workplace decisions,” says Paul Farnsworth, president of the firm. “The research suggests that employee buy-in comes from making AI feel like something being done with workers rather than to them.”

In many cases, IT management runs the deployment of AI, and this can ultimately result in employees being left out of any decision making.

“When IT leaders drive deployment, they ask questions about integration, security, and capability,” says Amy Loomis, group vice president, Workplace Solutions at IDC. “That is not the same as asking workers how AI could actually improve their day, where they waste time on tasks that add no value, and where a well-designed tool would make a real difference.”

Following are some key steps to building an AI policy everyone can agree on. Bear in mind that any worker protection items should be in addition to the usual corporate governance, risk, and compliance AI policies, not a replacement for them.

Invite input from everyone involved

It might sound obvious but can’t be overstated: the only real way to produce an AI policy that employees will accept is to get their input.

“We started by surveying our employees through SurveyMonkey to see what they were already using and why,” says Monica Washington Rothbaum, COO and senior attorney at law firm J&Y Law. “Then we sat down with every department, and involved operations, IT, HR, and leadership from the beginning. We wanted to understand the opportunities, but we also wanted to understand the risks” of AI.

Most AI policies “fail when they’re created in a conference room and handed down from the top,” Rothbaum says. “The people using these tools every day need to be part of the conversation. That’s why transparency became a major focus for us” in creating an AI policy.

Organizations should include employees in policy development, pilot programs, and feedback processes, Farnsworth says. This is especially important because Dice research found that only 48% of organizations have formal AI policies, while nearly one quarter of professionals surveyed said they’ve used AI without manager approval.

Keep the lines of communication open

Creating an AI policy is not a one-and-done proposition. Organizations need to keep communicating with employees as AI and tools evolve.

“We communicated updates during company all-hands meetings, through email, in Microsoft Teams, and through department-level discussions,” Rothbaum says. “We even designated a member of our marketing team to oversee communications around AI adoption so there was clear ownership and accountability.”

The biggest mistake organizations make is treating AI like standard software, Rothbaum says. “It’s not. It’s an operational change,” she says. “It’s a communication challenge. It’s a governance challenge. The technology itself is often the easy part. The hard part is deciding what data can be used, who has access, how outputs are reviewed, and how the organization remains compliant while the technology continues evolving.”

Address fears about employment

One of the biggest drawbacks to AI adoption, from the standpoint of many employees, is the worry that AI tools will ultimately take away their jobs or many of their responsibilities.

Indeed, this has already been the case at some tech companies. A majority of non-AI technology professionals think AI eliminates more jobs than it creates, according to the Dice report, and three quarters think

junior-level workers are most at risk of displacement.

“Reassurances that no jobs will be lost ring hollow when workers can see
reorganizations happening around them,” Loomis says. “The organizations that sustain worker trust communicate specifically about what is changing, what it means for individual roles, and what the organization is committing to in return.”

One way to get around these concerns is to include provisions in policies that require any decisions around individual workers’ employment to be made by a human. That way no one can be dismissed from their job at the discretion of a machine.

Ensure access to training programs

Another way to gain workers’ support for AI policies is to include provisions about access to ongoing training and educational programs designed to build on their existing knowledge and provide them with valuable new skills.

“Employees are more likely to embrace AI when they see opportunities to grow alongside it,” Farnsworth says. “As AI becomes increasingly embedded in daily work, organizations should invest in AI literacy, upskilling, and career development programs to help employees adapt to changing job requirements.”

And those programs should be codified in AI policies. Guaranteeing workers access to training that evolves with the technology and enterprise workflows “requires treating training as a policy commitment with defined standards, timelines, and completion tracking,” Loomis says.

“Effective AI training does two things: it teaches workers how to use specific tools in the context of their specific roles, and it builds the human skills, judgment, critical thinking, and adaptability that determine whether workers can use AI well rather than just technically. Both are necessary,” she says.


When training is treated as a one-time event rather than a continuous policy commitment, Loomis says, adoption stalls and distrust grows. Ongoing “human skills training is gaining explicit recognition as core to
effective AI use,” she says.

Adopt guardrails against harmful uses of AI

This needs to be a standard component of any AI policy. But the language of proper and improper uses of AI tools and data must be clear for everyone in the workforce.

Such guardrails not only address cybersecurity and regulatory concerns, but can help prevent uses of AI that result in discrimination.

“The organizations that get the most value from AI won’t be the ones that adopt it the fastest,” Rothbaum says. “They’ll be the ones that communicate clearly, train consistently, and build the right guardrails before they need them.”

Confidential, client, firm, or employee information may not be entered into any AI tool unless explicitly authorized and approved, according to the J&Y Law policy.

Emphasize the positives of AI

Policies will of course include restrictions on the use of AI and rules around avoiding risks, but they also need to share how workers can leverage tools to help make their jobs easier or more fulfilling.

“One thing we’ve seen is that effective AI policies aren’t just lists of restrictions,” Farnsworth says. “Instead, they provide employees with clear guidance on how to use AI responsibly and confidently in their work. At Dice, our AI policy encourages employees to use AI when it can improve productivity, while establishing guardrails around data security, confidentiality, and human oversight.”

A good policy will help employees better understand that AI presents not just risks, but opportunities as well.

More on AI in the workplace:
Kategorie: Hacking & Security

Samořídící Tesla FSD se šíří Evropou, Česko volí vyčkávací taktiku

Živě.cz - 12 Srpen, 2026 - 12:45
Od dubna elektromobily značky Tesla samy řídí v Nizozemsku, mezi květnem a červnem schválily asistenční systém Tesla FSD Sepervised také v Litvě, Estonsku, Dánsku a Belgii. Se stanoviskem se ozvalo i české Ministerstvo dopravy a fanoušky zklamal zdrženlivější přístup. Ale naděje se upínaly k 30. ...
Kategorie: IT News

New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges

Bleeping Computer - 12 Srpen, 2026 - 12:15
Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldBreak" after Microsoft released the August 2026 Patch Tuesday security updates. [...]
Kategorie: Hacking & Security

Průmyslové odpadní vody mohou být zdrojem cenných kovů. Nová metoda zvládne i rychlé odstranění soli

Živě.cz - 12 Srpen, 2026 - 11:45
Nový elektrochemický systém dokáže současně odsolovat vodu a vyseparovat kovy • Přesnou změnou napětí na elektrodách získáte zpět velmi čistou měď • Výrobcům klesnou náklady na odpad a získají zpět cenné suroviny
Kategorie: IT News
Syndikovat obsah