Agregátor RSS
Gemini pro Windows je tady. AI od Googlu je zde chudší než na macOS
S půlročním zpožděním oproti verze pro macOS vyšlo Gemini pro Windows. • Může se automaticky spouštět po přihlášení a běží ve svém okně. • Klient nepodporuje sdílení okna s AI.
Kategorie: IT News
TSMC cílí na zdvojnásobení kapacit CoWoS do 2 let
Pomineme-li výrobní procesy (křemík), má TSMC v rukávu i eso v podobě pouzdření CoWoS. Umožňuje vytvářet složitá a velká pouzdra s podporou HBM pamětí a dalších technologií. Jenže nestačí kapacity…
Kategorie: IT News
Jak rozjet IT byznys a neztrácet čas v úředním labyrintu
Jako vývojáři a IT specialisté jste zvyklí věci automatizovat, refaktorovat a zrychlovat. Všechno ve vašem vývojovém stohu běží hladce a bez zbytečného tření.
Kategorie: IT News
Android i iPhone mají speciální funkci proti nevolnosti v autě. Každý na to jde trochu jinak
Google dohnal dvouletý náskok Applu v řešení nevolnosti v autě • Pokud se vám dělá v autě špatně při používání mobilu, nově vám pomůže i Android • Google má lepší možnosti personalizace, Apple zase daleko lepší dostupnost
Kategorie: IT News
Google fixes actively exploited Android zero-day on Pixel devices
Google has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks. [...]
Kategorie: Hacking & Security
Xiaomi 17 Ultra zlevnilo o sedm tisíc. Má skvělý displej, foťáky i výdrž
Xiaomi 17 Ultra teď koupíte za 18 990 Kč, běžně stojí 26 tisíc. • Má obří jasný OLED, nadupaný Snapdragon a rychlou čtečku otisků. • Trojice zadních foťáků patří mezi to nejlepší na trhu.
Kategorie: IT News
Mythos has made 2026 patching hell. It might make 2027 a breeze
When Microsoft delivered over 970 patches last week, many saw a nightmare for beleaguered security staff. Gartner research vice president Craig Lawson thinks infosec workers might soon see sunlit uplands as their workloads ease. Lawson outlined that scenario at Gartner’s IT Symposium in Australia today and explained it by theorising that the increased volume of vulnerability discoveries made possible by Anthropic’s Mythos and other bug-hunting AI might be getting close to finding most of the flaws in established codebases. “We've never had a situation where massive codebases have been audited to that level before,” he told The Register, and offered the recent series of CVEs found in OpenBSD – which has historically been an unusually secure and stable OS – as evidence that AI bug-hunters are cleaning up. “Think about how much technical debt has been retired in products just in the last six months,” he said. Lawson pointed to the fact security vendors, who in theory know what it takes to create secure products, are also using AI to find flaws in their wares. Those discoveries, he suggested, again indicate AI is taking out potential avenues for zero-day attacks. The high number of CVEs reported in 2026 is a positive signal. Lawson thinks Mythos and its ilk may also create an invisible signal as vendors use the AI to detect more bugs in their future releases. He therefore thinks that 2027 might see CVE numbers fall as vendors finish cleaning up old codebases, and because they use AI to more thoroughly test their next releases. “2027 could be the first year we see a net drop, maybe not in aggregate vulnerabilities, but definitely in severity of flaws,” he told The Register. He thinks AI will also make defenders happy by giving them better tools. Today, he said, a red-teaming exercise is an infrequent and costly event that usually involves hiring an external provider. AI bug-hunters could mean organizations can effectively run a red team every day. And if a red team exercise produces tickets that need solving, he thinks AI will help analysts to identify fixes more quickly. “What if I could spend three minutes going to Gemini and saying ‘Write syntax for an F5 IRule’ that becomes a virtual patch? Everyone can do threat intelligence, enrichment, some of those harder tasks.” When infosec staff make those fixes, Lawson wants organizations to celebrate the impact of their work. Today, Lawson said, security operations centers measure staff by the number of tickets they process and close. He thinks a better approach is to celebrate the fact that cyber-defenders kept a hospital open or stopped a ransomware raid. ®
Kategorie: Viry a Červi
Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs.
"This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution," Wordfence said.
The WordPress security company said it has blocked over Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Elektrický VW Mission Efficiency ujel 1278 kilometrů s jedinou zastávkou u nabíječky
Elektrický prototyp Volkswagen stanovil tři rekordy v oblasti úspory energie • Na trase dlouhé 1278 km dobil malou baterii pouze na jediném místě • Špičková aerodynamika umožnila výrazně snížit celkovou spotřebu
Kategorie: IT News
Pracovník americké celnice vybíral ze sestav Core, RAM a SSD, měnil je za horší
Pracovník IT podpory amerických celních úřadů si našel zajímavý přivýdělek. Z celních systémů vybíral hodnotný hardware, který pro zachování funkčnosti nahrazoval levným. Škoda prý přesáhla $100 000…
Kategorie: IT News
Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr.
The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verification of a cryptographic signature that could result in account takeover. Hacktron Team has been credited with discovering and reporting the flaw.
"JWT authentication Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Banky v září rozdávají dětem peníze. Podívejte se, kdo dává teď nejvíc
Pokud se se začátkem školy poohlížíte po účtu pro děti a mladé, na který jim od banky přistane první kapesné, podívejte se, jaké máte možnosti.
Kategorie: IT News
Zálohování domácího serveru pomocí nástrojů tar a dump
Když jsem si stavěl domácí server s Debianem, tak mě vítr zavál rovněž i do světa FreeBSD, kde jsem se dozvěděl o příkazech tar a dump. Zde jsem se dozvěděl, že tar vznikl jako zálohovací software.
Kategorie: GNU/Linux & BSD
Softwarová sklizeň (16. 9. 2026): sjednoťte všechny správce balíčků
Rozjedeme několik kódovacích agentů zároveň, poskládáme lokální vývojové prostředí z jediné aplikace, promluvíme na všechny správce balíčků jedním příkazem a nakonec změříme v terminálu vytížení procesoru i sítě.
Kategorie: GNU/Linux & BSD
Čína plánuje 60tunový tank s 10MW reaktorem a railgunem
V Číně se pořádně odvázali a přicházejí s konceptem těžkého supertanku, poháněného kompaktním jaderným reaktorem a vyzbrojeného 50MJ railgunem. Jeho ochranu by zajišťoval elektromagnetický pancíř. Myšlenka je to smělá, ale její případnou realizací si Čína nejspíš sáhne na dno svých technologických možností, pokud je to vůbec technologicky smysluplné.
Kategorie: Věda a technika
Experiment s exotickými částicemi vyzývá Einstenovu gravitaci
Švýcarští fyzici dosáhli průlomu v produkci mionia, exotických atomů tvořených mionem a elektronem. Jejich úspěch je posunul blíž k vytouženému experimentu, v němž by měli otestovat gravitační chování mionů, jako prvních představitelů částic druhé a třetí generace Standardního modelu.
Kategorie: Věda a technika
Čínská YMTC je jen rok za západem ve výrobě SSD, CXMT 2-3 roky s DRAM
Korejská asociace výrobců provedla analýzu, podle jejíchž výsledků se skluz, který mají čínští výrobci pamětí za korejskými, opět zmenšil…
Kategorie: IT News
The vulnpocalypse rains iBugs down on Apple with record-setting number of patches
Apple has addressed more than 260 CVEs across all of its operating systems, browsers, and other software products, marking the largest single patch cycle in Cupertino's history. While this CVE count is hardly notable compared to some vendors - hello, Microsoft’s record-breaking 974 bugs disclosed earlier this month - it does set a company record for Apple. It also reflects the new reality of AI-driven bug hunting, as models become exponentially better and faster at finding security vulnerabilities. However, the flip side of the AI coin we were promised - that models would also excel at writing patches and automatically fixing software and systems - yeah, that hasn't happened yet. The silver lining for everyone updating their Apple products right now (including this humble vulture): none of the vulnerabilities are listed as being under active exploitation. Of course, that may change very quickly as attackers are, at this very moment, looking to exploit the newly disclosed bugs, too. And we promise you that they are using AI. Apple’s latest mobile and operating system versions, iOS 27 and macOS 27 Golden Gate, released on Monday, also address a record 122 and 204 security vulnerabilities, respectively, across phone, iPad, and computer operating systems. Of these hundreds of CVEs, however, there are only ten (by our count) that AI is directly credited with finding. iOS 27 fixes 122 flaws Just two of the iPhone and iPad CVEs fixed with iOS 27 credit a coding agent or AI assistant with finding them. These include CVE-2026-65410, a vuln that exists in iPhone and iPad AVE video encoders, that can cause unexpected system termination. Apple credited AI-bug-finding firm Calif, along with Claude and Anthropic Research, with finding and reporting this security flaw. Then there's CVE-2026-65409, a type-confusion issue in iOS’ Foundation framework that can be abused to cause a denial of service, also found by Calif - specifically human researcher Bruce Dang - in collaboration with Claude and Anthropic Research. Some of the more interesting and serious iOS bugs fixed with the newest update aren’t listed as found by AI. These include CVE-2026-43689, a privilege-escalation flaw that could allow an app to gain root access. Apple credited Nosebeard Labs’ Andreas Jaegersberger and Ro Achterberg with reporting this bug. Additionally, CVE-2026-65406, a logic-issue flaw due to improper validation in Background Assets, could be abused to access sensitive user data. Background Assets is an Apple framework that lets you download large files and content in the background before a user opens the app for the first time. Baidu Security researcher Ye Zhang spotted this one. macOS 27 patches 204 vulns Meanwhile, the new macOS 27 update that addresses 204 vulns also fixes both the AI hunted bugs: CVE-2026-65410 and CVE-2026-65409. Plus, it credits AI helpers with discovering eight others, including one especially nasty flaw that could lead to remote code execution through the CUPS printer interface. Let’s start with that one. CVE-2026-43692 is a validation issue in CUPS that can be exploited by a remote user to either terminate the app or execute malicious code. Aaron Grattafiori and the Nvidia AI Red Team receive credit for disclosing this flaw. CVE-2026-64790 in CUPS can be exploited to gain elevated privileges. Grattafiori and the Nvidia AI Red Team again get credit for the win. CVE-2026-43791, a validation issue in StorageKit, can be abused to read files. Grattafiori, the Nvidia AI Red Team, Meridian Miftari, and Amy from amys.website disclosed this flaw to Apple. CVE-2026-43690 is a race-condition bug in the Server Message Block (SMB) network communication protocol. A local user can exploit the flaw to read kernel memory. Calif’s Bruce Dang, with Claude and Anthropic Research, found this one. CVE-2026-43719 is another SMB use-after-free bug, discovered by Calif’s Dang and Jakob Pammer, Claude, and Anthropic. “Mounting a maliciously crafted SMB network share may lead to system termination,” Apple warned. CVE-2026-65376 is yet another SMB issue - this one an out-of-bounds-read flaw reported by Dang, Claude, Anthropic, and 재영 정. CVE-2026-65374 is a memory-corruption issue in the WebDAV protocol that can lead to code execution. Dang, Claude, Anthropic, and He Wei (ギカク) receive credit for finding this bug. CVE-2026-65375, also in WebDAV, can cause unexpected system termination. Apple credited Dang, Claude, Anthropic, and Devcore Research Team’s YingMuo. CVE-2026-43677 is an out-of-bounds write issue in WebDAV with a slew of researchers receiving credit for finding it. In addition to the usual trio (Dang, Claude, and Anthropic), bubu, Omar Cerrito, HE WEI(ギカク), Roman Zabicki, Richard Zana, Chris Bailey - Short Circuit, Aswin Kumar Gokulakannan, and Surya Narayan Kushwaha are on the list.®
Kategorie: Viry a Červi
Acronis warns of actively exploited flaw in its cPanel backup plugin
Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]
Kategorie: Hacking & Security
- « první
- ‹ předchozí
- …
- 69
- 70
- 71
- 72
- 73
- 74
- 75
- 76
- 77
- …
- následující ›
- poslední »



