Agregátor RSS

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

The Hacker News - 17 Červenec, 2026 - 23:20
Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story below reflects all of it. An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until
Kategorie: Hacking & Security

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

The Hacker News - 17 Červenec, 2026 - 23:20
Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story below reflects all of it. An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range untilSwati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Abbott probes two cyber incidents amid extortion claims

Bleeping Computer - 17 Červenec, 2026 - 22:45
Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal and stole company data. [...]
Kategorie: Hacking & Security

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

The Hacker News - 17 Červenec, 2026 - 22:20
Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte fix in June with no CVE, no advisory, and no changelog entry pointing at it. Okta's Red Team, which reported the denial-of-service bug and named it, published the
Kategorie: Hacking & Security

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

The Hacker News - 17 Červenec, 2026 - 22:20
Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte fix in June with no CVE, no advisory, and no changelog entry pointing at it. Okta's Red Team, which reported the denial-of-service bug and named it, published the Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Anthropic Says Chatbots Have What May Be a Key Feature of Consciousness. Are They Right?

Singularity HUB - 17 Červenec, 2026 - 21:57

When you interact with a large language model (LLM)—one of the systems behind chatbots such as ChatGPT and Claude—it can feel as though you are in contact with another conscious mind. But are you, really?

Some prominent scientists, such as Geoff Hinton and Richard Dawkins, claim you are. But most experts remain skeptical, arguing that the impressive cognitive capacities of LLMs occur in the absence of consciousness.

Recently, researchers at Anthropic, the company behind Claude, waded into this debate with an interesting finding. They claim Claude has a normally invisible set of representations of information that guide its internal reasoning and its verbal output.

This is where it gets interesting. The researchers argue this finding can be understood in terms of an influential theory of consciousness called the global workspace theory.

What Is the Global Workspace Theory?

First proposed by the psychologist Bernard Baars in 1998 and further developed by the neuroscientist Stanislas Dehaene and his collaborators, this theory holds that consciousness involves the activity of a “global workspace.” This is a kind of processing hub in the mind or brain that integrates and broadcasts information, allowing it to be used for reasoning, behavior control, and speech.

In a glossy video explaining the work, Anthropic depicts the contents of Claude’s “global workspace” as sailing ships afloat on a vast sea of unconscious mental activity.

How should we react to these developments? Do they provide evidence for artificial consciousness? If so, how strong is that evidence?

What Is a Global Workspace?

We can start by asking whether Claude does indeed have a “global workspace.” This is not straightforward, for the theory gives no formal definition of a global workspace.

The notion is characterized only informally. The (typically implicit) assumption is that any computational workspace “similar enough” to a human’s will qualify as a “global workspace.” But how similar is similar enough?

Anthropic researchers say they have found evidence of a space of internal thoughts that don’t appear in Claude’s output. Image Credit: Anthropic

Claude’s workspace may indeed have much in common with ours, but there do appear to be differences.

For example, the brain’s workspace is sustained by recurrent loops—signals cycling back through the same circuits over time. In contrast, Claude’s workspace evolves over a single pass through the network.

A related difference concerns how representations enter a workspace. Advocates of global workspace theory have long argued that in humans, a process called “ignition” occurs in which a non-linear process amplifies and sustains neural representations, allowing them to enter the workspace. As far as we know, nothing comparable occurs in Claude’s case.

Do these differences matter? The answer is not clear. Global workspace theory is based on data drawn from adult humans. There are questions about how far the notion can be—or should be—extended.

Does a Global Workspace Imply Consciousness?

But let’s suppose Claude does have a global workspace. To figure out whether that would be evidence for Claude being conscious we need to consider the status of the global workspace theory of consciousness.

There is no doubt it’s one of the most influential theories of consciousness, but it’s hardly uncontroversial among experts. (In a rather extreme understatement, Anthropic’s paper remarks that “the global workspace model is not universally accepted.”)

Many consciousness experts argue that computational properties alone are enough for consciousness. Even among those who think that consciousness is inherently computational, global workspace theory is only one of many options.

‘Conscious Access’ and Subjective Experience

What’s more, there are questions about whether global workspace theory is really a theory of consciousness in the relevant sense at all.

In an influential paper on artificial consciousness, the neuroscientist Dehaene and his collaborators advance the theory as an account of what they call “conscious access”—the availability of information for recall, the voluntary control of behavior, and verbal report. Crucially, they leave open the question of whether global workspace theory should be understood as an account of the subjective or experiential components of consciousness.

But if global workspace theory is just a theory of “conscious access,” then its implications for the artificial consciousness debate lose much of their significance. When we ask whether Claude is conscious we don’t want to know whether it has “conscious access”—instead, we want to know whether there is anything, subjectively speaking, that it’s like to be Claude. Global workspace theory doesn’t speak to that question if we treat it as nothing more than an account of “conscious access.”

So Has Artificial Consciousness Arrived?

Even taking these complications into account, there is no doubt that Anthropic’s findings are noteworthy. Global workspace theory can be understood as a theory of subjective experience, and Claude may indeed turn out to have something akin to a “global workspace.”

None of this is evidence that artificial consciousness has arrived. But it’s not unreasonable to think these findings do move the dial—if only ever so slightly—in the artificial consciousness debate.

But if that’s right, then it’s puzzling why Anthropic is quite so upbeat about these developments. As Anthropic recognizes, the creation of artificial consciousness would be a momentous event with wide-ranging social, ethical, political, and legal ramifications.

If chatbots are conscious then we would need to take their interests seriously. It would no longer be permissible to treat them as mere machines; instead, we would need to consider their welfare.

Should Anyone Even Be Trying to Do This?

Anthropic remarks that “it’s time to start thinking about whether we should be building conscious machines.”

I agree we need to have that discussion, but we should also pause work on building machines that might potentially be conscious. If Anthropic were serious, it would surely down tools rather than plough ahead with its attempt to develop conscious AI.

A moratorium on AI research that might be thought to lead to conscious AI would, of course, be far from straightforward. There are questions about the range of research it would affect and who might enforce it. But if we don’t close the stable door now we might find that the horse has already bolted.

This article is republished from The Conversation under a Creative Commons license. Read the original article.

The post Anthropic Says Chatbots Have What May Be a Key Feature of Consciousness. Are They Right? appeared first on SingularityHub.

Kategorie: Transhumanismus

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

The Hacker News - 17 Červenec, 2026 - 20:54
Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which was observed using an "unprecedented" four-tier blockchain-based command-and-control (C2) infrastructure spanning Tron,
Kategorie: Hacking & Security

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

The Hacker News - 17 Červenec, 2026 - 20:54
Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which was observed using an "unprecedented" four-tier blockchain-based command-and-control (C2) infrastructure spanning Tron,Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload

Bleeping Computer - 17 Červenec, 2026 - 19:56
A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes. [...]
Kategorie: Hacking & Security

Microsoft’s Patch Tuesday updates: Keeping up with the latest fixes

Computerworld.com [Hacking News] - 17 Červenec, 2026 - 19:47

Long before Taco Tuesday became part of the pop-culture vernacular, Tuesdays were synonymous with security — and for anyone in the tech world, they still are.  Patch Tuesday, as you most likely know, refers to the day each month when Microsoft releases security updates and patches for its software products — everything from Windows to Office to SQL Server, developer tools to browsers.

The practice, which happens on the second Tuesday of the month, was initiated to streamline the patch distribution process and make it easier for users and IT system administrators to manage updates.  Like tacos, Patch Tuesday is here to stay.

In a blog post celebrating the 20th anniversary of Patch Tuesday, the Microsoft Security Response Center wrote: “The concept of Patch Tuesday was conceived and implemented in 2003. Before this unified approach, our security updates were sporadic, posing significant challenges for IT professionals and organizations in deploying critical patches in a timely manner.”

Patch Tuesday will continue to be an “important part of our strategy to keep users secure,” Microsoft said, adding that it’s now an important part of the cybersecurity industry.  As a case in point, Adobe, among others, follows a similar patch cadence.

Patch Tuesday coverage has also long been a staple of Computerworld’s commitment to provide critical information to the IT industry. That’s why we’ve gathered together this collection of recent patches, a rolling list we’ll keep updated each month.

In case you missed a recent Patch Tuesday announcement, here are the latest six months of updates.

July’s Patch Tuesday sees an end-of-support collision amidst a massive, record-setting patch wave

Microsoft addressed 722 CVEs this month once the 427 Chromium upstream relays are set aside — roughly three times a normal cycle and one of the largest single months in recent memory. Two vulnerabilities arrive under active exploitation: an elevation of privilege in Active Directory Federation Services (CVE-2026-56155), and an elevation of privilege in SharePoint Server (CVE-2026-56164). A third, a BitLocker security feature bypass (CVE-2026-50661) is publicly disclosed but not yet exploited.

The July 2026 Patch Tuesday earns Patch Now recommendations for Windows, Office, Exchange, and SQL Server. SharePoint has two critical RCEs on top of its exploited zero-day, and Exchange Server returns with a critical on-premises spoofing flaw. Adding to our (dear) administrator’s efforts, SharePoint Server 2016/2019 and SQL Server 2016 all reach end of support today. The Readiness team has provided a handy infographic of the expected risk profile of this month’s Patch Tuesday updates.

More info is available here on Microsoft Security updates for July 2026.

For June, Patch Tuesday means an IT scramble

Microsoft this month released 206 updates affecting Windows, Office, Exchange Server, and its developer tools — including three Windows vulnerabilities already publicly disclosed. That trio includes an elevation of privilege in the Collaborative Translation Framework (CVE-2026-45586), a denial of service in HTTP.sys (CVE-2026-49160), and a BitLocker security feature bypass (CVE-2026-50507). At the moment, none appear to be under active exploitation, but all three are rated “Exploitation More Likely.” 

Even without an exploited zero-day, the June 2026 Patch Tuesday release requires Patch Now recommendations for Windows, Office, and Exchange. The latter is back in the patch picture with a consolidated security update that Microsoft recommends installing “as soon as possible.”

More info is available here on Microsoft Security updates for June 2026.

For May, Patch Tuesday means 139 updates — but no zero-days

Microsoft this month released 139 updates affecting Windows, Office, .NET, and SQL Server (though there were no updates for Microsoft Exchange Server). Despite the absence of zero-days, the May Patch Tuesday update still requires Patch Now recommendations for Windows and Office. 

The combination of three unauthenticated network RCEs (Netlogon, DNS Client, and SSO Plugin for Jira and Confluence), four Word Preview Pane RCEs, the large TCP/IP vulnerability cluster, and the carry-over BitLocker recovery condition (still active on Windows 10 and Windows Server) warrants an accelerated deployment release schedule. 

More info is available here on Microsoft Security updates for May 2026.

Microsoft’s Patch Tuesday release for April is a whopper

Windows admins are going to be busy this month, dealing with the largest Patch Tuesday cycle in memory. The April release involves 165 updates and roughly 340 unique CVEs from Microsoft — including two zero-days, one of which is already being actively exploited in the wild. 

The Readiness team recommends “Patch Now” schedules for nearly every major product family: Windows, Office (with a zero-day), Microsoft Edge (Chromium), SQL Server, and Microsoft Developer Tools (.NET). April also brings Phase 2 of Microsoft’s Kerberos RC4 hardening with full enforcement set for July. There is a lot to cover, so here’s a useful infographic mapping the deployment risk for each platform.

More info is available here on Microsoft Security updates for April 2026.

For March, Patch Tuesday delivers fixes for 83 vulnerabilities

Microsoft’s March Patch Tuesday release addresses 83 vulnerabilities across Windows, Office, SQL Server, Azure, and .NET — with two publicly disclosed zero-days affecting SQL Server and .NET (though neither is being actively exploited in the wild.) Six additional vulnerabilities spanning the Windows KernelGraphics ComponentSMB ServerAccessibility Infrastructure, and Winlogon are flagged as “Exploitation More Likely.”

The most significant change this month is the introduction of Common Log File System (CLFS) hardening with signature verification, which will affect how Windows handles log files across the operating system. More info on Microsoft Security updates for March 2026.

February’s Patch Tuesday release fixes 59 flaws, including 6 being exploited

The company’s Patch Tuesday release for February addresses 59 CVEs across the company’s product family — roughly half the volume of January’s 159 patches. Six vulnerabilities, affecting Windows Shell, MSHTML, Desktop Window Manager, Remote Desktop, Remote Access, and Microsoft Word, are already being actively exploited. (All five Critical-rated CVEs target Azureservices rather than Windows, however.) 

Both Windows and Office get a “Patch Now” recommendation, with CISA setting a March 3 enforcement deadline for all six exploited vulnerabilities. Two new enforcement timelines also take effect in April: Kerberos RC4 deprecation (CVE-2026-20833) and Windows Deployment Services hardening (CVE-2026-0386). More info on Microsoft Security updates for February 2026.

Kategorie: Hacking & Security

OnlyFans performers become unlikely allies of CISOs in securing websites

Computerworld.com [Hacking News] - 17 Červenec, 2026 - 19:37

CISOs at government organizations and universities have an unexpected ally coming to their aid: OnlyFans models.

For some time, hackers have exploited weaknesses in the websites of universities or government departments to host scams or malware, using content stolen from the OnlyFans website as bait to attract victims.

Now, according to security researchers at Upguard, the fightback has begun: creators of adult content on OnlyFans are leveraging Google search results and the protection offered by copyright law to break up the traffic distribution systems created by bad actors.

These distribution systems work in three stages: entry points using adult or other content to attract and capture web traffic, a routing system sends it to destination sites, and those sites monetize the traffic through scams and malware. It has proved to be a lucrative business for the scammers.

Google recognizes the approach and calls such actors SEO parasites as they benefit from the reputations of other organizations — in particular government or academic sites, which Google views as having high authority.

Since the creators of OnlyFans content are also the copyright holders, they are able to issue Digital Millennium Copyright Act (DMCA) take-down notices for the stolen content posted by the bad actors to other sites. Upguard was able to track this through Google’s DMCA Transparency Report, and through the Lumen Database, another tracker of takedown notices, to which it was granted research access.

“This allows us to identify likely compromised sites: government and university domains advertising unlicensed adult content,” Upguard said.

The OnlyFans creators’ action has two benefits for the operators of the affected websites: The adult content associated with their domain disappears from Google search results, no longer affecting their reputation — and if they receive takedown notices for such content they can check their webservers for the vulnerabilities that enabled the bad actors to post it there in the first place.

This article first appeared on CSO.

Kategorie: Hacking & Security

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

The Hacker News - 17 Červenec, 2026 - 19:12
A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the image generators, local model runners, and workflow builders that teams stand up fast and firewall late. The intel feed behind that counter
Kategorie: Hacking & Security

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

The Hacker News - 17 Červenec, 2026 - 19:12
A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the image generators, local model runners, and workflow builders that teams stand up fast and firewall late. The intel feed behind that counter Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

OpenAI’s new hardware is a $230, 13-switch keyboard for Codex

Computerworld.com [Hacking News] - 17 Červenec, 2026 - 19:07

OpenAI is selling its first hardware — without any help from Jony Ive. It describes the Codex Micro as a “command center for agentic work” but it’s really a 13-switch wireless keyboard customized to help developers keep tabs on what their Codex agents are doing. It costs $230.

The keyboard has 13 mechanical switches (one keycap covers two of them by default), a rotary encoder, joystick, and RGB backlighting around the whole keypad and individual keys. It comes with 32 customizable icon keycaps.

OpenAI claims that the Codex Micro is a serious business tool: The command keys enable Codex users accept changes, reject outputs, push-to-talk, start new chats, and trigger custom actions. The rotary encoder can be used to dial up the “brainpower” allocated to tasks — or in more conventional terms, how many tokens to allocate to reasoning on a task. And the RGB lighting can provide feedback on how various tasks are progressing. And the RGB lighting under the “agent” keys can provide feedback on how various tasks are progressing.

The Codex Micro’s manufacturer, Work Louder, already has a similar device on the market, the Creator Micro, which offers similar functionality, but without the colorful keys. It costs $56 less than the Codex Micro, however.

The Codex Micro will fit in snugly with OpenAI’s other merchandise, where using Codex is as much about a fashion statement as a technological choice.

This article first appeared on InfoWorld.

Kategorie: Hacking & Security

El Niño hýbe světem a peněženkami. Když Pacifik kýchne, zdraží i vaše káva (Podcast Živě)

Živě.cz - 17 Červenec, 2026 - 18:45
Klimatický fenomén El Niño vzniká nepravidelně změnou proudění větrů nad Tichým oceánem. Když pasáty zeslábnou, teplá voda se nakumuluje v rovníkové oblasti poblíž Jižní Ameriky. V Austrálii a jihovýchodní Asii jev způsobuje sucha a požáry, zatímco Peru nebo Ekvádor trápí povodně. V Evropě ...
Kategorie: IT News

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft

The Hacker News - 17 Červenec, 2026 - 18:39
Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group), a Chinese cybercrime group known for its targeting of the gambling and gaming sectors using
Kategorie: Hacking & Security

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft

The Hacker News - 17 Červenec, 2026 - 18:39
Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group), a Chinese cybercrime group known for its targeting of the gambling and gaming sectors using Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Why Mobile Proxies Are Harder to Block Than Datacenter IPs

LinuxSecurity.com - 17 Červenec, 2026 - 18:24
You're running a web scraping project to collect pricing data from e-commerce sites. You set up a pool of datacenter proxies, launch your scripts, and within minutes — banned. CAPTCHAs everywhere. Your data pipeline stops before it really begins.
Kategorie: Hacking & Security

AI spam filters are getting suckered by old-school text salting

The Register - Anti-Virus - 17 Červenec, 2026 - 18:15
Notice more spam getting through that corporate email filter lately? Attackers are using a technique known as "text salting," which hides benign-looking words intended to confuse some AI-powered email filters, says cybersecurity firm Barracuda. The email security outfit said on Thursday that it had detected more than one million retail-themed phishing attacks using text salting since April. It’s not a new technique by any stretch and has been used to fool traditional secure email gateways for years, but Barracuda says it can also confuse machine-learning and LLM-based security tools. Text salting involves peppering (sorry) a malicious email with random, harmless-seeming words in order to fool an email scanning system into thinking there’s nothing off about the flavor of a message (sorry again), tricking the system into passing it to its recipient for consumption (I’ll stop with the food jokes here). Pour a pile of salty text on top of an email and a human reader would probably get suspicious, however, so attackers typically use one or more of three flavor variations (okay, I'm done – promise) to hide the additives from human readers, but not automated scanners, per Barracuda. Typical techniques include CSS cropping, which sets the visible window small enough that a human won't see the hidden filler text; text manipulation to move the salty copy outside the visible screen; and zero font techniques which insert misleading words between suspicious phishing copy that’s visible to a machine but not a human. The end result of each of those techniques is a message that reads less malicious, more gibberish to a machine, leading it to assume the email is fine, and which looks exactly as the attacker intended when viewed by a human. Modern email security systems have largely adapted to these techniques, with newer tools able to remove hidden text to see what a reader is supposed to see, sounding alarms when a lot of hidden stuff is inserted in an email, and the like. AI, however, hasn’t managed to follow suit, says Barracuda. “Text salting and related techniques can be used to confuse AI-driven content analysis engines by flooding the email with random terms that encourage the AI system into making an incorrect classification decision,” the company wrote in its report - just like those early 2000s SEGs. What a technological leap we’ve made! LLMs, Barracuda explained, are typically designed to process email text and source code plainly, with no understanding of whether text is visible or hidden from a user. They can be trained to do so, but that just means most tools probably aren’t doing that by default. So, what can enterprises do to stop the flow of salty spam to their employees? Barracuda recommends a layered approach to email security rather than relying solely on keyword detection, including checking sender reputation, authentication results, embedded URLs, HTML-rendering techniques, and differences between user-visible and hidden content. Ditching that AI spam filter might not be a bad idea, either. ®
Kategorie: Viry a Červi
Syndikovat obsah