Agregátor RSS

Římský dvanáctistěn palisády nezapaloval. Možná je pomáhal vyměřovat

OSEL.cz - 23 hodiny 11 min zpět
Bronzový předmět s pěti dvojicemi nestejných otvorů mohl být trvanlivou optickou součástí jednoduchého nočního dálkoměru. Hypotézu lze ověřit přesným měřením několika exemplářů a jedním poctivým večerním pokusem.
Kategorie: Věda a technika

Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware

The Hacker News - 14 Srpen, 2026 - 20:48
Threat actors are acquiring expired domains to inherit website traffic and reputation to redirect victims to scams and malware on a large scale. DNS threat intelligence firm Infoblox has given the name dropcatch domains to those that get a second chance, where an expired domain becomes available for registration and is then snapped up by another party. During the first half of 2026, 50,400 Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Vulnerability giving attackers full control of Macs is under active exploitation

Ars Technica - 14 Srpen, 2026 - 20:32

Dutch officials have warned that a high-severity macOS vulnerability that allows attackers to execute malicious code is under active exploitation.

“The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet,” the Netherlands National Cyber Security Centrum warned earlier this week. “In all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed.”

Do you know if your screen sharing is on?

The vulnerability, tracked as CVE-2026-65400, received a patch from Apple last week for macOS Tahoe, Sequoia, and Sonoma. The vulnerability, with a severity rating of 7.1 out of 10, stems from a bug in the macOS screen sharing capability, which allows a remote party to view the screen and control the keyboard and mouse while a machine is turned on. A flaw in the “state management,” which keeps track of preceding events, user interactions, variables, and other system states, is the underlying cause.

Read full article

Comments

Hackers arrested over €30M bank fraud exploiting service provider flaw

Bleeping Computer - 14 Srpen, 2026 - 20:04
Four cybercriminals were arrested in Brazil, and three others were charged in Europe over allegations that they exploited a vulnerability at a service provider, allowing them to withdraw funds from Commerzbank customers' bank accounts. [...]
Kategorie: Hacking & Security

Zákeřný malware zneužívá mobilní NFC platby v Česku. Útočníci si přes něj mohou sjednat půjčku na vaše jméno

Živě.cz - 14 Srpen, 2026 - 19:50
Útočníci nejprve po telefonu přimějí oběť k instalaci trojského koně • Škodlivý kód přeposílá živá NFC data karty do terminálu podvodníka • Během krátkého hovoru stihnou na jméno oběti sjednat vysokou půjčku
Kategorie: IT News

1.6M RingCentral accounts' data dumped after ShinyHunters extortion attack

The Register - Anti-Virus - 14 Srpen, 2026 - 19:34
Some 1.6 million unique email addresses tied to RingCentral have been leaked online, alongside names, physical addresses, and phone numbers, according to Have I Been Pwned. RingCentral disclosed the breach on July 28 and said “it was the target of a sophisticated social engineering campaign” affecting a “limited portion of RingCentral customers.” The comms platform said that it promptly responded to the intrusion upon detecting it, “took steps to stop the unauthorized activity,” and immediately launched an investigation into the security incident with help from a “leading third-party forensic firm.” “We have not seen any new unauthorized activity since taking these remediation efforts,” the company added. RingCentral did not immediately respond to The Register’s request for comment on this story. We will update it as needed. While the company hasn’t named its attacker, notorious data theft and extortion gang ShinyHunters previously claimed it compromised the collaboration platform, according to a post on its data leak site, viewed by The Register. Screenshots of the post also circulated on social media. The crooks claimed they stole more than 623 GB of data, and set a July 30 deadline for RingCentral to pay up - or else the crew would dump the stolen information online. RingCentral apparently didn’t pay the extortion demand, and ShinyHunters followed through on its threat, posting customers’ details on the internet. “The company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don’t care,” the crims wrote on August 3. A ShinyHunters spokesperson told us that the group broke into RingCentral by voice-phishing an employee and tricking them into giving the crooks their password. This same group, which security sleuth Dominic Alvieri says is his “top threat group and probably is for most analysts,” has hacked hundreds of organizations since the start of the year, including education tech firms that provide services for schools and universities along with healthcare-sector organizations. Recently, ShinyHunters dumped data stolen from Abbott’s cancer diagnostics business with the leak containing 10.9 million unique email addresses alongside personal and health information. The crooks claim that they made off with more than 30 million rows of customer information, including more than one million Social Security numbers and 7.5 million dates of birth. More concerning, however, they said the haul includes 22 million-plus rows of client notes containing confidential doctor-patient conversations and health information, and more than 20 million medical-order records containing patient IDs, prescription types, order dates, and refill information.® Editor's note: This story was amended post-publication with comment from ShinyHunters.
Kategorie: Viry a Červi

IAM Compliance Requirements and Best Practices

The Hacker News - 14 Srpen, 2026 - 19:19
IAM compliance is the practice of demonstrating that identity and access controls are not only documented but actually enforced across users, applications, infrastructure, and non-human identities. This guide explains what IAM compliance requires, which regulations matter, and how organizations move from periodic access reviews toward continuous, evidence-backed verification that auditors can [email protected]
Kategorie: Hacking & Security

PBS station fears losing 50TB of data after being ghosted by cloud storage provider

Ars Technica - 14 Srpen, 2026 - 19:03

After its cloud storage provider went defunct, a PBS affiliate decided to sue a data center provider to regain access to 50TB of TV shows, videos, and other data dating back 70 years.

As reported this week by Current, a trade newspaper covering public broadcasting, St. Louis affiliate Nine PBS filed a lawsuit against Iron Mountain Data Centers on July 28, seeking access to the data. In the litigation filed in Denver District Court, Nine PBS says that its cloud storage provider, Open Source Storage (OSS), used one of Iron Mountain’s Denver data centers to store the channel’s data. However, OSS is being unresponsive, and Nine PBS says Iron Mountain has refused to release its data.

The data in question includes the station’s coverage of the COVID-19 pandemic, East St. Louis’ history, The Great Flood of 1993, and over 11,000 files, The Denver Post reported in July. The lawsuit claims that “most” of the data is “unique and irreplaceable,” according to the Post.

Read full article

Comments

Windows 11 čeká dieta a dřina. Microsoft chce okna zeštíhlit i zrychlit (Podcast Živě)

Zive.cz - bezpečnost - 14 Srpen, 2026 - 18:45
Microsoft do léta splnil většinu slibů o tom, jak zlepší Windows 11. Jen mu to trvá a široká distribuce většiny novinek teprve protéká z testovacích kanálů do stabilní větve. Ve druhém pololetí chce optimalizovat. Ví totiž, že Jedenáctky nepodávají nejlepší výkon. Některé prvky se spouští pomalu a ...
Kategorie: Hacking & Security

Windows 11 čeká dieta a dřina. Microsoft chce okna zeštíhlit i zrychlit (Podcast Živě)

Živě.cz - 14 Srpen, 2026 - 18:45
Microsoft do léta splnil většinu slibů o tom, jak zlepší Windows 11. Jen mu to trvá a široká distribuce většiny novinek teprve protéká z testovacích kanálů do stabilní větve. Ve druhém pololetí chce optimalizovat. Ví totiž, že Jedenáctky nepodávají nejlepší výkon. Některé prvky se spouští pomalu a ...
Kategorie: IT News

August’s Patch Tuesday is a monster: 751 fixes, with an exploited Windows flaw

Computerworld.com [Hacking News] - 14 Srpen, 2026 - 18:23

Microsoft’s August 2026 Patch Tuesday closes at 751 CVE entries (across all product families), with 108 rated as critical. One flaw is already exploited, CVE-2026-68820, an elevation of privilege in the Windows WinSock driver (afd.sys). Two more were disclosed but not exploited, CVE-2026-62832 (User Profile Service) and CVE-2026-72971.

This security-only release earns Patch Now for Windows, Office and Exchange; no SQL Server updates this month. Unfortunately, several critical issues affect server roles: Windows DNS Server carries a cluster of critical RCEs; Windows DHCP Server is the most-populated Microsoft product family at 14 entries. Testing should lead with printing and fonts and the Remote Desktop client, then a WinSock smoke test given the exploited afd.sys flaw. The Readiness team has provided a helpful infographic on the deployment risks for this Microsoft August update.

Known issues

Both August client and server-side updates ship with empty known-issues lists. This may change over the coming days so checking back to the Microsoft Security Update Guide (MSRC) may be prudent. July’s open items have all closed: the Dell/Intel driver hold, the mid-July WSUS sync degradation, and the Emoji Panel GIF outage (August swaps in GIPHY).

  • On the server side, WSUS synchronisation error details stay suppressed. The August Windows Server 2025 (KB5120233) and 2022 (KB5120242) updates still list this, the detail pane removed to address a remote code execution flaw CVE-2025-59287, with no published workaround.

One July item has been dropped from the documentation without a resolution note: the Windows Server 2022 BitLocker recovery prompt on first restart, for hosts carrying the PCR7 Group Policy condition. With no fix published, the Readiness team recommends that all recovery keys are (easily) retrievable before restarting freshly patched servers.

Major revisions and mitigations

Between the July and August Patch Tuesdays (15 July to 10 August), the MSRC Security Update Guide revised 534 CVEs. Almost all these changes (458) were routine Microsoft Edge and Chromium re-publications – none of which required customer action. That leaves 76 touching Microsoft’s own products, 60 of them flagged customer action required, including:

  • Windows storage and file system: four NTFS entries, all three July ReFS elevation-of-privilege flaws, and two Brokering File System fixes.
  • Identity and federation: six AD FS denial-of-service CVEs, plus two Azure Active Directory entries.
  • Developer runtimes: nine .NET and .NET Framework CVEs, with PowerShell and ASP.NET Core alongside.

The Readiness team has reviewed the 751 published updates, and it appears that Microsoft has not published any mitigations for updates in this August release.

Windows lifecycle and enforcement updates

Microsoft has not published any service or enforcement deadlines for this August. The 13 October 2026 cluster stacks five migration tracks onto one date, with a second wave on 10 November; dates below come from the linked Microsoft lifecycle pages.

One diary note: Windows 11 24H2 Home and Pro reach end of updates on 13 October 2026, two Patch Tuesdays out.

Microsoft’s August 2026 Patch Tuesday is a security-only release: 109 Windows test-guidance entries, four High Risk (July had 14). Printing and fonts lead: win32kfull.sys is the most-patched binary at seven entries and carries three of the four High Risk flags (32-bit printing on 64-bit Windows and font rendering); the Remote Desktop client carries the fourth. The testing guidance below works through each product and feature grouping.

Printing, fonts and graphics

Three of the four High Risk flags sit in win32k and touch print or font paths: 32-bit application printing on 64-bit Windows (two) and font rendering (one). GDI+, the Windows Imaging Component, and the kernel graphics driver (dxgkrnl.sys, five entries) change alongside; estates with 32-bit line-of-business printing or font-heavy documents take this first.

  • Print from your 32-bit applications to physical and virtual (PDF or XPS) printers, using text-heavy, graphics-heavy, and multi-page documents, and repeat after each relaunch, orientation, scaling, and resolution change.
  • Render varied fonts, sizes, and styles across browsers, Office, PDF viewers, and Notepad, and confirm Print Preview matches the printed page – watch for clipping, distortion, or missing glyphs.
  • Copy and paste images between Paint, Word, and Excel at different bit depths, and open EMF and TIFF files.
  • Exercise the graphics kernel: full-screen DirectX, multi-monitor hot-plug, resolution, HDR, and DPI changes, and sleep/resume.
Remote desktop and remote access

The RDP client carries the fourth High Risk flag; the fixes touch every redirection path and multi-session behaviour. RemoteApp, the display pipeline, and the RRAS and SSTP VPN stack change alongside.

  • Open several concurrent RDP sessions, enable printer, clipboard, audio, drive, and smart card redirection together, and exercise each across the sessions, confirming none interferes with another.
  • Disconnect and reconnect a session, confirm redirected devices and drives reattach, and test a RemoteApp end to end.
  • Configure a standard client VPN and an SSTP VPN over HTTPS and confirm sustained connections across reconnects and a restart.
Storage, file sharing and virtualization

The SMB client and server, NTFS and UDFS, the virtualised file layers (Cloud Files, Projected File System, Work Folders), and the platform stack (Hyper-V, virtual TPM, USB, and Windows Installer) all change. Standard Risk.

  • Connect to SMB shares (including RDMA, leases, and Continuous Availability), copy large sets both ways, and interrupt and reconnect a session; exercise NTFS extended attributes, UDF mounts, and cloud-file hydrate and dehydrate.
  • Create, checkpoint, and export a Generation 2 Hyper-V VM, enable a virtual TPM and BitLocker, and connect USB storage and MIDI devices.
  • Install, repair, and uninstall an MSI package, and confirm UAC elevation still prompts.
Telephony, networking and core services

TAPI is the busiest component (11 entries) but carries only parity fixes; the rest spans TCP/IP, HTTP.sys, Windows Firewall, Bluetooth, wired 802.1X, and message queuing. Broad and shallow.

  • Exercise TAPI line status and dialling locations against a shared line, and verify HTTP.sys under IIS over HTTP/1.1, HTTP/2, and HTTP/3.
  • Confirm TCP/IP IPsec tunnels on IPv4 and IPv6, toggle Windows Firewall rules across a restart, pair a Bluetooth headset, authenticate wired 802.1X, and validate MSMQ send and receive.
Office and SharePoint

This August patch cycle affects click-to-run (C2R), Microsoft 365 Apps, and MSI deployments of Microsoft Office with the following updates:

  • On MSI Office 2016, apply the client updates: Access (KB5002813), the ACE database engine (KB5002832), the Office proofing and UI components (KB5002791, KB5002795), Outlook (KB5002755), VBA (KB5002900), and Word (KB5002901), then exercise macros, external data, embedded objects, and line-of-business add-ins.
  • On SharePoint Server, patch 2016, 2019, and Subscription Edition, then check browser-based editing; mind the rollback rules – server updates cannot be uninstalled and always require a reboot.
Microsoft Exchange Server

On-premises Exchange takes a security update this month, seven CVEs across Exchange Server 2016, 2019, and Subscription Edition: one critical elevation of privilege and six important, spanning further elevation of privilege, remote code execution, denial of service, spoofing, and a security feature bypass.

  • Apply the update from an elevated command prompt: an un-elevated run leaves Exchange services partially patched and broken. Then confirm every Exchange service returns and that the server reports healthy.
  • Exercise mail flow end to end: send and receive internal and external mail, drain the transport queues, and check connectors and transport rules; confirm Outlook (MAPI over HTTP), Outlook on the web, and the Exchange admin centre for sign-in and core actions.
  • Confirm Autodiscover and free/busy resolve, test any hybrid connection to Exchange Online, and plan for the reboot the update requires – validate in a maintenance window before production.
Developer tools: .NET

The developer estate gets a broad, low-drama sweep; no SQL Server this month. Both the .NET Framework (Windows Server 2012 to Windows 11 26H1 and Server 2025) and the modern runtime and SDK patch, including WPF and WinForms.

  • Install the .NET Framework and modern .NET runtime and SDK updates, run a representative set of WPF, WinForms, web, and command-line applications, confirm normal behaviour, and build and run a .NET project to check for regressions.

The Readiness team recommends the following priorities for your larger enterprise deployments:

  • Start with printing and fonts: three of the four High Risk flags sit in win32k, so regress 32-bit printing, PDF and XPS export, font rendering, and Print Preview before anything else.
  • Take Remote Desktop next, the fourth High Risk flag, across the redirection paths, concurrent sessions, reconnects, RemoteApp, and SSTP VPN.
  • Give the busy but lower-risk areas a smoke pass: Telephony, the graphics kernel, DNS and DHCP, Active Directory, and the SMB stack.
  • Close out the rest: Office spans MSI 2016, SharePoint and Microsoft 365 Apps this month (Click-to-Run is in scope, unlike July), and .NET is a representative-application check.

Each month, we break down the update cycle into product families, as defined by Microsoft, with the following groupings.

Browsers

After July’s 46-strong Microsoft Edge (Chromium-based) haul, the browser family has nothing to report: August’s Security Update Guide carries no Edge-specific CVEs at all. It’s Margarita time – look busy or look elsewhere for patch-related testing and deployments.

Microsoft Windows

Windows carries the bulk again: 233 CVEs, 18 critical, the rest important bar one moderate. Elevation of privilege leads by volume (143 entries), but all but two of the 18 are rated as critical remote code execution vulnerabilities, on the network-facing server roles.

  • DHCP and DNS lead the critical-rated issues. Windows DHCP Server takes 14 CVEs, the busiest component by far, topped by a critical remote code execution flaw (CVE-2026-62823, “Exploitation More Likely”), with DHCP Client adding four more. Windows DNS Server is the headline RCE risk: six entries, four of them critical (CVE-2026-62878, CVE-2026-62817, CVE-2026-62820, CVE-2026-65789), reaching back to Server 2012. Patch the resolvers alongside the DHCP boxes.
  • A wider critical cluster. Beyond DNS, critical-rated issues also reach Microsoft QUIC, RRAS, the iSCSI Target Service, the WDS TFTP Server, the Remote Desktop Client, GDI+ graphics and Active Directory Certificate Services; domain controllers take priority, and Print Spooler and WSUS are for once absent.
  • Most-patched tally. DHCP Server leads (14, one critical), Win32k next (13 across two groupings), then the Telephony Service (11), the DNS client resolver (10), Windows Installer (nine), and the Windows Kernel and NTFS (eight each).

Add this Windows update to your Patch Now schedule, with your DHCP and DNS servers updated first.

Microsoft Office

Microsoft released 120 Office CVEs this month, 24 of them critical, remote code execution the through-line (62 entries). The packaging work sits on MSI Office 2016 and the SharePoint farms, but the exposure is overwhelmingly Click-to-Run: 89 of the 120 list Microsoft 365 Apps for Enterprise as affected, 20 of them critical, straight through the update channel.

  • Office clients – the critical RCE runs across Office, Word and Excel, mostly in document-rendering paths that fire on preview or open. The top-rated critical client entry, CVE-2026-70130, lists Microsoft 365 Apps among its affected builds, so Click-to-Run estates are squarely in scope rather than sitting this one out, as they could in July.
  • SharePoint Server – three critical-rated vulnerabilities on the on-premises farms, led by CVE-2026-65665, an RCE rated “Exploitation More Likely” (2019 and Subscription Edition), with two critical elevation-of-privilege entries behind it; a separate SharePoint Online spoofing flaw is fixed service-side.

Nothing in Office is exploited this month, but that critical SharePoint RCE and 20 Click-to-Run critical-rated vulnerabilities argue against waiting. Add the August Office and SharePoint updates to your Patch Now schedule.

Microsoft Exchange and SQL Server

Exchange Server has seven CVEs across Exchange Server 2016, 2019 and Subscription Edition, as four build-specific updates (KB5121573 through KB5121576). One is critical and six important; none is disclosed or exploited, but Exchange is internet-facing, so we would not wait.

  • Exchange Server (on-premises) – the critical entry is an elevation of privilege (CVE-2026-62911); the heaviest of the rest is a remote code execution (CVE-2026-62913). Apply it from an elevated command prompt and plan for the reboot (the test-guidance section covers mail-flow). Subscription Edition is the go-forward release; 2016 and 2019 still being carried is a reprieve, not grounds to defer migration.
  • SQL Server – nothing to install. On-premises SQL Server ships nothing; the only SQL-branded entries are cloud-side Azure SQL fixes, resolved service-side.

Add the on-premises Exchange update to your Patch Now schedule; SQL Server does not require anything this month.

Microsoft developer tools

Microsoft released 23 CVEs across its developer tooling this month, all rated as important: 13 in .NET and the .NET Framework, and 10 across Visual Studio Code and its Copilot extensions.

  • Microsoft .NET and .NET Framework – the runtime and framework are the focus this month, led by two remote code execution entries (CVE-2026-62897, .NET Framework, and CVE-2026-70354, .NET Core). The Framework rollups span Windows Server 2012 to Windows 11 26H1 and Server 2025; Visual Studio 2022 17.14 and 2026 18.8 take their exposure through the bundled runtime.
  • Visual Studio Code and Copilot – have three remote code execution entries and security feature bypasses across the Python extension, Copilot Chat and the core editor.

Add these developer-focused updates to your standard release schedule, behind this month’s Windows and Office priorities.

Adobe (and third-party updates)

Unusually, Adobe published an early-August emergency fix for a maximum-severity Adobe flaw (CVE-2026-48449), an incorrect authorisation that runs code with no user interaction. This makes this an Adobe “whatever you have installed” Patch Now moment due to how Adobe tends to share code between products. This August, there were two third-party flaws on Microsoft’s third-party list: the Trusted Computing Group’s TPM 2.0 reference-code bugs CVE-2026-6726 and CVE-2026-6727, both Important and issued by MITRE. If unpatched, a local attacker with TPM command access can work back to keys the chip should keep sealed, up to the RSA Endorsement Key behind device attestation. This completely defeats the purpose of the TPM chip – and, some would say, of migrating to Windows 11. Sorry, not sorry.

Kategorie: Hacking & Security

Máme Pixel 11 Pro a začínáme testovat. Google letos inovace odměřil na lékárnických vahách

Živě.cz - 14 Srpen, 2026 - 17:45
Do redakce dorazily zbrusu nové smartphony řady Google Pixel 11 • Na pohled jsou velmi podobné loňské desítkové generaci • Novinek je poskrovnu, hlavním vylepšením je dioda HiLight
Kategorie: IT News

Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

Bleeping Computer - 14 Srpen, 2026 - 16:59
The Netherlands' National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged. [...]
Kategorie: Hacking & Security

Google dotírá na Claude a GPT cenou i schopnostmi. Rychle připravil schopný model Gemini 3.7 Flash

Živě.cz - 14 Srpen, 2026 - 16:45
Gemini 3.7 Flash míří na rychlé a náročné AI úlohy. • V řadě benchmarků překonává svého předchůdce i konkurenci. • Oproti modelům od OpenAI a Anthropicu je i levnější.
Kategorie: IT News

Ploopy A+ Trackball

AbcLinuxu [zprávičky] - 14 Srpen, 2026 - 16:42
Open-source trackball Ploopy Adept má novou verzi nazvanou A+. Stále jde o symetrický desktopový trackball s šasi z 3D tiskárny a firmwarem QMK. Novinkami jsou dvojice tlačítek, jimiž půjde také otáčet, a volitelná opěrka ruky. Funkcionalita firmwaru je rozšířena o gesta, vrstvy a možnost konfigurace za běhu. Schémata a kód jsou jako obvykle na GitHubu. A+ půjde předobjednat za 99 CAD (bez dopravy a cla/DPH).
Kategorie: GNU/Linux & BSD

OpenAI and Anthropic in price war as Chinese AI rivals gain ground

Ars Technica - 14 Srpen, 2026 - 16:27

Leading US AI labs such as OpenAI and Anthropic are releasing cheaper models as they fight to retain cost-conscious customers who are switching to cut-price alternatives from Chinese rivals.

The price war comes as rising AI bills push companies to curb usage and seek cheaper models, helping Chinese developers including Moonshot and DeepSeek make inroads with users from Silicon Valley to Europe.

OpenAI recently said that it was slashing prices for GPT-5.6 Luna, its “fastest and most affordable model”, by 80 percent. Anthropic has launched Claude Opus 5, touting the system’s “frontier intelligence... at half the price” of Fable 5, the company’s most capable model.

Read full article

Comments

French tax authority admits data heist after crook touts 2M records

The Register - Anti-Virus - 14 Srpen, 2026 - 16:27
France's tax authority has confirmed that an intruder accessed its systems and extracted data in June after an alleged cybercriminal advertised a purported database of 2 million taxpayers. Using the alias "ZeroBytes," the alleged crook behind the attack on the General Directorate of Public Finances (DGFiP) advertised the stolen database on a cybercrime forum on Wednesday. They claimed the database contained details of more than 2 million French taxpayers and that they gained access using stolen credentials and an MFA bypass technique. ZeroBytes also claimed to retain access to DGFiP's systems and offered to sell it alongside the database. DGFiP did not immediately answer our questions about the attacker's claims. However, in a statement released Thursday, it disputed the claim that ZeroBytes retained access. "On Wednesday, August 12, 2026, a malicious actor claimed unauthorized access to the information system of the French Public Finances Directorate, which occurred at the end of June 2026 following identity theft," it said. "Initial investigations confirm that this access, which had been severed at the end of June as part of an audit, nevertheless allowed the consultation and extraction of data concerning individuals and professionals. "Following this complaint, the French Public Finances Directorate immediately implemented new restrictions to stop the unauthorized access and prevent further unauthorized use. In-depth investigations are ongoing to determine precisely which data and number of users were affected." DGFiP said it would report the attack to French data protection watchdog CNIL and notify affected users once it had determined who they were. The intrusion is the latest in a string of security breaches affecting France's public sector this year. France's Ministry of Finance, which oversees DGFiP, admitted in February that miscreants had accessed a database containing French citizens' bank details. The attackers used stolen credentials and made off with 1.2 million records, despite the ministry saying it quickly revoked their access. A few weeks later, France's Health Ministry confirmed a cyberattack on healthtech supplier Cegedim Santé in which around 15.8 million administrative files were stolen. Around 165,000 of these contained doctors' notes, which in "very limited cases" revealed medical histories. In April, the Interior Ministry confirmed reports of an attack on France Titres, the government agency responsible for identity documents including passports and driver's licenses. The alleged culprit, reportedly a 15-year-old, advertised the stolen data online and claimed the breach affected between 18 million and 19 million people – more than a quarter of metropolitan France's population. In June, the department responsible for Tchap, France's encrypted government messaging platform, investigated a suspected breach. The alleged attackers claimed to have accessed more than 73,000 user accounts, 643,000 messages, nearly 60,000 media files, and hundreds of chat rooms. ®
Kategorie: Viry a Červi

The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI

Bleeping Computer - 14 Srpen, 2026 - 16:00
Google Workspace attacks do not always begin with phishing. Stolen OAuth tokens can provide another path into Gmail, Drive, and connected systems. Material Security explains why organizations need defenses that cover the entire Workspace attack chain. [...]
Kategorie: Hacking & Security

Biology Needs an AI Declaration

Singularity HUB - 14 Srpen, 2026 - 16:00

In the Leiden Declaration, mathematicians issued a treatise on how AI challenges their field. Others must do the same.

This article was originally published on Undark. Read the original article.

In June, a community of mostly mathematicians released the Leiden Declaration on Artificial Intelligence and Mathematics, an articulation of the values they hope to preserve as automated systems are integrated into the practice of developing mathematical proofs. This is necessary because some frontier AI systems have shown striking capabilities for solving certain advanced mathematics problems, though independent tests show that AI still has important limits.

Although I’m not a member of the pure mathematics community in any strict sense, much of the declaration’s message resonated with me and was relevant to my own research interests as a computational biologist.

I’m encouraged that the mathematics community decided to take a stand on the issue and that it has been successful in organizing a large number of eminent mathematicians to sign the document. The Leiden Declaration, which originated at a conference held at Leiden University in the Netherlands, should spawn proper copycats, because what is true for mathematics is true for virtually every field that calls itself as a science. The inventions of mathematics percolate into the algorithms and statistical methods that help scientists design experiments, build simulations, and analyze data, from sociology to statistical physics and beyond.

I argue that biological fields should consider something of the sort, because the kinds of knowledge that biology generates and predicts are uniquely vulnerable to subversion and mischaracterization by artificial intelligence.

The conversation in the mathematics community has been illuminating, in that the declaration is a coordinated response to the powers and risks of AI, whose acceleration has felt like a Thanos snap, changing the universe in an instant. And part of the reason that mathematicians felt the effects so immediately is tied to the manner in which their research is conducted: A mathematical proof, in principle, is transparent and independently verifiable, and no proprietary equipment is (generally) required to check it.

The Leiden Declaration should spawn proper copycats, because what is true for mathematics is true for virtually every field that calls itself as a science.

As the Leiden Declaration notes, automated techniques now present mathematics with a new forgery problem: Because mathematical truths are fixed and verifiable, one can identify a counterfeit formalism by comparing it to the genuine proof. Biology, however, offers no such guarantee; our so-called “truths” are often noisy and context-dependent, making it nearly impossible to define what an authentic version should even look like. Some of the most widely appreciated biological principles (such as Mendel’s laws of genetic inheritance) are better described as powerful but limited in scope, and with well-characterized exceptions that don’t undermine the laws but refine their application. This is true for many biological theories. Boundary conditions, edge cases, and noise are not bugs but features of how the natural world works.

For example, a mutation that confers drug resistance to a virus with one genetic background may have a much weaker, neutral, or even harmful effect in another, because its impact depends strongly on the surrounding genetic context. This phenomenon, which biologists call epistasis, is not an exotic edge case but a powerful force across the biosphere in shaping the relationship between an organism’s genes and its expressed characteristics. And epistasis is just one of many examples of context dependence in biological systems, in which a finding that holds true in a dish falls apart in a body or has an effect in a mouse model but not in a primate.

When it comes to AI, the mathematician fears producing a counterfeit solution. But the biologist often cannot say, even acting in the fullest good faith, what the authentic version is supposed to look like.

Despite the differences between mathematics and biology, the life sciences should consider embarking on an exercise that is at least analogous to the Leiden Declaration. If nothing else, a biology version could borrow its structure and ambition. We should insist that researchers disclose their use of automated tools, that they are responsible for the veracity of their findings, that credit and accountability belong to people rather than to systems, and that early-career scientists be protected from incentives that prioritize high-volume output over genuine scientific insight.

A biology declaration should adopt these ideas and others, and emphasize additional provisions that are important to the field: the validation of AI-generated hypotheses against results from the wet lab, the management of training data drawn from the biological commons, and the heightened scrutiny owed to any model whose outputs will eventually touch a patient or an ecosystem. The last point is crucial: In the biomedical realm, AI’s missteps and triumphs will manifest in living bodies, with all of the associated corporeal, emotional, ethical, and legal consequences.

We should insist that researchers disclose their use of automated tools, that they are responsible for the veracity of their findings, that credit and accountability belong to people rather than to systems.

A biological Leiden Declaration must appreciate the nature of the data and observation in biology, and other particulars of the field. But the most important feature for responsibly managing the relationship between AI and living systems involves the durability of what is produced.

A mathematical declaration can aspire for permanence because verified proofs can remain valid across centuries. Biological understandings, on the other hand, tend to shift over time, sometimes rapidly. A policy hastily calibrated to the models of this summer might already be miscalibrated by winter. A declaration written in the hope of lasting a decade could risk spending much of that decade catching up.

If we are to orchestrate a responsible treatise for artificial intelligence in the life sciences, it should be adaptive: versioned, dated, revisited on a published schedule, and amended in the open by the very community it claims to represent. And because different subfields of biology have unique challenges—cardiology versus forest ecology, for instance—perhaps we need multiple declarations (but not too many).

The Leiden Declaration incorporates some of these elements, clarifying that its content reflects AI technologies and mathematical practice as of May 2026 and that updates on the document will be shared. Biology should make that feature part of the central architecture, wiring the process of revision into the document, so that updating it becomes a positive action rather than a confession of failure.

Fortunately, life scientists are well equipped for this task. We have long understood that structures unable to change with their environments rarely endure. It would therefore be a strange betrayal of our discipline to write a declaration that forgets this basic principle. Our policies for technological change must keep the dynamism of living systems at the center of how we imagine the future of biology.

The post Biology Needs an AI Declaration appeared first on SingularityHub.

Kategorie: Transhumanismus

Linux BPF Patches Fix Sparse CPU Bugs Causing Out-of-Bounds Read

LinuxSecurity.com - 14 Srpen, 2026 - 15:55
Two fixes posted August 13 correct separate per-CPU map failures on Linux systems whose logical CPU IDs contain gaps. 
Kategorie: Hacking & Security
Syndikovat obsah