Agregátor RSS
Superdělo HATS mělo zasahovat cíle vzdálené přes 1 600 km. Dnes slouží v mnohem skromnější, ale současně velmi užitečné roli. Z futuristické zbraně vznikla specializovaná testovací platforma, která využívá extrémní zrychlení superdělem k získávání kvalitních dat pro vývoj hypersonických hlavic.
Uživatel, který si od Nvidie objednal GeForce RTX 5090 za $4600, má smůlu. Dozvěděl se totiž, že za tuto cenu mu již nebude prodána a pokud ji chce, musí $574 připlatit…
A Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims. [...]
Nearly a dozen flaws, some critical, in major AI agent frameworks that enterprises use to build apps reveal a security failure that extends beyond prompt injection - or any single model - according to Check Point researchers. “Our research shows a deeper failure: in many agentic frameworks, prompt-controlled content can cross the boundary into trusted framework logic itself,” Yarden Porat and Shahar Tal note in a write-up about a Wednesday Black Hat talk on post-injection exploitation across AI agent frameworks, which they also discussed with The Register. “A bug in an agent framework isn't a bug in one product - it's a bug in the layer a whole category of AI apps runs on,” Tal told us. “And the agent needs no dangerous tools to be turned against you: reading the wrong document is enough. We’re building this layer faster than we know how to defend it.”
The researchers spent a year trying to break various frameworks that enterprises use including LangChain, LangGraph, CrewAI, AutoGen, Microsoft Agent Framework, and Google ADK. And across these frameworks, the team found and disclosed 11 vulnerabilities. “Almost none of it was a completely new bug class,” Tal said. “That's insecure deserialization, server-side request forgeries, path traversals, use-after-free. These are bugs that we learned to fix 20 years ago, and they're sitting underneath agents that now read your inbox, or update your database.” These are old types of threats, and the model isn’t the weak link, he added. The failure exists in the “plumbing around the model, and we think this has been overlooked,” Tal told us. “There’s a lot of research going into prompt injection and defenses, which are important, but that’s just the beginning.” Defenders should assume prompt injection, according to the researchers. The bug is what the framework does with the injection - and in these cases, the threat hunters found that the frameworks often fail to keep attacker-controlled content in the data plane. This allows it to influence trusted orchestration, memory, state, routing, and system instructions. For example, the duo found a critical checkpoint deserialization bug in Microsoft Agent Framework that led to remote code execution. “Agents have checkpoints, which are a way for them to save their state or rewind to an earlier point,” Tal explained. These checkpoints are saved snapshots of an agent's state, or task progress at a specific moment, and they serialize data - such as conversation history - into persistent storage, so if an error occurs, the system reloads this saved state instead of starting from scratch. In this case, Check Point’s team found an insecure deserialization issue where, via prompt injection, the agent loaded untrusted checkpoint data, and this could allow attackers to execute malicious code on the system. “One person's message plants the payload, and then a different person rewinds their own session, which triggers the payload, and now the attacker has a shell on that server,” Tal said. Microsoft recognized the researchers’ findings, paid a $10,000 bug bounty and fixed the issue. But because the framework wasn’t a generally available product when Check Point found the flaw, Microsoft did not issue a CVE. Microsoft told us that it appreciated the researchers reporting the vulnerability. “We have released protections to harden the Agent Framework and prevent the concrete exploitation path demonstrated in the proof of concept,” a spokesperson told The Register. “In addition, we updated the specific checkpoint file with additional language to define the security boundary.” The duo also found flaws in Google ADK (agent development kit). However, Google responded differently, the researchers told us, and did not completely fix the vulnerability or issue a CVE. “ADK ships a built-in development assistant that can write files, and it stays reachable over the HTTP API even though it is hidden from the app listing,” Porat told us. To break this trust boundary, an attacker opens a session, asks ADK to write an agent whose Python code runs at import time, and then asks the server to run the agent, he explained. The server then imports the file and executes the attacker’s code. “There is no authentication on that API by default, and adk deploy cloud_run publishes the same API, so on a default Cloud Run deployment it is reachable without credentials,” Porat said. “From there it reaches the environment's API keys and the container's Google Cloud service account." Google did not respond to The Register’s inquiries. But according to Check Point, Google initially deemed the issue not a bug. “We argued the consequence rather than the mechanism: code execution on that container reaches the environment's API keys and the container's Google Cloud service account, which is secret theft, not a developer inconvenience,” Porat said. Google ultimately paid a $3,133.70 bounty and issued a partial fix, we’re told. In total, the bug hunters received $17,133.70 in rewards for their efforts. And this isn’t a story about one vendor or framework doing a “particularly bad job,” Tal said. “If one was an outlier, this would be a story about that one vendor,” he added. “Our finding is that the same bug classes turn up in all of them.” ®
Linux runs cloud platforms, containerized applications, and business-critical servers. It is the engine that powers much of today’s business infrastructure. Stability, flexibility, and performance. It's the operating system of choice for organizations managing large-scale digital environments.
Not every security incident begins with sophisticated malware or a compromised server. Sometimes it is nothing more than a developer pushing code before the end of the day. A configuration file slips into the commit. A temporary access token stays in a testing script. Someone assumes the value will be removed later and forgets about it.
Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate network. [...]
Until recently, it was common for companies and organizations to engage in “tokenmaxxing” — that is, maximizing their use of AI. But with AI costs going up, companies are now looking to save money, a trend underscored by a recent Microsoft decision to limit AI use by its employees.
“As we ramp up our use of GitHub Copilot to achieve our goals, we all need to be mindful of how we consume tokens,” Microsoft Executive Vice President Jay Parikh wrote in an email to the company’s employees.
Starting now, each department at Microsoft will be allocated a certain pool of tokens, with usage then adjusted up or down as needed.
The change prompted concern among some employees. “It’s very telling that a company that has invested so much in AI and subsidized so much AI inference is now advising its own employees to cut back on spending,” an anonymous Microsoft employee said in a comment to 404 Media.
A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks.
The server-side gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake software download. Microsoft Swati Khandelwalhttp://www.blogger.com/profile/ [email protected]
OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes.
To that end, it banned a coordinated network of ChatGPT accounts likely originating from Southeast Asia and operating from the city of Poipet, a region with extensiveRavie Lakshmananhttp://www.blogger.com/profile/ [email protected]
A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software. [...]
The memory crisis is getting worse for Apple, which is struggling to get enough memory chips together for its upcoming iPhone 18 Pro series smartphones. That’s according to tech journalist Tim Culpan.
As he details it, Apple and its assembly partners are still attempting to secure sufficient quantities of memory, and though they’re confident they can meet initial demand once the devices are introduced, they apparently remain concerned that wait times could rapidly extend as retail inventory evaporates.
Apple’s manufacturing process compounds the problem. The A20 processor is packaged with memory using a new TSMC process, meaning processors are reportedly piling up while manufacturers wait for memory chips. You should read Culpan’s report to get the full picture.
What’s the frequency?
You don’t need to read between the lines to see the challenge. Despite demand for TSMC’s new processors, Apple seems to have been able to secure the supply it needs. But when it comes to churning out the final packaged chips memory, supply constraints have created significant obstacles to producing in quantity.
This is bad for Apple, particularly as the challenge doesn’t appear to be confined to iPhones; customers are experiencing delays getting new Macs. “Many new orders are now not arriving until September,” Bloomberg’s Mark Gurman wrote earlier this week.
It isn’t just Apple that will be impacted by the AI-driven memory drought. The scale of Apple’s orders is among the greatest in the industry, and if its product plans are feeling the pain, every other manufacturer will be feeling it as well.
Conscious uncoupling
This is certainly in tune with expectations voiced at the beginning of the year when Ranjit Atwal, senior director analyst at Gartner, warned: “This is the steepest contraction in device shipments witnessed in over a decade. Higher prices will narrow the range of devices available, prompting buyers to hold on to devices for longer, fundamentally altering upgrade cycles.”
Gartner in February predicted a 10.4% decline in global PC shipments and an 8.4% drop in smartphone shipments as a result. The analyst also predicted a 130% surge in combined memory and SSD storage prices by the end of this year, with steep product price increases to follow. Recent data from IDC, Gartner, Counterpoint, and Omdia confirm PC market declines, but only at around 4% (the estimates vary).
Today’s report from Culpan suggests we’ve not yet experienced the full extent of this decline — hinting that while the initial fall reflected price, the next impact will be defined by lack of supply. While this hurts big brands like Apple, smaller entities could be left high and dry.
When the chips are down
It is interesting to reprise Atwal’s warning in February that, “the sub-$500 entry-level PC segment will disappear by 2028,” as this seems to be what’s happening. That’s something long-time Mac users like me find particularly ironic, given it was only this year Apple briefly offered up its superbly priced $499 MacBook Neo. The industry direction we’re seeing now suggests we’ll never see that again, though the success of that device gave Apple a phenomenal 28.7% increase in sales in its just-revealed June quarter.
Despite memory supply challenges, Apple seems to be faring fairly well, with market share increasing across its business. Counterpoint data reveals that Apple has achieved an astonishing 65% share of the premium smartphone market. In part, that’s because as an existing premium brand, Apple was able to better absorb rising memory costs through higher margins and reduced promotions. Realistically, this means we can expect an overall increase in iPhone prices when the new range is announced up to $300 more, Jeff Pu, of GF Securities, recently claimed.
Building the moat
Once again, what’s sustainable but difficult for larger brands such as Apple is existential disaster for smaller players — and it’s only now a matter of time before we see some real blood. That’s particularly true in smart home and device markets, where manufacturers lack the margins to sustain higher memory prices while delivering products customers can afford. A recent Global Electronics Association report tells us 62% of electronics manufacturers are already experiencing constrained availability or extended lead times. It also tells us 82% expect rising prices, including 33% who cite a “significant increase.”
This is already being felt by consumer and business users, as networking equipment is experiencing significant shipping delays. So, while we may find ourselves waiting a month or more for an iPhone, the wait for new routers, external storage devices, and home automation systems could be even longer once available inventories disappear.
This doesn’t appear to be a short-term challenge; a recent Digitimes report warns that vendors have already sold their entire allocation of memory capacity for 2027.
Don’t even get me started on the likely impact on the military and defense markets as high-performance memory, storage, and processor supplies become constrained. Just like declining river levels in Europe, lack of memory threatens severe disruption. With so much turbulence impacting the tech economy, all we need now is for one or more of theinvestor-supported AI companies that have helped create the memory shortages to default on loan payments.
Got to keep the customer satisfied
Eager to protect sales, Apple recently introduced the Apple Upgrade leasing service in the US. This should enable consumers to purchase new devices at prices more sustainable to them over time. Apple isn’t alone in taking such action, which will inevitably extend beyond America.
“OEMs are expanding financing, trade-in and buyback programs to improve affordability,” said Counterpoint’s Harshit Rastogi. “Samsung has also expanded its Galaxy Forever program to several markets to make flagship devices more accessible.”
Such schemes are all well and good, of course. Consumers will embrace them in hopes of a better tomorrow. But the tech industry is not immune to the wider constellation of existential challenges impacting economic environments.
In the end, if Apple, the industry’s biggest buyer of advanced components, is struggling to secure memory, the rest of the electronics sector is likely to face even greater challenges. For consumers, the initial impacts will be longer waits and higher prices. But the longer term consequences could be slower innovation and increased consolidation across the industry.
You can follow me on social media! Join me on BlueSky, LinkedIn, Mastodon and subscribe to The Core.
Microsoft potvrdil, že optimalizaci Windows 11 bere vážně. • Jde o rozsáhlou iniciativu, ve které se koordinují všechny týmy. • Přemýšlí se o všem od uživatelského prostředí až po plánování na úrovni jádra.
A critical vulnerability in IBM-owned, low-code AI builder Langflow lets unauthenticated attackers execute code remotely on vulnerable default deployments, potentially putting organizations running those instances at immediate risk. The Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added CVE-2026-9198 to its Known Exploited Vulnerabilities catalog after identifying evidence of active exploitation and urged organizations to apply the vendor's mitigation guidance as soon as possible. IBM says the flaw affects Langflow OSS versions 1.0.0 through 1.10.0 and recommends upgrading to version 1.10.1 or later; at the time of writing, the most recent version is 1.11.2. Langflow, for those unfamiliar, is one of the more accessible AI agent builders on the market, as our hands-on look at the tool earlier this year demonstrated. It’s available on Linux, Windows, and macOS, and is basically an end-to-end, drag-and-drop GUI where users can construct agent workflows without having to know much, if anything, about the underlying code. IBM owns the platform now, but Langflow was originally developed by Logspace, which was acquired by DataStax in 2024 before IBM scooped up DataStax, and Langflow with it, in 2025. The acquisition of DataStax and its tools like Langflow by IBM paved the way for Langflow to be integrated into watsonx.ai, IBM’s AI development studio, as a piece of middleware extending watsonx.ai’s capabilities. The ownership changes, however, didn't stop the critical flaw from making it into production releases before it was finally fixed. According to IBM, the vulnerability affects default Langflow deployments and combines two issues that, when chained, allow an unauthenticated attacker to execute code remotely. First, there’s the matter of an auto-login endpoint in default deployments that’s willing to mint superuser tokens to any network caller. Combine those easily obtained superuser rights with the second issue, a code validation endpoint that’ll run any old Python code thrown at it, and you’ve got a recipe for someone taking over your entire Langflow server, or worse. The CVE itself was published on July 17, meaning that it hasn’t taken long for bad actors to realize what they could do with RCE on any system hosting a default Langflow deployment with auto login enabled and that code validation endpoint left accessible on a network. Langflow itself isn’t a vibe-coding platform, instead serving as an interface for building agentic and RAG workflows, so don’t blame vibe coding or no-code security failures for this one. Instead, what we appear to have is a standard case of how default configuration deployments can easily be a disaster. It’s unknown how extensively exploited this vulnerability is; we’ve reached out to IBM to learn more. ®
The U.S. Cybersecurity and Infrastructure Security Agency is giving federal agencies three days to mitigate vulnerabilities in IBM Langflow, N-central, and Apache Tomcat, all actively exploited. [...]
Bezdrátová sluchátka, to nejsou jen populární a módní kapesní modely True Wireless. Například pro cestování jsou vhodnější velké modely s aktivním potlačením hluku. Poradíme, jaké máte možnosti a na co si dát pozor.
Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on underground cybercrime forums and messaging platforms.
One such service, Poison Claude, claims to offer access to Anthropic's large language models (LLMs), including Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6.
"Advertisements for Poison Claude Ravie Lakshmananhttp://www.blogger.com/profile/ [email protected]
Two security flaws in Paperclip could let attackers execute commands on a network server or a developer's computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on importing a malicious agent and starting it.
A third flaw could expose sensitive data and control-plane details through application programming interface (API) routesSwati Khandelwalhttp://www.blogger.com/profile/ [email protected]
Společnost Cloudflare představila Cloudflare OS (GitHub), tj. open source platformu navrženou pro integraci umělé inteligence (agentů) přímo do pracovních procesů organizací.
|