Agregátor RSS
New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege boundary between a cPanel account and the server's administrative database identity. It shipped in a targeted security release that closes two other routes past account boundaries.
The database bug is tracked as CVE-2026-58048 (CVSS 4.0 score: 9.4) and affects Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
SlideRshow, prohlížeč fotek, ale i jejich organizér a prezentátor
Edvard Rejthar na blogu zaměstnanců CZ.NIC představil svou aplikaci SlideRshow (GitHub). Funguje jako prohlížeč fotek, ale i jako jejich organizér a prezentátor. Neinstaluje se, běží přímo v prohlížeči. Bez serveru. Offline.
Kategorie: GNU/Linux & BSD
SketchForge je povedený webový CAD pro začátečníky v 3D tisku. Spustíte ho na vlastním PC nebo serveru
Jednoduchý webový Tinkercad od Autodesku patří i po letech k nejoblíbenějším editorům pro 3D tisk. Sice i nadále platí, že každý modelář udělá nejlépe, když se hned na začátku naučí přinejmenším základy klasického CAD modelování, ale sčítání a odečítání kostiček v Tinkercadu zase pochopí i ...
Kategorie: IT News
Kermit má 45 let. Vydán C-Kermit 11
Kermit, tj. protokol pro přenos souborů, vznikl před 45 lety. Při této příležitosti byla po 15 letech od vydání poslední stabilní verze 9.0.302 vydána nová stabilní verze 11 implementace C-Kermit. S podporou IPv6.
Kategorie: GNU/Linux & BSD
20 let Pandoc
První verze konverzního nástroje Pandoc byla vydána před 20 lety. Jeho autor John MacFarlane při tomto výročí rekapituluje jednotlivé etapy vývoje a přidávání nových funkcí – rozšíření nejen Markdownu a podporu mnoha dalších formátů.
Kategorie: GNU/Linux & BSD
DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT
A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims' browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager.
"The first stage drops a steganographic PNG image into the browser's cache, retrieves its hidden content, and executes the second
Kategorie: Hacking & Security
DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT
A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims' browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager.
"The first stage drops a steganographic PNG image into the browser's cache, retrieves its hidden content, and executes the secondRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Výkonný domácí NAS zlevnil na osm tisíc. Ugreen má až 16 GB RAM a přehraje i videa
Výborný NAS Ugreen NASync DXP2800 zlevnil na 8100 Kč, běžně stojí 10 tisíc. • Pojme dva plotnové disky a dvě NVMe SSD. • Díky rychlému čipu, až 16 GB RAM a Dockeru poslouží i jako domácí server.
Kategorie: IT News
Ušetřete 30 %: Windows 11 Pro jen za €22,50 a Office 2024 Pro za €17,15 – akce Back to school Goodoffer24
Využijte obrovské výhody ze skvělých cen softwaru od Goodoffer24.com, například za zcela novou verzi kancelářského balíku Office 2024 Pro, nebo Windows 11 Pro.
Kategorie: GNU/Linux & BSD
Čínský výrobce zvládl „X670 XPANSION KIT“ levněji, dostupně a lépe než ASRock
Pamatujete, jak roku 2023 přiletěly titulky o kartě, která z B650 desky udělá X670? Kartu, která byla kompatibilní s pár deskami ASRocku a nikdy nevyšla? Tak noname Číňan to zvládl lépe a bez omezení…
Kategorie: IT News
Ušetřete 30 %: Windows 11 Pro jen za €22,50 a Office 2024 Pro za €17,15 – akce Back to school Goodoffer24
Využijte obrovské výhody ze skvělých cen softwaru od Goodoffer24.com, například za zcela novou verzi kancelářského balíku Office 2024 Pro, nebo Windows 11 Pro.
Kategorie: GNU/Linux & BSD
Vodafone láká studenty na mobilní tarify. K vybraným přidá AirPods 4 za symbolickou 1 Kč
Kategorie: IT News
CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the wild.
The vulnerability, tracked as CVE-2026-18577 (CVSS score: 8.2), is a case of incomplete patching for CVE-2026-18556 (CVSS score: 8.2) that allows
Kategorie: Hacking & Security
CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the wild.
The vulnerability, tracked as CVE-2026-18577 (CVSS score: 8.2), is a case of incomplete patching for CVE-2026-18556 (CVSS score: 8.2) that allows Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Computer 8/26: otestovali jsme levné domácí NASy
Jste poslední, kdo rozumí počítačům • Aplikace pro spokojenou domácnost • Jak nakupovat pomocí AI
Kategorie: IT News
El Niño by mohlo přepsat veškeré historické rekordy. Pokud vyjdou odhady, příští rok nás čeká ještě větší peklo
Mimořádně silné El Niño může drasticky přepsat dosavadní historické rekordy • Kombinace klimatických změn a horka z oceánu extrémně rozpálí rok 2027 • Katastrofální sucha a povodně způsobí obrovské škody lidstvu i ekosystémům
Kategorie: IT News
Samsung zavedl pětiletky, kdo chce mít paměti jisté, musí objednat na 5 let
Na pět let předem musejí zákazníci objednávat, pokud chtějí mít jisté, že jim Samsung dodá paměti v objemu, který potřebují. V praxi to znamená, že nyní mají zákazníci možnost objednávat na rok 2031…
Kategorie: IT News
Cloudflare has mostly ditched third party security tools, suggests not trying that at home
Cloudflare has used AI to automate processing of incoming reports to its bug bounty program for $58 a month using Anthropic’s Claude Sonnet model and chose it partly because using the AI company’s security-specific Mythos model would burn through around $200,000 a month to do the same job. The company’s chief security officer (CSO) Grant Bourzikas shared those numbers with The Register last week during a press lunch in Sydney, Australia, where he said Cloudflare used to manually process all incoming bug reports. Sonnet now sifts through submissions, assesses them to ensure they aren’t duplicates, and evaluates the likelihood each represents something worthy of human consideration. Bourzikas said the result is a more efficient bug bounty program that requires less scutwork, and proof that AI users need to learn how to match the right model to the right job. The CSO said Cloudflare gained experience making those matches while creating over 200 autonomous agents it uses to handle its own security needs – and which have seen the company ditch almost all third-party security tools and replace them with home-grown applications, some coded with help from AI. The CSO recommended not trying that at home, saying that Cloudflare’s business and unique infosec challenges mean its buy vs. build calculus is different from other organizations’. “We have expertise in building security software,” he said. “That's why I would just want to make sure we've got one takeaway from this: We are not believers in the SaaSpocalypse. We do not think every bank on the planet should start building all their own software systems.” Stephanie Cohen, Cloudflare’s Chief Strategy Officer, then chimed in with her view that AI will mean the way vendors work with their customers will “fundamentally change” away from selling packaged software. She thinks vendors will instead place forward-deployed engineers at their clients and charge them with “constantly making software that works for you.” Cohen explained Cloudflare’s recent round of 1,100 job cuts as a similar AI-induced change, because some of the people let go were in roles she said “make no sense” now that AI enables more automation and different styles of customer engagements. She added her “guess” that Cloudflare will end up with the same headcount as it did before the layoffs. But Bourzikas added his view that even some early-career IT pros don’t have the skills Cloudflare now needs, such as developers with five to ten years’ experience, because when he is using AI to develop a new piece of software, he can describe what he wants but that desire can be lost in translation when explaining it to a coder. He said a very recent college graduate with a year of experience, but excellent skills writing potent prompts, can be more appropriate for some jobs. Kindly building a business model for AI While Cloudflare enjoys using AI, Cohen thinks the technology doesn’t have a business model. Today’s web, she said, thrives on an advertising-based business model. While AI companies are making billions from subscriptions, she feels they are yet to properly address the fact that they do not pay to access most of the content scraped to feed their large language models and search services. Some of those services, such as Google's AI-powered search, deliver fewer clicks to publishers and therefore make it harder for them to monetize their content. Cloudflare is offering itself as an intermediary to build that business model for publishers and AI companies alike, by using the fact it already sits between users and content providers. The company hopes to offer AI companies the chance to pay publishers to access their content, possibly using micropayments. Cloudflare will of course charge for this service. The Register put it to Cohen that many organizations have been burned, often multiple times, by big tech companies that make themselves all-but essential parts of an ecosystem and then change the rules. We pointed out that social media platforms can redirect traffic on a whim, and sometimes close e-commerce companies’ accounts with little warning and scant chance of appealing to secure restoration. Changes to search engine algorithms can make a once-prominent website invisible. We therefore asked why publishers or content creators should trust Cloudflare’s ambition to run a content tollbooth, given it would create a relationship ripe for future exploitation. Cohen pointed to the company choosing to add SSL connections for all customers, an act she said was an “expensive choice” but one that also reflects Cloudflare’s desire to build a better internet. Later at the event, she shared her view that Silicon Valley companies often make the mistake of thinking that people want internet companies to relentlessly optimize products and services. “Most people aren't working 20 hours a day and don't want to outsource everything,” she said, before observing that on her travels she often sees people shopping in actual real-world stores because they enjoy that experience and find it valuable – never mind that an e-tailer might offer a better price. For the record, and in the context of Cloudflare’s content intermediary ambitions, we note that the company calls San Francisco home. ®
Kategorie: Viry a Červi
Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. [...]
Kategorie: Hacking & Security
New Pass-ta-key attacks let malware hijack Google-synced passkeys
Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager's synced passkeys to take over accounts, bypass user verification, and extract passkey private keys. [...]
Kategorie: Hacking & Security
- « první
- ‹ předchozí
- …
- 27
- 28
- 29
- 30
- 31
- 32
- 33
- 34
- 35
- …
- následující ›
- poslední »



