Agregátor RSS
Pokročilí uživatelé mohli instalovat druhou lištu do Windows 11 pomocí nástrojů třetích stran. Nyní přibyla i do oficiálního balíku PowerToys, kde rozšiřuje již tak užitečnou Paletu příkazů.
AI is becoming both an attack tool and a high-value target, with attacks by AI-enabled adversaries rising 89 percent in 2025, according to CrowdStrike. The security firm's annual Threat Hunting Report details criminal gangs and nation states using AI throughout the attack chain. Attackers are also targeting organizations' AI infrastructure and poisoning popular software packages to compromise their users. "AI is both the weapon and the target," CrowdStrike counter adversary division senior VP Adam Meyers told reporters. "AI is a high-value attack surface, and it's being used by more and more threat actors." These attacks include LLMjacking, in which criminals steal corporate credentials to access frontier-model APIs, and cost harvesting – deliberately inflating a victim's AI usage to run up its bill. In one campaign, CrowdStrike documented a token thief sending about 200,000 API requests in just two minutes. The security vendor's threat hunting team now tracks AI agent-triggered leads at 2.5x the rate of human-triggered threats, and Meyers said this increased volume remains true across both government-backed goons and financially motivated criminals. CrowdStrike tracks more than 290 adversary groups, having added about ten this year. Of the 290, a North Korean crew it tracks as Famous Chollima – a sub-unit operating under the Lazarus Group umbrella and best known for its fake IT worker scams – "demonstrated the most advanced AI usage" over the second half of 2025 and first half of 2026, according to the report. This government-backed crew created "entire fake companies with AI-generated websites, GitHub accounts, and email infrastructure to support insider threat operations," the authors wrote. AI supply-chain compromise was the second most common MITRE ATLAS technique used by attackers to gain initial access, and Famous Chollima's campaign targeting AI-focused development environments "was one of the most sophisticated examples of this technique in practice," the report noted. This included a supply-chain attack in January and February targeting cryptocurrency and blockchain companies. In these attacks, the Norks published trojanized repositories, primarily hosted on GitHub, that contained legitimate-looking project files alongside hidden, malicious scripts. When developers opened these repos, malicious scripts automatically executed commands that gave Famous Chollima access to their environments. "AIs themselves are being targeted through that supply chain and through the CI/CD pipelines that they're dependent on," Meyers said. Threat hunters suspect another Lazarus Group offshoot, tracked as Stardust Chollima or Sapphire Sleet, was behind the March Axios supply chain attack. Last week, Amazon attributed four npm compromises over the past 18 months to the same North Korean crew. Meanwhile, a financially motivated crew tracked by CrowdStrike as Altered Spider and elsewhere as TeamPCP targeted developers' AI tools, compromising more than 300 software dependencies in one day. It harvested credentials and secrets before pivoting into cloud environments for theft and extortion. Altered Spider "hits the endpoint in seconds and within minutes, they're inside of the cloud," Meyers said. "It gives you a sense of how quickly they can move throughout that environment, and this is all tied again to software supply chains." Patching window slams shut CrowdStrike argues that AI is helping attackers exploit newly disclosed vulnerabilities at machine speed. From January to June, 88 percent of the exploitation observed by CrowdStrike using public proof-of-concept (PoC) code occurred within 48 hours of the code's release. The company said China-linked groups such as Vault Panda and Genesis Panda moved even faster, launching attacks within 24 hours of disclosure. "Vulnerabilities are weaponized through the use of AI," Meyers said. "This is creating a rich ecosystem of vulnerabilities for attackers to use against various systems, and what this really means is that the 30-day patch window, which frankly, was aspirational, is completely obsolete. We're down to 24-hour, 48-hour patch cycles, and organizations are really struggling under that." Meanwhile, as anyone who follows Microsoft's Patch Tuesday – or any other software vendors' vulnerability disclosures over the past few months – knows, AI is also really good at finding bugs in code. This means more CVEs and more patching for sysadmins racing to fix flaws before miscreants reverse-engineer the updates and develop exploits. "In 2025, there were something like 48,200 CVEs that were registered," Meyers said. "We're already, as of last week, at 43,000 for this year. We're not even into August yet, and we're already coming very close to the number from last year." June alone saw more than 7,600 software bugs reported and tracked through CVEs, he added. "The vulnerability ecosystem is going to be the big story for the next couple of months." ®
N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers.
Its first fix was incomplete. CVE-2026-18577 affects N-central builds prior to 2026.3.1.7. N-able shipped build 2026.3.1.7 on August 2 as the first unaffected version.
N-central is the remote monitoring and management platform
N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers.
Its first fix was incomplete. CVE-2026-18577 affects N-central builds prior to 2026.3.1.7. N-able shipped build 2026.3.1.7 on August 2 as the first unaffected version.
N-central is the remote monitoring and management platform Swati Khandelwalhttp://www.blogger.com/profile/ [email protected]
Three high-severity security flaws have been disclosed in Hugging Face's Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code on machines that load it, opening the artificial intelligence (AI) supply chain to security risk.
"These vulnerabilities are bypassing trust_remote_code, the safeguard designed to stop unreviewed code from running in the
Three high-severity security flaws have been disclosed in Hugging Face's Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code on machines that load it, opening the artificial intelligence (AI) supply chain to security risk.
"These vulnerabilities are bypassing trust_remote_code, the safeguard designed to stop unreviewed code from running in the Ravie Lakshmananhttp://www.blogger.com/profile/ [email protected]
Spontánní kolony vznikají řetězovým zesílením brzdění nepozorných řidičů • Časté přejíždění mezi jízdními pruhy narušuje plynulost a vyvolává zácpy • Jediné autonomní vozidlo dokáže efektivně stabilizovat celý dopravní proud
Některé procesory s architekturou Zen 6 budou obsahovat tak zvaná Zen LP jádra pro snížení energetických nároků. Jejich podoba je docela zajímavá, neboť přebírají prvky z pěti různých procesorových generací…
Příspěvek na blogu Google Security popisuje, jak tým Chrome Security využívá umělou inteligenci k zásadnímu zrychlení a zlepšení procesu odhalování, třídění a opravování bezpečnostních chyb v prohlížeči Chrome. Díky AI byla nalezena kritická chyba, která byla v kódu přes 13 let. Ve verzích Chrome 149 a 150 bylo opraveno více chyb než v předchozích 23 verzích dohromady.
OpenAI has revealed Astra, an unreleased model designed to tackle complex, long-running tasks, after an internal version produced ten significant advances in mathematics and theoretical computer science. [...]
ADATA SC750: Výkonný SSD disk s rozměry flashdisku. Zasloužený klid na dovolené: Cloudová správa Nebula řeší dohled nad firemní sítí. Největší změna spisové služby za 20 let: odklad legislativy není důvod zastavit modernizaci. Čína podle zdrojů zahájila výrobu zařízení pro domácí produkci vyspělých čipů. Apple se stal druhou firmou, jejíž tržní hodnota přesáhla 5 bilionů dolarů. Neočekávaná magnetická odezva v atomových kontaktech ze zlata a stříbra je v rozporu s dosavadní teorií. Fortinet rozšiřuje řešení FortiEndpoint o nové funkce pro éru AI.
Někteří zaměstnanci rizikových profesí se sami obírají o peníze, které by jim umožnili jít do penze dřív. Získat výhodu je přitom snadné.
Nově si budete moci automaticky odkládat drobné z plateb a okamžitě poslat až milion korun. Zpřísní se ale pravidla pro reklamace karetních transakcí. Upřesňují se podmínky používání virtuální asistentky Anety a obchodování s investicemi.
V tomto vydání Postřehů se podíváme na AI model, který si sám nahrál malware na PyPI, na severokorejské útoky na npm balíčky, kritické díry ve VMware, ruský zero-day v Outlooku a únik dat u Coca-Coly.
Společnost Canonical představila Enterprise Store, nové řešení dostupné v rámci předplatného Ubuntu Pro. Experimentální systém XIOS přináší unixová desktopová prostředí na mobilní platformu firmy Apple.
Byť šéf TSMC od počátku hovořil o procesu Intel 18A jako o konkurentovi TSMC N3P, CEO Intelu tvrdil, že je na úrovni 2nm procesu TSMC nebo vyšší. Ve skutečnosti sotva dotáhl 3nm proces Samsungu…
aneb jak se mě pokoušel vyděsit jeden mykologický influencer
V horkých letních dnech sahá tisk po lehčích tématech. Zde by to mohlo být něco o psychologickém jevu známém pod názvem pareidolie, při kterém fantazie z různých podnětů (mraky na obloze, přirozené tvary kamenů aj.) vytváří obrazy, např. zvířata, lidské tváře a jiné smysluplné obrazy. Představa, že by mohl existovat artefakt z mladého paleolitu zobrazující lidskou tvář, může být pro někoho šokující, přitom taková zobrazení existují. Např. portrét ženy nalezený v Dolních Věstonicích.
Oxid uhličitý v atmosféře přebývá a strategicky významný grafit zase schází. Nová technologie z kalifornského Berkeley řeší dvě tyhle mouchy jednou ranou. Vyvinuli slibnou metodu pro přeměnu oxidu uhličitého zachyceného z atmosféry na grafit. Je to grafit ze vzduchu. Mohla by se z toho stát alternativa těžby grafitu.
|