Agregátor RSS

Něco jako Wikipedie pro chytrou domácnost. Vzniká databáze produktů kompatibilních s Home Assistantem

Živě.cz - 28 Červenec, 2026 - 18:45
Vzniká centrální místo, kde budou všechny informace o chytré domácnosti. • Žádný marketing, jen reálná anonymizovaná data uživatelů Home Assistantu. • Každý se dozví, jak se produkty připojují, zda běží lokálně a co všechno umožňují.
Kategorie: IT News

AI has become Apple’s latest bug detective

Computerworld.com [Hacking News] - 28 Červenec, 2026 - 18:17

Artificial intelligence is becoming a force multiplier for Apple security research. Apple’s latest 26.5.2 software update includes patches for a record number of bugs — many of them identified by security researchers using AI-assisted tools.

A record haul of fixes

The numbers tell the story. Apple fixed 87 security vulnerabilities in iOS and iPadOS 26.6, along with an additional 155 patches for Macs. Roughly 100 flaws have been patched in each of Apple’s other operating systems: watchOS, tvOS, and visionOS. Taken together, these represent record numbers for an Apple security update. 

This is only the beginning. The scale of the release echoes the impact AI coding agents are already having on security research and may well reflect Apple’s Project Glasswing research with Anthropic and others to use AI to identify software vulnerabilities. 

Apple’s use of AI for security research is visible in the official release note. Read through it and you’ll see multiple credits to Claude, Codex, and AI adjacent tools, labs, and researchers. These tools identified flaws across Apple’s systems, including in WebKit, WebDAV, and WebKit Storage.

For good and ill

It’s a neat illustration of the sea change under way as AI adoption accelerates. This release highlights how security researchers are leaning into AI tools to check platform security just as heavily as attackers are. One fix in today’s release is credited to researchers from Calif.io, who some may recall used Anthropic’s Mythos Preview model to create a working macOS kernel memory corruption exploit in just a few days.

The release is proof positive that while AI can be used to identify vulnerabilities to undermine protection, it can also be used to identify opportunities to further secure the platforms. It is also true that as AI use across the security industry grows, the number of flaws identified will also accelerate; it’s doubtful we’ll ever reach a point at which there are no flaws at all. Apple is likely to beef up its own internal observability tools following the acquisition of SigLens, which might help it identify even more bugs using AI.

Don’t delay, install today

None of these matters much, though, if the security patches never get installed — and the delay between security patch release and installation represents a huge opportunity for attackers. Recent analysis from Fleet Device Management found that 79% of organizations take more than a day to deploy critical security patches, even as attackers increasingly exploit vulnerabilities within hours of disclosure. The same report also showed something else to worry about: AI tools are spreading fast across the enterprise, often without the version control or auditability that would let anyone track how they’re actually being used.

Despite their number, the tally of fixes Apple has published isn’t the end of the story. In this case, while Apple has published its latest fixes, how many of those vulnerabilities have already been abused in the weeks between discovery and security patch release? More to the point, how swiftly will Apple’s installed base update devices now, and how many attackers will use that delay to dive in and do the damage?

It’s a security arms race

Adam Boynton, senior security strategy manager at Jamf noted that one vulnerability, CVE-2026-43810, can be exploited by a remote user to corrupt kernel memory. “The WebKit fixes are easy to read as a phishing story, when they are actually something slightly different,” he said.

“The raw material for targeted spyware is browser engine memory corruption, and those chains are expensive enough that they get pointed at specific people like senior executives, journalists, anyone whose access justifies the cost. That’s the honest reason to update promptly rather than eventually. 

“In other words, this update matters less for its raw numbers than for what those numbers represent: an arms race between defenders and attackers who are both, increasingly, running the same kind of tools,” Boynton said.

You can follow me on social media! Join me on BlueSky,  LinkedInMastodon and subscribe to The Core.

Kategorie: Hacking & Security

DEF CON bans Meta-style 'pervert glasses'

The Register - Anti-Virus - 28 Červenec, 2026 - 18:05
Ahead of DEF CON 2026 opening its doors in Las Vegas next week, conference organizers said they have imposed a ban on “Meta-style glasses with recording capabilities.” Statements made via its social media channels went on to say that no exceptions will be made for those using the devices with prescription lenses. “Be sure to pack non-violating eyewear if you need them,” DEF CON said, before directing delegates to the conference’s official photo policy. That policy has not been updated since 2023, predating the recent growth of camera-equipped eyewear developed by Meta with EssilorLuxottica under its Ray-Ban and Oakley brands. It states that public photography is permitted but with several caveats that essentially prohibit capturing the image of anyone, except on-stage speakers, unless the photographer obtains consent from the subject(s). EFF director of cybersecurity Eva Galperin welcomed the decision, saying: “Love to see a ‘no pervert glasses’ policy at DEF CON.” The conference’s reminder follows similar moves from other major organizers and promoters. Monopoly Events banned the same style of smart glasses from its shows, which include UK Comic Cons, in recent days. “After a consultation period, we can no longer permit the wearing of any recording device at our events,” it stated last week. “The vast majority of the talent and agents at our events felt that these were a violation of their privacy and were damaging and spoiling the interactions at the tables. “Several expressed concerns that they might not continue to attend in-person events if they were being recorded in secret. “We had similar feedback from event attendees, many of whom are not comfortable with the knowledge that other convention goers might be filming them without consent.” The event management company said that anyone caught wearing glasses with recording capabilities may be asked to leave the show and forfeit any unfulfilled autographs or photographs they had purchased. Similarly, Scottish ferry operator CalMac temporarily suspended unplanned visits to ships' bridges of its ships after a passenger wearing recording glasses made crew and passengers feel uncomfortable while filming during a crossing in June, the Ayrshire Weekly Press reported. Growing privacy concerns Originally pitched as a convenient tool for recording everyday moments without needing to occupy one’s hands with a phone or camera, Meta’s smart glasses quickly attracted a mixed reception. Old fans of the Google Glass project were enamored by Meta’s take on the concept, more than ten years after the Chocolate Factory debuted its chunkier, costlier wearable, which was swiftly axed after two years. Meta’s glasses, and crucially their recording capabilities, are considerably more clandestine than Google Glass', appearing to many as a normal set of specs. Only when you inspect the frame from a much closer perspective does the embedded camera become more apparent. The devices have become associated with creepy behavior. A quick search for “Meta glasses privacy violations” will throw up countless examples of questionable conduct from glasses-wearers, typically reported by women and children. While photography and videography in public spaces are widely permitted for casual use, smart recording glasses make the activity much more discreet. The Register has heard that such devices can be paired with unsophisticated apps to dox passersby in seconds, and have inspired separate projects to alert Android users to nearby glasses-wearers using Bluetooth signals. Meta is also facing scrutiny from the UK’s data protection watchdog, including over cross-border data flows. The watchdog’s questions follow reports originating in Sweden that Kenya-based contractors reviewing footage from wearers were exposed to some of their more private moments. Human reviewers based in Kenya, who are tasked with labelling images and video to help train Meta’s AI, have reportedly reviewed captures taken from toilet visits, wearers changing their clothes, and users engaging in conversations that revealed alleged wrongdoing. Meta has routinely defended its wearables amid privacy concerns, saying that when they are recording, a light on the frame illuminates to indicate that the camera is active. Further, attempts to cover or otherwise tamper with this light result in the glasses refusing to capture images. The Register contacted Meta for its take on the recent bans of its devices at conferences and will update this article if we hear back. ®
Kategorie: Viry a Červi

AI-found bugs aren't proving any easier to exploit despite the hype

The Register - Anti-Virus - 28 Červenec, 2026 - 17:26
Anthropic's Project Glasswing may have uncovered tens of thousands of potential security flaws, but new research suggests AI-assisted vulnerability discovery has yet to produce the wave of real-world attacks many expected. In research shared with The Register, VulnCheck analyzed 1,061 publicly attributed AI-assisted vulnerability discoveries from Anthropic's Project Glasswing and the Berkeley Vulnerability Research Initiative, then cross-referenced them against its Known Exploited Vulnerability (KEV) database. The result: just 14 vulnerabilities, or 1.3 percent, have been confirmed as exploited in the wild, almost identical to the rate across all vulnerabilities in VulnCheck's dataset. That's a far cry from the narrative that frontier AI is dramatically tilting the balance in attackers' favor by churning out instantly weaponizable bugs. Instead, the data suggests that AI is currently better at increasing the volume of vulnerabilities researchers can uncover than at increasing the proportion that attackers actually exploit. The report takes particular aim at Anthropic's much-publicized Project Glasswing, unveiled in April with warnings that AI-assisted vulnerability discovery could allow attackers to hijack systems, disrupt operations, or steal data. Claude Mythos may have identified 23,019 vulnerability candidates, but there's remarkably little public evidence showing what became of most of them. VulnCheck notes that only 126 have been published as CVEs, that just one has been confirmed exploited in the wild, and that Anthropic's public disclosure record has seen little movement since Project Glasswing launched. But that doesn't mean AI-assisted vulnerability research has failed, according to Patrick Garrity, security researcher at VulnCheck. "AI-assisted vulnerability discovery clearly has value for both attackers and defenders," Garrity wrote. "The data does not suggest that AI-discovered vulnerabilities are inherently more likely to be exploited than those found through traditional methods." Instead, he argues, AI is simply helping researchers discover more flaws, giving defenders an opportunity to patch them before criminals get there. Garrity stopped well short of declaring the threat overblown forever, but he did suggest some of the rhetoric has outpaced reality. "The data so far, including Anthropic's own stalled disclosure ledger, suggests that AI-assisted vulnerability discovery and frontier capabilities have been overhyped relative to the evidence available today," he wrote. "That doesn't mean the risk is imaginary. It means the impact has been real but modest." Meanwhile, attackers haven't exactly been sitting idle. VulnCheck identified 495 known exploited vulnerabilities during the first half of 2026, with content management systems accounting for roughly one-third of them and network edge devices remaining a firm favorite. AI products themselves are also becoming an increasingly attractive target, as attackers look beyond using AI and start hunting for weaknesses in the rapidly expanding AI software stack. In other words, AI may be changing vulnerability research, but it hasn't yet produced the exploitation apocalypse some predicted. ®
Kategorie: Viry a Červi

Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

The Hacker News - 28 Červenec, 2026 - 17:01
A new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its main process. If that happens, Tengu's other persistence mechanisms get another chance to relaunch it. Nozomi Networks Labs observed the dropper reaching its honeypots through Telnet credential brute force. Tengu supports 25 distributed denial-of-service (Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Mak's Weekly Security Roundup: Linux Security Priorities This Week

LinuxSecurity.com - 28 Červenec, 2026 - 16:50
The volume of Linux security advisories remains high across enterprise distributions, but the more difficult task is determining which updates carry the broadest operational risk. Looking across this week's advisory set, one pattern stood out more than any other.
Kategorie: Hacking & Security

24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

The Hacker News - 28 Červenec, 2026 - 16:41
Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management Interface (IPMI) protocol to the public internet. Of the 36,872 internet-exposed server-management interfaces running IPMI, 24,650 have been found to disclose password-derived authentication hashes before login due toRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Is Your SSO Protected Against Modern Credential Attacks?

Bleeping Computer - 28 Červenec, 2026 - 16:00
A compromised SSO login can provide attackers with access to multiple enterprise applications and services. Specops Software explains how stronger passwords, phishing-resistant MFA, and identity hardening help secure modern SSO environments and the applications they protect. [...]
Kategorie: Hacking & Security

Synsira Launches Kind Local Pro with 100% On-Device AI

Computerworld.com [Hacking News] - 28 Červenec, 2026 - 15:57

Operating entirely offline, Kind Local Pro gives individuals local data sovereignty without sacrificing AI performance

Synsira Software is addressing the biggest concern with AI: privacy. Today, the company introduced Kind Local Pro, an AI platform that operates independently of corporate cloud-based LLM models and is available to download onto desktops and laptops. Designed for people and organizations wanting the benefits of AI without sending their data, analysis and queries to external sources, the platform allows users to take control of their information.

Kind Local Pro builds on Synsira’s flagship Kind platform, giving professionals, researchers, communicators, legal teams, educators and organizations a more private way to search and understand their own files using AI. Built to operate locally on a user’s desktop or laptop, Kind Local Pro lets users create collections and ask questions across their materials, with answers generated only from their data and not the open web.

“People want AI to be useful, but they also want to know where their data is going,” said Dr. Jonathan Schaeffer, founder of Synsira Software and creator of Kind. “That is not a small concern. For many people and businesses, it is the whole issue. Kind Local Pro was built for users who want AI on their own terms: private, local and grounded in their own information.”

With Kind Local Pro, users add documents, presentations, research papers, notes, videos, images, email inboxes, audio and other supported files into collections. Once the content is indexed, summarized, tagged and analyzed by Kind AI, they can ask natural-language questions or do fuzzy searching and receive answers with precise citations into the information in those files. If the user’s data does not contain enough information to answer a question, Kind Local Pro is designed to say so rather than invent a response.

The platform is purpose-built for data-sensitive environments:

  • Legal and Compliance: Lawyers can analyze internal memoranda and client files with all analysis private and staying local to their machine
  • Intellectual Property: Agency professionals, influencers, creators and executives can organize proprietary brand assets, manuscripts and corporate strategies with zero risk of their data being used to train public models.
  • Academic Research: Scientists and researchers can search years of papers, drafts and video lecture materials while keeping unpublished work on their own machine.

The product reflects Synsira’s broader view that AI adoption depends on trust, transparency and practical value. Many people remain cautious about AI because of concerns about errors or bias in internet answers, privacy, data training, security and the environmental demands of large-scale cloud computing. Kind Local Pro addresses those concerns by moving the AI experience closer to the user and keeping private data under local control.

“Not every AI task needs to be sent to a massive data center,” said Schaeffer. “Sometimes the smartest place for AI to work is right where the information already lives: on your own computer. Bigger is not always better. Private, practical and accurate is better.”

Kind Local Pro allows for 10,000 files to be uploaded, up to 500 at a time. It is now available for an initial subscription cost of $79 at Kind.Synsira.com. Local Kind Free allows up to 50 files to be uploaded. Both versions are 1.9GB installed plus 6GBs of AI models installed.

A media kit with logos, headshots and screenshots of Kind Local Pro is available here.

About Kind by Synsira

Synsira builds ethical, user-friendly Al products from rigorously evaluated and curated Al models for folks who demand privacy and environmental responsibility in Al. Synsira’s flagship product, Kind, available now at synsira.com, is a desktop Al application that securely and privately helps users unlock the knowledge contained in their own curated data. By putting guardrails on the Al commercial and open-source models and implementing strict data controls, Kind Al delivers accurate, reliable results with surgical precision across all personal files, photos, video and audio.

Contact

Bethany Rhodes

[email protected]

Kategorie: Hacking & Security

Bank for charities pulls online services over security fears

The Register - Anti-Virus - 28 Červenec, 2026 - 15:53
CAF Bank, which serves 14,000 charities, has suspended online banking as it fixes a vulnerability in how third-party software connects to its portal. The outage has left some organizations struggling to run payroll after being cut from their accounts. In a message to customers, seen by The Register, the Charities Aid Foundation-owned bank confirm online services had been unavailable since July 24 and will remain so until further notice. The bank's communications say the decision resulted from reports of suspicious activity on some customer accounts. It said the bank detected the problem early on and notified customers of any attempted fraud. Following an investigation, CAF Bank identified a previously undetected vulnerability in the connection between third-party software and the online banking portal. It is working with its technology partner on a fix. The bank assured customers that its core banking services were not affected and that money held in their accounts was safe. However, it was making changes to the online service. In a statement, CEO Alison Taylor said: "We have informed CAF Bank customers that the online banking service will be unavailable until further notice. I am very sorry for the disruption and understand the frustration this can cause for our customers. "We are working with external experts to fix an issue we identified with third-party software related to our online banking portal. The core bank is not affected. We are acutely aware of the impact this has on our customers and want this to be fixed as soon as possible, but we cannot restore access to the online service until we are assured the issue is safely resolved. "We are still able to support on the phone, and we are prioritizing time-sensitive payments such as payroll." She declined to comment on whether the bank will compensate customers. Last year, CAF Bank came under fire from customers who were unable to log in or make transactions when a new banking platform was introduced. The bank later apologized to customers experiencing difficulties with the service. At the time, a CAF Bank spokesperson said it was focused on supporting its customers through the transition and helping them with the new online banking service. "The vast majority of our customers are online, with thousands of payments being made and received every day. We are sorry for the disruption and waits on calls that some of our customers have experienced following the launch." The bank has not disclosed how much it has spent on the platform. It held £1.45 billion ($1.93 billion) in customer deposits at the end of its 2024/25 financial year. ®
Kategorie: Viry a Červi

Linux Logs Have Become a Prompt Injection Target

LinuxSecurity.com - 28 Červenec, 2026 - 15:45
An attacker may no longer need to erase Linux logs to hide an intrusion. They may only need the AI reading them to believe a different story.
Kategorie: Hacking & Security

Chytré semafory s umělou inteligencí zrychlí dopravu a spravedlivěji rozdělí čas mezi řidiče i chodce

Živě.cz - 28 Červenec, 2026 - 15:45
Umělá inteligence nahradí fázové řízení plynulou analýzou dopravy v reálném čase • Projekt v americkém Pittsburghu potvrdil zkrácení čekací doby na křižovatkách • Propojená dopravní infrastruktura se stává potenciálním cílem kybernetických útoků
Kategorie: IT News

JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

The Hacker News - 28 Červenec, 2026 - 15:33
JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment. Artifactory is JFrog's software repository manager. OpenAI says the models then escalated privileges and moved laterally until they reached an internet-connected node. JFrog says it has since developed and released fixes for cloud Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

The Hacker News - 28 Červenec, 2026 - 14:56
OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default. The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1 in OpenWrt's GitHub advisory, lets an unauthenticated attacker able to reach the DHCPv6 server overwrite a stack buffer in odhcpd through a crafted DHCPv6 Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Uncle Sam needs you to fight for 6G leadership and security, lest Beijing get there first

The Register - Anti-Virus - 28 Červenec, 2026 - 14:49
America wants its allies to come together and help it lead the way in defining 6G communications standards, with security and resilience seen as key goals for next-generation networks. The latest effort to corral international work on 6G comes from the US National Telecommunications and Information Administration (NTIA), which says it is pursuing the objectives of a December 2025 memo from President Trump on "Winning the 6G Race." That memo didn't identify who America is racing against, but it is a fair bet that it is China, which gained a lead during the development of 5G technology. Huawei in particular is understood to hold more declared 5G standard-essential patent families than any other company. The NTIA says it is launching this initiative alongside more than 20 governments, including several European nations like the UK and the Nordic countries, Japan, South Korea, and Australia. The Nordics are significant as they are home to telecoms equipment suppliers Nokia and Ericsson. These governments have all pledged to strengthen cooperation on 6G over the next 12 months and beyond in support of greater security, interoperability, and resilience for next-generation networks, the NTIA claims. "The Call to Action for 6G Leadership and Security reflects an unprecedented level of international coordination on the future of communications technology," stated NTIA administrator Arielle Roth. "By working now with trusted partners, we will ensure that next generation networks reflect our shared security interests, strengthen our competitiveness, and drive innovation." So after President Trump has spent 18 months since inauguration disparaging and threatening America's "trusted partners," the US has decided it would really like their help in becoming the world leader in 6G technology. Isn't that nice? The initiative lays out specific milestones on strategic coordination over the next year or so, as 6G moves toward commercialization. These include engaging with the telecoms industry to understand the "political and economic landscape" for 6G networks and meetings to identify the potential for more coordinated approaches. It also calls for a big meeting in 2027 to review joint progress, where the partners are expected to evaluate funding strategies, share information on 6G research and development, assess 5G and 6G technical and cybersecurity risks, and promote common 6G policies. All of this seems aimed at coordinating positions on the spectrum needed for 6G ahead of the next World Radiocommunication Conference (WRC-27). Scheduled for October 18 to November 12 in Shanghai next year, the conference will consider which frequency bands are made available for next-generation mobile networks. But it isn't the first attempt at international collaboration over the next-gen wireless standard. The US-UK Tech Prosperity Deal, agreed last year, proposed greater cooperation in a range of science and technology areas including 6G, but this was put on ice by President Trump after just a few months over trade disagreements. Earlier this year, the Global Coalition on Telecommunications (GCOT) unveiled a set of security and resilience principles it wanted to see baked into 6G from the start. The organization includes many of the same nations as the latest US scheme. "This is a clear attempt by the US and its allies to shape the 6G landscape before commercial networks arrive," PP Foresight founder and analyst Paolo Pescatore told The Register. "The priority is to embed security, resilience, interoperability, and supply-chain diversity from the outset, rather than repeat the costly mistakes and geopolitical tensions that defined the 5G era. "Although China is not explicitly mentioned, the strategic intent is obvious: to reduce dependence on high-risk suppliers and to ensure that trusted nations have greater influence over standards, investment, and innovation. However, this remains a political framework rather than a binding agreement." The first 6G deployments could arrive as soon as 2029, with the US and South Korea likely to lead in early adoption, according to a report from Juniper Research earlier this year. Despite this, the exact characteristics that will define 6G networks have yet to be thrashed out. Bodies representing the mobile networks want to see a smooth and cost-effective migration path for their members, avoiding the mistakes made with 5G, while the GSMA has already put it out there that 6G networks may need up to three times the spectrum currently allocated to meet the anticipated demands for data. ®
Kategorie: Viry a Červi

Internet získá novou doménu .web. Spravovat ji bude organizace stojící za .com

Živě.cz - 28 Červenec, 2026 - 14:45
Společnost Verisign po více než deseti letech sporů a odkladů oficiálně zařadila doménu nejvyšší úrovně .web do kořenové zóny DNS. Jde o poslední krok před spuštěním registrací, které mají začít ještě letos. Doména .web patří dlouhodobě k nejočekávanějším novým generickým TLD (Top Level Domain), ...
Kategorie: IT News

Česká národní kvantová komunikační infrastruktura

AbcLinuxu [zprávičky] - 28 Červenec, 2026 - 14:30
Dne 30. června 2026 byla završena fyzická realizace projektu Czech National Quantum Communication Infrastructure (CZQCI), tedy České národní kvantové komunikační infrastruktury. Projekt byl realizován od 1. března 2023 a financován z Národního plánu obnovy částkou 121,6 milionu Kč. Cílem podpořeného projektu bylo vybudovat základy národní kvantové komunikační infrastruktury a ověřit možnosti jejího praktického využití. Mezi hlavní výsledky projektu patří vznik optického propojení mezi Prahou, Brnem a Ostravou o celkové délce přibližně 600 kilometrů se šesti segmenty kvantové distribuce klíčů (QKD). Síť dále doplnily dvě sekundární metropolitní větve využívající komerční QKD zařízení a dvě metropolitní větve založené na experimentálních QKD technologiích. Realizace zahrnovala také ověření integrace stávajících telekomunikačních systémů s prostředky kvantové komunikace a testování tří scénářů využití pro vojenské účely.
Kategorie: GNU/Linux & BSD
Syndikovat obsah