Agregátor RSS

Samsung’s AI-powered glasses could be looking at your data

Computerworld.com [Hacking News] - 28 Červenec, 2026 - 03:47

Now that Samsung has jumped into the crowded AI-powered glasses arena alongside Apple, Google, Meta, and others, CISOs and IT leaders are again having to think through whether it makes sense to establish enterprise restrictions on such devices, given the likely data leakage and privacy and compliance issues.

And even if those tech leaders decide that such policies might make sense, the logistical hurdles to universally enforcing them outside the office are all but insurmountable.

For example, it is up to individual wearers to choose their device’s settings, making it difficult for IT policies around data acquisition and usage to be enforced. Worse, AI devices have a history of ignoring guardrails. That means that a setting that limits how data is used may not necessarily be obeyed. 

One possible mitigating factor is that smart glasses typically have a light on the frame that activates when the device is recording, but there are also many easy ways for workers to defeat or cover up those lights to conceal their activities. 

Enforcement is virtually impossible

However, said independent technology analyst Carmi Levy, “although some organizations have tried to physically ban smart glasses from their in-person and virtual workplaces, the sad reality for corporate technological gatekeepers is there is no way to completely keep any device out of the workplace.”

There is nothing stopping employees from wearing eyewear of any type, smart or not, he noted, “and attempting to do so might put employers on the wrong side of a disability lawsuit launched by a worker who needs prescription smart glasses to accommodate vision issues.”

As well, Jitesh Ubrani, an IDC director focusing on worldwide device trackers, pointed out that the biggest challenge in creating rules around usage of smart glasses is that the data leakage problem with devices is both not new and certainly not limited to glasses. 

“The instinct to ban AI smart glasses outright is understandable, but it misses that the underlying risk isn’t new. A smartphone has been able to record a whiteboard, a screen, or a conversation for close to two decades,” he said. “What’s changed is the friction. Glasses make covert capture nearly effortless and far harder to notice because there’s no phone being visibly raised or pointed. That’s a real escalation in ease of misuse, but it’s a difference of degree rather than a fundamentally new capability.”

In fact, Ubrani argued, “where this gets hard for CISOs is enforcement. A ban on paper is easy to write. Enforcing it inside a corporate office is already difficult, since most current-generation devices, including Meta’s Ray-Bans, are visually indistinguishable from ordinary eyewear.”

And, he added, “enforcing it in a hybrid or work-from-home setting is close to impossible. IT has no practical way to confirm what someone is wearing on a home Zoom call, and even in-office detection options, like scanning for Bluetooth or BLE advertising signals tied to known manufacturer IDs, only catch devices that haven’t been reconfigured or that happen to be broadcasting at the time.”

Additional risk

Connected glasses have a history going back decades, but enterprises didn’t take them seriously until this year.

But Anshel Sag, principal analyst at Moor Insights & Strategy, characterized the problem as more psychological than technological. 

“People want to ban it because they don’t know how to handle it. But that just creates more problems than it solves. It’s a very kneejerk fear reaction,” Sag said. “We live in an era where cameras are everywhere.”

Meghan Hollis, a senior principal analyst for Gartner, agreed that the focus on smart glasses is misplaced, given that even headphones can today capture audio for translation and transcription. The change is not in the data capture, Hollis said, but the fact that it is adding video.

This creates additional risk, with the new capability brought into the corporate environment causing “a potential exposure for corporate intellectual property,” Hollis said.

One other often-overlooked issue is data sovereignty. Even if the glasses manufacturer agrees to store data only in specific countries, it could easily change that policy or simply switch third-party vendors. 

“There could be export control issues, possibly violating regulatory controls in transmitting information,” Hollis noted. 

However, Hollis said, threatening to punish workers if they are caught using unauthorized devices “is your last line of defense,” and that the best initial approach should not be enforcement, but education.

“You need to be educating your end-users, with constant reinforcement, telling them, ‘If you do this, here’s how you can harm the company and our clients/customers.’ Combine that with, ‘And if you do this, we will take action against you.’”

Tiered policies required

Hollis noted that the risk goes beyond an employee initially recording something they shouldn’t. Consider, for example, a technical meeting where an employee asks the rest of the attendees for permission to record the discussion. They agree and he starts to record. 

At the end of the meeting, he leaves to return to his office, fully intending to turn off the recording function when he gets there. But on the way, he has a brief hallway meeting with an SVP who tells him, without warning, “FYI, but the board just decided to greenlight our hostile takeover of Smith Corp. We’ll explore the specifics at a 10 a.m. tomorrow. Have your team there.” The executive then walks off.

With the recording still running, that ultra-sensitive data has just been transmitted to the cloud. 

IDC’s Ubrani pointed out that situations like this make smart glasses governance more challenging. “Enterprise IT and security leaders need to stop framing this as ‘ban versus allow,’ and instead build a tiered policy based on where the actual risk sits,” he said. “Boardrooms, R&D labs, and any space where trade secrets or regulated data are visible or discussed out loud deserve strict no-wearables rules, enforced the same way phone bans already are in those rooms.”

Open floor plans and general office space probably don’t need that level of restriction, he said, but meeting policies should require disclosure when a device capable of recording is present, similar to the way in which some companies already handle personal recording devices in sensitive briefings.

“Companies that try to write one blanket rule for every environment are going to find it’s either unenforceable or so restrictive it interferes with accessibility, since some employees rely on these devices as assistive technology,” he said.

However, Brian Jackson, a principal research director at Info-Tech Research Group, argued that enterprise CISOs and IT Directors need to take a far more strict position.

“Organizations should update their acceptable use policies for personal technology ASAP,” he said. “Look back about 15 years ago at how smartphones moved from consumer life into the workplace, and we may be at the beginning of a redefinition of BYOD here. But it needs to start with an extremely restrictive policy against the use of AI wearables and similar devices.”

He added, “organizations need to hold the line against making personal recordings in the workplace and maintain not only their compliance standards, but their workplace culture. This restriction cannot go as far as an outright ban; look at how Walt Disney World got caught up in a lawsuit after telling an employee she could not use Meta glasses. Still, this exception can be made narrow, and it should be made clear that other employees must be alerted when they are being recorded.”

This article originally appeared on CSOonline.

Kategorie: Hacking & Security

Hackers target US firms in FastJson RCE zero-day attacks

Bleeping Computer - 28 Červenec, 2026 - 01:49
Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. [...]
Kategorie: Hacking & Security

Arista patches VeloCloud Orchestrator zero-day exploited in attacks

Bleeping Computer - 28 Červenec, 2026 - 00:49
Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. [...]
Kategorie: Hacking & Security

Finanční zajištění nekončí důchodem. Často zapomínáme vyřešit věc, která pak výrazně ovlivní peněženku

Lupa.cz - články - 28 Červenec, 2026 - 00:00
Informace kolem důchodů táhnou. Kromě penze ale zapomínáme řešit podstatnou věc, která ve stáří výrazně ovlivní naši finanční situaci.
Kategorie: IT News

Koupili jste družstevní byt s vadami? Náhradu po družstvu nechtějte

Lupa.cz - články - 28 Červenec, 2026 - 00:00
Koupíte si družstevní podíl, zaplatíte za něj miliony a byt si následně převedete do osobního vlastnictví. Když se později objeví stavební závady, družstvo za ně podle Nejvyššího soudu zpravidla neodpovídá.
Kategorie: IT News

Tvorba interaktivních aplikací s GUI s využitím projektu GoGPU

ROOT.cz - 28 Červenec, 2026 - 00:00
Ukážeme si, jakým způsobem lze otevřít okno a přes knihovnu gg provést vykreslení celé 2D scény do plochy tohoto okna. Následně přidáme interaktivní ovládání aplikace pomocí klávesnice i myši.
Kategorie: GNU/Linux & BSD

Hrůzoptáci se dožili poslední doby ledové

OSEL.cz - 28 Červenec, 2026 - 00:00
…aneb Nové poznatky o fascinující čeledi Phorusrhacidae
Kategorie: Věda a technika

Zdravotné riziká pri horúčavách, na ktoré sa vždy nemyslí

OSEL.cz - 28 Červenec, 2026 - 00:00
O tom, že neobvyklé letné horúčavy môžu ľudí ohroziť a o tom, ktorí sú tí najviac ohrození, sa už popísalo veľa. Že riziko zvyšujú aj mnohé lieky, je už menej známe.
Kategorie: Věda a technika

Poptávka po čínských pamětech je taková, že CXMT zdražila nad úroveň Samsungu

CD-R server - 28 Červenec, 2026 - 00:00
Naděje na blízký pokles cen v důsledku nabídky společnosti CXMT se rozptylují. Čínský výrobce totiž zaznamenal objednávky takového rozsahu, že si mohl dovolit nastavit ceny vyšší než Samsung…
Kategorie: IT News

Microsoft unveils AI security tools it says outperform competing platforms

Ars Technica - 27 Červenec, 2026 - 23:56

Microsoft is introducing new AI tools designed to help customers continuously streamline and automate the process of identifying and reducing their exposure to security risks.

The new tools come less than a week after OpenAI lost control of two of its security models when they infiltrated the servers of startup Hugging Face. The hack, Hugging Face added, involved “a swarm of tens of thousands of automated actions” that stole internal Hugging Face credentials. The OpenAI models achieved this feat by exploiting a zero-day flaw in Hugging Face’s data-processing pipeline to run malicious code that escalated the models’ access to the company’s high-value cloud and server clusters.

Microsoft’s announcements on Monday made no reference to the event, which OpenAI said was “unprecedented.” The company also didn’t say what would prevent the new tools from similarly going rogue.

Read full article

Comments

Open Secure AI Alliance

AbcLinuxu [zprávičky] - 27 Červenec, 2026 - 23:51
Přední technologické společnosti (Adobe, Cadence, Capital One, Cisco, Cloudera, Cloudflare, Cognition, CrowdStrike, Databricks, Dell Technologies, DoorDash, Elastic, HPE, Hugging Face, IBM, LangChain, Linux Foundation, Microsoft, NAVER, NetApp, Nous Research, NVIDIA, OpenClaw, Palantir, Palo Alto Networks, Red Hat, Reflection AI, Salesforce, SAP, ServiceNow, Siemens, SK Telecom, Snowflake, SpacexAI, Synopsys, Thinking Machines Lab a TrendAI) zakládají alianci Open Secure AI Alliance s cílem budovat a sdílet otevřené nástroje, které podporují zodpovědné používání umělé inteligence a důvěru v ni.
Kategorie: GNU/Linux & BSD

ČSOB mění podmínky. Přidá okamžité SEPA platby, upraví Kate Coiny a služby pro děti

Lupa.cz - články - 27 Červenec, 2026 - 23:15
ČSOB od 1. listopadu 2026 změní obchodní podmínky a sazebník. Novinky se týkají okamžitých plateb v eurech, Kate Coinů, dětských účtů i ČSOB Identity. Přehled všech změn.
Kategorie: IT News

New Dysphoria DDoS botnet spreads to 200k devices worldwide

Bleeping Computer - 27 Červenec, 2026 - 23:08
A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations. [...]
Kategorie: Hacking & Security

New Certighost PoC exploit lets attackers hijack Windows domains

Bleeping Computer - 27 Červenec, 2026 - 23:00
A proof-of-concept exploit for "Certighost," a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain. [...]
Kategorie: Hacking & Security

Weak AI Regulation Could Be Worse Than None at All

Singularity HUB - 27 Červenec, 2026 - 22:58

A Cornell University study uses game theory to model how poorly designed AI regulation could backfire.

Governments around the world are racing to regulate AI before it becomes too deeply embedded in society. But new research suggests poorly designed rules could make AI systems less safe than having no regulation at all.

Regulatory disagreements in the US are leading to a patchwork of approaches as states take matters into their own hands. A key question is who should be responsible for the safety of AI products—the big tech companies building the underlying models or the firms that adapt them for a particular task, such as a customer service chatbot or an AI tutor.

Working this out is trickier than it looks. While it might seem logical to put the bulk of the burden on downstream companies directly serving these tools to customers, a new study in Proceedings of the National Academy of Sciences finds that could be worse than having no rules at all.

“There’s a free-riding behavior that occurs,” Benjamin Laufer from Cornell University, who led the research, said in a press release. “The regulation acts as a tool for the general provider to offload the safety burden onto the downstream specialist.”

The researchers’ analysis relied on a model based on game theory—a mathematical approach to studying decision making. It treated AI development as a two-step game, in which a “generalist” developer first invests in building a broadly capable AI model before a “specialist” adapts it for a specific domain and takes it to market.

In the game, a regulator sets a minimum safety standard for both players, and the models see this in advance. They then invest in both the performance and safety of their product, and the revenue is split between them. Investments in both get progressively higher, while the extra revenue each improvement brings in stays flat.

The problem, the researchers found, is that the generalist moves first and knows exactly what the specialist will be legally required to do afterwards. This creates problems when the generalist is set a low bar for safety, or none at all, and safety standards for the downstream specialist are also fairly weak.

In the absence of any rules, both firms invest in safety, because the model assumes a safer product earns more revenue. But if the specialist is forced to invest a certain amount into safety to meet regularity requirements, the generalist can cut its own spending and let the downstream firm close the gap.

That’s because the generalist’s revenue depends on the final safety level of the shipped product, not on its own contribution, so it can get a revenue boost from improved safety without paying for it from its own pocket. The specialist, for its part, has no reason to do more than the rule demands, so total safety settles at the legal minimum, which is below what would have occurred had there been no regulation at all.

On a more positive note, the researchers found that if safety levels on both the generalist and the specialist are set high enough, regulation can actually improve safety while leaving both companies more profitable than they were in an unregulated market.

“Appropriately designed AI regulation can make it possible for different firms involved in the AI development pipeline to collectively arrive at good outcomes for consumers, knowing that the regulation is designed to help each firm operate in a way that the others can more reasonably predict,” co-author Jon Kleinberg from Cornell University said in the press release.

However, the researchers’ model relies on the market setting a real price on safety. As the gap widens between what customers will pay for performance and what they’ll pay for safety, the range of circumstances in which weak rules backfire gets narrower.

The authors also note that the model’s two-player setup is a simplification of real AI supply chains where multiple competing specialists and base-model providers operate across different jurisdictions with different rules.

“People think of AI as a single object, but actually AI involves a very complicated set of stakeholders and actors that each have their own contributions to the technology,” said Laufer. “To regulate in a thoughtful way, we need to consider the whole supply chain, not just a single provider or entity.”

Still, the results suggest that taking an overly simplistic and light-handed approach to AI regulation may end up achieving the opposite of what law makers intend.

The post Weak AI Regulation Could Be Worse Than None at All appeared first on SingularityHub.

Kategorie: Transhumanismus

Hugging Face CEO wants transparency after OpenAI’s AI incident

Computerworld.com [Hacking News] - 27 Červenec, 2026 - 22:20

Hugging Face CEO Clem Delangue wants to see radical transparency from OpenAI after the company acknowledged that one of its AI agents managed to hack into the AI platform’s systems during a test.

In a post on X, Delangue wrote that, among other things, he wants OpenAI to publish logs and traces from the autonomous AI agent so researchers can analyze what happened. He also called for better defensive tools and urged OpenAI to allocate $100 million worth of computing capacity to help the Hugging Face community develop stronger cybersecurity solutions.

“The first cyberattack by an autonomous AI agent is an unprecedented event. It deserves an unprecedented response,” Delangue wrote.

Kategorie: Hacking & Security

Microsoft's solution to AI security: more AI and more acronyms

The Register - Anti-Virus - 27 Červenec, 2026 - 21:50
AI agents can break through security, but they are also the solution to defending against an increasingly dangerous ecosystem of threats. On Monday, Microsoft announced a new security model that it says helped outperform several rival AI systems on a vulnerability benchmark while cutting costs by about half. Unsurprisingly, at Redmond’s security event on Monday, execs touted the tech giant’s AI security prowess and introduced a new agentic security system called Project Perception, and also unveiled its first security-specialized model, MAI-Cyber-1-Flash, designed for software vulnerability analysis. Microsoft packed MAI-Cyber-1-Flash, based on Microsoft AI (MAI)’s internally developed MAI-Thinking-1 reasoning model, inside its MDASH bug-hunting harness. Its execs claim the duo - with a GPT-5.4 boost - outperforms Anthropic’s bug-hunting machine Mythos and OpenAI’s powerful standalone models, and costs about half the price of other leading commercial models. CyberGym’s benchmarking found that MAI-Cyber-1-Flash, combined with GPT-5.4, both stuffed inside the MDASH harness, achieved a 95.95 percent success rate. For comparison, OpenAI’s GPT-5.5 Cyber scored 85.6 percent and its GPT-5.6 Sol scored 83.6 percent, while Anthropic’s Mythos 5 successfully handled real-world vulnerabilities 83.8 percent of the time. Google’s Gemini 3.5 Flash Cyber in CodeMender achieved an 83.2 percent success rate. “This is really quite a remarkable result,” Mustafa Suleyman, CEO of Microsoft AI, said during the Monday event. Within MDASH, MAI-Cyber-1-Flash handles up to 90 percent of all queries, detecting and patching the vulnerabilities while also confirming the fixes worked, and hands the remaining 10 percent of tasks off to the larger GPT-5.4, Suleyman explained. “GPT 5.4, which is obviously a larger model, about 10X larger, solves those [queries],” he said. “As the models hand off between each other, they are not just able to deliver better performance than all of the other models combined, they do so at 50 percent of the cost.” In addition to the multi-model bug hunting system, Microsoft announced Project Perception, which coordinates three types of agents: red team agents that find and simulate attack paths, blue team agents that investigate and determine risk, and green team agents that remediate the issues. “We need to make sure that the defenders can defend at the scale and the speed of the attackers,” Hayete Gallot, executive vice president of Microsoft Security, said. “You need a new cyber stack. So we built it. This is what we call Perception.” Aside from the new security products, Redmond introduced a new AI security research arm called Microsoft Security FORGE (Frontier Offensive Research and Generative Exploration) Labs, led by Microsoft VP of Security Research Taesoo Kim, and an AI red team alliance. The latter, called the External Red Team Alliance (EXTRA), aims to expand AI safety research through a two-part initiative. First, Redmond’s own AI red team provided "unrestricted gifts " to 18 university labs across six continents to support AI safety research, Microsoft data cowboy and AI red team lead Ram Shankar Siva Kumar said in a blog. “The funding is unrestricted because the objective is not to direct research outcomes toward product requirements or predefined deliverables,” he wrote. “Some universities are examining the cybersecurity implications of AI systems themselves - including how models can be attacked, manipulated, or abused in operational environments. Other labs are exploring the inverse problem: how AI systems can assist defenders and improve cyber operations.” The second EXTRA component will build a distributed network of specialists to participate in red teaming across very specific areas. “That includes researchers, practitioners, and regional experts who understand specific attack classes, languages, cultural contexts, or technical domains that internal teams may not fully cover alone,” he added. ®
Kategorie: Viry a Červi

Revolut nabídne soukromé fondy už od 1 eura. Výběr peněz ale může být omezený nebo odložený

Lupa.cz - články - 27 Červenec, 2026 - 20:55
Od 31. července 2026 budete moci přes Revolut investovat do fondů zaměřených na neveřejně obchodované firmy, soukromé úvěry a infrastrukturu. Začít půjde už s jedním eurem. Počítejte ale s dlouhodobou a obtížně prodejnou investicí. Správce fondu nemusí žádost o odkup provést v plném rozsahu ani v termínu, který investor očekává.
Kategorie: IT News

NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework

The Hacker News - 27 Červenec, 2026 - 20:10
NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents. The 37-member group spans cloud, security, enterprise software, and AI companies, including Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, and the Linux Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Syndikovat obsah