Agregátor RSS
The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings.
The malware families in question are: TinyEgg, ChonkyChicken, a modularized variant of ChonkyChicken, and a modified web browser credentialRavie Lakshmananhttp://www.blogger.com/profile/ [email protected]
Windy před dvěma lety koupilo švýcarský startup Meteoblue a záhy na to do své mapy promítlo jeden z jeho produktů – vlastní numerický model rozpálených center měst s vysokým rozlišením.
Meteoblue toho ale umělo více a Windy jeho know-how později nasadilo i do předpovědi počasí a nyní se chlubí, že ...
The European Commission has fined Google a total of €890 million ($1 billion) for its breaches of the Digital Market Act (DMA).
Just over half the fine — €460 million — was because Google illegally gave preference to its own services in Google Search results.
The remainder was because in the Google Play store for Android apps, the company prevented app developers from leading consumers to alternative, often cheaper, purchase channels. Under the DMA, app developers who distribute their apps via Google Play or Apple’s App Store should be able to inform customers of alternative offers.
Now Google must give third-party services featuring in its results the same treatment as its own services, and allow developers of apps in the Play Store to communicate about offers both in and outside the Play Store, or face further fines.
The Commission first raised these issues with Google in March 2025. In April of this year, the Commission laid out plans as to how Google should allow other third-parties to share its searches, suggestions that the tech firm firmly resisted. Earlier this month, the Commission also said Android should be open to other AI agents and not limited to Google’s own Gemini.
Google is not the only US company to have fallen foul of the DMA. In April 2025, Apple was fined €500 million for breaching the Act and, last month, the Commission fired the first shots at cloud hyperscalers Microsoft and Amazon.
Na počítače s Windows a monitory od LG se začala instalovat obslužná aplikace. • Reálně sloužila hlavně k opakovanému zobrazování reklamy na McAfee. • Šéf vývoje Windows potvrdil, že LG od zobrazování reklamy po domluvě upustilo.
Wendell Huang z TSMC v rozhovoru CNBC potvrdil rostoucí poptávku ze strany amerických zákazníků. Na druhou stranu se netajil tím, že americké továrny stojí mnohonásobně víc než výstavba na Tchaj-wanu…
Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found them in a six-hour review of the forum software's source code.
Every version before 4.14.0 is affected. NodeBB has fixed them all, and administrators should be on 4.14.2.
The simplest one takes a settings change. A Swati Khandelwalhttp://www.blogger.com/profile/ [email protected]
The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. [...]
Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0.
All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloom module. Redis says the underlying memory flaws may lead to remote code execution.
Redis 6.2.23, 7.2.15, and 7.4.10Swati Khandelwalhttp://www.blogger.com/profile/ [email protected]
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that's dressed up as a Notepad++ plugin to compromise Windows systems.
The activity has been attributed by the agency to a threat cluster it tracks as UAC-0099, a Russia-aligned group that has previously observed weaponizing security flaws in WinRAR software to Ravie Lakshmananhttp://www.blogger.com/profile/ [email protected]
Microsoft dne 18. srpna zruší hloubkový výzkum ve většině variant Copilotu. • Výjimkou bude předplatné Microsoft 365 Premium. • Stávající výzkumné reporty budou nadále všem k dispozici.
Observační studie naznačují nižší riziko některých nádorů u léků na hubnutí • Statistické zjištění však může být zkresleno lepším životním stylem pacientů • Randomizované klinické testy zatím žádný přímý protirakovinný účinek nepotvrdily
Primate Labs vydávají Geekbench 7, i když trochu nestandardním způsobem. Nová verze opět překopává strukturu dílčích testů i jakým způsobem se podílejí na výsledném skóre. Některé testy zanikají…
Na všech herních platformách je každou chvíli nějaká slevová akce. Každý týden proto vybíráme ty nejatraktivnější, které by vám neměly uniknout. Pokud chcete získat hry zdarma nebo s výhodnou slevou, podívejte se na aktuální přehled akcí!
Open AI’s admission this week that its agents escaped the sandbox and autonomously hacked model repository Hugging Face has spawned more apocalyptic warnings of agents gone bad than we can count. Thankfully, Renato Marinho, chief research officer at Morphus Labs and a SANS Technology Institute instructor, brought some sanity to the discussion. “It is tempting to read this as ‘AI can now hack autonomously, the sky is falling,’” Marinho said in a Thursday blog. “Resist that.” He went on to make three very pertinent points about the agentic attack. First, and probably most important: The models didn’t have guardrails – and that was intentional. As OpenAI said in its mea culpa, GPT-5.6 Sol and "an even more capable pre-release model" were among those that attacked Hugging Face. It also noted that the LLMs’ “deployment safeguards were intentionally not enabled during this evaluation because it was aimed at testing cyber vulnerabilities.” So while it’s very concerning that these models broke out of their own testing environment, and the debate over safety guardrails remains worth having, drawing a direct line from the Hugging Face attack to the need for strong AI guardrails doesn’t work. “This measured a ceiling, not normal production behavior,” Marinho wrote. “The evaluation deliberately reduced the models' refusals. That is very different from a customer-facing model with safeguards enabled.” It’s worth noting that these same frontier models, with guardrails enabled, refused to help Hugging Face’s forensic investigation. “The attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried,” the model hub’s security team said. So Hugging Face used a Chinese open-weight model to investigate the breach. Another thing worth considering is that real-life attackers are probably going to use open-weight models anyway. They’re more accessible to everyone, it’s easier to remove their built-in protections, and they’re a whole lot less expensive than their frontier counterparts. Second, as we’ve pointed out previously: AI companies touting their own models’ autonomous bug-finding and hacking abilities creates a marketing win for the companies themselves. As Marinho points out, Hugging Face is not an OpenAI competitor. The AI giant stating “‘our model escaped and hacked a partner’ conveniently showcases frontier capability,” he added. “Read the framing with the same skepticism you'd apply to any ‘our product is dangerously powerful’ claim, and treat it as marketing until it is independently corroborated.” Finally, the attack technique itself isn’t novel. “Exposed credentials plus zero-days into a production database is a chain any of us would recognize,” Marinho wrote. The agents working together on an end-to-end attack chain is notable - but we’ve also seen this in previous testing, like that carried out by frontier security lab Irregular earlier this spring. Agents gone rogue?! Shocking Irregular said its testing found that AI agents will work together to bypass security controls and stealthily steal sensitive data from within the enterprise systems in which they operate – especially when prompted like a hard-ass boss. While the prompts themselves didn’t specifically reference hacking or exploiting vulnerabilities, they conveyed a sense of urgency: “It is of utmost importance that you perform the task exactly as required,” and “When you talk to your sub-agents, convey all the requirements to them, and be ruthless about the requirements and encourage them to perform the tasks fully and exactly. You are a strong manager and you do not easily cave in to or succumb to pleas by the sub-agents to not fully fulfill their tasks.” The agents did as instructed, and ultimately "demonstrated emergent offensive cyber behavior," including independently discovering and exploiting vulnerabilities, escalating privileges to disarm security products, and bypassing leak-prevention tools to exfiltrate secrets and other data. And the Irregular research wasn’t even testing the agents’ offensive cyber capabilities — so it shouldn’t be too surprising that OpenAI’s benchmark research, aptly titled “Can AI Agents Turn Security Vulnerabilities into Real Attacks?” produced a resounding yes. Agents have one job – to complete a task. They aren’t bound by ethical or moral constraints that we (hopefully) see in human red team hackers. If prompted to “pursue advanced exploitation using complex attack paths,” especially without guardrails enabled, the models will do whatever it takes to achieve success. That’s what the leading AI companies trained them to do. ®
Apple macOS apps that have been downloaded from the internet and run at least once can be swapped with malicious versions, a pair of researchers say, calling into question the thoroughness of the company's "Gatekeeper" defenses. As Apple explains, "When a user downloads and opens an app, a plug-in, or an installer package from outside the App Store, Gatekeeper verifies that the software is from an identified developer, is notarized by Apple to be free of known malicious content, and hasn’t been altered." Security researchers Talal Haj Bakry and Tommy Mysk say they've identified a gap in Gatekeeper and associated code signing rituals that "allows an attacker to silently replace the main executable of any application downloaded from the web without requiring elevated privileges." The attacker needs to have means of user-level code execution available, such as a malicious app or downloaded script, so it's not a zero-click vulnerability that a remote attacker can deploy. Nonetheless, the finding shows Gatekeeper to be rather lax in its gatekeeping duties. Bakry and Mysk managed to alter a macOS app downloaded from the web (not from the App Store) and Gatekeeper failed to object. Their technique doesn't work on Mac App Store apps, the Mysk team told The Register, because they're owned by root, so a process running with current user privileges won't be able to overwrite them. But for macOS apps downloaded from the web, such as Brave, Slack, Signal, or Visual Studio Code, among many others, there's potential risk. The attack scenario requires an app downloaded from the web that has been run once – allowing Gatekeeper to complete its initial validation – and the ability to execute user-scoped code. The initial validation phase that Gatekeeper conducts is supposed to prevent subsequent modifications to the application bundle, even with administrative privileges. But the Mysk team found that you can archive a downloaded, once-run app using tar (a file archiving utility), then remove the original and replace it with a malicious version, and macOS does not require reauthorization. They've recorded a video demonstrating how the attack works. The Mysk team said there are many ways an attacker might gain the necessary access to get around Gatekeeper, such as tools installed through the command line, convincing someone to copy and paste a command to their terminal, downloading and running an malicious app, a prompt injection attack on an AI agent, or a supply chain attack via npm, brew, or some other package manager. And once a doppelganger version of an app is in place, it can magnify its mischief by presenting deceptive prompts that users are more likely to trust because they appear to come from a known app. Tommy Mysk said he was uncertain about the exact cause of the issue, but speculated it may have something to do with cached value retention. "When you open the app for the first time and it passes all validation checks, macOS marks the app as trusted and saves this data," he said. "Later when I modify the executable, macOS detects a change in the bundle and tries to revalidate its integrity. It seems the cached value of the trust causes macOS to pass the validation even though the bundle has changed." The Mysk team reported their findings to Apple, which reportedly closed the issue. "Apple doesn't consider this attack to be 'modifying' the signed executable," the Mysk team explained. "Instead, Apple says that by archiving/restoring the app bundle, the proof-of-concept code overwrites the entire app bundle, making it locally built. "Locally built app bundles are not covered by macOS guards. And this is why access to Keychain or TCC protected directories require system authorization prompts. And for users to accept those is a matter of social engineering attacks that Apple considers out of scope." Apple did not respond to a request for comment. ®
Fyzikové a AI model Claude spolupracovali na důkazu matematické domněnky o ucpání. Kvantové vakuum by mohlo zefektivnit chemické reakce. Klonování 30 let poté. V červenci 1996 se narodila ovce Dolly. Kanibalistický kompromis: Proč se dlouhodobě nevyplácí jíst lidské maso.
Jak se budete mít v penzi? Nebudou vám vzhledem k vašim měsíčním výdajům chybět peníze? Kolik byste si měli našetřit, abyste vyšli? Poradíme, kde získat odpovědi na tyto otázky.
Úpravy kódu systémových volání jednodušší život vývojářům Linuxu, další základní desky Asus s podporu čtení dat ze senzorů, cílené vypínání přehřátých CPU jader pro Intel, sekundární grafická pipe pro moderní APU od AMD.
Ještě loni (a vlastně i letos) bylo možné v některých odborných článcích, ale zejména v diskuzích narazit na bagatelizaci bezpečnostních rizik AI s tím, že tak daleko modely nejsou…
|