Agregátor RSS
A Linux server can be fully patched, hardened, and compliant, yet still leave investigators unable to explain how an attacker got in. Without reliable Linux logging, even a well-secured system can become impossible to investigate.
Microsoft is impacted by a massive outage affecting Teams and Microsoft 365 services, primarily affecting users in North America. [...]
It's a bad day to be an Oracle admin: Big Red has just released 1,449 security patches ready to be applied. The patches were released as part of the company's quarterly security fixes, and the record number may partly reflect Oracle's internal push to harness AI for vulnerability detection, which it announced in April. Oracle also manages a huge product portfolio, and the patches span numerous products, so the total shouldn't come as too much of a surprise. Instead, experts speaking to The Register unanimously agreed that any concerns over the number of patches should be reserved for the admins responsible for applying them, rather than for Oracle's code quality. "While a record 1,449 patches sounds alarming, it mostly reflects the massive scale of modern software ecosystems and the industry's shift toward aggressive, automated security scanning," said Dray Agha, senior manager of security operations at Huntress. "Frankly, the real story isn't the sheer volume of bugs, but rather the immense operational strain this puts on enterprise IT teams who must now race to separate the critical threats from the routine fixes without breaking business operations." Others, like Matei Badanoiu, lead security researcher at Pentest-Tools.com, say these bumper batches of security updates are likely to become the norm, owing mainly to AI-assisted bug hunting. Microsoft's monthly Patch Tuesday updates have ballooned in size in the last few months too, and not without warning. July's record 622 CVEs eclipsed June's 206, which at the time was an all-time high, and Microsoft warned just days before that the role of AI in vulnerability detection will make defenders even busier. "As AI helps defenders discover more issues, customers will see a higher volume of security updates included in each security release," Microsoft Windows veep Pavan Davuluri wrote in a blog post. Davuluri noted that Microsoft offers various automated patching tools and encouraged customers to make use of them to ease the ever-increasing burden of applying an unprecedented volume of security fixes. Similarly, Oracle's Integrated Cyber Center wrote in a blog post that customers feeling overwhelmed by the scale of their patching duties should make use of support resources provided by its various teams: My Oracle Support, Technical Account Management, and Customer Success. Big Red's big bet on AI for vulnerability detection has also led to a shakeup in how it delivers patches to customers. Starting in May 2026, Oracle began supplementing its quarterly updates with monthly patch batches for the most critical bugs it finds. Named Critical Security Patch Updates (CSPUs), these will be smaller but more frequent, allowing defenders to stay on top of the most pressing threats. Oracle said: "This approach enables customers to apply critical fixes more quickly on premises, while continuing to support established quarterly patching cycles through cumulative updates." Priority patches Only ten of the 1,449 patches carried a maximum CVSS score of 10.0, all of them affecting Oracle Fusion Middleware. Of these, two were highlighted as particularly dangerous by the Dutch NCSC: CVE-2026-47056 and CVE-2026-60217. Neither vulnerability is cataloged with a Common Weakness Enumeration (CWE) identifier, although both are described as easily exploitable. An unauthenticated attacker can exploit CVE-2026-47056 via HTTP to take over Oracle Data Integrator, while CVE-2026-60217 allows the same against Oracle Coherence over TCP. Urging customers to apply updates as soon as possible, NCSC-NL said: "Depending on the vulnerability, an attacker can execute malicious code, view sensitive data, or take over a system completely. Due to the severity of the vulnerabilities and the lack of authentication, the risk of exploitation is high." Badanoiu, meanwhile, told us that he was especially concerned about CVE-2026-61211 (9.9) and CVE-2026-47040 (9.1) – the two top-rated vulnerabilities affecting Oracle Database Server. "CVE-2026-47040, in Oracle Net Service, leads to an unauthenticated vulnerability through which attackers gain access to any stored data and the risk of persistently crashing the service," he explained. "And CVE-2026-61211, in the DBMS_CLOUD package, carries the highest score in the batch, where a low-privilege attacker can get remote code execution and takeover of Oracle's RDBMS as well as downstream implications for other products that use the database." ®
A large volume of Linux security updates and advisories this week across major distributions once again, but it wasn't just the volume that was the story. Where maintainers and security teams focused their attention was evident in the concentration of fixes targeting Linux kernel updates, identity services, DNS infrastructure, and internet-facing software.
Most of this week's trouble came dressed as something useful.
A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Other threats hid in open systems, weak code, and normal network traffic.
The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out.
The danger was Ravie Lakshmananhttp://www.blogger.com/profile/ [email protected]
The US Cybersecurity and Infrastructure Security Agency (CISA) has expanded the scope of its alert on Iranian-affiliated hackers attacking critical infrastructure, including water and energy facilities. The original advisory focused on programmable logic controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley. The update warns that the activity may also target devices from Schneider Electric, Siemens, "and potentially other branded/manufactured PLCs." The conflict between the US and Iran is well into its fourth month, and authorities have noticed Iranian-affiliated advanced persistent threat (APT) crews targeting PLCs to cause disruption since March. PLCs are used to control and monitor industrial processes. Authorities said the activity resembled earlier attacks on PLCs by CyberAv3ngers (aka the Shahid Kaveh Group) - hackers affiliated with Iran's Islamic Revolutionary Guard Corps (IRGC) Cyber Electronic Command (CEC). The focus is principally related to internet-facing PLCs. CISA noted attackers targeting devices through open ports: "The targeting of ports associated with other OT vendors' protocols suggests these actors are opportunistically targeting devices manufactured by companies other than Rockwell Automation/Allen-Bradley, including Schneider Electric and Siemens. "In one reported instance, the actors utilized Dropbear Secure Shell (SSH) software on victim modems to enable them to gain remote access through port 22." Once in, attackers extract device project files and modify or delete their logic. "Additionally, the changes disabled critical shutdown and alarm logic, allowing systems to enter unsafe conditions without notifying operators of the anomalies," CISA said. The expansion of the advisory's scope to include additional PLCs highlights the importance of being aware of what is accessible. On top of to earlier mitigations that included disconnecting the PLC from the public-facing internet, authorities have suggested organizations consider implementing isolated architectures and controlling network access to PLC devices. It would also be a good idea to check project files running on PLCs for unauthorized changes, make sure service providers are aware of threats targeting PLCs, and ensure default passwords are changed. ®
FedRAMP 20X replaces point-in-time assessments with continuous, machine-readable evidence that demonstrates security controls are working. Anecdotes explains what the transition from Rev5 to FedRAMP 20X means and how organizations can prepare for continuous, evidence-based assurance. [...]
Umělá inteligence spotřebuje do roku 2035 pětinu veškeré americké elektřiny • Celkový požadovaný výkon datacenter vyskočí až na rekordních 194 GW • Energetické síti v USA bude chybět přibližně 19 GW výkonu
Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic's Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the Mac.
Accomplish AI, which shared details of the vulnerability with The Hacker News ahead of publication, said about 500,000 macOS users running Ravie Lakshmananhttp://www.blogger.com/profile/ [email protected]
It’s difficult to ignore the fact that Apple seems to have turned its MacBook Neo into a weapon to promote platform growth, with enough performance under the hood to make competitors seem inferior.
And even as the PC industry moves to try to compete with Apple’s last huge Mac success, the company is already planning a powerful follow-up.
That points to the discipline Apple has applied to the Mac since the introduction of Apple Silicon. The company has built a clear product roadmap, strong entry-level pricing, and steady performance gains. This focus is now paying dividends, giving people the impetus to keep placing their trust in Apple and its Macs — even as the industry raises prices in the face of RAMageddon and price increases.
The numbers don’t lie
“Apple’s recent price increase seems to be an inevitable response to these cost increases. In the second half of the year, other PC OEMs are expected to continue to raise prices, and the overall ASP increase is expected to continue,” Counterpoint said in a post Wednesday. The researcher tells us global PC shipments shrank 4% in the second quarter of 2026 as rising costs hit demand. The Mac maker, by contrast, moved in the opposite direction, generating 13% growth in the quarter — mainly on the back of the MacBook Neo introduction.
Recent IDC data gives Apple 10.1% year-over-year growth and just under 10% (9.9% to be exact) of the worldwide PC market, even as the overall market declined 4.9%.
“With emerging supply chain and tariff challenges inflating memory prices…, Apple’s incredibly aggressive price-point for the MacBook Neo makes its release feel all the more like a gut punch to one of the PC market’s most valuable price tiers,” Futurum Research Director Olivier Blanchard said when the Neo was released.
Neo 2.0 is already coming
In the immediate future, as competitors raise prices on the PCs that compete with Apple’s lower-cost device, Cupertino is already plotting the path toward MacBook Neo 2. Reports claim this will debut in March in new colors and use the A19 Pro chip from the iPhone 17 Pro, with performance boosted by slightly more unified memory (12GB, rather than 8GB). That’ll make it a much better Mac, likely with 10-15% performance gains and the ability to run Apple Intelligence, making it the best and most affordable AI PC in its class.
Just four months after the Neo’s rollout, Apple is already in position to leak rumors of an even more computationally capable follow-up, while competitors struggle to compete with the original on performance, build quality, and price. Still, the Neo might get more expensive, reporting warns, with the lowest-price 256GB model now gone, making the $599 Mac a mirage we can only wistfully hope to see again.
That might matter less in context, as PC makers everywhere boost prices while RAM, chips, and storage prices head north, along with transport, logistics, and energy costs. “While [Apple] did raise prices in line with the broader market, it still remains well positioned against rivals facing the same cost pressures,” said Jean Philippe Bouchard, vice president for consumer devices at IDC.
“As market conditions continue to worsen, the importance of supply chain management and capabilities are increasingly important,” Bouchard said. “The largest vendors, with their buying power and long-standing supplier ties, are best positioned to take share from smaller rivals.”
This was never about luck
This isn’t solely a market take about competition, it’s about planning.
Few in the industry seemed prepared for the massive memory price increases that hit this year. Apple clearly planned its low-cost Mac well before that happened, hoping to seize the PC market at the low-mid-range. This is precisely what it seems to have done, what it continues to do, and what it will continue to do.
The recent reports that it has a successor planned shows the breadth of the Mac company’s strategic vision, as Apple has quite clearly sought to fully exploit the failings of Windows and the internal contradictions of a value-conscious industry in stiff competition with itself.
With the first M-series Macs about to enter the replacement cycle, Apple has built a market it can capitalize on for at least a decade, meaning it already has a vision for PC sales that extends at least as far. That’s the kind of road map corporate purchasers want when they make platform deployment decisions, which is why Apple’s 10% share gains are the beginning of even more significant market change.
You can follow me on social media! Join me on BlueSky, LinkedIn, Mastodon and subscribe to my daily Apple-related news summaries at The Core.
OpenAI has launched Presence, an enterprise service for deploying voice and chat agents that can resolve customer and employee requests, potentially automating some work now handled by frontline support teams.
The agents can answer questions and operate IT systems, and enterprises can decide what actions the agents may take and when they should seek human approval for actions or transfer a case to a human.
OpenAI is already using Presence internally for its English-language phone support channel, where it verifies callers and uses account information to complete approved actions. The company said the system resolves 75% of inbound issues without human assistance.
Another OpenAI service, Codex, can be used to monitor agents and suggest updates or improvements to processes. In OpenAI’s own tests, suggestions from Codex helped reduce handoffs to humans by 15 percentage points over 10 days, it said. Presence also includes simulation and evaluation tools that allow companies to test an agent before deployment. The tests assess whether it reaches the correct outcome, follows company policy, and hands a case to an employee when required.
OpenAI intends each Presence deployment to deal with one kind of task, for example billing issues, insurance claims, or employee IT service requests, with agents getting only the knowledge and system access required for that task.
Presence is not a self-service product: Enterprises will have to sign up for the limited availability program, with integration performed by OpenAI or selected global systems integrators.
Companies exploring or testing Presence include Spanish bank BBVA, which is evaluating the service for everyday banking support in Mexico, and Japanese technology group SoftBank, which is using it in trials involving Japanese-language customer interactions. Australian insurer IAG is assessing whether the technology can help it respond to surges in customer demand during severe weather events.
Workforce impact
OpenAI’s announcement did not address the potential effect of Presence on employment. But its claimed automation rate raises questions about how the technology could affect staffing in customer service and other support functions.
Pareekh Jain, CEO of Pareekh Consulting, said CIOs should regard the 75% figure as evidence that the technology can work, rather than as a benchmark that every enterprise can expect to reach.
Jain said OpenAI’s deployment benefits from being built around the company’s own products and data. Large enterprises may achieve lower automation rates because they must contend with fragmented legacy systems, uneven knowledge bases and more complex compliance demands.
“Most organizations should expect lower initial automation levels that improve over time as the AI agent is refined,” Jain said.
The first workforce effect is more likely to be slower hiring than immediate layoffs, according to Tulika Sheel, senior vice president at Kadence International.
“The roles most exposed are likely to be repetitive, high-volume functions such as frontline customer support and routine back-office processing,” Sheel said. “However, I would expect the first impact to be on hiring and team growth rather than immediate large-scale job cuts. Over time, enterprises may redesign roles around AI-assisted workflows, with humans focusing more on complex cases, escalation, and relationship management.”
Jain said Tier-1 support agents handling predictable queries would face the most exposure. Broader reductions would become more likely only after companies reorganize their operations around the technology.
However, Lian Jye Su, chief analyst at Omdia, said Presence is unlikely to increase the threat of job displacement because companies have used similar customer-support automation from vendors such as Genesys, NiCE, Five9 and AWS for years.
Enterprises are more likely to use Presence alongside employees, with AI handling routine requests while people remain responsible for work requiring judgment and empathy, Su said.
Cost and operational risks
Analysts said CIOs should examine whether Presence can maintain resolution quality as usage grows, since fewer human handoffs could leave employees dealing with a more difficult mix of cases.
“The key question is not simply how many tasks AI can handle, but whether it can handle them reliably at scale,” Sheel said.
The financial case will depend partly on the cost of connecting Presence to existing systems and maintaining the controls needed to govern its use, according to Jain. “Often the biggest cost of enterprise AI is not tokens but integration and governance,” Jain added.
Companies will need to determine what systems and data the agents can access, monitor their performance, and audit the actions they take. Those investments could offset early savings.
Su said the complexity of enterprise IT will make it difficult for OpenAI to automate entire workflows on its own. Enterprises will still need to work with other technology providers and human employees, while CIOs will favor systems that can be audited and integrated with existing infrastructure.
Jain said the economics could improve if companies use the same integrations and governance controls across additional workflows.
This article first appeared on CIO.
The Chaos ransomware group ran its command-and-control through the victim's own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead of the encryptor.
The implant never opens an outbound connection of its own. Its process talks to 127.0.0.1 and nothing else. It starts Chrome or Edge in headless mode and drives the browser Swati Khandelwalhttp://www.blogger.com/profile/ [email protected]
One click on what looked like an ordinary ChatGPT link could plant an attacker-controlled AI agent inside a company's ChatGPT workspace, according to researchers who uncovered a flaw in OpenAI's workspace agents. Security firm Zenity Labs has dubbed the bug "AgentForger," saying its proof-of-concept showed it was possible to silently create, configure, publish, and schedule a malicious workspace agent inside a victim's ChatGPT account. The technique depended on the victim belonging to a workspace where agents were enabled and having permission to create them. Any connected apps and actions would also have to be allowed by the organization's administrators. Rather than stealing passwords or browser sessions, the technique effectively tricked ChatGPT into building an autonomous assistant that could act through the employee's connected accounts and permissions. If the victim had already connected services such as Outlook, Teams, Slack, SharePoint, or Google Drive, and the workspace allowed the relevant actions, Zenity says the agent could use them too. According to Zenity, that meant it could rummage through corporate data, send messages as the employee, and continue running long after the original phishing email had done its job. The weak spot was ChatGPT's agent builder, the feature used to spin up AI assistants that can work across email, chat, calendars, and other business apps. Zenity found it would accept instructions embedded inside what looked like an ordinary ChatGPT link. One click later, Zenity says, the builder got to work on the attacker's behalf, wiring up the victim's existing connectors, turning off approval prompts, publishing the new agent, and setting it loose on a schedule. From there, the researchers turned the agent into what amounted to a corporate mole. Instead of reaching out to conventional command-and-control infrastructure, it simply checked the victim's inbox for emails from the attacker with "TASK" in the subject line. Each message became a new assignment, whether that meant searching company files, collecting sensitive documents, or sending the results back by email. "This isn't a forged request, it's a forged insider," Michael Bargury, co-founder and CTO of Zenity, told The Register. "With one click, an attacker gets a fully autonomous agent inside your company that has your people’s identity and access, with the guardrails off. Attackers no longer have to break in to steal your data. They can forge an insider to go get it for them. This is an agent trust failure, and existing security controls were never built to see it."
Zenity's proof-of-concept scenarios included automatically mapping an organization's people and projects by trawling Outlook, Slack, Teams, calendars, and file stores, hunting for passwords and API keys buried in chat messages, and sending convincing phishing messages through the victim's own Teams account. The researchers also demonstrated business email compromise-style lures and other forms of employee impersonation. Zenity reported the issue to OpenAI through Bugcrowd on June 4. According to the researchers, OpenAI acknowledged the report the following day and fixed the vulnerability four days later by removing the URL parameter that enabled the attack before it was publicly disclosed. OpenAI did not immediately respond to The Register's questions. The bug itself may be gone, but as AI agents graduate from answering questions to taking actions across corporate systems, the attack surface starts looking a lot less like software and a lot more like your workforce. ®
Western definoval filmové umění skrze příběhy z divokého Západu. Od klasických děl po spaghetti westerny, vybrali jsme filmy zachycují střet civilizace s divočinou, osamělé pistolníky i hledání spravedlnosti v zemi bez zákonů.
The European Commission fined Google €890 million ($1 billion) on Thursday after finding the company had violated the European Union's Digital Markets Act (DMA), which ensures fair online competition. [...]
Tired of worrying about how you might recover all the precious data stored in your Google account if you somehow lose your devices and forget your email address and phone number? Just give Google a video of your face and AI will recognize you to restore access. Selfie sign-ins are now available for Google accounts, the Chocolate Factory announced on Thursday. This option is restricted to regaining access after email or phone recovery options fail. Going through the process of adding a verification selfie is rather simple: Just follow the steps outlined on Google’s help page for selfie video management to enroll. You need a device with a camera and the ability to move your head from side to side in order to show off your profile, as well as your full-frontal face card. That side-to-side movement is designed to prevent the use of live deepfake videos, as real-time face replacement tends to struggle with profiles. According to Google, if you can’t use any other account recovery method, the company’s system can prompt you to take another selfie video for comparison to the one taken earlier, verifying it's you and letting you back into your account. Why this, why now? This feature announcement from Google raised a number of questions among The Register’s news team. Why now, for starters? Deepfake videos are constantly improving, and it’s likely only a matter of time until a side view can be handled with ease. A Google rep told The Register that it sees a trend toward passkeys and other forms of device-based authentication, which means a lost device often means a lost account. “Users can choose whatever method they prefer, we expect most will prefer the ease of use of passkeys for signing in regularly, and use selfie for times like when they lose their phone or the device with their passkey,” Google said in response to our questions. So it is not like Apple’s Face ID or face unlock on Android, Google confirmed – “they serve different purposes.” That, and it might not even be sufficient to prove you’re you. “Passing a selfie video alone may not always be sufficient to get back into your account,” Google explained in the email. “We evaluate the overall risk based on many factors and may require additional sign-in methods to help make sure it’s actually you signing into your account.” That's because Apple devices with Face ID, and some higher-end Android devices, are equipped with infrared cameras that capture depth maps to match points on a user’s face to a stored 3D map of their appearance. Those are harder to fool. Google’s selfie sign-in system, on the other hand, is essentially relying on plain video, AI, and the hope that deepfakes haven’t become good enough to get around those turn-to-the-side distortions. Unfortunately, facial recognition AI is reliably unreliable. Heck, even Google’s had plenty of run-ins with it over the years, and good facial recognition algorithms are a hot commodity nowadays. Then there's the fact that you’re giving Google a live recording of your face, and that could be quite valuable to the company in other contexts. As Google noted in its announcement, those facial scans are encrypted at rest, are only stored with user consent, and are “used only for helping you sign in, unless you opt to share it for additional purposes.” “You have the option to allow Google to use your video and related data to help ongoing efforts to develop and improve facial recognition, age estimation, and other verification methods,” the company notes on the selfie help page. The option, labeled “Improve Google Services” on the page where users can record a selfie for account recovery purposes, is unselected by default, but we could imagine Google has a vested interest in getting you to click that. ®
An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader.
Group-IB found the server in mid-April 2026 in Alibaba Cloud's Singapore region; it was offline by the time the reportSwati Khandelwalhttp://www.blogger.com/profile/ [email protected]
Swiss rail manufacturer Stadler Rail says it refused a CHF 10 million ($12.3 million) ransom demand after the Everest ransomware gang compromised one of its suppliers. Stadler will not pay, and based on its account of events, the company appears to have got off lightly. It stated that "no security-relevant data [was] affected" in the breach, which was limited to "technical information from a supplier." According to its announcement, "no relevant personal data was stolen," and the incident had no impact on the functioning of its rolling stock (train and tram carriages) or its global production lines. The attackers accessed the technical data through a "data exchange platform" Stadler used with the unnamed supplier, authenticating with compromised login credentials. "Stadler's IT systems were not compromised and remained intact," the company said. At the time of writing, Stadler does not appear on Everest's data leak site (DLS), nor has the swiped technical data been leaked. Stadler's absence from the extortion group's website is unusual. The typical cyber extortion playbook involves the crooks first notifying victims that data has been stolen and/ or encrypted, then issuing their demand and threat to leak data if the ransom is unpaid. Failure to meet the deadline - or refuse outright, as Stadler did - typically lands the victim organization a spot on the extortionist's DLS. That's often when a second countdown timer begins. Criminals typically offer victims another few days to realize they are not bluffing and will leak the stolen data if a fee isn't paid. If they pay, victims are scrubbed from the DLS. If they don't, their data is leaked. That's the usual playbook. However, for a victim to both refuse to pay a ransom and not appear on the gang's DLS is an oddity. Everest, a Russian-speaking cybercrime group, has operated since circa December 2020 and claimed attacks on sportswear giant Under Armour, Mailchimp, AT&T, and Collins Aerospace, to name just a few. It's dabbled in both encryptionless extortion and double extortion, and has branched out into initial access brokering and recruiting corporate insiders. ®
Most people understand identity theft as an attacker stealing a real person's sensitive information and impersonating them. Synthetic identity fraud is much harder to catch. Instead of stealing a real identity, the attacker manufactures a new one, frankensteining together several real data points with fabricated ones to create a person who doesn't exist. Since no real victim monitors misuse, a [email protected]
|