Agregátor RSS

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

The Hacker News - 19 Červenec, 2026 - 15:18
A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026. Cybersecurity company Volexity is tracking the activity under the moniker UTA0533. The discovery was made following an incident response investigation earlier this
Kategorie: Hacking & Security

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

The Hacker News - 19 Červenec, 2026 - 15:18
A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026. Cybersecurity company Volexity is tracking the activity under the moniker UTA0533. The discovery was made following an incident response investigation earlier this Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Albert, Globus a Kaufland nasazují AI do pokladen. Zákazníkům zrychlí odbavení, nenápadně upozorní na zloděje

Živě.cz - 19 Červenec, 2026 - 13:45
Nakupování v oblíbených českých obchodech prochází změnou, díky které odbavíte svůj nákup rychleji • . • Zdlouhavé hledání pečiva či zeleniny v menu přebírají kamery a váhy s AI. • Tuto novinku nasazují do provozu řetězce Albert, Globus a Kaufland.
Kategorie: IT News

Řada běžných léků na nachlazení obsahuje látku, která vůbec nefunguje. Dnes už víme, kde je zakopaný pes

Živě.cz - 19 Červenec, 2026 - 11:45
Fenylefrin v lécích na nachlazení neúčinkuje lépe než běžné placebo • Při spolknutí tablety se totiž účinná látka nedostane do nosní sliznice • FDA proto navrhl stažení těchto neúčinných pilulek z volného prodeje
Kategorie: IT News

Největší průšvihy Applu. Nesmysl století, úmyslně zpomalené iPhony a nabíječka, která zkusila ignorovat fyziku

Živě.cz - 19 Červenec, 2026 - 09:45
Okolo Applu se dnes rozprostírá pomyslná aura skvělých prémiových produktů, které fungují spolehlivě a mají propracovaný ekosystém. Jenže i Apple má za sebou nepovedené produkty a několik populárních telefonů nebo laptopů se zásadními vadami.
Kategorie: IT News

Zatímco spojenci teprve čekají na F-35, v USA se už chystají na budoucnost. Autonomní stíhačka poprvé vystřelila

Živě.cz - 19 Červenec, 2026 - 07:45
Stíhací bojový dron Anduril YFQ-44A amerického letectva poprvé odpálil střelu vzduch-vzduch AIM-120. Test se odehrál nad pouští Mojave v Kalifornii. Letoun zvládl většinu mise samostatně, ale konečné povolení k odpalu vydal lidský operátor. To odpovídá dosavadní americké politice, podle níž musí ...
Kategorie: IT News

Vybíráme nejlepší tahové strategie. Veďte armádu koček, připomeňte si nepřekonané Heroes of Might & Magic

Živě.cz - 19 Červenec, 2026 - 07:10
Při hraní čehokoliv musíme vždy dobře promýšlet své další kroky. Nejvíc to ale platí u her, kde jeden špatný tah může znamenat obrat celé situace. Právě takové najdete v našem článku.
Kategorie: IT News

Týden na ITBiz: MPO posílí využití AI ve firmách, uvolní 630 mil. Kč

AbcLinuxu [články] - 19 Červenec, 2026 - 00:01

MPO posílí využití AI ve firmách, uvolní 630 mil. Kč. Jak AI může měnit nejen styl komunikace, ale i vlastní přesvědčení? Jak přemýšlí umělá inteligence? Evropské výdaje na AI do roku 2029 dosáhnou 290 miliard dolarů. Globální převod na SAP S/4HANA s výraznou českou stopou.

Kategorie: GNU/Linux & BSD

this is a test

Kurzweil AI - 15 Červenec, 2026 - 23:45
this is some typing
Kategorie: Transhumanismus

Bypassing Windows Administrator Protection

Project Zero - 26 Leden, 2026 - 10:00
A headline feature introduced in the latest release of Windows 11, 25H2 is Administrator Protection. The goal of this feature is to replace User Account Control (UAC) with a more robust and importantly, securable system to allow a local user to access administrator privileges only when necessary. This blog post will give a brief overview of the new feature, how it works and how it’s different from UAC. I’ll then describe some of the security research I undertook while it was in the insider preview builds on Windows 11. Finally I’ll detail one of the nine separate vulnerabilities that I found to bypass the feature to silently gain full administrator privileges. All the issues that I reported to Microsoft have been fixed, either prior to the feature being officially released (in optional update KB5067036) or as subsequent security bulletins. Note: As of 1st December 2025 the Administrator Protection feature has been disabled by Microsoft while an application compatibility issue is dealt with. The issue is unlikely to be related to anything described in this blog post so the analysis doesn’t change.
Kategorie: Hacking & Security

A 0-click exploit chain for the Pixel 9 Part 3: Where do we go from here?

Project Zero - 14 Leden, 2026 - 20:01
While our previous two blog posts provided technical recommendations for increasing the effort required by attackers to develop 0-click exploit chains, our experience finding, reporting and exploiting these vulnerabilities highlighted some broader issues in the Android ecosystem. This post describes the problems we encountered and recommendations for improvement. Audio Attack Surface The Dolby UDC is part of the 0-click attack surface of most Android devices because of audio transcription in the Google Messages application. Incoming audio messages are transcribed before a user interacts with the message. On Pixel 9, a second process com.google.android.tts also decodes incoming audio. Its purpose is not completely clear, but it seems to be related to making incoming messages searchable.
Kategorie: Hacking & Security

A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave

Project Zero - 14 Leden, 2026 - 20:00
With the advent of a potential Dolby Unified Decoder RCE exploit, it seemed prudent to see what kind of Linux kernel drivers might be accessible from the resulting userland context, the mediacodec context. As per the AOSP documentation, the mediacodec SELinux context is intended to be a constrained (a.k.a sandboxed) context where non-secure software decoders are utilized. Nevertheless, using my DriverCartographer tool, I discovered an interesting device driver, /dev/bigwave that was accessible from the mediacodec SELinux context. BigWave is hardware present on the Pixel SOC that accelerates AV1 decoding tasks, which explains why it is accessible from the mediacodec context. As previous research has copiously affirmed, Android drivers for hardware devices are prime places to find powerful local privilege escalation bugs. The BigWave driver was no exception - across a couple hours of auditing the code, I discovered three separate bugs, including one that was powerful enough to escape the mediacodec sandbox and get kernel arbitrary read/write on the Pixel 9.
Kategorie: Hacking & Security

A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby

Project Zero - 14 Leden, 2026 - 19:59
Over the past few years, several AI-powered features have been added to mobile phones that allow users to better search and understand their messages. One effect of this change is increased 0-click attack surface, as efficient analysis often requires message media to be decoded before the message is opened by the user. One such feature is audio transcription. Incoming SMS and RCS audio attachments received by Google Messages are now automatically decoded with no user interaction. As a result, audio decoders are now in the 0-click attack surface of most Android phones. I’ve spent a fair bit of time investigating these decoders, first reporting CVE-2025-49415 in the Monkey’s Audio codec on Samsung devices. Based on this research, the team reviewed the Dolby Unified Decoder, and Ivan Fratric and I reported CVE-2025-54957. This vulnerability is likely in the 0-click attack surface of most Android devices in use today. In parallel, Seth Jenkins investigated a driver accessible from the sandbox the decoder runs in on a Pixel 9, and reported CVE-2025-36934.
Kategorie: Hacking & Security

Kniha kryptologie, šifrování a tajná písma v prodeji !

Security News - 12 Květen, 2025 - 14:00
KYBERCENTRUM vydalo knihu ceského kryptologa a popularizátora Pavla Vondrušky, která dokazuje, jak muže veda o kódech a šifrách být fascinující a dobrodružná.
Kniha byla v drívejším vydání v edici OKO zcela vyprodána a nebylo ji možné získat.
Nyní je tedy možnost ji zakoupit v e-shopu KYBERCENTRA. Ale pozor k prodeji touto cestou bylo uvolnen pouze omezený pocet 200 kusu .
Kategorie: Aktuality

Sháníte knihu : Kryptologie, šifrování a tajná písma ?

Security News - 12 Květen, 2025 - 14:00
Kniha p?edního ?eského popularizátora kryptologie dokazuje, jak fascinující a dobrodružná m?že v?da o kódech a šifrách být.
Kniha vyšla v 2006 v nákladu 8000 ks a byla brzy zcela vyprodána.
Kniha nyní vyjde pomocí Crowdfundingu v rámci projektu Centra kybernetické bezpe?nosti, z. ú. (KyberCentrum).
Podpo?te tento projekt a stanete se vlastníci této knihy.
Kategorie: Aktuality

Kryptologie, šifrování a tajná písma

Security News - 12 Květen, 2025 - 14:00
Kniha P.Vondrušky - Kryptologie, šifrování a tajná písma op?t vyjde.
Knihu lze získat v rámci projektu Kybercentra (Crowdfunding).
Kategorie: Aktuality
Syndikovat obsah