Agregátor RSS

Vulnerability giving attackers full control of Macs is under active exploitation

Ars Technica - 1 hodina 14 min zpět

Dutch officials have warned that a high-severity macOS vulnerability that allows attackers to execute malicious code is under active exploitation.

“The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet,” the Netherlands National Cyber Security Centrum warned earlier this week. “In all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed.”

Do you know if your screen sharing is on?

The vulnerability, tracked as CVE-2026-65400, received a patch from Apple last week for macOS Tahoe, Sequoia, and Sonoma. The vulnerability, with a severity rating of 7.1 out of 10, stems from a bug in the macOS screen sharing capability, which allows a remote party to view the screen and control the keyboard and mouse while a machine is turned on. A flaw in the “state management,” which keeps track of preceding events, user interactions, variables, and other system states, is the underlying cause.

Read full article

Comments

Hackers arrested over €30M bank fraud exploiting service provider flaw

Bleeping Computer - 1 hodina 42 min zpět
Four cybercriminals were arrested in Brazil, and three others were charged in Europe over allegations that they exploited a vulnerability at a service provider, allowing them to withdraw funds from Commerzbank customers' bank accounts. [...]
Kategorie: Hacking & Security

Zákeřný malware zneužívá mobilní NFC platby v Česku. Útočníci si přes něj mohou sjednat půjčku na vaše jméno

Živě.cz - 1 hodina 56 min zpět
Útočníci nejprve po telefonu přimějí oběť k instalaci trojského koně • Škodlivý kód přeposílá živá NFC data karty do terminálu podvodníka • Během krátkého hovoru stihnou na jméno oběti sjednat vysokou půjčku
Kategorie: IT News

1.6M RingCentral accounts' data dumped after ShinyHunters extortion attack

The Register - Anti-Virus - 2 hodiny 12 min zpět
Some 1.6 million unique email addresses tied to RingCentral have been leaked online, alongside names, physical addresses, and phone numbers, according to Have I Been Pwned. RingCentral disclosed the breach on July 28 and said “it was the target of a sophisticated social engineering campaign” affecting a “limited portion of RingCentral customers.” The comms platform said that it promptly responded to the intrusion upon detecting it, “took steps to stop the unauthorized activity,” and immediately launched an investigation into the security incident with help from a “leading third-party forensic firm.” “We have not seen any new unauthorized activity since taking these remediation efforts,” the company added. RingCentral did not immediately respond to The Register’s request for comment on this story. We will update it as needed. While the company hasn’t named its attacker, notorious data theft and extortion gang ShinyHunters previously claimed it compromised the collaboration platform, according to a post on its data leak site, viewed by The Register. Screenshots of the post also circulated on social media. The crooks claimed they stole more than 623 GB of data, and set a July 30 deadline for RingCentral to pay up - or else the crew would dump the stolen information online. RingCentral apparently didn’t pay the extortion demand, and ShinyHunters followed through on its threat, posting customers’ details on the internet. “The company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don’t care,” the crims wrote on August 3. A ShinyHunters spokesperson told us that the group broke into RingCentral by voice-phishing an employee and tricking them into giving the crooks their password. This same group, which security sleuth Dominic Alvieri says is his “top threat group and probably is for most analysts,” has hacked hundreds of organizations since the start of the year, including education tech firms that provide services for schools and universities along with healthcare-sector organizations. Recently, ShinyHunters dumped data stolen from Abbott’s cancer diagnostics business with the leak containing 10.9 million unique email addresses alongside personal and health information. The crooks claim that they made off with more than 30 million rows of customer information, including more than one million Social Security numbers and 7.5 million dates of birth. More concerning, however, they said the haul includes 22 million-plus rows of client notes containing confidential doctor-patient conversations and health information, and more than 20 million medical-order records containing patient IDs, prescription types, order dates, and refill information.® Editor's note: This story was amended post-publication with comment from ShinyHunters.
Kategorie: Viry a Červi

IAM Compliance Requirements and Best Practices

The Hacker News - 2 hodiny 27 min zpět
IAM compliance is the practice of demonstrating that identity and access controls are not only documented but actually enforced across users, applications, infrastructure, and non-human identities. This guide explains what IAM compliance requires, which regulations matter, and how organizations move from periodic access reviews toward continuous, evidence-backed verification that auditors can [email protected]
Kategorie: Hacking & Security

PBS station fears losing 50TB of data after being ghosted by cloud storage provider

Ars Technica - 2 hodiny 43 min zpět

After its cloud storage provider went defunct, a PBS affiliate decided to sue a data center provider to regain access to 50TB of TV shows, videos, and other data dating back 70 years.

As reported this week by Current, a trade newspaper covering public broadcasting, St. Louis affiliate Nine PBS filed a lawsuit against Iron Mountain Data Centers on July 28, seeking access to the data. In the litigation filed in Denver District Court, Nine PBS says that its cloud storage provider, Open Source Storage (OSS), used one of Iron Mountain’s Denver data centers to store the channel’s data. However, OSS is being unresponsive, and Nine PBS says Iron Mountain has refused to release its data.

The data in question includes the station’s coverage of the COVID-19 pandemic, East St. Louis’ history, The Great Flood of 1993, and over 11,000 files, The Denver Post reported in July. The lawsuit claims that “most” of the data is “unique and irreplaceable,” according to the Post.

Read full article

Comments

Windows 11 čeká dieta a dřina. Microsoft chce okna zeštíhlit i zrychlit (Podcast Živě)

Zive.cz - bezpečnost - 3 hodiny 1 min zpět
Microsoft do léta splnil většinu slibů o tom, jak zlepší Windows 11. Jen mu to trvá a široká distribuce většiny novinek teprve protéká z testovacích kanálů do stabilní větve. Ve druhém pololetí chce optimalizovat. Ví totiž, že Jedenáctky nepodávají nejlepší výkon. Některé prvky se spouští pomalu a ...
Kategorie: Hacking & Security

Windows 11 čeká dieta a dřina. Microsoft chce okna zeštíhlit i zrychlit (Podcast Živě)

Živě.cz - 3 hodiny 1 min zpět
Microsoft do léta splnil většinu slibů o tom, jak zlepší Windows 11. Jen mu to trvá a široká distribuce většiny novinek teprve protéká z testovacích kanálů do stabilní větve. Ve druhém pololetí chce optimalizovat. Ví totiž, že Jedenáctky nepodávají nejlepší výkon. Některé prvky se spouští pomalu a ...
Kategorie: IT News

August’s Patch Tuesday is a monster: 751 fixes, with an exploited Windows flaw

Computerworld.com [Hacking News] - 3 hodiny 23 min zpět

Microsoft’s August 2026 Patch Tuesday closes at 751 CVE entries (across all product families), with 108 rated as critical. One flaw is already exploited, CVE-2026-68820, an elevation of privilege in the Windows WinSock driver (afd.sys). Two more were disclosed but not exploited, CVE-2026-62832 (User Profile Service) and CVE-2026-72971.

This security-only release earns Patch Now for Windows, Office and Exchange; no SQL Server updates this month. Unfortunately, several critical issues affect server roles: Windows DNS Server carries a cluster of critical RCEs; Windows DHCP Server is the most-populated Microsoft product family at 14 entries. Testing should lead with printing and fonts and the Remote Desktop client, then a WinSock smoke test given the exploited afd.sys flaw. The Readiness team has provided a helpful infographic on the deployment risks for this Microsoft August update.

Known issues

Both August client and server-side updates ship with empty known-issues lists. This may change over the coming days so checking back to the Microsoft Security Update Guide (MSRC) may be prudent. July’s open items have all closed: the Dell/Intel driver hold, the mid-July WSUS sync degradation, and the Emoji Panel GIF outage (August swaps in GIPHY).

  • On the server side, WSUS synchronisation error details stay suppressed. The August Windows Server 2025 (KB5120233) and 2022 (KB5120242) updates still list this, the detail pane removed to address a remote code execution flaw CVE-2025-59287, with no published workaround.

One July item has been dropped from the documentation without a resolution note: the Windows Server 2022 BitLocker recovery prompt on first restart, for hosts carrying the PCR7 Group Policy condition. With no fix published, the Readiness team recommends that all recovery keys are (easily) retrievable before restarting freshly patched servers.

Major revisions and mitigations

Between the July and August Patch Tuesdays (15 July to 10 August), the MSRC Security Update Guide revised 534 CVEs. Almost all these changes (458) were routine Microsoft Edge and Chromium re-publications – none of which required customer action. That leaves 76 touching Microsoft’s own products, 60 of them flagged customer action required, including:

  • Windows storage and file system: four NTFS entries, all three July ReFS elevation-of-privilege flaws, and two Brokering File System fixes.
  • Identity and federation: six AD FS denial-of-service CVEs, plus two Azure Active Directory entries.
  • Developer runtimes: nine .NET and .NET Framework CVEs, with PowerShell and ASP.NET Core alongside.

The Readiness team has reviewed the 751 published updates, and it appears that Microsoft has not published any mitigations for updates in this August release.

Windows lifecycle and enforcement updates

Microsoft has not published any service or enforcement deadlines for this August. The 13 October 2026 cluster stacks five migration tracks onto one date, with a second wave on 10 November; dates below come from the linked Microsoft lifecycle pages.

One diary note: Windows 11 24H2 Home and Pro reach end of updates on 13 October 2026, two Patch Tuesdays out.

Microsoft’s August 2026 Patch Tuesday is a security-only release: 109 Windows test-guidance entries, four High Risk (July had 14). Printing and fonts lead: win32kfull.sys is the most-patched binary at seven entries and carries three of the four High Risk flags (32-bit printing on 64-bit Windows and font rendering); the Remote Desktop client carries the fourth. The testing guidance below works through each product and feature grouping.

Printing, fonts and graphics

Three of the four High Risk flags sit in win32k and touch print or font paths: 32-bit application printing on 64-bit Windows (two) and font rendering (one). GDI+, the Windows Imaging Component, and the kernel graphics driver (dxgkrnl.sys, five entries) change alongside; estates with 32-bit line-of-business printing or font-heavy documents take this first.

  • Print from your 32-bit applications to physical and virtual (PDF or XPS) printers, using text-heavy, graphics-heavy, and multi-page documents, and repeat after each relaunch, orientation, scaling, and resolution change.
  • Render varied fonts, sizes, and styles across browsers, Office, PDF viewers, and Notepad, and confirm Print Preview matches the printed page – watch for clipping, distortion, or missing glyphs.
  • Copy and paste images between Paint, Word, and Excel at different bit depths, and open EMF and TIFF files.
  • Exercise the graphics kernel: full-screen DirectX, multi-monitor hot-plug, resolution, HDR, and DPI changes, and sleep/resume.
Remote desktop and remote access

The RDP client carries the fourth High Risk flag; the fixes touch every redirection path and multi-session behaviour. RemoteApp, the display pipeline, and the RRAS and SSTP VPN stack change alongside.

  • Open several concurrent RDP sessions, enable printer, clipboard, audio, drive, and smart card redirection together, and exercise each across the sessions, confirming none interferes with another.
  • Disconnect and reconnect a session, confirm redirected devices and drives reattach, and test a RemoteApp end to end.
  • Configure a standard client VPN and an SSTP VPN over HTTPS and confirm sustained connections across reconnects and a restart.
Storage, file sharing and virtualization

The SMB client and server, NTFS and UDFS, the virtualised file layers (Cloud Files, Projected File System, Work Folders), and the platform stack (Hyper-V, virtual TPM, USB, and Windows Installer) all change. Standard Risk.

  • Connect to SMB shares (including RDMA, leases, and Continuous Availability), copy large sets both ways, and interrupt and reconnect a session; exercise NTFS extended attributes, UDF mounts, and cloud-file hydrate and dehydrate.
  • Create, checkpoint, and export a Generation 2 Hyper-V VM, enable a virtual TPM and BitLocker, and connect USB storage and MIDI devices.
  • Install, repair, and uninstall an MSI package, and confirm UAC elevation still prompts.
Telephony, networking and core services

TAPI is the busiest component (11 entries) but carries only parity fixes; the rest spans TCP/IP, HTTP.sys, Windows Firewall, Bluetooth, wired 802.1X, and message queuing. Broad and shallow.

  • Exercise TAPI line status and dialling locations against a shared line, and verify HTTP.sys under IIS over HTTP/1.1, HTTP/2, and HTTP/3.
  • Confirm TCP/IP IPsec tunnels on IPv4 and IPv6, toggle Windows Firewall rules across a restart, pair a Bluetooth headset, authenticate wired 802.1X, and validate MSMQ send and receive.
Office and SharePoint

This August patch cycle affects click-to-run (C2R), Microsoft 365 Apps, and MSI deployments of Microsoft Office with the following updates:

  • On MSI Office 2016, apply the client updates: Access (KB5002813), the ACE database engine (KB5002832), the Office proofing and UI components (KB5002791, KB5002795), Outlook (KB5002755), VBA (KB5002900), and Word (KB5002901), then exercise macros, external data, embedded objects, and line-of-business add-ins.
  • On SharePoint Server, patch 2016, 2019, and Subscription Edition, then check browser-based editing; mind the rollback rules – server updates cannot be uninstalled and always require a reboot.
Microsoft Exchange Server

On-premises Exchange takes a security update this month, seven CVEs across Exchange Server 2016, 2019, and Subscription Edition: one critical elevation of privilege and six important, spanning further elevation of privilege, remote code execution, denial of service, spoofing, and a security feature bypass.

  • Apply the update from an elevated command prompt: an un-elevated run leaves Exchange services partially patched and broken. Then confirm every Exchange service returns and that the server reports healthy.
  • Exercise mail flow end to end: send and receive internal and external mail, drain the transport queues, and check connectors and transport rules; confirm Outlook (MAPI over HTTP), Outlook on the web, and the Exchange admin centre for sign-in and core actions.
  • Confirm Autodiscover and free/busy resolve, test any hybrid connection to Exchange Online, and plan for the reboot the update requires – validate in a maintenance window before production.
Developer tools: .NET

The developer estate gets a broad, low-drama sweep; no SQL Server this month. Both the .NET Framework (Windows Server 2012 to Windows 11 26H1 and Server 2025) and the modern runtime and SDK patch, including WPF and WinForms.

  • Install the .NET Framework and modern .NET runtime and SDK updates, run a representative set of WPF, WinForms, web, and command-line applications, confirm normal behaviour, and build and run a .NET project to check for regressions.

The Readiness team recommends the following priorities for your larger enterprise deployments:

  • Start with printing and fonts: three of the four High Risk flags sit in win32k, so regress 32-bit printing, PDF and XPS export, font rendering, and Print Preview before anything else.
  • Take Remote Desktop next, the fourth High Risk flag, across the redirection paths, concurrent sessions, reconnects, RemoteApp, and SSTP VPN.
  • Give the busy but lower-risk areas a smoke pass: Telephony, the graphics kernel, DNS and DHCP, Active Directory, and the SMB stack.
  • Close out the rest: Office spans MSI 2016, SharePoint and Microsoft 365 Apps this month (Click-to-Run is in scope, unlike July), and .NET is a representative-application check.

Each month, we break down the update cycle into product families, as defined by Microsoft, with the following groupings.

Browsers

After July’s 46-strong Microsoft Edge (Chromium-based) haul, the browser family has nothing to report: August’s Security Update Guide carries no Edge-specific CVEs at all. It’s Margarita time – look busy or look elsewhere for patch-related testing and deployments.

Microsoft Windows

Windows carries the bulk again: 233 CVEs, 18 critical, the rest important bar one moderate. Elevation of privilege leads by volume (143 entries), but all but two of the 18 are rated as critical remote code execution vulnerabilities, on the network-facing server roles.

  • DHCP and DNS lead the critical-rated issues. Windows DHCP Server takes 14 CVEs, the busiest component by far, topped by a critical remote code execution flaw (CVE-2026-62823, “Exploitation More Likely”), with DHCP Client adding four more. Windows DNS Server is the headline RCE risk: six entries, four of them critical (CVE-2026-62878, CVE-2026-62817, CVE-2026-62820, CVE-2026-65789), reaching back to Server 2012. Patch the resolvers alongside the DHCP boxes.
  • A wider critical cluster. Beyond DNS, critical-rated issues also reach Microsoft QUIC, RRAS, the iSCSI Target Service, the WDS TFTP Server, the Remote Desktop Client, GDI+ graphics and Active Directory Certificate Services; domain controllers take priority, and Print Spooler and WSUS are for once absent.
  • Most-patched tally. DHCP Server leads (14, one critical), Win32k next (13 across two groupings), then the Telephony Service (11), the DNS client resolver (10), Windows Installer (nine), and the Windows Kernel and NTFS (eight each).

Add this Windows update to your Patch Now schedule, with your DHCP and DNS servers updated first.

Microsoft Office

Microsoft released 120 Office CVEs this month, 24 of them critical, remote code execution the through-line (62 entries). The packaging work sits on MSI Office 2016 and the SharePoint farms, but the exposure is overwhelmingly Click-to-Run: 89 of the 120 list Microsoft 365 Apps for Enterprise as affected, 20 of them critical, straight through the update channel.

  • Office clients – the critical RCE runs across Office, Word and Excel, mostly in document-rendering paths that fire on preview or open. The top-rated critical client entry, CVE-2026-70130, lists Microsoft 365 Apps among its affected builds, so Click-to-Run estates are squarely in scope rather than sitting this one out, as they could in July.
  • SharePoint Server – three critical-rated vulnerabilities on the on-premises farms, led by CVE-2026-65665, an RCE rated “Exploitation More Likely” (2019 and Subscription Edition), with two critical elevation-of-privilege entries behind it; a separate SharePoint Online spoofing flaw is fixed service-side.

Nothing in Office is exploited this month, but that critical SharePoint RCE and 20 Click-to-Run critical-rated vulnerabilities argue against waiting. Add the August Office and SharePoint updates to your Patch Now schedule.

Microsoft Exchange and SQL Server

Exchange Server has seven CVEs across Exchange Server 2016, 2019 and Subscription Edition, as four build-specific updates (KB5121573 through KB5121576). One is critical and six important; none is disclosed or exploited, but Exchange is internet-facing, so we would not wait.

  • Exchange Server (on-premises) – the critical entry is an elevation of privilege (CVE-2026-62911); the heaviest of the rest is a remote code execution (CVE-2026-62913). Apply it from an elevated command prompt and plan for the reboot (the test-guidance section covers mail-flow). Subscription Edition is the go-forward release; 2016 and 2019 still being carried is a reprieve, not grounds to defer migration.
  • SQL Server – nothing to install. On-premises SQL Server ships nothing; the only SQL-branded entries are cloud-side Azure SQL fixes, resolved service-side.

Add the on-premises Exchange update to your Patch Now schedule; SQL Server does not require anything this month.

Microsoft developer tools

Microsoft released 23 CVEs across its developer tooling this month, all rated as important: 13 in .NET and the .NET Framework, and 10 across Visual Studio Code and its Copilot extensions.

  • Microsoft .NET and .NET Framework – the runtime and framework are the focus this month, led by two remote code execution entries (CVE-2026-62897, .NET Framework, and CVE-2026-70354, .NET Core). The Framework rollups span Windows Server 2012 to Windows 11 26H1 and Server 2025; Visual Studio 2022 17.14 and 2026 18.8 take their exposure through the bundled runtime.
  • Visual Studio Code and Copilot – have three remote code execution entries and security feature bypasses across the Python extension, Copilot Chat and the core editor.

Add these developer-focused updates to your standard release schedule, behind this month’s Windows and Office priorities.

Adobe (and third-party updates)

Unusually, Adobe published an early-August emergency fix for a maximum-severity Adobe flaw (CVE-2026-48449), an incorrect authorisation that runs code with no user interaction. This makes this an Adobe “whatever you have installed” Patch Now moment due to how Adobe tends to share code between products. This August, there were two third-party flaws on Microsoft’s third-party list: the Trusted Computing Group’s TPM 2.0 reference-code bugs CVE-2026-6726 and CVE-2026-6727, both Important and issued by MITRE. If unpatched, a local attacker with TPM command access can work back to keys the chip should keep sealed, up to the RSA Endorsement Key behind device attestation. This completely defeats the purpose of the TPM chip – and, some would say, of migrating to Windows 11. Sorry, not sorry.

Kategorie: Hacking & Security

Máme Pixel 11 Pro a začínáme testovat. Google letos inovace odměřil na lékárnických vahách

Živě.cz - 4 hodiny 1 min zpět
Do redakce dorazily zbrusu nové smartphony řady Google Pixel 11 • Na pohled jsou velmi podobné loňské desítkové generaci • Novinek je poskrovnu, hlavním vylepšením je dioda HiLight
Kategorie: IT News

Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

Bleeping Computer - 4 hodiny 47 min zpět
The Netherlands' National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged. [...]
Kategorie: Hacking & Security

Google dotírá na Claude a GPT cenou i schopnostmi. Rychle připravil schopný model Gemini 3.7 Flash

Živě.cz - 5 hodin 1 min zpět
Gemini 3.7 Flash míří na rychlé a náročné AI úlohy. • V řadě benchmarků překonává svého předchůdce i konkurenci. • Oproti modelům od OpenAI a Anthropicu je i levnější.
Kategorie: IT News

Ploopy A+ Trackball

AbcLinuxu [zprávičky] - 5 hodin 4 min zpět
Open-source trackball Ploopy Adept má novou verzi nazvanou A+. Stále jde o symetrický desktopový trackball s šasi z 3D tiskárny a firmwarem QMK. Novinkami jsou dvojice tlačítek, jimiž půjde také otáčet, a volitelná opěrka ruky. Funkcionalita firmwaru je rozšířena o gesta, vrstvy a možnost konfigurace za běhu. Schémata a kód jsou jako obvykle na GitHubu. A+ půjde předobjednat za 99 CAD (bez dopravy a cla/DPH).
Kategorie: GNU/Linux & BSD

OpenAI and Anthropic in price war as Chinese AI rivals gain ground

Ars Technica - 5 hodin 19 min zpět

Leading US AI labs such as OpenAI and Anthropic are releasing cheaper models as they fight to retain cost-conscious customers who are switching to cut-price alternatives from Chinese rivals.

The price war comes as rising AI bills push companies to curb usage and seek cheaper models, helping Chinese developers including Moonshot and DeepSeek make inroads with users from Silicon Valley to Europe.

OpenAI recently said that it was slashing prices for GPT-5.6 Luna, its “fastest and most affordable model”, by 80 percent. Anthropic has launched Claude Opus 5, touting the system’s “frontier intelligence... at half the price” of Fable 5, the company’s most capable model.

Read full article

Comments

French tax authority admits data heist after crook touts 2M records

The Register - Anti-Virus - 5 hodin 19 min zpět
France's tax authority has confirmed that an intruder accessed its systems and extracted data in June after an alleged cybercriminal advertised a purported database of 2 million taxpayers. Using the alias "ZeroBytes," the alleged crook behind the attack on the General Directorate of Public Finances (DGFiP) advertised the stolen database on a cybercrime forum on Wednesday. They claimed the database contained details of more than 2 million French taxpayers and that they gained access using stolen credentials and an MFA bypass technique. ZeroBytes also claimed to retain access to DGFiP's systems and offered to sell it alongside the database. DGFiP did not immediately answer our questions about the attacker's claims. However, in a statement released Thursday, it disputed the claim that ZeroBytes retained access. "On Wednesday, August 12, 2026, a malicious actor claimed unauthorized access to the information system of the French Public Finances Directorate, which occurred at the end of June 2026 following identity theft," it said. "Initial investigations confirm that this access, which had been severed at the end of June as part of an audit, nevertheless allowed the consultation and extraction of data concerning individuals and professionals. "Following this complaint, the French Public Finances Directorate immediately implemented new restrictions to stop the unauthorized access and prevent further unauthorized use. In-depth investigations are ongoing to determine precisely which data and number of users were affected." DGFiP said it would report the attack to French data protection watchdog CNIL and notify affected users once it had determined who they were. The intrusion is the latest in a string of security breaches affecting France's public sector this year. France's Ministry of Finance, which oversees DGFiP, admitted in February that miscreants had accessed a database containing French citizens' bank details. The attackers used stolen credentials and made off with 1.2 million records, despite the ministry saying it quickly revoked their access. A few weeks later, France's Health Ministry confirmed a cyberattack on healthtech supplier Cegedim Santé in which around 15.8 million administrative files were stolen. Around 165,000 of these contained doctors' notes, which in "very limited cases" revealed medical histories. In April, the Interior Ministry confirmed reports of an attack on France Titres, the government agency responsible for identity documents including passports and driver's licenses. The alleged culprit, reportedly a 15-year-old, advertised the stolen data online and claimed the breach affected between 18 million and 19 million people – more than a quarter of metropolitan France's population. In June, the department responsible for Tchap, France's encrypted government messaging platform, investigated a suspected breach. The alleged attackers claimed to have accessed more than 73,000 user accounts, 643,000 messages, nearly 60,000 media files, and hundreds of chat rooms. ®
Kategorie: Viry a Červi

The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI

Bleeping Computer - 5 hodin 46 min zpět
Google Workspace attacks do not always begin with phishing. Stolen OAuth tokens can provide another path into Gmail, Drive, and connected systems. Material Security explains why organizations need defenses that cover the entire Workspace attack chain. [...]
Kategorie: Hacking & Security

Linux BPF Patches Fix Sparse CPU Bugs Causing Out-of-Bounds Read

LinuxSecurity.com - 5 hodin 50 min zpět
Two fixes posted August 13 correct separate per-CPU map failures on Linux systems whose logical CPU IDs contain gaps. 
Kategorie: Hacking & Security

Max severity SAP Commerce Cloud flaw now targeted in attacks

Bleeping Computer - 6 hodin 1 min zpět
A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused. [...]
Kategorie: Hacking & Security

Okénko Boeingu 737, které nasálo cestujícího, rozbila lopatka motoru. Prostudovali jsme předběžnou zprávu

Živě.cz - 6 hodin 1 min zpět
Ulomená lopatka motoru prorazila okénko a způsobila dekompresi v kabině • Podtlak částečně vtáhl cestujícího ze sedadla 11F do vzniklého otvoru • Vyšetřovatelé zjišťují příčinu únavy materiálu i možnou roli srážek s ptáky
Kategorie: IT News

OpenAI loses its AI ethics lead

Computerworld.com [Hacking News] - 6 hodin 26 min zpět

OpenAI has lost its AI ethics lead Chloé Bakalar just a year after she joined the company, the Financial Times reported. Bakalar has maintained a silence and has yet to update her LinkedIn profile, but if her departure is confirmed then it will add to the list of OpenAI executives who have quit in recent months.

Other departures include robotics chief Caitlin Kalinowski, who left the company over its deal with the US Department of Defense; researcher Zoe Hitzig, who quit in a very public way by writing an article in the New York Times; and Johannes Heidecke, head of safety systems.

OpenAI’s ethical stance has been called into question following an attack by OpenAI models on Hugging Face.

The departure of its sole ethicist will add to the pressure on the company. In her year at OpenAI Bakalar focused on ethical approaches to model development, looking at how humans interact with AI and examining machine consciousness, according to the FT report.

Bakalar had considerable expertise in the area. She was previously at Meta, where she developed the company’s ethics programs, but has also held several positions at prestigious universities on both sides of the Atlantic. Her departure will cause some anxiety at OpenAI as it continues to prepare the ground for its IPO.

Kategorie: Hacking & Security
Syndikovat obsah