Agregátor RSS
Dronte mauricijský za nelichotivé označení dodo (ťulpas) či blboun nejapný, vděčí námořníkům, kteří ho objevili, lovili a navíc přivezli na ostrov mangusty aby ho zbavili hadů. Tohoto nelétavého ptáka se tak lidem spolu se zavlečenými nepůvodními druhy, podařilo zcela vyhubit během necelých sta let. Poslední zmínka o něm na ostrově v Indickém oceánu je z roku 1662.
Jak dostat na oběžnou dráhu v co nejkratším čase co nejvíc satelitů? Rocket Lab navrhují flatelity, velice ploché satelity, které je možné vyrábět ve velkém. Vesmírné síly zapojily flatelity do programu Space-Based Airborne Moving Target Indicator (SB-AMTI), v němž budou z nízké oběžné dráhy sledovat vzdušné cíle.
Týden v KDE převážně o ladění UI pro Plasmu 6.8, týden v GNOME #261 vylepšující Nautilus/Sushi a Boxes, počáteční podpora Apple M3 Pro, Max a Ultra v jádru Linux 7.3, podpora programovatelných tlačítek Logitech HID++ 2.0, IceWM 4.1 a oprava vzácné výkonnostní chyby ve videu.
Donedávna vydaným Windows 11 Insider končí platnost. • Microsoft každé sestavení podpisuje certifikát. • Nový certifikát mají pouze čerstvá sestavení.
Oživeno 8. srpna | Od posledního letu Starshipu uplynuly už dva týdny a loď se stále pohupuje na hladině. SpaceX se totiž v Indickém oceánu poblíž australského pobřeží snaží raketu zachránit a odvézt do přístavu na pevnině.
Sociálními sítěmi se už dříve šířily záběry z družic, teď se ale konečně ...
The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors. [...]
Future
Should AI Labs Be Treated Like the Owners of Dangerous Animals?Staff | The Economist ($)
“Gabe Weil of the Institute for Law and AI, in Massachusetts, proposes a system of strict liability. As with rules around keeping wild animals, it would assume that any harm is always the fault of the party carrying out the risky activity.”
Tech
Google Overhauls AI Leadership as Longtime Chief Scientist Joins Wave of ExitsMeghan Bobrowsky | The Wall Street Journal ($)
“Demis Hassabis is stepping down as chief executive of Google DeepMind to become chairman and chief scientist, Google CEO Sundar Pichai said in a post on X. Google DeepMind technology chief Koray Kavukcuoglu is taking on responsibility for all AI-model development, and Jeff Dean, Google’s current chief scientist, is leaving with three other company veterans to co-found a new AI startup.”
Biotechnology
Gene-Edited Puppies Will Melt Your Heart—but Won’t Trigger Your AllergiesEmily Mullin | Wired ($)
“Bailey and Alfie are two young beagles that can do tricks like any other dog, but they lack the protein that causes sniffles. They’re the culmination of years of work at Kindred Companion Sciences, a biotech company [Matt] Walker founded in 2020 that emerged from stealth this week with the two pups in tow.”
Biotechnology
Large Genome Models Used to Design New VirusesJohn Timmer | Ars Technica
“This isn’t science fiction—all the viruses the models created are closely related to an existing virus. But they do have some distinct features that would be challenging to evolve. And the researchers who did the work, based at Stanford University, suggest we may want to start thinking now about preparing for the potential that someone could develop a related AI that can design a virus that targets vertebrates.”
Future
Why Is Anthropic Destroying Books?Kathryn James | The Guardian
“We should worry that Anthropic decided it was easier to scan and destroy physical books than to deal with the ‘legal/practice/business slog.’ We should worry that the current understanding of fair use allowed Anthropic to decide that it was easier to buy and destroy ‘all the books in the world’ than to pay the creators of those works.”
Biotechnology
FDA Approves Moderna’s mRNA Flu VaccineChristina Jewett | The New York Times ($)
“In the case of flu, scientists believe that mRNA technology offers an advance from traditional vaccine options that take several months to prepare using decades-old technology, some requiring the virus to develop in fertilized eggs. Moderna has said that the faster new approach will enable a shift away from the current process of focusing on one flu strain for an entire hemisphere each season and allow each nation to pick its best option.”
Computing
AI Hacks Are Bad. AI Worms and Viruses Will Be WorseWill Knight | Wired ($)
“The work is an alarming window into how the next generation of AI agents could do more than just hack into other systems’ computers without permission. It also raises the prospect of future AI agents acting like super-smart, highly aggressive, and rapidly adapting computer viruses.”
Computing
OpenAI’s Expensive Smart Speaker Will Use Moving Parts to Seem ‘More Alive’Scharon Harding | Ars Technica
“Per Bloomberg, the OpenAI speaker’s main appeal is ChatGPT capabilities. Today, ChatGPT has significantly more users than Alexa+, but those users are largely accustomed to accessing the chatbot on devices they already own. With the rumored speaker, OpenAI would be betting on people’s willingness to pay substantial money for dedicated hardware to access chatbot features, the most advanced of which also require a subscription fee.”
Artificial Intelligence
China’s New AI Gold Rush: World ModelsJuro Osawa | The Information ($)
“World models are considered the key to unlocking breakthroughs in humanoids and autonomous vehicles, two areas where China has the world’s broadest and deepest supply chain. The Chinese neolabs think they have a shot, because the race to build world models is still in the early stage, with no front-runners yet, in contrast with the well-beaten path of large language models.”
Space
These Are the Sharpest Images Ever Taken of the Sun, and They Might Solve a Decades-Old MysteryEllyn Lapointe | Gizmodo
“The images are more than beautiful—they’re packed with critical information about the fundamental physics of our home star, including the first experimental confirmation of a long-theorized phenomenon that only the high spatial resolution of the Inouye Solar Telescope could reveal.”
The post This Week’s Awesome Tech Stories From Around the Web (Through August 8) appeared first on SingularityHub.
Prusa Research se letos v zimě pochlubil, že vyvinul zdaleka nejzářivější tiskové PETG na trhu. Říká mu Ultraglow Green a ve tmě zeleně světélkuje díky příměsi v podobě hlinitanu strontnatého.
Jak svítí samotná tisková struna, jsme vám ukázali na sklonku června v pořadu Týden Živě, ve kterém jsme ...
Despite the popularity of Claude Code, Cursor, GitHub Copilot, and OpenAI Codex, developers have plenty of complaints about AI coding tools. So researchers affiliated with York University and the University of Calgary in Canada decided to sift through developers' concerns about LLM-based integrated development environments (LIDEs) by analyzing Reddit discussions for common themes. Their findings suggest that the builders of such tools failed to prioritize security and privacy, leaving developers to defend themselves. Gias Uddin, associate professor at York University and a co-author of the research, told The Register that these tools are still relatively new and are evolving rapidly, which creates pressure to add new capabilities. "Our study cannot say whether that pressure caused any particular problem, but it does show that many reported issues come from how these tools are designed and what access they are given, not simply from the underlying models," Uddin said. "In that sense, we believe prevention is better than cure; that is, security and privacy mechanisms should be built into the design before a tool is given broad access to a developer’s files, data, or systems." Uddin and co-authors Mostafijur Rahman Akhond, Md Afif Al Mamun, and Song Wang say they wanted to look beyond the known issues with AI-generated code at LLM-based tooling and how developers interact with it. They describe their findings in a preprint paper titled "'Impossible to hide secret …': Uncovering Security and Privacy Issues in LLM-native IDEs," accepted at the 41st IEEE/ACM International Conference on Automated Software Engineering (ASE), 2026. Starting from a set of 1.1 million Reddit posts, they identified 446 posts and more than 6,000 comments to develop a taxonomy of security and privacy issues associated with using these LIDEs for AI-assisted coding. "Our taxonomy reveals a broad range of developer-reported concerns, including unauthorized file operations, unsafe or unexpected code execution, triggering of destructive actions, opaque data flows, telemetry collection, and potential leakage of sensitive information through expanded context access," the authors state. Some 43.1 percent of the posts covering security-related issues involved unauthorized file operations. These involved LIDEs removing project directories or files without authorization (28.3 percent). Users also described AI tooling modifying files without explicit user consent (8.8 percent), as well as accessing content beyond the active workspace (5.7 percent). "In one severe case (1npqf2f), Claude Code executed chmod +x on scripts without consent (File Permission Changes 0.6%)," the paper recounts. "Although rare, such actions pose disproportionate security risks." Another set of posts describes operational safety issues arising from LIDE use, including impacts on production services. These accounted for 23.9 percent of security-related posts. Examples cited include reports of Replit removing a SaaS production database and Cursor deploying code to production despite an explicit directive not to do so. A third category of woes covers unsafe code generation (18.2 percent). This involves incidents like nine VirusTotal detections reported for Cursor-generated software and hallucination-driven code changes: "When using Cursor, I noticed that after more than 10 rounds of dialogue, it starts to hallucinate and secretly modify code outside the requirements…" Then there are the instances where these LIDEs ignored user instructions, allow lists, gates, permission settings, or .ignore files, which account for 16.5 percent of the security-related posts, as well as third-party tool integration risks (4.7 percent). As for privacy problems, these were mentioned in 194 posts and cover issues like lack of transparency (45.9 percent) – the absence of clear information about what data an LIDE collects, retains, transmits, uses for training, or exposes to administrators – and unauthorized data access (23.7 percent). Other privacy categories include privacy leakage violations (15.5 percent), unauthorized data collection and transmission (11.9 percent), and context integrity failures (8.8 percent), which refer to situations where "for example, a user of Claude Desktop reported receiving messages originating from another user’s session." Uddin said, "We don’t think developers are completely unaware of these issues, as we found ongoing discussions about security and privacy concerns across many of these tools. Still, people continue to adopt them because they can make development faster and easier. They are also making programming more accessible to a wider group of people, including those with little formal programming experience or limited knowledge of software security." Uddin said users cannot be expected to thoroughly understand which permissions are risky, which files need to be protected, or whether a tool is doing something it shouldn't. "That makes it even more important for tool makers to build security into the tools themselves, with safer defaults and safeguards that do not depend on the user being a security expert," he said. Even so, users of LIDEs are trying to manage the risks. The authors enumerate 13 mitigation strategies that developers have employed to get by. These fall into five general approaches: configuration management (33 percent); code governance (31 percent); data protection and privacy control (13 percent); isolation (13 percent); and external guidance (9 percent). Based on their findings, the authors offer six recommendations. They advise: directing LIDE makers to implement proper security and privacy controls; enforcing security and privacy guardrails at an architectural level; incorporating a verification layer in LIDEs to validate generated code against security and privacy standards; establishing a formal protocol for assessing the trustworthiness of third-party tools; integrating sensitive file protection; and implementing strict security as a default. "We believe secure defaults would be one of the most important improvements these tools could make," said Uddin. "Developers should not have to discover after something goes wrong that a tool had more access or freedom than they expected. "Our findings point to practical measures such as limiting access to sensitive files by default, requiring clear approval before consequential actions, isolating projects and conversations, and making it easier to see and review what the tool is doing. "Users should still have flexibility, but the safer option should be the starting point rather than something they have to configure themselves. In fact, developers from the Reddit posts in our study were already using many of these safeguards in ad hoc ways; we think several of them should be built into the tools and enabled by default." ®
Windows 11 Insider Experimental Preview testují optimalizaci Průzkumníku. • Velké fragmentované soubory i mnoho malých souborů smaže rychleji. • Podle dřívějších informací by mělo jít o 30% zrychlení.
NASA se připravuje na misi Artemis III • Ke startu má dojít ve druhé polovině roku 2027 • Kosmická loď Orion se čtyřmi astronauty se nejdříve spojí s lunárním modulem Blue Moon Mark od Blue Origin a poté se Starship od SpaceX
Attacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of those routes is confirmed closed.
PromptArmor, an AI security firm, hid the instructions in content Rovo reads. It said an uploaded file wasSwati Khandelwalhttp://www.blogger.com/profile/ [email protected]
Ruský antimonopolní úřad žaluje Apple za neinstalování státních aplikací • Americký gigant přitom v Rusku své produkty oficiálně vůbec neprodává • Hrozící pokuta ve výši čtyř miliard rublů je ale prakticky nevymahatelná
New research shows content inside an email can escape its message boundary and interfere with the webmail interface.
Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take over third-party accounts, leak tokens, hijack trusted UI actions, and manipulate AI tools that read email.
PortSwigger researcher Gareth Swati Khandelwalhttp://www.blogger.com/profile/ [email protected]
Česká DG Solutions se prosadila v dodavatelském řetězci čipů díky unikátnímu mikronově přesnému obrábění materiálů • . • Konkurenční výhodou firmy jsou vlastní výrobní postupy, které přinášejí marže až 60 procent. • Na Tchaj-wan míří přes Čínu, vývoj ale zůstává v Česku a firma cílí na světové ...
Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day.
The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain Ravie Lakshmananhttp://www.blogger.com/profile/ [email protected]
N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product.
"We are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques," the company said.
"This is not a duplicate of our Ravie Lakshmananhttp://www.blogger.com/profile/ [email protected]
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.
The vulnerability, tracked as CVE-2026-8037 (CVSS score: 9.6), is a command injection flaw that could be weaponized to achieve arbitrary Ravie Lakshmananhttp://www.blogger.com/profile/ [email protected]
|