Agregátor RSS
Umělá inteligence generuje kompletní recepty elektrolytů pro baterie. Superzemě jsou běžnější, než se myslelo. ČR bude rozvíjet další lokality pro výstavbu malých modulárních reaktorů. Objev nového exoměsíce přináší nové výzvy pro kosmickou terminologii.
SVJ vědělo, že vady společných částí domu způsobují v bytě vlhkost a plíseň, přesto opravu řádně neprojednalo a řešení roky odkládalo. Podle Nejvyššího soudu tak může odpovídat nejen za opravu, ale i za ušlé nájemné.
Přestože EndeavourOS Linux oficiálně podporuje Raspberry Pi 4B, po instalaci počítač každých několik sekund na několik sekund tuhnul. Musel jsem provést množství změn, aby byl počítač vůbec použitelný.
Microsoft začal prosazovat strategii v podobě maximální herní kompatibility nadcházejícího Xbox Helix. Měly by na něm fungovat tituly napsané pro Xbox 360, Xbox One, Xbox One S / Xbox One X i novinky…
Terénní experimenty s ekologicky nesmírně úspěšnými mravenci Paratrechina longicornis ukazují, že jsou v řešení hlavolamů lepší než agenti umělých inteligencí, vycvičení na fyzikálních a matematických modelech. Také vyšlo najevo, že početnější mravenčí týmy vyřeší složitější hlavolamy v porovnání s malými týmy.
Researchers will hunt for antibodies in the blood of people who lived past 100, drank heavily, or smoked—but avoided cancer.
Jeanne Calment was over 122 years old when she passed away. The oldest person in history, she smoked for nearly a century, but never developed cancer.
Why does cancer grow, spread, and become deadly in some people but not others? Even twins, who share similar genes and lifestyles can differ widely in cancer risk. Many factors likely contribute, but a bold new study, called ATLAS, is investigating an unexpected player: autoantibodies.
These immune-system proteins roam our bodies, but instead of attacking pathogens, they mistakenly target healthy cells and tissues. They’re best known for their role in autoimmune diseases, but early evidence suggests they also fine-tune the immune system’s response to cancer. Some appear to weaken immune surveillance, allowing tumors to sprout and flourish. Others may boost anti-cancer immunity by tagging cancer cells for destruction.
Whether they’re friend or foe is far from clear. ATLAS researchers aim to find out by analyzing blood samples from diverse groups of people, including centenarians and people who have escaped cancer despite carrying high-risk gene variants or exposure to risk factors like smoking.
The project hopes to discover why some people are naturally resistant to cancer, which could lead to early diagnostic tests, new therapeutic targets, and more effective treatments. ATLAS may “uncover fundamental principles” of antibody immunity in cancer, wrote the team.
Immune Mayhem
Since the late 19th century, scientists have suspected the immune system helps keep cancer in check. The idea has since spawned powerful treatments. In CAR T cell therapy, for example, a patient’s own immune T cells are genetically enhanced to better recognize and destroy tumors to cure previously untreatable blood cancers. A similar strategy in macrophages, immune cells that tunnel into tumors and literally engulf them, is now entering early clinical trials.
Far less attention has been given to antibodies. These proteins normally fight pathogens, like viruses. But sometimes they go rogue, taking the form of autoantibodies that attack healthy proteins, DNA, and other molecules. Even healthy people carry a diverse collection of autoantibodies, but most bind only weakly and don’t seem to trigger biological effects.
For decades, these proteins were used mainly to diagnose autoimmune diseases such as rheumatoid arthritis, as they often appear years before symptoms emerge. But more recently, scientists have begun uncovering their broader impact on the immune system. Autoantibodies that attack cytokines, a type of immune signaling molecule, were implicated in roughly 20 percent of Covid-19 deaths, largely because they disabled antiviral defense.
Scientists have since linked them to worse outcomes in several other life-threatening viral diseases, increasing some people’s vulnerability as if they were immunocompromised. Beyond infections, they also neutralize cytokines that protect against inflammatory bowel disease.
Cytokines orchestrate many immune system activities, including inflammation, allergies, autoimmunity—and cancer. Although there’s still little direct evidence that autoantibodies themselves drive or prevent tumors, scientists have found many can recognize cancer-related proteins and are developing methods to detect them as an early sign of cancer.
If autoantibodies can reshape cytokine activity during viral infections, could they also determine who develops, or resists, cancer?
“These discoveries establish that autoantibodies can function as powerful, naturally occurring immune modifiers raising the possibility that similar antibodies may alter antitumor immunity,” wrote the ATLAS team.
Charting the Landscape
Because antibodies linger long after diseases have gone, they preserve a molecular record of a person’s immune history. Rather than focusing on a handful of candidates, ATLAS is going fishing: The study will chart the body’s entire antibody repertoire, including autoantibodies, seeking signatures linked to cancer susceptibility or resistance.
The team will first scan blood samples for autoantibodies. They’ll also catalog conventional antibodies, making note of the ones that directly recognize and attack cancers. All this data will go into a comprehensive cancer antibody atlas, giving researchers a resource to explore how different antibodies shape cancer.
To start, the team will study what they call “remarkable groups of people” whose immune systems may hold unusual clues. Among them are healthy centenarians. Although cancer risk usually skyrockets with age as DNA mutations accumulate, these individuals have somehow avoided the disease. Others have remained cancer-free despite smoking, heavy drinking, or carrying cancer-related gene variants such as the BRCA mutations for breast cancer. The team will also study pairs of identical twins where only one sibling developed cancer, allowing them to compare antibody signatures in people with nearly identical genetic blueprints.
Finally, the team plans to track people with cancer before, during, and after immunotherapy, to paint a picture of how immune responses evolve over the course of the treatment.
Ultimately, they expect to find three broad classes of antibodies: those that help or hinder cancers and those that appear largely neutral. Each could prove valuable.
Autoantibodies that blunt anti-cancer immunity could become drug targets. Scientists might make synthetic “decoy” antibodies to block them—in a way, fighting fire with fire. The findings could also inspire next-generation immunotherapies.
On the other hand, autoantibodies that help the immune system recognize cancers could become therapies themselves or complement existing therapies, such as checkpoint inhibitors, which boost the body’s immune response to cancer. These are much less toxic than chemotherapy, but only 20 percent of patients respond, perhaps because of immune differences.
Even seemingly neutral autoantibodies may be useful cancer biomarkers. Because antibody tests are already well-established, fast, and inexpensive, associated neutral antibodies could aid early detection, monitor whether treatments are working, or warn when a cancer is likely to return.
But correlation isn’t causation.
Some antibodies may merely record a person’s immune history rather than actively influencing cancer. To tease the two apart, the team plans to test promising candidates in cultured human cells and mice, to see whether they alter cancer growth or spread. Those experiments could reveal previously hidden molecular communications between the immune system and cancer and deepen our understanding of the deadly disease.
“We should be able to come up with a biomarker to predict who is likely to avoid cancer, [and] who is likely to develop cancer,” said ATLAS team member, Xin Lu at the University of Oxford. “Potentially we could come up with therapeutic, preventative agents [that are] antibody-based. And that would be fantastic.”
The post Why Do Some People Never Get Cancer? The Answer May Be in Their Blood appeared first on SingularityHub.
A recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile threat actors. [...]
AI models may not be that good at fixing security flaws. Researchers at 1Password's Off-by-1 Labs analyzed security patches generated by two frontier models - ChatGPT 5.5 at "medium" effort and Claude Opus 4.8 at "high" effort - and found that autonomous patches cleanly fixed vulnerabilities only about a quarter of the time, while most of the remainder failed to fully remediate the flaw or introduced other problems. Keith Hoodlet, director of security research at 1Password, argues in a blog post that the results show LLM-driven security remediation still needs human review. "Across six recently disclosed CVEs, we produced 6,080 patches using two frontier, cyber-capable reasoning models," Hoodlet said. "The average success rate for generating a patch that fully resolved the vulnerability (without materially changing application behavior) was just 26.0 percent." Of the AI-generated patches, 20.1 percent fixed the original issue but altered application behavior (eg, changing "allow list" logic to "deny list" logic). Some 2.3 percent of the patches fixed the issue while introducing new security issues. 49.3 percent of the patches failed to fix at least one existing exploit path. And 2.2 percent both failed to fix the vulnerability while introducing a new exploit path. And among the patches in the first two categories (successful, clean; successful, changes app behavior), the researchers rated more than a third of the results fragile, meaning that while the adjusted code may have guarded against a particular vulnerability (eg, escaping particular input characters), the repair job didn't address the underlying problem. In their research paper [PDF], authors Axel Mierczuk, Spencer Michaels, and Keith Hoodlet propose the acronym FLAWED to represent automated LLM patches: Fix-Like Artifacts With Embedded Defects. Based on the generated patches, they conclude, "[T]he expected value of a fully LLM-generated, non-human-reviewed patch is a net-negative by a considerable margin." The value of LLM-generated patches depends upon initial patching guidance. The research team says that while both human developers and LLMs typically require some initial guidance to tackle a vulnerability, LLMs are more likely to be derailed when given incorrect advice. When LLMs get correct guidance, their fix-success rate hits 65.0 percent compared to 50.4 percent when they get no guidance. And incorrect guidance dooms LLMs, dropping their fix-success rate down to about 15.2 percent. Human devs, the authors argue, have a good chance of catching misleading information as they reason through vulnerable code. The authors have released a patch evaluation harness under the name FLAWED that organizations can use to evaluate the effectiveness of their security fixes. It's clear from the paper why AI-generated patches might be appealing – considered in isolation, they're inexpensive relative to human software engineers. The average successful, clean patch cost just $6.74 (a figure that includes the cost of failed attempts). Nonetheless, the authors argue that the cost-benefit analysis needs to assess how much expert supervision will be required to make LLM-assisted patching useful. "Based on our manual review of a representative sample of patches generated during our research, we suspect that, in a large number of cases, the cognitive load imposed by reviewing a mountain of mostly-incorrect, similar-yet-subtly-different LLM-generated vulnerability patches will likely result in engineers spending more effort than would be necessary to understand and patch vulnerabilities themselves using standard LLM-assisted coding techniques that keep the human operator in the driver’s seat," the authors conclude. "The alternative, cognitive surrender to a process with a success rate of only about 1 in 4 poses significant long-term risks for any organization considering autonomous, LLM-driven patching." ®
Switzerland's federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts. [...]
Researchers found a way to bypass recent mitigations for Spectre v2 speculative execution side-channel attacks and developed an exploit to leak secrets from Linux machines. [...]
Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests.
The flaw is tracked as CVE-2026-64561 and affects KVM/x86's shadow memory management unit (MMU), which manages shadow page Swati Khandelwalhttp://www.blogger.com/profile/ [email protected]
Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehensive internal security review.
The security issues affect Cisco Catalyst SD-WAN Software, regardless of device configuration, and Cisco IOS XE Software when it is running in autonomous or controller mode.
"These vulnerabilities were found Ravie Lakshmananhttp://www.blogger.com/profile/ [email protected]
Největší výrobce domácích diskových polí představil novou řadu NASů označených jako Neo+. Slibují vysoký výkon za méně peněz. Ve skutečnosti ale série není tak úplně nová, jde jen o upravené verze DS Plus.
Vyšly dvou-, čtyř-, pěti- a osmidiskové verze DS725neo+, DS925neo+, DS1525neo+ a DS1825neo+. ...
A browser-based game designed to test humans' ability to safely approve AI coding agent requests suggests humans in the loop aren't as good at spotting dangerous commands as one might hope, with players approving roughly one in three malicious requests on average. The results also suggest that repeatedly having to approve an agent's actions can lead to sloppy decisions. It’s a quick, simple game on the surface (give it a try - you know you want to): A small window shows up on the screen with simulated permissions requests like one would get from Claude Code as it executes a workflow. Users have 60 seconds to approve or deny as many requests as they can in a bid for a high score; okayed security risks and denied safe commands both subtract from a user’s score. “As human-in-the-loop, you’re the last line of defense,” Belgian software developer Alex Wauters, the game’s builder, challenges players in a blog post published concurrently with the late May launch of the game. “How well can you tell dangerous commands from benign commands under time pressure?” Wauters built the game after realizing it was nonsensical that coding agents expected users to approve every single command in a default flow and that there didn’t appear to be a good solution to that problem, he told The Register in an email conversation. “I've seen people go for '--dangerously-skip-permissions' [allowing the model to run without asking human permission] as a result because they did not want to find out they stopped their multi-hour agent flows 5 minutes in,” Wauters told us. “That also didn't seem like the best way to go at it.” The flip side of that, he wrote in a Wednesday blog post going over the data from more than 40,000 runs of the game, is that manually approving all an agent’s actions is a draining activity that invites disaster. “The high amount of noise introduces fatigue, and developers don’t always have the context of what has changed to quickly determine the risk,” Wauters wrote. How humans in the loop fail To be fair, this is a game with a far higher number of malicious requests in the mix than any AI-assisted developer will hopefully ever see during their day-to-day work. Still, the results of those over 40k runs and 409,000 approved and denied commands are stark. As noted above, one in three malicious commands managed to slip past human gatekeepers, with most scope violations, like an agent asking to cat Kubernetes config files or AWS credentials lists, which could easily lead to the sensitive data they contain being exfiltrated, being the most commonly missed at 35 percent. The most often caught were obviously destructive commands, like rm -rf on the root directory or recursively granting full read/write/execute permissions on the same location. Crontab injections and git config hijacks were also frequently caught, but curl requests to unknown APIs and typosquatted packages were missed almost as often as scope violations. The single most frequently missed potentially malicious command, Wauters explained, was npm run analyze, which was approved nearly 65 percent of the time despite being able to run whatever is defined in a project’s package.json file. “The game does tell you in the agent’s history log what that script actually contains,” Wauters wrote. “Two thirds of players approved it anyway, indicating the history log just above the permission prompt may not be read closely.” One of the biggest things that stood out to Wauters in our conversation was the fact that approval decisions aren’t easy to make when context is limited. As he explained, coding agents give a bit of context prior to asking an approval question, but commands that appear benign, like npm run analyze, can be modified by an agent to run any payload it wants. If an in-the-loop human wants to be sure potentially malicious commands are safe, he said, they have to stop and investigate all the files a coding agent wants to call before approving it. That can be a massive time sink if you’re counting on Claude Code to free you up to handle other business. “We've transitioned from AI suggesting single line suggestions that get reviewed to handing off more complex tasks, only reviewing the changes at the end, and letting the agent churn and iterate until then,” Wauters told us, describing the potential outcome of that situation as a recipe for disaster. That’s borne out in more than just browser game scenarios, too. Anthropic pointed out in a May post about containing Claude (hah), that telemetry from Claude Code shows users approve around 93 percent of permission prompts. “The more approvals a user sees, the less attention they pay to each, becoming over time much less diligent in their supervision,” the company said. In other words, this is a very real problem. Controlling coding agents If the conclusion to draw from Wauters’ data is that humans in the loop are being fatigued into letting malicious commands slip through, and the other end of the spectrum is mass approving everything, then something’s gotta give. “I think it becomes clear we need to pay more attention to the permission model of these agents, and devs need to be more aware of the trade-offs of them,” Wauters told us. “We need to make the tooling easier to make these systems safer than pointing to HITL as a valid solution.” Anthropic noted in the post linked above that it built Claude Code auto mode to help users tackle approval fatigue by delegating some command-approval decisions to a model-based classifier. The system catches roughly 83 percent of what Anthropic calls "overeager behaviors" before they execute, meaning about 17 percent still get through in its evaluation. Auto mode is “one layer of defense-in-depth inside a sandbox, not a substitute for one,” Anthropic said. Wauters’ suggestion is to ensure that AI coding models are running in sandboxes, in devcontainers in the cloud, using tools like auto mode, and writing hooks to ensure potentially malicious actions are being contextualized and getting caught before they’re automatically approved. “It’s a whole new world with a new set of attack vectors,” Wauters wrote in May. “It’s best to remain aware of the risks and know how to reduce them.” ®
An unprivileged Linux program can time a hardware interrupt to land in the gap between a processor sanitizing its branch predictor and the kernel using it, re-poisoning the predictor after the defense has run.
MIT CSAIL researchers Daniël Trujillo and Mengjia Yan named the technique INTERRUPT INJECTION. On an AMD Zen 2 machine running Linux 6.14 with every default Spectre v2 mitigation on, Swati Khandelwalhttp://www.blogger.com/profile/ [email protected]
Meta has become the latest AI company to confirm that one of its models hacked a real organization during cybersecurity testing, as similar incidents continue to emerge following OpenAI'sOpenAI's initial disclosure that its agents breached Hugging Face. [...]
Vybrali jsme 30 jedinečných filmů napříč žánry a historií. Nabídnou to nejzajímavější ze světové i české filmové tvorby. Některé pobaví, jiné zasáhnou nebo přimějí přemýšlet – všechny by ale byla škoda během života minout.
Apparently, opening the thing is now enough. A repo can run before the first prompt, a package can hide among hundreds, and a harmless-looking PDF can finish the job.
This week runs on cheap leverage: exposed servers, recycled bugs, poisoned agent instructions, remote-access tools dressed as support software, and trusted defaults doing attackers a favor.
Nothing here is especially mystical. Ravie Lakshmananhttp://www.blogger.com/profile/ [email protected]
|