Agregátor RSS
Jak dobře vybrat bezdrátová sluchátka. Velká zajistí ticho a pohodlí, s malými klidně můžete sportovat
Bezdrátová sluchátka, to nejsou jen populární a módní kapesní modely True Wireless. Například pro cestování jsou vhodnější velké modely s aktivním potlačením hluku. Poradíme, jaké máte možnosti a na co si dát pozor.
Kategorie: IT News
Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt
Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on underground cybercrime forums and messaging platforms.
One such service, Poison Claude, claims to offer access to Anthropic's large language models (LLMs), including Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6.
"Advertisements for Poison Claude Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
Two security flaws in Paperclip could let attackers execute commands on a network server or a developer's computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on importing a malicious agent and starting it.
A third flaw could expose sensitive data and control-plane details through application programming interface (API) routesSwati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Cloudflare OS
Společnost Cloudflare představila Cloudflare OS (GitHub), tj. open source platformu navrženou pro integraci umělé inteligence (agentů) přímo do pracovních procesů organizací.
Kategorie: GNU/Linux & BSD
Google Blogger locks hundreds of blogs in malware false positive
Google has locked hundreds of Blogger websites after a false positive claimed they violated its "Malware and Similar Malicious Content" policy, with some sites deleted from the platform. [...]
Kategorie: Hacking & Security
Nejslavnější overclocker odstranil z chladiče procesoru větrák a nasadil na něj komín. Fungovalo to skvěle
Německý overclocker a hardwarový nadšenec Roman „der8auer“ Hartung, známý svými experimenty s chlazením a přetaktováním procesorů i grafických karet, opět zaujal netradičním projektem. Tentokrát se rozhodl ověřit, zda lze výkonný procesor AMD Ryzen 7 9800X3D uchladit bez ventilátorů pouze pomocí ...
Kategorie: IT News
Reducing Attack Surface Without Breaking Production
When people talk about Linux hardening, the conversation often quickly turns to enterprise security platforms, EDR agents, and complex monitoring stacks.
Kategorie: Hacking & Security
Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django.
The three most serious:
An unauthenticated flaw in Veeam's console that hands over a managed agent's credentials, rated 9.5
A cross-tenant flaw in HashiCorp's MCP server that lets one user's Terraform token be reused for later users'Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
How AI-powered phishing killed blocklists for good
AI is helping attackers create disposable phishing infrastructure and rapidly evolving toolkits that blocklists cannot track fast enough. Push Security explains why browser-level, technique-based detection offers a more durable defense than relying on domains, signatures, and other known-bad indicators. [...]
Kategorie: Hacking & Security
Lego má novou kosmickou ikonu. Série Icons se rozšířila o téměř půlmetrový Hubbleův dalekohled
A teď už může mít Hubbla na stole úplně každý. Lego rozšířilo svoji sbírku Icons o novou legendu: 38 centimetrů dlouhou repliku Hubbleova vesmírného dalekohledu.
Stavebnice se skládá z 1252 kostiček a stejně jako u ostatních zástupců technické sbírky nabízí hromadu detailů. Nechybí možnost ...
Kategorie: IT News
Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain
Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer.
The new dead drop resolver approach, observed in two trojanized npm packages "bianira-ui" and "fluid-type-ui," has been codenamed NullReceiver by Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
London cops handed victim's new address and number to her stalker, watchdog says
UPDATED The UK's data protection regulator has criticized London's Metropolitan Police Service (MPS) after its officers handed a victim's stalker details about her new phone number and home address, among other failures. The Information Commissioner's Office (ICO) today issued the MPS with an enforcement notice [PDF] and a reprimand over the two incidents, which occurred in 2024. Enforcement notices include specific steps offending organizations must take to meet their data protection duties under UK law, while reprimands serve as official warnings concerning breached data protection laws. The ICO outlined two major incidents that were caused by failures at the MPS, but added that they were not isolated and "reflected wider weaknesses in MPS policies, procedures, and assurance arrangements for handling sensitive personal information." The first involved a man subject to an interim Stalking Protection Order (SPO), which restricted him from contacting his victim. An MPS superintendent authorized an application for an interim SPO in January 2024 concerning a man who had been arrested the previous year on suspicion of harassment and malicious communications offences. The man was also, at the time, subject to bail conditions that included a prohibition on contacting the victim and their friends and family. As a result of the man's actions, the unnamed victim had to change her phone number and home address. Despite warnings that all personal information had to be redacted from the copy handed to the defendant, officers included unredacted witness statements and other documents. These exposed the new address and phone number of the victim, and those of her friends and family members. Within days, after the man fled the UK, breaching his bail conditions, the victim reported to the MPS that the defendant had contacted her on her new phone number. A full SPO was issued in May 2024, and the stalker was arrested in July upon re-entering the UK. He was later charged with stalking offenses and imprisoned following a guilty plea. The second incident was a classic CC-not-BCC email blunder, exposing the addresses of 18 people connected to the UK Parliament who had been targeted in a honeytrap operation by "a malicious actor." The MPS emailed those affected by the honeytrap scheme to update them about the date by which the suspect would have to answer bail, but forgot to use the BCC function, exposing the target's email addresses to one another. The MPS reported the breach that day, acknowledging that recipients might be able to deduce one another's identities from their email addresses, although three of the accounts had recently been deactivated. The MPS told the Information Commissioner that there was "no reported detriment" as a result of the breach and no official complaints made, although it was aware that "some" targets were "displeased" that their names had been shared. One MP raised the issue in the House of Commons. The ICO said that regarding the honeytrap scheme, the officer who sent the email had not completed data protection training for over four years at the time, and their line manager had not completed it for nearly four years also. The ICO found that data protection training completion rates were low across the force, and the MPS has committed to improving them. Jo Stones, group manager of civil and cyber investigations at the ICO, said: "People entrust the police with some of their most sensitive personal information, often at moments when they are vulnerable or at risk. They have the right to expect that information will be handled securely. "In these cases, the Metropolitan Police Service failed to put in place the safeguards needed to protect people's personal information. One breach exposed a stalking victim's new contact details to the person she needed protection from. Another revealed the identities of people connected to a highly sensitive investigation. "These incidents were foreseeable and preventable. Our action makes clear that organisations, particularly those in the public sector handling sensitive law enforcement information, must have effective training, monitoring and assurance in place. Policies and reminders are not enough if they are not followed, checked and enforced." The Met now has 12 months to improve compliance with its data protection training requirements, aiming for 100 percent completion and following up with staff who miss the deadline. It must also review every three months how officers send emails to multiple recipients, consider more secure alternatives, and report its progress on training completion to the ICO. Earlier this year, the ICO served the Met's commissioner with a separate enforcement notice over failures to meet duties under the Freedom of Information Act. It followed a previous notice issued two years earlier, with which the MPS complied. ® Updated to add at 1447 UTC: A Met spokesperson told The Reg: “We take all information breaches extremely seriously and ensure they are reported to the Information Commissioner’s Office (ICO) as soon as they become apparent. “We are aware that these incidents can have real consequences for victims and have apologised to those affected by these two cases. “While we are disappointed to have received this enforcement action, particularly given the improvements already made, we recognise that these breaches were not acceptable and fell short of the standards we expect. “The Met has taken significant steps to strengthen information disclosure processes, as acknowledged by the ICO, and remains committed to ensuring the right training and safeguards are in place to prevent similar breaches from happening again in the future.”
Kategorie: Viry a Červi
Super klávesnice do obýváku. Tahle bezdrátová za 419 Kč má touchpad, Bluetooth i české popisky
Alzácká klávesnice Eternico K200S zlevnila o 30 % na 419 Kč. • Bezdrátově se připojí ke třem zařízením, má české popisky a touchpad. • Spíš než k počítači se hodí na klín nebo konferenční stolek k televizoru.
Kategorie: IT News
Spotify má problém. Aplikace zpomaluje, zamrzá a přerušuje přehrávání i na výkonných telefonech
Kategorie: IT News
New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch
A memory corruption flaw in the Linux kernel's Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distributions, and a public exploit ships with pre-built records for roughly 800 kernel builds.
The vulnerability, tracked as CVE-2026-64531 (CVSS score: 7.8) and codenamed OVSwrap by its discoverer, was disclosed by security researcher Asim Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk
Kali365 is turning a legitimate Microsoft login into a gateway to corporate data.
The phishing kit targets US organizations with attacker-controlled device codes that victims approve on Microsoft's real authentication page. Once access and refresh tokens are issued, attackers may retain access to email, documents, and cloud resources, creating a direct path to data exposure, financial fraud, [email protected]
Kategorie: Hacking & Security
Asistent Google definitivně končí. Od září bude v Androidu jediným chytrým pomocníkem Gemini
Kategorie: IT News
UK charities count the cost of Beacon CRM cyberattack
Beacon CRM has confirmed it was hit by a cyberattack that exposed data belonging to a growing list of UK charities. The company, which markets its software to charities and has more than 1,500 customers, said its investigation remains ongoing. However, it appears that a substantial amount of customer data was copied, and Beacon is warning users to assume everything they stored on the platform was downloaded. "Currently, our investigation has confirmed that copies of database backups were made and likely downloaded by the unauthorized third-party," it said on Tuesday. "We have evidence that shows a spike in activity during the incident timeline symptomatic of data leaving our systems. "It is highly unlikely we will be able to ascertain any more granular detail regarding exactly what data this was and to whom it relates so out of an abundance of caution, you may want to assume that all data that you store in Beacon, including attachment files, has been downloaded." Beacon also warned that although customer data is encrypted, "it is possible that the unauthorized third party responsible for this incident was able to decrypt it." Customers should therefore assume the copied information was readable. Beacon did not answer any of The Register's questions, instead offering a statement that echoed the wording of its public FAQ pages. It did not comment on whether extortion demands were made, nor how or when the attackers got in. Beacon's information page says early evidence points to compromised credentials being used to access its systems. One affected charity said the company became aware of the attack on July 29. Beacon also said anyone with a paid account or free trial created before July 27 should assume that all data stored in it was downloaded. While the incident response folk do their thing, customers have been urged to investigate how badly they were affected. Beacon also reset every user's password and imposed stronger requirements on replacements. Charities hit Because Beacon CRM is a product specifically engineered for the charity sector, the bulk of those confirmed to be affected are UK charities. Among the higher-profile victims is the Molly Rose Foundation, a persistent campaigner on the UK's Online Safety Act. It said Beacon informed it of the situation on August 3, five days after the CRM company became aware of the breach. The foundation confirmed that personal data belonging to supporters, donors, and service users was affected. That includes names, addresses, email addresses, phone numbers, genders, dates of birth, records of donations or payments made to the foundation, and other information supplied in connection with its services and activities. The Scottish Council for Voluntary Organisations (SCVO) did not identify individual victims, but said many Scottish charities use Beacon CRM. Other charities confirmed to be affected include: London-based homeless charity The Upper Room Chiswick House and Gardens Trust Victim Support (no victim data affected) Macmillan Cancer Support Jersey, per the Bailiwick Express Young person's charity Motiv8, according to Portsmouth News UK-Med PANS PANDAS UK, a children's charity for those with the PANS and PANDAS conditions, said that it was unsure whether its data had been affected, having abandoned Beacon earlier in the year. English National Ballet told The Register: "As one of Beacon CRM's customers, English National Ballet was informed on 3 August 2026 that an unauthorised third party had gained access to their system. "English National Ballet has not received confirmation that our data was directly affected, however as a precaution we have informed all contacts as soon as possible that their data could potentially have been accessed. ENB take data privacy extremely seriously. We are doing everything we can to reduce the risk of anything similar happening in the future." ®
Kategorie: Viry a Červi
Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup
An unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in versions 1.22.1 through 1.27.0. No login, no repository write access. A public repository and crafted Org-mode markup are enough. The flaw is fixed in Gitea 1.27.1.
The file-read flaw is tracked as CVE-2026-59774, rated Critical with a CVSS score of 9.8, and received its Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Ošklivé elektrické Ferrari je vyprodané. Internet prorokoval fiasko, šéfové tech firem z USA a Číny vytáhli peněženky
Když se v květnu představilo první elektrické Ferrari všech dob, strhla se na internetu bouře všemožných názorů proč a jak je úplně špatně. Je elektrické, má tvary crossoveru, nikdo ho kupovat nebude, a když se zákazníci budou cukat, italská značka jim neprodá své výjimečnější modely se spalovacími ...
Kategorie: IT News
- « první
- ‹ předchozí
- …
- 24
- 25
- 26
- 27
- 28
- 29
- 30
- 31
- 32
- …
- následující ›
- poslední »



