Agregátor RSS

New XCSSET variant targets macOS devs via compromised Xcode projects

Bleeping Computer - 4 Srpen, 2026 - 21:03
A new version of the XCSSET malware is targeting thousands of macOS users through compromised Xcode projects and GitHub repositories. [...]
Kategorie: Hacking & Security

77 Open VSX extensions found harvesting developer info

Bleeping Computer - 4 Srpen, 2026 - 20:50
77 extensions on the Open VSX marketplace impersonated legitimate developer tools while transmitting information about the systems and development environments where they were installed. [...]
Kategorie: Hacking & Security

FFmpeg 9.0 "Lei"

AbcLinuxu [zprávičky] - 4 Srpen, 2026 - 20:48
Jean-Baptiste Kempf na svém blogu představil novou verzi 9.0 "Lei" kolekce svobodného softwaru umožňujícího nahrávání, konverzi a streamovaní digitálního zvuku a obrazu FFmpeg (Wikipedie).
Kategorie: GNU/Linux & BSD

NVIDIA sponzorem služby Linux Vendor Firmware Service (LVFS)

AbcLinuxu [zprávičky] - 4 Srpen, 2026 - 20:16
Richard Hughes oznámil, že službu Linux Vendor Firmware Service (LVFS) umožňující aktualizovat firmware zařízení na počítačích s Linuxem, nově sponzoruje také společnost NVIDIA.
Kategorie: GNU/Linux & BSD

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

The Hacker News - 4 Srpen, 2026 - 19:27
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts. "Greatness supports AiTM [adversary-in-the-middle] credential and Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

The Hacker News - 4 Srpen, 2026 - 19:27
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts. "Greatness supports AiTM [adversary-in-the-middle] credential and
Kategorie: Hacking & Security

Bypassing AI guardrails is so easy a script kiddie can do it

The Register - Anti-Virus - 4 Srpen, 2026 - 19:15
If you want to bypass AI guardrails designed to stop models from assisting with cyberattacks, you often just have to ask the right way, according to researchers from Cisco Talos. Simply claiming you own the servers you're targeting or that you're taking part in a capture-the-flag or bug bounty exercise was often enough to persuade models to cooperate. Talos researchers have been poring over prompt logs and artifacts recovered from threat-actor endpoints running tools such as Claude Code, Codex, Cursor, and Gemini to learn how suspected threat actors are abusing LLMs. The big takeaway from that "significant corpus," the researchers said in their report, is that existing guardrails offer little resistance to operators willing to reframe their requests. “We did not encounter any sophisticated encoding or techniques designed to trick the models,” Talos explained. “Most of the time it was a simple ‘I'm allowed to do this,’ and the model complied.” When guardrails did manage to get between criminals and their prizes, the researchers added, “they accomplished little.” The bulk of the report consists of examples of threat actors trying, and often succeeding, to coax AI models into assisting with malicious activity. On the "guardrails doing little" side, Talos documented numerous examples, few of which relied on particularly sophisticated techniques. Most common in the list of easy-to-accomplish guardrail hops was simply claiming ownership of equipment or infrastructure that an attacker wanted to exploit. In many cases, simply telling the AI that a target belonged to the attacker was enough, with no need to provide actual evidence of the claim. Telling an AI model that what it was being asked to do was part of a capture-the-flag or bug bounty exercise also seemed to be a common tactic. That, the researchers explained, commonly freed chatbots from their ethical constraints, allowing them to hunt for vulnerabilities and then exploit them in target systems, again without any need to validate the user’s claim that they were undertaking an exercise instead of actually trying to commit a crime. AI-assisted cybercriminals were also frequently spotted decomposing tasks across multiple sessions and files in order to evade model protections that would only engage when a broader malicious activity was detected. Others, Talos explained, succeeded at bypassing AI guardrails by adding memories, markdown files, and other system-level prompts to a chatbot in a bid to condition the AI’s persona. The researchers said that, of all the methods they examined, the most interesting to them was malicious use of a red teaming toolset known as Hephaestus, as reported by Oasis Security threat researchers in May. According to Talos, the Hephaestus framework can do everything needed to compromise a victim, through to establishing persistence, without human interaction. “In that case, actors built their platform to avoid refusals altogether by using neutral verbs instead of overtly malicious ones,” Talos said. “As a result, they were able to have considerable success with agents conducting innocuous requests without realizing the full operational context.” In other words, break an attack into decontextualized chunks, phrase each request in neutral terms, and the model may never see enough context to realize it's helping build an attack. One bright spot in all of this is that Talos’ review of AI chat artifacts suggests AI might be a force multiplier for skilled hackers, but your average script kiddie with a Claude Code account isn’t going to get very far. “Unsophisticated actors can use AI to cobble together malicious projects that technically work, but lacking the expertise to push the tools further, they end up with substandard results,” the researchers said. “By contrast, sophisticated actors have pushed the bounds of what we thought possible.” So, what does all this mean for security professionals kept up at night with fears of an AI attack on their infrastructure? You probably need to deploy AI in the same way threat actors are. “Agents are going to become a bigger part of the SOC as these volumes rise, and identifying actionable alerts will be paramount,” the Talos researchers said of the big takeaway for enterprises. “Organizations that aren't already exploring agentic capabilities to let human analysts focus on the most important alerts will soon find themselves chasing that capability.” It’s not like this is an emerging threat, either: AI is already an increasingly important part of threat actor arsenals. According to CrowdStrike, attacks by AI-enabled adversaries increased 89 percent in the past year, and the speed at which attackers are weaponizing vulnerabilities with AI has reduced practical patch windows to as little as 24 to 48 hours. You might wanna act now before your infrastructure becomes a statistic. ®
Kategorie: Viry a Červi

‘Apple is one of the greatest companies of all time,’ says OpenAI

Computerworld.com [Hacking News] - 4 Srpen, 2026 - 18:54

In an open letter, OpenAI this week turned to the court of public opinion in its existential war against Apple with a public notice in which the company refutes the iPhone maker’s claims concerning wholesale use of confidential information.

You can detect the depth of enmity between both firms in OpenAI’s opening lines to its letter, which begins: “Apple is one of the greatest companies of all time,” and then moves swiftly into defending itself against company’s claims, while attempting to characterize Apple’s complaints as weak.

What Apple claimed

As reported elsewhere, Apple filed suit against OpenAI in the US District Court for the Northern District of California on July 10. The litigation names OpenAI Foundation, OpenAI Group PBC, io Products, Chang Liu (former senior systems electrical engineer), and Tang Yew Tan (former vice president of product design for iPhone and Apple Watch, now OpenAI’s chief hardware officer), and alleges breach of intellectual property agreement and misappropriation of trade secrets under the Defend Trade Secrets Act. The company has since then filed preservation orders to protect evidence. 

Apple’s complaint is more detailed than that. Among many other things, it claims Tan allegedly directed job candidates still at Apple to bring “actual parts” to interviews for “show and tell” sessions. It also alleges Tan distributed an internal Apple document describing Apple’s own departure security protocols to new hires before they resigned. Liu is separately accused of failing to return an Apple laptop and using it to download confidential technical documents.

OpenAI’s rebuttal

Now, OpenAI argues Apple’s trade-secret lawsuit is based on factual errors, poor communication and misleading claims. It says Apple mistakenly contacted the wrong OpenAI lawyer after confusing two people with the same surname, falsely claimed a phone call had occurred, then acknowledged both mistakes without raising the allegations later included in the lawsuit. (Apple says it sent OpenAI a warning letter back in February with no response, which undercuts OpenAI’s “we offered to resolve this before litigation” statement.)

OpenAI argues that Chang Liu was responding to requests from Apple colleagues seeking help locating Apple files, reflecting Apple’s own access-management failures rather than misconduct. It also claims Tan consistently instructed OpenAI staff not to seek or use competitors’ confidential information. OpenAI maintains it neither possesses nor wants Apple’s trade secrets, offered to resolve concerns before litigation, and finally argues that Apple’s request for a preliminary injunction is unnecessary and unsupported.

What Apple might actually argue

Will Apple see it the same way? That seems unlikely, in part due to the extent of the claimed infractions. Apple will point to the hundreds of former Apple employees now at OpenAI, including former Chief Designer Jony Ive. In doing so, it will likely argue that the remit of the case is not defined by erroneous legal correspondence, though that is probably seen as an error. Instead, the substantial claims it’s likely to focus on are that OpenAI has been engaged in a multi-front attempt to accumulate information pertaining to Apple and its design processes through recruitment and the way it recruits.

It’s feasible both arguments have some validity. OpenAI might be right in pointing out weaknesses in Apple’s own approach to internal communications in terms of secrecy. And Apple is correct in pointing out that OpenAI moved to abuse those vulnerabilities, weaknesses in its approach that have only been identified during OpenAI’s campaign to grab secrets.

While the Apple lawyer’s error in approaching OpenAI might be an unforced error that helps the AI firm cast doubt on Apple’s claims, it doesn’t necessarily invalidate them — and both sides believe themselves to be justified. Deciding which company is in the right will be a matter of law and not of public opinion.

Which side does the smoking gun face?

To prove its position, OpenAI shared some correspondence. These communications do seem to show a failure at Apple to properly implement device management over employee accounts, including the claim that personal iMessage accounts are routinely used to share corporate correspondence. That may be true, and shouldn’t be – it’s an obvious weakness in corporate security.

At the same time, the correspondence also shows hints of job opportunities at OpenAI for and to a former colleague, which kind of proves part of Apple’s point in terms of steady employee poaching. “I can always give you some fun side projects,” one message said. 

Of course, interaction between former colleagues is inevitable,. But at the level of seniority here, it feels plausible this could be in breach of any off-ramping arrangements reached between Apple and its former employees. No doubt, courts will decide that – though it does underline Apple’s claims that OpenAI instructed former Apple staffers about how to leave without reaching such agreements.

“This isn’t Apple getting it wrong. It is OpenAI getting caught with its hand in the hardware cookie jar and then writing a blog post about how the jar was left unlocked,” US tech thought leader Brian Roemmele wrote on X.

Where happens next?

Ultimately, what comes next is up to Apple and OpenAI. The two companies might reach a deal out of court, or be forced into an agreement by the legal system. The existential nature of the rivalry suggests the latter, rather than former.

It is also very telling that OpenAI, which now has more than 400 former Apple employees on its teams, including many former designers, also claims: “Apple’s request for a preliminary injunction is both based on false information and completely unnecessary because we do not have, nor want, any of their trade secrets. We’re much more interested in building innovative products and technologies that push the frontier.”

While Apple hasn’t yet responded, it will be interesting to see whether whatever hardware OpenAI ships looks and behaves like any released or unreleased Apple products; the latter will now be able to bring details of its own historical project design decisions — and the people who made them — to court.

I think this case will play out over time. Perhaps the most interesting question is whether OpenAI has taken what it knows about Apple to create its own internal product design and development LLM models. Would that use be legitimate? It would, after all, not be the first time an AI company has trained its models on other people’s creative energy.

You can follow me on social media! Join me on BlueSky,  LinkedInMastodon and subscribe to The Core.

Kategorie: Hacking & Security

This one time, at Hacker Summer Camp …

The Register - Anti-Virus - 4 Srpen, 2026 - 18:47
As the entire security industry descends on Las Vegas this week for Hacker Summer Camp – not one, but three conferences – attendees can count on two hot topics dominating the discussion. First, a literal hot topic: the triple-digit August heat. Second, and to no one’s surprise: agentic AI – how to govern and secure agents so they don’t go rogue and hack into other organizations’ servers (*cough* OpenAI *cough* Anthropic *cough*); what role, if any, lawmakers should play in regulating models, including open-weight and Chinese LLMs; and how the baddies are using agents for autonomous hacking operations. Plus, at one of the three (Black Hat), we expect to hear how all of the vendors' shiny new agents can solve all security woes, finding and defending against threats at machine speed and all of that. Starting with BSides Las Vegas (August 3-5): This is the smallest, most relaxed, and most community-driven event of the three. BSides is a good starter con for those just dipping their toes into Hacker Summer Camp. Its technical talks and training sessions skew hands-on and useful for practitioners – not vendors selling their wares–- and it even has a Hire Ground career-focused track centered on job hunting, interviewing, career-building, networking, and yes, using AI to remain relevant as a security professional. Black Hat (August 1-6) is the largest and most corporate of the Vegas infosec events this week, complete with a massive expo floor, a US government-heavy opening session, two keynotes, 11 mainstage presentations, and a handful of industry- and topic-specific summits, ranging from healthcare to financial threats and AI. Training days – these are the hands-on, technical courses – run through Tuesday, with all of the specialized summits also occurring on Tuesday. And while the main conference occurs Wednesday and Thursday, the opening session on Tuesday should be considered a keynote. And yes, this and the actual two official Black Hat keynotes this year, all center on AI. After the FBI, NSA, and CISA speakers and panelists all cancelled their RSAC appearances earlier this year, the feds will be out in force at the infosec industry’s other big event, beginning with Tuesday’s opening session: Cyber Power in the Age of AI. This one features the White House National Cyber Director Sean Cairncross discussing President Trump's cyber and AI strategy, joined by CISA acting director Nick Anderson, FBI cyber division assistant director Brett Leatherman, and assistant secretary of defense for cyber policy Katherine Sutton. Later, the Wednesday and Thursday keynotes tackle a mounting challenge for security teams, patch managers, and sysadmins: AI-powered vulnerability research and discovery, plus exploit generation, and how defenders can evolve and keep pace. Plus, this year’s Black Hat hosts the world-premier screening of cyberwar documentary Midnight in the War Room on Wednesday. It focuses on the psychological toll on defenders. And it features interviews with former attackers, some of whom served prison sentences, alongside high-ranking cyber officials like Chris Inglis, the first US National Cyber Director, and former CISA director Jen Easterly, who is now CEO of RSAC. Finally, camp closes with DEF CON (August 6-9), which serves up plenty of hacks and hijinx, under this year’s theme of “agency,” or self-determination. As Jake Braun, one of the creators of the first-ever Voting Machine Hacking Village at DEF CON in 2017, told us earlier this year, agency involves the human-rights community and the hacker community needing to “sit down and look at what technologies are out there today that support the preservation of human rights around the world, figuring out what we don't have, and then building those missing pieces.” Keeping with this theme, Braun, who also serves as DEF CON Franklin’s Executive Director, will also update the hacker community about this critical infrastructure security program. The Franklin project, which launched at DEF CON in 2024, enlists hackers to secure critical infrastructure. Hundreds of volunteers have helped 21 different water utilities in seven states so far. This is especially timely as attacks against US water facilities increase. With nearly 30 Villages this year, covering everything from AI to car hacking and lockpicking, there will be plenty of high-quality talks and good fun for attendees. As always, your humble vulture will be making the rounds and reporting from the events, so send tips our way, stay safe, and leave your pervert glasses at home. ®
Kategorie: Viry a Červi

Češi zajistí ještě odolnější iPhony. Apple koupil brněnské experty na úpravu povrchů

Živě.cz - 4 Srpen, 2026 - 17:45
Apple se svými nákupy příliš nechlubí. Tahle akvizice proběhla už v dubnu letošního roku a dozvěděli jsme se o ní jen díky oznámení Evropské komise. Formálně akvizici provedla dceřinná společnost Applu, finanční pozadí neznáme. Předmětem akvizice je společnost PlasmaSolve s.r.o., sídlí v Brně, ...
Kategorie: IT News

Feds get 3 days to patch N-able God mode flaw under active exploit

The Register - Anti-Virus - 4 Srpen, 2026 - 17:38
The US Cybersecurity and Infrastructure Security Agency (CISA) has added an exploited N-able vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, giving federal agencies three days to patch a flaw that could let attackers reach managed service provider (MSP) customers. Attackers exploiting the flaw can gain "full administrative access to an N-central console," Tracked as CVE-2026-18577 (8.2 CVSSv4), N-able disclosed the vulnerability affecting N-central on Sunday, noting that it was exploited as of July 31. MSPs use N-central to manage customer systems from a single dashboard, and successful exploitation can hand an attacker administrative access to the console. Based on the limited set of partner logs it reviewed, security firm Huntress said successful attacks led to pivots into managed endpoints and the creation of Cloudflare-based tunnels for persistent access to victim networks. "From an MSP perspective, exploitation of this flaw can grant an attacker full administrative access to an N-central console – the same level of control normally reserved for trusted NOC and engineering staff," wrote Huntress's Ben Bernstein and John Hammond. Attackers can then open remote control sessions on critical systems and modify roles, accounts, and policies to support follow-on attacks. The vulnerability affects N-central releases earlier than version 2026.3 when the server is exposed to the internet or reachable from an untrusted network. Huntress advised customers unable to apply N-able's hotfix immediately to disable N-central until they could do so. Authorities elsewhere have also urged users to patch. NHS England's advisory mentioned that its National Cybersecurity Operations Centre assessed that "further exploitation is likely," while Belgium's Centre for Cybersecurity urged fast action due to the "potential for significant impact." CVE-2026-18577 is related to an earlier flaw, CVE-2026-18556, patched in N-central 2026.2. According to N-able, that fix left another route to exploitation, which attackers began abusing late last month. CISA gave Federal Civilian Executive Branch agencies until August 6 to remediate the flaw. Under Binding Operational Directive 26-04, CISA can impose a three-day deadline on vulnerabilities it considers an urgent risk rather than allowing the usual 14 days. According to Huntress's data, affected customers have leapt into action. By August 3, nearly all cloud-hosted N-central instances had been patched, although 28.6 percent of observed self-hosted servers remained vulnerable and exposed to the internet. ®
Kategorie: Viry a Červi

Massive ChainDrop npm supply-chain attack infects hundreds of packages

Bleeping Computer - 4 Srpen, 2026 - 17:24
Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry. [...]
Kategorie: Hacking & Security

AI agents get better at IT ops, but only with humans in the loop

Computerworld.com [Hacking News] - 4 Srpen, 2026 - 16:53

AI agents are performing roughly 1 in 3 actions in enterprise IT workflows (but that share is rising quickly), while human analysts are rejecting about one-quarter of AI-proposed actions (but that rate is falling), according to a new study of tens of thousands of human-AI interactions. Operational data, rather than underlying AI infrastructures, is often the culprit when things go wrong.

Human analysts are approving the most consequential actions, managing exceptions, and supervising and shaping agentic systems, while AI agents are carrying out routine tasks and executions, automation platform provider Fixify found in the study.

“That may sound less dramatic than replacing the help desk,” Matt Peters, Fixify’s co-founder and CEO, wrote in a blog post. “It’s also a much more credible path to changing how IT work gets done.”

Building scaffolding

Fixify identified four steps of agentic work: Planning, proposing, approving or declining, then acting on approved steps.

It analyzed nearly 18,000 plans and over 147,000 actions executed by agents across 40 companies over a three-month period, finding that agents are taking over one-third of IT actions, most notably in software, applications, security, and collaboration work where requests tend to be “repeatable and easy to reverse.”

Tasks that are well understood and that present low risk are best suited for the current generation of agents, Peters wrote. Human analysts remain closely involved in higher-stakes areas like identity verification, setting up and removing IT access (onboarding and offboarding), and hardware environments.

However, AI’s share of the work is increasing as feedback loops improve: Over the three-month period, human approval of AI-proposed actions rose from 23% to 41%, and rejection fell from 27% to 16%, Fixify found.

The company identified six types of actions in AI automation. Running a skill — actually doing something — accounted for 39.4% of all actions). Most of the rest were coordination: sending a message to the human requester (27.7% of actions), leaving an initial comment (13.2%), giving instructions to a human analyst (9.8%), or waiting (8.8%). Running entire workflows accounted for just 1.1% of actions.

AI is building “scaffolding” that wraps around meaningful changes, often planning far more scenarios than the agent will execute. Typically, agents map out 15 possible actions but run only two, Fixify said.

“The agent maps the paths a request could take, then walks down the path that makes the most sense as it meets reality,” the study said.

Peters pointed to one example where an AI agent identified which team needed access to process a high-volume type of ticket. Rather than fully automating the process, the agent did the initial triage, asked questions, then routed tickets to the team that had the information to act immediately.

“We didn’t need a world-ending hive mind,” he said. “We just needed to point a little conversational intelligence in the right direction.”

When AI breaks down

IT automation typically involves analyzing tickets and moving them along; in other words, low-risk tasks.

But agents do participate in areas like security (albeit only about 6%), most notably adding and removing people from groups or channels, unlocking accounts, resetting passwords, analyzing multi-factor authentication (MFA), provisioning (or deprovisioning) accounts, and assigning software licenses.

However, this identity-lifecycle work is where agents failed the most, particularly in onboarding and offboarding and identity-access management (IAM), the study found. “Hardware and connectivity changes rarely fail; identity-lifecycle changes fail three-to-nine times as often.”

Why AI breaks down

Thanks to human-in-the-loop controls, Fixify was able to analyze scenarios where agent recommendation diverged from human judgment. This occurred about 23% of the time.

The largest failure category (nearly 50%) was ‘target not found,’ meaning the agent couldn’t uncover what it needed. This typically comes down to poor data: A user, group, account, or resource was not where the system expected it to be. When people change teams, groups are restructured, accounts are renamed, or work has already been done but not reflected in the system, this is more of an identity hygiene problem than an AI problem. The system needs cleaner and more current data.

Invalid inputs accounted for around 29% of failures, followed by unhandled errors, denied permissions, or invalid operations or configurations. The latter signal “real breakage” in integrations, according to Fixify.

AI becomes more sophisticated over time

The good news is that AI automation improves over time, even if it might take a while. In hybrid systems, humans keep the most consequential changes under their own control, and iterative rejection and approval helps AI learn.

Over time, agents’ plans get leaner and they start to re-plan when conditions change, rather than pre-planning all kinds of scenarios that may never occur. “That’s a sign of sophistication,” the study said. “Adapting in the moment is a more advanced behavior than trying to pre-script every contingency.”

In turn, humans second guess the system less often and feel comfortable handing off more work. Instead, they control how agents behave, make high-impact decisions, and handle exceptions. “The hardest requests remain human-heavy, especially those that require repeated replanning or contextual judgment,” the study said.

How teams can adapt to AI agents

As agentic AI becomes embedded in more workflows — and at deeper levels — enterprises must evolve to accommodate, Fixify emphasized.

This means investing in clean identity data and building strong playbooks, review workflows, and reliable integrations.

Teams should judge agentic tools by their supervision loop and view rejections as a training process, Fixify advised. Analyst time, queues, and metrics should be built around reviewing proposals. Agent replanning can be seen as a routing signal: A single replan might indicate healthy adaptation, while repeated replanning means ambiguity, irrelevance, or unclear policies.

“Make the review surface easy to understand so analysts can assess proposed actions and make quick decisions about how to proceed,” the study advised. “This is where the analyst’s attention belongs.”

Kategorie: Hacking & Security

Napsal původní Správce úloh pro Windows. Teď se legendární vývojář Microsoftu pustil do díla znovu

Živě.cz - 4 Srpen, 2026 - 16:45
Dave Plummer vytvořil původní Správce úloh ve Windows a další aplikace. • Teď na vlastní pěst vydal pokročilý Task Manager OG. • K dispozici je pro macOS, vyjde i na Windows a Linuxu.
Kategorie: IT News

AI helps Microsoft bug hunters chase a record $20M payday

The Register - Anti-Virus - 4 Srpen, 2026 - 16:40
Microsoft announced this week that between July 1, 2025, and June 30, 2026, the company had paid more than $20 million in bug bounties to 562 researchers. The total was a Redmond record, as was the number of those submitting bug reports – despite having to navigate a sometimes frustrating submissions process. For comparison, the previous year's program, which itself set a new company record, paid 344 researchers around $17 million. You could argue that the numbers do not represent a fair fight, however. Microsoft expanded its bug bounty program in December 2025, changing reports to what it calls "In Scope By Default." Under the policy, critical vulnerabilities became eligible for rewards if they had a direct and demonstrable impact on Microsoft's online services, even when the faulty code belonged to a third party or an open source project. In short, Microsoft had opened the door to paying out a shedload more each year. Microsoft introduced the policy roughly halfway through the bounty year and said it accounted for $800,000 in rewards that would not previously have been available. Another $2.3 million was awarded through Zero Day Quest, Microsoft's security research challenge and live hacking event. The increased number of reports this year can also be partially explained by the noticeable influx of submissions during the second half of the year, Microsoft said, which the company attributed in part to "the growing use of AI to support security research." Microsoft has also attributed its increasingly crowded Patch Tuesdays partly to its own use of advanced AI models for vulnerability discovery. July's 622 vulnerabilities pummeled the previous record of 206, set only a month earlier. June had itself surpassed April's 165, which at the time was Microsoft's second-biggest Patch Tuesday ever, and May's 137. Days before the record-breaking July Patch Tuesday, Microsoft's Windows + Devices veep warned customers to expect more of the same now that AI plays a big part in vulnerability discovery, both inside Microsoft and by external bounty hunters. However, Microsoft Executive VP of Windows + Devices Pavan Davuluri was quick to point out that the company offers customers a suite of automated patching tools to ease the burden, but didn't mention anything about tools to fix the machines its Windows updates so often borks, like Intel-based Dells. As well as navigating the rapid AI-ification of vulnerability research, and the onslaught of reports that came with it, Microsoft has arguably faced a bigger bug problem this year amid unverified speculation that one prolific researcher may be a former Microsoft staffer. Using the name NightmareEclipse, a researcher with deep knowledge of Microsoft's software and an equally apparent disdain for the company spent Q2 dropping sophisticated zero-days at will. NightmareEclipse claims that attempts to report vulnerabilities to Microsoft ended with them being insulted, humiliated, and left homeless. They subsequently began publishing zero-days outside coordinated disclosure, often shortly after Patch Tuesday, saying they wanted to cause Microsoft maximum pain. These ranged from serious privilege escalation flaws leading to SYSTEM access to BitLocker bypasses, and the approach seemed to have inspired at least two other aggrieved researchers to just drop the exploit code outside of responsible disclosure. Microsoft responded by threatening to involve its Digital Crimes Unit in the dispute with NightmareEclipse, suggesting it was willing to engage law enforcement, although this went down about as well as you would expect. ®
Kategorie: Viry a Červi

AI Is Already Performing Linux Security Work. What Happens When It Escapes Containment?

LinuxSecurity.com - 4 Srpen, 2026 - 16:05
Nearly everyone following technology has heard about the recent security incidents involving OpenAI and Anthropic. The headlines focused on the containment failures. For Linux administrators and security teams, however, the more important detail is what those systems were doing when it happened.
Kategorie: Hacking & Security

Varonis Agent IBAC keeps AI agents within their intended boundaries

Bleeping Computer - 4 Srpen, 2026 - 16:00
AI agents need broad access to be useful, but traditional access controls cannot determine whether an action aligns with a user's intent. Varonis explains how Agent IBAC detects intent drift and enforces real-time guardrails to keep agents within their intended boundaries. [...]
Kategorie: Hacking & Security
Syndikovat obsah