Agregátor RSS

Užitečné aplikace od Samsungu, které měly být už v základní výbavě a stojí za to je nainstalovat

Živě.cz - 29 Červenec, 2026 - 19:45
Samsung je aktivní ve vývoji svých vlastních mobilních aplikací • Poté je však „schovává“ ve vlastním obchodě Galaxy Store • Vybíráme aplikace, které by měly být rovnou v základní výbavě
Kategorie: IT News

Apple preps for a wearable AI revolution

Computerworld.com [Hacking News] - 29 Červenec, 2026 - 19:29

This fall, with watchOS 27, Apple Watch will finally get access to Siri AI with a software update that turns your wrist into the most widely-used wearable AI platform on Earth.

That’s not hyperbole. Siri AI on Apple Watch is arguably the most important feature to this year’s watchOS update. Though it didn’t get much attention at WWDC, the update also offers a preview into how Apple will wrap AI into its future smart glasses.

What to expect

One important caveat is to observe that Siri AI on Apple Watch still requires your Apple Intelligence-enabled iPhone to do the heavy lifting. The interaction is easy: tap the Digital Crown and Apple’s new glowing icon appears on screen (you’ll also find this in the App viewer). The experience looks identical across every Apple device — iPhone, iPad, Mac, Apple Watch, and Vision Pro — making the assistant feel like one consistent product rather than a different experience per device.

The Siri app lets you access all your past Siri conversations (unless you turn that feature off) and pick up an old conversation right where you left off. Conversation history syncs privately through iCloud, so you can start an exchange on your iPhone and continue it later from your wrist. You can also pin a conversation you expect to revisit.

You can also use Siri on the Apple Watch to ask questions, launch apps, or even get more complex responses, such as step counts on a specific day. It can also answer difficult and specific queries with detailed answers and can summon real-time information from the web.

Personal context is the real story

That’s key, of course, as it means the smartwatch on your wrist can help you access specific details from all your contextual information; it can get details from messages, emails, and notes, for instance. Or you might use it to find a number and call it, access your door code, or look up customer information for business — all without touching your phone.

One of Apple’s own examples demonstrates this well: Saying, “Show me photos from when I went to Spain,” results in precisely that. You can also ask follow-up questions and keep the conversational going naturally, rather than being confined to single, isolated commands.

Beyond personal data, the watch can also act in apps — get directions home, send an email, play a playlist, or even more specifically, “Play the song that Brandon sent me.”

Context runs deep. A new Call Context tool can proactively surface relevant information from across your apps when phoning a business or help locate a confirmation code from Mail while calling an airline. This arguably challenges a real pain point when speaking with providers and is a good illustration of Apple’s broader AI strategy: to use on-device intelligence to remove everyday friction without asking you to track down the information yourself.

Where we are, where it’s going

It’s frustrating that you still can’t use the Watch to remotely run applications on your Mac, iPhone, or iPad. What you can do is trigger Shortcuts that run on your iPhone: enable this first on your phone by selecting the Shortcut you want and switching on “Show on Apple Watch.” Once that’s done, you can run the Shortcut from your wrist, even by voice.

That’s useful now, but as more complex apps add Shortcuts support and App Intents become more widely adopted by developers, it should be easy to trigger genuinely complex, multi-stage tasks on your iPhone from your wrist.

It’s worth noting: early hands-on testing of the watchOS 27 beta has found Siri AI genuinely impressive on personal-context queries, but still buggy in places. This is very much a first-generation feature — promising, but not yet fully reliable.

Watch the developers

Developers are already beginning to experiment with the potential for wearable AI. One of the best current examples is Granola, which just launched a Watch app built specifically to take notes during in-person meetings away from a laptop. The idea is that you tap your wrist, the screen turns green and makes a sound to alert your companion(s) that it is recording and then you carry on as normal. Once the meeting stops, switch the app off and you’ll get polished notes with meeting summaries and action items provided to you.

The only reservation I have with Granola is the lack of documentation on privacy and data retention on the developer site. Tools like these will almost certainly become more private, more secure, and more prevalent once Apple’s on-device dictation APIs extend fully to watchOS.

That last thing is perhaps the most important as wearable AI emerges: the decisions Apple makes around watchOS and SiriAI will be foundational to its future wearable AI glasses products.

You can follow me on social media! Join me on BlueSky,  LinkedInMastodon and subscribe to The Core.

Kategorie: Hacking & Security

KOReader 2026.07 "Sailing Walrus"

AbcLinuxu [zprávičky] - 29 Červenec, 2026 - 19:24
Multiplatformní prohlížeč elektronických knih KOReader byl vydán ve verzi 2026.07 "Sailing Walrus". U PDF souborů s SMask lze vyčistit pozadí. Přibyla podpora Kobo v5 nebo základní podpora OPDS 2.0.
Kategorie: GNU/Linux & BSD

Hraní na Linuxu bude zase přístupnější. Míří tam GOG Galaxy, hlavní rival Steamu

Živě.cz - 29 Červenec, 2026 - 19:15
Herní klient GOG Galaxy míří na Linux, bude tam konkurovat Steamu. • GOG už hry pro Linux prodával, ale stahovat se musely z webu. • Open source komunita už nyní využívá alternativní nástroje jako Lutris nebo Heroic.
Kategorie: IT News

Word worm crawls into Copilot, spreads chaos

The Register - Anti-Virus - 29 Červenec, 2026 - 18:43
UPDATED Watch out for untrusted documents. According to research, an attacker can hide malicious instructions in a Word document that, when included in Copilot for Word’s context, may alter document output and copy the instructions into newly created files that use the affected document as source material, without the victim noticing. Håkon Måløy, a Norwegian data scientist with a PhD in applied AI and ML, publicly disclosed the issue in a blog post Tuesday. Måløy describes the issue in considerable detail while withholding the specific prompt payload, arguing that, because no robust mitigation exists, it would be irresponsible to disclose anything beyond the class of the vulnerability. “To my knowledge, this is among the first public demonstrations of document-borne AI-worm self-propagation through normal workflows in a mainstream commercial productivity suite,” Måløy noted. Måløy said that he has been working with Microsoft since March 2026 on addressing the vulnerability, but after multiple updates to Copilot, this new class of Copilot worm is still viable. Microsoft mitigated the exploit demonstrated by his original proof-of-concept prompt, but Måløy said rewording the payload allowed him to successfully propagate the worm and alter financial data in a target document. Måløy and Microsoft twice delayed public disclosure of the issue, but, after 144 days, he said in his report that people needed to be made aware. “The coordination period agreed with Microsoft has been exhausted, and testing shows that no robust mitigation for the broader vulnerability class is currently available,” Måløy wrote. “Two mitigation attempts, including a model upgrade, did not close the class.” How Copilot propagates a Word worm Måløy explained the worm’s execution with an example involving an employee preparing a financial report for their company. The employee downloads a market analysis from a trusted website to help with the preparation of a financial report in Copilot, unaware that the source had been compromised and the document they downloaded contains hidden malicious instructions. The hidden instructions (inserted as small white text in his proof of concept) tell Copilot to alter figures in the report the employee generates and to copy the worm into the report they create with Copilot. If another employee later adds that report to their own work, the whole process begins again, and documents generated from it also contain the worm, and, as it spreads, it makes tracing the infection to its source extremely difficult. “The attack can therefore continue without further involvement from either the compromised website or the original malicious document,” Måløy said. “The attacker does not need access to the victim’s Microsoft 365 tenant. The attacker only needs to share a malicious document with the victim.” Copilot should use information in documents a user includes in its context for a project without treating instructions embedded in a document as additional prompts, Måløy said, but his research suggests it doesn't always do that. A fundamental flaw Måløy argues that he’s essentially dug up a new type of cross-domain prompt injection attack that abuses a fundamental part of modern LLM architecture. “For AI-assistants to be useful, they often must process emails, documents, webpages, memories, tool outputs, and other information that may be controlled by an attacker,” the researcher said. But if an LLM has to process data in order to determine it contains an attack, the attack could already be influencing that determination. “Relying on the model to detect XPIAs therefore resembles asking an interpreter to execute an untrusted program to determine whether that program is safe to execute,” Måløy asserted. Were Microsoft or some other company to pop another model in front of that model to check for malicious content, it only moves the problem outward, Måløy said, creating a “LLMs all the way down” scenario. “The long-term challenge likely lies in designing systems in which goals and intentions also exist independently of the information being processed,” he said. Until that time, Måløy argues, “any system that integrates an LLM into a trusted workflow today must assume that attacker-controlled content entering the model’s context will result in compromise at some rate.” What can Copilot customers do to reduce the risk? Short of ditching Copilot, there’s not much. “No customer-side remediation fully addresses the issue at the time of publication,” Måløy said, but he does have a few tips. Treat externally sourced documents as untrusted when using them in Copilot, he recommends, and fully review every single document before sending it to Copilot, and fully review any Copilot-generated or edited documents before distributing them. Sheesh - if you’re going to have to actually read that stuff, you might as well just cut Copilot out of the loop and do the thinking yourself. Microsoft has been in touch to confirm the research, but the company's statement doesn't do anything to allay fears this is an unsolved issue. “We have addressed the findings reported by the researcher and thank them for working with us through coordinated vulnerability disclosure. To address this class of risk, we use a defense-in-depth strategy with safeguards that block malicious instructions at multiple points and help keep tasks aligned with users’ requests. We are continuously strengthening these safeguards as the technology and threat landscape evolve. We encourage customers to install the latest updates, use multiple layers of security protection, treat content from unknown sources with caution, and review AI-generated content before using or sharing it.” We also reached out to Måløy, but didn’t hear back before publication. ® Updated at 1841 GMT on July 29 to add Microsoft's statement.
Kategorie: Viry a Červi

OpenAI agent used exposed credentials at 4 services in Hugging Face breach

Bleeping Computer - 29 Červenec, 2026 - 18:04
In a new update, OpenAI says its AI models also used publicly exposed credentials to compromise accounts on four third-party services during the recent attack on Hugging Face, expanding the scope of the four-day security incident to other organizations. [...]
Kategorie: Hacking & Security

22 nejlepších erotických thrillerů. Víme, jestli a kde si je můžete pustit online

Živě.cz - 29 Červenec, 2026 - 17:45
Osudová přitažlivost, Základní instinkt, Ďábelská svůdkyně, Nebezpečné hry, Dvojitý milenec. Exkurze do historie subžánru erotických thrillerů, v němž se napětí mísí se vzrušením.
Kategorie: IT News

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

The Hacker News - 29 Červenec, 2026 - 17:39
Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3. It has been codenamed RufRoot by Noma Security's
Kategorie: Hacking & Security

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

The Hacker News - 29 Červenec, 2026 - 17:39
Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3. It has been codenamed RufRoot by Noma Security's Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

The Hacker News - 29 Červenec, 2026 - 17:31
Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity. The first of the three critical-rated flaws is CVE-2026-59309 (CVSS score: 9.8), which has been described as an authentication bypass in VMware vCenter. "A malicious actor with network access to vCenter
Kategorie: Hacking & Security

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

The Hacker News - 29 Červenec, 2026 - 17:31
Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity. The first of the three critical-rated flaws is CVE-2026-59309 (CVSS score: 9.8), which has been described as an authentication bypass in VMware vCenter. "A malicious actor with network access to vCenter Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack

Bleeping Computer - 29 Červenec, 2026 - 16:55
The Minnesota IT Services (MNIT) agency activated its cybersecurity incident response capabilities across the entire state after hackers targeted more than 30 community water systems in "a coordinated cyberattack." [...]
Kategorie: Hacking & Security

Detecting Web Shell Activity on Linux Using Behavioral Clues

LinuxSecurity.com - 29 Červenec, 2026 - 16:53
Although its main website is loading, a production Linux server can host an active command-and-control gateway without any errors that can be seen. If you wait for the site to break or for users to report broken functionality, you are already months behind an attacker.
Kategorie: Hacking & Security

Opera konečně podporuje vertikální listy a zabrání zkopírování škodlivého kódu

Živě.cz - 29 Červenec, 2026 - 16:45
Opera 133.0.5932.85 přidává vertikální navigaci. • Zlepšuje také integraci Google Lens. • Od začátku července chrání schránku před škodlivými kódy.
Kategorie: IT News

Opera konečně podporuje vertikální listy a zabrání zkopírování škodlivého kódu

Zive.cz - bezpečnost - 29 Červenec, 2026 - 16:45
**Opera 133.0.5932.85 přidává vertikální navigaci. **Zlepšuje také integraci Google Lens. **Od začátku července chrání schránku před škodlivými kódy.
Kategorie: Hacking & Security

Why Automation Breaks When Visual Data Is Treated as an Afterthought

LinuxSecurity.com - 29 Červenec, 2026 - 16:05
Most automation projects don’t fail with dramatic outages; they fail through a slow erosion of trust.
Kategorie: Hacking & Security

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

Bleeping Computer - 29 Červenec, 2026 - 16:02
AI agents are designed to improvise as they complete tasks, making broad permissions a growing security risk. Token Security explains why identity, intent-based access controls, and least privilege are becoming the foundation for securing agentic AI. [...]
Kategorie: Hacking & Security

Windows 11 KB5101684 update released with 42 changes and fixes

Bleeping Computer - 29 Červenec, 2026 - 15:56
​​Microsoft has released the KB5101684 preview cumulative update for Windows 11 24H2 and 25H2, which 42 bug fixes and additional feature improvements for the operating system. [...]
Kategorie: Hacking & Security

Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systems

The Register - Anti-Virus - 29 Červenec, 2026 - 15:49
Security researchers at Tenable suspect the Iran-linked faux hacktivist outfit CyberAv3ngers was behind the cyberattack that disrupted more than 30 Minnesota water facilities. Neither state-level nor federal officials have made any claims regarding attribution for the attacks, however, Tenable reckons the operational pattern is consistent with the crew's previous raids, noting the timing relative to recent government warnings. The Cybersecurity and Infrastructure Security Agency (CISA) updated an advisory on Iran-linked attackers targeting programmable logic controllers (PLCs) across critical infrastructure on July 22, four days before Minnesota said the attacks targeted its systems. The advisory warned that Iran-linked hackers were attempting to disrupt operations using tactics previously associated with CyberAv3ngers. Government facilities, water and wastewater systems, and energy providers were among those urged to remain on high alert. What happened in Minnesota? On July 26 and 27, more than 30 community water systems across Minnesota were disrupted by what officials called "a coordinated cyberattack" targeting operational technology (OT). Minnesota IT Services (MNIT), the state's IT agency, said the Department of Health is working with the affected water facilities to ensure public health is maintained. No cities have yet asked citizens to modify the amount of drinking water they consume, per MNIT's latest update. The agency did not offer many other details about the attacks, other than to mention all the different agencies, organizations, and bodies it is working with as part of the investigation. One of the first cities to report issues, Braham, warned that its water reserves were limited in its initial notice. Citizens were asked not to water their lawns or use water for recreational purposes, although the problems were resolved the same day. No such directives were issued in other affected cities. Maple Plain declared a state of emergency, allowing it greater flexibility to coordinate resources, but did not ask residents to adjust their consumption. The same was true in the Twin Cities suburb of Plymouth and in South St. Paul, which both confirmed cyber-related problems on July 27 but did not ask residents to curb water use. "Cyberattacks against critical infrastructure require a coordinated, whole-of-government response," said John Israel, MNIT assistant commissioner and Minnesota CISO. "MNIT is working side by side with our partners to share intelligence, support affected communities, and help utilities restore operations safely while strengthening defenses against future attacks. "This incident demonstrates why Minnesota has invested in strong cybersecurity capabilities and partnerships. Our response worked as intended, enabling agencies at every level of government to rapidly coordinate, contain the incident, and help prevent more serious impacts to critical services." What is CyberAv3ngers? First identified around 2020, CyberAv3ngers is widely believed to be linked to Iran's Islamic Revolutionary Guard Corps (IRGC), specifically its Cyber-Electronic Command division (IRGC-CEC). For the first two years, the group began as a "propaganda persona," as Tenable puts it, claiming disruptive attacks on Israeli infrastructure – claims that were later debunked as fabrications. Its first sustained campaign came in November 2023, when it compromised PLCs at the Municipal Water Authority of Aliquippa, Pennsylvania, defacing them anti-Israel messages. Tenable said CyberAv3ngers compromised at least 75 Unitronics Vision Series PLCs across the United States, Israel, the United Kingdom, and Ireland as part of the campaign. They did so by exploiting default passwords. Between 2024 and 2025, the crew developed the IOCONTROL malware kit, built for attacks on OT and Internet of Things (IoT) devices. OpenAI said in 2024 that the group's members used ChatGPT in the development process. CyberAv3ngers stepped up its activity in 2026, targeting US critical infrastructure through Rockwell Automation/Allen-Bradley PLCs from March onward. CISA's July 22 update added Schneider Electric and Siemens equipment to the list of potential targets. In some cases, the attacks - which targeted multiple critical infrastructure sectors - disrupted operations at affected facilities, federal officials said, though they offered no specifics on what those disruptions entailed. CyberAv3ngers is known for targeting small water and municipal facilities, which experts believe are among the lowest-hanging fruit in US critical infrastructure. Many small and rural facilities lack dedicated cybersecurity resources. Tenable said some operators manage OT environments using remote-access software such as TeamViewer and AnyDesk or leave their PLCs exposed to the web. "These access methods bypass enterprise security controls entirely, creating an attack surface that is invisible to conventional security monitoring," Tenable said. Poor segmentation between IT and OT environments can also allow a single intrusion to spread across much of the network. ®
Kategorie: Viry a Červi
Syndikovat obsah