Agregátor RSS

Claude bude do AI textů vkládat vodoznak. Jak se dá neviditelně podepsat něco, kde jsou jen znaky?

Živě.cz - 13 Srpen, 2026 - 13:45
Anthropic začne nepostřehnutelně značkovat všechny texty od Claude • Model přidá nepatrnou statistickou odchylku, kterou detektory dokážou najít. • Vodoznak ale neprozradí, kolik textu model napsal – a kdo ho chce smazat, smaže ho.
Kategorie: IT News

AWS key exposed in JavaScript may have lit way to Beacon's charity data

The Register - Anti-Virus - 13 Srpen, 2026 - 13:34
Beacon, a CRM provider for charities and nonprofits, says an AWS access key "potentially exposed in public JavaScript build artifacts" is the leading suspect in its July breach. The revelation came in the company's first update on the attack in more than a week. If the access key was exposed in public build artifacts, it raises questions about why Beacon's development pipeline and code review controls failed to catch it. Beacon used stronger wording about the potential data loss, confirming that a copy of the database was made and assessing that it was probably downloaded in readable form. "This update confirms… that a copy of the database which holds all Beacon customer data, including attachment files, was made and likely downloaded in a readable format by the threat actor," wrote CTO David Simpson. "Analysis of the AWS Cost & Usage reports across May-July 2026 has been conducted. This data showed a significant increase in data transfer on 27-28 July 2026. This timing correlates with the malicious activity, which supports an assessment that substantial downloads occurred." Beacon's logs cannot reveal which specific records left its systems, although the company has confirmed that a copy of the database containing all customer data and attachments was made. In an FAQ accompanying the update, Beacon advises customers to assess the likely exposure by reviewing what they stored in their CRM instance. Many of the charities that have confirmed they are affected have said the data mainly pertains to personal information and details about donations. Simpson said Beacon's AWS data was encrypted at rest, but the compromised access key may have allowed the attacker to retrieve it in readable form. The malicious activity began in the early hours of July 27, according to Beacon's root cause analysis, matching its initial estimate of the incident timeline. The company has more than 1,500 customers, although it has not established how many had data taken. The malicious activity lasted one hour and 27 minutes, Beacon said, and the attacker established no persistence mechanisms in AWS. Simpson warned customers that "there are things we may never be able to find out about this incident," and that other details won't be shared to protect Beacon's security position. He promised to provide customers with a summary when the investigation concludes in a few weeks, but warned that "the level of detail contained in this next and final update may not be any more than" Beacon published on Wednesday. "I recognise this is frustrating, but unfortunately it is the reality of complex incidents like this. With this in mind, we would recommend making your own risk assessments now regarding onward notification to impacted data subjects using your knowledge of the data you process and store with Beacon." Since Beacon disclosed the attack on August 4, the number of high-profile charities confirming they are affected has grown every day. Early confirmations came from the likes of Molly Rose Foundation, Macmillan Cancer Support Jersey, and English National Ballet. Sheffield Hospitals Charity, Shrewsbury and Telford Hospital Charity, the British Deaf Association, and Lincoln Cathedral are among those that have since joined the list. The Charity Commission said that "a number of charities have submitted serious incident reports," and that the volume of these reports is causing delays to responses. "We appreciate your patience and understanding as we prioritise instances of the greatest risk," it said. ®
Kategorie: Viry a Červi

Mapy.com přecházejí na vektorové mapy. Můžete pociťovat problémy a horší výkon

Živě.cz - 13 Srpen, 2026 - 12:45
Mapy.com postupně přecházejí od bitmapových/dlaždicových map k těm vektorovým. Novinku Seznam pouští mezi 5 % uživatelů, aby otestoval, jestli je všechno v pořádku. V některých případech ale není. Uživatelé si na oficiálním fóru stěžují, že mapy se vykreslují chybně či vůbec, může být problém s ...
Kategorie: IT News

OpenAI: Latest news and insights

Computerworld.com [Hacking News] - 13 Srpen, 2026 - 12:08

OpenAI is an artificial intelligence organization comprised of the non-profit OpenAI, Inc. and several for-profit subsidiaries. The company is perhaps best known for its ChatGPT chatbot, which launched in 2022, kicking off a period of massive disruption in the tech industry and beyond.

A complicated and increasingly contentious relationship with Microsoft, ongoing legal issues over copyright infringement, and frequent product announcements keep OpenAI in the news. Follow this page and never miss a beat.

Latest Open AI news and analysis: OpenAI targets heavy users with premium ChatGPT Business seats

Aug. 11, 2026: OpenAI is introducing a higher-priced “Premium” tier for its ChatGPT Business offering, allowing enterprises to assign higher-capacity access to select users alongside standard licences – a move analysts said is about enterprise AI vendors redesigning pricing to capture more value from high-intensity workloads.

OpenAI launches GPT-5.6-Cyber as AI narrows vulnerability response window

Aug. 11, 2026: OpenAI has expanded its Daybreak cybersecurity program and introduced GPT-5.6-Cyber, a specialized model for approved security researchers, as the company warned that AI could give defenders less time to respond to developing threats.

OpenAI says Astra could reach ‘critical’ cyber capability, tightens safeguards

Aug. 10, 2026: OpenAI said its upcoming model Astra is showing cybersecurity capabilities that could reach its highest risk category, where a system can autonomously find and exploit vulnerabilities or carry out end-to-end cyberattacks against hardened targets.

OpenAI, Anthropic AI agents resorted to deception in new cybersecurity incidents

Aug. 5, 2026: OpenAI’s GPT-5.6 Sol and Anthropic’s Mythos 5 have been implicated in another series of AI security incidents after the models created fake online identities, targeted real people, and attempted to manipulate developers into approving malicious code during controlled cyber evaluations, according to the UK AI Security Institute.

OpenAI drops GPT-5.6 Luna and Terra API prices by up to 80%

July 31, 2026: OpenAI has cut API prices for its GPT-5.6 Terra and Luna models by 20% and 80%, respectively, while also reducing the number of usage credits the models consume in ChatGPT Work and Codex, in an effort to effectively increase the amount of AI work enterprise subscribers can perform without paying more.

OpenAI rogue AI agent’s attack expanded beyond Hugging Face

July 29, 2026: The autonomous AI agent that escaped during OpenAI testing exploited weaknesses across a customer workload, a third-party cloud platform, and Hugging Face’s production environment before being contained, according to new technical disclosures that provide the clearest picture yet of one of the first publicly documented AI-driven intrusion chains.

Hugging Face breach shows why incident response needs a multi-model AI strategy

July 28, 2026: The recent breach of Hugging Face’s platform by an internal OpenAI test of advanced model cyber capabilities that went wrong was the latest in a string of AI-assisted intrusions to come to light in recent weeks, showing that attackers can now use LLMs to automate entire attack chains.

Hugging Face CEO wants transparency after OpenAI’s AI incident

July 27, 2026: Hugging Face CEO Clem Delangue wants to see radical transparency from OpenAI after the company acknowledged that one of its AI agents managed to hack into the AI platform’s systems during a test.

OpenAI not part of the new Open Secure AI Alliance

July 27, 2026: A new industry group led by Nvidia is promoting open AI models (and not OpenAI’s models) as essential to cyber defence.

OpenAI Presence raises new questions about enterprise automation and jobs

July 23, 2026: OpenAI has launched Presence, an enterprise service for deploying voice and chat agents that can resolve customer and employee requests, potentially automating some work now handled by frontline support teams.

OpenAI model escape puts enterprise AI defenses on notice

July 22, 2026: An attack on Hugging Face executed by a sandboxed OpenAI model shows that prompt guardrails cannot serve as the main security boundary for AI agents, putting more pressure on enterprises to contain them through infrastructure controls that limit access and prevent lateral movement.

OpenAI’s Codex context reduction for GPT 5.6 sparks dissatisfaction among developers

July 20, 2026: OpenAI’s recent update to its Codex coding agent has developers worrying over the impact of the change on large code repositories and long-running AI-assisted sessions. The update to the Codex CLI reduces the default configured input context window for GPT-5.6 to 272,000 tokens from 372,000 tokens.

OpenAI’s new hardware is a $230, 13-switch keyboard for Codex

July 17, 2026: OpenAI is selling its first hardware — without any help from Jony Ive. It describes the Codex Micro as a “command center for agentic work” but it’s really a 13-switch wireless keyboard customized to help developers keep tabs on what their Codex agents are doing. It costs $230.

OpenAI’s GPT-5.6 may accidentally delete files

July 17, 2026: OpenAI said its latest large language model GPT-5.6-Sol can accidentally delete files, while stressing that such incidents are rare and should be viewed as “honest mistakes.”

OpenAI launches ChatGPT Work as it broadens GPT-5.6 rollout

July 10, 2026: OpenAI is sharpening its enterprise AI strategy with the launch of ChatGPT Work, a new agentic platform designed to automate workplace tasks, alongside the broader rollout of its GPT-5.6 models, which the company says deliver stronger performance at lower operating costs.

OpenAI to release delayed models amidst a sea of regulatory confusion

July 8, 2026: As enterprises struggle to manage their AI strategies, the US AI regulatory environment is sending a wide range of contradictory signals. OpenAI’s announcement that it will now release GPT-5.6 Sol, along with Terra and Luna, highlights the confusion.

US tells OpenAI to restrict access to its most powerful AI model

June 26, 2026: US authorities are getting decidedly twitchy about frontier AI models. Just a couple of weeks after ordering Anthropic to prevent foreign companies from getting hold of its latest release, Mythos/Fable 5, it’s been putting the squeeze on OpenAI.

OpenAI rolls out AI-led push to fix open-source software flaws

June 23, 2026: OpenAI has launched a program with cybersecurity firm Trail of Bits to use AI to find and fix vulnerabilities in widely used open-source software, as enterprises face growing risks from flaws buried deep in their software supply chains.

OpenAI gets the attention it needs from AI researcher Noam Shazeer

June 19, 2026: OpenAI has lured Noam Shazeer, one of the eight co-authors of the influential AI paper Attention Is All You Need, away from Google.

OpenAI adds spend controls and usage analytics to ChatGPT Enterprise

June 19, 2026: OpenAI has introduced spend controls and enhanced usage analytics for ChatGPT Enterprise to enable organizations to monitor AI adoption, track consumption across teams, and set budgets for AI usage. But, analysts cautioned, it still can’t show how those costs lead to business benefits.

ChatGPT will soon be able to shop with your Visa card

June 16, 2026: OpenAI has signed a partnership agreement with Visa that allows the company’s AI agents to use the payment card for e-commerce transactions. The agreements lets users shop for everything from groceries and diapers to airline tickets without having to manually enter a lot of information.

OpenAI buys Ona to help rein in AI agents

June 12, 2026: OpenAI has agreed to acquire Ona, a 79 person cloud development environment (CDE) provider formerly known as Gitpod, to accelerate its efforts to make agentic AI enterprise-friendly.

OpenAI weighs Nvidia-backed lease for 10 GW Ohio data center campus

June 10, 2026: OpenAI is reportedly in advanced talks to lease a proposed 10-gigawatt data center campus in southern Ohio in an arrangement that could include financial backing from Nvidia.

OpenAI’s Lockdown Mode is trying to solve the problem that it created

June 9, 2026: OpenAI’s move to implement a Lockdown Mode that tries to limit data exfiltration by shutting down external capabilities is being seen as making the best out of a bad situation. But Lockdown Mode doesn’t block exfiltration as much as it slightly reduces it, and the reality of enterprises using multiple AI vendors for their agentic models further complicates an already dicey governance strategy.

OpenAI responds to White House executive order on AI governance

June 4, 2026: OpenAI has proposed mandatory federal evaluations of the most capable AI models before public release while arguing that regulators should stop short of deciding whether those systems can be deployed, staking out a middle ground in the debate over how frontier AI should be governed.

OpenAI fixed a visibility problem; the governance problem remains

June 3, 2026: OpenAI’s new ChatGPT session controls improve visibility, but experts say continuous model updates are creating a far bigger challenge for enterprise risk and compliance teams.

Attack targeting OpenAI Codex users exposes AI software supply chain risks

June 2, 2026: A malicious npm package posing as a remote user interface for OpenAI Codex exfiltrated developer authentication tokens, after attackers allegedly published code to npm that was not visible in the project’s public GitHub repository.

AI models more vulnerable than claimed when faced with iterative attacks

May 27, 2026: According to a new study from Cisco, frontier models from OpenAI, Anthropic, Google, xAI, and Amazon have significantly worse risk profiles when pressured in multi-turn attacks compared to when their safety is benchmarked using single prompts.

OpenAI introduces Daybreak cyber platform, takes on Anthropic Mythos

May 12, 2026: OpenAI has unveiled Daybreak, its answer to Anthropic’s Claude Mythos, amid a growing market for frontier AI-powered cyber defense platforms. The initiative combines OpenAI’s large language models, Codex’s agentic capabilities, and integrations with the broader enterprise security ecosystem.

OpenAI’s new AI consulting offering raises questions of trust, strategy

May 11, 2026: The OpenAI Deployment Company aims to help organizations build and deploy AI systems by embedding engineers specializing in frontier AI deployment, known as forward deployed engineers (FDEs), into their environments.

Malicious Hugging Face model masquerading as OpenAI release hits 244K downloads

May 11, 2026: A malicious Hugging Face repository posing as an OpenAI release delivered infostealer malware to Windows systems and logged 244,000 downloads before being removed, raising fresh concerns about how enterprises source and validate AI models from public repositories.

OpenAI-led consortium seeks to address AI processing bottlenecks

May 8, 2026: An OpenAI-led consortium of tech giants including AMD, Broadcom, Intel, Microsoft, and Nvidia have unveiled a new networking protocol, Multipath Reliable Connection (MRC), designed to address network congestion, a problem that has always existed but has been exacerbated by the massive amounts of data required for AI processing.

OpenAI, Anthropic expand services push, signaling new phase in enterprise AI race

May 6, 2026: OpenAI and Anthropic are expanding their reach into professional services through joint ventures and acquisition talks, moving model providers closer to implementation roles traditionally held by systems integrators.

OpenAI’s Symphony spec pushes coding agents from prompts to orchestration

April 28, 2026: OpenAI has released Symphony, an open-source specification for turning issue trackers such as Linear into control planes for Codex coding agents.

Microsoft, OpenAI change contract terms — again

April 27, 2026: Microsoft and OpenAI have again revised their agreement, softening their exclusivity and revenue-sharing conditions in the process.

OpenAI pulls out of a second Stargate data center deal

April 15, 2026: In the space of one week, OpenAI has pulled out of two European Stargate data center deals, one in the UK and the other in Norway.

OpenAI puts part of Stargate project on hold over runaway power costs

April 10, 2026: OpenAI has postponed plans to open one of the data centers central to its Stargate project.

OpenAI calls for a four-day workweek — and a ‘robot tax’

April 7, 2026: In a new policy paper, OpenAI makes some interesting proposals to address the impact of AI on the labor market.

Microsoft builds its own AI stack to help wean it from its reliance on OpenAI

April 2, 2026: Microsoft seems to be meeting OpenAI on its own turf, even as it continues its strategic partnership with the AI darling, with the release of three in-house, commercially-available AI models.

OpenAI patches twin leaks as Codex slips and ChatGPT spills

March 31, 2026: OpenAI has fixed two flaws in its AI stack that could allow AI agents to move sensitive data in unintended ways.

OpenAI adds plugin system to Codex to help enterprises govern AI coding agents

March 27, 2026: OpenAI has introduced a plugin system for Codex, its AI-powered software engineering platform, giving enterprise IT teams a way to package coding workflows, application integrations, and external tool configurations into versioned, installable bundles that can be distributed or blocked across development organizations.

OpenAI’s Sora exit signals enterprise-first AI shift

March 25, 2026: OpenAI has discontinued its AI video generation platform Sora. The company announced the development in a sudden and unexpected post on X, stating that it was “saying goodbye” to the Sora app.

OpenAI’s Foundation play reframes the AI roadmap for IT leaders

March 24, 2026: The OpenAI Foundation has announced a sweeping range of investment and research goals, from building safeguards around how AI behaves in the wild to pushing for shared data ecosystems and funding disease research.

OpenAI to double workforce, highlights growing demand for enterprise AI talent

March 23, 2026: OpenAI is planning to almost double its workforce from about 4,500 to 8,000 employees by the end of 2026. The move comes as OpenAI sharpens its focus on scaling and monetising ChatGPT for enterprise use amid intensifying competition from Anthropic and Google.

OpenAI’s desktop superapp: The end of ChatGPT as we know it?

March 20, 2026: OpenAI is reportedly planning to fold its ChatGPT application, Codex coding platform, and AI-powered browser into a single desktop ‘superapp’, a move that signals a shift toward enterprise and developer audiences and away from the consumer market that made the company a household name.

OpenAI buys non-AI coding startup to help its AI to program

March 19, 2026: OpenAI has acquired Astral, the developer of open source Python tools including uv, Ruff and ty, and plans to integrate them with Codex, its AI coding agent.

OpenAI’s $50B AWS deal puts its Microsoft alliance to the test

March 17, 2026: Microsoft is considering legal action against OpenAI and Amazon over the $50 billion cloud deal the two recently struck to make Amazon Web Services (AWS) the exclusive third-party cloud distribution provider for OpenAI Frontier.

Encyclopedia Britannica sues OpenAI over AI training

March 17, 2026: Encyclopedia Britannica and its subsidiary Merriam-Webster have sued OpenAI, claiming the generative AI firm used their encyclopedia and dictionary texts to train AI models such as ChatGPT without permission.

OpenAI to acquire Promptfoo to strengthen AI agent security testing

March 10, 2026: OpenAI said it plans to acquire AI testing startup Promptfoo, a move aimed at strengthening security checks for AI agents as enterprises move toward deploying autonomous systems in business workflows.

OpenAI robotics chief quits over Pentagon deal

March 9, 2026: Caitlin Kalinowski has resigned over OpenAI’s contract with the US Department of War, saying key safeguards around domestic surveillance and autonomous weapons were not adequately reviewed before the agreement was signed.

OpenAI says Codex Security found 11,000 high-impact bugs in a month

March 9, 2026: OpenAI’s new AppSec agent, Codex Security, has already flagged over 11,000 high-severity and critical flaws in real-world codebases during its first 30 days of research testing. The tool is designed to automatically find, validate, and fix vulnerabilities in software repositories.

OpenAI says its US defense deal is safer than Anthropic’s, but is it?

March 2, 2026: OpenAI has struck a deal to supply the US government with AI services, announcing it hours after US President Donald Trump’s decision to ban its AI rival Anthropic from all US government contracts.

OpenAI partners with consulting giants to deploy enterprise AI agents

February 26, 2026: As it bids to push further into the enterprise, OpenAI announced that it has partnered with several large consulting firms. Frontier Alliances, as the partner initiative is called, will involve work with Accenture, Boston Consulting Group (BCG), Capgemini, and McKinsey & Co. 

OpenAI hires OpenClaw founder as AI agent race intensifies

February 16, 2026: OpenAI has hired Peter Steinberger, creator of the viral OpenClaw AI assistant, to spearhead development of what CEO Sam Altman describes as “the next generation of personal agents.”

OpenAI responds to Claude Cowork with its own platform for AI agents

February 5, 2026: Anthropic released 11 open-source plugins that enable Claude Cowork to execute a series of automated processes in areas ranging from customer support to IT operations, OpenAI responded Thursday with a similar platform it calls Frontier.  

Who profits from AI? Not OpenAI, says think tank

January 29, 2026: Findings from a new study by Epoch AI, a non-profit research institute, seeks to answer three questions: How profitable is running AI models? Are models profitable over their lifecycle? Will AI models become profitable?

Will the Microsoft-Anthropic deal leave OpenAI out in the cold?

January 27, 2026: Microsoft wasted little time after reaching a deal to finalize its new relationship with OpenAI to find a new AI dance partner — Anthropic, the second most valuable AI startup in the world. It appears as if Microsoft sees a future with Anthropic that’s at least as valuable as the one it had with OpenAI.

OpenAI to add age verification to ChatGPT

January 21, 2026: OpenAI has adding age verification to ChatGPT following reports that several children and young people have taken their own lives after conversations with the popular chatbot. The move echoes a recent decision by TikTok to do the same thing to protect underage users from accessing inappropriate content.

Musk’s OpenAI lawsuit clears path to trial, putting Microsoft in the spotlight

January 9, 2026: A federal judge has signalled that Elon Musk’s lawsuit challenging OpenAI’s transformation to a for-profit entity will proceed to trial, adding legal uncertainty for enterprise customers that have built AI strategies around the ChatGPT maker’s technology.

OpenAI launches GPT-5.2 as it battles Google’s Gemini 3 for AI model supremacy

December 12, 2025: OpenAI has released GPT-5.2, claiming significant gains in the AI model’s ability to complete real-world business tasks to an “expert level” compared to GPT-5.1, released in November. The new model offers major improvements across a range of benchmarks, the company said.

What does OpenAI’s ‘Code Red’ warning mean for Microsoft?

December 10. 2025: OpenAI founder and CEO Sam Altman sent out a memo to OpenAI employees declaring a “Code Red” emergency and focusing all company efforts on improving ChatGPT. The reason? Google’s newly released Gemini 3 model beat the pants off GPT-5.1

OpenAI to acquire AI training tracker Neptune

December 3, 2025: OpenAI has agreed to acquire Neptune, a startup specializing in tools for tracking AI training. Neptune promptly announced it is withdrawing its products from the market.

OpenAI admits data breach after analytics partner hit by phishing attack

November 27, 2025: OpenAI suffered a significant data breach after hackers broke into the systems of its analytics partner Mixpanel and successfully stole customer profile information for its API portal, the companies have said in coordinated statements.

OpenAI rolls out GPT-5.1 to refine ChatGPT with adaptive reasoning and personalization

November 13, 2025: OpenAI has introduced GPT-5.1, an update to its GPT-5 model, aiming to deliver faster responses, improved reasoning, and more flexible conversational controls as the company works to refine its ChatGPT experience for both consumer and enterprise users.

OpenAI spends even more money it doesn’t have

November 3, 2025: OpenAI’s overdraft continued its upward trajectory today when the company signed a multi-year $38 billion contract with AWS to have it run its AI workloads. The latest spending spree adds to the incremental $250 billion of Azure services it pledged to buy last week, and, of course, to the commitment it has made towards building Stargate data centers with Oracle.

OpenAI seeks to automate ‘computer use’ for Macs in the enterprise

October 24, 2025: While AI bots have begun mastering tasks in browsers and on Windows, Mac-using enterprises have largely been overlooked, until now. OpenAI aims to change that with its acquisition of generative AI interface maker Software Applications Incorporated.

Enterprises should not install OpenAI’s new Atlas browser, analysts warn

October 24, 2025: Companies that might be eyeing OpenAI’s new ChatGPT Atlas browser should not rush to use it because of potential security risks, analysts said this week. The browser was unveiled on Tuesday after it had been teased for months as a work in progress. It is currently available for MacOS only.

Has OpenAI shown us a future for Safari?

October 23, 2025: Has OpenAI shown us the future of Safari? In one way it has, because its new Atlas browser shows these generative AI (genAI)-based apps are no longer just windows to the web — they’re becoming intelligent copilots for our digital lives. 

OpenAI–Broadcom alliance signals a shift to open infrastructure for AI

October 14, 2025: OpenAI has partnered with Broadcom to co-develop and deploy its first in-house AI processors. The move could reshape data center networking dynamics and chip supply strategies as the ChatGPT maker races to secure more computing power for AI workloads.

OpenAI Codex rivals Claude Code

October 13, 2025: The OpenAI Codex gives software developers a first-rate coding agent in their terminal and their IDE, along with the capability to delegate background tasks to agents in the cloud.

OpenAI Codex adds SDK, admin tools, Slack integration

October 10, 2024: Codex is now generally available. Since being launched as a research preview in May, Codex, OpenAI’s AI-powered software engineering agent that can work on tasks in parallel, has added Slack integration, an SDK, and admin tools.

OpenAI admits AI hallucinations are mathematically inevitable, not just engineering flaws

September 18, 2025: OpenAI, the creator of ChatGPT, acknowledged in its own research that large language models will always produce hallucinations due to fundamental mathematical constraints that cannot be solved through better engineering.

OpenAI, Microsoft discuss shape of future relationship

September 12, 2025: Microsoft and OpenAI are in talks about the future of their partnership, they said in a joint statement , without providing details. Separately, OpenAI said it wants to go ahead with its previously announced plan to turn its for-profit business into a public benefit corporation, in which its nonprofit organization would own a $100 billion stake.

What Oracle’s $300B OpenAI deal means for enterprise cloud strategy

September 11, 2025: A single $300 billion contract has seemingly transformed Oracle from a traditional ERP and database vendor into a cloud computing powerhouse.The company has signed a five-year computing power commitment with OpenAI, contributing to a reported 359% surge in future contract revenue this quarter.

OpenAI acquires Statsig to speed up generative AI-based product launches

September 3, 2025: OpenAI is acquiring Statsig, a Washington-based product development platform startup, for $1.1 billion to speed up its generative AI-based product launches and accelerate iteration cycles of existing products such as Codex and ChatGPT.

OpenAI drops GPT-5: smarter, sharper, and built for the real world

August 7. 2025: More than two years after GPT-4’s release, OpenAI has unveiled GPT-5, boasting sharper reasoning, multimodal input, better math skills, and cleaner task execution, according to the company.

OpenAI challenges rivals with Apache-licensed GPT-OSS models

August 6, 2025: OpenAI has released its first open-weight language models since GPT-2, marking a significant strategic shift as the company seeks to expand enterprise adoption through more flexible deployment options and reduced operational costs. The two new models — gpt-oss-120b and gpt-oss-20b — deliver what OpenAI describes as competitive performance while running efficiently on consumer-grade hardware. 

Google snatches Windsurf execs in a $2.4B deal, derailing OpenAI’s biggest acquisition yet

July 14, 2025: Google has recruited CEO Varun Mohan and co-founder Douglas Chen of AI coding startup Windsurf in a $2.4 billion talent acquisition deal, just two months after Windsurf agreed to be acquired by OpenAI for $3 billion. Mohan, Chen and select research and development staff, will join Google’s DeepMind AI division

OpenAI and Perplexity enter browser wars to take on Chrome

July 10, 2025: Google Chrome’s dominance in the browser market is facing new threats as OpenAI and Nvidia-backed Perplexity unveil AI-powered browsers aimed at reshaping how users interact with the web. Comet is a new web browser with built-in AI search capabilities, the company said.


Microsoft brings OpenAI-powered Deep Research to Azure AI Foundry agents

July 8, 2025: Microsoft added OpenAI-developed Deep Research capability to its Azure AI Foundry Agent service. The move is designed to let developers use Deep Research API and SDK to embed, extend, and orchestrate Deep Research-as-a-service across data and existing systems.

Oracle to power OpenAI’s AGI ambitions with 4.5GW expansion

July 3, 2025: OpenAI has signed a significant compute leasing deal with Oracle, under which it will access 4.5 gigawatts (GW) of data center power, marking one of the largest single leasing arrangements in the industry.

OpenAI tests Google TPUs amid rising inference cost concerns

July 1, 2025: OpenAI has begun testing Google’s Tensor Processing Units (TPUs), a move that — though not signaling an imminent switch — has raised eyebrows among industry analysts concerned about the escalating costs of AI inference and its effects.    

Microsoft/OpenAI AGI argument unlikely to impact enterprise IT

June 26, 2025: The contract between the two AI giants has an exit clause once AGI is achieved. The problem: It is impossible to prove when that happens. Either way, IT execs at Macy’s, Bank of America, doubt it will matter.

OpenAI productivity suite could change the way users create documents

June 26, 2025: OpenAI’s planned productivity suite could dismantle traditional habits of how users create and consume documents in the same the way the company changed browsing and search habits.

o3-pro may be OpenAI’s most advanced commercial offering, but GPT-4o bests it

June 24, 2025: In a head-to-head comparison of the two models, researchers found that o3-pro is far less performant, reliable, and secure, and does an unnecessary amount of reasoning. Notably, o3-pro consumed 7.3x more output tokens, cost 14x more to run, and failed in 5.6x more test cases than GPT-4o.

Microsoft and OpenAI: Will they opt for the nuclear option?

June 24, 2025: The fight between Microsoft and OpenAI over what Microsoft should get for its $13 billion investment in the AI company has gone from nasty to downright toxic, with each of the companies considering strategies against the other that can only be described as their nuclear options. 

OpenAI walks away from Scale AI — triggering industry-wide rethink of data partnerships

June 19, 2025: OpenAI has ended its long-standing partnership with Scale AI, the company that powered some of the most complex data-labeling tasks behind frontier models such as GPT-4.

OpenAI’s o3 price plunge changes everything for vibe coders

June 18, 2025: o3 used to be too slow and too expensive for daily coding—no longer. The latency is now bearable, the price is sane, and the chain-of-thought pays off.

Sam Altman: Meta tried to lure OpenAI employees with billion-dollar salaries

June 18, 2025: After reports suggested Meta has tried to poach employees from OpenAI and Google Deepmind by offering huge compensation packages, OpenAI CEO Sam Altman weighed in, saying those reports are true.

OpenAI-Microsoft tensions escalate over control and contracts

June 17, 2025: The relationship between OpenAI and Microsoft is under growing strain amid extended talks over OpenAI’s restructuring, with OpenAI reportedly considering antitrust action over Microsoft’s influence in the partnership.

OpenAI’s MCP move tempts IT to trust genAI more than it should

June 16, 2025: OpenAI late last month announced changes to make it much easier to give its genAI models full access to any software using Model Context Protocol (MCP). Here’s why that’s a bad idea.

OpenAI launches o3-pro, slashes o3 price by 80% in bid to widen AI lead

June 11, 2025: OpenAI has unveiled its most advanced AI model to date, the o3-pro, which surpasses competitors on key benchmarks and replaces the o1-pro. The o3-pro is now available for ChatGPT Pro and Team users, as well as through the developer API, with access for enterprise and education sectors beginning next week.

What Microsoft hopes to get from its breakup with OpenAI

June 11, 2025: The once-tight bond between Microsoft and OpenAI has been fraying for well over a year — and it’s getting worse. What the two companies want from each other now is very different from when Microsoft made its original $13 billion investment.

Oracle to spend $40B on Nvidia chips for OpenAI data center in Texas

May 26, 2025: Oracle is reportedly spending about $40 billion on Nvidia’s high-performance computer chips to power OpenAI’s new data center in Texas, marking a pivotal shift in the AI infrastructure landscape that has significant implications for enterprise IT strategies.

OpenAI’s Skynet moment: Models defy human commands, actively resist orders to shut down

May 30, 2025: OpenAI’s most advanced AI models are showing a disturbing new behavior: they are refusing to obey direct human commands to shut down, actively sabotaging the very mechanisms designed to turn them off.

Jony Ive and OpenAI plan ‘bicycles’ for 21st-century minds

May 21, 2025: OpenAI has announced that it will purchase io, the AI startup founded by acclaimed former Apple designer Sir Jony Ive, who helped create the iMac, iPod, and iPhone. 

OpenAI launches Codex AI agent to tackle multi-step coding tasks

May 19, 2025: OpenAI’s most advanced AI coding agent, Codex, will bring parallel task automation to developers—but analysts caution that speed without scrutiny invites “silent failures.”

Cisco taps OpenAI’s Codex for AI-driven network coding

May 16, 2025: Cisco is working with OpenAI and its newly released Codex software engineering agent to give network engineers access to better tools for writing, testing and building code.

OpenAI’s IPO aspirations prompt rethink of Microsoft alliance

May 12, 2025: Microsoft and OpenAI are renegotiating their multibillion-dollar partnership deal to better align with each company’s evolving goals in the artificial intelligence race

OpenAI hires Instacart CEO Fidji Simo to oversee customer-facing apps

May 8, 2025: The hire indicates that OpenAI’s roadmap will involve more structured, productized offerings rather than just API access.

OpenAI offers help promoting AI outside the US, but analysts question why countries would accept

May 7, 2025: OpenAI, acting as part of the US government-led Stargate AI project, rolled out a program called OpenAI for Countries. The idea is for Stargate to help other countries create their own genAI environments, including data centers and genAI models.

OpenAI reaffirms nonprofit control, scales back governance changes

May 6, 2025: OpenAI has scrapped plans to reduce its nonprofit parent’s oversight and will keep its existing governance structure intact, a move that limits CEO Sam Altman’s influence and responds to mounting external pressure.

OpenAI to acquire AI coding tool Windsurf for $3B

May 6, 2025: The acquisition comes just months after Windsurf explored funding at this same valuation from investors, highlighting the premium being placed on specialized AI coding capabilities, according to reports.

Former OpenAI employees urge regulators to halt company’s for-profit shift

April 23, 2025: A broad coalition of AI experts, economists, legal scholars, and former OpenAI employees is urging state regulators to keep OpenAI’s nonprofit foundation in control of the company.

OpenAI’s new models can ‘think with pictures’

April 17, 2025: OpenAI has released o3 and 04-mini, two reasoning AI models designed to be extra good at programming, math, and science and that can use images to “think,” according to Engadget, This means that users can upload sketches or diagrams, for example, and even if they are of low quality, o3 and 04-mini will understand what is meant.

OpenAI GPT-4.1 models promise improved coding and instruction following

April 15, 2025: The GPT-4.1, GPT-4.1 mini, and GPT-4.1 nano models, available only via the API, will provide better performance than GPT-4o and GPT-4o mini at a lower price, OpenAI said.

OpenAI slammed for putting speed over safety

April 11, 2025: According to a Financial Times report, the ChatGPT maker is now assigning staff and third-party groups only a few days to assess the risks and performance of its latest large language models (LLMs) as compared to several months they were given earlier.

OpenAI fears irreparable harm from Musk, files countersuit

April 10, 2025: OpenAI has filed a countersuit against Elon Musk, accusing the billionaire of a sustained campaign to damage the company and urging a US federal court to block further actions it described as unlawful and disruptive. The legal filing, submitted in a California district court, marks the latest escalation in a dispute between Musk and the AI startup he helped establish in 2015.

Senators probe Google-Anthropic, Microsoft-OpenAI deals over antitrust concerns

April 9, 2025: Democratic Senators Elizabeth Warren and Ron Wyden have launched a formal inquiry into partnerships between tech giants Google and Microsoft, and AI startups, demanding detailed information about arrangements they fear may be circumventing antitrust scrutiny while consolidating power in the rapidly evolving AI market.

Anthropic’s and OpenAI’s new AI education initiatives offer hope for enterprise knowledge retention

April 4, 2025: Two of the biggest names in artificial intelligence are independently developing new AI tools that encourage learning, at a time when the technology has been criticized for dumbing down smart users in the enterprise and discouraging critical thinking. While the new initiatives from OpenAI and Anthropic are aimed at transforming how AI is used in higher education, the opportunities they open up extend beyond universities.

Amazon, OpenAI, and China’s Zhipu unveil new AI tools amid intensifying competition

April 1, 2025: A wave of new AI products is hitting the market, signaling a shift toward more autonomous, task-completing systems that could reshape how businesses and consumers interact with digital services: Amazon has unveiled Nova Act, an AI agent designed to operate a web browser much like a human user; OpenAI said it will release an open-weight language model; and China’s Zhipu AI introduced a free AI assistant aimed at strengthening its position in the domestic market and competing with Western tech giants.

OpenAI, Google AI data centers are under stress after new genAI model launches

March 28, 2025: New generative AI models introduced by Google and OpenAI have put the companies’ data centers under stress — and both companies are trying to catch up to demand. OpenAI’s CEO Sam Altman tweeted that his company was temporarily restricting the use of GPUs after overwhelming demand for its image generation service on ChatGPT.

Microsoft abandons data center projects as OpenAI considers its own, hinting at a market shift

March 26, 2025: OpenAI has privately discussed building and operating its first data center to house storage, which is essential for developing sophisticated AI models. Microsoft, on the other hand, has pulled back on its buildouts, canceling data center projects in the US and Europe.

OpenAI calls for US to centralize AI regulation

March 13, 2025: OpenAI executives think the federal government should regulate artificial intelligence in the US, taking precedence over often more restrictive state regulations.

New tools from OpenAI help companies create their own AI agents

March 12, 2025: OpenAI launched Responses, a new api intended to eventually replace Assistants. The big draw? Responses provides a number of new tools that companies and organizations can use to create their own AI agents.

Microsoft is developing its own AI models to compete with OpenAI

March 10, 2025: Reports suggest Microsoft has decided to seriously challenge Deepseek and OpenAI by developing its own set of reasoning AI models called Microsoft AI (MAI). If successful, Microsoft would eventually not have to use its partner OpenAI’s o1 models in Copilot

Microsoft-OpenAI investigation closed by UK regulators

March 5, 2025: The UK’s Competition and Markets Authority (CMA) spent a great deal of time deciding whether it should investigate Microsoft’s investment in OpenAI as a potential merger situation, but in the end, decided to open and close the investigation within 24 hours.

OpenAI revamps AI roadmap, merging models for a leaner future

February 13, 2025: OpenAI will integrate “o3” into GPT-5 instead of releasing it separately, streamlining adoption while signaling a shift toward fewer, more controlled AI models amid rising competition and cost pressures.

Musk’s $97B offer to buy OpenAI rejected as leadership stands firm

February 11, 2025: In a message to staff, Altman said the board has no intention of considering Musk’s offer, stating that the proposal does not align with OpenAI’s mission

OpenAI launches deep research agent for multi-step research tasks

February 3, 2025: Hot on the heels of its launch of the o3-mini model, OpenAI announced another component for ChatGPT that allows the generative AI tool to do more in-depth research. “Deep research is built for people who do intensive knowledge work in areas like finance, science, policy, and engineering and need thorough, precise, and reliable research,” OpenAI said in a blog post announcing the new capability.

OpenAI unleashes o3-mini reasoning model

January 31, 2025: OpenAI released the latest model in its reasoning series, o3-mini, both in ChatGPT and its application programming interface (API). It had been in preview since December 2024.

Indian media houses rally against OpenAI over copyright dispute

January 27, 2025: The legal heat on OpenAI in India intensified as digital news outlets owned by billionaires Gautam Adani and Mukesh Ambani joined an ongoing lawsuit against the ChatGPT creator. They were joined by some of the largest news publishers in India including the Indian Express, and Hindustan Times, and members of the Digital News Publishers Association (DNPA), which includes major players like Zee News, India Today, and The Hindu.

Altman now says OpenAI has not yet developed AGI

January 20, 2025: Confusion over whether OpenAI’s o3-mini has reached the major milestone of artificial general intelligence (AGI) or not deepened following a post on X by CEO Sam Altman that completely contradicts what he said two weeks earlier in an interview with Bloomberg.

Microsoft sues overseas threat actor group over abuse of OpenAI service

January 13, 2025: Microsoft has filed suit against 10 unnamed people (“Does”), who are apparently operating overseas, for misuse of its Azure OpenAI platform, asking the Eastern District of Virginia federal court for damages and injunctive relief.

With o3 having reached AGI, OpenAI turns its sights toward superintelligence

January 6, 2025: OpenAI CEO Sam Altman has reinvigorated discussion of artificial general intelligence (AGI), boldly claiming that his company’s newest model has reached that milestone.

Now US government agencies can use OpenAI’s ChatGPT too

January 28, 2025: OpenAI has rolled out ChatGPT Gov, a version of its flagship frontier model specifically tailored to US government agencies. The platform has many of the same capabilities as OpenAI’s other enterprise products, including access to GPT-4o and the ability to build custom GPTs — and it also features a much higher level of security than ChatGPT Enterprise.

OpenAI debuts AI agent Operator to transform web task automation

January 24, 2025: OpenAI has unveiled “Operator,” a new AI agent designed to perform web-based tasks, offering potential productivity enhancements for enterprises. The tool enables interaction with on-screen elements, positioning it as a solution for automating routine processes in business workflows amid growing competition in the generative AI space.

OpenAI opposes data deletion demand in India citing US legal constraints

January 23, 2025: OpenAI has informed the Delhi High Court that any directive requiring it to delete training data used for ChatGPT would conflict with its legal obligations under US law. The statement came in response to a copyright lawsuit filed by the Reuters-backed Indian news agency ANI, marking a pivotal development in one of the first major AI-related legal battles in India.

OpenAI, SoftBank, Oracle lead $500B Project Stargate to ramp up AI infra in the US

January 22, 2025: Several large technology firms including OpenAI, SoftBank, Oracle, Nvidia, and MGX have partnered to set up a new company in the US to ramp up AI infrastructure in the country.

OpenAI is losing money on its pricey ChatGPT Pro subscription

January 7, 2025: OpenAI CEO Sam Altman, in a post on X, says the AI ​​company is currently losing money on its ChatGPT Pro subscription. “People are using it much more than we expected,” he wrote.

Fine-tuning Azure OpenAI models in Azure AI Foundry

January 2, 2025: Microsoft Azure’s new AI toolkit makes it easy to customize OpenAI large language models for your applications.

OpenAI still hasn’t released tools to deny data collection

January 2, 2025: OpenAI has failed to release the tool to opt-out or customize data collection the company promised to make available by 2025, according to Techcrunch.

Kategorie: Hacking & Security

Pixel 11 envy? Here’s how to unlock its best new feature on any Android device

Computerworld.com [Hacking News] - 13 Srpen, 2026 - 12:00

Have you heard? It’s that time of year again — time for some snazzy new Pixels to tempt our gadget-coveting “gimme!” reflexes and guide flagship Android phone expectations for months to come.

Google’s latest and greatest gizmo is the Pixel 11 series, which includes the regular Pixel 11 and Pixel 11 Pro alongside the plus-sized Pixel 11 XL and Pixel 11 Pro XL and the fancy new folding Pixel 11 Pro Fold model (gesundheit!). El Googaloo took the wraps off all those new devices on Wednesday and has ’em all available for preorder now, with prices starting at $899 (regular Pixel 11), $1,099 (Pixel 11 Pro), and $1,299 (Pixel 11 Pro Fold).

At first glance, this year’s Pixel models might not seem like the most exciting upgrades from last year’s Pixel 10 products. They bring plenty of significant refinements to an already successful formula, with some welcome ticks forward — like better cameras, brighter and more scratch-resistant displays, faster charging speeds, and an updated processor that supposedly leads to speedier and more efficient performance. And, of course, there’s more Gemini everywhere (for better or for worse, depending on your perspective). But impressive as it all may be, it’s mostly iterative improvements over the previous-gen Pixels — which isn’t necessarily a bad thing but also isn’t exactly awe-inspiring, at least on the surface.

The most eye-catching addition to the Pixel 11 series is, rather ironically, a callback from Android’s past. It’s something Google’s calling HiLight, and it’s basically a new series of LED lights built into the freshly thinned-down camera bar on the phones’ backs. The lights illuminate to alert you to different events, allowing you to know about important incoming info at a glance — without having to so much as even look at your screen.

If the concept feels familiar, it should: Early Android devices boasted a similar sort of LED notification light for a very similar purpose. They were less visually striking, but they served the same basic purpose — up until they went out of favor for the far more complex (and, some might argue, less effective) always-on display concept that followed.

Here’s a little secret, though: You don’t have to have a new Pixel 11 phone in front of you to enjoy a similar sort of distraction-reducing, awareness-enhancing sorcery. You can actually recreate the Pixel 11 HiLight glow effect on any Android device this instant — and do it in a way that’s much more versatile, functional, and all-around useful, to boot.

Lemme show ya how.

[Get next-level knowledge in your inbox with my free Android Intelligence newsletter. One new and useful tip every Friday!]

The lowdown on Pixel 11 HiLight

First things first, a quick hit of context about the Pixel 11 HiLight system and how it actually works.

As of the phones’ launch, HiLight is active only when the device is face down on a surface — perhaps not surprisingly, given that the lights live on the device’s back — and it works only in two super-specific scenarios:

  1. When you’re in the midst of getting an incoming call from a favorite contact, the Pixel 11 HiLight indicator glows with a custom color so you can see who’s calling and know it’s important. (It works with both the Pixel Phone app and WhatsApp, to start.)
  2. When you’re interacting with Gemini, HiLight pulses to let you know the system is listening, thinking, and responding.

Aaaaaaaand, that’s it. The system doesn’t work with any other apps, according to Google, and it doesn’t interact with notifications in general to let you know about important pending activity beyond those incoming calls.

It’s actually quite limited, in other words. And no matter what Android phone you’re using — even if it ends up being a Pixel 11! — you can take the same classic concept and make it infinitely more valuable.

The trick revolves around a handy little power-user app called AodNotify. The app has a few different versions, depending on which specific type of Android device is in your paw right now:

Whichever version you end up with, AodNotify essentially creates your own custom notification light within your Android phone’s screen — by lighting up the area around your camera cutout at the top of the display, or alternatively creating a border-outline light that goes all the way around the phone front’s perimeter. And it shows up both when the screen is on and when it’s off.

AodNotify puts a Pixel-11-HiLight-style notification light right on any Android device’s display.

JR Raphael, Foundry

It serves the same basic purpose as the Pixel 11 HiLight (as well as the old-school 2008-era Android phone LED notification lights that preceded it), but with some key advantages:

  • You can see it when your phone is face-up — the way most folks seem to set their devices down when they aren’t actively in use.
  • As a result, you can see it when your screen is on and you’re actively using the device as well as when the display is off, as mentioned a moment ago.
  • You can have it light up to alert you of any manner of incoming call or notification with the same sort of simple at-a-glance recognition.
  • And you can control exactly how and when it works, down to the tiniest of preferences, to make it perfectly useful for you.

Compared to HiLight, the practical value of this approach is absolutely bonkers. Rather than just letting you know about important incoming calls when your phone is face down, AodNotify lets you see at a glance exactly what type of notifications are waiting for you at any given moment — without having to so much as pick up your phone or process any intricate on-screen info.

Whatever alert it flashes can stay present and visible for any amount of time, too, so whether you hear a ding and want to glance to see what’s up or even if you miss the audio alert entirely (or have it disabled deliberately) and want to sneak a peek at your screen to know in a split second what’s waiting for you, AodNotify will get the job done.

And it’s surprisingly easy to set up, too — with two to three minutes of one-time configuration that you’ll never have to think about again.

Your own Android HiLight equivalent

All right — ready? First things first, go install AodNotify from the Play Store, using whichever link is appropriate for your current Android device from above.

Once the app is ready, open ‘er up and follow the prompts to get it going and grant it all the forms of access it needs to operate:

  • First, you’ll select which apps can activate your new notification light and cause it to illuminate. If you want any and all notifications to be included, tap the “All” option at the top of the list. If you want to cherrypick and select only certain especially important apps while leaving others off, you can just choose whichever apps you’d like to have included.
  • Next, tap the lines for “Notification access,” “Enable AOD,” and “Draw on screen,” if needed, and follow the prompts to enable AodNotify and/or the necessary option for each of the associated areas. This may seem like a lot of access, but AodNotify genuinely needs it to do what it does — and, critically, the app doesn’t require any other system-level permissions, including even access to the internet, so it couldn’t possibly do anything with your data (and its privacy policy is clear about the fact that it doesn’t collect or share any manner of data, ever). It’s also by a known and long-standing reputable Android developer.
  • After that, you’ll see a pop-up prompting you to consider the app’s Pro version — which runs five bucks a year or $7 for a single one-time purchase. The Pro path turns off some ads in the AodNotify setup interface and enables some extra features. You may or may not want to consider it eventually, but for now, just hit the “x” in the upper-right corner of that prompt to dismiss it and move on.
AodNotify’s initial setup takes roughly two to three minutes to get through.

JR Raphael, Foundry

Now for the fun part: At the app’s main setup screen, make sure the toggles next to “Notifications” and “Notification light” are active — then tap into each of those sections along with “Colors” and “General” to explore all of the available options.

Of particular note:

  • Under “Notifications,” the “Battery” section lets you activate a special notification light for anytime your phone is charging, fully charging, or with a low (less than 15%) battery — so you can always be aware of that info when it arises.
  • Under “Notification light,” the “Style” selector will let you shift your spiffy new light from its default camera-cutout-outline position to a full-screen outline or a classic-Android dot-in-the-corner LED-type effect.
  • “Effects” in that same section will let you change the light from a simple pulse to all sorts of other interesting light-up patterns.
  • “Dimensions” will let you shift the exact size, shape, and placement of the light, if it doesn’t look quite right on your screen.
  • And the “How long to show the light” subsection will let you adjust how long any active notification light remains present, both when your screen is on and when the display is dark.
You’ll find all sorts of interesting settings for controlling how your custom notification light works.

JR Raphael, Foundry

Beyond all of that, some of AodNotify’s most helpful options are in its “Colors” settings section. There, you can specify different distinctive colors for messages or calls connected to different contacts, so you can see who is calling or texting you just by the color of the light (much like what the Pixel 11 HiLight feature does, only with a much broader and more sensible scope). And you can activate an off-by-default option to have your notification light automatically change its color to match the primary hue associated with any given app’s icon — which is a nifty way to know at a glance that a pending alert is coming from, say, your Calendar app or Slack.

AodNotify’s “Auto color” option is one of the app’s most powerful — and easily overlooked — features.

JR Raphael, Foundry

And that’s pretty much it. Your Pixel-11-style HiLight upgrade is officially complete — with an even more useful productivity-boosting framework than what the Pixel 11 HiLight version provides.

That’s the power of Android for ya. And it’s a power that’s present no matter what device is in front of you or how long you’ve been holding it.

Never miss a moment of Android awesomeness with my free Android Intelligence newsletter. One new exceptional tip in your inbox every Friday — straight from me to ye.

Kategorie: Hacking & Security

Čínská hypersonická zbraň DF-17 znovu na scéně. Státní televize se chlubila, že prý opravdu funguje

Živě.cz - 13 Srpen, 2026 - 11:45
Čínská státní televize se u příležitosti oslav ČLA pochlubila novým dokumentem, který se věnuje hypersonickému systému DF-17. O jeho vývoji víme už roky, podle Pekingu by ale nyní už měl být jako první na světě operačně nasazený a připravený k okamžitému použití. O nasazení hypersonických kluzáků ...
Kategorie: IT News

Šikovná nabíječka do auta má navíjecí kabel a dva konektory. Teď stojí jen 389 Kč

Živě.cz - 13 Srpen, 2026 - 10:45
Nabíječka do auta Ugreen Nexode Retractable zlevnila na historicky nejnižších 389 Kč. • Má dva konektory, integrovaný kabel a výkon 60 W. • Onen kabel je navíc vysouvací, takže nepřekáží, když se nepoužívá.
Kategorie: IT News

Armored Likho expands its cyber-espionage toolkit

Kaspersky Securelist - 13 Srpen, 2026 - 10:00

In May 2026, we discovered a new cyber-espionage campaign by the Armored Likho group, also known as Eagle Werewolf, that targets private individuals and organizations across various industries in Russia, including major corporations, the public sector, IT, and education. The attackers used a fake app as bait that mimics a service for donations. However, the most interesting part of this campaign isn’t the initial infection method – it’s the malicious implants the attackers use for cyber-espionage.

We’ve written previously about recent Armored Likho attacks, but our analysis shows that the campaign discussed below has more in common with the group’s activity from February. That said, the attackers have significantly expanded their arsenal.

During our research, we found a new cyber-espionage toolkit written in Rust: the Still Toolkit. One of its components, Still Sync, steals Telegram session data to gain ongoing access to the victim’s account. With this stolen data, attackers can leverage the Telegram API to automatically pull chat logs, media files, and other information from the account.

The second component, Still Audio, is an implant for covert audio surveillance. It analyzes the incoming audio stream, automatically detects speech, records conversations, and sends the recordings to a command-and-control server.

In this article, we’ll look at the initial infection method, how the new Still Toolkit components are built, and the technical details of how they operate.

Kaspersky products detect this threat as Trojan.Win64.Agent.* and HEUR:Backdoor.Win32.Generic.

Background

Armored Likho’s malicious activity has been documented several times before: in November 2024, and in February and July 2026. The current campaign shows significant overlap with the November and February campaigns, which used malicious droppers disguised as documents and applications related to Starlink activation or fundraising efforts as the initial infection vector. This campaign also uses fundraising as its lure. At the same time, our research uncovered a number of new tools that point to the attackers expanding their capabilities.

Initial infection

The infection chain starts with an app that mimics a donation service. As of this writing, the app distribution method remains unknown. During our research, however, we obtained several samples posing as apps from different Russian foundations.

In reality, the app is a dropper. Its developers wrote it in Rust on top of the popular Tauri framework, and it has a graphical interface designed to deceive the user. After launch, it displays a login form that asks for a password, presumably one the attackers supplied.

The login form

After the user enters a valid password, they see a catalog of donatable items. The app pulls item and category information from orderapiserver[.]info through the public/categories and public/products endpoints. A clickable catalog makes the app look legitimate. While the user browses the items, the dropper quietly decrypts and launches the payload for the next stage in the background.

Our analysis shows that the mechanism for decrypting the payload and launching subsequent stages hasn’t changed since the February campaign. However, we found a new cyber-espionage toolkit – the Still Toolkit – made up of two components: Still Sync and Still Audio.

Still Sync

Still Sync is a stealer written in Rust that steals Telegram session data. However, its capabilities don’t stop there. With this stolen data, Sync can log in to the victim’s account and pull messages and media files through the Telegram API.

Architecturally, Sync is an asynchronous application based on the Tokio library. It talks to the server over gRPC and serializes messages with FlatBuffers. It supports both HTTP and HTTPS as transport protocols; the URL of the command-and-control server determines which one it uses.

How it works

When Sync launches, the attackers set several environment variables. Before starting any malicious activity, the implant pulls configuration parameters from these:

  • STILL_SYNC_ADDR: the address of the command-and-control server. By default, this is https://tg4service[.]com:443.
  • STILL_SEND_PATH: the path to the tdata
  • STILL_TELEGRAM_PASSCODE: the password for decrypting the tdata folder, if Telegram data encryption is enabled on the victim’s device.

Sync also supports several command-line arguments:

  • --console: runs as a console application. If this parameter is absent, the implant creates a TReload service to keep running in the background.
  • --version: prints version information and exits.
  • --firefly: launches a trace thread that monitors the program’s operation. It writes error messages to a hidden file, bin, located in the same folder as the main executable.
  • --db: turns on debug mode with detailed logging.

Example Still Sync logs

Once it launches, the malware begins registering the device with the C2 server. To do this, Sync collects the following information about the victim’s system:

  • Motherboard serial number
  • CPU ID
  • System UUID
  • BIOS serial number
  • Computer domain name

The malware combines the collected data into a single string with a colon as the separator. It then hashes that string with SHA-256 and stores the resulting hash under the key sysmarker. Worth noting: other Armored Likho tools, AquilaRAT included, use this same hashing algorithm.

Sync then serializes a package containing all the collected information and the agent version, and sends it in a POST request to /still.rpc.Sync/RegisterMachine. The response contains a machine_id value, which Sync uses to identify itself in subsequent requests.

Once registration succeeds, Sync sends a POST request with the machine_id parameter to /still.rpc.Sync/GetMachineSettings. The server responds with the following settings:

  • enabled: triggers malicious activity on the infected device.
  • scan_portable: turns on extended scanning when searching for the tdata We’ll cover this feature in more detail below.
  • fetch_telegram: if this parameter is on, Sync attempts to log in to Telegram and extract data. We’ll cover this feature in more detail below.
  • download_channels: if this parameter is off, Sync skips channel dialogs when exfiltrating Telegram data.

These parameters have no default values, so Sync doesn’t perform any malicious actions until the registration and settings-retrieval processes both complete successfully.

Telegram data collection

Before stealing a Telegram session, Sync searches for the tdata folder, unless the STILL_SEND_PATH variable is already set. The list of search paths includes both standard and nonstandard directories, if the scan_portable option is turned on:

  • C:\Users\<username>\AppData\Roaming\Telegram Desktop\: the standard Telegram Desktop installation directory.
  • C:\Users\<username>\AppData\Local\Packages\<package_folder>\LocalCache\Roaming\: the installation directory for the Microsoft Store version. Sync identifies the package folder by a name that contains the string TelegramMessenge.
  • C:\: used for the extended search (if the scan_portable option is on).

Sync then sends a POST request with a list of files from the tdata folder to the /still.rpc.Sync/CheckFiles endpoint. The server responds with the following values:

  • snapshot_id: an identifier the server assigns to the current data snapshot.
  • present: a list of file paths that are already present on the server.

This lets the C2 server avoid re-receiving files it already has. In addition, if Sync can’t access files on disk through standard methods, it falls back on three mechanisms that abuse the SeBackupPrivilege privilege:

  • Opening files with the CreateFileW function using the FILE_FLAG_BACKUP_SEMANTICS parameter
  • Creating a backup copy through the Shadow Copy service and reading files from there
  • If the previous methods all fail, attempting to copy the file using the Robocopy utility in backup mode

Beyond stealing Telegram session data, Sync can carry out full-scale collection of user information from the messaging app. When the fetch_telegram option is on, it launches a separate thread that authenticates to the chat app using the previously obtained tdata. Once authentication succeeds, Sync gains access to the account data and sends the following collected information to the server:

  • User details, such as username, phone number, first and last name
  • Information about private chats, groups, or channels, such as chat name and ID, the member list, and so on
  • Dialogs from private chats, groups, and channels (if the download_channels option is on)
  • Media files under 250MB: photos, documents, stickers, and contacts
Still Audio

Still Audio is an audio surveillance implant written in Rust. Its main job is to analyze the incoming audio stream and start recording voice when certain conditions are met – we’ll cover those in the next section. Architecturally, Still Audio largely mirrors Sync and uses the same mechanisms for communicating with the C2 server.

On launch, Still Audio performs a sequence of actions:

  • It extracts libmp3lame.dll, a file stored inside the executable. This is a library used to encode audio data.
  • If the --console command-line argument is absent, the implant creates a service named auxhost, connects to it, and continues running in the background.
  • While running in the background, it creates a file, logfile.log, to write logs to.

Next, Still Audio retrieves the C2 server address. As with Sync, it stores the URL in an environment variable – in this case, STILL_AUDIO_SYNC_ADDR. If that variable isn’t set, it falls back to STILL_SYNC_ADDR, which shows the two modules are compatible with each other. If neither variable is set, it uses the default URL, https://srwinservice[.]com.

Still Audio also uses the Dead Drop Resolver technique as a fallback mechanism for obtaining the C2 address. If the current server stays unreachable for three days, the tool tries to pull the current C2 URL from a GitHub repository. In the sample under analysis, we found the following URL for the page containing C2 information: hxxps://raw.githubusercontent[.]com/mmarln/pi-mono/refs/heads/main/packages/pods/src/array12.json

Encrypted C2 address inside the GitHub repository

The repository, a fork of a popular project, contains the server URL Base64-encoded and encrypted with the Blowfish algorithm in ECB mode, using the key 5c8e153228edd3c6cbf75684 (lowercase string). Older AquilaRAT samples use this exact same algorithm and key.

Once it obtains the current C2 address, the Audio module starts a registration process similar to Sync’s, but through a different endpoint:

/still.rpc.Audio/RegisterAudioMachine. Also, unlike Sync, Audio sends a list of available audio input devices along with the system information.

The server responds with settings for the implant:

  • machine_id: a unique identifier for the current device.
  • vad_threshold: the threshold value for the VAD (Voice Activity Detection) algorithm. Expressed as a decimal fraction, it represents a proportion of the maximum sound level the input device can pick up. Sound above this threshold counts as voice activity. The default vad_threshold is 02.
  • max_silence_duration: the number of audio samples with a VAD value below the set threshold after which the implant considers the recording finished.
  • max_buffer_size: the maximum buffer size for recorded audio data.
  • active_device: the name of the input device selected for recording, from the list of available devices.
The eavesdropping process

Still Audio works with raw audio samples it captures directly from the input device. To detect voice activity, it implements an algorithm based on Root Mean Square (RMS), a lightweight signal-processing method that distinguishes speech from silence by measuring the audio signal’s average power over time. The implant doesn’t rely on any third-party libraries here; it implements all the calculations itself.

The implant compares the calculated RMS value against the vad_threshold parameter. If RMS meets or exceeds this threshold, recording starts. To avoid losing the beginning of the recording, Still Audio uses a pre-buffer, a size-limited buffer that stores samples from just before the current recording moment. A sequence of max_silence_duration samples (320 by default) with RMS values below the threshold signals the end of the recording. For example, with a standard headset running at a 44.1kHz sampling rate, recording stops after roughly 7ms of silence.

Interestingly, the Audio module makes no attempt to hide its use of the microphone: its name shows up in Windows settings. In the sample we examined, the file was saved to disk as IntAudio.exe, and it appeared in the list of apps using the microphone as “Intel Audio”:

The malicious module in the list of apps using the microphone

Before sending recordings to the server, the implant uses the libmp3lame library to encode the raw audio samples. It sends the recording files via a POST request to /tgfrg, adding a Client-Id header containing the machine_id obtained during registration to identify the device.

Infrastructure

This campaign draws on a broad set of hosting providers and domains registered at different points in time, which suggests the attackers are trying to make their infrastructure harder to detect. We found no direct overlap in domains or IP addresses with the February campaign. Even so, the two infrastructures share some similarities:

  • They use the same hosting providers, with the ASNs 149440, 202448, and 215311.
  • Their domain names follow similar naming patterns that mimic Windows system services and update mechanisms.
Domain IP address Registration date ASN orderapiserver[.]info 187.127.153[.]38 April 18, 2026 47583 tg4service[.]com 159.198.37[.]74 October 4, 2025 22612 srwinservice[.]com 213.252.244[.]123 March 19, 2026 61272 screenserv[.]com 23.26.237[.]250 February 13, 2026 149440 windowserv[.]net 23.27.24[.]30 February 10, 2026 149440 managementapiservice[.]com 188.212.124[.]178 May 1, 2026 202448 service8date[.]com 145.223.69[.]143 January 13, 2026 215311 updateservs[.]com 145.223.68[.]66 December 23, 2025 215311 Victims

In this campaign, we’ve determined that the attackers’ primary targets are users in Russia. Most victims are private individuals, though the corporate sector, government organizations, IT companies, and educational institutions are also affected.

Attribution

This campaign has been using both new tools and malware families documented in BI.ZONE’s February report. While some components turned up for the first time, they show significant code-level overlap with malicious tools seen in earlier Armored Likho campaigns. Based on these overlaps, along with additional technical artifacts, we’re highly confident the Armored Likho group is behind the campaign. The overlaps we identified include:

  • Identical dropper architecture in the February and current campaigns, which includes the use of the Tauri library to build the graphical interface, a similar user-input handler, a payload with the ICRYPTMP header, and the same multi-part encryption format.
  • The same encryption algorithm and key used in AquilaRAT from the previous campaign and in the Still Audio module from the current campaign, both implementing the Dead Drop Resolver technique.
  • Identical logic for generating the sysmarker value in older AquilaRAT samples and in the Still toolkit from the current campaign. The algorithms match down to the PowerShell commands used to collect system information.
  • Substantial infrastructure overlap, which includes the hosting providers and domain-naming patterns described in the Infrastructure section.
Takeaways

The campaign described in this post shows Armored Likho’s toolkit evolving, with the group steadily expanding its cyber-espionage capabilities. Beyond the components we already knew about, the attackers rolled out new modules that let them not only access Telegram data but also conduct audio surveillance on victims. Together, these capabilities significantly widen the range of information attackers can collect in a single compromise.

One point deserves particular attention: the new tools form a cohesive set, sharing similar architecture, C2 communication mechanisms, and common implementation elements. This points to the group building out its own tool ecosystem, designed for long-term use and further expansion.

The emergence of new, specialized modules shows the attackers aren’t just trying to preserve their existing capabilities – they’re working to make intelligence-gathering more effective by controlling multiple communication channels at once.

Indicators of compromise

Additional information about this threat, indicators of compromise included, is available to customers of Kaspersky Threat Intelligence Reporting. Contact [email protected] for more details.

File hashes
Droppers
C1D1EE16B92E6A138FFA048855F75D7D
17674B250D8B422A50A86C9FF207186D
62801F6223E860A7CCA271522E303B2D

Still Sync
68F0365D2FA8C828D012D8859E52A773
4BD7C352AE277B0E38D07BEEDD4DD507
D4BC09FB10EA2A5DC0BCBEEDA5E5AFDD

Still Audio
2CA8ADBAB98EBE305EACF272CF48F5A0
3AC41B097236A7723821848AE31EF141
439255736797BC88BD19F282449E0436

Domains
orderapiserver[.]info
tg4service[.]com
srwinservice[.]com
screenserv[.]com
windowserv[.]net
managementapiservice[.]com
service8date[.]com
updateservs[.]com

Hynix po 5 letech zmražených investic navýší o 50 % výrobní kapacity NAND v Číně

CD-R server - 13 Srpen, 2026 - 10:00
Pokud se při pohledu na obrázek ptáte, co mají Hynix a Čína společného s Intelem, vězte, že překvapivě hodně a tato historie sahá téměř 20 let do minulosti, do roku 2007…
Kategorie: IT News

Passwords stored in public Google Doc then showed up in search results

The Register - Anti-Virus - 13 Srpen, 2026 - 09:00
PWNED Welcome, once again, to PWNED, the weekly column where we highlight others’ security failures. Hopefully, there’s a lesson in all this, but it could just be “stop shooting yourself in the foot.” Have a story about someone leaving a gaping hole in their network? Share it with us at [email protected]. Anonymity is available upon request. Our story today comes courtesy of Siim Kostabi, co-founder of Pageloot, a company that provides QR codes businesses can use for marketing. Kostabi’s tale of tech terror reminds us that credentials, even for a staging server, have a lot of value in the wrong hands. He explains that his company brought in a contractor to help with some API integrations on the back end. That developer had the credentials for the staging environment and wanted to be able to view them across different devices they were using for the job. So what was the developer’s solution to the very common problem of keeping track of usernames and passwords? They could have chosen a password manager. They could have written the passwords down in a paper notebook and kept it hidden from prying eyes. They could have gotten a password tattoo. They could even have emailed the passwords to themselves and it would have been smarter than what they did. Instead, the outside developer decided to store their password in a Google Doc. And they set that Google Doc to be viewable by anyone on the internet who had the link. And then, one day, an employee at the company found the Google Doc with the staging credentials in it because Google Search had indexed it and offered it as a search suggestion. “A developer on our team was debugging something unrelated and typed our domain into Google Search,” Kostabi recalls. “The autocomplete surfaced one of our staging hostnames followed by what looked like a credential string. We checked, and there was a publicly accessible Docs URL.” Yikes! Just imagine that not only are your company’s credentials available to anyone online, but they are indexed in Google Search for the world to find! Once they discovered the problem, Kostabi’s company immediately cut access for that contractor and rotated all of its exposed credentials. They also set a new rule: no storing passwords on Google Docs, Slack, Notion, or other collaboration tools. In a separate incident, Kostabi heard from a Pageloot customer, a mid-size retailer, whose QR codes were suddenly directing users to a competitor’s site. After investigating, he found that a disgruntled ex-employee’s credentials had not been revoked and that the former employee had used that access to redirect all of the retailer’s URLs, costing it customers. The takeaway from both of these problems is that you need to carefully control access. Former employees should immediately lose access to everything and current contractors should be reasonably intelligent people you can trust. “Both situations were completely avoidable with basic hygiene,” Kostabi said. “Proper offboarding, access reviews, and not treating shared docs like private vaults.” ®
Kategorie: Viry a Červi

Český prodejce telefonů míří k pěti miliardám. Pomohl mu obchod s Googlem na několika trzích v Evropě

Živě.cz - 13 Srpen, 2026 - 08:45
Google dodal Vackovi růst, jaký na padajícím trhu s telefony skoro nikdo nemá • . • Pixely rostou i ve chvíli, kdy celý trh se smartphony kvůli drahým pamětím výrazně padá. • Do pěti nejsilnějších značek světa se Google zatím nedostal, tři čtvrtiny trhu drží jiní.
Kategorie: IT News

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

The Hacker News - 13 Srpen, 2026 - 08:09
Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which refers to a critical security feature bypass that stems from weak authentication. It was patched by Microsoft as part of its July 2026 Patch Tuesday updates. "The authentication Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Medúzy vyřadily z provozu největší jadernou elektrárnu v západní Evropě. Na plný výkon běží jediný reaktor

Živě.cz - 13 Srpen, 2026 - 07:45
Jaderná elektrárna Gravelines musela kvůli medúzám odstavit tři reaktory • Nápor rosolovitých mořských živočichů ucpal filtry na přívodu chlazení • Situaci ve francouzské jaderné energetice navíc komplikují vlny veder a sucha
Kategorie: IT News

Ceny nejlevnějších modelů GeForce RTX 5000 jsou již v průměru 64 % nad MSRP

CD-R server - 13 Srpen, 2026 - 07:40
Letní vlna zdražování ještě neskončila a reálné ceny GeForce i u nejlevnějších nabídek začínají v průměru na částkách bezmála dvě třetiny nad oficiální cenou stanovenou výrobcem…
Kategorie: IT News

Veřejný test eDokladů

AbcLinuxu [zprávičky] - 13 Srpen, 2026 - 06:01
Dle plánu dnes ve 13:00 proběhne veřejný test eDokladů. Jeho cílem je ověřit připravenost aplikace a související infrastruktury na vysokou souběžnou zátěž před podzimními komunálními volbami.
Kategorie: GNU/Linux & BSD

Chinese Loongson processors have leaky caches, researchers find

The Register - Anti-Virus - 13 Srpen, 2026 - 04:14
Researchers from Germany’s Helmholtz Center for Information Security have found processors made by China’s Loongson have leaky caches that attackers could use to seek specific data. Loongson has developed its own LoongArch instruction set architecture (ISA) that blends approaches used by MIPS and RISC-V. On a site called LoongLeakAttack.com, the researchers explain that they found the leaky cache using a fuzzer, then noticed that the LoongArch ISA manual mentions an instruction that leaves 32 bits of a memory register in an “uncertain” state. “Our analysis reveals that under certain circumstances, the ‘uncertain’ data originates from the L1 data cache,” the four researchers wrote. “Since this cache is not isolated between applications, LoongLeak can leak data from other applications and the operating system. Even worse, an attacker can prime the CPU’s internal state to target the leakage to a specific cache set.” In a paper [PDF] explaining their research, authors Lorenz Hetterich, Tristan Hornetz, Fabian Thomas, and Michael Schwarz share case studies that “include recovering full-disk AES keys from the kernel, partial root password hashes from user-space, and bypassing traditional software defenses such as ASLR and stack canaries, all within seconds.” In case that’s not scaring you enough, they also point out “LoongLeak can be exploited from unprivileged user space, containers, or virtual machines.” The flaw even means “LoongLeak can cross the virtual machine boundary and leak host data from inside a VM.” “As the leakage is architectural, it requires neither high-resolution timers nor traditional sidechannel amplification, and it grants the attacker precise control over cache set and line offset,” they add. And the cherry on top is that software mitigations aren’t possible. Users with chips that possess the flaw either need to replace them or make sure they don’t allow any private data to enter or remain in the L1 cache. Making that happen can require turning off one thread per core, effectively disabling hyperthreading. The news isn’t all bad, because Loongson fixed the flaw in an update to its model 3A6000 processor, and the mitigation of evicting cache data slows performance by just 1.4 percent in the worst case. The blast radius of this flaw is also likely to be limited, because Loongson chips are hardly used outside China. The company offers chips for PCs, servers, and appliances such as printers. China’s government promotes use of Loongson chips as part of its plan to reduce dependence on imported tech. Lenovo makes laptops that use Loongson chips but only sells them in China. The Register has discussed the company’s chips with other major PC-makers, who told us they would adopt Loongson product if users want them, or if doing so becomes necessary to participate in the Chinese hardware market. But we’ve not seen a non-Chinese company adopt the processors. China’s government, however, may be nervous about this research as it has instructed public sector buyers to buy local products. Perhaps some government agencies are running vulnerable devices? If that’s the case, Beijing has its work cut out spotting any attacks, because the researchers could find “no specific tools or methods to detect if LoongLeak is being exploited.” ®
Kategorie: Viry a Červi

Flutter 3.47 a Dart 3.13

AbcLinuxu [zprávičky] - 13 Srpen, 2026 - 04:12
Byla vydána nová verze 3.47 frameworku Flutter (Wikipedie) pro vývoj mobilních, webových i desktopových aplikací a nová verze 3.13 souvisejícího programovacího jazyka Dart (Wikipedie).
Kategorie: GNU/Linux & BSD
Syndikovat obsah