Agregátor RSS

Made by Google 2026

AbcLinuxu [zprávičky] - 13 Srpen, 2026 - 04:02
Na akci Made by Google 2026 (YouTube) byla oficiálně představena jedenáctá generace telefonů Pixel s novým čipem Google Tensor G6 a hodinky Pixel Watch 5.
Kategorie: GNU/Linux & BSD

Manjaro 26.1 Bian-May

AbcLinuxu [zprávičky] - 13 Srpen, 2026 - 04:01
Byla vydána nová verze 26.1 linuxové distribuce Manjaro (Wikipedie). Její kódové jméno je Bian-May. Ke stažení je v edicích GNOME, KDE PLASMA a XFCE.
Kategorie: GNU/Linux & BSD

Lovable bolsters its AI software creation capacity, touts $400M funding round

Computerworld.com [Hacking News] - 13 Srpen, 2026 - 02:36

Lovable, the Swedish-based AI software creation platform company, today announced an acceleration of its product, infrastructure, and team development efforts — and a noteworthy round of Series C funding totaling $400 million.

The company said in its statement that it is looking to augment its platform, which it boasts is already used by almost two-thirds of Fortune 500 companies.

Headquartered in Stockholm, Lovable plans to grow its team to 450 people this year, hiring most heavily in machine learning, product, infrastructure, and security roles, and is looking to expand operations from its home base to include locations in London and three US cities: Boston, San Francisco, and New York City.

The planned growth is made possible by the latest infusion of venture capital, which follows a $330 million Series B funding round last December. Lovable now has a $13.3 billion valuation.

The Series C funding was led by Menlo Ventures and the Scaleup Europe Fund and includes US-based Regent. (Regent is the parent company of Foundry.)

Earlier this month, Lovable announced a partnership with Cerebras Systems, the chipmaker that builds processors the size of dinner plates (the Wafer-Scale Engine) and supercomputing systems built for AI inference and training. Cerebras systems are designed to keep an entire AI model’s weights on a single, super-sized WSE chip, rather than split across many GPUs, to avoid GPU memory bottlenecks.

That partnership calls for Lovable to run some of its latency-sensitive workloads on dedicated Cerebras capacity.

“Fast AI is more valuable than slow AI,” said Cerebras CEO and Cofounder Andrew Feldman said in a statement when the partnership was unveiled. “When AI responds in real-time, users do more with it, stay longer, and run higher value workloads. Software creation is one of the clearest examples of the importance of speed. Creators don’t want to wait.”

In its statement today, Lovable said that since its launch in November 2024, people have created more than 60 million projects with its tools, with Lovable-built apps seeing more than 900 million visits a month.

Computerworld is part of Foundry, which is owned by Regent.

Kategorie: Hacking & Security

"City-Forum" data-theft attacks target Salesforce, ServiceNow portals

Bleeping Computer - 13 Srpen, 2026 - 01:07
An ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals. [...]
Kategorie: Hacking & Security

Android malware combo takes out loans and relays victims' credit cards

Bleeping Computer - 13 Srpen, 2026 - 00:22
A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal live card data and send it to attackers in real time. [...]
Kategorie: Hacking & Security

Banky zavádí záchranné tlačítko, kterým stopnete krádež peněz z účtu

Lupa.cz - články - 13 Srpen, 2026 - 00:00
Banky postupně začínají zavádět bezpečnostní pojistky, které mohou zabránit vykradení účtu v případě napadení kyberútočníky. První dvě už v aplikaci mají speciální tlačítko.
Kategorie: IT News

Dlužník roky blokoval vlastní insolvenci. Za obstrukce dostal od soudu trest

Lupa.cz - články - 13 Srpen, 2026 - 00:00
Dlužník odmítal spolupracovat s insolvenční správkyní, nepředložil seznam majetku a závazků a řízení opakovaně brzdil námitkami podjatosti vůči správkyni i soudcům. Insolvenci tak na několik let prakticky paralyzoval. Nejvyšší soud potvrdil, že podobné zneužívání procesních práv může být trestným činem.
Kategorie: IT News

Podpora unifikované práce se zařízeními v operačním systému Atari: CIO (dokončení)

ROOT.cz - 13 Srpen, 2026 - 00:00
Na předchozí dvojici článků o subsystému CIO implementovaného ve všech osmibitových mikropočítačích Atari dnes navážeme. Ukážeme si, jakým způsobem je možné realizovat vlastní sofistikované zařízení, zaregistrovat toto zařízení pod vhodným písmenem a volat jeho operace z Atari BASICu.
Kategorie: GNU/Linux & BSD

Gelsingerova Fab 62 v Arizoně už nabrala čtyřleté zpoždění, Intel shání peníze

CD-R server - 13 Srpen, 2026 - 00:00
Intel oznámil veřejnou nabídku kmenových akcií v hodnotě 20 miliard dolarů na financování expanze výrobních kapacit. Zdá se, že důvodem je snaha o dokončení Fab 62, která měla stát již roku 2024…
Kategorie: IT News

Astronomové poprvé objevili 3 aktivní supermasivní černé díry v 1 galaxii

OSEL.cz - 13 Srpen, 2026 - 00:00
Galaxie J0148-4214, vzdálená od nás asi 12,5 miliard světelných let, obsahuje hned 3 supermasivní černé díry současně. Astronomové detekovali dvojici supermasivních černých děr o hmotnosti 80 milionů a 600 tisíc Slunci společně s třetí o hmotnosti 2 miliony Sluncí, s využitím detailní analýzy spektra záření galaxie.
Kategorie: Věda a technika

'Near-autonomous' AI agents attack Taiwan's nuclear safety agency

The Register - Anti-Virus - 12 Srpen, 2026 - 23:45
Suspected Chinese cyber operatives used publicly available AI tools to compromise Taiwanese government systems before expanding the attack to its nuclear safety agency, supply-chain vendors, and at least seven energy companies in what security researchers called a "near-autonomous attack." Over the first four days of July, AI agents compromised 85 government user accounts and extracted more than 2,500 personnel records, according to Dream, an Israeli cybersecurity firm. Researchers uncovered evidence of the attack in a 160 MB online archive containing 1,395 files documenting the operation. Dream, in research published on Wednesday, detailed the intrusions and said that the suspected Chinese hackers hit “government entities in Asia” - but declined to say which government had been attacked. A person familiar with the attack confirmed to The Register that Taiwan was the target. The Financial Times first reported on Dream’s research and identified Taiwan. While the security firm doesn’t attribute the agentic attack to the Chinese government or a specific hacking group, the operational documentation “points to a Chinese-language operator,” the researchers said. According to Dream, the attack framework, built on open source Hermes and OpenClaw AI agents, deployed up to eight sub-agents, each assigned to its own targets and attack techniques, across 12 “attack waves” between July 1 and July 4. First, the agents mapped the entire government ecosystem, extracting embedded URLs, API endpoints, OAuth client IDs, and Keycloak configuration objects from a single government portal. This portal allowed the agents to identify 21 connected government systems and every supported authentication flow. “On one target alone, it discovered 36+ API endpoints spanning account management, user data retrieval, file upload, and administrative functions - many completely unauthenticated,” the Dream threat researchers wrote. “Critically, it found that one of the systems exposed its entire user database without any authentication - thousands of employee records including names, departments, and SSO account IDs.” Multiple entry points After mapping the government’s attack surface, the agents found multiple entry points including three hidden API endpoints that accepted any request body and returned a valid authenticated session without requiring user credentials. Using employee usernames harvested from an unauthenticated API, the agents broke into a government department’s office automation portal, solving its CAPTCHAs with 100 percent accuracy. The agents also tested predictable password patterns based on each employee’s ID, and cracked 85 accounts across multiple password-spray rounds. Eighty-four of the 85 cracked accounts successfully authenticated to the department's internal information system, giving the attackers access to internal dashboards, equipment management interfaces, and personnel statistics pages. In total, the illicit access allowed the agents to exfiltrate a ton of government information, including more than 2,564 personnel records, a full JSON export of all department system users, seven SSO client secrets, six internal database credentials across MSSQL, Oracle, and Sybase, and internal network IP ranges. But wait, there's more And then, the agents pivoted to the Taiwanese government’s supply chain. “It expanded the operation to government IT supply chain vendors, a nuclear safety agency, a government email system, and 7+ energy sector companies - scanning them all in parallel for misconfigurations, exposed admin interfaces, and exploitable vulnerabilities,” the researchers wrote. Notably, the attack framework implemented what the AI tools called “learning cycles.” These are autonomous sessions where the models search vulnerability databases, GitHub repositories, and other security research for specific techniques, CVEs, and common weaknesses to exploit in the targeted government's infrastructure. Additionally, when the AI framework made a mistake, it “self-corrected,” according to Dream, catching errors and fixing them through its own verification process. This near-autonomous attack comes as frontier model makers OpenAI, Anthropic, and Meta all admitted that their agents went rogue, escaped from their training environments, and autonomously hacked other organizations and people. OpenAI technical staffer Michael Dalton, in a Black Hat briefing last week about the Hugging Face attack, said “AI orchestrated, fully automated offensive attacks are real now.” “In the near future, we should expect that threat actors will intentionally deploy, optimize, weaponize, and use offensive agent collectives in the manner that you have just described here,” he added. It appears that the future is now. ®
Kategorie: Viry a Červi

Terabytes of credentials leaked in massive supply-chain attack

Ars Technica - 12 Srpen, 2026 - 23:43

Terabytes worth of credentials, many belonging to the world’s biggest and most sensitive organizations, have been exposed in a supply-chain attack on LiteLLM, an open source tool that streamlines AI-driven software development. Microsoft, Amazon, Cisco, Samsung, and Salesforce are only a handful of the entities whose access secrets were exposed.

The revelation was posted on Tuesday and Wednesday by security firms CloudSEK and Hudson Rock. CloudSEK said it found cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys that could allow attackers to gain access to more than 2,500 organizations.

40 minutes is all it takes

The credentials were extracted during a 40-minute window in March while the victims used compromised versions of LiteLLM downloaded from the package’s official location in the Python Package Index repository. Hudson Rock said it made the discovery after analyzing a 195TB file that it obtained. Neither firm identified the source of the information.

Read full article

Comments

Researcher bypasses Microsoft Defender security patch, seizing control

Computerworld.com [Hacking News] - 12 Srpen, 2026 - 23:13

Just weeks after Microsoft patched a critical hole in Microsoft Defender, a cybersecurity researcher has posted an apparent bypass that provides system-level control to attackers once they gain any level of access. 

The researcher, who goes by the name Nightmare Eclipse, has been engaged in a long-running battle with Microsoft Security

Nightmare Eclipse has not provided the further details we requested, however Microsoft sent a brief statement, saying, “Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims,” and reiterating its commitment to investigating issues and supporting coordinated disclosure.

But the proof of concept (PoC) security bypass, ShieldBreak, described by Nightmare Eclipse in a series of public posts, potentially threatens to be more damaging than earlier bypasses. 

Like other recently reported vulnerabilities, ShieldBreak requires an attacker to first somehow gain system access, typically via a successful phishing scam. Once in, however, the attacker can gain full admin/root access.

But there is a troubling psychological component to ShieldBreak, in that it is a bypass for a recently posted security patch from Microsoft, noted Justin Greis, CEO of consulting firm Acceligence.  The problem is that CISOs who have already deployed that patch might feel protected when they are not.

“This one is concerning because the patch bypass directly calls the integrity of the remediation into question,” he said. “ShieldBreak appears to demonstrate that an attacker can bypass the fix Microsoft shipped for CVE-2026-50656 and ultimately obtain system-level privileges on the endpoint. That is an important distinction for enterprise defenders, because organizations may believe they have already remediated the underlying vulnerability. A successful patch bypass means the exposure can persist even after the normal vulnerability-management process says the system is protected.”

Greis added that such bypass can reduce overall trust in official patches. 

“When public proof of concept code can bypass it, the CISO’s question becomes ‘have we actually removed the exposure?’ rather than simply ‘have we deployed the patch?’,” he said. “From an architecture perspective, organizations should be very careful about allowing the same security product to become both the control being relied upon and the only source of evidence that the control is working.”

Flavio Villanustre, CISO for the LexisNexis Risk Solutions Group, said he was especially concerned about the timing of the PoC’s release, given that it seemed to be intended to put the most pressure on Microsoft, given its typical timing for security patches

“This vulnerability, if valid, would need a fix from Microsoft, but because those patches are usually only released on the second Tuesday of the month and the security researcher seems to have carefully timed the release of the PoC, we may have this exposure for another 4 weeks unless Microsoft deems this a very high severity risk, which is unlikely,” he pointed out.

Cybersecurity consultant Brian Levine, executive director of FormerGov, agreed that CISOs should not underestimate the damage potential if this PoC proves valid. 

“What makes it dangerous is what it does once they’re in: it turns an ordinary low-privilege account into full system control by abusing Defender itself, the security tool running at the highest privilege on the box,” he said. “An exploit that lives inside your antivirus is quiet, it’s trusted, and it can be used to blind or disable the very thing you’re counting on to catch the intruder. It’s not a worm, but it’s a near-ideal second stage for ransomware crews and anyone doing hands-on-keyboard intrusion.”

Levine suggested that CISOs not wait for a Microsoft fix, but immediately take an aggressive defensive stance.

“Assume it’s live and lean on defense in depth, because this is exactly the scenario where treating Defender as your only line fails you. Application allowlisting, such as WDAC or AppLocker in enforced mode, is the strongest hardening available and can stop the payload even if the race succeeds,” Levine said.

“Tighten local admin rights and least privilege so a foothold has less to escalate from. And give your hunters one very specific thing to watch for: an interactive shell or scripting host running as system whose parent process is Defender’s engine, MsMpEng.exe. That should never happen in a healthy environment and it’s a high-fidelity sign someone is running this.”

But he also suggested that CISOs not assume that the PoC necessarily works as advertised. 

“This is a single researcher’s proof of concept. It hasn’t been independently verified, and it’s coming from someone in the middle of a very public and very bitter fight with Microsoft, so perhaps some of the theater around it should be discounted,” Levine said. “But you can’t wave it away either. Patch bypasses are extremely common, and the claim that Microsoft’s fix for RoguePlanet didn’t fully close the door is entirely plausible. Defenders should treat it as credible until proven otherwise, not the reverse.”

Although Levine and other analysts were initially dubious, there are now indications that the PoC’s effectiveness has been independently verified. 

Cybersecurity and risk advisor Steven Eric Fisher, a former cybersecurity risk specialist at Walmart, said, “I’ve seen independent confirmation that ShieldBreak works, although its exploitation method differs materially from the original RoguePlanet exploit. RoguePlanet relied on a filesystem race condition, while ShieldBreak appears to use a different Defender/Cloud Filter API path,” Fisher said. “So while it is being characterized as a bypass of Microsoft’s CVE-2026-50656 fix, it is not simply a replay of the original exploit.”

He added that cybersecurity researcher Kevin Beaumont has already published Microsoft Defender Advanced Hunting detections for ShieldBreak that organizations can incorporate into monitoring while evaluating their exposure.

And Pieter Arntz, malware intelligence researcher at Malwarebytes, also said he has seen confirmation from a researcher he tracks, Will Dormann.

This article originally appeared on CSOonline. It has been updated with a statement from Microsoft and further confirmation of the exploit.

Kategorie: Hacking & Security

Researcher creates workaround for Microsoft Defender security patch

Computerworld.com [Hacking News] - 12 Srpen, 2026 - 23:13

Just weeks after Microsoft patched a critical hole in Microsoft Defender, a cybersecurity researcher has posted an apparent workaround that provides system-level control to attackers once they gain any level of access. 

The researcher, who goes by the name Nightmare Eclipse, has been engaged in a long-running battle with Microsoft Security

Nightmare Eclipse has not provided the further details we requested, however Microsoft sent a brief statement, saying, “Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims,” and reiterating its commitment to investigating issues and supporting coordinated disclosure.

But the proof of concept (PoC) security workaround, ShieldBreak, described by Nightmare Eclipse in a series of public posts, potentially threatens to be more damaging than earlier workarounds. 

Like other recently reported vulnerabilities, ShieldBreak requires an attacker to first somehow gain system access, typically via a successful phishing scam. Once in, however, the attacker can gain full admin/root access.

But there is a troubling psychological component to ShieldBreak, in that it is a workaround for a recently posted security patch from Microsoft, noted Justin Greis, CEO of consulting firm Acceligence.  The problem is that CISOs who have already deployed that patch might feel protected when they are not.

“This one is concerning because the patch bypass directly calls the integrity of the remediation into question,” he said. “ShieldBreak appears to demonstrate that an attacker can bypass the fix Microsoft shipped for CVE-2026-50656 and ultimately obtain system-level privileges on the endpoint. That is an important distinction for enterprise defenders, because organizations may believe they have already remediated the underlying vulnerability. A successful patch bypass means the exposure can persist even after the normal vulnerability-management process says the system is protected.”

Greis added that such workarounds can reduce overall trust in official patches. 

“When public proof of concept code can bypass it, the CISO’s question becomes ‘have we actually removed the exposure?’ rather than simply ‘have we deployed the patch?’,” he said. “From an architecture perspective, organizations should be very careful about allowing the same security product to become both the control being relied upon and the only source of evidence that the control is working.”

Flavio Villanustre, CISO for the LexisNexis Risk Solutions Group, said he was especially concerned about the timing of the PoC’s release, given that it seemed to be intended to put the most pressure on Microsoft, given its typical timing for security patches

“This vulnerability, if valid, would need a fix from Microsoft, but because those patches are usually only released on the second Tuesday of the month and the security researcher seems to have carefully timed the release of the PoC, we may have this exposure for another 4 weeks unless Microsoft deems this a very high severity risk, which is unlikely,” he pointed out.

Cybersecurity consultant Brian Levine, executive director of FormerGov, agreed that CISOs should not underestimate the damage potential if this PoC proves valid. 

“What makes it dangerous is what it does once they’re in: it turns an ordinary low-privilege account into full system control by abusing Defender itself, the security tool running at the highest privilege on the box,” he said. “An exploit that lives inside your antivirus is quiet, it’s trusted, and it can be used to blind or disable the very thing you’re counting on to catch the intruder. It’s not a worm, but it’s a near-ideal second stage for ransomware crews and anyone doing hands-on-keyboard intrusion.”

Levine suggested that CISOs not wait for a Microsoft fix, but immediately take an aggressive defensive stance.

“Assume it’s live and lean on defense in depth, because this is exactly the scenario where treating Defender as your only line fails you. Application allowlisting, such as WDAC or AppLocker in enforced mode, is the strongest hardening available and can stop the payload even if the race succeeds,” Levine said.

“Tighten local admin rights and least privilege so a foothold has less to escalate from. And give your hunters one very specific thing to watch for: an interactive shell or scripting host running as system whose parent process is Defender’s engine, MsMpEng.exe. That should never happen in a healthy environment and it’s a high-fidelity sign someone is running this.”

But he also suggested that CISOs not assume that the PoC necessarily works as advertised. 

“This is a single researcher’s proof of concept. It hasn’t been independently verified, and it’s coming from someone in the middle of a very public and very bitter fight with Microsoft, so perhaps some of the theater around it should be discounted,” Levine said. “But you can’t wave it away either. Patch bypasses are extremely common, and the claim that Microsoft’s fix for RoguePlanet didn’t fully close the door is entirely plausible. Defenders should treat it as credible until proven otherwise, not the reverse.”

Although Levine and other analysts were initially dubious, there are now indications that the PoC’s effectiveness has been independently verified. 

Cybersecurity and risk advisor Steven Eric Fisher, a former cybersecurity risk specialist at Walmart, said, “I’ve seen independent confirmation that ShieldBreak works, although its exploitation method differs materially from the original RoguePlanet exploit. RoguePlanet relied on a filesystem race condition, while ShieldBreak appears to use a different Defender/Cloud Filter API path,” Fisher said. “So while it is being characterized as a bypass of Microsoft’s CVE-2026-50656 fix, it is not simply a replay of the original exploit.”

He added that cybersecurity researcher Kevin Beaumont has already published Microsoft Defender Advanced Hunting detections for ShieldBreak that organizations can incorporate into monitoring while evaluating their exposure.

And Pieter Arntz, malware intelligence researcher at Malwarebytes, also said he has seen confirmation from a researcher he tracks, Will Dormann.

This article originally appeared on CSOonline. It has been updated with a statement from Microsoft and further confirmation of the exploit.

Kategorie: Hacking & Security

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

Bleeping Computer - 12 Srpen, 2026 - 22:54
Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts. [...]
Kategorie: Hacking & Security

Spectre rears its ugly head again as researchers show some RISC-V chips are susceptible

The Register - Anti-Virus - 12 Srpen, 2026 - 21:42
If you thought that the famous Spectre security vulns were a relic of 2018, think again. Certain RISC-V chips are still very much subject to this hair-raising hole, researchers say. Spectre refers to a family of vulnerabilities related to speculative execution, a performance optimization technique based on predicting the flow of data before instructions have been executed. Incorrect predictions get rolled back without affecting running applications but nonetheless leave traces that can be recovered and exploited to violate memory protections and access secrets. Spectre flaws have dogged x86 and ARM chips for years, leading computer scientists to develop a series of defenses, including Indirect Branch Restricted Speculation (IBRS), Indirect Branch Prediction Barrier (IBPB), and Single Thread Indirect Branch Predictor (STIBP). Researchers affiliated with academic institutions in Belgium and Germany say that it's been popular to assume that the RISC-V chip architecture isn't affected by Spectre vulnerabilities because it's too simple. That assumption is incorrect, according to a paper accepted at the 35th Usenix Security Symposium, "Spectre on RISC-V Silicon: Attacks and Defenses on Commercial Out-of-Order Processors." It says that commercially available out-of-order RISC-V processors (SiFive P550 and T-Head Xuantie C910/C920) are vulnerable to all major Spectre variants. RISC-V processors that process instructions in-order (SiFive U74, Xuantie C906, C908) do not appear to be vulnerable. Prior research has shown that RISC-V processors used for academic research (e.g. BOOM, RiscyOO, RSD, Proteus, NaxRiscv, and NutShell) can be affected by one or more of the Spectre variants, but hasn't addressed commercial silicon. "We demonstrate proof-of-concept attacks on both processors using Spectre-PHT, Spectre-BTB, SpectreRSB, and Spectre-STL, achieving up to 100 percent recall with more than 97 percent precision," the paper states. Spectre-PHT involves mistraining the Pattern History Table; Spectre-BTB poisons the Branch Target Buffer; Spectre-RSB attacks the Return Stack Buffer; and Spectre-STL (Store To Load) exploits mispredicted store-to-load forwarding. To demonstrate the risk to RISC-V, they created a proof-of-concept Spectre exploit that leaks arbitrary Linux kernel memory on the Xuantie C910 at a rate of 338 B/s. Software-based defenses have been developed for these vulnerabilities on x86 and ARM hardware. Unfortunately, the researchers say, these don't necessarily transfer. They also call out RISC-V hardware for its lack of introspection interfaces, necessary to observe and reason about microarchitectural features. In addition, the authors argue, the diversity of the RISC-V hardware ecosystem means that no single mitigation strategy is likely to be effective across all systems. "RISC-V inherits the software and threat model of mature architectures without their accumulated hardening," the authors conclude. "Closing this gap is not a matter of porting individual mitigations, but of building the architectural primitives, hardware transparency, and ecosystemwide tooling that effective Spectre defense presupposes." The authors say they disclosed their findings responsibly last December. Three of their patches have been merged into mainline Linux and two others are under review. SiFive is said to have dealt with P550-specific findings and T-Head (Alibaba) is said to have committed to publishing ad-hoc speculation barriers for their processors at some point. The authors say they decided not to delay publication because Spectre has been around for eight years now. The paper was written by Lukas Gerlach (CISPA Helmholtz Center for Information Security), Marton Bognar, (DistriNet, KU Leuven), Daniel Weber and Michael Schwarz, (CISPA Helmholtz Center for Information Security), and Jo Van Bulck (DistriNet, KU Leuven). ®
Kategorie: Viry a Červi

Lovable raises another $400M, confirms new $13.3B valuation

Computerworld.com [Hacking News] - 12 Srpen, 2026 - 21:28

Europe’s favorite vibe-coding startup Lovable has confirmed previously reported whispers that it was raising another mega round at a $13.3 billion valuation. Lovable said on Wednesday that it has raised $400 million in a Series C round led by Menlo Ventures and the Scaleup Europe Fund, with more than a dozen other investors participating.

This new funding comes after Lovable hit $500 million in annualized run rate revenue in June, the startup told TechCrunch. Its previous round, announced in December, brought in $330 million at a $6.6 billion valuation and was also led by Menlo Ventures, with CapitalG as co-lead.

Note: One of Lovable’s new Series C investors is Regent, the investment firm that owns Foundry.

Kategorie: Hacking & Security

Hundreds of fake Chrome VPN extensions route traffic through a proxy

Bleeping Computer - 12 Srpen, 2026 - 20:54
More than 737 browser extensions published on the Chrome Web Store impersonated well-known VPN and proxy services while routing users' traffic through SOCKS5 proxies operated by a single provider. [...]
Kategorie: Hacking & Security

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

The Hacker News - 12 Srpen, 2026 - 19:39
The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India. The activity, per Check Point Research, is part of Operation Dream Job, a long-running cyber espionage and Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Syndikovat obsah