Agregátor RSS
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads.
The rogue gems are listed below -
git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3) - Published on July 18, 2026
Dendreo (versions 1.1.3, 1.1.4) -
Kategorie: Hacking & Security
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads.
The rogue gems are listed below -
git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3) - Published on July 18, 2026
Dendreo (versions 1.1.3, 1.1.4) - Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
S osvobozením zaměstnaneckých benefitů to bude opět jinak. Stěžovat si ale (asi) nebudete
Pravidla pro osvobození zaměstnaneckých benefitů se od příštího roku opět změní. Přibudou plnění, která budou osvobozená bez limitu i další způsoby, jak budou moci zaměstnavatelé svým lidem přispět.
Kategorie: IT News
Postrehy z bezpečnosti: AI agentom sa nedá veriť ani vlastná pamäť
Pozrieme sa na to, ako sa dá jediným e-mailom prepísať pamäť AI agenta, ako sa dá agentovi klamať, čo dokáže cudzie rozšírenie v prehliadači a prečo AI útočník naletí na návnadu ochotnejšie než človek.
Kategorie: GNU/Linux & BSD
Arch Linux pro Steam Frame, Google uzavírá Android
Byl představen projekt Holo Core, oficiální portu Arch Linuxu pro ARM64, který bude tvořit základ operačního systému připravovaného VR headsetu Steam Frame. Od září 2026 bude Google na Androidu blokovat software třetích stran.
Kategorie: GNU/Linux & BSD
5,4GHz Zen 6 / Medusa otestován, mainstream CPU na úrovni high-end Panther Lake
Základní mobilní APU Medusa Point s jádry Zen 6 se v podobě 5,4GHz vzorku dočkalo výkonnostního testu. Po procesorové stránce je srovnatelné s 65W top modelem řady Panther Lake od Intelu…
Kategorie: IT News
Převratný 3D termální kryt blokuje teplo ve všech směrech
Nový termální kryt z hybridního materiálu dokáže skrýt objekty téměř libovolného tvaru před infračervenými kamerami a zároveň je chrání před extrémními teplotami. 3D tištěná hliníková mřížka vyplněná pryžovitým materiálem dokáže zázraky. Infračervená kamera nevidí vůbec nic.
Kategorie: Věda a technika
Tajemství Obřího ještěřího šéfa
…aneb Jak se to skutečně má s rodem Futalognkosaurus
Kategorie: Věda a technika
Americká armáda investuje do vývoje superlaseru o výkonu 500 kW
Pentagon má zálusk na tak výkonné lasery, že sestřelí střely s plochou dráhou letu nové generace nebo vyřídí celá hejna dronů. Chtělo by to výkon 500 kW. V rámci iniciativy Scaled Directed Energy (SCADE) Critical Technology Area na tom v Lockheed Martin Aculight a nLIGHT Defense už pracují.
Kategorie: Věda a technika
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and 1.31.3 (mainline), and in NGINX Plus 37.0.3.1; anyone on an earlier build should upgrade.
Triggering it can crash or restart the worker, causing a denial of
Kategorie: Hacking & Security
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and 1.31.3 (mainline), and in NGINX Plus 37.0.3.1; anyone on an earlier build should upgrade.
Triggering it can crash or restart the worker, causing a denial of Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Connecting AI agents to outside services explodes the risk radius
Avoiding the "lethal trifecta" – access to private data, exposure to untrusted content, and an external communication path – is difficult enough when working with AI agents. But the use of connectors – integrations with third-party services like Gmail or Slack – expands the scope of concern in a way that makes it exceedingly difficult to reason about defensive due diligence. PromptArmor, an AI security biz, recently looked at how OpenAI's ChatGPT and Anthropic's Claude work with connectors. The results are not reassuring. Shankar Krishnan, co-founder of PromptArmor, told The Register in an email that enterprise adoption of connectors and the rate of change among connectors helped focus concern on the connector ecosystem. Connectors share some of the risks of MCP servers, upon which connectors are based. "For connectors, the risks are mostly about the type of tools, what they can do, where the data is going, and what is being done with the data," said Krishnan. Introduced about a year ago, connectors (for Claude or ChatGPT) have been going through a lot of changes recently. According to PromptArmor, 931 of 2,517 connectors (37 percent) changed over the six-week period from mid-May to the end of June. So any security assumptions based on declared capabilities may no longer be valid. PromptArmor found that 1,686 new tools were added to connectors that were already live, creating new ways for AI models to operate on user data and interact with third-party services. It also found that 1,127 tool descriptions were rewritten, potentially changing how and when an AI model decides to invoke a tool. And there are a variety of other changes, all of which potentially could raise data security concerns or invalidate governance assumptions. PromptArmor cited the Dropbox connector as an example, noting that at the start of the study it exposed eight tools and by the end of the study that number had risen to 24. It went from having three write-capable tools to 10, and from zero potentially destructive tools to four. Permission scopes changed and injected instructions for the model were added. If that weren't enough to worry about, connectors can behave like intrusive websites that run dozens of tracking scripts: connectors commonly send data to additional AI services. PromptArmor evaluated all 7,517 tools used by 487 Claude connectors and found that 189 of the connectors, or about 2 in 5, are likely to call additional AI services. "As an example, if your Claude agent activates Zoom's connector tool to search meetings with natural language, and passes in a query containing sensitive data, Zoom AI may send that data to any of its ten AI subprocessors in order to generate a response from one of eight different model families it uses," the security company said. "The issue is that most teams approving connectors are evaluating and considering the connector – unaware that the vendor is calling more AI services, adding new subprocessors and terms," explained Krishnan. "So someone concerned about AI risks who has evaluated Claude may not be aware of AI services that the connector is calling externally." Anthropic's connector documentation acknowledges that its security controls don't necessarily cover third-party data processing. "Connected services process data on their own infrastructure, under their own terms, which may be located outside the United States," the AI biz explains. "Settings that control where Claude's inference runs, like the US-only inference setting on Enterprise plans, don't change where third-party services operate." Krishnan said that connectors vastly expand the risk surface for attacks. "Bringing agents new sensitive data, new untrusted data, and new sensitive actions to take, the blast radius of an attack explodes," he said. "We recently highlighted a risk in Codex where even with one connector – email – the combination of sensitive and untrusted data enables exfiltration of legal and financial communications." ®
Kategorie: Viry a Červi
Hackers abuse ViPNet software to target Russian govt agencies
An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies. [...]
Kategorie: Hacking & Security
USA jsou blíž ke zrušení střídání času. Pokud návrh projde, v listopadu se už ručičky nevrátí zpět
Sněmovna reprezentantů USA schválila zavedení trvalého letního času • Návrh však stále naráží na odpor u několika vlivných senátorů • Podle lékařů přitom temná zimní rána vážně naruší lidský biorytmus
Kategorie: IT News
UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware.
According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has been attributed to UAC-0145, a sub-cluster within Sandworm, an advanced hacking unit affiliated with GRU, Russia's
Kategorie: Hacking & Security
UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware.
According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has been attributed to UAC-0145, a sub-cluster within Sandworm, an advanced hacking unit affiliated with GRU, Russia's Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026.
Cybersecurity company Volexity is tracking the activity under the moniker UTA0533. The discovery was made following an incident response investigation earlier this
Kategorie: Hacking & Security
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026.
Cybersecurity company Volexity is tracking the activity under the moniker UTA0533. The discovery was made following an incident response investigation earlier this Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Přenosné 100" 4K kino na chalupu i do ložnice. Projektor Xgimi Elfin Flip váží jen 1,5 kg a není to bludička
Kategorie: IT News
Albert, Globus a Kaufland nasazují AI do pokladen. Zákazníkům zrychlí odbavení, nenápadně upozorní na zloděje
Nakupování v oblíbených českých obchodech prochází změnou, díky které odbavíte svůj nákup rychleji • . • Zdlouhavé hledání pečiva či zeleniny v menu přebírají kamery a váhy s AI. • Tuto novinku nasazují do provozu řetězce Albert, Globus a Kaufland.
Kategorie: IT News
- « první
- ‹ předchozí
- …
- 69
- 70
- 71
- 72
- 73
- 74
- 75
- 76
- 77
- …
- následující ›
- poslední »



