Agregátor RSS

Bezpečnostní chyby v produktech od Intelu – 08/2026. Mikrokód 20260811

AbcLinuxu [zprávičky] - 12 Srpen, 2026 - 14:23
Intel vydal 42 upozornění na bezpečnostní chyby ve svých produktech. Současně vydal verzi 20260811 mikrokódů pro své procesory.
Kategorie: GNU/Linux & BSD

Apple’s response to RAM-ageddon? Lease, downgrade, refurbish, repair

Computerworld.com [Hacking News] - 12 Srpen, 2026 - 14:07

Apple is in the process of tweaking its business models to cope with the unyielding memory price and availability crisis. Its response is now emerging across multiple fronts.

Finance or lease

The company’s recently-introduced Apple Upgrade scheme in partnership with Klarna is a smart response to the reality that as devices inevitably become more expensive, consumers will shift from outright ownership to flexible lease and financing arrangements. With its partnership, Apple continues to generate revenue while also maximizing the likelihood customers will return the product at EOL, more about which later.

Samsung and Google have introduced similar schemes. “Financing models already dominant in India and Africa are now poised to reshape the US and European markets,” said CCS Insight in a presentation exploring the consequences of the memory shortage.

Downgrade

Apple has seen a lot of success with the iPhone 17 this year. That success wasn’t entirely because it’s such a good smartphone; it also reflects consumers making the decision to purchase lower-specced devices to stay within budget. Apple continues to see strong sales of its Pro range, which represents the power of its reach into more affluent consumer groups. It’s also important to note that at the moment, the iPhone 16e is the biggest-selling device on the US pre-paid market.

People still want the best, but are being more cautious in how they acquire it.

Refurbished

The trade in refurbished devices is fundamentally built on two things: A large installed base of originally-sold devices resilient enough to be refurbished in the first place and buy-back deals attractive enough to encourage consumers to trade those devices in at all. That’s why it matters that Apple recently increased the value of its trade-in scheme: you’ll get up to $480 for an iPhone 16 or up to $720 for an iPhone 16 Pro Max under Apple’s new deal. It’s also important because Apple has its own growing refurbished business in Apple Refurb, and also because devices that really have reached end-of-life can be broken up for parts, taking a little pain out of Apple’s ongoing component crisis.

In 2024, Apple shifted 15.9 million refurbished devices and accessories.

Delay and Repair

As prices rise, consumers will keep their devices longer and are far more willing to repair existing hardware than upgrade. It’s well-known that iPhones are the most durable smartphones and ship with extensive future system support, so these devices can be successfully used for five years — sometimes more. Apple offers its own service and support package to keep your devices in good shape, and its recent decision to extend AppleCare One support to new nations reflects consumer sentiment. Those who want Apple’s trusted support for up to three devices can now get it for just a few dollars each month.

Not just about iPhones

All these initiatives are important in their own right, of course, and while I’ve focused on iPhone here, Apple is implementing these changes and services across all its product lines. It knows that in the face of AI-flation, consumer habits will change. Demand for new devices — assuming Apple can even get enough components to make them — will fall. “Demand for refurbished models and financing will grow — fast,” said CCS.

The other transformation concerns price. The hyperinflation driven by decisions made by the effective cartel of the big three memory vendors (who could have continued to support the consumer memory industry while providing less support for data centers) is driving low-tier smartphone manufacturers to exit markets or raise prices. CCS expects smartphone prices to increase by 25%. Counterpoint says DRAM prices have risen 70% since 2025, while Gartner and others expect price inflation to remain into next year.

As Intel’s CEO said, “There’s no relief until 2028.”

Price increases leave a huge gap in the sub-$500 device market; that’s a vacuum the second-user market in refurbished smartphones will fill. As the value of that tier increases, it becomes a more strategically important market for both Apple and Samsung, who make the vast majority of smartphones. For both vendors, ongoing market changes mean the second-user market is becoming a primary channel for both companies; you can expect continued business pivots from both as they seek to capture business revenue.

Incoming structural challenges

Even there, there’s a structural challenge to overcome. That is that as memory prices surge, sales of new devices decline. Down the road, there will be fewer devices to trade in, meaning the supply of used devices will fall, creating a future supply-and-demand imbalance in the second-user market. I predict this could get quite bitter, with manufacturers grabbing larger chunks of available devices to the detriment of the small renew-and-refurbish retailers. CCS Insight expects the market for second-user smartphones to grow by 9% in 2026 as cost-and-supply challenges bite.

Making the circle

There is opportunity within the chaos. Apple has committed to building a circular manufacturing ecosystem by 2030, which is only four years away. 

We don’t know how far along the company is on that road, or the extent to which changing market conditions have undermined its attempt to reach that goal. But the company will have spent time developing new manufacturing and production processes to enable more extensive use of recycled and renewable raw materials in that attempt.

The signs are positive — the recently introduced MacBook Neo has a 90% recycled aluminium enclosure and 100% recycled cobalt battery. 

Distorted loop

There is a reality in which any slowdown in new device manufacturing — or, indeed, the cadence of new device introductions — gives Apple and its partners a little breathing space in which to develop and deploy new manufacturing process technologies. 

In that narrative, it does perhaps matter that under its new iPhone release schedule, there will be an 18-month gap between the launch of the best-selling iPhone 17 and the spring 2027 release of the iPhone 18. With a 20th anniversary iPhone and new iPhone Ultra range, along with some talk of a future flip phone, Apple may soon be in position to maintain the marketing buzz with new iPhones every six months while actually crafting an 18-month wait between major device improvements.

Doing so will likely reduce initial unit shipments while also flattening sales revenue for more predictable income. It also builds in extra time to retool the production lines for each device family.

Leading with the new

When it comes to the deployment of new circular manufacturing tech, that potential 18-month gap buys that most precious of resources, time. Which means that while memory price inflation has caused huge problems, raised prices and forced Apple to change business practices, it could also give the company an opportunity to introduce one of the most profound changes in manufacturing of the 21st Century: circular manufacturing. To some extent, this transition in the nature of Apple’s business is reflected at board level, as the company is itself transitioning to new leadership under incoming CEO John Ternus.

You can follow me on social media! Join me on BlueSky, LinkedIn, Mastodon and subscribe to The Core to keep pace with daily Apple news in one email.

Kategorie: Hacking & Security

OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning

The Hacker News - 12 Srpen, 2026 - 13:47
A newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API calls let researchers recover internal reasoning and secrets from session logs, including API keys and passwords. The weakness affected encrypted reasoning objects used by the providers' reasoning APIs, where a block created in one session could be replayed into another and, during testing, Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Enterprise Defenses Recovered at the Edge and Collapsed Inside

The Hacker News - 12 Srpen, 2026 - 13:41
Enterprise defenses are tuned to catch the attacks that make noise. This year's data shows attackers winning by making none. According to Picus Labs' new Blue Report 2026, which measured more than 338 million real attack simulations across actual client production environments in the first half of 2026, defenses are having one of their strongest years yet. Average prevention effectiveness [email protected]
Kategorie: Hacking & Security

Signal adds new security feature to thwart man-in-the-middle attacks

Bleeping Computer - 12 Srpen, 2026 - 13:21
​Signal has introduced Automatic Key Verification, a new security feature that gives users a new way to ensure their encrypted chats haven't been intercepted. [...]
Kategorie: Hacking & Security

Brit rail cops bring live facial recognition to the London Underground

The Register - Anti-Virus - 12 Srpen, 2026 - 13:19
British Transport Police is expanding its trial of live facial recognition (LFR) to the London Underground, despite concerns about privacy and mistaken identification. The force, which polices railways across England, Scotland, and Wales, will begin its Tube deployments at Victoria Underground station. The cameras will then rotate between Underground and Network Rail stations until the trial ends in November. The trial began at London Bridge railway station in February and is intended to assess how the technology performs in a railway setting. It follows deployments by the Metropolitan Police, which says it will start using face-scanning cameras in London's West End and Soho by the end of this year after a six-month pilot in the south London borough of Croydon. Live facial recognition scans faces within a camera's field of view and compares them with a police watchlist. A possible match generates an alert that an officer must review before deciding whether further action is warranted. According to the railway bobbies, the technology deployed relies on the NEC NeoFace M40 algorithm, which appears to be the same across several forces. "Expanding deployments into London Underground stations will help us assess the technology in a different transport environment while continuing to refine how it is used across the railway network," said the officer responsible for the project, chief superintendent Chris Casey. Critics describe the technology as dystopian and intrusive, and errors have already resulted in innocent people being mistaken for criminals and detained. Members of ethnic minorities appear to be more at risk of being mistaken for someone else by facial algorithms. "This is a disturbing and dystopian expansion of live facial recognition that will capture millions of innocent people's faces. Far from reserving this for exceptional cases, British police are now using live facial recognition routinely in the sort of pervasive way you might expect in China, but not in a democracy," says Silkie Carlo, director of civil liberties group Big Brother Watch. The London Underground network is estimated to handle more than 3.7 million passenger journeys a day on weekdays. A recent Opinium survey of 2,000 UK adults, commissioned by facial recognition biz Face Int, found that 69 percent believed the public should have a say in how the technology is used. It also found that 61 percent worried errors could get people into trouble for things they had not done, while 57 percent were concerned about how facial images were stored. Britain's railway fuzz says images of anyone who does not match the authorized watchlist are deleted immediately and permanently. Whether that remains the policy in future is another matter, of course. We asked the British Transport Police to comment regarding public concerns about the use of facial recognition technology. A spokesperson for the force referred to us to the comments made in the announcement by chief superintendent Casey, who said: "Our focus remains on protecting the public, preventing crime and bringing offenders to justice, while ensuring the technology is used lawfully, proportionately and transparently." ®
Kategorie: Viry a Červi

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

The Hacker News - 12 Srpen, 2026 - 13:13
Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation. The most severe of the flaws are listed below - CVE-2026-48362 (CVSS score: 10.0) - An operating system command injection vulnerability in ColdFusion that couldRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

AI policies work better when employees help write them

Computerworld.com [Hacking News] - 12 Srpen, 2026 - 13:00

It’s likely that many enterprises have created — or are at least considering — AI policies that clearly lay out approved AI tools and their uses, set up training programs for employees to help them use the tools in their jobs, and establish guardrails around those systems to avoid issues such as security vulnerabilities and data bias.

But how many of these policies have received the blessing of employees? It’s a key question, because many workers are highly wary of AI.

They worry that it will cost them their jobs, either by taking over their work or because companies will cut jobs and use the savings to fund investments in AI research and infrastructure. They worry about AI-powered performance tracking software impacting raises and promotions. They worry about AI screening of job applications for future roles.

Even employees who have embraced AI to assist their work have reason to worry. Many say that using generative AI tools saves them time, but the time savings are eroded by “botsitting” — having to check and recheck output, provide missing context, fix errors, and go through multiple iterations before the desired outcome is achieved. They may also have to wade through “workslop,” low-quality genAI output that hasn’t been properly vetted by co-workers.

Additionally, workers say that as AI makes them more productive, their workload keeps increasing. All of this can add up to “prompt fatigue” or “AI brain fry,” mental exhaustion that affects heavy genAI users, particularly when they bounce between multiple AI tools.

AI policies that don’t take these factors into account are apt to be problematic. Employees may even organize to protect themselves from AI in the workplace. Indeed, tech pros are increasingly interested in unionizing, driven in part by the incursion of AI.

It doesn’t have to come to that. Company leaders can proactively work with their employees to develop AI policies that take employee well-being into account. The result might be stronger AI adoption, better business outcomes, and a happier, more productive workforce.

The 2026 Tech Sentiment Report by technology career marketplace Dice found that professionals are generally not resisting AI itself, “but rather, they’re looking for clarity around how it will affect their jobs, careers, and workplace decisions,” says Paul Farnsworth, president of the firm. “The research suggests that employee buy-in comes from making AI feel like something being done with workers rather than to them.”

In many cases, IT management runs the deployment of AI, and this can ultimately result in employees being left out of any decision making.

“When IT leaders drive deployment, they ask questions about integration, security, and capability,” says Amy Loomis, group vice president, Workplace Solutions at IDC. “That is not the same as asking workers how AI could actually improve their day, where they waste time on tasks that add no value, and where a well-designed tool would make a real difference.”

Following are some key steps to building an AI policy everyone can agree on. Bear in mind that any worker protection items should be in addition to the usual corporate governance, risk, and compliance AI policies, not a replacement for them.

Invite input from everyone involved

It might sound obvious but can’t be overstated: the only real way to produce an AI policy that employees will accept is to get their input.

“We started by surveying our employees through SurveyMonkey to see what they were already using and why,” says Monica Washington Rothbaum, COO and senior attorney at law firm J&Y Law. “Then we sat down with every department, and involved operations, IT, HR, and leadership from the beginning. We wanted to understand the opportunities, but we also wanted to understand the risks” of AI.

Most AI policies “fail when they’re created in a conference room and handed down from the top,” Rothbaum says. “The people using these tools every day need to be part of the conversation. That’s why transparency became a major focus for us” in creating an AI policy.

Organizations should include employees in policy development, pilot programs, and feedback processes, Farnsworth says. This is especially important because Dice research found that only 48% of organizations have formal AI policies, while nearly one quarter of professionals surveyed said they’ve used AI without manager approval.

Keep the lines of communication open

Creating an AI policy is not a one-and-done proposition. Organizations need to keep communicating with employees as AI and tools evolve.

“We communicated updates during company all-hands meetings, through email, in Microsoft Teams, and through department-level discussions,” Rothbaum says. “We even designated a member of our marketing team to oversee communications around AI adoption so there was clear ownership and accountability.”

The biggest mistake organizations make is treating AI like standard software, Rothbaum says. “It’s not. It’s an operational change,” she says. “It’s a communication challenge. It’s a governance challenge. The technology itself is often the easy part. The hard part is deciding what data can be used, who has access, how outputs are reviewed, and how the organization remains compliant while the technology continues evolving.”

Address fears about employment

One of the biggest drawbacks to AI adoption, from the standpoint of many employees, is the worry that AI tools will ultimately take away their jobs or many of their responsibilities.

Indeed, this has already been the case at some tech companies. A majority of non-AI technology professionals think AI eliminates more jobs than it creates, according to the Dice report, and three quarters think

junior-level workers are most at risk of displacement.

“Reassurances that no jobs will be lost ring hollow when workers can see
reorganizations happening around them,” Loomis says. “The organizations that sustain worker trust communicate specifically about what is changing, what it means for individual roles, and what the organization is committing to in return.”

One way to get around these concerns is to include provisions in policies that require any decisions around individual workers’ employment to be made by a human. That way no one can be dismissed from their job at the discretion of a machine.

Ensure access to training programs

Another way to gain workers’ support for AI policies is to include provisions about access to ongoing training and educational programs designed to build on their existing knowledge and provide them with valuable new skills.

“Employees are more likely to embrace AI when they see opportunities to grow alongside it,” Farnsworth says. “As AI becomes increasingly embedded in daily work, organizations should invest in AI literacy, upskilling, and career development programs to help employees adapt to changing job requirements.”

And those programs should be codified in AI policies. Guaranteeing workers access to training that evolves with the technology and enterprise workflows “requires treating training as a policy commitment with defined standards, timelines, and completion tracking,” Loomis says.

“Effective AI training does two things: it teaches workers how to use specific tools in the context of their specific roles, and it builds the human skills, judgment, critical thinking, and adaptability that determine whether workers can use AI well rather than just technically. Both are necessary,” she says.


When training is treated as a one-time event rather than a continuous policy commitment, Loomis says, adoption stalls and distrust grows. Ongoing “human skills training is gaining explicit recognition as core to
effective AI use,” she says.

Adopt guardrails against harmful uses of AI

This needs to be a standard component of any AI policy. But the language of proper and improper uses of AI tools and data must be clear for everyone in the workforce.

Such guardrails not only address cybersecurity and regulatory concerns, but can help prevent uses of AI that result in discrimination.

“The organizations that get the most value from AI won’t be the ones that adopt it the fastest,” Rothbaum says. “They’ll be the ones that communicate clearly, train consistently, and build the right guardrails before they need them.”

Confidential, client, firm, or employee information may not be entered into any AI tool unless explicitly authorized and approved, according to the J&Y Law policy.

Emphasize the positives of AI

Policies will of course include restrictions on the use of AI and rules around avoiding risks, but they also need to share how workers can leverage tools to help make their jobs easier or more fulfilling.

“One thing we’ve seen is that effective AI policies aren’t just lists of restrictions,” Farnsworth says. “Instead, they provide employees with clear guidance on how to use AI responsibly and confidently in their work. At Dice, our AI policy encourages employees to use AI when it can improve productivity, while establishing guardrails around data security, confidentiality, and human oversight.”

A good policy will help employees better understand that AI presents not just risks, but opportunities as well.

More on AI in the workplace:
Kategorie: Hacking & Security

Samořídící Tesla FSD se šíří Evropou, Česko volí vyčkávací taktiku

Živě.cz - 12 Srpen, 2026 - 12:45
Od dubna elektromobily značky Tesla samy řídí v Nizozemsku, mezi květnem a červnem schválily asistenční systém Tesla FSD Sepervised také v Litvě, Estonsku, Dánsku a Belgii. Se stanoviskem se ozvalo i české Ministerstvo dopravy a fanoušky zklamal zdrženlivější přístup. Ale naděje se upínaly k 30. ...
Kategorie: IT News

New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges

Bleeping Computer - 12 Srpen, 2026 - 12:15
Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldBreak" after Microsoft released the August 2026 Patch Tuesday security updates. [...]
Kategorie: Hacking & Security

Průmyslové odpadní vody mohou být zdrojem cenných kovů. Nová metoda zvládne i rychlé odstranění soli

Živě.cz - 12 Srpen, 2026 - 11:45
Nový elektrochemický systém dokáže současně odsolovat vodu a vyseparovat kovy • Přesnou změnou napětí na elektrodách získáte zpět velmi čistou měď • Výrobcům klesnou náklady na odpad a získají zpět cenné suroviny
Kategorie: IT News

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

The Hacker News - 12 Srpen, 2026 - 11:01
Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrary code. Patches for the flaw were Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Počítače by teď mohly stát víc i kvůli Microsoftu. Windows zdražil až o 10 %

Živě.cz - 12 Srpen, 2026 - 10:45
Počítače v posledních měsících velmi zdražují, protože šly nahoru ceny výrobních procesů u moderních logických čipů, na několikanásobek původních hodnot se pak posunuly paměťové čipy pro RAM a SSD. Za počítače si ale nejspíš připlatíme i kvůli aktuálnímu kroku Microsoftu. Podle tchajwanských médií ...
Kategorie: IT News

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

The Hacker News - 12 Srpen, 2026 - 10:04
Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems that installed them. Threat intelligence firm CloudSEK now says a dataset it obtained, built from roughly 434,000 files the attackers captured, maps potential exposure to more Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Microsoft: Zdražuje hardware, proč nezdražit i licence Windows?

CD-R server - 12 Srpen, 2026 - 10:00
Nejen operační a grafické paměti, SSD a mechanické pevné disky. Od OEM výrobců prosákla informace, že i Microsoft zdražil licence na operační systém Windows 11…
Kategorie: IT News

SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

The Hacker News - 12 Srpen, 2026 - 09:31
SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution. The vulnerability, assigned the CVE identifier CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It has been described as a case of insufficient authorization checks and input validation. "SAP Commerce Cloud allows an Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access

The Hacker News - 12 Srpen, 2026 - 08:41
The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldBreak. The vulnerability, rooted in Microsoft Defender for Windows, demonstrates a patch bypass for CVE-2026-50656 (CVSS score: 7.8), otherwise known as RoguePlanet. RoguePlanet has been described Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Syndikovat obsah