Agregátor RSS

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

The Hacker News - 11 Srpen, 2026 - 18:47
Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent. The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft's Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Nevyžádaná instalace OneDrive Photos ve Windows 11 byl omyl. Microsoft aplikaci zase potichu odvolal

Živě.cz - 11 Srpen, 2026 - 18:45
Ve Windows 11/10 se bez vašeho vědomí automaticky instaluje nová aplikace. • OneDrive Photos jsou prohlížečem obrázků spojeným s klientem OneDrivu. • Nelze je odinstalovat a zejména firmy jsou nespokojené.
Kategorie: IT News

DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt

The Hacker News - 11 Srpen, 2026 - 18:35
The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience. "Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process," the Microsoft Threat
Kategorie: Hacking & Security

DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt

The Hacker News - 11 Srpen, 2026 - 18:35
The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience. "Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process," the Microsoft Threat Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

DEF CON dingus suspected of trying to take over Delta in-flight Wi-Fi

The Register - Anti-Virus - 11 Srpen, 2026 - 18:27
A passenger on a Delta Air Lines flight from Las Vegas to Atlanta after DEF CON is suspected of jamming the in-flight Wi-Fi and broadcasting an unauthorized network in what could amount to a federal offense. It seems like someone forgot the old truism "what happens in Vegas stays in Vegas." News of the incident began circulating late Monday when flight watchers spotted Aircraft Communications Addressing and Reporting System (ACARS) messages from the crew of Delta Flight 591 indicating that something was up with the Wi-Fi and that they suspected a passenger was to blame. “HEY ALERT CORP SECURITY WE HAVE A PAX [passenger] ON THAT HAS CREATED A SCAM WIFI CALLED DELTA WIFI FAST WE BELIEVE THEY ARE TRYING TO SCAM THE OTH PAX,” the first notice read. Several minutes later, the flight crew followed up with a second message stating they had little additional info at the time, but pointing the blame at “A BUNCH OF PAX THAT WERE AT A CYBER CONFERENCE IN LAS” who “WERE ABLE TO JAM OUR WIFI” and broadcast their own signal. From there, the timeline and truth of the situation get a bit fuzzy, with accounts on social media differing as to what happened next. A poster on X speculated that the culprit was trying to phish for passenger credentials by setting up the fake Wi-Fi network, while a Facebook post shared to Reddit claimed that the incident involved a deauthentication attack that kicked users off the legitimate network before bringing up their own, which included a fake landing page, possibly using a device like a Wi-Fi Pineapple, which can broadcast fake networks, perform deauth attacks, and the like. A commenter in a thread on the Hacking subreddit (linked above) claimed to have been at the terminal in Las Vegas and said the individual was doing the same thing to airport Wi-Fi. The Facebook and X posts both claimed that law enforcement was waiting at the gate, though a post in the Delta subreddit included a comment from someone claiming to have been on the flight who didn’t see any police waiting at the gate. Regardless of what actually transpired once the plane landed, Delta Air Lines confirmed the incident to The Register. “We are fully investigating to gather a complete set of facts, which will take time,” a Delta spokesperson told us in an email. “We will partner with federal law enforcement and aviation regulators to ensure the incident is thoroughly investigated.” Delta further noted that the safety of the plane, crew, and passengers was never in question, and no aircraft systems were affected. The airline also told us that there was no hack of any Delta system, including the in-flight Wi-Fi, though it did confirm that an unauthorized Wi-Fi network was broadcast onboard the aircraft for a short period of time. Some of the confusion over the possible deauthentication attack may have come from the cabin crew deactivating the in-flight Wi-Fi for around 30 minutes due to the incident, Delta explained. The airline reiterated that the flight was leaving following the wrap-up of Black Hat and DEF CON, suggesting it suspected an attendee was behind the bad decision. We asked the Atlanta Police’s airport division if it was involved at all, and a representative told us they were unaware of the incident. Atlanta’s Department of Aviation declined to provide any comment on the matter. Based on Delta’s comment, it’s not clear whether the incident involved deliberate interference with authorized Wi-Fi communications, but if investigators determine that it did, the penalties could be severe. According [PDF] to the Federal Communications Commission, intentional Wi-Fi blocking can violate the Communications Act’s section 333. A willful and knowing violation punishable under the Act’s general criminal provision could carry a penalty of up to one year in prison and/or a fine of up to $10,000 upon conviction. If this wannabe hacker with a penchant for choosing the worst possible target in the world is stupid enough to have been caught doing this before (and let’s be frank - if you’re going to try jamming the Wi-Fi on a commercial airplane, you’re not that bright), that prison term could extend to up to two years. ®
Kategorie: Viry a Červi

Apple’s price hikes are a warning to IT

Computerworld.com [Hacking News] - 11 Srpen, 2026 - 17:59

IT purchasing is being hit by a double-whammy: Enterprises want to ensure their hardware is good enough to support AI, even as memory shortages caused by AI deployments are driving steep price increases for Macs, iPhones, iPads, tablets, Android devices and Windows PCs. 

The root cause is widely known. JP Morgan estimates DRAM prices have risen more than 400% since the beginning of 2024 as data center construction and hyperscaler demand consumed a gargantuan chunk of global memory production capacity.

More pain is coming

“It is not a secret that the industry will stay in shortage for multiple years,” warned analyst Jay Kwon. IDC analysis expects DRAM manufacturing capacity to fall short of demand, while SK Hynix believes demand will exceed supply well into the next decade. AI data centers are absorbing around 70% of output. 

This tough provisioning juggling act plays out as economic insecurity continues and the supply of key materials beyond memory also remains constrained. It makes for a perfect storm of shrinking purchasing budgets, rapid price increases, and competitive pressure to accelerate ongoing patterns of digital transformation.

To some extent, business leasing schemes will probably become more popular, while IaaS and SaaS vendors will widen their offerings to also include the kind of AI services businesses need. But the scale of the problem is pretty clear:

These price increases are not isolated; they reflect the global memory price challenge. Gartner expects memory prices will increase roughly 130% by the end of the year, while TrendForce’s recent survey sees further DRAM price increases ahead.

No one will be spared

This is a global challenge affecting businesses and consumers everywhere in real time. What’s important about these price hikes is their unpredictability; in most cases, business leaders will not have known the increases were coming, which means existing, pre-determined purchasing budgets do not reflect this new reality.

“The IT landscape faces a seismic shift, and its epicenter is memory,” according to Insight. “The market dynamics have fundamentally changed.” In other words, this challenge is long-term, structural, and here to stay.

As a result, every device that contains memory or a processor will get more expensive; this is already particularly visible in networking equipment, the cost of which climbed up to seven-fold in some cases this year. Games consoles, smart TVs and streaming boxes — including Apple TV — have not been spared.

IT purchasers are looking at these trends and wondering what to do. When it comes to PCs, price unpredictability means that lower cost isn’t necessarily an advantage. It makes more sense to spend a little more today to end up with a system that can continue working for your business for five years or more. Purchasers want longer hardware life cycles and are more willing than they once were to look at refurbished devices, which is driving growth in reconditioned markets.

(Apple sees this, which is why it recently raised trade-in prices for its kit as it seeks to recondition and resell its own products where possible.)

Reliability, resale value, and recycling and energy costs need to be considered, concerns that are in part driving businesses toward Macs. Regular readers will recognize the numbers often add up. Forrester’s Total Economic Impact research says lower support costs mean Macs save hundreds of dollars per seat in comparison to PCs over just three years, while Cisco has reported significant cost savings

So, what should IT purchasers do?

Waiting for prices to stabilize isn’t a strategy. All the analyses show there will be no change for some time. Seeking some resilience, purchasers are seeking multi-year leasing agreements and bulk purchase deals even while vendors become more resistant to them.

Three-year replacement cycles are being extended, prompting purchasers to make better buying decisions in the first place, and canny buyers should already be auditing what roles need what kind of machine. Does every computer need to be AI-ready? Probably not, so it’s important not to over-spec the whole fleet. 

Many purchasers will likely be investing more in Macs as they seek to diversify vendor exposure, while total cost of ownership over time is becoming a far more significant concern than before. It really matters that Macs are cheaper to run over time than PCs, particularly when costs have become so unpredictable. The same logic applies to tablets and smartphones, too.

None of these steps take the problem away. But sensible decision making now could help manage what is likely to be a highly uncertain period in IT purchasing, reiterating the need for resilience, so anticipated price shocks don’t blow your budgets apart.

You can follow me on social media! Join me on BlueSky,  LinkedInMastodon and subscribe to The Core.

Kategorie: Hacking & Security

Wesco confirms security incident after ExfilSquad claims data theft

Bleeping Computer - 11 Srpen, 2026 - 17:59
Global supply chain and distribution giant Wesco has confirmed in a statement for BleepingComputer that it is investigating a cybersecurity incident. [...]
Kategorie: Hacking & Security

Two wars and a World Cup lead to epic DDoS attacks on publishers

The Register - Anti-Virus - 11 Srpen, 2026 - 17:33
Ongoing wars in Ukraine and Iran and the FIFA World Cup all contributed to a DDoS walloping of media organizations throughout 2026 so far, according to Cloudflare’s latest data, which identified the sector as the most targeted this year. Attacks on media, production, and publishing accounted for 14.2 percent of all DDoS attacks launched since January 1. Over the first six months of the year, the sector saw nearly four times the number of attacks leveled at the second most-targeted sector, gambling and casinos, and six times more in Q2 alone. “DDoS attacks on media organisations can be highly effective at achieving their core goals, which differ fundamentally from attacks on other sectors," Blake Darché, Head of Cloudforce One and Threat Intelligence at Cloudflare, told The Register. "For publishers, availability is the deliverable. While a DDoS attack on an e-commerce site could aim to steal transaction revenue, an attack on a publisher is typically aimed at censorship, information suppression or timing disruption. “DDoS attacks are uniquely effective against publishers because news expires quickly - taking an outlet offline for just two hours during an election night, a military conflict, or a breaking news story successfully silences it at peak readership. The attack succeeds even if systems recover shortly after.” Cloudflare's data aligns with third-party reporting shortly after the US started a war with Iran in February. Akamai reported a 245 percent uplift in cybercrime in the immediate weeks following the war breaking out, with DDoS attacks up 38 percent. Similarly, Justin Moore, senior manager at Palo Alto Networks' Unit 42, previously told The Register that by the start of March, the company’s telemetry showed a clear increase in pro-Russia hacktivism too. Hacktivists rely heavily on DDoS attacks to carry out their objectives. Often assembled on social media platforms, hacktivist groups decide on which organizations they will attempt to down and launch coordinated attacks against them. Signals intelligence agencies say these efforts are almost always low-level and low-impact, but equally advise that businesses should not underestimate these groups. The advice applies largely to operators of critical infrastructure, which if attacked successfully and for a sustained period, could lead to vital service disruption. The US’ war in Iran also led to a major uptick in attacks targeting government entities. From the 29th most-targeted sector in Q1, it jumped to number nine in Q2. The US and China comprised the two most-targeted regions, although Turkey shot up to third after it hosted the Ankara NATO summit in July. 1 Tbps network-layer attacks explode Cloudflare said it mitigated 805 network-layer attacks exceeding 1 Tbps in Q2 alone, representing a 519 percent increase compared to Q1. To quickly debunk some jargon for the uninitiated, network-layer attacks are confined to layer 3 of the Open Systems Interconnection (OSI) model, meaning that they target core routing, transport, and infrastructure protocols to overwhelm networking equipment. Not all 1 Tbps+ attacks target the network layer. These high-packet onslaughts are referred to as hyper-volumetric DDoS attacks and involve transmitting a huge amount of data to a network – enough to take down even the most robust internet infrastructure. Despite the growth in these hyper-volumetric attacks, these comprise only the smallest fraction of DDoS attacks overall (0.004 percent). The vast majority – 96.62 percent – transmit less than 500 Mbps and 90.6 percent end in under ten minutes. That isn’t to say that these attacks are inconsequential, either. Cloudflare said that even attacks of this size would be enough to knock most networks offline. Putting it into perspective, the company said a 100 Mbps attack would be sufficient to knock a website or server offline, while a 1 Gbps attack could disrupt an entire datacenter if it wasn’t protected from DDoS attacks. 1 Tbps hyper-volumetric attacks are among the fastest ever observed. The first of this kind on record targeted Dyn DNS in 2016, in turn downing major websites such as Twitter, Netflix, Reddit, Spotify, and GitHub, and they have become increasingly common since then, despite their markedly low proportion compared to other DDoS attacks. A law enforcement operation in March disrupted the infrastructure relied upon by four of the most significant botnets operating at the time, including Aisuru, which by the end of 2025 had recruited up to 4 million devices and was rattling out multiple 1 Tbps attacks daily. Hyper-volumetric attacks are often short-lived, measured in seconds rather than greater units, although Cloudflare said even this is enough to cause significant damage. “Whether an attack lasts half a minute or ten minutes, there is no practical window for human intervention: By the time an alert reaches a security analyst, the attack has already completed,” said Cloudflare in its report. “Manual mitigation and on-demand solutions are simply too slow for this reality. Yet while the attack itself may be brief, its aftershocks are not. The cascading effects of even a short burst can trigger routing instability, TCP retransmissions, application timeouts, and downstream service degradation that takes hours or days to fully resolve – all while services remain down or impaired.” ®
Kategorie: Viry a Červi

Levnější předplatné YouTube Premium Lite míří do Česka. Zbaví vás reklam, ale jen někde

Živě.cz - 11 Srpen, 2026 - 16:45
YouTube Premium Lite zamíří všude, kde je normální Premium. • U nás by levnější tarif mohl stát něco přes sto korun za měsíc. • Lite odstraňuje reklamy u všech nehudebních videí, ale má i určitá omezení.
Kategorie: IT News

Million-Person Study Finds a Rare Gene Variant That Slashes the Risk of Diabetes and Heart Disease

Singularity HUB - 11 Srpen, 2026 - 16:00

The discovery could lead to treatments and demonstrates the power of efforts to unearth rare, beneficial genes in large populations.

“Burn fat, build muscle.” It’s a familiar workout slogan, but the benefits go far beyond aesthetics. Having less belly fat and more muscle guards against heart attacks, Type 2 diabetes, and a host of other metabolic diseases.

Some people may have a genetic edge.

A massive study of over one million people across three continents discovered a rare mutation in a gene called FNIP1 is linked to a healthier metabolic profile. The gene helps cells sense nutrients and generate energy. All of us have FNIP1, but about one in 7,000 people inherit a protective version. On average, they had a 60 percent lower risk of heart disease and metabolic disorders.

Silencing FNIP1 in human liver cells switched on a genetic program that breaks down fats. In mice fed a tasty but high-fat diet, disabling the gene curbed weight gain, prevented fatty liver disease, improved insulin sensitivity, and kept their blood sugar levels steady.

The findings are great news for everyone else. Rather than relying on a naturally occurring mutation, future gene editing therapies could potentially recreate its protective effects in people against a host of cardiometabolic diseases, a leading cause of death worldwide.

Everyone has a unique metabolic profile shaped by both genes and environment. By analyzing diverse populations, the study fished out a protective variant that spans ancestries and lifestyles. The broad reach suggests targeting FNIP1 could benefit people around the world.

The study illustrates the power of efforts to find rare, beneficial genes across large populations, wrote the authors at Regeneron Pharmaceuticals, a New York biotechnology company.

Mutant Protector

Small changes in DNA can have large consequences. Some genetic variants raise the risk for health issues. The APOE4 variant, for example, increases the chances of developing Alzheimer’s disease. Others, however, are a gold mine for new treatments.

A notable example is CCR5. People who inherit a rare mutation in both copies of thegene are naturally resistant to HIV. The mutation prevents the virus from tunneling into immune cells and replicating. The discovery has led to multiple success stories in which bone marrow transplants from donors carrying the mutation kept HIV at bay, without the need for lifelong antiviral drugs.

Protective mutations could also lower the risk of heart disease. Rare variants of PCSK9, a gene involved in cholesterol metabolism, disable the gene and slash dangerously high levels of LDL, or “bad” cholesterol that clogs arteries. The discovery has already spurred a handful of therapies that block the gene or its protein with early successes.

“Identifying genetic variants associated with protection from disease is a powerful strategy,” wrote the authors. “However, protective genetic variants are often extremely rare, so finding them requires sequencing the genomes of large populations.”

Go Big

To better understand cardiometabolic diseases, the team sequenced the genomes of over a million people from 11 studies across the Americas, Europe, and Asia, including people with African ancestry. They also linked genetic data with participants’ health records.

The researchers searched for gene variants that influence a blood biomarker for cardiometabolic disease. Called TG:HDL, the biomarker is the ratio between two types of fats. The first, triglycerides, is packaged into tiny “bubbles” that circulate the bloodstream. High levels are linked to heart attacks, strokes, and other metabolic problems. In contrast, high-density lipoprotein, often called “good” cholesterol, ferries excess fat away from tissues and blood vessel walls to the liver, where it can be cleared.

Across the populations in the study, a lower TG:HDL ratio—that is less TG, more HDL, or both—tracked with better metabolic health. People with lower ratios had reduced insulin levels, lower blood pressure, and less fat buildup in the liver and muscles. The biomarker also predicted diabetes risk, heart problems, and liver scarring, making it a powerful snapshot of overall metabolic health.

The team then scanned the genome for rare gene variants linked to TG:HDL. Roughly 60 genes popped up, all involved in energy storage and active in the liver and fat tissues.

But one gene stood out: FNIP1. Rare variants essentially disable the gene by disrupting its protein-making instructions. People with one copy of these variants had lower liver fat and blood sugar and roughly 60 percent lower risk of cardiometabolic disease.

The finding “was remarkable and thought-provoking, and immediately motivated us to dig deeper into the biology of this discovery,” wrote the team. But a key question remained: Were the variants actually protecting people, or were they simply correlated with better health?

To find out, the team silenced the gene in human liver cells using a method called siRNA. Rather than snipping the gene, siRNA blocks cells from producing targeted proteins. Without functional FNIP1, liver cells ramped up genes involved in breaking down fats.

The researchers then turned to mice. Using CRISPR-Cas9, they got rid of FNIP1 and related signaling pathways specifically in mice fed a high-fat, high-sugar diet. The intervention rapidly activated mitochondria—the cell’s energy factories—and lysosomes, the acid-filled recycling centers that break down waste. Despite gorging on the unhealthy diet, mice lacking functional FNIP1 had less body and liver fat, more muscle mass, and better sensitivity to insulin.

That’s not to say FNIP1 is a “villain” gene. Normally, it acts as a metabolic brake, helping the body conserve precious energy when food is scarce. But many of us now face the opposite problem, an abundance of calories and not enough physical activity. Releasing that brake, through medication or gene editing, could rev up the body’s natural fat-burning machinery.

Turning the finding into a therapy won’t be simple. The protective effects were found in people who carried the mutation from birth. A short-term drug or gene therapy delivered later in life might not reproduce the same effects.

Safety is another major concern. Paradoxically, people who have mutations in both copies of FNIP1 develop heart disease and immune deficiency. And mice without functional FNIP1 throughout the body are more prone to liver damage and cancer. Targeting treatments specifically to the liver—for example, using lipid nanoparticles—could limit side effects, but any potential therapy will need to be thoroughly tested for safety.

The team is searching for drug candidates that inhibit FNIP1. But for now, they’ve shown the power of large-scale genetic screens across diverse populations to find rare protective variants—and potential paths towards treating diseases that affect millions of people.

“Identifying FNIP1, a previously poorly characterized gene involved in lipid metabolism, is highly novel and promising for future drug development for metabolic health,” Satoshi Koyama at the Broad Institute, who was not involved in the study, said in a research briefing. “I sincerely hope that this discovery will one day benefit patients with metabolic disorders.”

The post Million-Person Study Finds a Rare Gene Variant That Slashes the Risk of Diabetes and Heart Disease appeared first on SingularityHub.

Kategorie: Transhumanismus

Jak nastupovat do letadla rychle a bez tlačenic. Řešení existuje 18 let, aerolinky ho nepoužívají

Živě.cz - 11 Srpen, 2026 - 15:45
Fyzik spočítal matematicky nejrychlejší způsob nastupování cestujících do letadla. • Tato metoda usazuje pasažéry postupně od oken po uličky ob jednu řadu. • Letecké společnosti tento postup nepoužívají kvůli lidské neukázněnosti a ziskům.
Kategorie: IT News

Public SCTPhantom Exploit Tests Linux Container Security Defaults

LinuxSecurity.com - 11 Srpen, 2026 - 15:30
Public exploit code is now available for SCTPhantom, a Linux kernel flaw that researchers used to escape an unprivileged container and take control of the underlying host. 
Kategorie: Hacking & Security

Mozilla updates GPG signing key for Firefox releases after exposure

Bleeping Computer - 11 Srpen, 2026 - 15:20
Mozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub. [...]
Kategorie: Hacking & Security

Vague Task, Total Access: When AI Delegation Becomes a Security Risk

Bleeping Computer - 11 Srpen, 2026 - 15:15
AI agents can improvise beyond the intended scope of a task when they are given broad access to enterprise systems and data. Token Security explains why organizations need to define agent intent and continuously enforce permissions around what each agent was actually created to do. [...]
Kategorie: Hacking & Security

OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development

The Hacker News - 11 Srpen, 2026 - 15:11
OpenAI on Monday unveiled a new cybersecurity-focused model called GPT‑5.6‑Cyber that it said is focused on vulnerability research, penetration testing, and incident response. "Built on GPT‑5.6 Sol, it is trained to improve capabilities on several specialized cybersecurity tasks (e.g., finding zero-day vulnerabilities and developing exploit chains) and to reduce refusals for certain higher-risk
Kategorie: Hacking & Security

OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development

The Hacker News - 11 Srpen, 2026 - 15:11
OpenAI on Monday unveiled a new cybersecurity-focused model called GPT‑5.6‑Cyber that it said is focused on vulnerability research, penetration testing, and incident response. "Built on GPT‑5.6 Sol, it is trained to improve capabilities on several specialized cybersecurity tasks (e.g., finding zero-day vulnerabilities and developing exploit chains) and to reduce refusals for certain higher-riskRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

DDoS attacks over 1 Tbps surged fivefold in the second quarter

Bleeping Computer - 11 Srpen, 2026 - 15:00
Cloudflare says it mitigated more than 800 network-layer distributed denial-of-service (DDoS) attacks exceeding 1 Tbps in the second quarter of the year. [...]
Kategorie: Hacking & Security

Drony britského námořnictva tajně posílaly data do Číny

AbcLinuxu [zprávičky] - 11 Srpen, 2026 - 14:46
Námořní drony používané elitními jednotkami britského královského námořnictva tajně posílaly údaje do Číny. Stroje vybavené čínskými komponenty měly být využívány pro vojenské operace na Blízkém východě. Kamery na dálkově řízených průzkumných člunech K3 Scout byly vybavené součástkami, které bez vědomí britského námořnictva odesílaly informace do spojeného zařízení v Číně. Britské námořní síly využívaly flotilu námořních dronů za 12 milionů liber (336 milionů korun). Po zjištění informací o propojení s Čínou nechalo ministerstvo obrany z kamer využívaných čluny odstranit veškeré spojení s internetem.
Kategorie: GNU/Linux & BSD
Syndikovat obsah