Agregátor RSS

Týden na ScienceMag.cz: Poprvé zjistili vysoký stupeň kvantového provázání v centimetrovém krystalu

AbcLinuxu [články] - 10 Červenec, 2026 - 00:01

K nejstaršímu známému dopadu asteroidu na Zemi došlo před 3 miliardami let. Zřejmě objevili nový zdroj neutrin. Buckyball připravili i z 80 atomů boru.

Kategorie: GNU/Linux & BSD

Usmíření po vydědění nestačí. Dědictví vrátí jen formální zrušení

Lupa.cz - články - 10 Červenec, 2026 - 00:00
Otec dceru vydědil kvůli dlouhodobému nezájmu. Později se jejich vztahy zlepšily, dcera se s ním začala znovu stýkat a po jeho smrti chtěla povinný díl z dědictví. Nejvyšší soud ale potvrdil, že samotné odpuštění ani obnovení kontaktu nestačí. Vydědění musí zůstavitel zrušit zákonem předepsaným způsobem.
Kategorie: IT News

MSI validovala DDR5-8000+ od čínské CXMT pro AMD / AM5 platformu

CD-R server - 10 Červenec, 2026 - 00:00
Je tomu jen lehce přes půl roku, co CXMT ukázala první vlastní DDR5-8000 čipy. Nyní již existují jako komerčně dostupné moduly a získaly validaci společnosti MSI na jejích AM5 deskách…
Kategorie: IT News

Železný prášek je černým koněm zelené energetiky

OSEL.cz - 10 Červenec, 2026 - 00:00
Spálením železného prášku vznikne teplo a oxid železa. Zelený vodík z obnovitelných zdrojů energie pak zase může odstranit kyslík a přeměnit "rez" zpátky na čisté železo. Železo má přitom oproti vodíku ohromnou výhodu v tom, že ho lze úžasně snadno převážet a skladovat. Železný prášek by se tak mohl stát klíčovým médiem obnovitelné energetiky.
Kategorie: Věda a technika

Linux 7.3 přinese barevné formáty pro AMDGPU i konec souborového systému, který v 21. století nejspíš nikdo nepoužil

ROOT.cz - 10 Červenec, 2026 - 00:00
Jádro Linux 7.3 už bez ovladače pro IBM pSeries eHEA 10Gbit/s, podpora pro mixážní pult Pioneer DJM-S11, konec souborového systému EFS, další omezení AF_ALG, DRM „Color Format“ v AMDGPU a možná i pro Intel a Rockchip.
Kategorie: GNU/Linux & BSD

Patch for Windows Defender 0-day could allow attackers to fill hard disk

Ars Technica - 9 Červenec, 2026 - 22:52

A patch Microsoft released on Wednesday to fix a zero-day vulnerability in its Defender security engine may cause Windows machines to write files large enough to completely consume available disk space, the researcher who discovered the flaw said.

RoguePlanet, tracked as CVE-2026-50656, came to public notice in June when NightmareEclipse, the pseudonymous name used by a researcher, disclosed it along with code for exploiting it. The vulnerability allows remote attackers to gain administrative control of Windows 10 and Windows 11 machines, even when real-time protection has been disabled. Over the past few months, the anonymous researcher has published a handful of other zero-days that have sent Microsoft scrambling to develop patches.

Writing files of unlimited size

Microsoft said Wednesday that it patched RoguePlanet with an update to the Microsoft Malware Protection Engine, which is used by the Defender antivirus app. The fix will automatically be downloaded and installed without users having to take any action. Wednesday’s update also includes “defense-in-depth updates to help improve security-related features.”

Read full article

Comments

Allstate accuses Broadcom of auditing it because it quit VMware, CA

Ars Technica - 9 Červenec, 2026 - 22:28

Allstate Insurance Company has accused Broadcom of haphazardly issuing audits against it because the insurance firm decided not to renew its contracts with VMware and CA Technologies.

The allegations were made in relation to a lawsuit that VMware filed against Allstate in December 2025, according to The Register. In the complaint, Broadcom alleges that Allstate failed to comply with license audits, which Broadcom claims its contract with Allstate requires.

In a June 12 filing, Allstate suggested that Broadcom issued the audits in response to Allstate deciding to end business with its companies. Allstate's statement reads:

Read full article

Comments

Injective SDK on npm infected with cryptocurrency wallet stealer

Bleeping Computer - 9 Červenec, 2026 - 22:10
Hackers compromised the Injective Labs SDK project's GitHub repository and used it to publish a malicious package on the Node Package Manager (npm) that stole cryptocurrency wallet private keys and mnemonic seed phrases. [...]
Kategorie: Hacking & Security

Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs

The Hacker News - 9 Červenec, 2026 - 20:38
Datadog Security Labs is warning of "several overlapping campaigns" that are systematically enumerating corporate GitHub organizations, repositories, and user accounts through the GitHub API. "Operators rely on automated scraping tooling with custom or legitimate-sounding user agents, leveraging GitHub 'ghost' accounts that are often years old, or compromised OAuth tokens and personal Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Nejlepší filmy o kung-fu a asijských bojových uměních. Létající kopance, údery jako blesk a nezapomenutelné legendy

Živě.cz - 9 Červenec, 2026 - 20:15
Kung-fu filmy patří mezi nejikoničtější a nejvlivnější akční žánry filmové historie. Od legendárních úderů Bruce Lee přes akrobatické kousky Jackieho Chana až po vizuálně ohromující moderní eposy typu Tygr a drak – nabídka je pestrá a nadčasová. Vybrali jsme nejlepší bojové filmy, které definovaly ...
Kategorie: IT News

New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware

The Hacker News - 9 Červenec, 2026 - 20:08
Microsoft has taken apart a destructive Windows backdoor it calls GigaWiper. What stands out is how it is built: not one tool but three older destructive programs bolted into one, offered as commands the operator can choose from. Each is a different way to break a machine: wipe the whole disk, overwrite the Windows drive, or run fake "ransomware" that scrambles files with a key it never savesSwati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Počítače zažily nejhorší krizi za poslední dva roky. V prodeji se dařilo jen Applu díky levnému MacBooku Neo

Živě.cz - 9 Červenec, 2026 - 19:45
Od začátku dubna do konce června se do obchodů dostalo 68,2 milionu počítačů, o necelých pět procent méně než před rokem. Podle analytiků z IDC jde o první pokles po devíti čtvrtletích. Ne však nečekaný, o krizi se vědělo dopředu. Kvůli rostoucím cenám operačních a úložných paměti totiž počítače ...
Kategorie: IT News

New Helix vishing group emerges in SharePoint data theft attacks

Bleeping Computer - 9 Červenec, 2026 - 19:08
A new data-extortion group called Helix is using identity-focused tactics such as voice phishing (vishing), device code phishing, and multi-factor authentication (MFA) abuse to steal data from SharePoint environments. [...]
Kategorie: Hacking & Security

Microsoft expects more Windows security updates from AI-discovered flaws

Bleeping Computer - 9 Červenec, 2026 - 19:00
Microsoft says Windows users should expect to see an increase in security updates as the company increasingly relies on artificial intelligence to discover vulnerabilities in its codebase. [...]
Kategorie: Hacking & Security

npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk

The Hacker News - 9 Červenec, 2026 - 18:49
GitHub has officially announced the release of npm version 12 with install scripts disabled by default, along with deprecating granular access tokens (GATs) designed to bypass two-factor authentication (2FA). The Microsoft-owned subsidiary noted that the following npm install behaviors that used to run automatically before have been made opt-in - allowScripts defaults to off, meaning Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Meta má vlastní generátor obrázků a je rovnou druhý nejlepší na světě. Takhle zvládá „našeho“ Ježíše ve Fabii

Živě.cz - 9 Červenec, 2026 - 18:45
Meta uvedla první vlastní generátor obrázků, zkusit jej můžete zdarma. • Ihned vylétl mezi světovou špičku, lepší je jen ChatGPT. • Brzy zamíří rovnou do Facebooku, Instagramu a WhatsAppu.
Kategorie: IT News

Apple finally calls time on 15-year-old device support

Computerworld.com [Hacking News] - 9 Červenec, 2026 - 18:15

For those who wonder what the support window is for Apple products, the company now has an answer: it’s quietly ended support for some of its oldest iPhones and iPads, cutting off restore access for devices that first went on sale more than a decade ago. 

While the move has prompted some complaints, the truth is that it underlines just how unusually long the company has kept aging hardware alive. Even today, it provides support in the form of access to signed software upgrades for non-cellular devices as old as some teenagers. 

What devices have been cut?

Among other things Apple has cut support for a range of older cellular-equipped devices, as it no longer supports the modems. Take the iPhone 4S, introduced about the same time iconic Apple CEO Steve Jobs died. Apple has stopped signing iOS versions for that device, which means if you’re still running one, you won’t be able to restore or downgrade to several older iOS versions on it. 

This isn’t the only older system for which Apple has stopped signing versions, but all these newly abandoned products are 12-years old, or older. Affected devices include the iPhone 4, iPhone 4S, iPhone 5, iPhone 5c, iPad 2, iPad 3, iPad 4 and the original iPad mini. In each case, if you have an iPad without a cellular modem you should still be able to reinstall OS software, but cellular devices are abandoned. They’ll continue to work; you just can’t reinstall the operating system in the event of a problem.

The specifics are telling. The cut affects iOS builds like 6.1.3, 8.4.1, 9.3.5/9.3.6 and 10.3.3/10.3.4 — versions tied to the original iPad 2, iPad mini and iPhone 5c. One of those, iOS 10.3.4, was actually a special one-off patch Apple pushed out just for the iPhone 5 to fix a GPS bug tied to the GPS week rollover, underlining just how much engineering effort Apple still throws at older devices.

Why it kind of matters at the same time

The move to cut support is unlikely to cause any significant problems, as only a tiny number of these devices will be in active use. Some developers might use old devices for compatibility testing, though, and by making this move Apple is obviously telling developers to constrain their legacy device support. It’s also a reasonable piece of housekeeping: maintaining signing servers for decade-old, security-patched builds isn’t free. (Apple frames these moves as closing off outdated software that could expose old vulnerabilities.)

How does this compare with others?

Apple has always had a good reputation for product support; in part, this is why its devices maintain such strong resale values over time. That commitment became more explicit in 2024 following UK regulation, after which it now guarantees at least five years of security updates. Around the same time, Google and most big Android device manufacturers went a little further, committing to seven years of security and operating system updates. 

Smaller manufacturers don’t always match this commitment; in some cases, you might find similar support for budget Androids can be as short as two years. It’s also worth considering the user experience when working with older Android devices. While Apple’s tight software and hardware integration tends to support high-value user experiences, the more fragmented nature of the Android manufacturing process means some devices don’t offer the same degree of usability when older. Pixel’s Tensor have drawn criticism for struggling to run smoothly as they age, even if they’re still technically supported.

What this means is that Apple continues to under promise and overdeliver on its support commitment to older devices — so much so that it’s only now some customers who might still be running a 15-year-old iPhone have finally hit the support wall. 

Join me on social media at BlueSky,  LinkedIn, or Mastodon,and do please subscribe to The Core for your daily collection of human-curated Apple News lovingly assembled by yours truly.

Kategorie: Hacking & Security

EU 'Chat Control' snoopfest returns after vote to kill it falls short

The Register - Anti-Virus - 9 Červenec, 2026 - 17:51
An effort by European parliamentarians to block the reintroduction of an interim rule allowing tech companies to scan chats for evidence of child sexual abuse failed today, despite securing more votes than the MEPs who want to keep it alive. Commonly referred to by critics as Chat Control, or Chat Control 1.0, the interim rule acts as a derogation from the ePrivacy Directive, allowing online communications platforms to voluntarily detect, report, and remove child sexual abuse material (CSAM). Chat Control expired on April 3, 2026, after first being introduced in August 2021. Today, however, MEPs did not reach the required threshold to prevent it from moving toward reintroduction. Although 314 politicians voted to scrap Chat Control, while 276 voted to keep it, the vote required 360 MEPs to reject the Council of the European Union's position. As a result, the attempt to abolish the interim rule failed, despite more voting MEPs opposing it than supporting it. A separate, but related vote, which sought to limit scanning to accounts belonging only to individuals identified by the judiciary, also failed to reach the necessary majority, effectively permitting the scanning of all accounts without a warrant. MEPs did manage to secure a majority for excluding end-to-end encrypted (E2EE) platforms from Chat Control's scanning provisions, although the practical effect of that change may be limited, since providers should not be able to inspect message contents in transit. What's left is essentially the same legislation as introduced in 2021 – Chat Control 1.0, but without legal permission to scan E2EE messages. The European Parliament's amended position will now be sent back to the Council of the European Union, which has three months to approve or reject the legislation. Chat Control could be reintroduced in the EU in that time frame. If the Council cannot accept all the amendments, a conciliation committee will be convened to reach a resolution. If approved, it will be valid until 2028, or until a permanent solution is passed. One of the movement's more outspoken campaigners, former MEP Patrick Breyer, called Chat Control a vehicle for "suspicionless mass surveillance," and said it serves as a smokescreen to delay real action against the spread of CSAM online. "The fact that Chat Control is moving forward against the will of the majority of voting MEPs is a farce and damages democracy," he said. "Our children are the real losers in this undemocratic process. The passage of a genuine, permanent child protection regulation is now in serious jeopardy. The Council will never agree to a desperately needed paradigm shift as long as they can simply stick to the old approach of suspicionless scanning at the whim of the tech industry." At the heart of the Chat Control debate is the long-running conflict between the public's right to privacy and law enforcement's need to access evidence that could help prosecute those who create, possess, or distribute CSAM. Chat Control 1.0 is the interim measure the EU introduced to give tech companies legal permission to voluntarily scan user chats for signs of child sexual abuse. Tech companies are not required to scan messages, but may do so if they wish. It was introduced under the assumption that the Child Sexual Abuse Regulation (CSAR), aka Chat Control 2.0, would not take so long to pass. The CSAR is intended as the EU's permanent framework for detecting and tackling online child sexual abuse. Unlike the interim measure, it would create lasting obligations for platforms to assess and mitigate the risk of their services being used to spread CSAM or facilitate grooming. The Council wants laws that preserve E2EE while allowing client-side scanning for harmful material. Many say those two goals cannot coexist. Client-side scanning remains highly controversial. While technically feasible, client-side scanning breaks the principle of fully encrypted communications without exposing message contents in transit. Those on the other side of the argument, such as lawmakers and law enforcement officials, argue it is the best balance on offer: preserving user privacy by keeping analysis on the device while allowing authorities to protect children from serious online harms. Privacy campaigners, however, say the same technology could be repurposed by governments as a mass surveillance tool. Signal has previously said that the same scanning mechanisms could theoretically be used to block certain communications, such as negative expressions related to the state. Chat Control 2.0, or the CSAR, is still being discussed in trilogue negotiations between the European Parliament, the Council, and member states. Five rounds of negotiations, including what was supposed to be the final round on June 29, have passed without agreement on the legislation's shape. ®
Kategorie: Viry a Červi
Syndikovat obsah