Agregátor RSS

Advantest confirms personal information stolen in ransomware attack

Bleeping Computer - 7 Říjen, 2026 - 12:27
Advantest Corporation is notifying affected individuals that a ransomware attack earlier this year exposed their personally identifiable data. [...]
Kategorie: Hacking & Security

Lockheed Martin ukázal maketu autonomního wingmana Vectis. Měří dobrých deset metrů a startuje už příští rok

Živě.cz - 7 Říjen, 2026 - 11:45
Lockheed Martin představil maketu nového autonomního bojového letounu Vectis a současně oznámil rozšíření výroby vývojových prototypů. Namísto původně plánovaného jediného stroje jich bude celkem pět. Zbrojovka poprvé stručně odtajnila dron už v roce 2025, od té doby ale internetem kolovalo jen ...
Kategorie: IT News

Garmin Enduro 4 jsou odlehčené solární Fénixy pro vytrvalce. Ušetříte sedm tisíc a získáte ještě delší výdrž

Živě.cz - 7 Říjen, 2026 - 11:15
Garmin Enduro 4 se inspirovaly solárními Fénix 9, ale ubraly na hmotnosti • Vydrží navíc déle nabité a nechybí jim ani svítilna • Největším ústupkem je chybějící mikrofon, reproduktor a některé lifestylové funkce
Kategorie: IT News

Chytrá váha české značky Salente zlevnila na 311 Kč. Měří 15 parametrů a nevyžaduje cloud

Živě.cz - 7 Říjen, 2026 - 10:45
Chytrá váha české značky Salente SlimFit zlevnila na 311 Kč. • Měří 15 parametrů a data pošle do mobilu i bez cloudu. • Údaje umí synchronizovat s ekosystémy Apple Zdraví a Google Health Connect.
Kategorie: IT News

Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws

The Hacker News - 7 Říjen, 2026 - 10:07
Anthropic on Tuesday said it's expanding a program that allows vetted cybersecurity professionals to test its advanced artificial intelligence (AI) models with reduced safeguards and blocking classifiers, as the company claimed its Project Glasswing initiative uncovered at least 129,000 verified software vulnerabilities between April and July 2026. The company said it also found an additional Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Rusko vyvinulo vlastní systém pro 130nm výrobu na 200mm waferech

CD-R server - 7 Říjen, 2026 - 10:00
Ruská polovodičová výroba se posouvá. Společnosti ZNTC se podařilo vyvinout fotolitografický systém, který je určený až pro výrobu na 130nm technologii. Tím se snižuje náskok TSMC na zhruba 25 let…
Kategorie: IT News

100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer

The Hacker News - 7 Říjen, 2026 - 08:57
The Computer Emergency Response Team of Ukraine (CERT-UA) has identified more than 100 compromised websites that have been injected with malicious JavaScript to serve an information-stealing malware called LunexStealer (aka Psychedelic Stealer). The activity, which was observed by the agency in September 2026, has been attributed to a threat cluster dubbed UAC-0277. It did not disclose who the Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Umělá inteligence ničí tradiční IT firmy. V Praze a na Slovensku se peče jednorožec, který toho chce využít

Živě.cz - 7 Říjen, 2026 - 08:45
Americký fond Eldridge koupil polovinu IT firmy Sudolabs a cílí s ní během pár let na status jednorožce • . • Sudolabs dřív prodával hodiny vývojářů, dnes nasazuje AI u velkých firem, kde tradiční model chřadne. • Tržby firmy meziročně rostou o 60 až 70 procent, v tendrech teď spíš naráží na ...
Kategorie: IT News

Výroba humanoidního robota Tesla Optimus naráží na potíže. Drobné kosti musí montovat pomalý člověk

Živě.cz - 7 Říjen, 2026 - 07:45
Tesla zrychluje produkci robota Optimus navzdory mnoha komplikacím • Ruční montáž stovek součástek v dlaních výrazně zpomaluje výrobu • Řídicí software i dodávky klíčových dílů ze zahraničí stále selhávají
Kategorie: IT News

Epyc Verano bude mít socket SB1, tvrdí Dynatron

CD-R server - 7 Říjen, 2026 - 07:40
Nyní AMD uvedla Epyc Venice, na příští rok chystá půlgenerační rozšíření nabídky o Zen 6 Epyc Verano. Bude něčím jiným, úsporným řešením s podporou LPDDR5X v SOCAMM2 modulech. Přinese nový socket SB1…
Kategorie: IT News

South Korean president calls for creation of tools that stop all cyber-attacks

The Register - Anti-Virus - 7 Říjen, 2026 - 05:56
South Korean president Lee Jae Myung has told the nation’s cabinet that it’s time to develop AI-powered defensive tools to combat AI-wielding attackers. “Recently, a series of personal information leak incidents have been occurring at financial and public institutions,” he said yesterday – likely referring to incidents like the breach at e-tailer Coupang and last week’s raid on local banks that exposed customer data. “Circumstances indicate that artificial intelligence was utilized, causing great concern and anxiety among the public,” he claimed. “I request that the relevant authorities swiftly and clearly identify the circumstances of these incidents, and rapidly deploy and concentrate the necessary personnel and resources to minimize damage,” he added, before calling for South Korea’s government to “build security capabilities that can detect attacks in advance and preemptively block them.” “I urge the relevant ministries to quickly inspect the security systems across the entire national core infrastructure, as well as the private sector, and immediately implement any necessary security measures,” he continued. “I hope we can accelerate the development and distribution of AI technologies specifically tailored for cybersecurity.” President Lee thinks South Korea needs to “completely innovate our society's security paradigm to fit the AI era.” That work will involve public and private sector players collaborating “to transform our technology, systems, and awareness.” The remarks amount to a major policy statement, and a very public one at that. South Korean ministers and tech giants now get to turn the president’s words into action, a complex task given the broad scope of the leader’s demands and the fact that nobody thinks it's possible to defeat cybercrime. Meanwhile, Down Under Also yesterday, Australian politicians had their chance to grill OpenAI Chief Strategy Officer Jason Kwon, who fronted a parliamentary committee to answer questions about how his company’s agents accessed a government medical records website. Kwon allowed that OpenAI should have done better than emailing the abuse reporting email address at the relevant Australian government agency but defended the company’s efforts to learn from the Hugging Face incident. The committee is sitting for another two days this week, with one topic of debate being how or if Australia should tweak its copyright laws to ensure AI companies pay content creators whose works they use when training their models. Australian law doesn’t include a fair use provision like those that AI companies in the USA relied on when sourcing content. Creators fear a rumored opt-in payments scheme will be too weak, but Australia’s government fears it may miss out on big datacenter investments and access to onshore frontier models if it doesn’t change copyright law to make it more AI-friendly. ®
Kategorie: Viry a Červi

Open-weight model Beam od Reflection AI

AbcLinuxu [zprávičky] - 7 Říjen, 2026 - 04:07
Americká společnost Reflection AI světu představila Beam, open-weight model s 501 miliardami parametrů (z toho 23 miliard aktivních), určený především pro programování a práci autonomních agentů. Podle autorů jejich model nabízí výkon srovnatelný s většími modely při výrazně nižších nárocích na výpočetní výkon. Beam nyní ještě prochází závěrečným testováním, na stránkách Reflection AI se však lze zaregistrovat a získat předběžný přístup. Váhy modelu, dokumentace a nástroje pro vývojáře mají být zveřejněny v průběhu tohoto měsíce.
Kategorie: GNU/Linux & BSD

Atlassian’s critical flaw turns eight enterprise products into one big security problem

Computerworld.com [Hacking News] - 7 Říjen, 2026 - 03:58

A newly-disclosed critical flaw in Atlassian’s data center software has a remarkably wide reach, affecting eight core products across the company’s enterprise portfolio.

CVE-2026-21589, rated 9.3 (critical) in severity, is an arbitrary file access vulnerability that could allow an attacker with no login access to read files in web app root directories that they should not otherwise see, and potentially use them for nefarious purposes.

The impacted products require “immediate attention,” Atlassian said in a security advisory. Customers should patch to the latest fixed versions. The company said it has not yet found evidence of exploitation in its cloud offerings, which are already patched.

What is particularly concerning about this vulnerability is that it doesn’t require authentication or user interaction, and it impacts a broad set of Atlassian products that many organizations rely on for development, collaboration, and IT operations.

“On the surface, arbitrary file access might not sound as serious as remote code execution, but the real issue is what an attacker could potentially get access to,” said Erik Avakian, technical counselor at Info-Tech Research Group. “The business risk isn’t simply someone reading a file; it’s what that information could potentially allow them to do next.”

Patch now or isolate exposed instances.

The arbitrary file access vulnerability is present in all versions of Bamboo Data Center, Bitbucket Data Center, Confluence Data Center, Crowd Data Center, Crucible, Fisheye, Jira Service Management Data Center, and Jira Software Data Center.

It allows unauthenticated attackers to access the web application root directory, the base folder on a web server that contains its core structure and required files. In some configurations, there may be sensitive files present that increase risk.

“If sensitive files are present in that location, the information exposed could potentially help enable a much broader attack,” Info-Tech’s Avakian explained.

Using path traversal techniques, attackers could potentially access restricted files and directories outside the web root folder, Atlassian said. One mitigating circumstance: The attacker must already know a file’s exact name and path, and cannot do a directory listing.

For those who can’t patch right away, the company advised removing affected instances from the internet and restricting internet-accessible instances from external network access. This includes instances that require authentication. This is because “a login page does nothing against an unauthenticated flaw,” Dickson noted.

Atlassian outlined three temporary mitigations to block attackers:

Customers using any of the eight listed products could apply a rule on a Web Application Firewall (WAF) or proxy layer.

Another option is blocking requests using a Tomcat RewriteValve rule on each node in their data center cluster for Bamboo, Confluence, Crowd, Jira Software, and Jira Service Management. Each node should then be shut down and restarted. And Bitbucket users could back up their instances, write a rule in urlrewrite.xml, apply it to every node, mirror, and mirror farm node, and then restart.

But Atlassian called the mitigations “limited and not a replacement for patching your instance,” adding that it cannot confirm whether a particular enterprise’s instances have been affected by this vulnerability. “Engage your local security team to check all affected instances for evidence of compromise,” the company advised.

“The vendor cannot tell you whether you were visited. Only your logs can,” Dickson observed.

Files that could unlock sensitive secrets

The list of impacted products is particularly notable, Dickson pointed out: Bamboo builds and ships software. Bitbucket holds source code. Crowd manages identity and single sign-on. Jira and Confluence hold the company’s plans, service desk tickets, and documentation.

“These are the keys to the kingdom,” he said. “Attackers know it.” And to access them, they need no login, no user click, and no special conditions.

The patch path explains why some customer updating lags; Atlassian no longer ships binary patches, so fixing this means moving to a new maintenance release, he pointed out. That is an upgrade project rather than a quick fix, and every “we cannot update yet” is a risk acceptance.

But the most telling detail may be the flaw’s scoring vector, Dickson noted. It is rated as having no impact on the vulnerable server’s own integrity and availability, but assesses high impact on subsequent systems across confidentiality, integrity, and availability. In other words, the Jira or Confluence server survives untouched, but the systems its files unlock may not.

Essentially, “it is a burglar who takes nothing but the key ring by the front door,” Dickson said.

Exploitation requires a target file’s exact name and path, is limited to the web application root, and cannot do directory listings. “That sounds like a high bar,” he said. But “it is lower than it looks.”

Anyone can download these products and learn exactly where files live, he pointed out, and attackers also have the installation guide.

Additionally, configurations containing sensitive files increase an enterprise’s risk. “After years in production, a web root may collect configuration files, backups, and credentials nobody remembers putting there,” Dickson noted. “One readable secret becomes the first step in a much larger attack.”

Bottom line: The flaw “only” reads files, but the files it reads may open everything else, he said. “Patch, and if you cannot patch today, unplug it from the internet today.” Then, he advised, filter, search access logs for the published traversal pattern, and decode each line. If you find hits, assume the file was read. From there, rotate every credential, token, and key that could have lived in the web root.

Going forward, enterprises should focus on reducing their external exposure as much as possible and restrict access using VPNs, trusted networks, segmentation, or other controls, Info-Tech’s Avakian advised. Rotate sensitive credentials or secrets if exposure is suspected.

However, he noted: “These are compensating controls and they can certainly buy you time, but they shouldn’t be viewed as a replacement for getting to a tested and validated fixed version.”

This article originally appeared on CSOonline.

Kategorie: Hacking & Security

OpenCourant, komunitní fork OpenRadioss

AbcLinuxu [zprávičky] - 7 Říjen, 2026 - 02:08
OpenCourant je komunitní fork OpenRadioss, tj. open source softwaru pro simulace havárií, nárazů a vysoce nelineárních dynamických dějů metodou konečných prvků. Společnost Siemens v loňském roce dokončila akvizici společnosti Altair Engineering, jež před čtyřmi lety uvolnila open source verzi OpenRadioss svého proprietárního softwaru Radioss. Minulý týden Siemens OpenRadioss pohřbil. Integroval jej do svého softwaru Simcenter, webovou stránku OpenRadioss přesměroval na Simcenter a repozitář OpenRadioss na GitHubu odstranil.
Kategorie: GNU/Linux & BSD

Anthropic reconfigures its cool kids security program

The Register - Anti-Virus - 7 Říjen, 2026 - 01:29
Only a week after warning about the perils of competitor Z.ai's GLM-5.3 model and its advanced cybersecurity capabilities, Anthropic has expanded its Cyber Verification Program (CVP) – or rather, reconfigured it. "For the past six months, we’ve enabled trusted access through two programs: Project Glasswing and the CVP," the AI biz said. "Now, we’re integrating these programs into one expanded offering, designed to give more security organizations access to the capabilities they need to protect their systems." Project Glasswing and CVP launched in April 2026 alongside the debut of Mythos, the company's highly capable and equally hyped frontier model. Project Glasswing gave partners early access to Mythos so they could scour their systems for vulnerabilities before attackers beat them to it. VulnCheck researcher Patrick Garrity was not particularly impressed with CVEs identified by Project Glasswing, noting that fewer than 0.5 percent of the 225 Anthropic-linked vulnerabilities he tracked were being exploited in the wild. And Anthropic's own warning last month about the risks posed by GLM-5.3 somewhat undermines the idea that there's anything special about its own Mythos model. Even so, Anthropic says that its security program has allowed its partners to spot at least 129,000 verified software vulnerabilities between April and July 2026. And the biz claims that its own open source scanning efforts revealed an additional 5,500 verified vulnerabilities between April and October. "Of these verified vulnerabilities, more than 33,000 have so far been rated as critical- or high-severity," Anthropic said. "This is likely an undercount, as it is based on survey data from only a subset of Glasswing partners. As such, we expect the true impact to be at least five times higher." When these might get patched is unclear. The company's own figures indicate that of 5,674 true positive vulnerabilities, 3,014 are high severity, and 1,522 are critical severity, yet only 516 have been patched. Given industry boasting about the cybersecurity prowess of AI models, generating a fix, testing it, and deploying it ought to be nearly automatic at this point. But the gap between identification and remediation suggests there's a lot of slack in the system that needs to be ironed out. Two programs into one with three tiers Now Anthropic's two programs, one intended for organizations and one for individual security professionals, have been merged and reconfigured into three tiers. The AI biz has not explained why, but its stated intent is to tie model capabilities to specific tasks: Defense Access, Red Team Access, and Specialized Access. Depending on the tier, participants will encounter more or fewer blocks on security-related tasks. As a measure of program participation value, Anthropic said that based on five attempts at 10 CyScenarioBench challenges, those without CVP access got blocked on every attempt. Defense Access is intended for security teams at companies, nonprofits, universities, and government organizations that focus on system defense. In this tier, Claude Opus 5.5 faced refusals in 46 of 50 attempts and succeeded four times. Red Team Access is for penetration testing and offensive cyber evaluation, and participants will still face model refusals for model interactions that would cause physical harm or mass disruption. Specifically, Claude Opus 5.5 completed 34 of the 50 tasks with Red Team Access safeguards enabled, a rate similar to what would be expected from Specialized Access. Specialized Access sounds like a rebranding of Glasswing – it's "reserved for a limited set of verified organizations that are authorized to test safety systems that could impact people’s lives or disrupt markets, such as flight operating systems, power grids, telecom networks, interbank transfer infrastructure, and government administrative networks." Those granted admission to this exclusive tier will face the fewest model refusals, not counting anyone using abliterated open-weight models that have had their guardrails suppressed. For the next month or two, program participants will need to allow their data to be retained by Anthropic as part of its AI safety requirements. But soonish, the company's Enterprise Frontier Safeguards program will offer zero data retention. Organizations already granted zero data retention while using Claude Fable 5.1 or Claude Mythos 5.1 can participate in CVP under those same terms.®
Kategorie: Viry a Červi

Organizátoři síťařského setkání CSNOG 2027 vyhlásili Call for Abstracts

AbcLinuxu [zprávičky] - 7 Říjen, 2026 - 00:22
Pořadatelé devátého ročníku komunitního setkání správců nejen českých a slovenských sítí – CSNOG 2027, které se uskuteční 20. a 21. ledna, vyhlásili Call for Abstracts. Náměty na vystoupení mohou zájemci přihlašovat do 31. října na webu akce a vybírat mohou ze tří sekcí – správa sítí, legislativa a regulace a akademické projekty. Zveřejněny byly také Call of Partners určené sponzorům a partnerům setkání, kteří by například chtěli mít na CSNOG 2027 svůj stánek. Cílem tradičního setkání komunity CSNOG je umožnit vzájemnou výměnu zkušeností, diskuzi nad aktuálními tématy a sdílení řešení vedoucích k rozvoji internetových sítí v Česku a na Slovensku. Akci organizují sdružení CESNET, CZ.NIC a NIX.CZ.
Kategorie: GNU/Linux & BSD

Spoření v eurech: Jedna banka dá 0,01 %, jiná přes 2 %. Srovnali jsme aktuální nabídky

Lupa.cz - články - 7 Říjen, 2026 - 00:00
Eurové spořicí účty nabízí v Česku jen osm bank. Úročení se pohybuje od symbolických 0,01 % až po více než 2 % ročně. Wise a Revolut nabízejí ještě vyšší výnos, tam už ale nejde o klasické spoření, nýbrž o investování.
Kategorie: IT News
Syndikovat obsah