Agregátor RSS

Vzorky 52jádrového Intel Nova Lake nebudou distribuovány dříve než v prosinci

CD-R server - 6 Říjen, 2026 - 10:00
Zatímco vzorky procesorů Nova Lake s jednou procesorovou dlaždicí (až 28 jádry) kolují po světě přinejmenším od srpna, vzorky vybavené dvěma dlaždicemi poskytne Intel partnerům nejdříve v prosinci…
Kategorie: IT News

Recenze hry EA Sports FC 27. Zpomalení tempa fotbalu prospělo, větší změny se ale nekonají

Živě.cz - 6 Říjen, 2026 - 09:45
Další ročník fotbalu přináší žádané změny založené na žádostech komunity. FC 27 se ale stejně jako předchozí roky zdráhá udělat zásadnější změny, díky kterým by si oproti loňskému fotbalu ospravedlnilo plnou cenu.
Kategorie: IT News

Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

The Hacker News - 6 Říjen, 2026 - 08:58
A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory. The attacker must already know a file's exact name and path and cannot list what the directory holds. Atlassian disclosed the flaw, CVE-2026-21589, on October 5, rated it 9.3 out of 10, and Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach

The Hacker News - 6 Říjen, 2026 - 08:56
The U.S. Federal Bureau of Investigation (FBI) has removed an Accenture contractor for their alleged role in a ShinyHunters-breach that led to the theft of personal details of thousands of bureau employees. That's according to a report from Reuters, citing two sources familiar with the matter. "To date, our review has determined that the incident occurred as the result of a security failure ​Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

AI mění svět. Na ráně je hardware, elektrárny, trh práce i naše důvěra v realitu

Živě.cz - 6 Říjen, 2026 - 08:45
Počítače zdražují, internet zaplavuje tzv. AI slop a deepfake videa, jež už často ani nejdou rozeznat od reality, AI nahrazuje zaměstnance a ještě způsobuje finanční bublinu. Ale opravdu za to může AI a je vážně tak špatná?
Kategorie: IT News

Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account

The Hacker News - 6 Říjen, 2026 - 08:00
Unauthorized parties have gained access to the names, addresses, and personal identification numbers of about 8.8 million people, living and dead, in Denmark's national population register, the country's digitalization ministry said on October 5. They used a private Danish company's lawful right to look up records in the Central Person Register (CPR). The ministry has told people never toSwati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Němci postavili nejvyšší větrnou elektrárnu na světě. Překonala dokonce i Eiffelovu věž

Živě.cz - 6 Říjen, 2026 - 07:45
Nová rekordní německá větrná elektrárna měří úctyhodných 365 metrů • Silnější vítr ve výšce má zdvojnásobit celkovou roční výrobu elektřiny • Teleskopickou konstrukci zdvihali nitrem věže bez použití obřího jeřábu
Kategorie: IT News

Uživateli krátce po záruce odpadla část chladiče GeForce RTX 4090

CD-R server - 6 Říjen, 2026 - 07:40
Uživatel Maker_753 zjistil, že během stěhování PC z GeForce RTX 4090 odpadla část chladiče. Situace není moc vážná (oprava je zvládnutá uživatelsky), ale ukazuje, k čemu jsou kartě postranní pasivy…
Kategorie: IT News

ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits

The Hacker News - 6 Říjen, 2026 - 07:22
A new type of ClickFix attack is using compromised websites to trick users into executing a malicious payload cached in a web browser's cache. "Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the browser cache disguised as a PNG file," the Microsoft Threat Intelligence team said in a post on X. Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Atlassian warns of critical file access flaw in its datacenter products

The Register - Anti-Virus - 6 Říjen, 2026 - 06:20
Atlassian has told its users to patch its datacenter products, pronto, to prevent attackers accessing their files. The Australian collaborationware company on Monday sent users an email that opens with the words “Action required” and points to a security bulletin that explains CVE-2026-21589. The 9.3-rated arbitrary file access vulnerability is present in the datacenter versions of its Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible, and Fisheye products. Atlassian says the vulnerability “allows an unauthenticated attacker to access specific files within the web application root directory in affected versions.” That’s scary because Atlassian warns “In some configurations, there may be sensitive files present that increase your risk.” There’s also some good news in that attackers must know the exact filename and path to exploit the vulnerability, and the mess doesn’t allow anyone to see the contents of a directory. Another piece of good news is that Atlassian has updated its products – so users only need to find a change window in which to upgrade to a safe version of their software. Atlassian advised those who can’t patch ASAP to remove their instances from the internet, if possible. “Instances accessible to the public internet, including those with user authentication, should be restricted from external network access until you can take action,” the company warned. Its advisory also includes mitigations and advice on how to determine if your instances need the fix. Users who made the move from datacenter products to the Atlassian cloud have nothing to do, as Atlassian fixed the flaws in its own SaaS. That state of affairs rather vindicates Atlassian’s 2020 decision to stop developing its low-end server products and require users to shift into its cloud, and last year’s sequel in which it decided to discontinue its datacenter software, too. Atlassian admitted it hasn’t made that migration easy, because it somehow released a lift and shift tool that was worse than an earlier version. In March 2026, Atlassian axed ten percent of staff. The company’s share price was on a year-long slide at the time, as pundits suggested it might fall victim to the SaaSPocalypse, a theory that AI would replace business software. The price of Atlassian scrip has tripled since then, suggesting investors are more confident the company’s plan to use AI to power workflows represents a moat LLMs cannot cross. ®
Kategorie: Viry a Červi

Linux Kernel Vulnerability Fixed in Binder Device Creation

LinuxSecurity.com - 6 Říjen, 2026 - 05:10
Linux developers have merged a fix for a Linux kernel vulnerability that can leave Binder device creation writing to memory the kernel has already released.
Kategorie: Hacking & Security

Citrix NetScaler Vulnerability Is Being Exploited: Check SAML Systems

LinuxSecurity.com - 6 Říjen, 2026 - 05:00
Citrix has confirmed targeted attacks involving a Citrix NetScaler vulnerability and urged affected customers to update.
Kategorie: Hacking & Security

OpenOffice Vulnerability Can Run Code From Malicious Documents

LinuxSecurity.com - 6 Říjen, 2026 - 04:45
Apache is asking OpenOffice users to turn off its Java integration after warning that a malicious document could run code on their computer.
Kategorie: Hacking & Security

OpenOffice Vulnerability Can Run Code From Malicious Documents

LinuxSecurity.com - 6 Říjen, 2026 - 04:45
Apache is asking OpenOffice users to turn off its Java integration after warning that a malicious document could run code on their computer.
Kategorie: Hacking & Security

scrcpy 5.0

AbcLinuxu [zprávičky] - 6 Říjen, 2026 - 04:44
Multiplatformní open source aplikace scrcpy (Wikipedie) pro zrcadlení připojeného zařízení se systémem Android na desktopu a umožňující ovládání tohoto zařízení z desktopu, byla vydána v nové verzi 5.0. S podporou hardwarového dekódování videa na desktopu.
Kategorie: GNU/Linux & BSD

Apache Thrift 0.25.0 Adds Memory Limits for Network Messages

LinuxSecurity.com - 6 Říjen, 2026 - 04:40
Apache released Thrift 0.25.0 on Sep 30, 2026 with memory checks for several C++, Java, and Python components.
Kategorie: Hacking & Security

mold 3.0.0

AbcLinuxu [zprávičky] - 6 Říjen, 2026 - 04:35
Moderní linker mold, rychlejší alternativa k LLVM lld nebo wild, byl vydán v nové major verzi 3.0.0. Přepsán byl z C++ do Rustu.
Kategorie: GNU/Linux & BSD

Apache Directory LDAP API 2.1.9 Security Update for CVE-2026-103877

LinuxSecurity.com - 6 Říjen, 2026 - 04:30
Apache’s release notice on Oct 3, 2026 lists six Apache Directory LDAP API vulnerabilities.
Kategorie: Hacking & Security

OpenSSL Vulnerability Can Leak Server Memory Through DTLS

LinuxSecurity.com - 6 Říjen, 2026 - 04:20
OpenSSL issued fixes on Sep 29, 2026 for an OpenSSL vulnerability that can send unrelated program memory to another party during secure connection setup.
Kategorie: Hacking & Security

Security researcher claims they found KVM guest-host escape flaw

The Register - Anti-Virus - 6 Říjen, 2026 - 04:06
Linux KVM, the hypervisor favoured by hyperscale clouds, apparently has a full VM escape bug. That nasty news came from security researcher Paulos Yibelo, who on X shared a screenshot of a bug bounty award he won for discovering what he described as “Full VM escape zeroday (guest>host root in industry standard hypervisors)!” The bug bounty Yibelo participated in is run by Vercel, a company that provides MicroVMs as sandboxes for AI agents to work inside. The company’s Sandbox uses Firecracker MicroVMs, a technology created by AWS, which relies on Linux KVM – the kernel level hypervisor in Linux. Vercel CEO Guillermo Rauch named KVM as the hypervisor identified by Yibelo. “We’ve confirmed a KVM 0day through our Vercel Sandbox bounty program. Affecting the industry’s gold standard solution for Linux virtualization,” he wrote. And that’s all the info that has made it into the public view at this time. The Register can find no chat on relevant mailing lists. We have asked Rauch and Yibelo for additional details. Hopefully, we don’t hear from either of them for days or weeks, for two reasons. One is that guest-host escapes are the nightmare virtualization scenario because they mean whoever runs a guest VM could take over an entire server, and perhaps gain the ability to control other guests. The other is that KVM is astoundingly prevalent: AWS and Google both use it to power their public clouds. Enterprise virtualization players Nutanix, HPE, and Proxmox also rely on KVM. And of course KVM is also in Firecracker, which is open source and could therefore be running in all sorts of places. Whatever Yibelo discovered therefore very much needs a responsible disclosure process, because if hints about the flaw emerge it could allow attackers to do a lot of damage. Once a fix is found, the next question is whether implementing it will require disruption or downtime. It’s possible to hot-patch KVM, and to migrate live VMs from vulnerable hosts to machines running a patched version of Linux. Hopefully those techniques will work. This might be the second nasty bug discovered in KVM this year, after the so-called Januscape flaw. Beyond the potential risks this bug created, observers have suggested the potential seriousness of the flaw means Yibelo’s reward should exceed the $50,000 available under Vercel’s bug bounty program. ®
Kategorie: Viry a Červi
Syndikovat obsah