Agregátor RSS

OpenAI is adding invisible watermarks to ChatGPT and Codex text in the EU

Bleeping Computer - 6 Říjen, 2026 - 00:46
OpenAI is preparing to add invisible watermarks to text generated by ChatGPT and Codex in the European Union. [...]
Kategorie: Hacking & Security

MCP for agent-to-agent comms may be the riskiest protocol you've never heard of

Ars Technica - 6 Říjen, 2026 - 00:26

The adoption of AI agents in millions of organizations is creating new opportunities for attackers to make them take malicious actions, such as exfiltrating database contents and sensitive business and personal information.

In the past five months, Google and four other organizations—with little in common except for their use of AI agents—have acknowledged vulnerabilities that exploit one agent inside a targeted network to spread harmful instructions to other internal agents. The technique is a special form of prompt injection that targets not the LLM but a particular agent, such as one for translation or data analysis. Guardrails inside such agents, if they exist at all, are often lax and will send the instructions to other agents down the chain. Because the latter agent explicitly trusts the first one, it follows the directions.

Unexpected and hard to mitigate

Independent researcher Syed Anas Mohiuddin tested agents from organizations including Google, JP Morgan Chase, Weviate, Rapid7, the French government's interministerial digital directorate, and the US federal government. His proof-of-concept attacks exploit trust gaps in MCP, short for Model Context Protocol. The standard is one way AI apps and agents communicate with each other inside an internal network. The illustration below shows a simplified MCP in action.

Read full article

Comments

Je to krátkozraké, střílíme se do vlastní nohy: Odborníci hodnotí chystané snížení podpory v nezaměstnanosti

Lupa.cz - články - 6 Říjen, 2026 - 00:00
Opětovné snížení podpor v nezaměstnanosti a při rekvalifikaci nám podle odborníků jen uškodí. Podle nich jde o hloupé opatření, které znovu zabetonuje pracovní trh.
Kategorie: IT News

Cestovní náhrady mají nový paradox. Natural 95 je ve vyhlášce dražší než Natural 98

Lupa.cz - články - 6 Říjen, 2026 - 00:00
Od října se zvýšila vyhlášková cena Naturalu 95 z 34,70 na 41,80 Kč za litr. Prémiový benzin 98 přitom zůstává na 39 Kč. Ukážeme, jak se změna projeví při vyúčtování pracovní cesty.
Kategorie: IT News

AI proměňuje software, bezpečnost i svět kolem nás, zápisky z LinuxDays

ROOT.cz - 6 Říjen, 2026 - 00:00
Na LinuxDays se hodně mluvilo o tom, jak umělá inteligence mění open source, každodenní práci i bezpečnost. Řeč byla o chatbotech, telefonu Jolla Phone, RFID i aktuálních bezpečnostních hrozbách.
Kategorie: GNU/Linux & BSD

WebGL: tvorba 3D grafiky s využitím programovatelné vykreslovací pipeline (3. část)

ROOT.cz - 6 Říjen, 2026 - 00:00
Budeme se zabývat vykreslováním povrchů těles složených z trojúhelníků. A nezapomeneme ani na popis funkce paměti hloubky (depth buffer, Z-buffer). Tím získáme základní poznatky nutné pro vykreslování 3D scén.
Kategorie: GNU/Linux & BSD

Uživateli odešel čtvrtý 14900K, navzdory novému BIOSu a profilu Intel Default

CD-R server - 6 Říjen, 2026 - 00:00
Zdá se, že ani novější záplaty na degradaci procesorů Raptor Lake / Raptor Lake-refresh nejsou spolehlivou prevencí problémů. Dokonce ani v kombinaci oficiálního napájecího profilu Intel Default…
Kategorie: IT News

Uranové kostky prozrazují, že Německo nemělo šanci postavit atomovku

OSEL.cz - 6 Říjen, 2026 - 00:00
V letech 1939 až 1945 běžel pod vedením Wernera Heisenberga nacistický jaderný program Uranverein, jehož hlavním cílem do konce války bylo spustit štěpný reaktor. Jaderní archeologové analyzovali veškeré dostupné důkazy a dospěli k závěru, že to nacisti nemohli s dostupným uranem a hlavně těžkou vodou dokázat. Díky bohu za operaci Telemark!
Kategorie: Věda a technika

Soumrak programátorů? Lidé už ani nerozumí kódu, který teď píše AI

OSEL.cz - 6 Říjen, 2026 - 00:00
Kódování s AI je super a otevírá dveře každému, kdo to chce zkusit. Ale za podobné věci je vždy nutné něčím zaplatit. Narůstají obavy, že programátoři ztrácejí své dovednosti, a že k tomu dochází v době, kdy naopak potřebujeme co nejvíce zdatný dohled nad kódováním, které dělají umělé inteligence.
Kategorie: Věda a technika

Citrix NetScaler security snafus get even worse amid more 0-day reports

The Register - Anti-Virus - 5 Říjen, 2026 - 23:18
The attackers just keep coming after Citrix NetScaler appliances, as both the feds and private security researchers warn that someone found - and has already exploited - yet another Citrix bug before it had a patch. This latest vulnerability, tracked as CVE-2026-88779, is a memory overflow bug that leads to denial of service attacks. It only affects NetScaler ADC and Gateway appliances configured as a SAML (Security Assertion Markup Language) service provider or identity provider, used for single sign-on authentication. Late Friday, amid exploitation reports, Citrix confirmed that it was investigating a “newly observed issue related to SAML authentication in customer-managed NetScaler deployments.” By Saturday night, the vendor released a security advisory for NetScaler ADC and NetScaler Gateway with patches, urging vulnerable customers to “install the relevant updated versions as soon as possible.” Citrix also posted a blog about the vulnerability, confirming that it has observed targeted attacks on unmitigated NetScaler deployments that can lead to denial of service. Citrix did not answer our questions about CVE-2026-88779 - including how many instances have been affected and what attackers are doing after exploiting the bug - but urged customers to "quickly apply" the fix to NetScaler instances. "We were recently alerted to a new issue that affects service availability for some NetScaler deployments," a Citrix spokesperson told The Register. "After we were alerted to this issue we immediately developed and published a mitigation while concurrently developing, testing and deploying a fix." On Sunday, the US Cybersecurity and Infrastructure Security Agency (CISA) confirmed CVE-2026-88779 was under active exploitation and ordered federal agencies to patch the bug by Wednesday. While the new vulnerability is not technically related to the earlier eight CVEs finally disclosed by Citrix on September 27 - weeks after miscreants began abusing two of these security holes (CVE-2026-88772 and CVE-2026-88771) - watchTowr researchers told us they suspect it has been used to purposefully crash machines, making exploitation of CVE-2026-88771 faster. “This vulnerability is incredibly simple to trigger, with a single specially crafted request being all that is needed to knock an appliance offline,” watchTowr’s head of threat intelligence, Jake Knott, told The Register. “Exploitation is already occurring in the wild, and disrupting an authentication gateway can prevent legitimate users from accessing the services behind it.” WatchTowr reproduced the vulnerability on Friday, and Citrix credited the attack-surface management company along with Bishop Fox with helping it address the issue. “Citrix provides an indicator-of-compromise script that teams can run to check exposed appliances for signs of compromise, though a clean result is not definitive proof,” Knott said. “Security teams should prioritize appliances configured as a Gateway or AAA virtual server with SAML authentication enabled, and affected organizations should apply the fixed build or Citrix’s interim mitigation if an immediate upgrade is not possible.”®
Kategorie: Viry a Červi

Google DeepMind Gives AI-Designed Proteins a Watermark

Singularity HUB - 5 Říjen, 2026 - 22:54

A new system could help flag proteins generated by AI and ease risks to biosecurity. But it isn’t a perfect solution.

Proteins were once only created by nature. But it’s now possible to design completely new proteins from scratch using AI. The possibilities are endless. AI-designed proteins could become powerful drugs battling medical scourges, sentinels for the environment, or even the building blocks of synthetic life—including dangerous new pathogens.

Biosecurity is an obvious concern. But there’s another problem too: biological AI slop. AI-generated structures could pollute the databases scientists rely on to test theories or tweak protein functions. Without a way to distinguish experimentally validated structures from ones that AI simply dreamt up, scientists could spend months building on a rotten foundation.

To prevent this, AI-designed proteins could soon carry a watermark. Adapted from a technology that labels AI-generated text, images, audio, and video, a new Google DeepMind method called SynthID Bio sneaks a subtle signal into proteins during the design process. The tool could be built directly into protein-design systems such as AlphaFold and RFdiffusion.

“AI is expanding what scientists can design, and DNA synthesis companies have an important role in helping that innovation scale responsibly,” said James Diggans at Twist Bioscience in South San Francisco, who was not involved in the work but provided early feedback.

Not everyone is sold on blanket watermarking. The process can jostle protein structure just enough to produce a less optimal, if still functional, version of the molecules. For protein scientists tackling non-sensitive research questions, this could amount to “added complexity” that worries them, Oliver Crook at the University of Oxford told Science.

DeepMind acknowledges that SynthID Bio is just a first step towards tracking AI-generated biological molecules, and plenty of kinks still need ironing out. But they hope to start a conversation about the pros and cons of watermarks and how to best implement them. Ideally, watermarks allow research to continue freely while still preventing dangerous AI designs from crossing into the physical world.

Gap in the Guardrails

There’s no doubt AI is transforming biological research. From deciphering protein structures and mapping their interactions to dreaming up entirely new proteins, these tools have opened a new window on the mechanics of life.

But it’s a double-edged sword.

Last year, a study found that existing biosecurity software struggles to recognize synthetic toxins generated by freely available AI tools. And a more recent study in which scientists used AI to design entirely new bacteriophages—viruses that infect bacteria—earned scientific praise and set off alarm bells. The work showed AI can write biological functions at whole-genome scale, a scientific triumph that, in the wrong hands, could potentially help create a bioweapon.

Thankfully, a major guardrail is already in place. Cells build proteins from DNA instructions. So, to synthesize a protein, researchers must send the molecule’s genetic blueprint to a commercial provider. There, the provider can compare the sequence to a large database of “controlled” DNA sequences. Suspicious sequences are flagged for human review to make sure they don’t encode toxins or proteins from pathogens.

But AI-designed proteins complicate the picture. If a sequence widely differs from anything in the database, it could slip through the cracks, even if the resulting protein is a brand new toxin. AI tools can also tweak sequences just enough to evade detection. Conversely, a dangerous sequence might fly under the radar if it looks too much like one already labeled safe.

One workaround is to screen not just for matching sequences, but also for expected biological function. But that means those conducting the screening need to have some idea of what the resulting protein might do—a tall order for a new sequence unlike anything in nature.

A watermark might offer a simpler alternative.

A Digital Trail

DeepMind adapted its new method from SynthID-Text, released in 2024 to watermark AI-generated content.

The watermark is not an individual stamp slapped onto an existing sequence. Rather, it emerges from nuances in language during generation. When producing text, AI predicts how likely each word is to follow the words before it. SynthID-Text nudges those choices—for example, favoring “researcher” over “scientist”—without changing a sentence’s meaning. An average user wouldn’t notice. But across longer chats, the tiny tweaks add up to a statistical signature that a detector can recognize as “made by AI.”

Proteins are also strings of “letters,” or amino acids, that follow biophysical rules as they fold into three-dimensional shapes. SynthID Bio applies a similar trick to its predecessor, subtly altering design decisions, such as which amino acid comes next. It also slightly adjusts the protein’s final form through tiny shifts in its atoms’ locations. The approach fine-tunes a small part of AlphaFold3 for structural prediction, so proteins generated by the model inherently carry the watermark, regardless of who runs it.

Proteins are finicky, and even minute changes can scramble their function. So the team put its watermarking system through a series of stress tests, generating proteins designed to latch onto multiple targets, including those related to regulating the immune system, blood vessel growth, and viral proteins. In lab tests, the watermarked versions performed just as well as their unwatermarked counterparts, making them “the first-ever watermarked and biologically functional protein binders,” wrote the team.

But there’s a catch: The watermark can be scrubbed. If you run a marked protein through another design tool to generate a new but functionally similar sequence, the tag effectively disappears. Also, SynthID Bio can’t currently be used to identify the creator of a protein, limiting its ability to trace illicit use or to mark intellectual property.

Other systems are in the works. FoldMark, for example, embeds a unique 32-bit digital watermark into a protein’s structure by slightly changing its geometry. The team tested the system on several proteins and found they retained normal function. In simulations, the system could distinguish among as many as one million hypothetical users. Another idea is to give scientists a private “identifier” to watermark the proteins they create. A DNA synthesis provider could then check the sequence to see if an order came from an authorized user.

Regardless of the method, watermarking raises an inevitable question: Who gets the decoder key? DNA synthesis companies are one obvious choice. But there’s little agreement on who else should get access. A recent survey of 130 stakeholders including biosecurity experts, government agencies, policymakers, and academics did not land on a general consensus.

To keep the conversation going, DeepMind is releasing its SynthID Bio code and experimental data to researchers. The company is also expanding the technology to more complex biological systems. In collaboration with Arc Institute and Stanford University, the team has watermarked the genomes of AI-designed bacteriophages, without disabling them, in early tests.

“We believe this work has the potential to address some of the biosecurity risks associated with genome design,” wrote the team. “By working openly with partners across biosecurity, gene synthesis, and policy, we can ensure safety and responsibility keeps pace with AI-driven discovery.”

The post Google DeepMind Gives AI-Designed Proteins a Watermark appeared first on SingularityHub.

Kategorie: Transhumanismus

Rejetto HFS servers now actively scanned for critical RCE flaw

Bleeping Computer - 5 Říjen, 2026 - 22:20
Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows session forgery, account takeover, and remote code execution (RCE). [...]
Kategorie: Hacking & Security

MusicBrainz Picard 3.0

AbcLinuxu [zprávičky] - 5 Říjen, 2026 - 20:22
Po osmi letech od vydání verze 2.0 byla vydána nová major verze 3.0 multiplatformního editoru tagů MusicBrainz Picard (Wikipedie). Přehled novinek, vylepšení a oprav v changelogu.
Kategorie: GNU/Linux & BSD

Evropané dostanou jiný ChatGPT než zbytek světa. Bude jim neviditelně podepisovat texty

Živě.cz - 5 Říjen, 2026 - 20:15
OpenAI kvůli evropskému AI Actu zavádí vodoznaky v generovaném textu. • Technologie textGrain skrývá statistický signál ve výběru slov. • Záměna čtvrtiny slov sníží úspěšnost detekce na 17 %.
Kategorie: IT News

FBI confirms 'multiple' arrests related to ShinyHunters hack

The Register - Anti-Virus - 5 Říjen, 2026 - 19:46
The FBI and law enforcement partners have arrested “multiple” suspects as part of an investigation into a September hack allegedly involving data-theft-and-extortion group ShinyHunters, the bureau told The Register. “The bureau continues to aggressively investigate the recent cyber incident allegedly involving ShinyHunters, having already worked with partners to arrest multiple subjects and we will spare no resource in bringing each of the responsible individuals to justice,” an FBI spokesperson told us in an email on Monday. The FBI declined to comment on the specific arrests, including that of Saif al-Din Khader, a suspected ShinyHunters member who has reportedly been detained in Jordan, according to Reuters. Khader, who goes by the alias Rey, was reportedly brought into custody on September 29, and is said to be cooperating with the FBI to identify other members of the group. ShinyHunters did not respond to The Register’s inquiries about the arrest and Khader’s alleged involvement with the criminal group. Rey confirmed his real identity - Khader - to security journalist Brian Krebs last year. Krebs described Khader as the “technical operator and public face” of Scattered LAPSUS$ Hunters. “Rey got picked up finally,” said security sleuth Kevin Beaumont following news of the arrest. According to Beaumont, Rey was “one of the kids who got into JLR.” The Jaguar Land Rover (JLR) breach, which occurred in late August 2025, affected the company's IT systems and halted manufacturing operations. Dealer systems also went down, and suppliers faced canceled or delayed orders. In addition to crippling the carmaker’s business operations for months, the digital thieves stole personal payroll data belonging to thousands of JLR employees. The cyberattack, one of the most costly in UK history, was attributed to Scattered LAPSUS$ Hunters. Khader’s detention came two weeks after the Dutch National Police arrested a 24-year-old whom the FBI described as “one of the alleged leaders of ShinyHunters.” While Dutch cops have not named the suspect, Krebs and other reports say he is Pepijn van der Stap, who was convicted in 2023 for hacking and extorting numerous organizations and was on supervised release after three years in prison. Van der Stap also worked as a software engineer at the Amsterdam-based cybersecurity startup Hadrian and volunteered as a security researcher at the Dutch Institute for Vulnerability Disclosure (DIVD). In a video message following the arrest, Brett Leatherman, assistant director of the FBI's Cyber Division, had some advice for the “remaining members” of the data theft and extortion gang. “Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who's left,” Leatherman said last week. “The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.” At the time, the FBI declined to answer The Register’s questions about the video message, including whether it had seized any of the cybercrime group’s infrastructure, and whether any of ShinyHunters’ members had taken Leatherman up on his offer to “reach out first.” In late September, ShinyHunters hacked the FBIJobs.gov portal and claimed it stole sensitive personal details about current, former, and prospective FBI employees. A spokesperson told The Register that unlike most of its digital break-ins, this one was “NOT financially motivated … We want the FBI to correct or retract their statements they made, which included substantial false allegations.” Later, in an exclusive interview, the spokesperson told us the attention-grabbing hack was “fundamentally a public relations and marketing initiative for our business.” ®
Kategorie: Viry a Červi

Nejdřív porno, potom TikTok. Triky ze stránek pro dospělé dnes používají prakticky všechny aplikace

Živě.cz - 5 Říjen, 2026 - 19:45
Nekonečné scrollování i sledování odkoukaly mobilní aplikace z webů pro dospělé • Modelky z webkamer vymyslely prodej iluze blízkosti dávno před sociálními sítěmi • Sahání po mobilu při každém prostoji funguje na stejném principu rychlého rozptýlení
Kategorie: IT News

IQVIA fined $7.8 million for failing to properly anonymize health data

Bleeping Computer - 5 Říjen, 2026 - 19:19
Italy's Data Protection Authority (GPDP) has fined IQVIA €7 million ($7.8M) over poor data-processing practices that the agency says could have put roughly one million patients at risk of data exposure and de-anonymization. [...]
Kategorie: Hacking & Security

Google zase utahuje opasky. Gemini Free a tarif Plus budou používat horší AI modely

Živě.cz - 5 Říjen, 2026 - 18:45
Od 9. října Google změní chování dvou nejnižších tarifů AI chatbotu Gemini. Základní bezplatná verze už bude moci využívat jen základní rychlý model Flash-Lite (momentálně ve verzi 3.5). Placený Plus za 150 či 300 Kč pak poběží maximálně na modelu Flash. Doteď mohly oba využívat i nejpokročilejší ...
Kategorie: IT News

Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes

The Hacker News - 5 Říjen, 2026 - 18:21
Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulnerability, tracked as CVE-2026-96940, is rated 8.8 on the CVSS scoring system. "Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

iPhone po aktualizaci na iOS 27 rychleji vybíjí baterii. Na vině může být toto skryté nastavení

Živě.cz - 5 Říjen, 2026 - 17:45
Nové Posílené připojení v iOS 27 může výrazně zvyšovat spotřebu baterie • Tato funkce totiž využívá bezdrátovou i mobilní síť současně • Vypnutím této novinky v nastavení Wi-Fi můžete dosáhnout delší výdrže
Kategorie: IT News
Syndikovat obsah