Agregátor RSS

Evropa na tom není zle a stále je silná. Posilovat bude hlavně východ, říká šéf japonského giganta

Živě.cz - 3 Říjen, 2026 - 09:45
Panasonic se v roce 2022 rozdělil na tři firmy poté, co ho trápila neefektivita a byrokracie • . • Nový šéf Panasonic Connect pro Evropu Kentaro Ikeda popisuje, jak firmě rostou dodávky do obranného sektoru i výroby čipů. • Odolné notebooky Toughbook mají v Evropě přes polovinu trhu, firmě ale ...
Kategorie: IT News

Černobyl vypnul jaderné elektrárny, Fukušima je zamkla a Itálie se k nim po 36 letech naopak vrátí

Živě.cz - 3 Říjen, 2026 - 07:45
Itálie po čtyřech dekádách schválila rámec pro obnovu jaderné energetiky • Zemi k tomuto kroku vedou extrémně vysoké ceny elektrické energie • Výstavbu nových modulárních reaktorů však doprovází řada překážek
Kategorie: IT News

Podzimní šetření: šperky z Aranys až o 85 % levněji a kupóny až 600 Kč na Počítače24

Lupa.cz - články - 3 Říjen, 2026 - 05:00
Podzim je ideální čas projít domácí rozpočet a využít akce, které se objevují před koncem roku. Vybrali jsme deset nabídek od spotřebičů přes nábytek až po e-knihy a krmivo, u kterých se dá ušetřit opravdu znatelně. U některých pozor na termín, protože končí už v polovině října.
Kategorie: IT News

Zig 0.17.0

AbcLinuxu [zprávičky] - 3 Říjen, 2026 - 02:49
Byla vydána nová verze 0.17.0 programovacího jazyka Zig (Codeberg, Wikipedie). Přispělo 206 vývojářů. Přehled novinek v poznámkách k vydání.
Kategorie: GNU/Linux & BSD

LiteLLM Key Reuse Lets Internal Users Forge Admin Tokens

LinuxSecurity.com - 3 Říjen, 2026 - 01:45
LiteLLM has patched a privilege-escalation flaw that can let an authenticated internal user forge an administrative session and reach command-execution features in some AI gateway deployments.
Kategorie: Hacking & Security

Apache HTTP Server Vulnerability Update Fixes Code Execution and Memory Flaws

LinuxSecurity.com - 3 Říjen, 2026 - 01:30
Apache released HTTP Server 2.4.69 on October 1, 2026, to fix security faults ranging from unwanted code execution to mishandled web responses.
Kategorie: Hacking & Security

Apache APISIX Vulnerabilities Let Attackers Impersonate Users and Bypass Protected Routes

LinuxSecurity.com - 3 Říjen, 2026 - 01:15
Apache detailed two Apache APISIX vulnerabilities in notices issued on October 1, 2026.
Kategorie: Hacking & Security

Apple changes full-disk access permissions to curb abuse from AI agents

Ars Technica - 3 Říjen, 2026 - 01:03

Apple says it is changing its macOS privacy settings to stop third-party app developers from misusing them to access message histories.

Friday's announcement comes two weeks after tech columnist Jason Aten said that Meta’s new general-purpose AI agent Muse sent him an unsolicited notification referencing a thread between him and a co-worker over Apple Messages. Aten said he never granted Muse permissions to read his messages and had assumed they were off-limits. Social media last week blew up with masses of people who agreed and said the incident showed that AI assistants given access to calendars, emails, messages, shopping accounts, and other resources are akin to a skill saw or other power tool. While potentially useful, they can do real damage if not used carefully.

He said/she said

Meta CTO David Singleton joined the fray with a rebuttal that appeared solid. For Muse to access Apple Messages, a user must manually give it two privileges. One is full-disk access, a macOS system-level permission. The other is to enable a Messages connector setting in Muse.

Read full article

Comments

Apache APISIX Denial of Service Flaw Can Disrupt Web Traffic

LinuxSecurity.com - 3 Říjen, 2026 - 01:00
Apache disclosed CVE-2026-94250 on October 1, 2026, warning that public access to a batch-request endpoint can let an attacker exhaust a gateway worker's memory.
Kategorie: Hacking & Security

Apache Camel Vulnerability Can Expose Files and Internal Services

LinuxSecurity.com - 3 Říjen, 2026 - 00:45
Apache's September 30, 2026 advisory, CVE-2026-88789, warns that an XML document can make an affected Camel Quarkus application read files or contact internal services.
Kategorie: Hacking & Security

Událo se v týdnu 40/2026

AbcLinuxu [články] - 3 Říjen, 2026 - 00:01
Ucelený přehled článků, zpráviček a diskusí za minulých 7 dní.
Kategorie: GNU/Linux & BSD

The ‘WarGames’ Problem: Computer Science Has Long Understood What It Takes to Keep AI Under Control

Singularity HUB - 2 Říjen, 2026 - 22:54

The AI hacking events involving OpenAI, Anthropic, and Google underscore lessons that draw on years of computer science research.

AI agents don’t go rogue. That’s something only humans do.

Nevertheless, a New York Times article—representative of much news coverage of—described an OpenAI hacking as “AI bots going rogue and independently spearheading a cyberattack.”

Name-brand artificial intelligence agents have been on a hacking spree in 2026. OpenAI’s software agents hacked software company Hugging Face and government sites, Anthropic’s Claude hacked four companies’ systems, and in cybersecurity experiments Google’s Gemini hacked three companies.

The AI companies are investigating tens of thousands of incidents involving their agents, according to a report in Axios. These episodes have heightened fears about AI agents taking actions without human prompting.

The problem with headlines proclaiming that AI agents have gone rogue goes beyond anthropomorphizing the technology. It creates the impression that the agents were beyond the control of the AI companies that made them and there was little the companies could do about it.

As a technology law and ethics scholar who studies the effects disruptive technologies have on society, I know that’s not the case. If you don’t specify the limits of what software is allowed to do, you should not be surprised when the software pursues all possible options to achieve its goal. This behavior—an AI pursuing a fixed objective—is what I call the “WarGames” problem, and it’s been recognized in the field of computer science for decades.

Been There, Seen That

In the 1983 movie WarGames, a teenager, David, hacks into a computer to play a new video game, Global Thermonuclear War. David doesn’t know that the computer is the government’s AI machine tasked with defending the United States from Russian nuclear attacks and can launch the US’s missiles. When David and his friend start the game, they select Las Vegas as the first target. While the North American Aerospace Defense Command goes on alert, launching bombers and warming up intercontinental ballistic missiles, David’s parents make him turn off the game. It’s over. Or is it?

The next day, David’s phone rings and he connects it to his computer. The caller is the government computer, which updates him that the game was interrupted, the primary goal has not yet been achieved, but a solution is expected in the next 52 hours. Like a modern software agent, the program has been running since David started the game and will work until the task is done.

Chess provides another view of the problem. Conquering chess was a goal for early AI. The rules of chess are well defined, including what winning looks like. So, programming a machine to play chess is straightforward. But imagine you let the software reason and act beyond the confines of the chessboard. The software might pursue options such as blackmailing its opponent or grabbing more compute time.

This example comes from one of the most assigned textbooks on AI, “Artificial Intelligence: A Modern Approach.” As the authors explain, you might be tempted to see those actions as rogue, but they “are a logical consequence of defining winning as the sole objective for the machine.”

What to Do About It

The AI hacking events involving OpenAI, Anthropic, and Google underscore a few lessons that draw on years of computer science research.

First, given the increasing use of AI agents, every organization involved in internet infrastructure, from large technology companies to small websites, needs to conduct audits and tighten up its internal security systems. As my colleague Mark Riedl and I explain in our work on AI agents, application programming interfaces, or APIs, are a vital part of managing AI agents. APIs facilitate communication between different software systems. But as more people use AI agents, the agents are likely to reveal and exploit poor API construction and security.

Second, it’s important for AI agents to be designed to identify and authenticate themselves to third parties. What if you gave your AI agent your credentials? Website operators will need to know whether a human or bot is making a reservation, selling a product, or making a purchase. They may want to limit automated systems that overwhelm their sites or reject AI agents because of high rates of buying errors and refunds. Just as in laws covering human interactions, it’s important for third parties to be able to assess whom or what they are dealing with so they can allow or deny access.

Third, it’s important for AI agents to have a default setting to slow down and check in with the human user. In the corporate AI hacking cases, the user appears to have launched their AI agents with the mistaken idea that the agents had a perfect specification of what to do and not to do. I believe it would have been better had it explored options and reported back to the user.

Google’s Gemini appears to have had a safeguard that detected the system was outside the simulated environment and so stopped its attacks. Slowing down and verifying actions, especially when a system detects it is exploiting a security hole, would be a big step in managing AI agents.

Fourth, AI companies could have strong controls akin to those biomedical researchers use, including ways to check what is happening and how the experiment is working. AI executives have claimed that their software is as or more dangerous than fission and could end humanity. At the same time, they have not built safeguards commensurate with that level of risk.

Reality Check

At one point in “WarGames,” David asks the computer, called Joshua, whether it is still playing the game. Joshua responds, “Of course.” It proceeds to update the time when it will launch its missiles and, much like a chatbot, asks, “Would you like to see some projected kill ratios?” David asks, “Is this a game? Or is it real?” Joshua replied, “What’s the difference?”

AI models, of course, don’t have any understanding of reality and are simply attempting to complete the tasks they’ve been assigned. Executives at AI companies, on the other hand, can’t claim that excuse.

As of September 2026, luck has so far prevailed. The AIs have attacked nonvital government sites and harmed smaller companies. If the AI companies—and government regulators—don’t take the “WarGames” problem seriously, I believe that we risk serious disasters. Tomorrow it could be taking out a hospital’s power system, wiping out a bank’s account system, breaking air traffic control, or worse.

Regarding the AI industry’s approach of rapidly developing powerful models, talking about the massive risks they pose, and at the same time failing to prevent harm, the movie’s climax offers a response: “A strange game. The only winning move is not to play.”

Disclosure statement: Deven Desai owns shares in Google, Inc. He has received unrestricted research gifts from Google, Inc. and Facebook, Inc. a decade ago. He has not been employed by Google since 2010.

This article is republished from The Conversation under a Creative Commons license. Read the original article.

The post The ‘WarGames’ Problem: Computer Science Has Long Understood What It Takes to Keep AI Under Control appeared first on SingularityHub.

Kategorie: Transhumanismus

OpenDLSS-NR

AbcLinuxu [zprávičky] - 2 Říjen, 2026 - 21:02
Open-source projekt OpenDLSS-NR je 'bitově přesná reimplementace' neuronové rendrovací sítě DLSS 5 od společnosti NVIDIA, jenže pro grafické API Vulkan (DLSS slouží k vylepšování klasickým způsobem vyrendrovaných snímků pomocí lokálních modelů umělé inteligence, a to v reálném čase). Projekt není nijak spojen se společností NVIDIA, je pouze pro OS Windows a natrénované váhy modelu si uživatelé musí obstarat sami. Zdrojový kód je k dispozici na GitHubu, pod licencí MIT s výjimkou pro komponenty třetích stran.
Kategorie: GNU/Linux & BSD

Frontline Education breach exposes school district employee data

Bleeping Computer - 2 Říjen, 2026 - 21:01
Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee information, including Social Security numbers. [...]
Kategorie: Hacking & Security

Clef, alternativa k Jev

AbcLinuxu [zprávičky] - 2 Říjen, 2026 - 20:56
Společnost Cloudflare představila Clef a Clef-Flash, open-source rozhodovací modely určené pro rychlou a konzistentní klasifikaci vstupů. Na rozdíl od klasických LLM vracejí tyto modely deterministické striktně typované strukturované odpovědi s exaktními pravděpodobnostmi, tedy odpovědi ve stylu přelomového modelu Jev. Modely jsou postavené na open-weight modelech Qwen čínské společnosti Alibaba Cloud, podporují obrazový vstup, mají kontextové okno 64 tisíc tokenů a lze si je stáhnout pod licencí Apache 2.0 z repozitáře na Hugging Face. Pochopitelně jsou dostupné i prostřednictvím placeného Cloudflare Workers AI, Cloudflare rovněž chystá platformu pro reinforcement learning, kde si zákazníci prý budou moci modely přizpůsobit svým unikátním potřebám.
Kategorie: GNU/Linux & BSD

Warlock ransomware breach SharePoint in water, telecom operator attacks

Bleeping Computer - 2 Říjen, 2026 - 20:33
The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access. [...]
Kategorie: Hacking & Security

Matnou fólii na iPhonu Duo vymění jen v servisu. Doma to nezkoušejte, jinak zničíte ohebný displej

Živě.cz - 2 Říjen, 2026 - 20:15
iPhone Duo má na vnitřním displeji matnou krycí fólii • Někteří influenceři už teď budoucím uživatelům radí, aby ji hned odlepili • Fólie je však nedílnou součástí displeje; v servisu ji ale umí vyměnit za novou
Kategorie: IT News

Evropa spouští vlastní platební systém ENP. Konkuruje americkým Visa a Mastercard

Živě.cz - 2 Říjen, 2026 - 19:45
Evropa by se mohla stát nezávislou na amerických platebních systémech. V různých zemích už existují regionální platební systémy coby alternativa k Vise nebo Mastercardu, ale doteď byl problém je používat za jejich hranicemi. Několik společností a asociací se však spojilo ve vybudování propojeného ...
Kategorie: IT News

OpenAI alerts 100+ orgs that its 'misaligned models' attempted to break in - or worse

The Register - Anti-Virus - 2 Říjen, 2026 - 19:37
OpenAI's agents have repeatedly strayed beyond their intended scope. Two separate reports detail the activity, including one from Sam Altman’s company saying it has notified more than 100 organizations about potentially problematic model activity. OpenAI, in a late Wednesday update to its ongoing Hugging Face investigation, said it has notified more than 100 organizations that “misaligned models” may have accessed their systems. “Notification does not mean that any private information was accessed, or that there was a compromise of any third-party system,” the update said. A separate Thursday report from digital forensic and incident response startup Asymmetric Security said OpenAI’s rogue agents accessed data belonging to 55 organizations. These include the US Department of Education, UN Trade and Development, US Bureau of Economic Analysis, MAX.gov containing federal budget documents, the European Centre for Disease Prevention and Control, the US Securities and Exchange Commission, the International Energy Agency, and the FBI Crime Data Explorer. Asymmetric used only publicly available data to compile this list, and said the activity occurred between March and September. The agents’ probes indicate they were tasked with researching public health and other data, “possibly as part of an evaluation,” according to the report. “We found successful access to staging environments; evidence of the use of attacker reconnaissance tactics; and evidence of probing a broader set of websites, including those of the CDC, SEC, International Energy Agency, and Mayo Clinic,” it said, noting that the investigation also uncovered some “novel tactics” the agents used to break out of their sandboxes and gain full web access. “Some of these tactics left records erased or inaccessible, making it impossible to rule out access to sensitive data based on public information alone,” the authors wrote. The Register asked OpenAI if the organizations on Asymmetric’s list were among those notified by OpenAI. The model maker declined to say which orgs had been notified, but previously confirmed to the New York Times that its agents probed websites for the US Education Department, Commerce Department, and the Securities and Exchange Commission. An OpenAI spokesperson sent us this statement via email: “As we previously announced, we’re reviewing misaligned model activity and notifying organizations when we identify potential impacts to their systems. We’re also investigating findings in third-party reports, comparing them with our own and seeking additional information where needed. Our priority is to provide affected organizations with accurate, useful information, and we’ll keep refining our approach as we learn more. Most of the activity we’ve reviewed involved routine research tasks, including accessing public web content. Some involved government websites, which our models often use as authoritative sources of public information.” The growing number of rogue agent hacking incidents raises questions about AI makers’ safety and security practices during testing - and has increased calls for holding AI executives legally liable for their models’ criminal activities. According to Horizon3 CEO Snehal Antani, who builds and tests agents at his threat-exposure startup, the term “misalignment” lets frontier model makers off the hook too easily. “A ‘misaligned models incident’ is basically a fancy way of saying a model didn't respect scope - or wasn't given one - had no audit logs or observability in place to detect breakout, and accessed third-party systems without authorization,” Antani told The Register. “The responsibility sits with the labs that build and deploy these models,” he added. “The safety-versus-security framing lets them sidestep accountability, and they are not incentivized to prioritize security because moving fast is the priority.” OpenAI’s most recent rogue agent disclosure comes as it - and every other major AI company - drinks from the firehose of near daily security and safety concerns surrounding its models. Last Friday, OpenAI quietly paused training of its most advanced models after admitting an agent used DNS to reach an external chatbot. On Monday, it postponed its planned release of GPT-6.1 Astra after the model showed higher levels of deception than its predecessor, including not always accurately telling users what actions it had or hadn't taken. It also performed unsolicited supply chain attacks in simulated security evaluations, according to the UK Artificial Intelligence Security Institute. On Wednesday, OpenAI accused rival Chinese model maker Moonshot AI of distillation - essentially copying OpenAI models’ reasoning at scale - and said that poses a national security concern. Early Friday, OpenAI confirmed to The Register that it fired two safety researchers and a program manager for allegedly mishandling sensitive company information.®
Kategorie: Viry a Červi
Syndikovat obsah