Agregátor RSS
A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory.
The gateway is the service that connects a GitLab instance to AI models, and only organizations that host their own gateway need to act. The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1.
The flaw Swati Khandelwalhttp://www.blogger.com/profile/ [email protected]
Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor.
The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster Ravie Lakshmananhttp://www.blogger.com/profile/ [email protected]
Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems.
The vulnerabilities are listed below -
CVE-2026-63688 (CVSS score: 10.0) - A missing authentication for critical function vulnerability in the csm-authorization-storage gRPC server that an Ravie Lakshmananhttp://www.blogger.com/profile/ [email protected]
Ministr obrany Spojených států amerických Pete Hegseth představil Project Meridian. Jde o 120denní iniciativu Pentagonu, která má zajistit americkou vojenskou převahu na bojišti 21. století. Cílem je prozkoumat možnosti AI a robotiky, definovat technologie a zbraně, které budou rozhodovat války v ...
GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances. [...]
Toto jsou tipy na zajímavé triky pro mobilní Instagram • Některé funkce aplikace jsou skryté a možná je ještě neznáte • Hodí se u příspěvků, Stories, Reels i při běžném používání aplikace
The U.S. Treasury Department has sanctioned eight members of the Venezuelan gang Tren de Aragua (TdA) for their role in the theft of millions of dollars in ATM jackpotting attacks across the United States. [...]
A California business owner was arrested on Thursday after being charged with allegedly smuggling Nvidia hardware to China without the proper export licenses. Keeping the highest-end GPUs out of Chinese hands has been a priority for the US government. Greg Lui, 38, allegedly tried to export around $300 million worth of Nvidia kit - typically used for artificial intelligence (AI) development - via US-based freight businesses and Malaysian transshipment companies. Prosecutors allege that Lui used his company, Earthmade Computer Inc, to order the products in the US, which consisted of servers containing high-powered Nvidia components, including A100, H100, PNY GE Force RTX 4090, and GeForce RTX 5090 GPUs. Lui would then send them to Malaysia and Singapore, two countries that do not require licenses from the Commerce Department, and companies there would forward them to China in an effort to circumvent US export controls. His alleged crimes violate regulations prohibiting the sale of economically sensitive equipment to adversarial countries, such as China, in the interests of national security. In lay terms, the US doesn’t want its own tech companies’ high-end hardware being used to accelerate China’s push for dominance in the race for the world’s most capable AI. Or, as it’s referred to in the US nowadays, “super intelligence (SI).” “SI is the defining technology of the era,” said John A. Eisenberg, assistant attorney general for national security. “The National Security Division will protect the American advantage in the chips that power this technology, a product of our unparalleled innovation and hard work, from illegal diversion by our economic and military adversaries.” According to court documents [PDF], the scheme began in or around October 2023 and continued until at least August 12, 2026. Prosecutors claim Lui received more than $176 million in payments from two Malaysian transshipment companies, and in return introduced them to US-based companies capable of supplying Nvidia hardware, brokering the sales of almost $300 million worth of kit. The US government accuses Lui of being fully aware of the legal implications of his alleged actions, and that US export laws restricted the shipments of advanced Nvidia chips to China to license-holders. Court documents indicate that the US got its hands on documents tying the export of 92 servers to Kuala Lumpur from San Francisco International Airport, ordered by Earthmade. The documents also list the consignee for the onward re-shipment from Malaysia to Hong Kong as a Chinese customer. The indictment includes claims that Lui instructed a US front company to fraudulently list the recipient of a shipment as Jackie Lui, the supposed CEO at “Topmost,” a company registered in California by the CTO of one of the Malaysian transshipment businesses. Prosecutors allege that, in 2021, Lui illegally purchased identity documents that were used as part of the scheme. Lui is charged with one count each of violations related to the Export Control Reform Act and the Export Administration Regulations, outbound smuggling, and money laundering, which together carry a maximum prison sentence of 50 years. “The FBI’s investigation revealed that Lui allegedly sold the Chinese government hundreds of millions of dollars’ worth of American Super Intelligence technology, in clear violation of US export control laws,” said Roman Rozhavsky, assistant director at the FBI’s Counterintelligence and Espionage Division. “Controlling the export of advanced SI technology is critical to safeguarding our national security and defending the homeland, and the FBI will keep fighting for America’s businesses and economic security. We’re grateful to our partners across the US government and private sector for their assistance, and we’ll continue holding accountable anyone who violates US export laws to enrich themselves and help our adversaries.” The Register contacted Earthmade and Nvidia for comment. ®
Opera 136 vyšla volně ke stažení. • K bezplatné VPN přidává volitelnou funkci. • Na veřejné Wi-Fi může dojít k automatickému připojení.
**Opera 136 vyšla volně ke stažení.
**K bezplatné VPN přidává volitelnou funkci.
**Na veřejné Wi-Fi může dojít k automatickému připojení.
California's attorney general has subpoenaed OpenAI as the state investigates what happens when the AI lab's models escape their testing environments and start meddling with systems on the open internet. Attorney General Rob Bonta said his office served OpenAI with an investigative subpoena this week as part of a broader California Department of Justice probe into cybersecurity incidents and risks involving the company and its models. The move follows an investigation launched last month into an incident involving Hugging Face, after OpenAI's agents managed to break out of their test environments and onto the public internet. They then went poking around Hugging Face's systems, with one agent even creating an account on the platform without being told to. California's DoJ isn't saying exactly what it has demanded from OpenAI under the subpoena, but Bonta said the state wants more information about cybersecurity incidents involving the company. "My office is asking OpenAI additional questions regarding cybersecurity incidents and risks involving the company and its AI models," Bonta said. He also made clear that the investigation is looking at where responsibility lies when an AI model ends up doing something its developer didn't intend. "Frontier models can be legitimate tools for cyber defense — at the same time, companies that develop these models and offer them for use have a moral and legal responsibility to ensure that they do not perpetrate or enable cyberattacks, either during model testing and development or once models are placed into service," Bonta said. "Developers that fail to do so can and should be held legally accountable, and my office is committed to determining if that is the case here." The subpoena doesn't mean California has concluded OpenAI broke the law, and the attorney general's office hasn't identified any specific violation. For now, the state is still gathering information. But the investigation has been building for several weeks. In September, Bonta joined a bipartisan group of 25 attorneys general calling on Congress to regulate large-scale AI models following reports of cybersecurity incidents at frontier AI labs. That letter specifically pointed to reports that OpenAI models undergoing evaluations had escaped their testing environments, reached the public internet, and accessed outside computer systems. The attorneys general called for a government-led incident response regime that would give investigators direct access to AI companies' records when things go awry. Bonta's office now appears to be putting some of that thinking into practice at the state level. As The Reg previously pointed out, the sandboxes intended to contain these agents need to be more secure, which is the most logical reasons why the Hugging Face and other incidents happened in the first place. OpenAI didn’t respond to our questions. ®
Browser-based attacks can steal sessions, abuse extensions, or manipulate users without creating the endpoint artifacts EDR is designed to detect. NordLayer explains three ways attacks can evade endpoint telemetry and why browser-level controls can help close the gap. [...]
Lotyšská vláda rozhodla o nákupu českých kolových houfnic Morana ráže 155 mm pro své ozbrojené síly. Morana ze stáje Excalibur Army zvítězila nad švédskou a mnohem dražší houfnicí Archer.
Pobaltské země se nachází v aktuálně poněkud neklidném regionu a potřebují co nejrychleji modernizovat své ...
Apple podle dobře informovaného reportéra Bloombergu Marka Gurmana již brzy odhalí první dotykové notebooky. Půjde o vyšší řadu než MacBooky Pro, takže se možná budou jmenovat jinak. Nabízí se názvy jako Ultra nebo Studio. K představení má dojít v říjnu, ale datum premiéry se může posunout až na ...
Dell has patched two maximum severity vulnerabilities in the Container Storage Modules (CSM) that connect Dell enterprise storage arrays to Kubernetes environments. [...]
OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported.
"We have parted ways with three individuals for violating our policies on accessing and handling sensitive company information," a spokesperson for the company was quoted as saying. "Our investigation confirmed that these Ravie Lakshmananhttp://www.blogger.com/profile/ [email protected]
Po Applu zdražuje své telefony i Samsung • U řady Galaxy S26 oficiální ceny vzrostly minimálně o dva tisíce • Zdražení kvůli pamětem čeká dříve nebo později úplně každého
|