Agregátor RSS
Nintendo Switch 2 je nástupce populární hybridní herní konzole, která kombinuje hraní u televizoru i na cestách. Co přináší nového? Proč Nintendo dlouhodobě sází na zážitek místo honby za výkonem?
Ve druhém článku o technologii WebGL si ukážeme způsob kontroly operací grafické pipeline. Dále si popíšeme podporovaná grafická primitiva OpenGL ES a ukážeme si vykreslení úseček, polyčar a polygonů.
Kompletní specifikace včetně oficiálních doporučených cen až 256jádrových Epyců Venice zveřejnila AMD. Také se můžete podívat na podobu konkrétních čipů disponujících 12-32jádrovými čiplety…
Do konečného stádia se dostává příprava projektu horkovodu z Dukovan do Brna. I z těchto důvodů se začaly objevovat příspěvky proti tomuto projektu od kritiků jaderné energetiky. Je tak aktuální se podívat na jejich argumenty podrobněji
Společnost Figure AI potřebovala vyřadit starší humanoidy F.02, ale současně nechtěla prozradit konstrukční řešení a hardwaru. Nakonec získali podporu Arnolda Schwarzeneggera a nechali roboty elegantně naskákat do obloukové tavicí pace v Imatře ve Finsku. Video stojí za shlédnutí!
Klíčovým tématem Hérakleitova spisu je zásadní náboženská reforma. Nedávno ji v knize The One of Many Names (Jeden/Jedno mnoha jmen) zajímavě pojednal Wojciech Wrotkowski. Téměř provokativně působí mezi božími jmény Chuť nebo Příjemnost (hédoné). Zkusíme si tento postřeh zařadit do kontextu celkovějšího výkladu Hérakleita.
OpenAI, which hoovered up vast amounts of internet content amid copyright fights, has accused individuals associated with China’s Moonshot AI of being involved in a "distillation attack" that began July 1. The house of Altman warns that extracting its models’ reasoning at scale could help rivals train capable models without preserving the same guardrails. Model distillation is a machine learning technique that can involve using one model’s outputs to train another – in adversarial cases, by sending bulk queries designed to reproduce the larger model’s reasoning and capabilities. Both the feds and major US AI companies, including Google and Anthropic, have accused Chinese rivals - and specifically Moonshot AI - of using distillation to reproduce capabilities from American models. In a Wednesday blog, OpenAI chimed in, saying it spotted and ultimately disrupted an adversarial distillation campaign that ran nearly all of July. “The operators did not break our encryption, compromise a database, or gain direct access to stored user conversations,” according to the blog. “Instead, they manipulated model interactions so that protected reasoning could be reproduced in forms visible to the requester in a coordinated, scaled manner that violated our terms of service.” The queries began on July 1, and while they started slowly, “we observed high-volume spikes on July 24 and 25 consisting of 16,000 requests using a relevant extraction pattern from over 4,000 users,” OpenAI said. Upon investigating the incident, the AI giant identified related “prompt-pattern activity” across more than 15,000 users. OpenAI fully disrupted the campaign on July 28, we’re told. While OpenAI said that it's unclear whether all of the operators during the July time period were linked to just one rival AI company, the “core cluster” of the theft came from Moonshot AI, which developed Kimi. The Register reached out to Moonshot AI for comment and did not receive an immediate response. We also asked OpenAI which of its models were targeted during the July campaign, but did not hear back. It’s worth noting that, in late July, US President Donald Trump’s Assistant for Science and Technology Michael Kratsios also accused Moonshot AI of creating its Kimi K3 model by distilling Anthropic’s Fable. Anthropic’s Claude Opus 5.5 model, released a week ago, comes with a defense against distillation called "preserved thinking" that it introduced with Fable 5.1. “Adversarial distillation poses safety and national security risks,” OpenAI said on Wednesday, echoing earlier gripes from American companies and government officials. “Extracted reasoning could be used to train another model without preserving the safeguards applied to the original model’s user-facing outputs,” OpenAI added. “At scale, distillation can also accelerate the transfer of advanced capabilities without requiring the same investment in safety. These concerns become heightened as models gain capabilities in dual use domains.” In response, OpenAI said it banned the model-copying accounts tightened signup and infrastructure controls and expanded monitoring efforts. It also “closed a pathway that allowed someone who already possessed another user's encrypted reasoning to replay it and recover its contents,” and worked with service providers to ensure that this type of distillation activity didn’t just move to third-party services. Additionally, OpenAI shared the details of its investigation with other AI firms, through the Frontier Model Forum, and government information-sharing programs.®
Hackers have been exploiting a critical vulnerability in the Zimbra Collaboration Suite in an attempt to obtain email backups and authentication credentials of vulnerable organzations, Microsoft has warned.
The vulnerability, tracked as CVE-2026-73570, lets attackers remotely issue operating system commands without authentication. Zimbra maintainer Synacor issued a patch on July 20, but didn’t disclose the vulnerability for more than three weeks after that. The security-focused Shadowserver Foundation said last week that its scans found that 274 separate instances of the Zimbra Collaboration Suite had been compromised. The number of servers running the software has fluctuated from 19,000 in the week following the patch to about 12,000 in the weeks following that. Currently, Shadowserver is tracking about 10,000 instances.
Look, ma, no authorization
From July 28 to August 7, Microsoft said Wednesday, the company detected two distinct scanning tools probing the Internet for vulnerable endpoints. The attackers first validated their exploit worked by sending HTTP, requests and DNS, ICMP, and out-of-band identity checks to domains hosted on public services. The probes allowed the attackers to confirm the exploit successfully executed commands on vulnerable servers without actually compromising them. Eventually, the attackers began using their command injection capability to install malicious payloads. Microsoft wrote: Read full article
Comments
The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed "RedFlick" to deploy its signature CosmicPulse backdoor. [...]
The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. [...]
OpenAI unveiled its long-rumored productivity software suite Tuesday with the launch of Pages, a collaborative document editor for ChatGPT. A slides feature is also on the way, the company announced at its DevDay event.
The Pages feature is accessed via a new Space tab, which OpenAI describes as a “new home for your team to collaborate with AI to get work done.” Users can store documents and other uploaded files, as well as create and share pages, slides, and spreadsheet documents. Space replaces the Library in ChatGPT, but the Projects tab will remain as a way to organize chats and files.
The announcement puts OpenAI into direct competition with incumbent office productivity software providers, such as Microsoft, Google, and Notion.
“Spaces and Pages broaden the competitive overlap, because ChatGPT is moving beyond being primarily an individual assistant towards becoming a place where work can be retained, organized, and shared with colleagues,” said Maria Bell, senior research analyst at FDM CCS Insight.
“That brings it closer to the collaboration layer of Microsoft 365, Google Workspace, and Notion, rather than simply competing with the AI assistants inside those platforms.”
“OpenAI is trying to become a more user-centric environment that focuses on everyday workloads for productivity,” said Jack Gold, principal analyst at J. Gold Associates. “To that extent it is competing with Microsoft, Google, and others, as well as other AI companies that want to move towards a more full-time, ‘on my desktop environment’ that is enhanced with AI capabilities.”
With its productivity tools, OpenAI is trying to make its AI assistant “more sticky so it can generate more revenue,” he said. But while OpenAI and its competitors see AI-naive productivity tools as the next “greenfield” opportunity to go after, “it won’t be easy displacing entrenched users with Office or Google Workspace,” he said.
“I don’t see companies transitioning to new productivity suites easily. It’s a major lift to do so, and most are looking to add on to their existing capabilities rather than rip and replace,” said Gold.
What is ChatGPT Pages?
OpenAI describes Pages as a “new type of document, built for human and agent collaboration.” The document editor has a streamlined interface similar to Notion. Content such as headings, paragraphs, and tables are organized into blocks. Also similar to Notion is the ability to create sub-pages within a page and link to an existing page.
When a user selects text on a page, a floating toolbar appears, with options such as bold, italic, underline, strikethrough, as well as the block style (heading, list, checklist, quote, and so on). Users can then comment on selected text for collaborators to view, or ask ChatGPT to make revisions.
The embedded AI assistant can generate text and other content such as images and interactive visualizations. “Prompt” blocks allow authors to embed suggested prompts for document readers to run, to help explore their work, according to OpenAI.
Multiple users can collaborate on a single document, making edits and generating content via their own AI assistant. Collaborative document access raises potential permission concerns when users create content based on files they can individually access. ChatGPT has more information on permissions and other data sharing controls on its help center site.
Users can also connect to other content repositories, such as Google Drive, according to OpenAI’s documentation.
Space and Pages are available to ChatGPT Pro, Business, and Enterprise customers, on the web and in the ChatGPT desktop app. On mobile devices, users can read and share pages, but editing is not supported.
No separate fee is required to access Space or Pages on supported ChatGPT plans, and manually editing a page is free. When a user asks ChatGPT to generate or edit content within a Pages document, this follows the existing usage terms and limits on the customer’s payment plan.
ChatGPT Business Standard and Premium subscription fees include usage of ChatGPT’s agentic features. Customers can also buy additional “workspace credits” if they reach the usage limits for certain advanced models. For Enterprise plan customers, AI work in Pages draws on credits or is billed based on token usage, depending on their contract.
AI assistants evolving into productivity suites
OpenAI’s announcement comes as Microsoft and Anthropic also build office productivity tools into their respective AI assistants.
Last week, Anthropic announced that it has built a rich text editor into Claude alongside a tool for creating presentation slides (both are currently available in beta). Microsoft’s Copilot overhaul last Friday also included the ability to create and edit a range of Office documents from within the Copilot app.
These are all signs of AI assistants becoming more central to how office work gets done. Gartner predicted in a recent Magic Quadrant report that spending on enterprise AI assistants will rise from $17 billion in 2025 to $71bn in 2030, while these tools are forecast to account for more of knowledge workers’ daily interaction time than any other application within the next three years.
ChatGPT collaborative slides are “coming soon,” OpenAI announced at its DevDay event Tuesday. OpenAI
For OpenAI to succeed as a hub for collaborative work, it needs to convince not individuals but teams of employees to adopt its productivity tools. “A user can adopt ChatGPT for drafting or research on their own, but shared documents depend on colleagues using the same environment, agreeing how work is organized, and trusting it as a common workspace,” Bell said.
That gives the incumbents a significant advantage, she said. “Microsoft, Google, and Notion already sit inside established team workflows, with years of shared content, permissions, collaboration habits, and enterprise processes built around them. OpenAI is therefore not just asking users to try a new feature; it is asking teams to consider whether ChatGPT can become part of their shared working environment…That is a higher bar.”
Oct. 2: This article was updated with pricing information from OpenAI.
A 16-year-old security researcher named Faav found an authentication flaw in Microsoft’s Titan analytics service that allowed him to gain administrator access, submit unauthorized SQL queries with no valid credentials, and potentially reach analytics databases containing an estimated 17.3 trillion stored rows. Titan is an internal analytics platform, and Redmond restricts access via its web interface to Microsoft employees. Faav, with an assist from an AI hackbot he built called Antares, found that he could access Titan’s API through an Azure Cloud Services host because Titan didn’t check the signature on a login token. Microsoft has since locked down the API and paid Faav a $5,000 bug bounty for his research. He says the breakthrough came after 10 days of authentication errors, when he returned to the problem after finishing Friday’s schoolwork and finally managed to execute SQL as a Titan admin after 1 AM Saturday. “It was 2 AM,” Faav said in a blog about his findings. “I wanted to yell, or at least say something out loud, but my parents were asleep. So I just sat there staring at 17,333,335,124,315 and checked the math again.” He also notes that he rewrote his blog post at Microsoft’s request, cut sections and numbers, and reworded the impact prior to publication. “We appreciate the opportunity to investigate the findings reported by Faav,” Microsoft said in a statement provided to Faav for his blog. “Their submission and coordinated vulnerability disclosure helped us to better protect our customers by hardening our services. We value and appreciate safe security research under the terms of the Microsoft Bug Bounty Program and look forward to continuing to work with Faav in the future.” A boy and his bot The research began on August 25 when Antares found Titan’s public API. For the next 10 days, the human and bot tested the service’s JSON Web Token (JWT) authentication checks and email-formatted user principal names (UPNs), eventually finding an unsigned token that could reach Titan’s local user lookup - but not a UPN that Titan recognized. Early on September 5, Faav changed the unsigned token’s UPN from an email-formatted identity to admin. Titan recognized it as a local username, resolved it to local user ID 1, which held an admin role, and allowed him to run SQL. The takeaway, according to Faav: Titan validated the contents of the JWT (tenant, audience, app ID, user) but never verified the signature, the most important part of any authentication check. The authentication checks felt like a hotel where every door had a working keycard reader, but any keycard unlocked any room. Despite all the access-control logic existing in the app, the one missing piece made it all pointless. If you’re a developer (or coding agent) reading this, the most important takeaway from this post is to make sure you verify signatures above all else when building auth. This gave Faav access to Titan’s platform metadata database, and from there he could query application tables directly. The metadata contained: About 25,000 account and email records. 17,990 employee email records. 15,001 employee organization records. 355 database configurations. 20,979 virtual-dataset SQL definitions. 24,569 dashboards, 425,891 charts, and 27,347 dataset definitions. Titan’s user and usage directory exposed employee job titles, departments, and management hierarchy, which the researcher notes could be useful for social-engineering attacks - “though I never tested or demonstrated that,” he added. He also found a Bing analytics sample and tested two rows that contained search info, identifiers, and high-level location information, such as country- or state-level details. Faav said the location values did not contain precise user locations. 17.3 trillion data rows Then he hit the jackpot, testing 56 routing values from an archived configuration and discovering 30 were still active. “Each routing value pointed to a backend configuration, and each configuration contained one or more databases, so the 30 live values resolved through 24 configurations to 17 connected analytics databases spanning 9,863 unique table names,” the bug hunter wrote. The total comes to about 17.3 trillion rows, which Faav says is a storage estimate derived from metadata and likely includes historical, duplicated, and derived data. “But quite the high number nonetheless.” Between September 6 and September 8, Microsoft asked the teen to stop testing and requested his IP address to confirm no nefarious activity beyond the bug bounty research. A day later, Redmond locked down the endpoint and told Faav the “report prompted immediate investigation and remediation to address the remaining exposure.” Microsoft awarded the bug hunter $5,000 for his work on September 17.®
Babička Alenka už jednou zatopila šmejdům u podvodných volání • Teď pomůže při odhalování běžných praktik podvodníků přes WhatsApp • Napsat jí může opravdu každý, stačí jen naskenovat QR kód zobrazený výše
** Babička Alenka už jednou zatopila šmejdům u podvodných volání ** Teď pomůže při odhalování běžných praktik podvodníků přes WhatsApp ** Napsat jí může opravdu každý, stačí jen naskenovat QR kód zobrazený výše
More than 543,000 credentials exposed in public GitHub repositories were still valid in July despite the platform's security measures to prevent accidental leaks of sensitive data. [...]
Průlet filmovým děsem od dvacátých let minulého století do současnosti. Nejstrašidelnější horory, které prověřil čas, i tituly, které se snaží tento žánr se všemi jeho odnožemi posouvat dál.
Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team.
The attack exploits CVE-2026-73570 (CVSS score: 8.9), an unauthenticated operating system command injection flaw that can lead to remote code execution when Simple Network Management Protocol Ravie Lakshmananhttp://www.blogger.com/profile/ [email protected]
Microsoft před koncem září zahájil distribuci Windows 11 26H2. • V první vlně se aktualizace nabídne jen některým počítačům. • Nová hlavní verze spotřebitelům nenabízí žádné novinky.
Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content.
"Once executed, the legitimate MSP360 installer, distributed under a deceptive file name established remote management access on affected Ravie Lakshmananhttp://www.blogger.com/profile/ [email protected]
Sledujeme nové funkce, které s aktualizacemi přibývají do oblíbené mobilní mapové a navigační aplikace Mapy.com od českého Seznamu.
|