Agregátor RSS

CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS

Bleeping Computer - 30 Září, 2026 - 17:49
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition. [...]
Kategorie: Hacking & Security

Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager

The Hacker News - 30 Září, 2026 - 17:24
Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an advisory on September 30. The flaw, CVE-2026-76504, could allow a remote attacker with no login access to use the Manager's API as the admin user. Fixed releases are available, and there is no workaround. It carries a Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures

The Hacker News - 30 Září, 2026 - 17:00
Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware. Huntress, which observed the activity in late September 2026, said it marks the abuse of yet another feature in trusted artificial intelligence (AI) platforms. Prior campaigns have weaponized shared Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Cisco warns of new SD-WAN zero-day exploited in attacks

Bleeping Computer - 30 Září, 2026 - 16:46
Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges. [...]
Kategorie: Hacking & Security

Apple má nabito i na zbytek roku. Brzy odhalí další tři zařízení včetně zcela nového produktu

Živě.cz - 30 Září, 2026 - 16:45
Po dlouhých letech dorazí nová Apple TV a HomePod mini. • Apple chystá i domácí Home Hub s displejem. • Jde o reakci na podobná zařízení od Googlu a Amazonu.
Kategorie: IT News

Je skoro zázrak, že se to letadlo nerozpadlo. Podívejte se na simulaci ranního pokusu o únos letu FZ1073

Živě.cz - 30 Září, 2026 - 16:43
Sociální sítě se během dne zaplnily záběry z pokusu o ranní únos linky FZ1073 na trase z Dubaje do Tel Avivu. Samotný souboj v kabině doprovázel poměrně divoký manévr a je svým způsobem zázrak, že letadlo nehavarovalo. Boeing 737 MAX 8 v barvách aerolinek Flydubai se po 2,5 hodinách klidného letu ...
Kategorie: IT News

RECENZE: ASUS ROG GR70 Mini PC - aneb malá krabička s vysokým výkonem

CD-R server - 30 Září, 2026 - 16:33
Nebyl by to ASUS, pokud by nedošlo na výrobu výkonného miniPC, které zvládne krmit až pět monitorů. Dnes se na jedno takové podíváme.
Kategorie: IT News

Trump’s answer to AI’s image problem: Industry self-regulation and a new name

Computerworld.com [Hacking News] - 30 Září, 2026 - 16:21

US President Donald Trump has ordered the federal government to call artificial intelligence “Super Intelligence,” while keeping the technology’s legal definition unchanged and relying on industry to set the rules for its use.

In an executive order, the White House administration said modern systems “far exceed what was envisioned when the term ‘Artificial Intelligence’ first came into use,” adding they “increasingly represent not merely artificial intelligence, but a new era of Super Intelligence.”

“It is therefore the policy of my Administration that, to the maximum extent permitted by law, the executive branch shall use the terms ‘Super Intelligence’ and ‘SI’ in place of ‘Artificial Intelligence’ and ‘AI’,” Trump ordered.

The executive branch “will not acknowledge” the older terms in any applicable setting, the order stated.

Yet the order defines the new term using the old one. Section 3 of the order says Super Intelligence means the technologies and systems covered by the statutory definition of artificial intelligence in 15 U.S.C. 9401(3).

That equivalence may not last. The order gives the White House 60 days to propose a new legal definition.

Trump also put the new name to use immediately. On the same day, he and the leaders of six technology companies signed the “White House Accord on Super Intelligence,” a voluntary set of safety commitments for frontier models, which Trump posted on Truth Social.

A voluntary accord, no enforcement

The accord, subtitled “Joint Commitment on Frontier Responsibilities,” carries the signatures of Sundar Pichai of Google, Dario Amodei of Anthropic, Mark Zuckerberg of Meta, Greg Brockman of OpenAI, Elon Musk of xAI and Jensen Huang of Nvidia, alongside Trump’s. Microsoft and Amazon, two of the seven companies that made voluntary AI commitments to the Biden White House according to a July 2023 White House fact sheet, do not appear on the new accord.

Companies that train and deploy frontier models need “robust internal processes and controls” to ensure their technology behaves as intended, the signatories wrote in the accord.

The document sets out four layers of controls and audits. The first is internal monitoring of model capabilities and alignment in areas including cybersecurity, biosecurity and chemical threats. The other three are an internal team to verify those controls, an independent external auditor or evaluator, and an independent committee of the board of directors to oversee the process.

The accord does not name auditors, set deadlines or require companies to disclose audit findings to customers or regulators.

The signatories said they “believe each company should implement” the four layers. Codifying the steps into laws or regulations “may make sense” over time, they added.

The accord refers to “frontier models” in its commitments, with only its title adopting the term “Super Intelligence” mandated by the new order.

60 days to put terminology in order

The Executive Order on Super Intelligence directs the White House’s top science and technology adviser to propose legislation for a new federal definition within 60 days, putting the deadline at November 28.

The new definition must reflect the capabilities of frontier systems, which Trump described in the order as doing “much more than imitate or automate discrete aspects of human intelligence.”

The proposal must assess whether the new definition should modify, expand upon or supersede the statutory definition of artificial intelligence, the order said. It must also propose amendments to existing laws that reference AI.

Until then, the current definition applies unless superseded by presidential action or an Act of Congress, according to the order. Changing the statutory definition itself would require Congress, the order added.

For now, the rename covers official correspondence, websites, reports, policy documents and other non-statutory documents, the order stated. Previously issued regulations, contracts and grants do not need to be altered, it added.

The order does not address vendor proposals, solicitation responses or product documentation that use the older terms.

This article first appeared on CIO.

Kategorie: Hacking & Security

AI's Third Wave: Coworkers Break the Security Model That Worked for Agents

Bleeping Computer - 30 Září, 2026 - 16:01
Persistent AI coworkers may operate continuously with standing access, creating identity risks that existing security models were not designed to handle. Token Security explains why these agents need their own identities, owners, scoped permissions, and lifecycle controls. [...]
Kategorie: Hacking & Security

Apple issues urgent iOS patch as it navigates the spyware arms race

Computerworld.com [Hacking News] - 30 Září, 2026 - 15:50

If you’ve not done so recently, you should update your Apple systems now as the company continues to fight sophisticated, targeted hacks. The latest patch protects against what the company called “an extremely sophisticated attack against specific targeted individuals.” 

Apple recently published an emergency security patch for users on iOS 26 and iPadOS 26 to fix the zero-click vulnerability (CVE-2026-86950), described as an “out-of-bounds write issue” in CoreGraphics. A patch was also made for macOS Sequoia. 

This was far from being a friendly vulnerability, as it could impact affected systems with no action on behalf of the user, hence its status as a “zero-click” attack. In this case it means that just the action of “processing a maliciously crafted file” could lead to arbitrary code execution. Apple said it was aware of a report that the issue could have been exploited in a targeted attack on older versions of iOS.

Apple did not specify how the attack is delivered, but SecurityWeek surmised it may have been delivered using the web, email, or messaging apps and that simply previewing the malicious file could have enabled the attack, no click required. The vulnerability impacts a range of Apple devices, including multiple generations of iPad, Macs, and iPhones back to iPhone 11.

A pattern of sophisticated exploits 

We don’t know how this exploit was used. Apple said it learned of the incident thanks to a tip-off from Meta’s product security team. It follows a similar incident in 2025 when a vulnerability in WhatsApp may have been exploited alongside another Apple flaw in zero-click targeted attacks against under 200 people. Meta has not said if this latest flaw was used via WhatsApp but described the discovery as part of its “routine security work.”

This attack is the latest in a long, long line of exploits made against Apple’s systems. Apple’s description of this attack strongly suggests its use in an advanced operation against chosen targets. Subsequent to the patch, blockchain security firm SlowMist suggested it had identified iOS exploitation activity targeting sensitive wallet data, which illustrates the danger of zero-click attacks. In response to the flaw, the US Cybersecurity and Infrastructure Security Agency (CISA) gave federal agencies three days to apply the patch and told them to conduct forensic tests to see if their systems had been at all compromised as a result of the flaw.

The spyware arms race

Apple and others across the space face an intensely challenging threat environment, one that’s only becoming worse as international relations fray and state, state-adjacent, and criminal actors intensify their attempts to subvert security. It was only in August 2026 that Apple warned customers across 110 countries that they may have been targeted by this level of sophisticated attack, sending Threat Warnings to each individual its systems showed to have been targeted. 

This kind of security is a work in progress, made a lot harder by the fact that unfriendly governments, state-adjacent spyware services, and criminal gangs are in position to pay security researchers much more money for a successful zero-day attack than Apple’s security bounty scheme can possibly reach.

Toughen up, just toughen up

That reality is precisely why any Apple user or admin — particularly in any kind of regulated space, health, defense, energy, or anywhere, really — must be vigilant. All the usual mitigations should be in place:

  • Update your Apple devices to the latest available security updates. 
  • Never install apps from unknown or untrusted sources. 
  • Don’t open suspicious links in Safari or in-app browsers.
  • Don’t open files, links or follow app installation prompts unless you are certain where the prompts of files came from. 

It’s also important to understand the changing nature of the threat environment. Artificial intelligence has become a double-edged sword in tech security, enabling hackers to identify flaws on the one hand, enabling security researchers to do the same thing on the other. The problem is that the rate of discovery has also increased, stretching the resources of platform security teams to verify and remediate flaws as they’re found. Apple is responding to this difficult new realty and this year began accelerating the release of security updates specifically to counter AI-assisted hacking.

If you receive one of Apple’s Threat Warnings or work in a high-risk role that may be of interest to sophisticated spyware customers, then you should use Lockdown Mode, which the US FBI this year tried and failed to break the security of. 

“We are not aware of any successful mercenary spyware attacks against a Lockdown Mode-enabled Apple device,” Apple spokesperson Sarah O’Rourke said at the time.

All the same, the threat environment is intense, and staying informed is becoming a critical component to that defense.

Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSky, LinkedIn, or Mastodon.

Kategorie: Hacking & Security

Microsoft to block Entra ID script injection attacks starting October

Bleeping Computer - 30 Září, 2026 - 15:37
Microsoft has reminded customers that the Entra ID authentication system will get better protection against external script injection attacks starting next month. [...]
Kategorie: Hacking & Security

TeamViewer urges users to patch severe flaws “as soon as possible”

Bleeping Computer - 30 Září, 2026 - 14:25
Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software. [...]
Kategorie: Hacking & Security

Know Your Enemy: Browser-Based Attack Techniques in 2026

The Hacker News - 30 Září, 2026 - 13:58
Given that the browser is where business apps are accessed and used, it makes sense that attacks are happening there too. Most breaches today begin in a browser session. Often, they never leave it, with the entire attack chain from initial access to exfiltration playing out in the browser. Here are the six most dangerous techniques that should be on every security team's radar in 2026. 1. [email protected]
Kategorie: Hacking & Security

Nejdražší vibrace všech dob. Apple má za porušení patentů na hmatovou odezvu zaplatit 122 miliard korun

Živě.cz - 30 Září, 2026 - 13:45
Porota v San Diegu rozhodla, že Apple při vývoji hmatové odezvy porušil dva cizí patenty, a přiznala firmě Taction odškodnění přes 5,7 miliardy dolarů, tedy zhruba 122 miliard korun. Apple s verdiktem nesouhlasí a chystá odvolání.
Kategorie: IT News

AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub

The Hacker News - 30 Září, 2026 - 13:30
AI coding agents asked to share screenshots of code changes for review have put internal company images in public GitHub repositories, security company Glow said. Its researchers found more than 13,000 internal images from developers at over 300 organizations, including customer billing records and screens of features not yet released. In most cases, they sat under developers' personal accountsSwati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Cloudflare plans to issue quantum-safe TLS certificates

Ars Technica - 30 Září, 2026 - 13:15

Cloudflare said Tuesday it plans to issue quantum-proof TLS certificates, making it one of the first authorities to issue such certificates, which use a form of cryptography that is widely believed to withstand attacks from quantum computers.

The Internet infrastructure provider said it will use an open source platform that issues both classic TLS certificates and a post-quantum equivalent known as Merkle Tree Certificates. The hybrid certificates will be free to both paying and non-paying users. To help build the massive system and establish ubiquity across the sprawling TLS ecosystem, Cloudflare will be acquiring an already trusted certificate root from CA GlobalSign. Cloudflare said the move will let millions of websites use post-quantum certificates at the flip of a switch and without incurring any increased performance overhead.

Fundamental architectural changes ahead

Cloudflare’s plans are part of a major overhaul in the web public key infrastructure (WebPKI) required to make website encryption and authentication safe for the coming post-quantum age. A major challenge is using quantum-proof signatures that can be easily transmitted during web requests and recorded in transparency logs to ensure counterfeit certificates aren't assigned to websites. The makeover will take years to complete, because it requires the work of an untold number of engineers who design operating systems, browsers, certificate authorities, and Internet infrastructure.

Read full article

Comments

Bitget hacked via zero-day in third-party security products

Bleeping Computer - 30 Září, 2026 - 13:11
Cryptocurrency exchange Bitget revealed today that attackers who stole $387.5 million last week breached its systems after exploiting a zero-day flaw in third-party security products. [...]
Kategorie: Hacking & Security
Syndikovat obsah