Agregátor RSS
CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS
V GTA 6 zažijeme hurikány i lov legendárních zvířat. Mrkněte na novou várku obrázků ze hry
Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
Cisco warns of new SD-WAN zero-day exploited in attacks
Apple má nabito i na zbytek roku. Brzy odhalí další tři zařízení včetně zcela nového produktu
Je skoro zázrak, že se to letadlo nerozpadlo. Podívejte se na simulaci ranního pokusu o únos letu FZ1073
RECENZE: ASUS ROG GR70 Mini PC - aneb malá krabička s vysokým výkonem
Trump’s answer to AI’s image problem: Industry self-regulation and a new name
US President Donald Trump has ordered the federal government to call artificial intelligence “Super Intelligence,” while keeping the technology’s legal definition unchanged and relying on industry to set the rules for its use.
In an executive order, the White House administration said modern systems “far exceed what was envisioned when the term ‘Artificial Intelligence’ first came into use,” adding they “increasingly represent not merely artificial intelligence, but a new era of Super Intelligence.”
“It is therefore the policy of my Administration that, to the maximum extent permitted by law, the executive branch shall use the terms ‘Super Intelligence’ and ‘SI’ in place of ‘Artificial Intelligence’ and ‘AI’,” Trump ordered.
The executive branch “will not acknowledge” the older terms in any applicable setting, the order stated.
Yet the order defines the new term using the old one. Section 3 of the order says Super Intelligence means the technologies and systems covered by the statutory definition of artificial intelligence in 15 U.S.C. 9401(3).
That equivalence may not last. The order gives the White House 60 days to propose a new legal definition.
Trump also put the new name to use immediately. On the same day, he and the leaders of six technology companies signed the “White House Accord on Super Intelligence,” a voluntary set of safety commitments for frontier models, which Trump posted on Truth Social.
A voluntary accord, no enforcementThe accord, subtitled “Joint Commitment on Frontier Responsibilities,” carries the signatures of Sundar Pichai of Google, Dario Amodei of Anthropic, Mark Zuckerberg of Meta, Greg Brockman of OpenAI, Elon Musk of xAI and Jensen Huang of Nvidia, alongside Trump’s. Microsoft and Amazon, two of the seven companies that made voluntary AI commitments to the Biden White House according to a July 2023 White House fact sheet, do not appear on the new accord.
Companies that train and deploy frontier models need “robust internal processes and controls” to ensure their technology behaves as intended, the signatories wrote in the accord.
The document sets out four layers of controls and audits. The first is internal monitoring of model capabilities and alignment in areas including cybersecurity, biosecurity and chemical threats. The other three are an internal team to verify those controls, an independent external auditor or evaluator, and an independent committee of the board of directors to oversee the process.
The accord does not name auditors, set deadlines or require companies to disclose audit findings to customers or regulators.
The signatories said they “believe each company should implement” the four layers. Codifying the steps into laws or regulations “may make sense” over time, they added.
The accord refers to “frontier models” in its commitments, with only its title adopting the term “Super Intelligence” mandated by the new order.
60 days to put terminology in orderThe Executive Order on Super Intelligence directs the White House’s top science and technology adviser to propose legislation for a new federal definition within 60 days, putting the deadline at November 28.
The new definition must reflect the capabilities of frontier systems, which Trump described in the order as doing “much more than imitate or automate discrete aspects of human intelligence.”
The proposal must assess whether the new definition should modify, expand upon or supersede the statutory definition of artificial intelligence, the order said. It must also propose amendments to existing laws that reference AI.
Until then, the current definition applies unless superseded by presidential action or an Act of Congress, according to the order. Changing the statutory definition itself would require Congress, the order added.
For now, the rename covers official correspondence, websites, reports, policy documents and other non-statutory documents, the order stated. Previously issued regulations, contracts and grants do not need to be altered, it added.
The order does not address vendor proposals, solicitation responses or product documentation that use the older terms.
This article first appeared on CIO.
AI's Third Wave: Coworkers Break the Security Model That Worked for Agents
Apple issues urgent iOS patch as it navigates the spyware arms race
If you’ve not done so recently, you should update your Apple systems now as the company continues to fight sophisticated, targeted hacks. The latest patch protects against what the company called “an extremely sophisticated attack against specific targeted individuals.”
Apple recently published an emergency security patch for users on iOS 26 and iPadOS 26 to fix the zero-click vulnerability (CVE-2026-86950), described as an “out-of-bounds write issue” in CoreGraphics. A patch was also made for macOS Sequoia.
This was far from being a friendly vulnerability, as it could impact affected systems with no action on behalf of the user, hence its status as a “zero-click” attack. In this case it means that just the action of “processing a maliciously crafted file” could lead to arbitrary code execution. Apple said it was aware of a report that the issue could have been exploited in a targeted attack on older versions of iOS.
Apple did not specify how the attack is delivered, but SecurityWeek surmised it may have been delivered using the web, email, or messaging apps and that simply previewing the malicious file could have enabled the attack, no click required. The vulnerability impacts a range of Apple devices, including multiple generations of iPad, Macs, and iPhones back to iPhone 11.
A pattern of sophisticated exploitsWe don’t know how this exploit was used. Apple said it learned of the incident thanks to a tip-off from Meta’s product security team. It follows a similar incident in 2025 when a vulnerability in WhatsApp may have been exploited alongside another Apple flaw in zero-click targeted attacks against under 200 people. Meta has not said if this latest flaw was used via WhatsApp but described the discovery as part of its “routine security work.”
This attack is the latest in a long, long line of exploits made against Apple’s systems. Apple’s description of this attack strongly suggests its use in an advanced operation against chosen targets. Subsequent to the patch, blockchain security firm SlowMist suggested it had identified iOS exploitation activity targeting sensitive wallet data, which illustrates the danger of zero-click attacks. In response to the flaw, the US Cybersecurity and Infrastructure Security Agency (CISA) gave federal agencies three days to apply the patch and told them to conduct forensic tests to see if their systems had been at all compromised as a result of the flaw.
The spyware arms raceApple and others across the space face an intensely challenging threat environment, one that’s only becoming worse as international relations fray and state, state-adjacent, and criminal actors intensify their attempts to subvert security. It was only in August 2026 that Apple warned customers across 110 countries that they may have been targeted by this level of sophisticated attack, sending Threat Warnings to each individual its systems showed to have been targeted.
This kind of security is a work in progress, made a lot harder by the fact that unfriendly governments, state-adjacent spyware services, and criminal gangs are in position to pay security researchers much more money for a successful zero-day attack than Apple’s security bounty scheme can possibly reach.
Toughen up, just toughen upThat reality is precisely why any Apple user or admin — particularly in any kind of regulated space, health, defense, energy, or anywhere, really — must be vigilant. All the usual mitigations should be in place:
- Update your Apple devices to the latest available security updates.
- Never install apps from unknown or untrusted sources.
- Don’t open suspicious links in Safari or in-app browsers.
- Don’t open files, links or follow app installation prompts unless you are certain where the prompts of files came from.
It’s also important to understand the changing nature of the threat environment. Artificial intelligence has become a double-edged sword in tech security, enabling hackers to identify flaws on the one hand, enabling security researchers to do the same thing on the other. The problem is that the rate of discovery has also increased, stretching the resources of platform security teams to verify and remediate flaws as they’re found. Apple is responding to this difficult new realty and this year began accelerating the release of security updates specifically to counter AI-assisted hacking.
If you receive one of Apple’s Threat Warnings or work in a high-risk role that may be of interest to sophisticated spyware customers, then you should use Lockdown Mode, which the US FBI this year tried and failed to break the security of.
“We are not aware of any successful mercenary spyware attacks against a Lockdown Mode-enabled Apple device,” Apple spokesperson Sarah O’Rourke said at the time.
All the same, the threat environment is intense, and staying informed is becoming a critical component to that defense.
Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSky, LinkedIn, or Mastodon.
Microsoft to block Entra ID script injection attacks starting October
TeamViewer urges users to patch severe flaws “as soon as possible”
Know Your Enemy: Browser-Based Attack Techniques in 2026
Nejdražší vibrace všech dob. Apple má za porušení patentů na hmatovou odezvu zaplatit 122 miliard korun
AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub
Cloudflare plans to issue quantum-safe TLS certificates
Cloudflare said Tuesday it plans to issue quantum-proof TLS certificates, making it one of the first authorities to issue such certificates, which use a form of cryptography that is widely believed to withstand attacks from quantum computers.
The Internet infrastructure provider said it will use an open source platform that issues both classic TLS certificates and a post-quantum equivalent known as Merkle Tree Certificates. The hybrid certificates will be free to both paying and non-paying users. To help build the massive system and establish ubiquity across the sprawling TLS ecosystem, Cloudflare will be acquiring an already trusted certificate root from CA GlobalSign. Cloudflare said the move will let millions of websites use post-quantum certificates at the flip of a switch and without incurring any increased performance overhead.
Fundamental architectural changes aheadCloudflare’s plans are part of a major overhaul in the web public key infrastructure (WebPKI) required to make website encryption and authentication safe for the coming post-quantum age. A major challenge is using quantum-proof signatures that can be easily transmitted during web requests and recorded in transparency logs to ensure counterfeit certificates aren't assigned to websites. The makeover will take years to complete, because it requires the work of an untold number of engineers who design operating systems, browsers, certificate authorities, and Internet infrastructure.
Bitget hacked via zero-day in third-party security products
- « první
- ‹ předchozí
- …
- 27
- 28
- 29
- 30
- 31
- 32
- 33
- 34
- 35
- …
- následující ›
- poslední »



