Agregátor RSS

Anthropic rolls out Claude Fable 5, but it's available for a limited time

Bleeping Computer - 10 Červen, 2026 - 04:03
Anthropic has begun rolling out a new model called "Fable," which is based on the same underlying model as Mythos, its most powerful AI model class. [...]
Kategorie: Hacking & Security

Vývoj operačního systému Redox OS (05/2026)

AbcLinuxu [zprávičky] - 10 Červen, 2026 - 03:36
Na čem pracují vývojáři v Rustu napsaného mikrokernelového unixového operačního systému Redox OS (Wikipedie)? Byl publikován přehled vývoje za květen. Vypíchnout lze nový scheduler EEVDF nebo port desktopového prostředí Xfce na Redox OS.
Kategorie: GNU/Linux & BSD

Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges

Bleeping Computer - 10 Červen, 2026 - 01:11
A security researcher has released a new Microsoft Defender zero-day exploit named "RoguePlanet" just hours after Microsoft fixed two previously disclosed flaws during June 2026 Patch Tuesday. [...]
Kategorie: Hacking & Security

AI is making Patch Tuesday (kinda) fun again

The Register - Anti-Virus - 10 Červen, 2026 - 00:49
Microsoft set a record with its June Patch Tuesday release, addressing 206 CVEs across its products and shipping fixes for them, with 38 deemed critical and the rest important. Three are listed as publicly known, but none (so far) have been exploited in the wild. We have no idea how many of these June bugs were uncovered using AI tools. Unlike last month’s patching event, when Redmond disclosed its agentic bug-hunting system found 16 of the 137 vulnerabilities, there’s no word on any AI assists for new releases. Still, it’s safe to assume AI played a major role. As Tom Gallagher, VP of engineering at Microsoft Security Response Center, said about May's Patch Tuesday with a whopping 30 critical flaws: “We expect releases to continue trending larger for some time.” June’s Patch Tuesday proved Gallagher correct, surpassing May in both overall volume and critical bugs. “I’ve been counting CVEs on Patch Tuesday since 2017, and this is by far the largest monthly release in that time,” Zero Day Initiative’s bug hunter in chief Dustin Childs said in his review. “It is extraordinary that Microsoft can produce so many patches in a single month, but it does raise concerns,” he added, asking, as we did: How many were found via AI? And: “How many patches were generated using AI to assist in coding or testing? What quality issues may exist in these patches? And likely most importantly, is this the new normal?” Childs noted that May and April also saw mega releases. “Should sysadmins adjust their processes for prioritization and patch deployment based on this new volume of updates? Unfortunately, Microsoft is not providing those answers right now,” he wrote, adding in this fun fact: “The current number of CVEs shipped by Microsoft this year exceeds the total number of CVEs shipped in all of 2018.” Wowza. While it’s fun to watch from a purely speculative standpoint, as in: "Will Microsoft top 300 next month?", our thoughts and prayers are nonetheless with sysadmins and vulnerability management teams drowning in the AI-induced vulnpocalypse by now. None of the Patch Tuesday security holes are listed as under attack – at least not yet – but three are listed as publicly known. Let’s take a look at those first. Three known vulnerabilities CVE-2026-49160 is an HTTP.sys denial of service vulnerability that we wrote about earlier this month. Calif researcher Quang Luong discovered the attack with an assist from OpenAI's Codex agent, named it HTTP/2 Bomb, and said it exploits the HTTP/2 header compression algorithm by sending thousands of tiny messages to the server, forcing it to rapidly allocate memory and ultimately crash. At the time, a Microsoft spokesperson told The Register that Redmond was “aware and actively investigating appropriate mitigations.” On Tuesday, the tech giant fixed the security issue by introducing a new MaxHeadersCount registry setting, which allows users to limit the number of headers included in HTTP/2 and HTTP/3 requests, and should prevent denial-of-service attacks. CVE-2026-50507, a security feature bypass bug in Windows BitLocker, is the second CVE listed as publicly disclosed, and “exploitation more likely.” An attacker with physical access to the vulnerable system could bypass the BitLocker Device Encryption feature and gain access to the device's encrypted data, according to the advisory. This flaw also seems to be a patch for one of the zero-days dropped in the ongoing war between Microsoft and a disgruntled bug hunter known as Nightmare Eclipse - likely the YellowKey vulnerability disclosed in May. Nightmare has published details about and in some cases, full proof-of-concept exploit code for six zero-days, and promised a “bone shattering” release on June 14. The third publicly known bug, CVE-2026-45586, is a Windows Collaborative Translation Framework (CTFMON) elevation of privilege vulnerability that can be abused by an authorized attacker to elevate privileges locally and gain SYSTEM access. From there, miscreants could deploy malware, steal data, and move laterally through the victim's environment - so patch this one sooner. Plus these two (of 38) critical bugs In addition to those three known vulnerabilities that made the rounds before Microsoft issued a patch, a couple of critical-rated 9.8 security flaws are worth highlighting this month. The first, CVE-2026-45657, is a Windows kernel remote code execution (RCE) bug that allows remote, unauthenticated attackers to run code with system-level privileges without any user interaction. It’s due to an error in how the Windows kernel processes some TCP/IP data, and can be exploited by sending malicious network packets to a vulnerable Windows system, thus triggering the flaw. While it’s listed as “exploitation less likely” by Redmond, we like Childs’ response. “Rest assured that every researcher and bug shop on the planet is reversing this patch right now trying to create an exploit,” he said. “Test and deploy this patch quickly.” CVE-2026-47291, an HTTP.sys RCE vulnerability that also earned a 9.8 CVSS rating, deserves attention as it can also be triggered with zero user interaction and Microsoft says it’s “more likely” to be exploited. “This vulnerability creates severe business risk because HTTP.sys is used by Windows services that process HTTP traffic,” Alex Vovk, CEO and co-founder of patch-management vendor Action1, told The Register. “A successful attack could lead to server takeover, malware deployment, data theft, service disruption, and lateral movement across the environment. Internet-facing systems are especially exposed.” The good news: systems using the Windows HTTP stack’s default MaxRequestBytes registry value are not affected. In the advisory, Redmond provides detailed instructions on how to edit registry settings, which can buy admins some time (and security) while deploying the patch. ®
Kategorie: Viry a Červi

Nemoc během dovolené. Dny volna si můžete v práci vrátit

Lupa.cz - články - 10 Červen, 2026 - 00:00
Nemoc vám může překazit nejen zájezd, ale i čerpání dovolené v práci. Kdy se dny volna nepočítají a jaké potvrzení musíte dodat zaměstnavateli?
Kategorie: IT News

Žáci a studenti: Kdo si může vydělávat na letní prázdninové brigádě a kdo i v průběhu školního roku

Lupa.cz - články - 10 Červen, 2026 - 00:00
Dlouho platilo, že brigádu si mohou sjednávat mladí lidé od 15 let a vykonávat ji mohou až po ukončení povinné školní docházky. Od loňska ale mohou na letní brigádu i čtrnáctiletí.
Kategorie: IT News

Paperless-ngx: archiv dokumentů stojící na metadatech a zálohách

ROOT.cz - 10 Červen, 2026 - 00:00
Paperless-ngx převádí skeny, faktury a smlouvy do lokálního prohledávatelného archivu s OCR, metadaty a plnotextovým hledáním. Na domácím serveru nebo NASu může nahradit hromadu PDF v adresářích.
Kategorie: GNU/Linux & BSD

Softwarová sklizeň (10. 6. 2026): připojte se ke svému automobilu

ROOT.cz - 10 Červen, 2026 - 00:00
Spustíme AI agenta přímo v terminálu, zorganizujeme projektový vývoj v lehkém lokálním trackeru, přeneseme zvuk do bezdrátových rendererů a diagnostikujeme auto přes sériový adaptér.
Kategorie: GNU/Linux & BSD

Mikrovlnka RapidDestroyer zlikvidovala během testů 80 dronů

OSEL.cz - 10 Červen, 2026 - 00:00
Britská společnost Thales (UK) nedávno otestovala svou mikrovlnnou zbraň RapidDestroyer ve vylepšené verzi se čtyřmi anténami a umělou inteligencí. Je sice určená proti celým hejnům dronů, ale v tomto případě šlo o testy s jednotlivými drony, v nichž vývojáři sledovali, jak mikrovlnný úder likviduje zasažené drony.
Kategorie: Věda a technika

Stezkami přírodovědného poznání v českých zemích

OSEL.cz - 10 Červen, 2026 - 00:00
Nedávno vyšla kniha s tímto názvem a s podtitulem Atlas exkurzí po pamětních místech vědy v českých zemích. Krom toho je na webu volně přístupná rozsáhlá aplikace Živá mapa dějin přírodních věd v českých zemních, s velkým množstvím dalších aktivních odkazů.
Kategorie: Věda a technika

Toxické Azory

OSEL.cz - 10 Červen, 2026 - 00:00
Z pohledu toxikologa jsou Azorské ostrovy na první pohled docela nuda. Nežijí zde žádní hadi ani štíři, a nenajdete tu ani chemičku chrlící průmyslové jedy. Pokud pomineme několik dráždivých endemických rostlin, například místní pryšec azorský (Euphorbia azorica), patří k nejvýznamnějším toxikologickým hrozbám invazní libora měňavá (Lantana camara).
Kategorie: Věda a technika

Hawkingova hvězda: Co se stane, když do hvězdy nabourá primordiální černá díra?

OSEL.cz - 10 Červen, 2026 - 00:00
Pokud se vesmírem potulují primordiální černé díry planetkové až lunární velikosti, mohla by je občas pohltit hvězda, která se jim připlete do cesty. Jak taková nešťastná hvězda asi skončí? A co bychom mohli v takovém případě pozorovat? Odpověď nabízejí modely vývoje hvězd s magnetohydrodynamickými simulacemi.
Kategorie: Věda a technika

Intel zrušil šestijádrový Nova Lake, nahradí ho starší WildCat Lake(-refresh)

CD-R server - 10 Červen, 2026 - 00:00
Segment, který měl Intel původně pokrýt šestijádrovou konfigurací Nova Lake, nakonec dostane starší WildCat Lake se zdvojnásobeným počtem velkých jader…
Kategorie: IT News

ServiceNow discloses security incident exposing customer data

Bleeping Computer - 9 Červen, 2026 - 23:34
ServiceNow is warning about a security incident after attackers exploited an unauthenticated access flaw through a vulnerable API endpoint, allowing them to query data from customer instances. [...]
Kategorie: Hacking & Security

OpenClaw AI agent found falling for phishing attacks, spills user data

Bleeping Computer - 9 Červen, 2026 - 23:20
Phishing simulation on an OpenClaw email agent with various configuration profiles showed that it was susceptible to tactics commonly used to compromise human users. [...]
Kategorie: Hacking & Security

Locked in heated rivalry with researcher, Microsoft fixes 0-day they disclosed

Ars Technica - 9 Červen, 2026 - 22:56

Microsoft on Tuesday released fixes for two high-severity zero-days that were disclosed by a researcher who has been locked in a testy beef with the software giant.

Nightmare Eclipse, the pseudonym the researcher goes by, released a handful of high-severity vulnerabilities in recent months, making them zero-days that had the potential to be exploited in the wild. The researcher has said the disclosures, which included proof-of-concept code, came after Microsoft reneged on an arrangement the two made regarding vulnerabilities they had discussed.

Disclosure drama

“But someone violated our agreement and left me homeless with nothing,” Nightmare Eclipse wrote in March. “They knew this will happen and they still stabbed me in the back anyways, this is their decision not mine.”

Read full article

Comments

Upozornění pro uživatele Asahi Linuxu: Neaktualizujte macOS na verzi 27 Golden Gate!

AbcLinuxu [zprávičky] - 9 Červen, 2026 - 22:39
Upozornění pro uživatele Asahi Linuxu: Neaktualizujte macOS na verzi 27 Golden Gate! Apple změnil detekci spouštěcích oddílů. Po aktualizaci oddíl s Asahi Linuxem nevidí. Snad je to jenom chyba.
Kategorie: GNU/Linux & BSD

SAP fixes critical flaws in NetWeaver and Commerce Cloud

Bleeping Computer - 9 Červen, 2026 - 21:36
SAP has released fixes for 15 vulnerabilities as part of its June 2026 Security Patch package, including four critical-severity flaws affecting SAP NetWeaver and SAP Commerce Cloud. [...]
Kategorie: Hacking & Security

Nextcloud adds Euro-Office to Hub workplace suite, expands AI assistant

Computerworld.com [Hacking News] - 9 Červen, 2026 - 20:50

MUNICH — Nextcloud has integrated Euro-Office into its workplace application suite, one of several updates to Nextcloud Hub unveiled on Tuesday that include a new compliance app for large organizations and a program to support developers building for its platform.

The announcements came during the company’s Nextcloud Summit 2026 here.

Euro-Office, announced in March, is billed as an open source, sovereign alternative to Microsoft Office for European organizations keen to reduce their reliance on US tech providers. It consists of four browser-based applications: a document editor, spreadsheet program, presentation tool, and a PDF editor — each enabling collaborative editing. Euro-Office documents can also be opened directly from the Nextcloud Files mobile app.

Nextcloud is one of several European companies that support Euro-Office, which is built on the open-source code base of OnlyOffice and distributed under the GNU Affero General Public License v3 (AGPL v3).

The integraton means Nextcloud users can now choose between two options in Nextcloud Office: Euro-Office and the existing Collabora integration. 

“Euro-Office uses a different architectural approach that can result in a better performance in the browser, a different user experience…, so it’s important that this option is available,” Jos Poortvliet, Nextcloud co-founder and vice president of communications, said at the Tuesday event.

Other changes in the Nextcloud Hub 26 Spring release include updates to Nextcloud‘s Talk video and voice meeting app, including AI noise suppression and the ability to start a call from any Nextcloud Hub app – an addition that will make collaborative editing easier, said Poortvliet. 

For Nextcloud Assistant, there are new AI agent capabilities. In addition to existing capabilities such as managing calendars and tasks, AI agents can now create cards in Nextcloud’s Deck task management app and update information in the Forms app.

There are also improvements to the AI assistant’s interface, which can be moved around to avoid blocking other applications and allow users to copy and paste text more easily without opening another tab. To meet EU AI Act requirements, Nextcloud will make it easier to see which  provider supplies the large language model (LLM) the Assistant runs on.

Nextcloud will also integrate the AI assistant directly into its Nextcloud Office suites via a sidebar chat interface, allowing users to address problems such as errors in the spreadsheet app.

NextCloud’s AI chat assistant is integrated into the company’s Office suites.


NextCloud

There’s also a new Governance app that helps large organizations — particularly governments and highly regulated industries — meet regulatory requirements with compliance tools to manage data held in Nextcloud Hub. It contains several features,  including sensitivity labels to control access rights; data retention and archive capabilities; and a legal hold option that preserves documents for legal purposes such as a court case.

The Governance app includes a Compliance Manager that provides a compliance score based on an organization’s regulatory requirements, and measures progress towards certain targets. Admins can also search and review documents shared by employees and generate audit reports for compliance. The Governance app is available to Nextcloud Enterprise customers.

Nextcloud also launched a program to support independent software providers interested in building apps on its platform. 

With AI making it easier for developers to build software that integrates with its platform, Nextcloud expects a 10-fold increase in the number of available apps — from 600 now to 6,000 over the next 12 months, according to Nextcloud CEO Frank Karlitschek.

Nextcloud promised to promote apps developed by partners in its App Store and sell subscriptions as part of the ISV program, as well as provide documentation and technical help to customers. In return, developers would provide guarantees to customers around security processes and long-term support.

“We can strengthen our ecosystem, the developers also make some money — because obviously we do a revenue share here — and we leverage the dynamics that we expect from AI coming very soon,” said Karlitschek.

Editor’s note: NextCloud paid for Matthew Finnegan’s travel and hotel costs for NextCloud Summit 2026, but had no editorial role in the creation of this story.

Kategorie: Hacking & Security

Microsoft releases Windows 10 KB5094127 extended security update

Bleeping Computer - 9 Červen, 2026 - 20:35
Microsoft has released the Windows 10 KB5094127 extended security update, which fixes the June 2026 Patch Tuesday vulnerabilities and adds new functionality to monitor the rollout of updated Secure Boot certificates that replace those expiring this month. [...]
Kategorie: Hacking & Security
Syndikovat obsah