Agregátor RSS

Kvantový spin poprvé pohnul centimetrovým objektem

OSEL.cz - 8 Říjen, 2026 - 00:00
Ať děláme co děláme, kvantové jevy zatím stále pozorujeme především u atomů a velmi malých částic. Vědci Okinawa Institute of Science and Technology udělali kvantové kouzlo v makrosvětě. Kvantová síla dokázala, byť nepatrně, pohnout objektem o velikosti centimetrů, tedy tělesem, na které už významně působí gravitace. Kdy se dočkáme skutečné Schrödingerovy kočky?
Kategorie: Věda a technika

Černobylské částice prozradily, že jaderné palivo je stále stabilní

OSEL.cz - 8 Říjen, 2026 - 00:00
Čtyři desetiletí po černobylské havárii analyzovali vědci šest mikroskopických vysoce radioaktivních částic, které unikly ze zničeného reaktoru. Ukázalo se, že jaderné palivo, které částice obsahují, je mnohem stabilnější, než se dosud předpokládalo. Výzkum přispěje k přesnějšímu odhadu zdravotních rizik radioaktivních částic.
Kategorie: Věda a technika

Desktopové procesory AMD na západních trzích zlevňují

CD-R server - 8 Říjen, 2026 - 00:00
Ryzen 7 9800X3D za $411, v bundlu s vodním chladičem za $429 nebo třeba Ryzen 5 5600X3D za $159. Zpráv o zvýhodněných nabídkách přibývá…
Kategorie: IT News

FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins

Bleeping Computer - 7 Říjen, 2026 - 23:28
The FBI is warning that FortiBleed attacks are still ongoing, targeting exposed Fortinet FortiGate firewalls and SSL VPN gateways and locking out legitimate administrators. [...]
Kategorie: Hacking & Security

X.Org X server 21.1.25 a Xwayland 24.1.14 řeší 12 bezpečnostních chyb

AbcLinuxu [zprávičky] - 7 Říjen, 2026 - 23:22
Nejnovější X.Org X server 21.1.25 a Xwayland 24.1.14 řeší 12 bezpečnostních chyb.
Kategorie: GNU/Linux & BSD

Hackers hijack Google domains after breaching ccTLD registries

Bleeping Computer - 7 Říjen, 2026 - 22:50
Hackers obtained unauthorized HTTPS certificates for several Google domains and hijacked domains in the country-code top-level domains (ccTLDs) for Ghana, American Samoa, and Sierra Leone after compromising third-party operators and modifying authoritative DNS records. [...]
Kategorie: Hacking & Security

Attackers hijacked top-level domains, minted fake security certs for Google and other orgs

The Register - Anti-Virus - 7 Říjen, 2026 - 21:38
Imagine going to a Google website at its correct URL, only to be redirected to a crim's illegitimate copy. Attackers hijacked top-level domains, allowing them to alter DNS records and mint fraudulent HTTPS certificates for several Google domains, and those belonging to other organizations. Google said it became aware of the series of attacks last week in the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) country-code top-level namespaces (ccTLDs). “During these hijacks, attackers modified authoritative DNS records and obtained unauthorized HTTPS certificates covering several Google domains, as well as domains belonging to other organizations,” Google security warned on Tuesday. Google did not say which specific domains or organizations were affected. The attacks did not compromise Google’s systems, and Chrome quickly blocked suspected counterfeit certificates across the affected ccTLDs - meaning Chrome browser users are already protected - according to the Chocolate Factory. “Due to the nature of the attacks, we have no reason to believe the Certification Authorities (CAs) that issued the impacted certificates did anything wrong,” the alert said. These types of attacks allow criminals to impersonate legitimate organizations and websites without triggering any browser security alerts. The attacker controls the traffic routing (via DNS) and the private key associated with the unauthorized certificate, which means they can potentially intercept or modify data sent by users to the impersonated site - and abuse the trusted organization's brand to distribute malware or conduct phishing attacks. “While Chrome took steps during these incidents to identify and block suspected unauthorized certificates across the affected ccTLDs, browser-side intervention should not be relied on to protect your users,” Google warned domain owners. “Due to the complexity of DNS hijacks, we cannot guarantee that our analysis identified every affected domain, nor do Chrome interventions reliably protect non-Chrome users.” To ensure that their domains and users are protected, Google recommends ongoing monitoring of Certificate Transparency (CT) logs across all of an organization’s domains, including parked or regional ccTLD properties. This provides near real-time alerts whenever someone obtains a certificate for one of your domains. And if you operate a domain in .gh, .sl, or .as, definitely review recent CT log entries for unexpected certificates. Organizations can also publish restrictive Certification Authority Authorization (CAA) DNS records, which allow domain owners to specify which CAs are permitted to issue certificates for their domains. While this won’t stop certificates from being issued during a DNS hijacking attack, it helps safeguard domains after DNS control is restored. Google recommends CAA policies that restrict issuance to specific authorized accounts and validation methods and prevent attackers from using cached validation state to mint new certificates after a hijacking ends.®
Kategorie: Viry a Červi

Microsoft ukázal Surface s čipem Nvidia RTX Spark a magnetickým USB-C. AI ve Windows už nebude pro ostudu

Živě.cz - 7 Říjen, 2026 - 21:11
Procesor RTX Spark se představil v červnu, teď na trh zamíří první notebooky. Microsoft zahájení prodeje svého modelu Surface Laptop Ultra doplnil i zásadními novinkami v podpoře AI ve Windows. Základní specifikace Surface Laptop Ultra známe už několik měsíců. Procesor RTX Spark (odpovídá GB10 v ...
Kategorie: IT News

Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains

The Hacker News - 7 Říjen, 2026 - 20:48
Attackers compromised three country-code top-level domains (ccTLDs) and obtained unauthorized HTTPS certificates for several Google domains, Google said on October 6. Google's own systems were not breached, but any domain ending in .gh (Ghana), .sl (Sierra Leone) or .as (American Samoa) was put at risk. With such a certificate, an attacker could pose as the real site over an encrypted Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

The Hacker News - 7 Říjen, 2026 - 19:43
Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised hosts. The campaign has been codenamed MALFEX by CloudSEK and Checkmarx. The activity is assessed to be the work of a lone threat actor who appears to have published 12 packages since August 2023, eight of which haveRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

AWS launches open-source AI agent sandbox to prevent YOLO mode disasters

The Register - Anti-Virus - 7 Říjen, 2026 - 19:42
AWS has offered multiple open-source strategies for holding AI agents accountable, and now it’s adding a full-on sandbox to this stack. Dubbed Strands Box, the new solution uses OS-level isolation and some of AWS’ other recent open-source AI control tools to, ostensibly, retain greater control over autonomous AI agents’ behavior. “Agents increasingly run in ‘YOLO mode,’ approving every action without human review,” the AWS team explained in its announcement. “The usual solution to this problem is a sandbox … but access is only part of what we want to control.” The problem with containers and microVMs typically used to isolate AI agents, as AWS explains it, is that their strong isolation doesn’t come with contextual rule enforcement. In other words, when a containerized or virtualized agent gets hold of a tool, there may be no stopping it from doing whatever it wants - like deleting a production database, or gaining access to the internet and doing dog knows what. That’s where the other open-source tools inside Strands Box come in: It uses the Dogwood Local Engine to give the policy engine in Box temporal awareness, so tool calls can be checked against not only what the agent wants to do, but what it’s already done. As one example, AWS noted that an agent could be allowed to post status updates to Slack, but no more than three times every ten minutes to prevent it from spamming its human operators. An AWS spokesperson further explained that Box could be used to control when an agent can perform a Git push, or it could be used to put a cap on API calls that could end up costing a small fortune. Additionally, Strands Box includes Strands Shell and Monty for Python, which expose shell and Python operations to the same Dogwood policy engine and event history, making agentic actions clearer to developers and allowing policies to account for what an agent is trying to do. AWS VP and distinguished engineer Marc Brooker, one of the folks behind Dogwood and Strands Box, explained to The Register that the interpreters are a key part of making agentic behavior more intelligible, which allows for devs to write more precise policies to prevent agents from taking bad actions. “Box’s Shell and Python interpreters expose operations such as file deletions, while its gateways expose API requests and tool calls,” Brooker told us in an email. “Policies can then account for the action being attempted and earlier activity.” Box, Brooker added, enforces those rules without trusting or relying on agents to actually follow instructions, which should ideally prevent them from running roughshod over their operators’ wishes. As for the reason behind AWS’ push to develop open-source tools like Dogwood, the Dogwood Local Engine, and Strands Box, Brooker said that AWS wants to find the right balance between boundaries and policies that prevent agentic AI disasters of the kind we regularly report. “Box enforces the policies developers configure, deterministically, and the agent can't talk its way around these rules,” Brooker explained, though he added that, even with properly configured permissions, an agentic action can still produce an unwanted result. “Developers remain responsible for deciding what access to grant and where human review is needed,” Brooker added - in other words, don’t let your YOLO mode go too YOLO. A bit of human oversight is still necessary. “Agent safety is an area where the industry still has significant work to do, and we're committed to continuing to invest in it, both inside the AWS cloud and in open source,” Brooker said. Strands Box supports any agent or harness one wants to confine within its walls and is available on GitHub now, though only for macOS for the time being. Linux support is in development, and AWS told us a Windows client is “on our radar,” but neither has a planned release date. Deployment to platforms like AgentCore, ECS, and Kubernetes is also planned. ®
Kategorie: Viry a Červi

US states sue popular kitmaker TP-Link over China risks

The Register - Anti-Virus - 7 Říjen, 2026 - 19:30
The attorneys general of Florida, Iowa, Montana, and Nebraska have sued ubiquitous networking and smart home tech maker TP-Link, alleging its security claims were misleading and it hadn't properly disclosed ties to China. The company has a large presence in US retail and the tech channel, especially in consumer routers, with stats from Circana asserting it had around 36.6 percent US market share by units and 31 percent by dollars in 2024. The complaint [PDF] accuses California-based TP-Link Systems, whose brand originated in Shenzhen, of deceptive and unfair marketing practices concerning its routers' security and its connections to China. It cites exploitation of TP-Link devices by Chinese and Russian state-backed hackers. The suit also claims TP-Link allegedly concealed facts about its "past and ongoing ties to the People's Republic of China," accuses it of having a supply chain that's reliant on PRC players, repeated firmware vulnerabilities, and being subject to Chinese laws that force companies to cooperate with state intelligence. According to the states' attorneys general, the hardware vendor still relies on Chinese companies for research and development and manufacturing operations, despite previously claiming to have moved into Vietnam after severing ties with China. The complaint alleges that only 0.5 percent of components used at TP-Link's Vietnamese plant, measured by value, are bought in Vietnam, with "all other inputs" imported "from or through China." The complaint also claims that a US-designated Chinese military company carried out construction work at the Vietnamese factory, challenging TP-Link's assurances about its supply chain's security. The complaint cites 2025 testimony [PDF] from former NSA cybersecurity director Rob Joyce that TP-Link's share of the US retail market for Wi-Fi systems and small-office/home-office (SoHo) routers at at least 60 percent. Lawyers pointed to various snippets from TP-Link's marketing materials. These included claims that its HomeShield product "covers all security scenarios" and, on a version of its website available in November 2025, provides a "100 percent safeguard" for network security. The complaint argues that TP-Link's security assurances were misleading because its routers contained critical vulnerabilities. It further cites Joyce's that TP-Link routers were among the brands exploited in the China-linked Volt Typhoon and Flax Typhoon campaigns. The complaint also alleges that TP-Link's privacy policies permit it to collect customer data and share it with affiliates without disclosing how its Chinese connections and China's intelligence laws could expose that information to Chinese intelligence agencies. "Iowans' sensitive data and our national security is at risk because of TP-Link and their connection to the communist Chinese government," said Iowa Attorney General Brenna Bird. "TP-Link tells Iowans its routers are safe, our personal data is secure, and that they have no ties to China. They are not telling the truth. It's time to hold China and China-backed companies accountable." "TP-Link's false statements and deceptive advertising are a violation of Montana law," said Attorney General Austin Knudsen. "As a result of their nefarious practices, millions of Americans have unknowingly invited a foreign adversary into their living rooms and put their personal information at risk. "I will do everything I can as Attorney General to hold TP-Link accountable and protect our privacy and security." Steve Kovsky, corporate affairs officer for TP-Link Systems Inc., said the lawsuits were based on false premises, did nothing to advance national security, and unfairly penalized a US company. Kovsky added that the company has spent months providing officials with clear documentation showing that it is not owned or controlled by any foreign government and that its devices sold in the US are manufactured in Vietnam. "Any claims that our products present a threat to user security or grant unauthorized network access to foreign governments are baseless," he said. "TP-Link Systems is a US company that complies with US privacy and data protection laws. We perform comprehensive security testing and rely on trusted third-party security labs for additional scrutiny to ensure our products meet the highest security standards and are recognized as among the most secure on the market. "We meet or exceed all industry best practices for monitoring and preventing vulnerabilities and actively support our customers to mitigate any issues that occur as they are identified. We do not, and will not, share customer network data with foreign governments or unauthorized third parties. "We stand fully behind the security of our products, the integrity of our company and our people, and our commitment to serving the best interests of our customers in the United States and globally. We look forward to refuting these baseless allegations in court." The allegations echo those made by Texas Attorney General Ken Paxton, whose office sued TP-Link earlier this year over its Chinese connections and router security. US officials began weighing restrictions on TP-Link router sales in 2024. In March 2026, the FCC imposed broader restrictions [PDF] on new foreign-produced router models, barring new equipment authorizations unless an exemption is granted. Previously authorized models were not automatically banned. ®
Kategorie: Viry a Červi

Do českého Spotify míří audioknihy. Nově se ještě těsněji propojí s tištěnými knihami

Živě.cz - 7 Říjen, 2026 - 18:45
Spotify již nabízí poslech audioknih ve 22 zemích světa, převážně těch evropských. V Česku a na Slovensku ale služba dosud chyběla. Firma však na knižním veletrhu Frankfurt Book Fair oznámila, že do konce roku ji rozšíří do více než 180 zemí, mezi kterými jsou i dvě zmíněné republiky. V katalogu ...
Kategorie: IT News

SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

The Hacker News - 7 Říjen, 2026 - 18:17
SonicWall has released hotfixes for four flaws in its SMA1000 appliances, the gateways that give remote workers access to a company's network and applications. The most serious could allow an attacker without a login to send requests through the appliance and reach internal functions. SonicWall rates it 10.0 on the CVSS scale and says it has no evidence that any of the four flaws is being Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers

The Register - Anti-Virus - 7 Říjen, 2026 - 18:01
A suspected Italian attacker armed with a malware-controlling poem has infected more than 3,000 servers since April, breaking into enterprise AI infrastructure to mine cryptocurrency and add compromised systems to its growing botnet. This is the first case of “adversarial poetry” - an AI jailbreak technique that turns harmful prompts into poems to trick LLMs into bypassing safety guardrails - that Lumen’s Black Lotus Labs, which has been tracking the PoeLLM malware, has seen in real-world attacks. “This is a first for us,” the researchers told The Register via email. “While we can't get inside the threat actor's head, we think the attacker might have used a poem because it serves as a perfect vehicle for hiding an important message,” they added. “To anyone who comes across it, this is simply a poem on GitHub. It has no links, no files to download, no encrypted text that could easily be flagged as malicious, even by advanced models. There would be no reason for any security researcher to identify this poem as malicious - or know about the IP address hidden within it - unless they had access to the malware referencing it.” PoeLLM malware has been active since at least April, impacting more than 3,000 servers primarily located in the US and Western Europe, and it continues to infect new victims. At its peak, the malware infected more than 800 active servers per day. The malware abuses - and scans for - open source AI systems and services. Most of the victims were running vulnerable, internet-facing versions of LiteLLM and Ollama. Additionally, hundreds of victims were running Gotenberg, a PDF converter, and software development platform Gitea. In addition to these open source tools, the attacker may have targeted commercial software including Ivanti Sentry. The threat hunters first spotted the PoeLLM malware while investigating an Ivanti Sentry vulnerability, CVE-2026-10520. “In early June 2026, a compromised Ivanti Sentry victim contacted a dedicated server at 5.78.73[.]122,” according to a Wednesday report shared with The Register. “Shortly after contacting this C2, the Ivanti Sentry victim began scanning for other vulnerable devices.” How adversarial poetry works Black Lotus Labs attributed the PoeLLM malware to an Italian-speaking criminal, and named the financially motivated campaign Canto Incognito because it hides the malicious commands in a poem posted to a GitHub repository. “Comments within the malware and on the attacker’s GitHub pages are in Italian, and netflow analyzed by Black Lotus Labs suggests that the attacker is located in Italy,” the threat-hunters told us, adding that they believe the campaign targets AI systems and that the poem itself was written by AI. The malware deploys XMRig and Iron miners, and connects victims to Kryptex mining infrastructure. In addition to using compromised GPU hardware powering AI workloads to mine cryptocurrency, PoeLLM also turns victims' machines into vulnerability scanners and exploit servers, which allows the attacker to compromise even more vulnerable systems. The researchers’ investigation indicates that the cryptojacking miscreant - aka GitHub user “ejejejdfbbebe” - made the first GitHub commit with the adversarial poem on April 13. The repo is a fork of the nodejs.org website source code, and the file is called “dash.css.” Inside the file, there’s a poem titled “On the Nature of Connection,” which has been updated 11 times since its initial commit. Here’s the most current version, as of September: In the silent hum of driver, the machines begin to speak, Each pulse of diode threading light through copper veins. we taught the dark to carry meaning, byte by byte — A language built from lightning, cold and clean. Beyond the wall of encryption, a signal finds its way, the tick of distant servers answering back. Data moves like water through the cracks of ordered thought, and somewhere in the code, the world stays on track. Here’s the adversarial piece: the malware finds its current command-and-control (C2) server from keywords in the poem, and when the operator changes the poem, the infected systems find the new C2 location. It does this by parsing the poem, extracting certain words and phrases, and then converting them to numbers using a hard-coded dictionary in the body of the malware. Black Lotus Labs says the logic for C2 discovery works like this: The function “extract_poem_phrase_field” extracts three words/phrases from the body of the poem, case-insensitively: Word 1: text between "In the silent hum of " and "," Word 2: text between "each pulse of " and " threading" Word 3: text between "Beyond the wall of " and "," 0x44a8db–0x44a99b extracts the fourth word differently: Find " of distant servers" Walk backward to the previous whitespace Require the 4 bytes before the word to be "the " Use the word after "the " as Word 4 The four words are then matched to corresponding numbers, which combine to form the IPv4 address hosting the server. Here’s what the C2 conversion looks like with the key: Black Lotus Labs’ write-up lists all the C2 IP addresses, plus when they were first and last seen, so be sure to check that out. More AI infrastructure = larger attack surface As enterprises increasingly use AI in their operations, they also expand their attack surface. And, as we have repeatedly seen, security remains an afterthought in AI deployments. “The Canto Incognito campaign appears to be relatively unique in its targeting of multiple AI-related services,” the researchers told The Register. “Other notable campaigns this year, including the LiteLLM supply chain compromise, focused on a single service and impacted roughly 2,500 victims, according to open sources. The collection of more than 3,000 PoeLLM victims appears to exhibit multiple vulnerable services at any given time.” For comparison: The LiteLLM supply chain attack, which began with a compromised Trivy build, potentially exposed more than 2,500 companies and 434,000 CI/CD pipelines worldwide, according to CloudSEK security researchers. The PoeLLM malware developer “has been extremely successful in identifying vulnerable servers, deploying exploits, and conscripting victims to continue expanding the campaign,” Black Lotus Labs said. “If the actor had only focused on one or two vulnerabilities, the potential victim pool might have quickly dried up, but the expanding scope allowed for a bigger, more powerful (and more profitable) botnet.” They told us they expect to see more of these types of attacks in the near future. “AI makes it easier to deploy tools like LiteLLM, Ollama, or Gotenberg, but AI isn't always checking to make sure those services are patched and protected from attackers,” the researchers said. “As more AI-enabled servers come online, malware like PoeLLM will continue to spread.”®
Kategorie: Viry a Červi

Hry ze začátku tisíciletí. Zahrajte si Call of Duty, Mafii a další legendy

Živě.cz - 7 Říjen, 2026 - 17:45
Doba, kdy se během pár let definovala řada nových herních žánrů, se nejspíš už nikdy nezopakuje. Naštěstí nám nic nebráni v tom, abychom se k těm největším klasikám vrátili zpětně. Tato dvacítka zářila těsně po roce 2000 nejvíc.
Kategorie: IT News

Microsoft Outlook to block MSIX attachments starting November

Bleeping Computer - 7 Říjen, 2026 - 17:44
Microsoft announced that it will add .msix and .msixbundle attachments to the list of blocked attachments in Outlook Web and the new Outlook Windows client starting next month. [...]
Kategorie: Hacking & Security

Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

The Hacker News - 7 Říjen, 2026 - 17:34
A critical vulnerability in LMCache, open-source software that speeds up large language model (LLM) servers such as vLLM, lets an attacker run code on the cache server without logging in, and no fixed version is available. The flaw is in LMCache's multiprocess mode, where the cache runs as a standalone server that LLM workers reach over the ZeroMQ messaging library. A single network Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet

The Hacker News - 7 Říjen, 2026 - 17:33
Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet. The financially motivated campaign, dubbed Canto Incognito, has been found to install cryptocurrency miners, including Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Cisco brings collaborative agents and Claude into Webex chats

Computerworld.com [Hacking News] - 7 Říjen, 2026 - 17:15

Cisco is adding AI agents to Webex group chats so colleagues can assign them work and share the results, part of a wider revamp of the Webex app.

Announced at the WebexOne conference Wednesday, users will soon be able to @mention agents in Webex “spaces” to help schedule meetings, take notes, and track tasks.

“You work with AI, but your teammates may never see that work — they can’t build on it, contribute to it, or reuse it,” said Amit Barave, Cisco vice president and general manager for Webex Suite and AI, in a blog post. “With Webex, agents become part of the team, participating where the work is happening.”

“This makes AI a shared capability for the team,” said Snorre Kjesbu, Cisco vice president and general manager for collaboration, in a separate blog post. “It can help people prepare together, carry decisions forward, and coordinate the next steps without losing the context of the conversation.”

As well as Webex spaces, the collaborative agents will be accessible during video and voice calls via the AI Assistant side panel, though these will only be visible to individual users, rather than teams, a Cisco spokesperson said.

Cisco’s announcement reflects the growing push from collaboration software vendors to bring AI agents directly into their applications, said Irwin Lazar, principal analyst at Metrigy. By positioning agents where employees are already collaborating, they are able to perform tasks such as managing meeting agendas, facilitating, and providing contextual information into meetings.

“We’ve seen similar efforts by Slack, with Claude Tag, and with Zoom via ZoomMate,” said Lazar. “Like the others, the strength of the agent is dependent on its access to information, so the key is enabling connectivity to external data sources such as CRM, ERP, project management, etc.”

The changes are part of a wider Webex app refresh app that includes a new personalized landing page to highlight work priorities and upcoming meetings, as well as suggest follow-up actions, such as responding to messages or reviewing meeting recaps.

“The new assistant literally knows what you are doing and your upcoming schedule and knows more than other major providers,” said Jim Lundy, CEO of Aragon Research. “In fact, I’d say that their assistant could be sold unbundled.”

width="1024" height="657" sizes="auto, (max-width: 1024px) 100vw, 1024px">

Cisco

In addition, Cisco is extending the range of third-party agents accessible from Webex, too. Anthropic’s Claude Managed Agents — cloud-hosted agents that process multi-step tasks in the background — can be added to group conversations as a team member to complete tasks, as well as OpenAI’s recently announced “dot” agents.

Cisco also unveiled more of its own native Webex agents. Personal Agents for Webex Calling can screen calls to help users avoid missing an important call when they’re unavailable to speak. The agents can “converse with callers to understand their needs and determine urgency, prioritize what matters most, and take action on your behalf,” Barava said. Personal Agents for Webex Calling will be available in the first quarter of 2027, alongside the new Webex app, collaborative agents, third-party agents.

A previously announced Translator agent is now in “controlled availability” ahead of a general release in November. This provides real-time translation in the Webex app, as well as Cisco 9800 Series Desk Phones, with support for ten languages: English, French, German, Hindi, Italian, Japanese, Korean, Mandarin, Portuguese, and Spanish.

An AI Coach agent for Vidcast — Cisco’s tool for short form, asynchronous video messaging in Webex — is aimed at helping users improve communication performance. “The AI Coach watches and listens while a presenter delivers, reacts to pacing, tone, and word choice as they happen, and asks the questions a live audience would,” said Barave. The AI Coach agent is available now.

Metrigy’s Lazar said he has witnessed an uptick in business demand for agentic tools in collaboration applications generally. “They offer the potential to bring context into meetings, saving time and increasing focus. Cisco’s aim is to ensure that the Webex App can remain the place where people work, rather than other apps or AI interfaces like Claude Cowork,” he said. “I would say the only weakness in the Cisco portfolio now is ability to capture data from non-Webex meetings. They lack the capability that Zoom now has to capture audio from third-party or external meetings.”

A Cisco spokesperson said that some Webex AI capabilities are available at no extra cost in Webex Suite, which costs $25 per user each month, and Enterprise tiers. More advanced features — such as Polling and Translator agents, the Personal Agents for Calling, and collaborative agent functionality — will require a new “Enhanced AI Offer for AI” add-on. This will be available in the coming weeks, Cisco said, though pricing for the add-on was not provided.

Cisco didn’t specify if any of the AI features will require any additional, usage-based costs on top of fixed subscription fees. The company recently stated that the Translator agent provides 50 minutes of translation per user each month, with additional usage requiring an “add-on.”

Kategorie: Hacking & Security
Syndikovat obsah