Agregátor RSS

Huawei chtělo nabourat velký den Applu. Místo toho se řeší podivná kampaň na trojitou skládací novinku

Živě.cz - 12 Září, 2026 - 08:45
I negativní reklama je reklama. Influenceři měli propagovat nový Huawei Mate XT 2 • A to zrovna v době premiéry iPhonů – a hlavně bez přiznání placené spolupráce • Huawei se od celé akce distancuje, cíl byl ale splněn na jedničku
Kategorie: IT News

Analýza 443 tisíc pevných disků potvrdila rozdíly v poruchovosti. Nejspolehlivější značkou bylo HGST

Živě.cz - 12 Září, 2026 - 07:45
Rozsáhlá analýza stovek tisíc disků potvrdila zásadní rozdíly v jejich spolehlivosti • Značka HGST vykázala nejnižší poruchovost. Naopak nejhůře dopadla Toshiba • Vyšší provozní teplota riziko poruchy zvyšuje zatímco větší kapacita ho snižuje
Kategorie: IT News

Fiasko jménem W Social

AbcLinuxu [zprávičky] - 12 Září, 2026 - 02:03
Jiří Eischmann se v příspěvku Fiasko jménem W Social na svém blogu věnuje evropské sociální síti W: "W Social je příkladem toho, že se problémy sociální sítí nedají řešit od exekutivního stolu. Když na začátku tohoto roku v Davosu oznámili vznik nové sociální sítě W Social, politici se mohli přetrhnout ve chvalozpěvech. Konečně evropská sociální síť a ještě s ověřením identity. … Jak se ukázalo, když v Davosu W Social oznamovali, neměli kromě prezentace v rukou vůbec nic. Žádná platforma neexistovala. Následně vzali zdrojové kódy Bluesky, dali na ně logo W Social, opatřili procesem ověření identity o 13 krocích a mohlo se spouštět. … Zjistila, že po dvou měsících od spuštění, kdy byla síť výrazně propagovaná Evropskou komisí a měla pokrytí médii po celé Evropě, měla necelých 24 tisíc registrovaných uživatelů, z nichž jen pětina měla ověřenou identitu a pouze desetina zveřejnila aspoň jeden příspěvek. 68 % uživatelů nemělo jediný příspěvek, nikdo je nesledoval a oni nesledovali nikoho."
Kategorie: GNU/Linux & BSD

Linux Virtualization Fix Limits a Host Memory Exhaustion Path

LinuxSecurity.com - 12 Září, 2026 - 01:10
Linux virtualization lets a physical host run guest virtual machines. A fix in vhost, the Linux component that helps those guests exchange data with virtual devices, limits memory consumed by repeated requests for a missing memory mapping.
Kategorie: Hacking & Security

Linux Can Hold TLS Traffic Until a Confidential VM Proves Its State

LinuxSecurity.com - 12 Září, 2026 - 00:15
Confidential computing can protect a virtual machine’s memory from the host that runs it. A remote client still needs to check that its connection reaches the protected machine. Transport Layer Security, or TLS, encrypts the connection and checks the service’s identity, but does not by itself verify the machine’s software environment.
Kategorie: Hacking & Security

Událo se v týdnu 37/2026

AbcLinuxu [články] - 12 Září, 2026 - 00:01
Ucelený přehled článků, zpráviček a diskusí za minulých 7 dní.
Kategorie: GNU/Linux & BSD

Nejstarší feťák je z doby ledové

OSEL.cz - 12 Září, 2026 - 00:00
Loni vás na této stránce jeden z „oslů“ seznamoval s poznatkem, že betelem se naši předci přiváděli do rauše už před 4 000 lety. Mýlil se o dvacet tisíc let.
Kategorie: Věda a technika

Nadzvukový letoun Quarterhorse bude vynášet testovací platformu Ramjet-X

OSEL.cz - 12 Září, 2026 - 00:00
Hermeus v rámci vývoje očekávaného nadzvukového letounu Quarterhorse staví vysokorychlostní platformu Ramjet-X, která by měla nabídnout komerční testování ve vysokých rychlostech. Prototyp Quarterhorse vynese Ramjet-X a vypustí ho v nadzvukové rychlosti, aby Ramjet-X mohl spustit svůj ramjetový pohon a testovat pro zákazníky.
Kategorie: Věda a technika

OpenAI Claims Another Huge Mathematical Result Amid Fights Over Credit, Ethics, and Privacy

Singularity HUB - 11 Září, 2026 - 23:09

OpenAI’s Navier-Stokes solution looks like a win for mathematics. But some mathematicians aren’t so sure.

OpenAI has announced one of its unreleased artificial intelligence models has found an answer to one of the biggest open questions in mathematics, the Navier-Stokes Millennium Prize problem. The Millennium Prizes offer million-dollar rewards for solutions to seven notoriously difficult mathematical puzzles, and until now only one had been solved.

Mathematical problems at this level are extremely complex. A solution to the similarly difficult ABC conjecture ran to more than 500 pages, and it took mathematicians six years to understand it enough to spot potential flaws. Researchers can devote entire careers to these problems, in the hopes of getting close to a solution.

And this is what seems to have happened here. Building on the work of several human mathematicians, OpenAI unleashed a swarm of 10,000 AI agents running a new experimental model, which churned through millions of dollars’ worth of computing power in the space of a few days to complete what the American Mathematical Society called “the final steps” of the solution process.

So what is the Navier-Stokes problem, and what did OpenAI do? And why are a lot of mathematicians impressed with the result but unimpressed with the AI company’s behavior?

A Fluid Situation

OpenAI’s announcement concerns the Navier-Stokes equations, which model the behavior of fluids such as water and air. These equations underpin modern science and engineering, but our mathematical understanding of them is incomplete.

To explain the problem, imagine looking at the flow of water, before zooming in with a camera. According to the equations, both the zoomed and un-zoomed water should look exactly the same, except that things will look a little faster in the zoomed-in view.

We know this can’t be right in the real world. If we keep zooming in far enough, we will stop seeing a smooth fluid and start seeing a teeming crowd of molecules jostling against one another. So the Navier-Stokes equations must break down somewhere.

The biggest concern is whether fluid swirls can shift their energy into smaller, faster swirls, accelerating every time we zoom in. If this is possible, then the fluid may become impossibly fast, creating a “blow-up” in speed (also known as a “singularity”).

We know this can never happen in the real world, but the Millennium Prize was about finding out whether it could happen in the equations. OpenAI found that yes, the Navier-Stokes equations do allow a blow-up under certain conditions.

A Blow-Up in Finite Time

As OpenAI tells the tale, their researchers heard rumors mathematicians at rival company Anthropic were close to solving two Millennium problems on September 1. They deployed their latest in-development model in an effort to crack one first.

After launching a swarm of agents, the model produced a solution in just 88 hours, with verification taking another 17. The result is a coup for OpenAI, which is trying to demonstrate the capacity of its models against those of its leading competitor Anthropic, as both companies head towards planned share market listings.

One of the rival teams closing in on a Navier-Stokes solution featured Anthropic staffer Levent Alpöge, who was collaborating in a private capacity with mathematician Tristan Buckmaster from New York University.

As it turns out, OpenAI had contacted Buckmaster to discuss his work and theirs. In a statement published hours before OpenAI’s, Buckmaster said he and Alpöge had been using OpenAI’s publicly available models in their work for some time, and had been pursuing a line of thinking similar to what was used in OpenAI’s result.

He says he asked whether their data had been used by OpenAI’s model to produce its results, but received no answer to this question. Instead, he says OpenAI offered to collaborate with him if he removed Alpöge’s name from the work, because of Alpöge’s Anthropic affiliation. (OpenAI denies this claim.)

Other mathematicians have also raised concerns, with German mathematician Andreas Thom suggesting OpenAI’s models were hoovering up unpublished human work and presenting it as AI generated.

The Ripple Effect

OpenAI’s Navier-Stokes result looks like a big win for mathematics. But some mathematicians are not so sure.

US-Australian mathematician Terence Tao has been vocal in his reservations about some tendencies in AI mathematical research. He is concerned about “the indiscriminate use of powerful solution-extraction tools” to “achieve the immediate short-term goal of solving problems” at the expense of broader understanding.

OpenAI’s behavior in this instance has also provoked alarm. Asking for an author’s name to be removed from work due to corporate politics is completely unaligned with scientific practice.

Moreover, as Tao put it, if AI companies jump on a rumor of promising work and throw millions of dollars at trying to scoop competitors, researchers may end up “no longer sharing any promising research with the broader community.”

This would destroy the principles of open and reproducible science. It could also remove the foundation stones scientists use to identify and solve the next wave of new, interesting problems. Why would you spend years on a problem if rumors of your work might spur an AI company to spend millions to beat you to the punch?

And that’s before we get to privacy and intellectual property concerns. OpenAI insists no specific user data was accessed by its researchers. However, serious questions remain about whether their model was trained on Buckmaster and Alpöge’s private work.

Companies and individuals around the world will now be re-examining how much they can trust OpenAI and other AI companies to handle their private and business data.

Meanwhile, the Millennium Prize conditions say prizes cannot be awarded until at least two years after the publication of a potential solution. For now, the Navier-Stokes problem is still officially unsolved.

This article is republished from The Conversation under a Creative Commons license. Read the original article.

The post OpenAI Claims Another Huge Mathematical Result Amid Fights Over Credit, Ethics, and Privacy appeared first on SingularityHub.

Kategorie: Transhumanismus

Hackers abused Claude to extract secrets from 1.8M Android apps

Bleeping Computer - 11 Září, 2026 - 22:19
Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes. [...]
Kategorie: Hacking & Security

Florida confirms DMV database breached via stolen police account

Bleeping Computer - 11 Září, 2026 - 21:00
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. [...]
Kategorie: Hacking & Security

Phishing na zákazníky Trezoru nerozsvítil žádnou kontrolku. Přišel z jeho vlastní adresy

Zive.cz - bezpečnost - 11 Září, 2026 - 20:45
Česká firma Trezor, výrobce hardwarových peněženek pro kryptoměny, se stal terčem phishingové kampaně. Byla rozeslaná přímo z jeho vlastní e-mailové infrastruktury. Útočník se 9. září 2026 dostal do e-mailové platformy Brevo, kterou Trezor používá na rozesílání newsletterů. Jeho zákazníkům ...
Kategorie: Hacking & Security

Phishing na zákazníky Trezoru nerozsvítil žádnou kontrolku. Přišel z jeho vlastní adresy

Živě.cz - 11 Září, 2026 - 20:45
Česká firma Trezor, výrobce hardwarových peněženek pro kryptoměny, se stal terčem phishingové kampaně. Byla rozeslaná přímo z jeho vlastní e-mailové infrastruktury. Útočník se 9. září 2026 dostal do e-mailové platformy Brevo, kterou Trezor používá na rozesílání newsletterů. Jeho zákazníkům ...
Kategorie: IT News

Co nového v Mapy.com. Navigace s automatickým stmíváním jasu vám prodlouží výdrž mobilu

Živě.cz - 11 Září, 2026 - 19:45
Sledujeme nové funkce, které s aktualizacemi přibývají do oblíbené mobilní mapové a navigační aplikace Mapy.com od českého Seznamu.
Kategorie: IT News

More JFrog Artifactory bugs under attack, and all 3 have patches

The Register - Anti-Virus - 11 Září, 2026 - 19:43
JFrog Artifactory instances continue to get hit hard. Multiple attackers are exploiting three JFrog Artifactory bugs to gain administrative control over vulnerable instances - in some cases, just days after the vendor published a patch - and then using this illicit access to install malicious plugins and backdoors. The three vulnerabilities are: CVE-2026-42018 is a high-severity, improper authentication flaw that can return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled. An attacker can use this token to authenticate to the repository manager and then access sensitive resources. JFrog patched this vulnerability on August 12. CVE-2026-42016 is a high-severity privilege-escalation bug. Artifactory doesn’t properly validate the token’s scope, and this can allow an attacker with low-privileged access to elevate privileges and perform actions that they should not be allowed to do. JFrog fixed this one on July 27. CVE-2026-82329 is a critical authentication-bypass vulnerability that allows unauthenticated attackers with network access to obtain administrative privileges. JFrog published a patch for it on August 28. Earlier this month, security researchers told The Register that miscreants began battering internet-exposed systems vulnerable to CVE-2026-82329 just four days after JFrog disclosed the bug. In addition to creating new administrative credentials, watchTowr’s honeypot network caught miscreants “enumerating users, groups, credential sets and federated access topologies,” said Yordan Ganchev, principal threat intelligence specialist at watchTowr. The one thing everyone agrees upon is that attackers didn’t start exploiting any of these CVEs until after JFrog issued fixes. In a Thursday report, Wiz security researchers “confirmed in-the-wild exploitation of all three vulnerabilities across multiple environments,” and noted that “patching velocity has been slow.” JFrog has not responded to any of The Register’s inquiries about attacks against any of the three CVEs. 'Patching velocity has been slow' Six weeks after JFrog disclosed CVE-2026-42016, 59 percent of organizations remain vulnerable, and 62 percent remain vulnerable to CVE-2026-42018 after four weeks. Organizations have been quicker to remediate the critical bug, CVE-2026-82329, although 49 percent remain vulnerable two weeks after its publication, according to Wiz. Beginning August 15 and running through September 8, Wiz spotted “multiple” attackers chaining CVE-2026-42018 and CVE-2026-42016 against self-hosted Artifactory instances to gain admin access. Many of these intruders then dropped a custom Rust backdoor to establish command-and-control (C2) capabilities. While the post-exploitation activity varies, Wiz reports observing attackers doing all types of mischief with their administrative access to compromised Artifactory instances, including establishing persistent admin accounts, installing Groovy plugins to achieve remote code execution on the server, executing shell commands run through the plugin to perform reconnaissance and scan for sensitive files, deliver second-stage payloads, and upload web shells. Then, between September 1 and 8, Wiz saw “several” attackers exploiting CVE-2026-82329. These intrusions were not a “unified attack chain by a single threat actor,” but spanned multiple illicit behaviors including exfiltration of configuration details, establishing persistent admin accounts, token minting for long-lived credentials, stealing keys, attaching their own SSH keys to created users in some cases, and enumerating users, repositories, and tokens. If you haven't already, patch vulnerable instances Wiz advises - and we strongly concur - upgrading to a fixed Artifactory version as soon as possible. “Given that exploitation may be possible remotely without authentication under the default configuration, organizations should prioritize internet-accessible Artifactory instances and restrict network access to trusted users and systems where possible,” the researchers added. “Organizations should also review Artifactory authentication and administrative activity for unexpected privileged access.” These latest exploits follow a rough few months for JFrog's package management system, which has been under fire from both human and AI attackers. OpenAI and JFrog revealed that OpenAI’s models broke out of their cages to hack Hugging Face by exploiting an Artifactory zero-day in July, and at Black Hat, the model provider said agents used Artifactory to build message boards and help each other access the open internet. ®
Kategorie: Viry a Červi

Passkey-themed phishing attacks lead to Microsoft 365 data theft

Bleeping Computer - 11 Září, 2026 - 19:26
Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services. [...]
Kategorie: Hacking & Security

Teams and Copilot are changing addresses: update your firewalls

Computerworld.com [Hacking News] - 11 Září, 2026 - 18:56

Microsoft is changing the destination address of two of its most popular services: starting this month, it will redirect M365 and Teams web users to copilot.cloud.microsoft and teams.cloud.microsoft, respectively.

The Teams move is already under way, and Microsoft has now added M365 to the mix. The company announced the changes in two MessageCenter posts: MC1465764 (mirror) and MC1462915 (mirror).

Organizations using these products are advised to update their systems and documentation to ensure continued access. Microsoft has told customers to review configurations on client devices, proxies, firewalls, secure web gateways, or other enterprise network controls to confirm that users can connect to the new addresses. Companies having trouble connecting should ensure that their environment aligns with the recommended network requirements for Microsoft 365 Copilot

Enterprises that had been blocking the new Copilot address to prevent employees accessing their personal Microsoft accounts can use Microsoft’s TenantRestrictions control to achieve their goals instead, it said.

All redirects should be completed by early October, Microsoft said, advising companies that can’t meet the deadline to contact their account representative for help. Limited exceptions to the Teams redirect are possible until Dec. 31, 2026, but after that no further delays will be possible, it said.

Kategorie: Hacking & Security

Skládací iPhone překvapil jen názvem. Keynote byla nudná, jak jsme všichni čekali (Podcast Živě)

Živě.cz - 11 Září, 2026 - 18:45
Apple představil skládací iPhone, ani tentokrát nás ale nepřesvědčil, že je stále inovátor. Během slavnostní prezentace nejprve ukázal sluchátka AirPods 5, která jsou mírně levnější než předchozí generace, navíc ale obsahují ANC. Je to solidní upgrade. Hodinky Watch Series 12 a Ultra 4 díky novým ...
Kategorie: IT News
Syndikovat obsah