Agregátor RSS

Nekradou vám heslo, kradou váš souhlas. Přihlašovací obrazovka byla přitom pravá

Živě.cz - 9 Září, 2026 - 14:45
Dostanete zprávu. Píše organizátor konference, novinář nebo někdo, kdo se za ně vydává, a v textu je odkaz na nějaký dokument, sdílení souborů nebo něco jiného, uvěřitelného. Kliknete, na stránce se ukáže klasická přihlašovací obrazovka Googlu nebo Microsoftu, která se dnes ukazuje na každém druhém ...
Kategorie: IT News

WeChat worm could pwn a friend before they even answered the call

The Register - Anti-Virus - 9 Září, 2026 - 14:45
Tencent has patched up a zero-click vulnerability that security researchers used to create a worm capable of spreading through calls on WeChat. With more than 1.4 billion monthly active users, WeChat is among the most popular apps in the world. According to researchers at Calif, its VoIP stack contained a memory corruption bug that could enable a trusted contact to take control of a user's account simply by calling them. Calif called the flaw WeWorm, describing it as the first zero-click worm capable of spreading through WeChat calls on both iOS and Android. Calif released a demo of the vulnerability in action this week, and although Tencent has pushed fixes to address the attack on August 21, the team that found it is still withholding key details. In Calif's demonstration, the exploit took control of a victim's WeChat account within seconds, without the recipient answering the call. The compromised account then called another contact and repeated the process without user interaction. Declining the call stopped infection, but answering it or allowing it to continue ringing did not. An attacker could also try again when the recipient was away from the phone, the researchers said. "Exploitation takes only seconds, and gives us full control of the WeChat account," Calif said. "We can read and send messages, make calls, and act on the victim's behalf." The exploit requires the attacker to be on the victim's friends list. Calif argued that this offered limited protection because a compromised account could be used to target its trusted contacts. Calif said the WeWorm exploit could be chained with other vulnerabilities to compromise an entire device rather than only a WeChat account. It did not disclose the full attack chain. "Chained with other Android and iOS bugs we've reported and are helping fix, it can lead to full control of the device," the researchers said. "[Attackers] could exploit another app, gain root access using techniques like those in OEMpocalypse, take over the victim's WeChat app, and use it to attack you." Calif said it used AI to find the vulnerability and develop its first remote code execution (RCE) exploit in about two days. Tencent later confirmed the researchers' findings. The researchers said they published their high-level findings to highlight how AI could make such capabilities available beyond "well-funded, sophisticated actors." Calif plans to present the full analysis of WeWorm "at an upcoming conference." Ryan Fedasiuk, an adjunct assistant professor in Georgetown University's Security Studies Program, described the discovery of WeWorm as "an extremely serious incident." He called on the US and China to maintain open communication and share information as AI increases the potential scale and severity of cyber threats. ® Updated to add on September 10: Tencent told us: "We were notified of a potential security issue by researchers at Calif through Tencent's official Security Response Center. We investigated the report and have implemented a fix. The fix was deployed on our servers and is now live for all users — no app update or any other action is required. "We have no evidence that the issue was exploited or that any user was affected. Protecting our users is our highest priority, and we're grateful to the researchers for bringing this to our attention and working with us."
Kategorie: Viry a Červi

Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE

The Hacker News - 9 Září, 2026 - 13:57
A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application data to build enough context to act. As AI accelerates vulnerability discovery and research, that delay matters more
Kategorie: Hacking & Security

Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE

The Hacker News - 9 Září, 2026 - 13:57
A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application data to build enough context to act. As AI accelerates vulnerability discovery and research, that delay matters [email protected]
Kategorie: Hacking & Security

Netflix, Spotify, ChatGPT a další služby můžete mít za polovinu. Raiffeisenbank láká atraktivním bonusem k založení účtu

Živě.cz - 9 Září, 2026 - 13:45
Raiffeisenbank láká k založení účtu 50% slevou na předplatné online služeb. • Polovinu zaplatíte za Netflix, Spotify, YouTube, Disney+, HBO Max, ChatGPT a další. • Ušetřit tak lze až 6000 Kč za první rok.
Kategorie: IT News

DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval

The Hacker News - 9 Září, 2026 - 13:17
A flaw in DeepSeek Harness, DeepSeek's open-source tool for running AI coding agents on a developer's machine, let a sandboxed agent turn off its own sandbox with a single command. The tool runs an agent's commands inside an operating-system sandbox, so that an agent working on untrusted files cannot write outside its workspace. The agent could remove that limit by calling the tool's own web
Kategorie: Hacking & Security

DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval

The Hacker News - 9 Září, 2026 - 13:17
A flaw in DeepSeek Harness, DeepSeek's open-source tool for running AI coding agents on a developer's machine, let a sandboxed agent turn off its own sandbox with a single command. The tool runs an agent's commands inside an operating-system sandbox, so that an agent working on untrusted files cannot write outside its workspace. The agent could remove that limit by calling the tool's own web Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

AI notetakers at work could leave companies at risk for lawsuits

Computerworld.com [Hacking News] - 9 Září, 2026 - 13:00

AI note-taking applications are increasingly used by workers to record meetings, generate conversation summaries and suggest post-meeting action items. 

Along with the promised productivity benefits — enabling users to focus on meetings rather than actively taking notes — the emergence of these AI tools has raised privacy questions, particularly around obtaining prior consent by meeting participants for their use. Those concerns, in turn, have prompted a spate of lawsuits against software vendors that sell AI notetaking tools.

In some ways, the underlying questions are not new: It’s long been possible to record a phone call with a dictaphone, and laws around surreptitious recording have been around for decades. Yet widespread access to AI notetakers via desktop or smartphone apps means that it’s easier than ever to record a conversation for future reference. 

Among the thorny questions arising from the technology’s use: what happens to conversation data sent to a software vendor’s servers for processing? Are the recording and transcript used to train those vendors’ AI models, for example, or create biometric voiceprints? Those practices are among the issues being considered in US courts. 

Otter, which claims to have 35 million users, was subject to a class-action complaint in a federal court in California last year. That complaint accused Otter of recording individuals without consent and using their voices to train its speech recognition AI tools. Last month, a judge rejected Otter’s attempt to dismiss the main claims, though the scope of the case was narrowed.

A lawsuit filed against another vendor, Fireflies, in an Illinois court late last year, alleges the company collects and stores biometric voiceprints without user consent, in violation of the Illinois Biometric Information Privacy Act (BIPA). Fireflies claims to have more than 20 million individuals and 1 million organizations as customers.

Earlier this year, a class-action complaint in a Washington court claimed that a live transcription feature in Microsoft’s Teams collaboration application also violates BIPA by collecting biometric data without consent. 

And most recently, a complaint alleged that Granola, a well-funded startup, designed its product to be used without the knowledge of all meeting participants, in violation of the Electronic Communications Privacy Act (ECPA). That complaint also claims Granola trains its AI models on conversation data without consent. 

None of these cases has yet been resolved, and it’s unclear whether any of the vendors broke the law in the design and delivery of their products and services. But the lawsuits highlight considerations for businesses that allow the use of AI notetakers, both in terms of prior consent for recordings and understanding how conversation data is handled.

More broadly, the lawsuits raise questions about how existing privacy and consent rules apply to new technologies that make it easier to record others, whether through AI note-taking apps, smartglasses, or other recording devices.

Computerworld spoke with Brian McGinnis, partner at law firm Barnes & Thornburg and a founding member and co-chair of the firm’s Data Security and Privacy Law practice group, about the focus of the lawsuits, potential outcomes, and how businesses can deploy AI notetaking apps safely.

Several cases have already been brought against popular AI note-taking apps. What are some of the main commonalities between these? Which laws are the vendors accused of breaching? “The common allegation is that these companies capture communications of people who did not agree to the recording or receive adequate notice. Some of the lawsuits also allege that meeting data is used to train AI models and that consent cannot meaningfully be withdrawn once the data has been processed.

“There are various federal and state claims. You’ve got the Electronic Communications Privacy Act, a federal wiretapping statute. As a general matter, the Electronic Communications Privacy Act permits an interception when one party consents, subject to statutory exceptions and questions about whether the technology constitutes an unlawful interception or third-party eavesdropping. In other words, if you, as the user, provide consent, you can be on a meeting with 20 other people and it’s deemed to be sufficient; you don’t necessarily need to get the consent of other people. 

“But California and a minority of other states are what we call ‘two-party consent’ states, meaning each individual on the call has to give consent; it’s not sufficient for you as the person who turns the notetaker on to provide the consent — you also have to get the consent of others that are being recorded. There are state laws around that.

“There’s a law called CIPA, the California Invasion of Privacy Act, that’s being utilized in this context.  We see a lot of suits being brought under that law — it’s a wiretapping statute designed for telephone wiretapping that’s now being applied to the internet.”

What about the use of biometric data? “A growing number of states regulate biometric data, with Illinois’ BIPA being particularly prominent because it provides a private right of action. This means an individual can sue a company for violation of the law.  

“That law covers biometric information. With an audio recording or recording of ‘dumb’ video that isn’t running any algorithms, you’re not necessarily collecting any biometrics. But when you start identifying people, you’re recording things like faceprints or voiceprints, which are in the definition of biometric information within the statute. Now you’re not only collecting personal information, but also biometric information, which is considered very sensitive and much more highly regulated. 

“Then you’ve got the private right of action that goes against it. Part of the argument here is that recordings taken by the AI notetakers can be used to produce some form of biometric information, such as a voiceprint.  

“We’ve seen a lot of cases, and a lot of changes in industry as a result of this law. Shutterfly had a famous case about scanning for people’s faces and things like that in Illinois that changed the photo storage and processing industry a little bit. 

“A lot of companies stay out of Illinois to avoid this law specifically. But a customer organization might not know exactly who’s in a meeting and where a person is located at the time of the meeting. So, you need to either follow that law and get individual consent, or stay out of states with biometric laws if you want to use some of these tools. 

“It’s just a further challenge for these applications if the goal is to be used as much as possible with as little detection as possible.”

What are some of the potential outcomes for these cases? “I think it’d be unlikely to get an outright ban, absent passing some kind of new law that says these tools are per se illegal for use. It’s much more likely the outcome will require some changes and controls over the way that they get used. The clearest case would be some kind of a pop-up notice: ‘Hey, this meeting’s being recorded, here’s who it is, here’s their privacy policy, here’s their terms of service – do you consent to it?’ And getting opt-in consent from anybody who wants to be recorded. 

“The notion that only one person in the meeting has to say it’s okay and you can just automatically record everybody else, I think that’s probably at risk, and could potentially be replaced with a standard that requires everybody to consent before it’s considered legal.

“But the newer —and more interesting — wave of these is the Granola case, where part of its marketing is that people aren’t aware that it’s there. The Granola complaint alleges that the product was designed to operate without alerting other participants. It’s possible that kind of activity could result in a decision that would ultimately ban it outright. In other words, that it’s illegal to utilize these tools if you aren’t providing notice to everybody and/or aren’t getting consent from everyone on the call. That’s a possible outcome that we could see.

“To me, that’s interesting when you think beyond AI note-taking and into the broader world, with conversations around, like, Meta Glasses, or any of these kinds of AI wearables. Granola in particular has an Apple Watch app, and there are other wearable or physical devices — there’s one [Plaud Note] that sticks on the back of your phone and is essentially an always-on recording device. 

“With these devices, you’re going from an online meeting where you can provide notice and there’s a structure to obtain consent, to walking down the sidewalk and recording people and casual conversations. Maybe it’s somebody you’re having a conversation with, maybe it’s somebody at the table next to you in the coffee shop that you have no relationship with whatsoever — what are the laws around consent and notice in those cases, where there’s no digital interface to put that up in front of people? Do you have to go around with a pad of paper and a pen and get people to sign consent to use these things? Do you have to physically tell them?

“Those are the more interesting conversations that this line of cases is just at the beginning of helping us get some answers on. In other words; how do you get consent? How do you provide notice in a world where we don’t have documents or screens in front of us to easily handle that? Those are interesting questions that the law will have to figure out here.”

These tools are increasingly used in the workplace. How can businesses be sure they deploy the technologies safely? “We’re getting a lot of questions from our clients about this topic, because they’re really unsure and uncertain of how to handle these tools.

“Obviously, there’s a push for broad use of AI within their companies, for productivity increases within their company. People like the tools; they want to be able to use them. But then we also hear a lot of stories about ‘I jumped on a meeting; I didn’t even know it was being recorded, then I got an email afterward with a transcript of it,’ and ‘half of what it recorded wasn’t actually what I said, or it was interpreted incorrectly’ — things like that. So there’s a lot of consternation amongst our clients about the people within their organizations using it. 

“I can’t tell clients definitively that they’re legal as they are; there are ways to use this legally and safely that aren’t going to get your organization sued, but you probably have to do some things that are beyond what’s provided ‘out of the box’ by the software providers. 

“With Granola, for example, my understanding is that certain notice features may not be enabled by default. You can turn on video or audio watermarking, and you can turn on the notice that pops up in these things, but I think it ships without those features enabled. That puts the responsibility on the individual user to determine and then implement their own legal privacy and legal compliance mechanisms using their settings.

“You really have to play to the most stringent state’s law. I would advise a company that, to decrease your chances of getting in trouble for use of these tools, you need to obtain consent of all parties on the call. You can do that verbally, as well; written is even better. 

“Then it’s about having an internal AI note-taking policy. Think of a BYOD policy, which all these companies have, or an AI usage policy — this could be part of that policy, or a standalone policy: ‘Here’s how our organization thinks about these tools:  you can only use these approved tools and, if you’re going to use them, you have to turn on these features. You have to get consent from everyone. Here are limits on what you can do with the output of those transcripts or recordings.’ 

“If you set all that up and do the compliance and governance work, I think you can use these tools and most likely stay on the right side of the law. Certainly, the law doesn’t prevent consenting adults from consenting to the use of these kinds of tools.  

“But the further you get away from that written consent standard, the more problematic it becomes. If you just want to go to a notice standard and not obtain actual opt-in consent, or, even worse, if you want to try and do this without anybody knowing, that potentially could get challenged.”

Kategorie: Hacking & Security

Aby se chytrá domácnost starala sama o sebe. Automatizace je v Samsung SmartThings otázkou pár klepnutí v aplikaci

Živě.cz - 9 Září, 2026 - 12:45
Chytrá domácnost Samsung SmartThings umožňuje snadné připojení řady zařízení a už ve výchozím stavu nabízí připravené šablony pro typické situace. Ale co když potřebujeme něco, na co výrobce nepomyslel?
Kategorie: IT News

Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets

The Hacker News - 9 Září, 2026 - 12:43
Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet. Alby Hub is a self-hosted Lightning wallet, meaning the owner runs it on their own computer or server, and it holds their bitcoin. The flaw affects versions v1.7.0 through
Kategorie: Hacking & Security

Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets

The Hacker News - 9 Září, 2026 - 12:43
Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet. Alby Hub is a self-hosted Lightning wallet, meaning the owner runs it on their own computer or server, and it holds their bitcoin. The flaw affects versions v1.7.0 through Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Over 36,000 exposed Plex servers vulnerable to recent flaws

Bleeping Computer - 9 Září, 2026 - 12:11
Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks. [...]
Kategorie: Hacking & Security

Chronomapy ČR: Kam se dostanete za hodinu, když sednete do auta, na kolo nebo počkáte na MHD

Živě.cz - 9 Září, 2026 - 11:45
Kam se z určitého místa dostanete třeba za hodinu, když oprášíte bicykl, sednete do auta nebo počkáte na nejbližší autobus a vlak? Na tuto otázku nabízí odpověď hned několik různých webových aplikaci, zpravidla ale pracují jen s jedním druhem cestování, anebo jsou regionálně omezené. Pak tu jsou ...
Kategorie: IT News

Wanna make your own Android ping tone? Ask Gemini

Computerworld.com [Hacking News] - 9 Září, 2026 - 11:45

By now, you probably know my stance on Gemini and other generative AI gobbledegook — right?

In short: It’s an insanely powerful form of technology (obviously). But it’s also wildly inaccurate and ineffective as an all-purpose answer engine, and by cramming it into every last nook and cranny, Google is doing a serious disservice to its users — and to itself.

That being said, generative AI can be incredibly useful. The key is simply to frame it as a purpose-specific tool for the right type of limited task as opposed to treating it as the end-all answer for everything, as most tech players seem overly eager to do these days.

Here in the land of Android, I’m always looking for purpose-specific ways Gemini can make our lives easier. Over time, I’ve found those ideas often aren’t the big headline-making features Google and other tech companies market but rather random little off-the-beaten-path possibilities that rarely get emphasized.

Today, I’ve got a new Gemini Android advantage for you to explore — another one that I’ve never seen advertised anywhere but that works brilliantly well and solves a long-standing limitation of our modern mobile gizmos.

It’ll take you all of a minute to master and cost you precisely $0 to pull off. Ready?

[Get next-level knowledge in your inbox with my free Android Intelligence newsletter — one useful new thing to try every Friday, straight from me to ye.]

Gemini’s custom sound advantage

This Gemini-provided power-up very much follows the path of thinking about AI as a limited, purpose-specific tool for a narrow task — the exact sort of area where AI excels.

I won’t keep you waiting: Gemini, as I discovered whilst poking around within it recently, is really good at generating unique, custom ringtones and notification sounds based on your personal preferences and specifications.

It almost seems obvious, once you think about it. But I sure hadn’t thought about it up until now — and I suspect most other folks haven’t, either.

The advantage here goes beyond just superficial silliness, too: By creating your own custom ringtones and notification noises, you can know exactly what event your phone is alerting you to within a split second of hearing the associated sound — without having to rely on the same limited and often underwhelming pool of default options that everyone else uses (or, worse yet, having to lean on shady, ad-ridden “ringtone apps” to find mediocre alternatives). That means you’ll know within a heartbeat when your boss or an especially important client is calling or if an incoming call is a random unknown number.

On the notification front, you can create a specific, memorable sound to accompany a new message in an important work-related Slack channel and a different distinctive sound for a high-priority email. They’ll all be sounds that you make and identity with and that no one else in the world uses. That’s pretty powerful.

And creating these custom sounds couldn’t be much easier, either, once you realize it’s possible:

First, just fire up Gemini on your phone (or on any device you’re using) and tell it what you want. So, for instance…

  • Create a soft, subtle ringtone that’s reminiscent of an old office phone sound.
  • Create a ringtone that sounds like an 8-bit version of The Final Countdown.
  • Create a one-second high-pitched notification sound that brings to mind the Super Mario Bros theme song.
  • Create a short notification sound that mimics the Back to the Future time circuits noise.
  • Create a notification sound that sounds like a robot saying “ALERT, ALERT!”

The only limit is your imagination. And if you’re not feeling especially imaginative, you can even ask Gemini to give you a list of ideas for distinctive, memorable ringtones or notification sounds based on geeky nostalgia, 80s pop-metal, or whatever it is that tickles your fancy.

Once you’ve sent a request, Gemini will — somewhat confusingly — spit back a big honkin’ block of HTML code. This is because, for reasons unknown, the system can’t or won’t just provide a sound file directly. Go figure.

Ask, and ye shall receive: Gemini’s ringtone-creating prowess in action.

JR Raphael, Foundry

But from there, it’s just one more quick step to get the file you need: Click or tap the copy icon in the upper-right corner of that code block — the icon that looks kinda like two stacked, rounded rectangles — to copy the entire chunk of code onto your system clipboard.

Then open up your browser and go to the website JSFiddle.net. It’s a well-known, long-standing tool for running code like HTML right in your browser and seeing the result, and it works entirely in the browser and without any downloads or special permissions required.

Tap or click into the “HTML” field, then paste in the code from your clipboard (by long-pressing any open space, on Android, and selecting “Paste” from the menu that appears). Click or tap the “Run” button, and — ta-da: You’ll see a player to listen to your custom Gemini-generated sound and a button to download it.

The JSFiddle website makes it easy to take Gemini’s output and both play and download a sound file from right within your web browser.

JR Raphael, Foundry

Provided you like what you hear, hit the button to download the file, then head into the Sound section of your Android system settings to save it and make it available for applying as any kind of alert or ringtone. The exact steps for doing that will vary from one type of Android device to another, but on a Pixel or another phone that follows Google’s core Android interface, you’ll tap on either “Ringtone” or “Notification,” then tap “My Sounds” and tap the plus icon to import your own custom file from your phone’s local storage.

On a Samsung device, you’ll start the same way but look for the plus icon within the “Ringtone” section of the settings, then tap the “Folders” tab to find your locally downloaded files. Samsung doesn’t make it easy to add in your own custom notification sounds, annoyingly, so what you’ll have to do is open up the Google Files app, find the file you downloaded in your “Downloads” folder, then tap the three-dot icon alongside it to copy it to the folder called “Notifications.” Once the file is in that folder, it should show up as a notification noise option within the Samsung Android settings.

And remember: You can use Android’s notification channels to set specific sounds to be used for different types of alerts, even within a single app — and you can use the Google Contacts app to set custom ringtones for different people, too.

With Gemini as your personal composer, you’ll never be stuck with generic overused sounds again — and you’ll always know exactly what’s happening from the first note of whatever noise you hear.

Keep the experience-enhancing wisdom coming with my free Android Intelligence newsletter. One new useful trick in your inbox every Friday!

Kategorie: Hacking & Security

U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok

The Hacker News - 9 Září, 2026 - 11:32
U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting "systematic extraction" of proprietary functionalities and capabilities of American frontier models through distillation attacks. The activity has been described as occurring at an industrial-scale and one that forms the "core" of their AI development strategy, according to
Kategorie: Hacking & Security

U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok

The Hacker News - 9 Září, 2026 - 11:32
U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting "systematic extraction" of proprietary functionalities and capabilities of American frontier models through distillation attacks. The activity has been described as occurring at an industrial-scale and one that forms the "core" of their AI development strategy, according toRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

The Hacker News - 9 Září, 2026 - 11:11
Google on Tuesday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine. "Out-of-bounds write in V8 in Google Chrome prior to
Kategorie: Hacking & Security
Syndikovat obsah