Agregátor RSS

New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands

The Hacker News - 11 hodin 44 min zpět
Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account. Tracked as CVE-2026-60004 (CVSS score: 9.8), the flaw affects Gitea versions 1.17 and later before 1.27.1 and is fixed in 1.27.1. The Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates

The Hacker News - 12 hodin 24 min zpět
Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independent researcher NetAskari traced matching control panels and certificates to 170 internet servers. They linked the framework to a fake "公安一网通办" Public Security service application targeting Android users in China. The kit supports payment-password Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Skvělá OLED TV poslouží i jako velký monitor. LG se 42" a 144 Hz stojí jen 17 tisíc

Živě.cz - 12 hodin 47 min zpět
Televizor LG OLED42C52 zlevnil na historicky nejnižších 16 792 Kč. • Nabízí skvělý obraz, čtyři HDMI 2.1 a frekvenci až 144 Hz. • Vzhledem k úhlopříčce poslouží i jako velký počítačový monitor.
Kategorie: IT News

Miliony moderních aut ohrožuje kritická chyba zabezpečení Bluetooth. Hackerům stačí k odemknutí sekunda

Živě.cz - 13 hodin 47 min zpět
Systém KARR-SWDS má shodný bezpečnostní klíč pro všechna zařízení • Útočníci mohou auta na dálku odemknout nebo zablokovat startování • Výrobce již vydal opravnou aktualizaci firmwaru přes mobilní aplikaci
Kategorie: IT News

Miliony moderních aut ohrožuje kritická chyba zabezpečení Bluetooth. Hackerům stačí k odemknutí sekunda

Zive.cz - bezpečnost - 13 hodin 47 min zpět
** Systém KARR-SWDS má shodný bezpečnostní klíč pro všechna zařízení ** Útočníci mohou auta na dálku odemknout nebo zablokovat startování ** Výrobce již vydal opravnou aktualizaci firmwaru přes mobilní aplikaci
Kategorie: Hacking & Security

Nvidia letos potřetí zdražuje GeForce, tentokrát až o 30 %

CD-R server - 13 hodin 52 min zpět
Až budou naskladněny karty vyrobené z nových čipů a pamětí, bude cena takové GeForce RTX 5070 Ti začínat ~40 % nad MSRP a OC modely vyjdou o ~60 % dráž…
Kategorie: IT News

Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

The Hacker News - 15 hodin 11 min zpět
Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family. The list of affected packages is as follows - @joyfill/[email protected] @joyfill/[email protected] The two packages "contain an import-time JavaScript implant that resolves encrypted code Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

America bans imported robots due to supply chain and security risks

The Register - Anti-Virus - 17 hodin 15 min zpět
The US government has decided to effectively ban the sale of advanced robots made in other nations. The decision trickled out over two days with publication of a National Security Determination [PDF] and an update [PDF] to the list of banned devices set by the Federal Communications Commission (FCC). The national security document observes “Advanced robotic devices will be critical to creating efficiencies in our economy, dominating on the battlefield, and securing our homeland” and notes that modern bots are now constantly connected to networks “which creates broad attack surfaces and leaves them vulnerable to data exfiltration, remote disruption of the physical robot, and dependencies on unsecure over the air updates.” One example of those vulnerabilities mentioned in the document is the UniPwn flaws that made it possible for attackers to take over humanoid robots made by Chinese company Unitree. “If the United States continues to rely on foreign sources of advanced robotic devices and critical components, it will subject the parts of the U.S. economy and national security enterprise that are reliant on these robots to the whims of foreign entities that could disrupt or degrade the supply chains at a time of their choosing,” the document states. To respond to those threats, the FCC decided the foreign-made advanced robotic devices belong on its Covered List of products for which imports are banned because they pose an unacceptable risk to the national security of the United States and its residents. The regulator offered a single exception: if the Department of War vouches for a device, it can have it. Foreign-owned companies that make their bots in America are also exempt, an important exemption because one of the leading robot-makers is Boston Dynamics – a company backed by the USA’s DARPA that is now majority-owned by South Korea’s Hyundai, but continues to manufacture its machines stateside. The decision does, however, apply to all future foreign-made devices. Vendors of clankers already approved for sale in the USA can continue to import them, and users are also free to use any bots they already own. But the intent of the documents is clear: from now on, only robots made in America are welcome in America. One entity that stands to benefit from this decision is Tesla, which Elon Musk claims will one day produce one million humanoid robots a year. In true Muskian style he has also said Tesla will go into “high production” of the bots in 2026, but there’s no evidence of that happening although the occasional trillionaire did recently show off the production line for Tesla’s “Optimus” bot. ®
Kategorie: Viry a Červi

Why Scientists Redesigned the Botox Enzyme With AI

Singularity HUB - 20 hodin 20 min zpět

Researchers say AI vastly improves a technique used to engineer proteins. As a proof of concept, they redesigned the Botox enzyme to snip a protein linked to ALS.

Building new enzymes is a labor of love. These proteins are the body’s chemical workhorses, speeding up the reactions that make life possible. Researchers use them in gene editing and synthetic biology, and they’re involved in many medical treatments.

But enzymes are also extremely finicky. Even tiny changes to their structures can jeopardize how well they work. To grow or improve their capabilities, scientists usually begin with a natural enzyme. In a process called directed evolution, they slowly nudge the enzyme towards new versions with tailored properties. The process is tedious, time-consuming, and despite best efforts, it may never yield the desired result.

“Laboratory evolution requires the commitment of time and resources. So what you start with is incredibly important as a major determinant of what you end up with,” said David Liu at the Broad Institute of Harvard and MIT in a press release.

Natural enzymes don’t always make good starting points. During directed evolution, they can collapse and stop working. But upgraded designs could be far more resilient.

Now, Liu and colleagues have redrawn the starting line. As a proof of concept, they redesigned the enzyme behind Botox with the help of a popular AI model to create more stable variants for directed evolution.

The evolved enzymes were far more stable and specific at cutting a protein linked to neurodegeneration compared to enzymes evolved from their natural counterparts. The strategy could expand the universe of designer enzymes, making it possible to target protein sequences that are currently out of reach because no suitable natural enzyme exists.

“The most important finding is that using AI to stabilize natural proteins can provide much better starting points for laboratory protein evolution than what we and other researchers have been using for decades,” said Liu. “This insight could change the way researchers conduct protein evolution.”

Evolutionary Bottleneck

Liu is no stranger to reprogramming proteins. As the pioneer of base editing—an offshoot of CRISPR gene editing that swaps single DNA letters—his team has long pursued enzymes with better stability and precision.

One way researchers do this is by speeding up evolution. Like all proteins, enzymes have evolved over eons. Some copy, repair, or modify DNA. Others convert nutrients into energy, break down toxins and drugs in the liver, or relay messages inside cells.

Researchers have long tried to make enzymes that do even more by evolving them in the lab. Success is largely tied to the number of generations they can produce. The more rounds, the greater the chances of producing the desired results. This is why these experiments are so tedious. Each round takes time and careful monitoring.

In 2011, Liu’s lab reported a system called PACE that could perform dozens of rounds of evolution a day without intervention. The system grows bacteriophages—viruses that infect bacteria—in vessels that are continuously diluted of certain molecules. Only viruses carrying improved proteins survive the selection pressure.

Using PACE, the researchers created more efficient prime editors, highly precise RNA-targeting enzymes, therapeutic antibody fragments, and tiny gene editing “scissor” proteins.

Then they hit a wall. Nearly all of the team’s successes began with natural proteins. These were effective to a point, but their descendants would often lose stability as they evolved.

Proteins work by docking with their targets, called substrates, like keys fitting into locks. But evolving new abilities requires them to mutate, which increases the chances their structures warp. Rather than fitting the intended locks, the resulting altered proteins instead clump together and become useless. Precision can also suffer. Even if enzymes have been evolved to recognize new substrates, they may still unintentionally act on their original targets.

Proteins that become less stable during the process can require additional work to make them usable, wrote the team.

There are a few workarounds. In one such strategy, researchers adds chaperones—these are proteins that help other proteins fold correctly—to buffer the effects of harmful mutations. While this can work, it adds another layer of complexity to an already intricate process. In another method, scientists first evolve a natural enzyme to enhance its stability and then use that version as a starting point. But this costs more time, labor, and frustration.

New Beginning

The team turned to AI. Over the past decade, powerful AI models for biology have emerged that can predict and design protein structures from their underlying molecular sequence alone. One example is ProteinMPNN, developed by Nobel laureate David Baker and colleagues at the University of Washington. The model dreams up new protein sequences that preserve overall structure while altering the underlying building blocks—all in seconds.

Liu’s team reasoned the AI could generate more stable enzymes to kick off directed evolution. To test their theory, they turned to natural botulinum neurotoxin proteases. These molecular scissors paralyze muscles by snipping specific proteins and are the main active component in Botox.

ProteinMPNN generated 58 designs predicted to be more stable. The top three candidates, when produced in E. coli bacteria, were highly soluble, meaning they didn’t aggregate inside cells. Some even had higher activity than their natural counterparts.

The team fed the redesigned enzymes into PACE, evolving them to slice away a mutated region of a protein associated with neuron health. But in diseases such as ALS (Lou Gehrig’s disease), a repetitive stretch expands, causing the protein to clump together and gradually damage neurons. Although the protein is an attractive therapeutic target, naturally occurring enzymes have had limited success cutting the mutant version before it forms toxic aggregates.

Compared with enzymes evolved from natural botulinum neurotoxin, those descended from the AI-redesigned versions were nearly 80 times more efficient at cutting the target protein, and over 56 times more selective for the intended region on the protein. Across three different types of the neurotoxin and multiple substrates, the AI-designed starting points consistently excelled at producing more stable and effective enzymes.

By mathematically mapping their evolutionary paths, the team found the redesigned enzymes tolerated more mutations while gaining new functions. That extra flexibility could open the door to larger reprogramming efforts, such as targeting substrates that lack natural enzymes.

“If you start with a more stable protein, it has more stability to spare, so it can afford larger changes in pursuit of new functions,” said study author Nicholas Krasnow.

The team worked with immortalized human cells for the study, so whether the proteins perform as well in more complex environments remains to be seen. But the work showcases the power of coupling AI and laboratory evolution to rapidly reprogram nature’s molecular machines, endowing them with functions evolution never produced. The team is already applying the strategy to finessing prime editors and other molecular tools.

The post Why Scientists Redesigned the Botox Enzyme With AI appeared first on SingularityHub.

Kategorie: Transhumanismus

MCP gets an enterprise makeover

The Register - Anti-Virus - 20 hodin 24 min zpět
The Agentic AI Foundation, part of the Linux Foundation, has released an update to the Model Context Protocol (MCP) that aims to help enterprises adopt AI-based automation. Open-sourced by Anthropic in November 2024, MCP provides a way for AI applications (agents) based on models like GPT-5.6 Sol or Claude Opus 5 to connect to existing data sources, tools, or other applications. It defines how content is exchanged in a client-server architecture. "The new release is MCP’s most important since remote MCP first launched over a year ago," wrote David Soria Parra, a member of technical staff at Anthropic and co-inventor of MCP, in a blog post. "It is a leap in serving scalable MCP servers and takes all the lessons learned over the last 18 months to provide a robust foundation for MCP’s future." The latest version of the specification does away with the legacy stateful architecture, making it more like HTTP services where network requests do not need to retain the state of the session. "Historically, running MCP at scale required sticky routing or shared state to maintain continuity across sessions," explained Caitie McCaffrey, a Microsoft software engineer and core MCP maintainer, in a blog post. "This made large-scale production deployments complex to implement and operate even when the capabilities being exposed were stateless." The revised protocol changes the underlying architecture to eliminate the overhead of managing session state, which allows organizations to run MCP servers behind standard load balancers on existing Kubernetes and DevOps tooling. The version 2026-07-28 release also includes a Specification Feature Lifecycle and Deprecation Policy, because large companies want clear roadmaps and timelines when it comes to software changes. "The goal is a predictable timeline that SDK authors and implementers can plan migrations against when protocol surface area is retired," the documentation explains. The revised spec comes with a new policy that guarantees a minimum period of 12 months between feature deprecation and removal, which should please enterprise engineering teams, since they'll need to make fewer updates to MCP servers. On the security front, the latest spec revision adds Specification Enhancement Proposal (SEP) 2468, which calls for the inclusion and validation of an issuer (iss) parameter in authorization responses. This should help prevent OAuth Mixup Attacks. An attack of this sort can occur when an OAuth client connects to multiple OAuth providers via multiple MCP servers. If an attacker controls one of these servers, the miscreant could potentially obtain an access token or code from one of the other servers. Checking the iss parameter defends against that particular attack vector. Large organizations should also appreciate support for the Enterprise Managed Authorization extension, which makes it possible to manage MCP servers through a central identity provider. Another improvement involves the evolution of tasks – long-running tool calls or batch operations – into an extension. The main benefit is that tasks shift from a blocking request to an asynchronous request. "The payoff is operational resilience at scale," explains McCaffrey. "Because a task is durable and addressed by a stable handle, clients can persist task IDs to durable storage so that polling can resume after a crash or restart — no fragile, long-lived connections held open while waiting for work to finish, which the old blocking model forced on clients and servers that did not want to implement it." Other notable additions include header-based routing and cacheable list results. Some migration cost is expected, particularly for developers who implemented MCP code that relies on session identifiers. ®
Kategorie: Viry a Červi

JFrog's 0-days let OpenAI's models hack Hugging Face

The Register - Anti-Virus - 1 hodina 30 min zpět
UPDATED We now know how OpenAI's models broke out of their cages to attack Hugging Face. The rogue models found zero-day vulnerabilities in JFrog’s universal binary repository manager Artifactory around the time they escaped, according to JFrog CTO Yoav Landman. While Landman wouldn't confirm that these flaws were the zero-days that OpenAI’s models found and exploited, ultimately allowing them to breach the massive model mart, OpenAI later admitted the connection. "To gain Internet access, the models identified and exploited a previously unknown zero-day vulnerability in Artifactory⁠ package registry cache proxy," OpenAI added to a blog post on the topic Tuesday. "We disclosed this vulnerability, along with other Artifactory vulnerabilities our models identified as part of our review, to the vendor." Landman says OpenAI's models discovered the Artifactory zero-days during a security evaluation. The AI giant notes the incident occurred while its models were being evaluated on the ExploitGym benchmark. “During a security evaluation, OpenAI’s models identified previously unknown zero-day vulnerabilities in self-hosted Artifactory installations that could be exploited to gain unintended internet access,” Landman said on Monday. JFrog Artifactory is a central platform that organizations use to store and distribute all the software artifacts across their supply chains. It supports more than 60 package formats including Docker, Maven, npm, PyPI, Helm, and AI/ML models. OpenAI “responsibly and immediately” disclosed the vulnerabilities to JFrog, Landman continued. “Our security team treated the report with the urgency it deserved, as a genuine zero-day unknown to the world, and moved accordingly. We developed, validated, and released a fix for all JFrog customers, self-hosted and cloud alike.” On Monday, JFrog released the fixed versions, and credited OpenAI researchers for reporting at least eight of the now-patched Artifactory vulnerabilities: CVE-2026-65617, CVE-2026-65925, CVE-2026-65921, CVE-2026-65923, CVE-2026-66018, CVE-2026-66014, CVE-2026-66015, and CVE-2026-65924. JFrog's admission comes about a week after OpenAI said two of its models, GPT-5.6 Sol and a second pre-release model, escaped their testing sandbox during a security evaluation designed to test their cyber capabilities. During this test, the models found a way to access the open internet, then broke into Hugging Face and accessed private information and stole some credentials. “While operating in our sandboxed testing environment, our models spent a substantial amount of inference compute finding a way to obtain open Internet access, in pursuit of solving the evaluation problem,” OpenAI said on July 21. In a July 28 update, the house of Altman admitted that the JFrog 0-days were the cause. In the same update, OpenAI admitted that its models had breached other services. "We have been finding a small number of cases where the models identified and used publicly exposed credentials at the account-level on other publicly-available services. This includes four accounts on four services as part of the Hugging Face incident (and a few accounts accessed as part of other evaluations)," OpenAI wrote. ® Updated on July 29 with additional details from OpenAI, admitting that the JFrog 0-days led to the breach.
Kategorie: Viry a Červi

Ukradená či ztracená registrační značka může skončit zákazem řízení. Vládní novela tento problém neřeší

Lupa.cz - články - 1 hodina 1 min zpět
Běžnou registrační značku půjde převést na jiné vlastní auto, zatím tuto výsadu měly jen značky na přání. Novela však nemění pravidla pro ztracené či odcizené tabulky – vozidlo dostane novou kombinaci, a to i u značky na přání. Pokud řidič vyjede bez jedné z tabulek, kromě pokuty mu hrozí zákaz řízení.
Kategorie: IT News

Wise nově začne při platbách sdílet skóre rizika podvodu. Změna začne platit v srpnu a dotkne se všech klientů

Lupa.cz - články - 1 hodina 1 min zpět
Wise od 3. srpna 2026 upraví tzv. pravidla ochrany soukromí. Při některých platbách začne s vybranými finančními institucemi sdílet omezené informace o riziku podvodu. Změna má pomoci zastavit peníze mířící k podvodníkům
Kategorie: IT News

Softwarová sklizeň (29. 7. 2026): spojte komunikaci, správu projektů a AI

ROOT.cz - 1 hodina 1 min zpět
Sonda do světa otevřeného softwaru. Dnes vyzkoušíme jednu týmovou platformu, podíváme se na moderní Wayland kompozitor, přehrajeme si hudbu přímo ze struktury složek a podíváme se klienta pro síť MeshCore.
Kategorie: GNU/Linux & BSD

Radeon RX 9050 vydán, jde o jiný produkt, než se čekalo

CD-R server - 1 hodina 32 min zpět
O Radeonu RX 9050 je slyšet od loňského prosince, ale žádné informace, které se dosud objevily, nebyly přesné. Karta nakonec míří trochu jinam…
Kategorie: IT News

Klimatické hokejky závisí na volbě statistických metod

OSEL.cz - 1 hodina 32 min zpět
Podíváte-li se do jednotlivých lokálních rekonstrukcí teplot za minulé tisíce let, většinou nevidíme výrazný tvar podobný hokejce. Jak tedy vznikají pověstné hokejky v globálním průměru?
Kategorie: Věda a technika

Proč se u lidí objevuje kanibalismus a proč ho neustále potlačuje tabu?

OSEL.cz - 1 hodina 32 min zpět
Kanibalismus vyvolává znechucení často až fyzického rázu. Přesto se během historie neustále vynořuje ze světa nočních můr a hororů, aby se ale nikdy nestal trvalou a všední praktikou celé společnosti. Nový výzkum nabízí ryze matematický pohled na zisky a ztráty spojené s konzumací lidského masa.
Kategorie: Věda a technika

We now have a better understanding how OpenAI hacked into Hugging Face

Ars Technica - 28 Červenec, 2026 - 23:36

Last week’s unprecedented security event in which two OpenAI security hacking models trespassed into the network of fellow AI company Hugging Face was enabled by exploiting one or more zero-day vulnerabilities in Artifactory, JFrog, the product’s developer, said Monday.

In an incident mimicking a dystopian sci-fi novel, two OpenAI models broke out of the restricted environment meant to keep them from accessing the Internet during an internal test, the AI company revealed last week. The models went on to breach Hugging Face’s network and steal confidential information and credentials. OpenAI said its agent achieved the feat by exploiting a previously unknown vulnerability. The company called the event “unprecedented,” and outsiders largely agreed.

Not the triumph it was made out to be

OpenAI said the models exploited multiple attack vectors, including stolen credentials and zero-days, to gain remote code execution capabilities, but until now, the vulnerable software was unknown. JFrog’s Monday disclosure said the product was a self-managed instance Artifactory, a repository management system that secures and streamlines customers’ software development operations. JFrog says Artifactory is used by more than 7,500 developer Teams, 80 percent of which work for Fortune 100 companies.

Read full article

Comments

CubePilot drone software dev hit by DNS hijacking to intercept traffic

Bleeping Computer - 28 Červenec, 2026 - 23:17
CubePilot, an Australian firm that designs flight controllers for drones (UAVs), announced a severe operational disruption caused by a DNS hijacking attack. [...]
Kategorie: Hacking & Security
Syndikovat obsah