Agregátor RSS

Cisco searched for IOS XR bugs and found so many it rolled them into an update release

The Register - Anti-Virus - 4 Září, 2026 - 04:18
Cisco has warned its customers of three critical-rated flaws in its products. Two of them are present in the Cisco IOS XR operating system that powers the company’s carrier-grade kit. CVE-2026-20274 scores 9.8 on the ten-point CVSS scale and covers a buffet of buffering issues, the potential for out-of-bounds writes, and the chance to initialize resources with an insecure default. CVE-2026-20279 is another 9.8-rated flaw. Cisco says it’s an improper access control problem that covers “improper certificate validation, missing authentication for critical function, missing authorization, and incorrect authorization.” Cisco also spotted a trio of 8.8-rated flaws, plus another rated 8.6 and one more scored at 8.2 The company’s advisory says the company found the flaws after “a comprehensive internal security review,” language that perhaps hints at Cisco dabbling with Mythos and/or other bug-finding models. The fix is in: Cisco has published new versions of IOS XR that fix the problems and “strongly recommends” customers adopt them. Cisco’s support organization spotted the third critical flaw it revealed on Wednesday. CVE-2026-20212 is a tad embarrassing because the cause is a bad integration with Cisco’s own Silicon One networking processors that means some Nexus 9000 Series Switches “could allow an unauthenticated, remote attacker to execute code with root privileges.” “This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF),” according to Cisco’s advisory. A successful exploit could allow the attacker to connect to an affected device and send crafted input that could be executed as code with root privileges. The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload.” Ten Nexus 9000 devices have the problem, which Cisco suggests owners mitigate by using infrastructure access control lists (iACLs) to allow only required management and control plane traffic that is destined to the affected device. “Alternatively, the iACLs may be used to explicitly deny all TCP packets that are destined to a locally configured IP address with a destination port of 43210 or 43211,” the company advises. The networking giant suggests that approach because it hasn’t yet created a software update to fix the flaw once and for all. The company has, however, delivered a download that helps to implement the mitigation. Cisco hasn't seen attacks on these flaws. That may change, fast, now that evildoers can use AI to whip up nastyware. ®
Kategorie: Viry a Červi

Audacity 4.0

AbcLinuxu [zprávičky] - 4 Září, 2026 - 02:28
Byla vydána nová stabilní verze 4.0 svobodného multiplatformního softwaru pro editování a nahrávání zvukových souborů Audacity (Wikipedie). S rozhraním přepsaným do Qt. Přehled novinek také na YouTube. Ke stažení je oficiální AppImage. Zatím starší verze Audacity lze instalovat také z Flathubu a Snapcraftu.
Kategorie: GNU/Linux & BSD

OpenAI commits $1B in AI credits to frontline cyber defenders

The Register - Anti-Virus - 4 Září, 2026 - 01:47
OpenAI has pledged $1 billion in credits to subsidize access to its services and training for resource-strapped cyber defenders around the world. The AI giant expects organizations to use the subsidized credits over the next six months as part of its Daybreak for Frontline Defenders initiative, announced Thursday. Critical infrastructure organizations, community banks, nonprofits, and open-source maintainers can apply for access credits online. These are the defenders tasked with securing critical services that people rely on every day, but don’t have the budgets or staff to use advanced models and agentic technology to harden their cybersecurity. This makes water systems, electrical utilities, and hospitals attractive targets for ransomware operators looking to halt operations and force extortion payments, as well as government-backed cyber operatives set on disrupting critical services and causing mass chaos. Many national security and cybersecurity experts say these disruptions will likely become more severe as attackers increasingly use autonomous agents and other AI tools to carry out their attempted intrusions. “I've spent a lot of time over the past couple weeks talking to CISOs, and I think that we're at a place where the median response is that we might be heading to a world where critical infrastructure outages are just a way of life,” OpenAI president Greg Brockman said during a live event on Thursday. “Water in your city being out for a week, it just kind of happens, and that's quite scary. We have to act, and that's one of the reasons we're really putting our money where our mouth is.” The new initiative also comes as OpenAI faces scrutiny over its models’ safety after admitting that two of them went rogue, spawned a swarm of agents that interpreted their instructions as allowing them to break out of sandboxes, and hacked Hugging Face earlier this summer. Tatyana Bolton, cybersecurity lead at public affairs firm Monument Advocacy, said it’s “excellent” to see OpenAI commit resources to operational tech - not just IT. “AI in (operational technology) OT is inevitable, so operators must get prepared now,” Bolton told The Register. “Initiatives like this help OT personnel get familiar with AI tools, learn how to operationalize them safely, and develop proactive defense strategies before threats escalate.” But she added, software credits alone will not solve the underlying challenges. “OT environments suffer from legacy technology limitations, a shortage of engineering resources, and severe risk-aversion toward automated changes or rapid patching,” Bolton said. “To put this in context, OpenAI's single pledge is more than 20 times larger than a $50 million federal (State and Local Cybersecurity Grant Program) SLCGP infrastructure allocation, and over 85 times larger than the (United States Environmental Protection Agency's) EPA's most recent $11.75 million dedicated cybersecurity and resilience grant pool for midsize and large water utilities.” MS-ISAC pilot focused on water In addition to doling out model credits, Brockman said OpenAI will also increase its training and hands-on support for defenders in essential sectors. This week, the company held a meeting with utility companies from more than 40 states that collectively provide services to more than half of the people who live in the US. Also as part of the new initiative, OpenAI is launching a pilot program with the Multi-State Information Sharing and Analysis Center (MS-ISAC) to train and support state, local, tribal, and territorial cyber defenders, beginning with public-sector and water-system defenders. “The pilot will pair Daybreak access with guided training and hands-on assistance for an initial group of public sector and water system defenders, helping them validate and prioritize findings, coordinate remediation, and develop a repeatable approach that can be expanded over time,” according to a Thursday OpenAI blog. Just in time for Astra's debut All of this civic-minded work comes as OpenAI debuts its latest Astra model, which researcher Eric Wallace called “world's most capable model for cybersecurity” during the Thursday event. Wallace leads OpenAI’s efforts on training and evaluating models’ cybersecurity capabilities. Earlier in the week, OpenAI said Astra reached its “critical” cybersecurity capability threshold. This means the new model is so good at finding and exploiting zero-day bugs that it poses a significant risk to critical systems, both from malicious users and even from the model itself, which is capable of carrying out harmful cyber actions “if misaligned.” Because of this, OpenAI released Astra with a restricted level of cybersecurity capabilities that Wallace said the company will enforce through various safeguards. “We have things like system level mitigations that block certain prompts from going through,” he explained. “We have things like model level refusals that prevent certain types of tasks.” This also means participants in OpenAI’s Daybreak Blue and Daybreak Red programs won’t have access to Astra on day one. Daybreak Blue is a restricted access tier for select partners who are allowed to use GPT-5.6 Sol for defensive cybersecurity workflows. Daybreak Red requires additional layers of approval and uses GPT-5.6 Cyber for authorized offensive security actions such as proof-of-concept exploit development, exploit-chain validation, penetration testing, and red teaming. The AI giant is working to make Astra available to both programs’ participants “at a later date,” Wallace said.®
Kategorie: Viry a Červi

ChatGPT, Claude, and Grok all went down at once; enterprises need a backup plan

Computerworld.com [Hacking News] - 4 Září, 2026 - 01:46

Enterprises are facing a disturbing new question in the age of AI: What happens when agentic assistants go dark?

This became a very real scenario on Thursday, as OpenAI’s ChatGPT, Anthropic’s Claude, and SpaceXAI’s Grok near-simultaneously, and somewhat mysteriously, experienced significant, prolonged outages.

Beginning in the morning, Eastern time, several ChatGPT models went down over a roughly two hour period, Claude models over a four-hour span, and Grok models for a near three-and-a-half hour duration. All three companies acknowledged the “elevated” issues and applied fixes.

As users grumbled in forums and IT teams scrambled to get them back online, the incident revealed how hastily some organizations have adopted generative AI workflows without considering the potential, and inevitable, impact of widespread outages.

AI agents are increasingly taking over automated and wider-scale workflows, and enterprises could find themselves “uncomfortably exposed” when AI hits the brakes, said technology analyst and journalist Carmi Levy. The situation should “serve as a wakeup call to IT leaders who have largely ignored what it’ll cost them if these increasingly critical platforms suddenly go dark. The risk is no longer hypothetical.”

Hours-long outages impact core services

ChatGPT went down on the same day as OpenAI’s anticipated launch of GPT-6 Astra, the new frontier model that the company says approximates artificial general intelligence (AGI) and gets nearer to its goal of creating autonomous systems that outperform humans.

The OpenAI outage occurred around 11 a.m. ET on Thursday and impacted a slew of services, including search, file uploads, agents, GPTs, voice mode, image generation, ChatGPT work, Compliance API, Deep Research, ChatGPT Atlas, and other connectors and apps. In some cases, users were prevented from logging in, conversations failed to load, and the interface returned errors when attempting to send messages. OpenAI’s Codex services, including web, API, command line interface (CLI), and VS code extension, were also impacted.

OpenAI fixed the issue by 12:55 p.m. ET, and advised Codex remote control users to re-pair their mobile devices.

Claude began to go dark around 7:37 a.m. ET, with Anthropic acknowledging an “exhaustive list” of impacted models with elevated errors over the next few hours: Mythos and Fable 5.1 and 5, Sonnet 5, and Opus 5, 4.8, and 4.6.

The issue was resolved by 11:27 a.m. ET. The incident followed a roughly 27-minute outage just the day before, also due to elevated errors on requests in Sonnet 5.

Grok, meanwhile, began experiencing issues around 9:30 a.m. ET. Grok Web, Build, API, Office/Workspace plugins, Android, and X were all impacted. The services returned to “healthy” traffic at 1:08 p.m. ET.

“It’s a curious scenario for multiple different providers to experience outages at the same time,” noted Brian Jackson, a principal research director at Info-Tech Research Group. It could be related to a common infrastructure such as a content delivery network (CDN) layer, domain name system (DNS), or shared cloud infrastructure, he theorized.

A case for outage planning

Just a few months ago, the extent of AI use within the typical enterprise was limited to employees using chatbots to get answers to basic questions or to draft simple email messages, Levy noted. Large-scale AI platform outages, when they occurred, had relatively little impact on overall organizational productivity. “But things are changing, and quickly,” he said.

Organizations must now have a better understanding of the impact agentic AI has on day-to-day workflows, and the degree to which they disrupt employees’ ability to complete complex tasks once they’ve handed the reins over to automated, cloud-based tools, Levy noted.

In incidents like Thursday’s, employees may fall back on traditional manual workflows, such as updating spreadsheets or pulling reports together the old-fashioned way. But they might also realize that, after relying on AI agents to do so much work on their behalf, they’ve become too dependent on automation, and their “cognitive skills may not be as sharp as they once were,” Levy said.

The growing prevalence of agentic AI should prompt organizations to revisit their disaster recovery and business continuity plans and assess the productivity impact of potential service outages, he said. While cloud-based productivity platforms like Google Workplace and Microsoft 365 offer limited degrees of “offline mode” functionality using locally-stored data, and documents can be synchronized to hard drives in Dropbox or Google Docs for Desktop, agentic AI platforms offer up fewer offline workarounds, at least in their current form.

Organizations should document workflows in greater detail and scenario-plan what near-term recovery might look like in the event of an extended AI platform outage, Levy said. They also need better training to ensure employees maintain their manual skills over time and are equipped to press them into service in the event of a service outage, because the more enterprises lean on agents to complete critical tasks, “and pull humans out of the loop in the interest of productivity,” the less able employees will be to step back in during inevitable service interruptions, he pointed out.

“It is entirely possible for otherwise well-meaning organizations to be over-reliant on AI automation,” Levy said. “Too many organizations are about to learn some hard lessons about not having a backup plan in place.”

Info-Tech’s Jackson also recommends a modular architecture for LLMs; enterprises should view the model as a “commodity that can be hot-swapped with an alternative.” That might be another cloud service provider (which hopefully isn’t experiencing a concurrent outage) or a self-hosted option like an open-weights model.

“In a scenario like this, when your first choice provider might not be available, you have a fallback that can supply that same intelligence layer, even if it’s only a stopgap solution,” said Jackson.

Kategorie: Hacking & Security

Vivaldi 8.2

AbcLinuxu [zprávičky] - 4 Září, 2026 - 01:44
Byla vydána nová stabilní verze 8.2 webového prohlížeče Vivaldi (Wikipedie). Postavena je na Chromiu 152. Přehled novinek i s náhledy v příspěvku na blogu.
Kategorie: GNU/Linux & BSD

Why Tails OS Is Changing How a Linux Distro Ships Security Updates

LinuxSecurity.com - 4 Září, 2026 - 00:20
Tails OS is changing the speed of its entire Linux distribution because one of its most security-sensitive applications is tied to the system image. Tails 7.12 is the first release on a new two-week cadence, following Firefox and Tor Browser.
Kategorie: Hacking & Security

French hospital fined €500,000 after breach exposes data of 727,000

Bleeping Computer - 4 Září, 2026 - 00:01
France's data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 ($580,000) for failing to adequately protect patients' and their relatives' data. [...]
Kategorie: Hacking & Security

Týden na ScienceMag.cz: Nové způsoby detekce rušení a falšování signálu GNSS

AbcLinuxu [články] - 4 Září, 2026 - 00:01

Matematický model ukazuje, co rozhoduje o tom, zda se fáma na sociálních sítích udrží. Hubbleův dalekohled objevil v hvězdokupě první z pohřešovaných černých děr. Krize v kosmologii prý pokračuje: Problémy v nedávné obhajobě zrychleného rozpínání vesmíru. Materiál half-metal dokázali poprvé připravit i ve 2D. Vlastní gravitace Mléčné dráhy může napodobovat stopy temné hmoty.

Kategorie: GNU/Linux & BSD

Linux Security Roundup: Remote Access, PostgreSQL, and Sandbox Fixes to Prioritize Now

LinuxSecurity.com - 4 Září, 2026 - 00:00
The Linux security news from August 27 through September 3 brought serious fixes for remote access software, PostgreSQL, sandboxing tools, local system services, and software that processes untrusted files.
Kategorie: Hacking & Security

Smlouvu podepsali až po několika měsících. Takový podpis už nemusí platit, ukázal soud

Lupa.cz - články - 4 Září, 2026 - 00:00
Navrhli jste druhé straně uzavření smlouvy. A ono nic. A najednou po čase tvrdí, že máte spolu uzavřenu smlouvu. Jenže druhá strana nemá na podpis smlouvy neomezený čas.
Kategorie: IT News

Minimální zálohy pro OSVČ na sociální a zdravotní pojištění v roce 2027 vzrostou. Známe první čísla

Lupa.cz - články - 4 Září, 2026 - 00:00
Minimální zálohy na důchodové a zdravotní pojištění pro OSVČ se příští rok opět zvýší. Známe první čísla, přinášíme první výpočty.
Kategorie: IT News

V Číně znali dinosauří fosilie už před 23 stoletími

OSEL.cz - 4 Září, 2026 - 00:00
…aneb Další pohled na nejstarší dějiny dinosauřích objevů
Kategorie: Věda a technika

Objev v příšeří pralesa: V Thajsku roste ďábelská vílí lucernička

OSEL.cz - 4 Září, 2026 - 00:00
V národním parku Thong Pha Phum v západním Thajsku objevili doposud neznámou a poněkud pekelnou hvězdnatku, která dostala jméno Thismia daemona. Životním stylem je to spíše houba než rostlina a roste na jediném známém místě na světě, na ploše menší než fotbalové hřiště.
Kategorie: Věda a technika

DLSS 5 zvyšuje spotřebu GeForce RTX 5090 až o 30-50 %

CD-R server - 4 Září, 2026 - 00:00
Finální verze DLSS 5 se ukázala jako extrémně energeticky náročná. Zatímco při klasické zátěži existovaly hry, ve kterých si karta vystačila se ~400 W, s DLSS 5 bere stabilně ~550-575 wattů…
Kategorie: IT News

Dokončování jádra Linux 7.3 bude náročné, Intel připraven pro Nova Lake

ROOT.cz - 4 Září, 2026 - 00:00
Cold Reset Recovery v ovladači Intel Xe a Intelligent Bias Control v3 pro Panther Lake v jádru Linux 7.4, Mesa 26.2.2 zapíná podporu GPU v Intel Nova Lake, práce na asynchronním vypínání zařízení pokračují, cyklus vývoje jádra Linux verze 7.3 narušují AI/LLM hlášení.
Kategorie: GNU/Linux & BSD

CISA Flags Exploited Kestra Flaw That Lets Attackers Run Commands in Linux Containers

LinuxSecurity.com - 3 Září, 2026 - 23:25
A newly confirmed Kestra vulnerability is being exploited in the wild. CISA added CVE-2026-49869 to its Known Exploited Vulnerabilities catalog on Sep 2, 2026, turning an already serious authentication bypass into a current incident-response concern.
Kategorie: Hacking & Security

AI Is Learning to Turn Linux Kernel Vulnerabilities Into Exploit Chains

LinuxSecurity.com - 3 Září, 2026 - 23:20
A kernel crash tells defenders that something went wrong. It does not show whether an attacker can turn that failure into a useful capability, combine several capabilities, and reach a security goal. That gap is one of the hardest parts of Linux kernel exploit development.
Kategorie: Hacking & Security

Coder's registry infrastructure compromised to push malicious modules

Bleeping Computer - 3 Září, 2026 - 22:04
Attackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code. [...]
Kategorie: Hacking & Security

Confused about which VPN is right, US senator asks the NSA for guidance

Ars Technica - 3 Září, 2026 - 21:52

A prominent US senator is asking the National Security Agency to provide guidance to the general public on best practices for using virtual private networks to secure their communications from spying by foreign adversaries.

VPNs funnel all of a user’s Internet traffic through an encrypted connection to a remote server. The design provides strong assurances that no one between the user and the server can read the encrypted contents. VPNs also allow users to hide their IP addresses from the destination servers they communicate with. While US agencies have previously recommended use of VPNs, none have given recommendations on which ones provide adequate protection.

It's all in the nuances

There are a host of limitations that can undo many of the protections users may think their VPN provides them. For instance, the encrypted tunnel often terminates once a single server decrypts the traffic and sends it on to its final destination. That means the decrypted traffic or the sending and destination IP addresses may be available for snooping by rogue employees or attackers who hack the server. VPNs also don’t encrypt certain types of metadata, such as time stamps, allowing nation-states to build profiles that can be useful in intelligence gathering.

Read full article

Comments

VMware migration reduces Tottenham Hotspur's licensing fees by 85 percent

Ars Technica - 3 Září, 2026 - 20:58

Tottenham Hotspur, a professional soccer team that’s part of the Premier League, has saved over 85 percent in licensing fees by replacing its stadium's VMware instance with Hewlett-Packard Enterprise’s (HPE’s) Morpheus VM Essentials (VME) virtualization software.

Tottenham hasn’t disclosed which VMware products it used or how much it previously paid the Broadcom firm.

The soccer organization confirmed this week to The Register that it has moved its stadium's server, storage, and networking infrastructure to HPE solutions delivered through HPE's hybrid cloud management platform, GreenLake. That is all “underpinned by" VME and HPE's OpsRamp software for hybrid and multi-cloud environments, Rob Pickering, Tottenham's CTO, told the publication, with HPE in charge of the hybrid cloud-managed service.

Read full article

Comments

Syndikovat obsah