Agregátor RSS
Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution. [...]
The disgruntled security researcher known as Nightmare Eclipse (aka Chaotic Eclipse, Infinite Nightmare, and now also MSNightmare) is moving away from their singular Microsoft vendetta and on to other vendors. On Thursday, they dropped a new zero-day bug called FalconFlank that affects CrowdStrike’s Falcon endpoint security platform - albeit with a Windows link. According to the prolific zero-day hunter, FalconFlank is a privilege escalation vulnerability that abuses the Microsoft Office malicious macros remediation feature in CrowdStrike Falcon. This is an automated security tool built into the platform that inspects Microsoft Office documents. If it finds any potentially harmful macros, the feature strips the suspect code and - hopefully - prevents malicious code or other dangerous payloads from executing when users open the document. “We are actively investigating these claims and advise customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting,” a CrowdStrike spokesperson told The Register. “Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. We refer customers to the FalconFlank Tech Alert in the CrowdStrike support portal.” The proof-of-concept (PoC) exploit works on fully updated Windows 11 25H2 and Windows Server 2025 systems running CrowdStrike Falcon with Phase 3 - Optimal Protection as well as the malicious macro removal feature enabled, Nightmare Eclipse said in a GitHub README. “Obviously by the time I drop this Crowdstrike would already have detections for it so if you want to test you either have to add it to the exclusions or obfuscate the PoC and change the dll load technique,” they wrote. Security sleuth Kevin Beaumont confirmed this exploit works, along with several others Nightmare released over the past week. Beaumont told us that he’s not surprised to see Nightmare digging into other, non-Microsoft zero-days. “Kinda makes sense they’d branch out to other vendors as there’s problems across the endpoint security space with the quality of the security products in terms of…security unfortunately,” Beaumont told The Register. “Hopefully it causes cybersecurity vendors to up their game, stop hyping hypothetical AI attacks, and instead make their own products secure for customers.” FalconFlank follows other vulnerabilities in various endpoint and antivirus products that Nightmare has found and published in the last several days. These include HardBreacher, an elevation of privileges bug in Kaspersky’s endpoint antivirus product. “So the problem is now leaking outside of Microsoft,” Nightmare said when they published the HardBreacher PoC last week. “There was poll held against either finding a bug in the home or commercial version and the poll results were the commercial version. At the time of writing this, the proof of concept works in a fully patched windows 11 25H2 & Kaspersky for Endpoint v14.0.0.504.” Beaumont confirmed that Nightmare’s HardBreacher exploit code works, as does a PoC for an elevation of privileges vuln in Gen Digital’s Avast antivirus software. This zero-day, named PrettyPrague, “will dump the SAM database by abusing a vulnerability in Avast Sandbox and spawn a full SYSTEM shell,” according to the researcher. "Gen was recently made aware of a security vulnerability affecting a subset of Gen products, including Avast Antivirus, that could allow an attacker to elevate their system privileges," Gen Digital told The Register. "We immediately initiated our security response procedures and are actively developing a patch. We take all security matters seriously and are committed to addressing this issue swiftly." Kaspersky did not immediately respond to The Register’s requests for comment. Nightmare also recently released an Nvidia memory corruption zero-day vulnerability dubbed GreenSection, but according to Beaumont, this one just crashes the system. Nvidia did not respond to our inquiries.® Updated to add at 0905 PT on September 4, 2026 "Kaspersky has resolved the HardBreacher issue. The corresponding fix is delivered via an automatic update, or users can trigger a database update manually," the company told The Register. "During our investigation into the reported issue, we identified an opportunity to enhance our existing behavior-based detections to ensure overall stability and prevent system freezes under certain configurations."
The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone might open the door?
That idea runs through this edition. Attackers use real tools, fake login pages, old account links, and software guides that point to unsafe downloads. One wrong letter in a web address can be enough.
There is also
The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone might open the door?
That idea runs through this edition. Attackers use real tools, fake login pages, old account links, and software guides that point to unsafe downloads. One wrong letter in a web address can be enough.
There is also Ravie Lakshmananhttp://www.blogger.com/profile/ [email protected]
Ministerstvo spravedlnosti USA podpořilo OpenAI ve sporu s New York Times. • Trénink modelů je podle vlády transformativní, jde tedy o fair use. • V EU spor nic nezmění, máme vlastní pravidla a AI Akt.
Microsoft’s text suggestion feature will now be turned off by default in both Word and Outlook, reports The Register. The text suggestions attempt to predict which words or phrases the user intends to type in advance.
According to Microsoft, some users appreciate the feature, while others find the suggestions distracting. With it disabled by default, interested users can now choose for themselves whether they want to turn it on manually.
It is unclear whether the change will disable text suggestions for existing users who already have the feature enabled, or if it applies only to new installations and profiles.
The change applies to Word for Windows, the web, iOS, and Android, and to classic Outlook for Windows and Outlook for Mac. Rollout timing will be communicated through the Microsoft 365 admin center and release notes, Microsoft said.
This article originally appeared on Computer Sweden.
Related:
A serious vulnerability was recently discovered in Exchange Server 2016, Exchange Server 2016, and Exchange Server Subscription Edition (SE). The vulnerability is designated CVE-2026-62911 and can be exploited by hackers to gain full access to affected systems, according to Bleeping Computer.
Microsoft has released security patches to address the vulnerability as part of its August 2026 Patch Tuesday release, but there are still 21,899 unpatched servers at risk, according to The Shadowserver Foundation. The highest concentrations of vulnerable servers are in the US and Germany, the security group said.
The Netherlands National Cyber Security Centre and other agencies have urged admins to install the latest patches as soon as possible.
This article originally appeared on Computer Sweden.
Related:
Microsoft a Meta jsou obří firmy s mnohamiliardovými zisky, které každoročně výrazným tempem rostou. Přesto odmítají investovat do vývoje nativních programů pro Windows a náklady přenášejí na uživatele. Peníze jsou opět jen na prvním místě.
Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version.
The Nexus vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), is
Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version.
The Nexus vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), isSwati Khandelwalhttp://www.blogger.com/profile/ [email protected]
Oživeno 3. září | Tohoto „kolonožce“ jsme poprvé viděli v lednu v Americe (info níže), teď si odbyl evropskou premiéru. Lačně jsem odroloval na konec tiskové zprávy, abych zjistil cenu a datum uvedení na trh, ale na tyto informace je stále příliš brzy.
„Evropská premiéra“ v tomto případě znamená ...
Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts.
"Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial
Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts.
"Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercialSwati Khandelwalhttp://www.blogger.com/profile/ [email protected]
I’ve been writing about Apple and how it benefits the enterprise for so long it’s easy to forget that the company doesn’t make enough noise about its accomplishments.
Sure, it has pursued and won the argument about Total Cost of Ownership, proving that while initial costs might be higher, dollar for dollar Macs are a far more cost-efficient platform, particularly when it comes to product reliability and tech support.
Apple already offers so much
Apple has also introduced extensive tools and APIs to help manage enterprise Macs, spawning a wide ecosystem of providers — most visibly, Jamf. Certain Apple products are already becoming deeply ingrained in some key professions; just think about Vision Pro and what it offers in medical care or prototype design, or the tens of thousands of Macs being carried around by AI developers across all the big name firms.
Some of what Apple delivers is already of major benefit to enterprise users. MLX for example, is being actively used to support real-life AI implementations, including by active AI-based businesses such as Yembo. And simplicity and ease-of-use isn’t just an advantage to consumer users, it boosts productivity in enterprise, too.
Almost 10 years ago, the focus was all about mobile enterprise, something that hasn’t gone away. Indeed, it is arguable that with Siri AI and third-party AI partners, Apple’s mobile enterprise story has become even more compelling. All the same, even then it was crystal clear that Macs had a big part to play in the future of enterprise tech. The iPhone accounted for 72% of all enterprise smartphone activations back then, while Jamf data has consistently shown us the steady forward momentum Mac has in business.
So why hide the light?
As former Apple Enterprise Marketing Manager Todd Dailey points out, Apple does have some people it trusts to tell its business and enterprise stories. But it isn’t investing very much in making sure they have stories to tell. For example, he notes just one enterprise-related story on the Apple website. Published in Chinese only, that story is about Haidilao, which is seeing serious TCO and energy consumption benefits by running its back-end operations on Mac minis.
He also points to a near-mythical Apple-in-business event the company ran in Cupertino last June. That event generated almost no coverage anywhere, because no one was there to report on it. And yet it gathered leaders from Disney, Ford, Anthropic, Perplexity, Christie’s and presumably elsewhere to talk about how they use Macs in business, many with a focus on enterprise AI. I’ve spent time trying to track down additional information from that event, but there is not much out there. And while I’m willing to accept that some of those who took part needed business confidentiality, it was a semi-public event, so it seems unlikely significant secrets would have slipped out.
It feels like a lost opportunity. Imagine the follow-up if Apple had paid a media team to attend the event to churn out stories, develop case studies, shoot video, and make viral influencer tik-toks. Is it that Apple doesn’t believe in its own enterprise offer? I don’t think so. It has a small army of business experts available to customers in stores, and they wouldn’t be there if it didn’t see a need for them.
Overcome myopia
Dailey thinks it’s a disconnect generated by Apple’s traditional focus on consumer markets. He’s probably correct, but it is frustrating; the real value Apple offers enterprise IT has been crystal clear for years – certainly since before then-Apple CFO Luca Maestri declared that Apple had set a new enterprise revenue record back in 2017. “Corporate buyers reported a 96% satisfaction rate and a purchase intent of 68% for the June quarter,” said Maestri at that time.
With that kind of momentum across such an extensive length of time, the company has without doubt built strong foundations of enterprise success. But these emerge most frequently as short footnotes in CFO statements during fiscal calls, rather than being shouted from the rooftops.
Here are some details
Highlights announced during those calls since 2024 include:
- Nvidia launched a Mac-as-choice program with more than 10,000 Macs deployed worldwide.
- UC-San Diego Health became the first hospital in the world to test Vision Pro spatial-computing apps in clinical surgical trials.
- BMW Group deployed tens of thousands of iPhones, including to factory employees.
- Capital One expanded its “Mac Choice” program with thousands more MacBook Airs.
- Crédit Agricole (France’s leading retail bank) turned to on-device AI on the MacBook Pro to cut regulatory-workflow processing time by more than 80%.
- Perplexity selected the Mac as its preferred platform for building enterprise-grade AI agents.
Apple knows these wins exist, and recently launched Apple Business, the all-in-one platform that combines hardware, software, and enterprise services to manage large-scale deployments. This showed the company knows what’s going on.
Mac does AI
Follow the money and it feels as if the next stage of the Apple-in-the-enterprise journey will at least in part be built around AI; Apple has major advantages it should celebrate with the sector. It offers the best systems for on-device AI, use and development. MLX is unique, ahead of its time, and worth leaning into. Its commitment to privacy is becoming increasingly and recognizably important to enterprise professionals. Even its battles to protect encryption are fundamental to business success.
Lots of its customers, not just Perplexity or Crédit Agricole, already see the advantages.
The successes it already has should be celebrated on the company’s own enterprise websites, and the company should recognize and invest in those stories and share them. Dailey points out that developers at Nvidia, Anthropic, OpenAI, and most enterprise AI shops all already use MacBook Pros for portable AI, suggesting a campaign around “Mac Does AI” should be in place. I see his point. I hope Apple does.
Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, and follow me on BlueSky, LinkedIn, or Mastodon.
Microsoft says a known issue that reverts mouse settings after installing the KB5120998 August 2026 preview update affects only non-English Windows 11 systems. [...]
ChatGPT and Codex are experiencing a major outage, with users reporting errors across nearly every major ChatGPT feature. [...]
Claude is experiencing an outage, with users encountering elevated errors when sending requests to multiple Anthropic AI models. [...]
A decade or two ago, board executives asked "why should I care about cybersecurity?" Five years ago, they were asking "Are you patching our software vulnerabilities?" Now, they're starting to ask: "Are we actually secure?" They might want a simple 'yes' or 'no' initially, but eventually they'll say the most dreaded thing of all, and it'll be a demand, not a question: "Prove it". Traditional vulnerability management and patching, won't survive that conversation. It's why a relatively new approach is gaining traction: Continuous Threat Exposure Management (CTEM). What's wrong with vulnerability management We define security flaws using Common Vulnerabilities and Exposures (CVEs), and we tell each other how bad they are by assigning the Common Vulnerability Scoring System (CVSS) to them. There are three problems with that. There's a firehose of CVEs, the CVSS scores aren't helpful when triaging them, and AI is about to make the whole thing much worse. CISOs are drowning in CVEs. The industry has spent decades creating tools that churn out vulnerability data and others that consume it. Few if any tell you which vulnerabilities an attacker could use to hurt you in your environment. The volume of CVEs is making traditional vulnerability management (patch it and forget it) less tractable every year, says Drew Vanover, principal security strategist at Horizon3. "Think about the last patch release that Microsoft put out," he says. "There were over 500 fixes in one patch cycle. That is incomprehensible. Nobody is going to be able to go through, vet, prioritize, and deploy all of those in a way that is truly considered safe." The number of CVEs created each year has been soaring, putting more pressure on the US’ National Institute for Standards and Technology's National Vulnerability Database, which has now been backlogged for years. NIST threw up its hands in April and effectively declared CVE bankruptcy. The US Department of Commerce highlighted the second issue (that current severity metrics aren't useful) as part of a report this May. Aside from launching a zinger at the NIST by saying that the NVD was poorly managed, it also suggested that it stop assigning CVSS scores altogether. These are highly subjective, it said. They also depend on exactly what the exposed system is doing in a particular organization's infrastructure. Is a critical severity score in a product important if only one sandboxed system ever interacts with it? Or could an attacker chain three apparently innocuous vulns to cause damage that a business executive would care about? AI will make vulnerability management harder These complex problems are a headache, but AI is about to turn it into a full-on migraine. Frontier LLMs like Claude's Mythos are already surfacing zero-days at scale, heralding a flood of CVEs. They don't just find bugs at scale; they also work much more quickly than their human counterparts to create and weaponize exploits. This makes it even more important that organizations patch the right bugs quickly. The Cloud Security Alliance now describes an asymmetric vulnerability cycle in which attackers can use AI to discover and exploit vulnerabilities more quickly, (increasingly before patches are even released), while organizations are taking longer to patch them. What is CTEM? Something has to change. Gartner figured this out in 2023, when it named CTEM a top cybersecurity trend. This is a way of staying on top of your vulnerabilities by triaging them properly. To do that, you have to go beyond the technical implications of a security flaw and understand what it really means for your business. Gartner lays out five steps to CTEM: ● Scoping Find the assets that carry significant business impact and prioritize them. ● Discovery Find how they're exposed by analyzing their weaknesses in depth. ● Prioritization Rank those exposures based on real business risk. ● Validation Test out the vulnerabilities to see if they're exploitable. ● Mobilization Fix them with a proper incident response plan. How automated pen testing helps manage vulnerabilities This approach promises to nail the security flaws that matter to an organization, but it's also more complex than traditional vulnerability management. It needs automation, which is what Horizon3 is providing with NodeZero. Scoping out systems is a commodity practice these days. So is discovery. Horizon3 is leaving those to partners so it can focus on the parts of the CTEM framework that aren't yet easy for customers to solve. Those are prioritization by business impact, and mobilization. NodeZero runs penetration tests across an organization's infrastructure and documents the exploitable paths with evidence a defender can follow. The output is the wheat sifted from the chaff; a shorter list of exposures that security teams and developers can focus on. The impressive part here is the chain-of-attack behavior. NodeZero probes for weaknesses, exploits them, and then pivots based on what it finds. This means it adapts to the environment to extend its attack, just as a real attacker adapts attacks and moves laterally through systems. This approach is based on a deterministic machine learning expert system rather than a general LLM, explains Vanover. "A good analogy is to think about the medical profession," he says. "A GP is your general LLM trying to cover everything. They know a little bit about a lot, but they aren't the experts, and that's where you start having hallucinations and guesses and misses." The company only uses generative AI for specific tasks. Using it to parse a two petabyte S3 blob looking for sensitive data or identifying high-value credentials, with data staying inside the customer's boundary via AWS Bedrock, for example. What it doesn't do is run amok spawning rogue agents in your system. Vanover says the value here is in proving that you've clobbered load-bearing security bugs. "If we say that we can exploit something, it's because we did, and we'll show you the proof in the platform," he says. The next step is closing the loop by retesting the exploit after it's been dealt with. Teams get to close tickets because NodeZero can no longer traverse the attack path. That is a testable definition of "fixed" and one that translates into a risk metric a CFO can read. Horizon3 also wants to solve customers' tool sprawl problems with a single product that handles all of the heavy CTEM lifting. A common failure mode of enterprise CTEM programs is a stack of vendors whose handoffs create precisely the blind spots the framework was meant to eliminate. That disappears when it's all under one service. Is automated penetration testing safe? CISOs might be nervous letting an autonomous penetration testing system loose on production systems. It sounds like something that could break running processes. Why not just test against a digital twin instead? Testing in production is the safest way to find bugs, retorts Vanover. That's because environments drift frequently, especially in an agile world driven by short development sprints and automated changes to code. If a user changes a password or a team pushes a feature fragment, a digital twin system won't reflect reality. So Horizon3 focuses on strong production guardrails instead. "I don't need to ransom your system to prove to you that I can ransom it," Vanover says. "If I can get on the system, install a remote access tool, create a file, encrypt the file, and delete that file, I've just proven that I can ransom your system." He says Horizon3 has run more than 320,000 production tests across customer organizations. These include some that are especially nervous about what's poking around in their systems, such as the NSA and the largest medical records processor on the planet, along with a couple of large healthcare providers. Where can I start with CTEM? Gartner's CTEM framework is powerful, but it might also be daunting for CISOs. Vanover advises them to begin by picking one thing and doing it well. "No organization is going to implement CTEM in a year. That is a recipe for failure," he says. "Break it down. Look at places for the low-hanging fruit." You could do worse than look at what systems are actually reachable instead of blindly trusting an asset inventory that might be out of date. The race is on to embrace CTEM, because metrics like the number of patches applied won't satisfy the board for much longer. They don't describe how much exploitable surface still exists. The point of running the CTEM loop is to move reporting from activity to outcomes, so that the board gets to see fewer exploitable paths and a smaller blast radius. The new goal is to prove that a security control worked, not just that you paid for it. Want to operationalize CTEM but don’t know where to start? Check out this whitepaper from Horizon3 Sponsored by Horizon3
NVIDIA kupuje Hugging Face za 12,93 miliardy dolarů.
A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server. [...]
|