Agregátor RSS

Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs

The Hacker News - 2 Září, 2026 - 20:27
Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program. "The Fairwind Program gives high-priority defenders (like governments, healthcare providers, and telecommunications services) early access to advanced models that help them
Kategorie: Hacking & Security

Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs

The Hacker News - 2 Září, 2026 - 20:27
Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program. "The Fairwind Program gives high-priority defenders (like governments, healthcare providers, and telecommunications services) early access to advanced models that help them Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Vybíráme nejlepší fotomobily současnosti. Tohle si kupte místo foťáku

Živě.cz - 2 Září, 2026 - 20:15
Smartphony válcují nejen levné, ale už i pokročilé kompakty • Vlajkové modely jsou skoro jistota, dobře fotí ale i levnější přístroje • Po kterých fotomobilech byste měli aktuálně sáhnout?
Kategorie: IT News

Chytré telefony fungují jako digitální antikoncepce. Ekonomové jim kladou vinu za klesající porodnost

Živě.cz - 2 Září, 2026 - 19:45
Dvě nové studie spojují globální pokles porodnosti s rozšířením smartphonů • Raná exkluzivita iPhonu u sítě AT&T prokázala zrychlený pád plodnosti • Digitální izolace a snazší přístup k pornografii vytlačily reálné schůzky
Kategorie: IT News

Acer vyvíjí Project DualPlay Mini – herní handheld a notebook s klávesnicí v jednom těle

Živě.cz - 2 Září, 2026 - 18:45
Na trh se zatím nechystá, ale nejde o úplně nesmyslnou myšlenku. Připravovaný herní handheld Acer Project DualPlay Mini řeší hlavní výtku pro herní handheldy. Jde totiž o jednoúčelová zařízení, která jsou možná dobrá na hry s ovladačem, ale dělat na nich cokoli jiného je téměř nemožné. V ...
Kategorie: IT News

A look inside Apple’s relationships with Intel and TSMC

Computerworld.com [Hacking News] - 2 Září, 2026 - 18:43

Former Apple chip supplier Intel has faced a lot of challenges since Apple ceased to be a client. It struggled to win back some of Apple’s processor manufacturing business, but seems to face one fundamental challenge — trust.

That’s the very briefest gist of an extensive and outstanding report today from Culpium, which gives us an insider look at the relationship between the firms. It’s particularly relevant, given that the Trump Administration has announced that Apple agreed to work with Intel in the future. (TSMC is Apple’s current supplier and that relationship seems very solid.)

The root of the challenge

The problem with Intel, according to the report, is that a lack of trust drove Apple to seek an alternative processor supplier in the first place. The report discusses some of those challenges, including Intel’s failure to keep the pace with Mac chips, which is why the M1 chip astonished the industry, because it gave Apple the performance it had always sought.

How we got here

The root of that release was mobile, of course. Apple’s A-series chips were built for mobile and eventually transcended to become M-series Mac chips. Intel turned Steve Jobs down when he asked it to make mobile processors, pushing Apple to TSMC. The history is more complex than that, of course — Apple also acquired chip development expertise from PA Semi, for instance — and established a foundry deal with TSMC that meant the company produced Apple-designed chips. The work Apple did on mobile processors eventually enabled the move to Apple Silicon.

That’s the history. Fast forward to today and an ailing Intel needed new client wins even as the Trump Administration sought to support onshore processor production; it’s a strategic need for the US. The problem is, as Culpium terms it, that Intel isn’t willing to build manufacturing capacity until it wins the supply contract. And Apple needs a much firmer promise than that to supply its huge mass market. It needs capacity before it can provide trust.

Telling tales too soon?

During the most recent negotiations concerning Intel’s capacity to deliver chips in quantity, the report tells us Intel somehow managed to challenge that trust by telling third-party partners that it had secured Apple as a client. Anyone who knows Apple will recognize that the company doesn’t like its business discussed that way. “A sure sign that the two companies may be on the path to some serious cultural clashes,” wrote Culpium.

TSMC, meanwhile, has a corporate commitment to trust, a promise recognized across the industry — even by Nvidia founder Jensen Huang. That trust extends into tomorrow, which is why TSMC invests vast sums in developing process technology it believes customers will need tomorrow, rather than waiting for them to order up capacity today. That’s also why TSMC today offers some of the world’s most advanced interconnects, enabling powerful tech that likely includes Apple’s M5 Ultra. But just as important as technology and manufacturing capacity is a trusted relationship between companies. 

That’s not to say capacity doesn’t matter. It does. And as Apple continues to sell its products in ever greater quantities, it knows it must source additional supply; that’s why it speaks to Intel, Samsung, or even CXMT about the components its products require. But ultimately, a company that historically has felt let down by numerous key competitors — think Google, Samsung, and Android or, more recently, elements of OpenAI — will place a great deal of value in discretion and corporate trust.

After all, Apple has learned that in the ultra-competitive market in which it exists, what some call paranoia will in the end be seen as business sense.

You can follow me on social media! Join me on BlueSky,  LinkedInMastodon and subscribe to The Core.

Kategorie: Hacking & Security

Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

The Hacker News - 2 Září, 2026 - 18:41
An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers. "The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users," Microsoft
Kategorie: Hacking & Security

Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

The Hacker News - 2 Září, 2026 - 18:41
An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers. "The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users," MicrosoftRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

SonicWall's SMA1000 boxes under active attack again

The Register - Anti-Virus - 2 Září, 2026 - 18:05
SonicWall says attackers are actively exploiting two chained zero-days to take over Secure Mobile Access (SMA) Series 1000 boxes. Aimed at midsize and large enterprises, SMA1000 gateways secure remote access and VPN connections. Compromising one can therefore provide attackers with a valuable route into corporate networks. So, get to applying those hotfixes, says SonicWall. There are no workarounds. The first zero-day, CVE-2026-83548, is a pre-authentication server-side request forgery (SSRF) vulnerability with a maximum CVSS v3 score of 10.0. SonicWall attributed it to an unintended alternative access path. "A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations," the vendor said. The second, CVE-2026-83549, is a post-authentication OS command injection vulnerability in the SMA1000 Appliance Management Console (AMC), rated 7.8 on CVSS v3. Under certain conditions, an attacker authenticated as an administrator could execute arbitrary commands on the appliance. The flaws affect the SMA 6210, 7210, and 8200v appliances, for which SonicWall has released hotfixes. SonicWall advised customers to contact its technical support team for help identifying indicators of compromise. If an appliance appears to have been compromised, SonicWall recommends reimaging or redeploying it, changing all passwords, and resetting TOTP tokens. NHS England, which published its own advisory, warned about the growing risk of attacks against internet-facing gateways. "Firewalls and other edge devices are internet-facing by design and are highly attractive targets to attackers, and there is an increasing number of edge device vulnerabilities disclosed each year that are rapidly exploited by attackers," it stated. "The NHS England National CSOC assesses future exploitation of these vulnerabilities as almost certain." The disclosures continue a difficult run for SonicWall and its SMA1000 product line stretching back through 2025. In July, the vendor disclosed an eerily similar pair of vulnerabilities. That pair also comprised a pre-authentication SSRF vulnerability, this time in the SMA1000 Appliance WorkPlace interface, and a post-authentication OS command injection flaw in the AMC. The SSRF received a maximum CVSS v3 score of 10.0, while the command injection bug was rated in the sevens. CISA later added CVE-2026-15409 to its Known Exploited Vulnerabilities catalog and marked it as known to have been used in ransomware campaigns. Throughout 2025, SonicWall patched a succession of SMA1000 vulnerabilities, including OS command injection and privilege escalation flaws, while investigating zero-days linked to ransomware attacks. ®
Kategorie: Viry a Červi

Hackers exploit critical JFrog Artifactory flaw to forge admin tokens

Bleeping Computer - 2 Září, 2026 - 17:47
A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide administrative access. [...]
Kategorie: Hacking & Security

Chlazené pivo i uprostřed lesa. Češi bourají Kickstarter s pípou, kterou pohání akumulátor

Živě.cz - 2 Září, 2026 - 17:45
Pro mě ten příběh začal před měsícem, když jsem viděl první teaser. Pípa s akumulátorem? To může napadnout jen Čechy. Když jsem viděl půllitr s nápisem Budějovický Budvar, měl jsem jasno. Trochu mě zmátla americká firma, ale marketingový guru týmu Robert Jr. mi vysvětlil, že kvůli vstupu na ...
Kategorie: IT News

Legacy Lenovo login opens 5,000 Dropbox accounts to attackers

The Register - Anti-Virus - 2 Září, 2026 - 16:25
Dropbox has warned around 5,000 users that attackers compromised their accounts by abusing a legacy Lenovo login integration. In an email sent to affected customers, the cloud storage biz said attackers exploited an integration that allowed users to access Dropbox using Lenovo IDs. Dropbox blamed "an issue with Lenovo's email verification process," which allowed attackers to register Lenovo IDs using Dropbox users' email addresses and then access the corresponding storage accounts. It did not explain why the integration was allowed to grant access without requiring the user to enter a Dropbox password. The compromise lasted from August 4 to 21. Dropbox told Bloomberg that attackers accessed files belonging to fewer than a third of the affected users. Jameson Lopp, co-founder of Bitcoin security company Casa, said attackers attempted to access just one of his files, "IMPORTANT.rtf," which had been encrypted locally before it was uploaded to Dropbox. Sometimes, it pays to be a nerd. Dropbox confirmed the scale of the attack to Reuters and said none of the affected accounts had two-factor authentication (2FA) enabled. After discovering the breach, Dropbox said it "promptly expired all sessions logged in through Lenovo IDs" and "severed any link" between the affected accounts and Lenovo. In its email, the company advised affected users to change their Dropbox and personal email passwords and enable 2FA. Lenovo told Reuters that its customers were unaffected and that its investigation was continuing. The Register asked Dropbox and Lenovo for more information. ®
Kategorie: Viry a Červi

Linux From Scratch 13.1

AbcLinuxu [zprávičky] - 2 Září, 2026 - 16:15
Příručka Linux From Scratch pro sestavení základního linuxového systému byla aktualizována v pravidelném půlročním termínu. Vydání 13.1 shrnuje přes 40 nových verzí balíčků a několik patchů. Navazující příručka Beyond Linux From Scratch s recepty pro sestavení dalších knihoven a aplikací zatím vydána nebyla, ačkoliv vývojová verze stále dostává aktualizace. Lze je číst online nebo stáhnout v HTML či PDF.
Kategorie: GNU/Linux & BSD

K Merkuru se blíží BepiColombo. Už brzy se stane jeho teprve druhou umělou oběžnicí v historii. Manévr trval osm let

Živě.cz - 2 Září, 2026 - 16:13
Evropsko-japonská sonda BepiColombo přilétá k Merkuru • Postupně bude navedena na oběžnou dráhu planety • Let trval dlouhých osm let
Kategorie: IT News

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

The Hacker News - 2 Září, 2026 - 16:06
Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication. The command executes as the user, outside the agent's sandbox and without an approval prompt, and exploitation requires the repository to arrive
Kategorie: Hacking & Security

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

The Hacker News - 2 Září, 2026 - 16:06
Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication. The command executes as the user, outside the agent's sandbox and without an approval prompt, and exploitation requires the repository to arrive Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Ransomware protection for MSPs: A 6-point checklist for faster recovery

Bleeping Computer - 2 Září, 2026 - 16:02
Ransomware resilience requires more than backups or endpoint detection alone. Acronis outlines six capabilities MSPs should test across client environments, from reducing exposure and detecting attacks to preserving recovery points and restoring operations quickly. [...]
Kategorie: Hacking & Security

Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages

The Hacker News - 2 Září, 2026 - 15:44
A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educational institutions, and using them to divert visitors to attacker-controlled pages promoting online gambling and sports betting. Check Point Research said it has tracked the campaign since mid-2025. The modules
Kategorie: Hacking & Security

Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages

The Hacker News - 2 Září, 2026 - 15:44
A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educational institutions, and using them to divert visitors to attacker-controlled pages promoting online gambling and sports betting. Check Point Research said it has tracked the campaign since mid-2025. The modules Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Syndikovat obsah