Agregátor RSS

Linux Logs Have Become a Prompt Injection Target

LinuxSecurity.com - 28 Červenec, 2026 - 15:45
An attacker may no longer need to erase Linux logs to hide an intrusion. They may only need the AI reading them to believe a different story.
Kategorie: Hacking & Security

Chytré semafory s umělou inteligencí zrychlí dopravu a spravedlivěji rozdělí čas mezi řidiče i chodce

Živě.cz - 28 Červenec, 2026 - 15:45
Umělá inteligence nahradí fázové řízení plynulou analýzou dopravy v reálném čase • Projekt v americkém Pittsburghu potvrdil zkrácení čekací doby na křižovatkách • Propojená dopravní infrastruktura se stává potenciálním cílem kybernetických útoků
Kategorie: IT News

JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

The Hacker News - 28 Červenec, 2026 - 15:33
JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment. Artifactory is JFrog's software repository manager. OpenAI says the models then escalated privileges and moved laterally until they reached an internet-connected node. JFrog says it has since developed and released fixes for cloud Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

The Hacker News - 28 Červenec, 2026 - 14:56
OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default. The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1 in OpenWrt's GitHub advisory, lets an unauthenticated attacker able to reach the DHCPv6 server overwrite a stack buffer in odhcpd through a crafted DHCPv6 Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Uncle Sam needs you to fight for 6G leadership and security, lest Beijing get there first

The Register - Anti-Virus - 28 Červenec, 2026 - 14:49
America wants its allies to come together and help it lead the way in defining 6G communications standards, with security and resilience seen as key goals for next-generation networks. The latest effort to corral international work on 6G comes from the US National Telecommunications and Information Administration (NTIA), which says it is pursuing the objectives of a December 2025 memo from President Trump on "Winning the 6G Race." That memo didn't identify who America is racing against, but it is a fair bet that it is China, which gained a lead during the development of 5G technology. Huawei in particular is understood to hold more declared 5G standard-essential patent families than any other company. The NTIA says it is launching this initiative alongside more than 20 governments, including several European nations like the UK and the Nordic countries, Japan, South Korea, and Australia. The Nordics are significant as they are home to telecoms equipment suppliers Nokia and Ericsson. These governments have all pledged to strengthen cooperation on 6G over the next 12 months and beyond in support of greater security, interoperability, and resilience for next-generation networks, the NTIA claims. "The Call to Action for 6G Leadership and Security reflects an unprecedented level of international coordination on the future of communications technology," stated NTIA administrator Arielle Roth. "By working now with trusted partners, we will ensure that next generation networks reflect our shared security interests, strengthen our competitiveness, and drive innovation." So after President Trump has spent 18 months since inauguration disparaging and threatening America's "trusted partners," the US has decided it would really like their help in becoming the world leader in 6G technology. Isn't that nice? The initiative lays out specific milestones on strategic coordination over the next year or so, as 6G moves toward commercialization. These include engaging with the telecoms industry to understand the "political and economic landscape" for 6G networks and meetings to identify the potential for more coordinated approaches. It also calls for a big meeting in 2027 to review joint progress, where the partners are expected to evaluate funding strategies, share information on 6G research and development, assess 5G and 6G technical and cybersecurity risks, and promote common 6G policies. All of this seems aimed at coordinating positions on the spectrum needed for 6G ahead of the next World Radiocommunication Conference (WRC-27). Scheduled for October 18 to November 12 in Shanghai next year, the conference will consider which frequency bands are made available for next-generation mobile networks. But it isn't the first attempt at international collaboration over the next-gen wireless standard. The US-UK Tech Prosperity Deal, agreed last year, proposed greater cooperation in a range of science and technology areas including 6G, but this was put on ice by President Trump after just a few months over trade disagreements. Earlier this year, the Global Coalition on Telecommunications (GCOT) unveiled a set of security and resilience principles it wanted to see baked into 6G from the start. The organization includes many of the same nations as the latest US scheme. "This is a clear attempt by the US and its allies to shape the 6G landscape before commercial networks arrive," PP Foresight founder and analyst Paolo Pescatore told The Register. "The priority is to embed security, resilience, interoperability, and supply-chain diversity from the outset, rather than repeat the costly mistakes and geopolitical tensions that defined the 5G era. "Although China is not explicitly mentioned, the strategic intent is obvious: to reduce dependence on high-risk suppliers and to ensure that trusted nations have greater influence over standards, investment, and innovation. However, this remains a political framework rather than a binding agreement." The first 6G deployments could arrive as soon as 2029, with the US and South Korea likely to lead in early adoption, according to a report from Juniper Research earlier this year. Despite this, the exact characteristics that will define 6G networks have yet to be thrashed out. Bodies representing the mobile networks want to see a smooth and cost-effective migration path for their members, avoiding the mistakes made with 5G, while the GSMA has already put it out there that 6G networks may need up to three times the spectrum currently allocated to meet the anticipated demands for data. ®
Kategorie: Viry a Červi

Internet získá novou doménu .web. Spravovat ji bude organizace stojící za .com

Živě.cz - 28 Červenec, 2026 - 14:45
Společnost Verisign po více než deseti letech sporů a odkladů oficiálně zařadila doménu nejvyšší úrovně .web do kořenové zóny DNS. Jde o poslední krok před spuštěním registrací, které mají začít ještě letos. Doména .web patří dlouhodobě k nejočekávanějším novým generickým TLD (Top Level Domain), ...
Kategorie: IT News

Česká národní kvantová komunikační infrastruktura

AbcLinuxu [zprávičky] - 28 Červenec, 2026 - 14:30
Dne 30. června 2026 byla završena fyzická realizace projektu Czech National Quantum Communication Infrastructure (CZQCI), tedy České národní kvantové komunikační infrastruktury. Projekt byl realizován od 1. března 2023 a financován z Národního plánu obnovy částkou 121,6 milionu Kč. Cílem podpořeného projektu bylo vybudovat základy národní kvantové komunikační infrastruktury a ověřit možnosti jejího praktického využití. Mezi hlavní výsledky projektu patří vznik optického propojení mezi Prahou, Brnem a Ostravou o celkové délce přibližně 600 kilometrů se šesti segmenty kvantové distribuce klíčů (QKD). Síť dále doplnily dvě sekundární metropolitní větve využívající komerční QKD zařízení a dvě metropolitní větve založené na experimentálních QKD technologiích. Realizace zahrnovala také ověření integrace stávajících telekomunikačních systémů s prostředky kvantové komunikace a testování tří scénářů využití pro vojenské účely.
Kategorie: GNU/Linux & BSD

Šumperk čelil kybernetickému útoku, úřad omezil provoz, únik dat se prověřuje

AbcLinuxu [zprávičky] - 28 Červenec, 2026 - 14:16
Město Šumperk se stalo terčem kybernetického útoku, chod úřadu je omezen. Zjišťuje se, jestli unikla nějaká data. Cílem hackerů byla městská datová síť. První útoky zaznamenali odborníci na informační technologie již v pondělí večer, závady se ale plně projevily až dnes ráno. Město událost nahlásilo Národnímu úřadu pro kybernetickou a informační bezpečnost (NUKIB).
Kategorie: GNU/Linux & BSD

Over 24,000 exposed server BMCs leak password hash via decades-old flaw

Bleeping Computer - 28 Červenec, 2026 - 14:10
More than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface. [...]
Kategorie: Hacking & Security

Samba 4.24.5, 4.23.10 a 4.22.11

AbcLinuxu [zprávičky] - 28 Červenec, 2026 - 14:00
Samba, svobodná implementace síťového protokolu SMB/CIFS, byla vydána ve verzích 4.24.5, 4.23.10 a 4.22.11. Řešeno je 6 zranitelností.
Kategorie: GNU/Linux & BSD

Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

The Hacker News - 28 Červenec, 2026 - 13:55
The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia. The intrusions involve the use of a previously undocumented Windows backdoor called NightLedger and two custom WebSocket tunnelers, Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Připojili jste se k palubní Wi-Fi Českých drah, ale internet nefunguje? Zkuste tohle

Živě.cz - 28 Červenec, 2026 - 13:45
Pravidelně teď cestuji Pendolinem napříč republikou. Palubní síť CDWiFi hlásí plný signál, ale internet nejede. Není to přitom páteřním spojením, protože České dráhy se spoléhají na 5G tuzemských mobilních operátorů (případně Starlink) a na mobilu po většinu cesty síť funguje. Máte-li stejný ...
Kategorie: IT News

Anthropic rejects open-weight AI bans, calls for China chip controls and safety tests

Computerworld.com [Hacking News] - 28 Červenec, 2026 - 13:13

Anthropic CEO Dario Amodei has argued that policymakers should keep lower-risk open-weight AI accessible while placing stricter safeguards around frontier systems, including mandatory testing and limits on China’s access to advanced computing and model capabilities.

In a post outlining Anthropic’s position, Amodei said broad restrictions, including bans on Chinese open-weight models used by US businesses, would not address his main national security concerns. Instead, he pointed to the possibility of authoritarian governments surpassing the US in advanced AI, as well as cyber, biological, and alignment risks posed by increasingly capable systems.

Amodei also called for action against industrial-scale model distillation, which he said allows Chinese developers to improve their models with less computing power than would be needed to train comparable systems from scratch.

The statement followed criticism of Anthropic for not signing an industry letter backed by Nvidia, Microsoft, Meta, IBM, Mistral, Hugging Face and other technology companies urging policymakers to avoid premature restrictions on open-weight models.

The letter said that open weights could broaden access to AI, intensify competition, and enable organizations to adapt and deploy models without relying on a single provider. Amodei agreed with parts of that case but disputed claims that openness inherently improves safety research or gives defenders an advantage over attackers.

He said regulation should be based on a model’s capabilities and risks rather than whether its weights are openly available. Under that approach, sufficiently capable open and closed models would undergo testing before release.

Conditional support

Analysts said Anthropic had moved closer to industry consensus by rejecting blanket bans, but its support remained more limited than the approach backed by many major technology companies.

Deepika Giri, head of research for AI, analytics, and data at IDC, said the Nvidia-backed letter presented open weights as strategic infrastructure that should remain broadly accessible, in contrast with Anthropic’s more restrictive position.

Amodei’s statement clarified that Anthropic supports open-weight models only under certain conditions, a stance that could also help the company preserve its competitive advantages as a proprietary model provider focused on compliance and tighter controls, according to Lian Jye Su, chief analyst at Omdia.

The statement was “a real olive branch” to supporters of open-weight models, according to Pareekh Jain, CEO of Pareekh Consulting. But he said the disagreement had shifted from whether such models should be released to where policymakers should draw the line.

“Anthropic still thinks that once a model gets powerful enough, releasing its weights publicly is riskier than keeping it locked behind an app, because you can never take it back or add safety fixes later,” Jain said.

Will the controls work?

Analysts differed over whether Anthropic’s proposed controls would achieve their aims without creating new barriers for smaller AI developers.

Jain said chip restrictions and measures against illicit model distillation would mainly affect model developers and infrastructure providers, rather than enterprises using models already on the market. Mandatory safety testing, however, could raise development costs and reduce the number of advanced open-weight models available.

“Testing is expensive and time-consuming, and so, giant, well-funded companies like Anthropic, Google and OpenAI can afford it,” Jain said. Smaller developers seeking to release cutting-edge open-weight models could struggle to meet the same requirements, he added.

The additional testing and screening could also restrict the number of open-weight models available to enterprises, according to Su. He said the requirements could weaken some of their principal benefits, including lower costs, reduced vendor dependence and community-led development.

Anand Joshi, managing director of market research firm JP Data, questioned whether limiting China’s access to advanced chips would materially slow its AI development, arguing that Chinese companies had shown they could build highly capable models with less computing power. He supported action against illicit distillation, however, saying safeguards were needed to prevent developers from reproducing the capabilities of other models without authorization.

The impact on most enterprise users could remain limited if less capable models were exempted, Jain said. Businesses deploying models that fall below the proposed testing threshold would probably face little additional cost.

How CIOs should choose

Giri said CIOs should assess models according to their capabilities rather than whether they are open, and should demand independent testing, clear licensing, model documentation and accountability for monitoring and incident response.

“Mandatory safety testing should be triggered by a model’s demonstrated capabilities, not its size or training cost,” Jain said, particularly when a system could significantly assist cyberattacks, biological misuse, or autonomous harmful actions.

Before deployment, CIOs should seek independent evaluations, detailed model documentation, security test results and information about the model’s software supply chain, he added. Charlie Dai, principal analyst at Forrester, said that assessment should include documented red-team results, model provenance, disclosures about training and fine-tuning, and evidence of independent testing against recognized safety benchmarks.

Kategorie: Hacking & Security

Microsoft’s Nadella calls out Big AI for hypocrisy — but what about his own company?

Computerworld.com [Hacking News] - 28 Červenec, 2026 - 13:00

The 19th-century French novelist Honore de Balzac is believed to have said that behind every great fortune lies a great crime.

That’s even more true today than it was 200 years ago — just look at how Big AI, including Anthropic, OpenAI, Google, and others have built their trillion-dollar fortunes. 

They all use vast amounts of copyrighted material to train their large language models (LLMs) without paying the copyright holders. In other words, they steal it. They don’t call it stealing, though. They call it “fair use,” which in this case amounts to the same thing.

Generative AI (genAI) training requires massive amounts of text. The better-written and more information-dense that text is, the more it helps. AI gets a lot smarter a lot faster when it’s trained on well-written books and magazine and newspaper articles than when it’s trained on social media banter (or most everything else you find on the internet).

Since the dawn of AI, companies have been hoovering up copyrighted material wherever they find it — on the open web, behind paywalls, even in manually scanned books — and then used the scanned text. And they do it all without asking authors’ or publishers’ permissions, and without paying them.

It’s the greatest intellectual property theft in history by a long shot — billions and billions of dollars worth. Books, articles, music, photographs, artwork, you name it. If a human being has created it, Big AI has likely grabbed it and ingested it without asking, then made big profits off it.

I know this from personal experience; I’ve got skin in the game. Big AI companies have used at least 30 of my books to train their models without asking.  And that’s only what I’ve confirmed. Big AI might well have stolen even more. And it also might have stolen many of the thousands of articles I’ve written through the years.

For the AI bigwigs, it’s standard operating procedure. So it was surprising to see Microsoft CEO Satya Nadella calling out Big AI for its hypocrisy in using other people’s intellectual property without paying, then crying foul when small AI companies use Big AI’s work to train their own models using a technique called distillation.

He wrote on X: “While the great innovation that comes from model providers having fair use rights to train models on public data is needed, I find it ironic that the status quo is to then turn around and impose restrictive terms on distillation, and to reserve the right to learn from customer usage and interaction data.” 

One important note here: Nadella believes Big AI should be allowed to steal copyrighted material for training purposes. He makes that clear by his mention of “fair use.” His issue is that he believes smaller AI companies should be able to use Big AI’s work to train their models — and Big AI doesn’t want to let them do it.

Alistar Barr, in Business Insider, makes a related point: “Anthropic, OpenAI, and Google are discovering what the rest of the internet has already learned through painful experience: once you put something online, people will find ways to use it in ways you don’t like and can’t stop.” 

Before we look at whether Nadella is right in calling Big AI’s actions hypocritical, let’s examine the technique at the heart of the issue: distillation.

The lowdown on distillation

Distillation refers to an AI training technique in which you take outputs from one AI model, such as the answer to a prompt, and use that output to train your own model. AI companies do that quite frequently and have been doing so for a long time.

Barr explains distillation this way: “Distillation looks an awful lot like what AI companies have been doing to the rest of the internet. Scrape web content for free and without permission. Turn it into a product you sell. Argue it’s fair use. Hope the lawyers sort out the details later.”

Elon Musk has admitted his company xAI used distillation techniques to take output from competitor OpenAI to train xAI’s Grok chatbot. He explained, “Generally AI companies distill other AI companies.”

Analysts point out the AI industry is built on distillation. Neil Shah, vice president of research at Counterpoint Research says, “The reality is none of the models is an island and the entire industry has mostly evolved based on recursive learning. The newer entrants are in many instances going through the same routes of ‘distillation’ and ‘optimization.’”

It’s only become an issue now because Chinese AI companies have been using distillation techniques to catch up to American AI companies.

OpenAI CEO Sam Altman has been pressuring the US to take legal action against the Chinese companies.  Anthropic has piled on as well, saying the fight against distillation requires a coordinated response across the AI industry, cloud providers, and policymakers.

Hypocrisy or fair use?

So are OpenAI, Anthropic and other big US AI firms hypocritical, as Nadella claims? Absolutely. They’ve built their businesses on the theft of billions of dollars of stolen intellectual property and call it fair use. Now, they’re playing the victims when competitors do the same to them. (They’re also in some cases paying up; Anthropic just last week settled a copyright suit, paying out $1.5 billion.)

It’s good to see Nadella call out their hypocrisy. But Microsoft is as guilty of intellectual theft as the others — its AI Copilot is powered by OpenAI’s and Anthropic’s chatbots. The company faces major lawsuits for intellectual property theft. Among them is one by the New York Times, New York Daily News, and Center for Investigating Reporting, another by 400 local and regional newspapers, and another by 11 authors, including Pulitzer Prize winners Kai Bird, Jia Tolentino, and Daniel Okrent.

So, don’t praise Nadella for speaking out. Criticize him (and other AI tech leaders) for stealing billions of dollars in intellectual property from countless writers and publishers and calling it fair use.

Kategorie: Hacking & Security

Nejpopulárnější benchmark v nové verzi. Geekbench 7 má lépe změřit výkon počítačů a mobilů

Živě.cz - 28 Červenec, 2026 - 12:45
Společnost Primate Labs představila Geekbench 7, novou generaci svého multiplatformního benchmarku pro měření výkonu CPU a GPU. Aktualizace přináší dosud největší změny v historii nástroje a zaměřuje se na realističtější simulaci běžných úloh, které odpovídají současnému využití počítačů i mobilů. ...
Kategorie: IT News

Kutil si postavil elektromechanický televizor. IMAX to sice úplně není, ale stačí 3D tiskárna, LED a motorek

Živě.cz - 28 Červenec, 2026 - 11:56
Někdo má doma nejmodernější televizor za statisíce, no a pak je tu ještě James (Ancient) Brown, který podobné zbytečnosti nepotřebuje. Když si chce večer dopřát nějaké to domácí kino, rozžhaví 3D tiskárnu a jedno si vytiskne. Říká mu Scanwheel a je to vlastně elektromechanický televizor s ...
Kategorie: IT News

Reflex 2 Nvidia nikdy nevydala, slíbila ho před 1,5 rokem, na hráče se vykašlala

CD-R server - 28 Červenec, 2026 - 11:30
Za pár dní to bude 19 měsíců, co Nvidia představila Reflex 2, jehož vydání mělo následovat brzy po CES. Jenže k němu nedošlo dosud a uživatelé ztrácejí naději, že Nvidia vůbec někdy slovo dodrží…
Kategorie: IT News

Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock

The Register - Anti-Virus - 28 Červenec, 2026 - 11:15
A critical flaw in Arista's VeloCloud Orchestrator has gone from zero to KEV in short order, with the networking giant confirming attackers are already exploiting it. The vulnerability, tracked as CVE-2026-16812, carries a maximum CVSS score of 10.0 and affects VeloCloud Orchestrator On-Prem, the self-hosted version of the software that enterprises use to centrally manage VeloCloud software-defined wide area networks (SD-WANs) connecting branch offices, datacenters, and clouds environments. According to Arista's security advisory, the flaw is an OS command injection vulnerability that allows an unauthenticated remote attacker to reach privileged internal functionality that was never meant to be exposed externally. Worse, Arista says the on-premises orchestrator is exposed by default, with no configuration capable of removing that exposure entirely. Exploitation requires access to the web interface but no credentials. Until administrators can patch, Arista recommends restricting that interface to trusted management networks and blocking IP addresses associated with observed attacks. "Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator," Arista warned. "Compromises to the VCO platform may allow attackers access to the VeloCloud Edge devices as well." Arista published three IP addresses observed conducting attacks, but otherwise kept its cards close to its chest. The company hasn't said who's exploiting the bug, when the attacks began, or how many customers have been affected, and didn't immediately respond to The Register's questions. Even without those details, the admission of in-the-wild exploitation was enough for CISA to add the flaw to its Known Exploited Vulnerabilities (KEV) catalog. The list is reserved for bugs with evidence of real-world abuse, and while the associated directive applies only to US federal civilian agencies, plenty of private sector security teams use KEV to decide which patches can't wait. The issue affects only on-premises deployments. Customers using Arista's hosted or dedicated VeloCloud Orchestrator service had already been patched before the advisory was published, the company said. Fixes are available in VeloCloud Orchestrator versions 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1. Arista urged customers running earlier releases to upgrade immediately. Arista is far from the first vendor to issue a patch after attackers had already begun exploiting the flaw. Over the past year, a steady stream of networking gear, VPNs, firewalls, and other edge-facing enterprise software has followed the same pattern: by the time customers learn there's a problem, somebody else has already proved it's worth exploiting. ®
Kategorie: Viry a Červi

Data breach at medical billing firm MCBS affects 1.26 million people

Bleeping Computer - 28 Červenec, 2026 - 11:10
Healthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people. [...]
Kategorie: Hacking & Security
Syndikovat obsah