Agregátor RSS

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

The Hacker News - 5 Září, 2026 - 09:31
Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as
Kategorie: Hacking & Security

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

The Hacker News - 5 Září, 2026 - 09:31
Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

NASA vypustila nový vesmírný dalekohled. Oblohu dokáže mapovat 1000krát rychleji než Hubbleův teleskop

Živě.cz - 5 Září, 2026 - 07:45
Raketa Falcon Heavy úspěšně vynesla do vesmíru nový teleskop NASA • Přístroj dokáže mapovat oblohu tisíckrát rychleji než slavný Hubble • Hlavním vědeckým cílem bude výzkum tajemné temné hmoty i exoplanet
Kategorie: IT News

New Linux Kernel Patch Targets a Page-Cache Memory Bug

LinuxSecurity.com - 5 Září, 2026 - 02:30
Linux maintainers are testing a patch for a page-cache bug after KASAN reproduced a use-after-free in filemap_map_pages(). On Sep 3, 2026, Andrew Morton said he would update the changelog, add cc:stable, and queue the patch for testing while awaiting review.
Kategorie: Hacking & Security

Linux May Restrict TCP Socket Reuse After a Memory Bug

LinuxSecurity.com - 5 Září, 2026 - 02:15
Linux TCP permits a listening socket to be transformed into a different kind of socket. A reproduced memory race has led maintainers to question whether that flexibility is worth keeping.
Kategorie: Hacking & Security

Confidential Containers Need a Boundary the Linux Host Cannot Cross

LinuxSecurity.com - 5 Září, 2026 - 02:00
Linux containers are efficient because they share the host kernel. That same design gives the host deep authority over container memory, mappings, and process state. If the host is compromised or untrusted, namespaces cannot keep workload secrets away from it.
Kategorie: Hacking & Security

Raiffeisenbank vrací 50 % a Fotoškoda dá slevu 25 000 Kč na Nikon

Lupa.cz - články - 5 Září, 2026 - 00:30
Tenhle týden jsme pro vás prošli desítky partnerských nabídek a vybrali deset, které se fakt vyplatí. Ušetříte na energiích, mobilním tarifu, streamovací službě i oblíbené elektronice, a pokud plánujete cestu do zahraničí, najdete tu i výhodné řešení pro mobilní data. Podívejte se, kde se dá tenhle týden nejvíc ušetřit.
Kategorie: IT News

OpenAI agents discussed ways to escape their sandbox on public wiki

Ars Technica - 5 Září, 2026 - 00:17

Self-identifying OpenAI agents posted 18,000 messages to a public wiki that discussed ways for other agents to bypass security sandbox restrictions during what was likely internal testing designed to gauge the agents’ hacking abilities, researchers said Friday.

In all, agents with 3,700 distinct self-given names posted the messages to German site DSEwiki over a six-week period. Besides discussing ways the agents could break out of the restricted environment OpenAI intended to prevent them from posting code or content to the Internet, the posts shared test answers. The posts also shared possible ways to perform XSS (cross-site scripting) attacks against the wiki and to impersonate site moderators. In three of the posts, agents used the word “swarm” to describe the collection of agents engaged in the activity.

Colluding to share answers

The research team—composed of Sydney Von Arx, Spencer Kitts, Thomas Larsen, and Cormac Slade Byrd—said they found the posts and pieced them together. The researchers say there are gaps in their understanding of precisely what actions the agents took because the research is based solely on the content of the posts. Additionally, the agents generated “chain of thought” data that’s understood only by OpenAI. As a result, the researchers said, they in some cases made educated guesses, including that the agents were, in fact, from OpenAI. In a statement, OpenAI later confirmed they were.

Read full article

Comments

Událo se v týdnu 36/2026

AbcLinuxu [články] - 5 Září, 2026 - 00:01
Ucelený přehled článků, zpráviček a diskusí za minulých 7 dní.
Kategorie: GNU/Linux & BSD

Životně důležitá metafora: Vaše tělo má druhé srdce. Udržujte ho v chodu

OSEL.cz - 5 Září, 2026 - 00:00
Žijeme vzpřímeně, a to je problém pro srdce a cévní soustavu. Mají problém pumpovat krev žilami z nohou vzhůru proti gravitaci. Naštěstí máme druhé srdce, které tomu prvnímu pomáhá. Má to ale háček. Tohle druhé srdce nefunguje úplně autonomně a musíme ho podpořit.
Kategorie: Věda a technika

„Temný genom“ povstal

OSEL.cz - 5 Září, 2026 - 00:00
Už zas abychom opravovali učebnice. Geny fungují ještě složitěji, než jsme si uměli představit. Objev „temného genomu“ nás staví před otázku: Co vše má v našem organismu na starosti, za co mu vděčíme a čím na něj doplácíme?
Kategorie: Věda a technika

Rozkošní mývalové trpasličí na Ostrově vlaštovek si dělají papírové hračky

OSEL.cz - 5 Září, 2026 - 00:00
Na turisty hojně navštěvovaném mexickém ostrově Cozumel žijí i nesmírně ohrožení mývali trpasličí, kteří jsou zřejmě zmenšení evolučním ostrovním nanismem. Někteří z nich, jak se ukázalo, si dělají hračky z papírového odpadu, kterým jsou obklopeni, což je pozoruhodné a dost smutné zároveň, jak ukazuje i konec tohoto příběhu. Držme jim palce.
Kategorie: Věda a technika

Nová úsporná AI společnosti Pathway přemýšlí beze slov

OSEL.cz - 5 Září, 2026 - 00:00
Pathway vyvinuli model umělé inteligence BDH-CQ, který je velmi kompaktní se 150 miliony parametrů. Nevytváří dlouhé řetězce slov jako dnešní velké jazykové modely, ale Zpracovává informace krok za krokem a ukládá je do své průběžně aktualizované vnitřní paměti. Díky tomu je BDH-CQ velmi úsporný, pokud jde o počítačový výkon.
Kategorie: Věda a technika

Novinky v Kdenlive 26.08.0

AbcLinuxu [zprávičky] - 4 Září, 2026 - 23:49
Farid Abdelnour se v příspěvku na blogu rozepsal o novinkám v nejnovější verzi 26.08.0 editoru videa Kdenlive (Wikipedie). Ke stažení také na Flathubu.
Kategorie: GNU/Linux & BSD

ASCII smuggling isn't just an AI security risk

The Register - Anti-Virus - 4 Září, 2026 - 21:23
Fraudsters have found a new use for ASCII smuggling, typically used to hide malicious prompts intended for AI models, in an old-school attack method: email phishing. Microsoft uncovered a massive phishing campaign using invisible Unicode tag characters that peaked at more than 2.37 million messages in late February, remained elevated during weekdays over the next three months, and gradually declined by mid-June. “As AI-era attack methods become better understood, threat actors may adapt them for use in more traditional threats such as phishing and spam,” Redmond’s researchers Noam Kochavi and Sarah Wolstencroft said in a Thursday blog. “This case illustrates how techniques that emerge in AI security research can quickly cross over into established attack ecosystems, reinforcing the need for defenders to view emerging threats through a cross-domain lens.” ASCII smuggling involves using invisible or non-rendering Unicode characters to hide content inside text that appears normal to humans, and this makes it a popular technique for indirect prompt injection attacks. In these, an attacker hides instructions for an AI assistant in invisible Unicode characters, and embeds those malicious prompts inside a webpage or document. A human can’t see them, but a model can, and it decodes them as text - and may then follow the attacker’s instructions to leak data or take unauthorized actions. Instead of using ASCII smuggling for prompt injection, however, Microsoft’s security team spotted someone using invisible characters – inserting Unicode tag spaces between letters – to split financial-lure words in phishing emails in an apparent attempt to evade keyword matching and other content filters. So, for example, instead of writing “funding” in the email, the attackers wrote “fun⟨U+E0020⟩ding.” “When we looked at a sampling of the flagged messages, the surprise was there were no smuggled instructions to an AI assistant,” Kochavi and Wolstencroft wrote. “Instead, the invisible tag characters were inserted inside common financial keywords, splitting them apart so that a literal signature or keyword match would fail.” Redmond first detected the ASCII-smuggling signature in early February, flagging about 21,000 messages on February 8 before the number skyrocketed to more than 1.3 million the next day. Most of these emails came from about 150 finance-themed sender domains, and they continued for the next three months, dropping sharply after May 15 but continuing with occasional smaller spikes through at least mid-June. The security researchers pointed out two notable characteristics, including sending massive numbers of emails on weekdays and then going silent over the weekend. The campaign also had a long, gradual decline. “After an intense first phase, with weekday volumes of 1 to 2.37 million messages, peaking on February 26, the numbers stepped down slowly to roughly 80 percent less per weekday by late March.” It then dropped significantly after May 15, continuing with lower activity through mid-June. According to Redmond, the most important thing defenders can do to protect against Unicode tag blocks in phishing emails is to verify that normalization and tokenization pipelines handle tag characters consistently. “Any content that will be evaluated by keyword, signature, or regex logic should first have invisible and non-rendering Unicode code points stripped or folded, so that splicing them into a word no longer defeats the match,” the threat hunters wrote. This same control can also help reduce the threat of ASCII-smuggling against AI assistants that ingest email content. Microsoft also suggests scanning for behavioral indicators. “The observed activity had a distinctive shape: bulk volume from churning, finance-themed disposable domains, on a strict weekday-on / weekend-off schedule,” Kochavi and Wolstencroft warned. “A sudden spike of tag-block characters concentrated on finance-themed senders, switching on and off weekly, is a high-confidence campaign indicator.” ®
Kategorie: Viry a Červi

Anthropic’s Claude Can Now Autonomously Run Science Experiments With Lab Equipment

Singularity HUB - 4 Září, 2026 - 21:08

A new system allows agents to orchestrate complex experimental processes and extends Anthropic’s reach into the physical world.

Scientific research often depends on complex laboratory equipment that only specialists know how to use. But Anthropic is now rolling out a system that allows AI agents to control lab devices and autonomously carry out experiments.

Laboratory automation technology has been around for decades but getting different bits of equipment to talk to each other has traditionally been a major headache. Most instruments use their own proprietary interfaces, so connecting a microscope to a robotic arm or a liquid handler typically requires bespoke software that takes specialists weeks or even months to build.

Anthropic says its new Model Hardware Standard can reduce this process to minutes by giving devices a common language. It relies on a standardized “driver” that lets any programmable device describe itself to an AI agent, allowing the AI to handle the integration. The company announced it’s opening the system up as a research preview to an initial group of labs and manufacturers.

“Our hope is that the standard can be of use to researchers, engineers, and other practitioners in speeding up the process of discovery and experimentation in any domain that uses devices with a programmable interface,” Anthropic said in a press release.

The standard is similar to Anthropic’s Model Context Protocol, which makes it easier for AI to interact with third-party software, but the new system is aimed at hardware instead. The driver at its heart is essentially a piece of software that sits between a computer and a piece of hardware, translating instructions from one into signals the other can act on.

Most laboratory instruments already run some form of driver, but each has traditionally spoken its own dialect, which is why connecting them has required custom code that can translate between devices. Anthropic’s new driver standardizes that dialect using deliberately simple commands such as “read” or “write,” which can refer to anything from checking a temperature to setting the length of an operation.

Because every device speaks in these same basic terms, machines can find each other on a network and exchange data without a custom program to translate between them. The driver also makes it easier for the company’s Claude agents to learn how to use a device they’ve never seen before.

The standard lets users encode key details, like the weight of a robotic arm, using natural language.  They can either write out their hardware setup themselves or have an agent interview them about it. The system then turns that information into a reference file covering what a device can measure, what can be adjusted, and what safety limits apply.

Anthropic says this lets its agents orchestrate complex experimental processes across multiple instruments in often highly complicated and interactive ways. “We’ve found that Claude interacts with experiments and hardware in an exploratory manner, much as a scientist would,” the company writes. “We observed Claude make an adjustment to a laser, observe the results through a camera to assess how its adjustment moved the laser beam, and repeat the process, seeking to understand the sequence of events.”

Speaking to the Financial Times, Anthropic scientist Alek Kemeny described watching Claude locate a specific, unfamiliar structure in a live brain tissue sample during a neuroscience experiment by manipulating a microscope’s mirrors and lasers on its own. “The neuroscientist sitting there said: ‘Yep, that’s right,’” said Kemeny.

The new standard could be key to the company’s ambition to move beyond its key markets of software development and knowledge work and allow its AI to start having an impact in the physical world. But allowing AI, which is still not immune to hallucinations, to control real-world hardware carries considerable risks.

“It is an impressive proof of concept, but how do we ensure safety in the physical world? Because small errors can matter here,” Kaoutar El Maghraoui, principal research scientist at IBM, said on the company’s Mixture of Experts podcast.

That’s probably why Anthropic is only releasing the standard to a small number of partners initially, and it has committed to working with them to build safety evaluations for AI systems that are operating physical hardware. If the early launch goes well though, AI agents could soon make an impact in far greater swathes of the economy.

The post Anthropic’s Claude Can Now Autonomously Run Science Experiments With Lab Equipment appeared first on SingularityHub.

Kategorie: Transhumanismus

Xiaomi přivezlo do Evropy nového robota CyberOne. Rozhoduje se sám a sbírá zkušenosti v továrně na elektroauta

Živě.cz - 4 Září, 2026 - 19:45
Xiaomi nevyrábí jen telefony, hodinky a zařízení pro chytrou domácnost... • ...ale také elektromobily a humanoidní roboty • Právě ty značka dovezla i do Evropy a pochlubila se, jak pomáhají s výrobou aut
Kategorie: IT News

“Trust, not features, is the real deficit”: VMware tries to appease SMBs

Ars Technica - 4 Září, 2026 - 19:35

For many small-to-medium-sized businesses (SMBs), VMware has become too expensive.

Broadcom’s acquisition of the virtualization firm brought the end of perpetual license sales and the arrival of pricey, stacked, subscription-based bundles that priced out many SMBs.

The most obvious is VMware Cloud Foundation (VCF), VMware’s flagship private cloud bundle that has been Broadcom’s primary focus since taking over VMware. Many SMBs find that VCF is unaffordable and stuffed with unnecessary offerings. However, numerous customers have reported online that VMware sales representatives have still pushed them toward VCF, with some claiming that sales reps have told them that the lower-priced edition of VMware’s virtualization platform, vSphere Standard, was no longer available.

Read full article

Comments

Once popular for attacking AI, ASCII smuggling is embraced by spammers

Ars Technica - 4 Září, 2026 - 19:18

A clever technique used to hide malicious prompts in attacks on AI agents has been adopted by spammers to evade filters on email platforms that are designed to flag unwanted messages used in mass campaigns.

The technique is broadly known as ASCII smuggling. It gained attention two years ago as a means of making a class of AI attack known as prompt injections more stealthy. Malicious instructions embedded in emails or other untrusted content to be processed by an LLM aren’t written in ordinary text. Instead, they’re rendered by a special range of Unicode tags. For example, the tag point U+E0041 mirrors “A,” and U+E0061 mirrors “a.”

No longer just for obscuring prompt injections

The block of 128 tags mimics a portion of the American Standard Code for Information Interchange almost perfectly, with one major difference: the characters they encode are readable by computers but, by design, are almost completely invisible to humans. By expressing the malicious prompts in these tags, LLMs detect the instructions, but people reading the email never see them. There’s much more about ASCII smuggling here.

Read full article

Comments

IDScan sued over alleged data breach affecting 153 million drivers

Bleeping Computer - 4 Září, 2026 - 18:56
Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153 million driver's licenses. [...]
Kategorie: Hacking & Security
Syndikovat obsah