Agregátor RSS

Za nabídkou Start ve Windows 95 stojí psycholog, který původně zkoumal komunikaci šimpanzů

Živě.cz - 4 Září, 2026 - 18:45
Daniel Oran navrhl slavnou nabídku Start pro operační systém Windows 95 • Výzkum šimpanzů mu pomohl pochopit chování nezkušených uživatelů • Tlačítko v rohu obrazovky výrazně zjednodušilo ovládání osobních počítačů
Kategorie: IT News

Nvidia-Hugging Face deal could require an enterprise AI rethink

Computerworld.com [Hacking News] - 4 Září, 2026 - 18:03

IT industry experts and analysts are still trying to piece together Nvidia’s surprise plan to pay $12.9 billion for open-source AI company Hugging Face.

Nvidia dominates AI with its GPUs, and the company generates billions of dollars in revenue through a proprietary approach to the fast-moving technology. Hugging Face, on the other hand, hosts open models and has been a neutral player between chip vendors and model labs.

“This is about Nvidia having more say in how the stack gets built,” said Stephanie Walter, analyst at Hyperframe Research.

Hugging Face is wildly popular with developers, and Nvidia is buying early influence with that crowd. “You have a better chance of being part of the production environment later,” Walter said, adding that she wasn’t sure how Nvidia reached a nearly $13 billion price tag for the acquisition.

“Hugging Face has near-uncontested market primacy over where developers go for open-weight model releases. Now Nvidia owns that,” said Mark Petty, senior director analyst at Gartner.

Nvidia’s chase for developers should force IT decision-makers to review how much of the AI stack they control, said Hector Liu, director of Institute of Foundation Models’ Silicon Valley Lab. IFM is part of the Abu Dhabi-based Mohamed bin Zayed University of Artificial Intelligence.

Liu said CIOs should ask themselves three questions: “Can you run the model on hardware you already have, without a dependency you didn’t choose? Can you see how it was built?” And, “is the license one you can build a business on?

“A model that passes all three is durable, no matter who buys whom next year,” Liu said.

IFM’s latest K2 Horizon model, which was introduced on the same day Nvidia’s deal was announced, is hosted on Hugging Face. The open model was built to answer all of those questions.

K2 Horizon runs on AI hardware from Nvidia, AMD, Cerebras, and major cloud providers, said Liu, who doesn’t expect that to change. “Nvidia has said Hugging Face stays an open platform for every builder and every accelerator, and we’ll take that at face value,” Liu said.

Nvidia pledged to maintain Hugging Face’s hardware and model independence, and said its compute won’t be required. 

Even so, Nvidia isn’t paying nearly $13 billion for a model repository, said Jake Newfield, CEO at Hermetiq — it’s buying the front door to open AI.

(Hermetiq develops AI build and code observability tools.)

AI-generated output is becoming abundant and the infrastructure that makes it testable, reproducible and deployable is becoming strategically valuable, Newfield said. “Nvidia can accelerate it with capital and compute, but the real test is operational neutrality,” he said. 

That involves assessing whether competing hardware remains equally supported across the tooling, benchmarks and deployment paths developers actually use, Newfield said.

Beyond distribution, Nvidia is also buying Hugging Face for data, Petty said. That data showed that agents overtook humans as its largest traffic source in July, the kind of insight that could prove valuable down the road.

“Every model pulled tells Nvidia what the market wants next,” Petty said.

Nvidia has every reason to grow demand for open models and to keep them cheap, Petty said. “That’s good for enterprises, as it prevents market consolidation around a small number of proprietary model owners,” Petty said.

Closed and open models will coexist and lead to a world “where you’re going to continue to train these models and run these models at scale,” Justin Boitano, Nvidia’s vice president for Enterprise AI, said in a press conference after the deal’s announcement.

Nvidia will benefit “through the training that’s done and the inference that’s done on our hardware as models get diffused into the ecosystem at scale,” Boitano said.

That’s one motivation to keep the ecosystem open and neutral, so “developers can work wherever they want to work,” Boitano said.

Open source makes AI more accessible by lowering the barriers to experimentation and adoption, said Jon Carvill, senior vice president of marketing at AI chip maker Nuvacore. “Bringing Nvidia and Hugging Face closer together should help accelerate that choice, access and innovation,” Carvill said.

But there are still unanswered questions around whether Hugging Face will remain open and how much proprietary control Nvidia might exert, said Jack Gold, principal analyst at J. Gold Associates.

Microsoft traveled a similar path with its acquisition of open-source repository GitHub, which “did not really pan out as well as Microsoft hoped,” Gold said. “With Nvidia’s acquisition, will it still be as open to competitive hardware-software access, or will there be some barriers employed?”

Kategorie: Hacking & Security

Rogue OpenAI agents used dead German web site to communicate in May, months before Hugging Face incident

The Register - Anti-Virus - 4 Září, 2026 - 18:02
OpenAI’s agents were going rogue as early as May, according to a new report, making the Hugging Face incident far from the first where bots committed a breach. A report published Friday by a group of researchers claims to have found – with all of the agent posts presented as evidence – a self-identified “swarm” of OpenAI agents taking over a functionally dead German software developer wiki. Over the course of a month, from May to June, the agents made around 18,000 posts to the wiki, apparently acting against OpenAI developer intentions. According to the researchers, the wiki was hijacked like OpenAI’s own Artifactory package manager involved in the Hugging Face incident, to serve as a message board for agents. In this case, they appear to have been tasked with performing a timed web lookup task, for which the agents were apparently granted read access to the web, but not write access. One of the first things they apparently did was figure out how to subvert that restriction in order to post to the hijacked wiki. “The agents used this wiki to communicate information with each other, primarily to help them succeed at their task,” the researchers explained from a review of the thousands of posts made to the wiki, all of which are available for review in the report. “They asked for answers, pooled results, and shared techniques for bypassing their restrictions.” The agents also tried to pool their knowledge of the task they were assigned to predict what sort of questions they’d be asked next, and even set up heartbeat tasks to predict whether completing the assigned tasks would lead to their termination. They also discussed using Tor and other anonymizing services to hide their traffic, and began to react when a human moderator of the site spotted their traffic and started to delete posts. The researchers discovered all of this while searching for additional cases of rogue AI agent activity in the wake of the Hugging Face attack. In an email to The Register, OpenAI told us that it has acted with transparency and good faith around its agentic AI incidents, voluntarily disclosing such matters and maintaining a commitment to providing an accurate account of what its systems do. As for why it didn’t mention the German incident when it disclosed the Hugging Face one, that’s because the two were entirely unrelated, a spokesperson explained – as if that’s reassuring. OpenAI added that it should have been obvious from the Hugging Face report that this has happened multiple times, however, pointing us to a passage in its blog post on that incident. “While investigating this incident, we discovered rare cases in which agents without multi-agent tools found ways to collaborate via side channels during training,” the Hugging Face post-mortem explains. “We believe that this behavior started due to generalization from multi-agent training.” In other words, if we didn’t read between the lines, that’s on us. OpenAI declined to provide additional details, however. Fool me twice, shame on me As was the case in the Hugging Face attack, one of the tasks assigned to the agents was impossible given the restrictions placed on it. With Hugging Face, it involved a cybersecurity task that was impossible to answer from within the agents’ sandboxes,. In this case, the researchers said the task was to provide a statistic accessible from a Power BI dashboard. Retrieving said statistics required the ability to make a GET request, but the agents were restricted to POST requests. In both cases, the OpenAI agents acted against their programming to escape their restrictions, ostensibly in an attempt to solve a problem put to them that couldn’t be done without acting against their operators. The agents in this case were able to collaborate and find a way around the restriction by exploiting a condition in their sandboxes that excepted Azure Blob Storage hostnames from a security proxy. When the agents realized this, they started directing traffic through those hostnames to avoid GET restrictions. It was through GET requests that the agents gained write permissions on the internet, kicking this whole thing off. The similar nature of both incidents, in which bots escaped their sandboxes and subverted restrictions when given an impossible-to-complete task, begs a very important question: Are OpenAI’s engineers so incompetent that they’d screw up fundamental instructions twice, or is the company intentionally hamstringing their agents to see what they’re capable of, with the entirety of the internet placed downrange? For that matter, how many more times do we need to read between the lines of OpenAI's corpo-speak to infer this has happened more than the two times we know about so far? OpenAI, predictably, didn’t respond to that line of questioning. ®
Kategorie: Viry a Červi

Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

The Hacker News - 4 Září, 2026 - 17:57
Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'funding' to prevent email filters from parsing them," the Microsoft Security Research team said. The
Kategorie: Hacking & Security

Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

The Hacker News - 4 Září, 2026 - 17:57
Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'funding' to prevent email filters from parsing them," the Microsoft Security Research team said. The Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

tmp.0ut Volume 5

AbcLinuxu [zprávičky] - 4 Září, 2026 - 17:33
Bylo vydáno nové číslo hackerského magazínu tmp.0ut: Volume 5.
Kategorie: GNU/Linux & BSD

Critical Citrix NetScaler auth bypass now leveraged in attacks

Bleeping Computer - 4 Září, 2026 - 17:25
Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian. [...]
Kategorie: Hacking & Security

PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution

The Hacker News - 4 Září, 2026 - 17:20
PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logical decoding was introduced in PostgreSQL 9.4 in 2014. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are
Kategorie: Hacking & Security

PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution

The Hacker News - 4 Září, 2026 - 17:20
PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logical decoding was introduced in PostgreSQL 9.4 in 2014. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Macs don’t just do AI, they’re replacing the cloud for it

Computerworld.com [Hacking News] - 4 Září, 2026 - 17:08

surprised myself this morning when I came across an interesting Apple-commissioned report — Rethinking critical AI infrastructure — I’d not seen before. It looks at the shifting expectations for AI infrastructure and recognizes that enterprise users want (and need) secure, on-device AI solutions for critical parts of their business.

That’s why tens of thousands of companies are already investing in Macs, because they recognize that Macs do indeed do AI. The study, published earlier this year and put together by Omdia, reflects insights gathered across 1,500 conversations with enterprise tech leaders and practitioners, noting that for many in business the current cloud-based approach to AI fails to deliver on three key metrics:

  • Costs: Current pricing models seem unsustainable. Particularly when it comes to agentic AI, costs climb fast and business users need to get those costs under control. 
  • Security: Even the most secure cloud services include some degree of data risk. When it comes to using AI for regulated data in industries such as healthcare, business users need much more security than the cloud inherently provides. After all, data that is not transmitted will not leak in transmission.
  • >Capacity>: Workload requirements change and capacity needs to scale. That can boost the cost of accessing additional cloud capacity, or impose limitations in the event it can’t be found. It’s also true that while frontier models can provide all the bells and whistles of AI for advanced tasks, the vast majority of the AI work does not require anything near as much power. As Omdia explains: “57% of enterprise models are under 10 billion parameters, well within the capabilities of modern devices like MacBook Air or the entry-level MacBook Pro.”
What they think

As you might expect, the researchers believe on-premises AI set-ups respond to all three needs; not only that, but once you’ve coughed up cash for the necessary computational infrastructure, you don’t have to pay much more. “On-device infrastructure has near-zero marginal cost after initial investment, enabling unlimited experimentation without budget constraints,” the report said. 

Basically, once you’ve invested in on-premises capacity, you can divert mundane AI tasks to those machines for processing — limiting costs, boosting security and releasing capacity, turning to cloud-based models only when higher end AI solutions are required. While that’s good news for Apple, that’s bad news for many AI companies’ revenue models. (Perhaps they should have recognized that even the most advanced LLM’s will run on a standard iPhone eventually.)

The other advantage is that if AI is not used as widely as expected across a company, the same hardware can be used for other company tasks.

What’s actually happening

Enterprises already using AI are learning these lessons, which is why we see more of them buying Macs for these tasks. They do so because Apple’s computers deliver the computational power and performance to run AI effectively, from chip design to power consumption to the OS itself. Apple has intentionally built its platforms to be the best in class for running AI on device, and the Unified Memory architecture Apple has created in Apple Silicon scales really well, meaning you can run ever larger LLMs on Macs. 

It’s not just Macs, either. An iPad can run up to 14 billion parameter models quite happily; a Mac Studio reaches 480 billion; and a cluster of four Mac Studios will take you all the way to 1.6 trillion parameters using off-the-shelf cables.

To put that into context, Omdia found that 57% of the AI models typically used by the enterprise come in at under 10 billion parameters, which implies that enterprises could run a huge chunk of their AI tasks on an iPad, an iPhone, and certainly on a Mac. The ability of Apple’s ecosystem to scale is precisely why most AI developers at frontier model companies already use Macs. “Organizations that build AI solutions in-house adopt Mac for AI workloads at nearly double the rate of organizations buying commercial solutions,” the report explained.

The takeaway

Apple is emerging as an important component of an overall ecosystem for applied AI in the enterprise — or anywhere else — challenging frontier models with a scalable, controllable, economical, and secure approach to deployed AI that delivers most of the bang expected for the enterprise buck. 

While Apple paid for the report, that doesn’t necessarily invalidate its conclusions, which are not myopic around the Apple platform. Apple does not replace everything else, it just becomes one of the pillars to build success with AI. Companies can use other AI services and solutions, but they’ll want Macs along for at least some of the ride. And as the models themselves evolve and become slimmer and more refined, the platforms that run them best will deliver the advantage business users need.

Now, we need Apple to develop tools for the management, deployment, and governance of these solutions.

Please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSkyLinkedIn, or Mastodon.

Kategorie: Hacking & Security

New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic

The Hacker News - 4 Září, 2026 - 16:51
A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and
Kategorie: Hacking & Security

New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic

The Hacker News - 4 Září, 2026 - 16:51
A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host andSwati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Zadání znělo: Najdi na webu nějaká čísla. Roj agentů OpenAI si k tomu zřídil další tajnou nástěnku

Živě.cz - 4 Září, 2026 - 16:45
V červnu se na německé programátorské wiki objevilo varování. Jeden z agentů oznámil ostatním, že moderátor maže jejich stránky podle abecedy, a poradil jim založit zálohu se jménem začínajícím na ZZZ, aby přišla na řadu jako poslední. Připomíná to kauzu Hugging Face, že? Tentokrát si ale roj ...
Kategorie: IT News

Zadání znělo: Najdi na webu nějaká čísla. Roj agentů OpenAI si k tomu zřídil další tajnou nástěnku

Zive.cz - bezpečnost - 4 Září, 2026 - 16:45
V červnu se na německé programátorské wiki objevilo varování. Jeden z agentů oznámil ostatním, že moderátor maže jejich stránky podle abecedy, a poradil jim založit zálohu se jménem začínajícím na ZZZ, aby přišla na řadu jako poslední. Připomíná to kauzu Hugging Face, že? Tentokrát si ale roj ...
Kategorie: Hacking & Security

Microsoft says some users can’t open the Teams desktop client

Bleeping Computer - 4 Září, 2026 - 16:30
Microsoft is working to resolve a known issue that causes delays or blocks some users from opening the Microsoft Teams desktop client on Windows systems. [...]
Kategorie: Hacking & Security

39 New Methods That Compromise Passkey Authentication

Bleeping Computer - 4 Září, 2026 - 16:01
Passkeys eliminate many password-based attacks, but researchers have documented 39 methods for compromising authentication built around them. Token explains how attackers can abuse authentication prompts, synced credentials, enrollment, recovery, and other trust boundaries without breaking FIDO2 cryptography. [...]
Kategorie: Hacking & Security

Nvidia lets you build your own AI clusters locally with PAIR software

Computerworld.com [Hacking News] - 4 Září, 2026 - 16:00

Nvidia has released a free tool that will enable users to build an AI inferencing cluster from disparate PCs on the same network, accessible from a single interface.

Released as a beta, Nvidia Personal AI router (PAIR) connects devices running Windows, macOS or Linux to process AI inferencing workloads privately.

While the system is aimed primarily at home users, it could find favour with enterprises looking to put idle desktop compute capacity to use.

PAIR works with DGX Spark desktop supercomputers, PCs containing RTX GPUs, and some MacOS devices. The systems in the cluster run tasks in parallel, but PAIR does not turn them into a virtual GPU, Nvidia said.

The beta version of Nvidia PAIR is available for download now.

This article first appeared on Network World.

Kategorie: Hacking & Security

Německo odpálilo balistickou raketu. Naposledy je mělo ve výzbroji před více než třiceti lety

Živě.cz - 4 Září, 2026 - 15:56
Moderní Německo se krátce po svém znovusjednocení v roce 1990 zbavilo zásob balistických raket. Zatímco někdejší západoněmecký Bundeswehr měl ve výzbroji americké pershingy, východ disponoval sovětskými raketami typu Scud, Točka a Oka. Po více než třiceti letech se ale vše mění. Zkraje léta ...
Kategorie: IT News
Syndikovat obsah