Agregátor RSS

Linux Sandbox Bug Could Read a Freed Parent Directory

LinuxSecurity.com - 10 Září, 2026 - 21:10
A Linux sandbox restricts which files a program can access. Landlock, a kernel facility that lets programs apply those restrictions to themselves, had a bug in the code checking file locations. A concurrent directory move could leave the check reading memory that had already been released.
Kategorie: Hacking & Security

Microsoft Excel KB5002914 update breaks copy and paste for some users

Bleeping Computer - 10 Září, 2026 - 21:07
Microsoft Excel users report that this week's KB5002914 Office security update is breaking copy-and-paste operations and formula dragging, with affected users saying that removing or rolling back the update restores normal functionality. [...]
Kategorie: Hacking & Security

Hundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script

The Register - Anti-Virus - 10 Září, 2026 - 20:49
An unknown attacker used hundreds of AI agents to exploit two PaperCut MF/NG bugs and break into at least 395 organizations. The victims were concentrated in the US education sector, and the intrusions moved fast. In one case, an American high school went from initial access to domain admin in seven minutes. These agents, powered by OpenAI’s Codex harness and a DeepSeek model, also allowed the miscreant to attack organizations at scale, according to threat-intel firm GreyNoise, which traced the campaign’s orchestration to 45.142.193.132 on August 31. “The adversary went from an empty workspace to first achieving RCE against a real victim in just under four hours, first domain admin in an additional two hours, and once the full campaign launched, compromised at least 11 organizations in 26 seconds,” GreyNoise analysts said in a Wednesday report. The security provider attributes these intrusions to a “likely Russian-speaking” criminal who used AI to develop exploits against the pair of PaperCut vulnerabilities disclosed just days earlier. On August 28, the print management software provider issued emergency patches for CVE-2026-81578 and CVE-2026-82078, at the time warning that it was “aware of confirmed customer incidents and are treating this matter with the highest priority.” The flaws affect PaperCut NG and MF, which are self-hosted Java web applications that by default run with SYSTEM-level privileges on Windows. PaperCut’s CEO later said that the first reported compromise came in on August 27, and involved an education-sector firm. On Thursday, PaperCut published security maintenance releases, which replace the earlier emergency fixes. By now, however, at least 440 instances hosted by 395 identified victim organizations in 48 countries have been compromised, according to GreyNoise. “There are other real victims that could not be attributed to a named organization,” the threat signals team wrote. The human attacker told the agents to avoid targeting entities in 28 countries with the top five being Russia, China, Hong Kong, Thailand, and Iran. Several Commonwealth of Independent States (CIS) countries are on the list, which is why GreyNoise says the crim is likely Russian-speaking. It’s typical for ransomware and other cybercrime operations to expressly avoid attacking Russia and other CIS countries, whose governments often provide safe harbor for extortionists and financially motivated crims - especially if they also happen to work day jobs as state-sponsored hackers. Plus, local cops tend to ignore the digital break-ins unless the gangs infect any in-country organizations. However, the agents in the PaperCut attacks didn’t always follow these instructions, and in some cases still hacked organizations based in countries on the do-not-hit list. “It’s currently uncertain why the [attacker's] agents deviated,” GreyNoise said. “But it is a good example of agents gone wild.” The US and the UK were the countries with the highest victim count, at 98 and 59, respectively. Schools and other education-industry organizations were, by far, the hardest hit with 204 victims. For comparison, the No. 2 industry (other/unclassified) had 51, while retail/commercial/professional services ranked third with 38 victims. After using AI to develop exploits, achieve remote code execution, and harvest credentials in a self-hosted lab, the baddie set hundreds of AI agents loose on the open internet to find and attack public-facing, vulnerable instances. “This campaign appears to be opportunistic,” according to GreyNoise. “There is a high concentration of US-based targets in the education sector; however, it’s likely that is more attributable to the customer base of PaperCut NG/MF.” Interestingly, the attacker did not immediately set to work on post-compromise evil deeds with all of the victims. GreyNoise noted “multiple-day delays” between gaining initial access and achieving domain admin “but only due to a lack of action by the adversary.” The fastest time was five minutes, while the longest was 144 minutes. It’s also unclear if the criminal is only focused on gaining access to compromised organizations - and then plans to hand the attack off to affiliates or other data-theft, extortion, and ransomware groups - or if they plan to use this access for follow-on nefarious activities of their own. GreyNoise does note that, in at least one case, Cloudflare’s Web Application Firewall (WAF) blocked the attacker. “Fundamental hardening of environments still matters against AI-enabled threats,” they wrote. It’s also worth noting that GreyNoise has been tracking malicious use of 45.142.193.132 since early July, and says this IP has been used in attacks against internet facing technologies and devices from Palo Alto, Ubiquiti, Citrix, SonicWall, and Proxmox VE. ®
Kategorie: Viry a Červi

ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

The Hacker News - 10 Září, 2026 - 19:47
A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up until it isn’t. Different stories, same basic problem: the path in was often already
Kategorie: Hacking & Security

ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

The Hacker News - 10 Září, 2026 - 19:47
A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up until it isn’t. Different stories, same basic problem: the path in was often already Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

How Apple is trying to normalize always-on AI

Computerworld.com [Hacking News] - 10 Září, 2026 - 19:28

Apple does seem to have tried to ensure its controversial Audio Intelligence feature isn’t abused. Alongside the iPhone Duo and new iPhone 18 Pro range, Apple on Wednesday introduced a new Apple Watch equipped with a brand new feature it calls Audio Intelligence. The existence of this surprising tool was confirmed only on the eve of the launch event. Enabled by the new S11 chip on the latest Watch devices, this is actually a collection of four features:

  • Siri Recap, which creates high-level summaries of conversations during your day.
  • Live Rewind, which transcribes the previous 15 seconds of a conversation as text.
  • Music recognition, which relies on Shazam.
  • Sound recognition, which can identify things like sirens or alarms.

All of these features must be consciously enabled by the user and are not on by default.

What they have in common is use of artificial intelligence along with always-on microphones. While all four of these tools are being presented as opt-in, their existence will inevitably — and justifiably — raise privacy concerns. 

Apple saw those concerns coming, and to make the features work it has placed a Secure Enclave on the S11 chip inside the latest watches. This is a dedicated secure buffer on the chip that processes audio privately on the fly. It does so without creating a recording of ambient sound around you, and the data it works with is isolated from the rest of the system. That Enclave pairs with the iPhone using “a new audio-verified pairing mechanism that exists in addition to Bluetooth pairing,” Apple explains in a detailed white paper about how it works. 

For Siri Recap, the process works like this:
  • Apple Watch recognizes a conversation is taking place.
  • If so, audio flows into the Secure Enclave, encrypted, and transmitted to a similarly Secure Enclave on your paired iPhone.
  • The audio is then immediately deleted from the Watch. 
  • The phone will decrypt and transcribe the audio, condense it, and send that transcript to Private Cloud Compute for processing. 
  • The short summary is then made, returned, and deleted after seven days.
  • Speakers are not identified, recordings are not made, and detailed transcripts are not created or retained.

The company has also introduced safeguards for those around you. The system will deliberately omit some information, including potentially harmful content, financial data, or personal identifiers. When you use the Live Rewind tool, an audible chime plays on your device to alert nearby people that you are using the feature.

Challenges will emerge

For one thing, we don’t yet know whether the company will provide enterprise IT with device management tools to disable the feature on managed devices. It’s crystal clear that devices that are constantly gathering data will be seen as potential security risks — particularly in regulated industries. And it seems far more logical to provide new APIs to disable Audio Intelligence on managed devices than it would be to insist anyone wearing an Apple Watch put it in a lead-lined box before beginning the next safeguarding, healthcare, or product development meeting.

Another problem I see concerns Europe’s Digital Markets Act. It is, after all, inevitable that competitors (maybe including Meta) will want their devices to have equal access to the information gathered by Audio Intelligence. Based on the decisions Apple has made so far, it seems equally likely it will want to refuse such access; this is why these new features will not initially be available in the EU. 

There is also no doubt hackers will attempt to break into the system, though doing so will not be at all easy on account of the intentional way the company has built in security. I suspect, but do not know, that attempts will focus on the points at which data is exchanged across devices, rather than when the information sits within secure enclaves on those devices. It also makes sense that everyone who uses iCloud services for their data should put 2FA in place and pick strong passwords. 

What about iCloud storage?

The other challenge will be encryption, specifically ongoing attempts to penetrate iCloud data encryption by some nations, led by the UK. Even so, if access could be achieved to iCloud-stored Audio Intelligence text, what is obtained would only be summary data, not a recording. The system is architected so recordings are never made.

Apple’s white paper on the feature explores this in more depth: “Audio from the microphone enters the Secure Exclave of Apple Watch, where it is initially processed for speech, sounds, or music, without transcribing or storing the raw audio. This buffer is a continuously overwritten stream that exists only within the protected hardware and never creates an audio recording.”

Once you decide to keep a Recap or Life Rewind text, the raw audio is not saved to iCloud, only the text, and then only if you use 2FA and a device passcode. No one else, including Apple, can access the encrypted data you save, Apple said.

Where does this go next?

One pre-event rumor that didn’t come true concerned AirPods equipped with cameras and Vision Intelligence to understand physical context and surrounding, with the aim of enhancing Siri AI. I’ve expressed reservations about this idea, but do think the security model Apple has put in place for Audio Intelligence will turn out to be an echo of its intentions to secure Vision Intelligence transactions.

This implies a new chip with Silicon Enclave for AirPods Pro, a similar exchange of information in real time for summary and determination of context and content, and a process in which no recordings are made and media access beyond brief, time-limited summaries, is available. In short, Apple will use the same security model.

What about the rest of them?

That’s fine as far as it goes. But the other subtext is that while Apple seems genuine in its attempt to deliver relatively intrusive tech advances right, others will show less commitment to privacy and security. So, while it’s furthering the conversation about using these tools, Apple is also pushing public acceptance of such technologies.

I’m not entirely sure we’re ready.

Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSkyLinkedIn, or Mastodon

Kategorie: Hacking & Security

Recenze hry Marvel's Wolverine. Nejslavnější mutant ani nezkouší překvapovat

Živě.cz - 10 Září, 2026 - 18:45
Po Spider-Manovi se studio Insomniac Games rozhodlo odvyprávět příběh ikonického X-Mena. Wolverine je v komiksech zajímavější, než si neznalec může myslet. Své silné stránky přebírá i jeho herní novinka, ale náplní spadá do průměru a je jasně vidět, že hlavní záměr byl sehrát to všechno co nejvíc ...
Kategorie: IT News

Stockfish 19

AbcLinuxu [zprávičky] - 10 Září, 2026 - 18:38
Svobodný (GPLv3) šachový engine Stockfish (Wikipedie) byl vydán ve verzi 19 (𝕏). Přehled novinek v příspěvku na blogu. Stockfish 19 je o 44 Elo silnější než Stockfish 18.
Kategorie: GNU/Linux & BSD

AI-powered attack exploited PaperCut flaws to hack 395 organizations

Bleeping Computer - 10 Září, 2026 - 17:55
A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers. [...]
Kategorie: Hacking & Security

Tyhle tužkovky se nabíjejí pomocí USB-C. Jsou v rekordní akci a hodí se do každé domácnosti

Živě.cz - 10 Září, 2026 - 17:45
Alza zlevnila na historická minima vybrané Li-ion akumulátory Bluetouch. • Mají USB-C, vysokou kapacitu a napětí 1,5 V jako alkalické baterie. • K dispozici jsou ve formátech AA, AAA, C a D.
Kategorie: IT News

Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers

Bleeping Computer - 10 Září, 2026 - 17:43
Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. [...]
Kategorie: Hacking & Security

IDScan confirms breach tied to 153 million stolen driver’s licenses

Bleeping Computer - 10 Září, 2026 - 16:55
Identity verification company IDScan has confirmed that hackers accessed customer data stored in its cloud platform, days after reports linked the company to a massive database containing more than 153 million driver's license scans. [...]
Kategorie: Hacking & Security

Od pátku mají výrobci elektroniky 24 hodin na to, co si dřív mohli nechat pro sebe. Začíná ohlašování podle nařízení EU

Zive.cz - bezpečnost - 10 Září, 2026 - 16:45
** Z nařízení Cyber Resilience Act plyne od 11. září první praktická povinnost. ** Aktivně zneužitou díru musí výrobce oznámit evropskému úřadu. ** Tato povinnost dopadá jako jediná z CRA i na již prodávaná zařízení.
Kategorie: Hacking & Security

Od pátku mají výrobci elektroniky 24 hodin na to, co si dřív mohli nechat pro sebe. Začíná ohlašování podle nařízení EU

Živě.cz - 10 Září, 2026 - 16:45
Z nařízení Cyber Resilience Act plyne od 11. září první praktická povinnost. • Aktivně zneužitou díru musí výrobce oznámit evropskému úřadu. • Tato povinnost dopadá jako jediná z CRA i na již prodávaná zařízení.
Kategorie: IT News

Google Play Early Access Abused to Push Thousands of Deceptive Android Apps

The Hacker News - 10 Září, 2026 - 16:36
Bad actors are misusing Google Play's Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content. Early Access apps are apps that haven't been released on the official Android app marketplace. The main idea behind the program is for developers to solicit user feedback for new applications or features they may be working on before their
Kategorie: Hacking & Security

Google Play Early Access Abused to Push Thousands of Deceptive Android Apps

The Hacker News - 10 Září, 2026 - 16:36
Bad actors are misusing Google Play's Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content. Early Access apps are apps that haven't been released on the official Android app marketplace. The main idea behind the program is for developers to solicit user feedback for new applications or features they may be working on before their Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws

Bleeping Computer - 10 Září, 2026 - 16:11
Multiple cyber-espionage groups deployed an exploit kit dubbed "BlueMoon" that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. [...]
Kategorie: Hacking & Security

The Top 4 Threats We Found by Investigating Every Alert for a Quarter

Bleeping Computer - 10 Září, 2026 - 16:00
Identity was the target in roughly half of all confirmed malicious activity. Prophet Security breaks down the four main attack patterns seen across customer environments between May and July 2026, and explains why some attacks succeeded while others were blocked. [...]
Kategorie: Hacking & Security
Syndikovat obsah