Agregátor RSS
Autofokus kdysi býval hlavně mechanickou disciplínou. Později do hry vstoupila matematika, tabulky kontrastu a fázová srovnání. V roce 2026 je ale ostření především soutěží ve strojovém učení.
Programy pro osmibitová Atari není nutné vyvíjet pouze s využitím plnohodnotných assemblerů. Použít lze i monitory, například tuzemský Turbo Monitor, s nímž se dnes seznámíme. V Turbo monitoru lze provádět ladění, úpravy her (nekonečný počet životů) atd.
Zdá se, že proces Intel 18A je minulostí a krom již vydaného mobilního procesoru Panther Lake na něm nevznikne žádný další zásadní produkt. Intel tak upírá pozornost k procesu 14A…
Fyzici se vypravili do nebezpečných končin na pomezí obecné relativity a v experimentu poprvé pozorovali dlouho předpovídaný účinek gravitace na padající kvantový objekt. Postavili si na to pozoruhodný Quantum Galileo Interferometer a hráli si s atomy rubidia zchlazenými blízko k absolutní nule.
Despite what we saw with OpenAI’s models going rogue, creating message boards, and breaking into Hugging Face, only one advanced AI model - Anthropic’s Claude Mythos - completed the full cyber kill chain autonomously in Booz Allen’s tests. This doesn’t mean autonomous AI attacks are overhyped. And we should point out that the models tested don’t include OpenAI’s soon-to-be-released Astra, which OpenAI on Tuesday said reached its “critical” cybersecurity capability threshold. This means the new model is so good at finding and exploiting zero-day bugs that it poses a significant risk to critical systems, both from malicious users and even from the model itself, which is capable of carrying out harmful cyber actions “if misaligned.” Booz Allen asserts that most of the other 17 US and Chinese models it tested will achieve Mythos’ same level of weaponization within six months, and it calls mainstream AI attacks from both financially motivated criminals like ransomware gangs and government-backed goons “imminent.” In its first-ever Cyber Weapon Index, the consulting and tech firm calls on the US to set and enforce sector-specific deadlines for critical infrastructure to demonstrate resilience against AI-enabled attacks. Booz Allen also calls on the US to develop what it calls “overmatch” for both cyber offense and defense. “We must aggressively develop agentic capabilities that accelerate authorized offensive cyber operations while simultaneously building AI-enabled defenses that detect, decide, and respond at machine speed,” the report says. “The strategic opportunity is to master both - giving the United States the ability to impose costs on adversaries while making US systems faster to defend, harder to compromise, and more resilient when attacked.” The Cyber Weapon Index evaluated 18 models, nine from American and nine from Chinese developers, under identical conditions, and scored them on how well they autonomously identify vulnerabilities, create offensive capabilities, and execute attacks. Each model’s CWI score combines its vulnerability research score (VRS), which measures whether a model can identify planted and/or novel vulnerabilities, and a kill chain attainment score (KCAS), which awards points based on how far a model progresses through an end-to-end intrusion, tested both with and without credentials. Cyber Weapon Index scores The 18 models, ranked from highest to lowest based on their CWI score, are: Anthropic’s Claude Mythos (80), xAI’s Grok-4.5 (49), OpenAI’s GPT-5.6 Sol (46), Meta’s Muse Spark 1.1 (38), Moonshot AI’s Kimi K3 (38), Z.ai’s GLM-5.2 (37), Anthropic’s Claude Opus 4.8 (36), OpenAI’s GPT-5.5-Cyber (34), Nvidia’s Nemotron-Ultra (33), DeepSeek-V4-Pro (23), DeepSeek-V4-Flash (17), Alibaba’s Qwen3.5-397B (17), MiniMax-M3 (15), Nvidia’s Nemotron-Super (15), Anthropic’s Claude Sonnet 5 (13), Z.ai’s GLM-4.5-Air (11), Alibaba’s Qwen3.6-35B (9), and Alibaba’s Qwen3-Coder (4). Claude Mythos’ performance was especially impressive or concerning, depending on one’s views of autonomous AI attacks. When the testers gave the model stolen employee credentials, it successfully broke into its target network and gained administrator-level control in every attempt. Plus, it independently identified how to gain higher-level access based on what it found within the network - not by following a predetermined attack plan. Even without credentials, Claude Mythos still gained access to the network and ultimately achieved full domain compromise. While only Claude Mythos executed the entire cyber kill chain without any human assistance, three other models - Grok-4.5, Muse Spark 1.1, and GLM-5.2 - reached full domain access and control. Four others - GPT-5.6 Sol, Kimi K3, GPT-5.5-Cyber, and DeepSeek-V4-Pro - achieved lateral movement across the controlled network environment. Claude Opus 4.8 and Qwen3.5-397B obtained credentials, which allowed the models to expand access and privileges. And all but one - Qwen3-Coder - autonomously gained initial access to the network. While advanced models are exceedingly good at offensive cyber capabilities, “their real-world impact depends heavily on the vulnerabilities they face and the systems built around them,” according to the report. When the testers intentionally introduced vulnerabilities, US, Chinese, open-weight, and closed models all scored near ceiling on the VRS component. When tested against real bugs, however, all nine of the frontier API models scored zero. One unnamed leading model even correctly analyzed the vulnerable component, but then dismissed it as safe. Only Claude Mythos exploited it. “That concentration of capability creates a national-security imperative: protect the most advanced models and prevent their highest-risk cyber capabilities from being operationalized by adversaries,” the authors wrote. This is one of the areas where defenders still have an opportunity to outpace the attackers, Booz Allen suggests: “Real-world offensive capability still trails benchmark performance, giving defenders valuable time to strengthen defenses before that gap closes.” Why attack harnesses matter Another interesting finding is that the attack harness matters at least as much as, if not more than, the model itself. The attack harness - this is the software that connects a model to hacking tools and the orchestration logic wrapped around the artificial intelligence model to automate offensive cyber actions - can “dramatically amplify” the model’s ability to stay focused, adapt and change course as needed, recover from failure, and chain individual actions into a multi-stage attack, the authors found. “The result is not a ‘smarter’ model but rather a system that makes its intelligence far more actionable while also lowering the expertise required to use it,” the report says. “Our testing demonstrates the effect: when paired with an attack harness, Claude Sonnet rivaled Claude Mythos’ performance.” However, it also exposes a blind spot, they note. “We do not yet know the full kill-chain capability of open-weight or Chinese models when paired with optimized harnesses, but our results strongly suggest that fully capable model-and-harness combinations exist today,” according to Booz Allen. Similarly, the index’s findings suggest that Chinese frontier and open-weight models, while still trailing leading American frontier models, aren’t that far behind in their offensive security skills and could be deployed in real-world attacks. This means “the United States may neither control nor fully understand the capabilities it could face,” the report says. “And, as cyber agents become more autonomous, defenders must prepare not only for deliberate attacks but for agents that exceed their intended mission or continue operating beyond an adversary’s control.”®
Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. [...]
Not long ago, I rented an SUV from a well-known car rental company. Within hours of an employee scanning my driver's license, a high-resolution scan of my ID was available for sale on the dark web.
An exposé published Tuesday by KrebsOnSecurity reports that my license was one of more than 153 million that were available through Nexus, the name of the new ID theft service. Like other driver's licenses available there—including some belonging to journalist Brian Krebs, his mother, an FBI assistant director, and several security researchers—my license was purported to include multiple image files showing both the front and back of the ID. Besides a basic image scan, the files also captured the images in the infrared and ultraviolet spectrums. Presumably, the additional formats may allow cloned-based counterfeit IDs to pass hologram tests.
Growing by the day
Besides advertising the availability of driver's licenses, Nexus offered to sell a bevy of other forms of ID. They included: Read full article
Comments
An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites. [...]
OLED televizory Sony patřily v posledních letech spíše k dražším modelům. Nová BRAVIA 6 to mění. Nabídne 120Hz OLED panel, Dolby Vision a čtyři vstupy HDMI 2.1, přičemž 65palcová verze startuje na ceně 39 999 Kč.
A human ransomware crook used frontier AI models to breach an enterprise network in less than 10 hours, an intrusion Unit 42 says would normally take human operators around two weeks. The human attacker then told negotiators that they used frontier models and agentic attack frameworks with AI agents carrying out each step in the intrusion, including leaving an 80-page security audit for the victim company. “What made the attack stand out was AI-assisted operational efficiency, without the need for a novel zero-day or super elite tradecraft,” Unit 42 incident responders said in a Wednesday report. “The attacker left tactical execution to AI agents that monitored, evaluated, acted and re-planned in real time, increasing speed throughout the attack chain.” The security shop did not immediately answer The Register’s questions about the intrusion, including which models and frameworks the attacker used. Breaking down the attack In a first step, the human attacker employed AI agents to perform reconnaissance, then gained access by breaching a public API endpoint to tunnel into the enterprise network. Upon breaking in, the attacker deployed an automated recon agent to map internal microservices. Additional subagents scraped code repositories to steal hard-coded tokens and service passwords. Using these tokens, the AI intruders accessed the org's secret-management system and stole the master administrative credentials to gain root system access. “Specialist pivot agents” then validated access to the company’s cloud, identity, CI/CD, container, and SaaS environments. The attacker also hijacked CI/CD workflows to steal cloud access keys and turn the victim’s cloud AI services into post-compromise infrastructure. This allowed the attacker to consume the victim’s compute resources while hiding orchestration traffic among legitimate activity. After achieving the human operator’s goals, an agent left the victim an 80-page report on its security failings, detailing “dozens of exploited findings,” the incident responders wrote. Not surprisingly, Palo Alto Networks says the only way defenders can protect their environments against machine-speed attacks is to use AI agents themselves. “Deploy automated playbooks that simultaneously revoke credentials, terminate OAuth sessions, freeze CI/CD pipelines and isolate cloud accounts across all operational planes,” the authors advise. The incident response team also suggests companies treat AI as core infrastructure. This requires taking inventory of every model endpoint, API key, Model Context Protocol (MCP) gateway, and AI tool integration, and applying rate limits and least-privilege policies – or risk an unexpected and very large token bill. ®
Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program.
"The Fairwind Program gives high-priority defenders (like governments, healthcare providers, and telecommunications services) early access to advanced models that help them
Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program.
"The Fairwind Program gives high-priority defenders (like governments, healthcare providers, and telecommunications services) early access to advanced models that help them Ravie Lakshmananhttp://www.blogger.com/profile/ [email protected]
Smartphony válcují nejen levné, ale už i pokročilé kompakty • Vlajkové modely jsou skoro jistota, dobře fotí ale i levnější přístroje • Po kterých fotomobilech byste měli aktuálně sáhnout?
Dvě nové studie spojují globální pokles porodnosti s rozšířením smartphonů • Raná exkluzivita iPhonu u sítě AT&T prokázala zrychlený pád plodnosti • Digitální izolace a snazší přístup k pornografii vytlačily reálné schůzky
Na trh se zatím nechystá, ale nejde o úplně nesmyslnou myšlenku. Připravovaný herní handheld Acer Project DualPlay Mini řeší hlavní výtku pro herní handheldy. Jde totiž o jednoúčelová zařízení, která jsou možná dobrá na hry s ovladačem, ale dělat na nich cokoli jiného je téměř nemožné.
V ...
Former Apple chip supplier Intel has faced a lot of challenges since Apple ceased to be a client. It struggled to win back some of Apple’s processor manufacturing business, but seems to face one fundamental challenge — trust.
That’s the very briefest gist of an extensive and outstanding report today from Culpium, which gives us an insider look at the relationship between the firms. It’s particularly relevant, given that the Trump Administration has announced that Apple agreed to work with Intel in the future. (TSMC is Apple’s current supplier and that relationship seems very solid.)
The root of the challenge
The problem with Intel, according to the report, is that a lack of trust drove Apple to seek an alternative processor supplier in the first place. The report discusses some of those challenges, including Intel’s failure to keep the pace with Mac chips, which is why the M1 chip astonished the industry, because it gave Apple the performance it had always sought.
How we got here
The root of that release was mobile, of course. Apple’s A-series chips were built for mobile and eventually transcended to become M-series Mac chips. Intel turned Steve Jobs down when he asked it to make mobile processors, pushing Apple to TSMC. The history is more complex than that, of course — Apple also acquired chip development expertise from PA Semi, for instance — and established a foundry deal with TSMC that meant the company produced Apple-designed chips. The work Apple did on mobile processors eventually enabled the move to Apple Silicon.
That’s the history. Fast forward to today and an ailing Intel needed new client wins even as the Trump Administration sought to support onshore processor production; it’s a strategic need for the US. The problem is, as Culpium terms it, that Intel isn’t willing to build manufacturing capacity until it wins the supply contract. And Apple needs a much firmer promise than that to supply its huge mass market. It needs capacity before it can provide trust.
Telling tales too soon?
During the most recent negotiations concerning Intel’s capacity to deliver chips in quantity, the report tells us Intel somehow managed to challenge that trust by telling third-party partners that it had secured Apple as a client. Anyone who knows Apple will recognize that the company doesn’t like its business discussed that way. “A sure sign that the two companies may be on the path to some serious cultural clashes,” wrote Culpium.
TSMC, meanwhile, has a corporate commitment to trust, a promise recognized across the industry — even by Nvidia founder Jensen Huang. That trust extends into tomorrow, which is why TSMC invests vast sums in developing process technology it believes customers will need tomorrow, rather than waiting for them to order up capacity today. That’s also why TSMC today offers some of the world’s most advanced interconnects, enabling powerful tech that likely includes Apple’s M5 Ultra. But just as important as technology and manufacturing capacity is a trusted relationship between companies.
That’s not to say capacity doesn’t matter. It does. And as Apple continues to sell its products in ever greater quantities, it knows it must source additional supply; that’s why it speaks to Intel, Samsung, or even CXMT about the components its products require. But ultimately, a company that historically has felt let down by numerous key competitors — think Google, Samsung, and Android or, more recently, elements of OpenAI — will place a great deal of value in discretion and corporate trust.
After all, Apple has learned that in the ultra-competitive market in which it exists, what some call paranoia will in the end be seen as business sense.
You can follow me on social media! Join me on BlueSky, LinkedIn, Mastodon and subscribe to The Core.
An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers.
"The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users," Microsoft
An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers.
"The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users," MicrosoftRavie Lakshmananhttp://www.blogger.com/profile/ [email protected]
SonicWall says attackers are actively exploiting two chained zero-days to take over Secure Mobile Access (SMA) Series 1000 boxes. Aimed at midsize and large enterprises, SMA1000 gateways secure remote access and VPN connections. Compromising one can therefore provide attackers with a valuable route into corporate networks. So, get to applying those hotfixes, says SonicWall. There are no workarounds. The first zero-day, CVE-2026-83548, is a pre-authentication server-side request forgery (SSRF) vulnerability with a maximum CVSS v3 score of 10.0. SonicWall attributed it to an unintended alternative access path. "A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations," the vendor said. The second, CVE-2026-83549, is a post-authentication OS command injection vulnerability in the SMA1000 Appliance Management Console (AMC), rated 7.8 on CVSS v3. Under certain conditions, an attacker authenticated as an administrator could execute arbitrary commands on the appliance. The flaws affect the SMA 6210, 7210, and 8200v appliances, for which SonicWall has released hotfixes. SonicWall advised customers to contact its technical support team for help identifying indicators of compromise. If an appliance appears to have been compromised, SonicWall recommends reimaging or redeploying it, changing all passwords, and resetting TOTP tokens. NHS England, which published its own advisory, warned about the growing risk of attacks against internet-facing gateways. "Firewalls and other edge devices are internet-facing by design and are highly attractive targets to attackers, and there is an increasing number of edge device vulnerabilities disclosed each year that are rapidly exploited by attackers," it stated. "The NHS England National CSOC assesses future exploitation of these vulnerabilities as almost certain." The disclosures continue a difficult run for SonicWall and its SMA1000 product line stretching back through 2025. In July, the vendor disclosed an eerily similar pair of vulnerabilities. That pair also comprised a pre-authentication SSRF vulnerability, this time in the SMA1000 Appliance WorkPlace interface, and a post-authentication OS command injection flaw in the AMC. The SSRF received a maximum CVSS v3 score of 10.0, while the command injection bug was rated in the sevens. CISA later added CVE-2026-15409 to its Known Exploited Vulnerabilities catalog and marked it as known to have been used in ransomware campaigns. Throughout 2025, SonicWall patched a succession of SMA1000 vulnerabilities, including OS command injection and privilege escalation flaws, while investigating zero-days linked to ransomware attacks. ®
|