Agregátor RSS

Cybercrooks trawl Fishbrain to net password hashes

The Register - Anti-Virus - 3 Září, 2026 - 14:45
Cybercriminals have reeled in password hashes and corresponding salts belonging to users of popular fishing app Fishbrain, opening the door to cracking attempts. Fishbrain AB, which says its eponymous app serves more than 20 million anglers, disclosed the August 19 breach to the California Attorney General's Office this week. The unknown perpetrators helped themselves to a trawl of user data, including names, dates of birth, email addresses, phone numbers, Fishbrain usernames, country information, password hashes, and salts. "Fishbrain passwords were not stored in plaintext; however, Fishbrain has determined that the compromised password hashes for some users may be susceptible to being decoded," the company said in its disclosure [PDF]. It added: "If you use your Fishbrain password for any other online accounts, you should promptly update those passwords and any associated security questions or answers. "You should also take other appropriate steps to protect any online accounts that use the same username or email address and password combination. We recommend using a strong, unique password for each of your accounts." With the hashes and salts in hand, attackers can make password guesses using their own hardware until they potentially recover the original credentials. Whether those attempts succeed depends on the strength of each password and the hashing algorithm Fishbrain used, which the company did not disclose. Fishbrain did not comment on the scale of the breach or how many of its claimed 20 million-plus users were affected. The Register asked Fishbrain for more information. After discovering the intrusion and conducting an initial forensic investigation, Fishbrain patched the vulnerability and reset every user's password. Customers must create a new one the next time they log in. Fishbrain also said it "restricted access to the affected environment," strengthened its security controls, and initiated "a broader review of our data security measures" while the investigation continues. Fisherfolk should also keep an eye out for phisherfolk using the stolen personal data to bait follow-on attacks. ®
Kategorie: Viry a Červi

Continuous Linux Security: Why a Hardening Checklist Is Not Enough

LinuxSecurity.com - 3 Září, 2026 - 14:39
A Linux server can be carefully hardened before it reaches production and still become less secure over time. Hardening means reducing unnecessary services, accounts, permissions, and other ways into the system. That work matters, but it describes the server at one point in time. Six months later, a new application may be installed, a firewall port opened for troubleshooting, an administrator given sudo access to run commands with elevated privileges, or a software update may have changed a c...
Kategorie: Hacking & Security

Microsoft says KB5120998 Windows update resets desktop settings

Bleeping Computer - 3 Září, 2026 - 14:16
Microsoft has confirmed that desktop settings are lost or reset on some Windows devices after installing the KB5120998 August 2026 preview update. [...]
Kategorie: Hacking & Security

US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries

The Hacker News - 3 Září, 2026 - 13:58
An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campaign spanning 46 countries. Around 45% of observed activity was associated with the United States, making it the campaign's top geographic target. ANY.RUN research connected 601 cases to the wider operation, which uses
Kategorie: Hacking & Security

US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries

The Hacker News - 3 Září, 2026 - 13:58
An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campaign spanning 46 countries. Around 45% of observed activity was associated with the United States, making it the campaign's top geographic target. ANY.RUN research connected 601 cases to the wider operation, which uses [email protected]
Kategorie: Hacking & Security

Adobe’s Slack integration brings AI content creation to workplace chats

Computerworld.com [Hacking News] - 3 Září, 2026 - 13:51

With the launch of a new integration this week, Adobe is making more than 70 Creative Cloud applications available in Slack, promising to bring generative AI (genAI) document creation closer to team conversations. 

The Adobe MCP (model context protocol) integration allows Slack users to access, edit, and create new documents from Adobe creative and productivity tools without switching apps. This includes Photoshop, Premiere, InDesign, Lightroom, and others.

The integration should help “improve efficiency and speed of content creation,” said Irwin Lazar, principal analyst at Metrigy. “We have consistently found in our research that companies want to use their team collaboration apps, like Slack, as work hubs.” 

To access the integration, users interact with Slackbot — Slack’s AI “teammate” — via natural language prompts. 

Adobe outlined several use cases in a blog post Wednesday. It’s possible to turn “project plans and conversations” in Slack into “PDFs, images and videos you can share with your team in Slack,” and turn speadsheet data into a “PDF or visual you can share with your team or client.”

Other uses include the ability to edit images such as headshots and event photos in bulk — with controls available to adjust lighting and tone, crop and resize images, and more — as well as to search for Creative Cloud assets from Slack.

The editing interface is more limited than in the full Adobe apps, which Adobe said users can switch to when they want “greater creative control” and “pixel-level precision.”

The Adobe integration is available to Slack Business+ and Enterprise+ customers. Adobe said that most Adobe apps are “currently available for free to users,” though it didn’t confirm whether this is a temporary or long-term pricing structure. The integration includes access to some generative AI features, with daily usage limits, though others, such as generative video, require paid Adobe accounts.  

Overall, the move is part of a wider effort by Slack to make AI tools available where work conversations occur. That was the idea behind the recent Slack Code launch, for instance; it’s aimed at aiding interaction with AI coding assistants for multiple coworkers around one-off software development tasks such as bug-fixes and feature updates.  

For Adobe, it’s a continuation of efforts to make its software available in other platforms. The company recently announced ChatGPT integration that lets users create and edit content from the AI assistant. 

The Adobe integration with Slack allows conversations and work to “move closer together,” said Joe Cicman, principal analyst at Forrester. “Instead of Slack being where requests are discussed and Adobe being where changes are made, the conversation itself can increasingly become part of the creative workflow,” he said.

“More broadly, we’re seeing enterprise software move toward bringing capabilities to the worker rather than forcing the worker to move between applications,” he said.

Cicman expects that the ability to interact with Adobe tools in Slack will appeal first to “hands-on marketers and content creators who want to prototype ideas quickly or generate variants of existing assets.

“More broadly, it appeals to people who have more ideas than they have expertise in Adobe’s professional tools,” he said. “They know what they want to create, but not necessarily how to navigate Photoshop, Premiere, or Illustrator. Conversational interfaces let them express intent instead of mastering the UI.”

There are other considerations about an integration that enables users to generate content with greater ease. It could, for example, increase the production of low-effort, AI-created documents within organizations. 

According to Adobe, the goal of the integration isn’t only to help workers create more content, but to “express their ideas, contribute to the creative process and bring those ideas to life faster.

“By making Adobe’s pro-grade tools accessible through conversation, people across teams can more easily explore ideas, build on each other’s thinking and collaborate on how to make the work better,” said Deepti Pradeep, senior director for Agentic Product at Adobe. “At the same time, making creation easier only makes human judgment more important. Adobe’s tools can accelerate the creative process, but people still bring the ingenuity, taste and point of view that distinguish great work. 

“For brands, that human perspective is ultimately what turns content into something that stands out and creates a meaningful connection with an audience.”

Easier content generation could require companies to more closely manage an acceleration in AI-generated outputs,” said Cicman. “What’s happening across marketing and creative teams is that prototyping is becoming dramatically faster,” he said. 

“A marketer with a concept can describe it in Slack, AI can generate several potential executions, and suddenly the organization has many more ideas moving through the pipeline. The challenge is that faster creation creates a pile-up of work that needs to be reviewed, refined, and approved.” 

A natural outcome from reducing the cost of prototyping, said Cicman, is the emergence of a new operating model for teams. 

“Historically, designers spent a significant amount of time creating initial concepts from scratch. Increasingly, AI can generate those first drafts,” he said. As a result, a designer’s role “shifts toward refinement, curation, editing, and applying taste.

“In that model, the marketer contributes the concept, AI produces the prototypes, and the designer elevates the work from ‘technically generated’ to ‘creatively excellent,’” he said. “The organizations that benefit most won’t be the ones that generate the most content. They’ll be the ones that combine abundant AI-generated prototypes with strong human judgment and creative taste.”

Kategorie: Hacking & Security

Z obýváku pod hladinu. Novinky značky Roborock uklidí doma, na zahradě a nově i v bazénu

Živě.cz - 3 Září, 2026 - 13:30
Na veletrhu IFA 2026 Roborock představuje nové modely důvěrně známých robotických vysavačů Saros, ale i novinky v podobě čističe bazénů nebo chytré sekačky.
Kategorie: IT News

Hexpair Vim plugin: ne až tak základní HEX editor – kdykoliv kdekoliv

AbcLinuxu [zprávičky] - 3 Září, 2026 - 13:23
Hexpair není nejlepší HEX editor na světě a ani se o to nesnaží. Zato je k dispozici kdykoliv a kdekoliv – všude tam, kde máte svůj Vim. Vznikl jako hobby projekt před pár měsíci a dospěl do stavu, kdy by mohl být užitečný širší komunitě. Přepnout do HEX režimu se dá i uprostřed rozdělané práce: Soubor, který už máte otevřený běžným vim file.md, jedním příkazem přepnete do HEX editoru a dalším příkazem ho můžete vrátit zpět do textu. Kurzor přitom zůstane stát na stejném místě v souboru. Úpravy (byť neuložené) v jednom režimu jsou po přepnutí ihned viditelné v tom druhém. Pokud předem víte, že potřebujete pracovat v HEX režimu, pomocí vimhex file.bin otevřete přímo HEX editor. A je úplně jedno, jestli pracujete s 8 KiB nebo 8 TiB souborem. Hexpair nenačítá do paměti celý soubor najednou, ale pracuje po stránkách (128 KiB ve výchozí konfiguraci). Pro libovolně velký soubor máte k dispozici plnou funkcionalitu Hexpair – na Linuxu, macOS, BSD a Windows ve WSL i nativně. Hexpair je Vim plugin implementovaný v čistém VimScriptu, bez externích závislostí krom utility xxd, která je ale standardní součástí instalace Vimu (a na Windows se navíc využívá PowerShell). Na cílovém počítači nepotřebujete administrátorská práva, stačí curl -LO 'https://github.com/.../vX.Y.Z/hexpair.vX.Y.Z.tar'; tar xvf hexpair.vX.Y.Z.tar -C ~/.vim/pack/plugins/start/ a ve svém Vimu máte HEX editor mocnější, než by se mohlo na první pohled zdát. Zvýraznění kurzoru a výběru je synchronizované mezi HEX editorem i ASCII náhledem. Plná editace – ne jen změna hodnoty existujících bajtů, ale i mazání a přidávání do libovolného místa souboru libovolné velikosti. Zvýraznění změn – změněné, ale dosud neuložené bajty jsou v editoru zvýrazněny. Vyhledávání v celém souboru – textem nebo HEX řetězcem, včetně podpory ? jako zástupného znaku pro libovolnou HEX číslici. Vyhledávání a nahrazování. Vložení bajtů dle zadaného řetězce a cílového kódování – zadám Škola, vloží se c5 a0 6b 6f 6c 61, UTF-8 je výchozí kódování; zadám ++enc=cp1250 Škola, vloží se 8a 6b 6f 6c 61. HEX diff režim, který zvýrazní rozdíly proti jinému souboru, včetně možnosti zobrazení obsahu vybraných bajtů proti porovnávanému souboru, přímých skoků mezi změnami, synchronizovaného dvoupanelového zobrazení pomocí vimhexdiff apod. Datový inspektor – co bajty pod kurzorem znamenají jako čísla (8 až 64 bitů, se znaménkem i bez, obě endianity, IEEE 754) či jako UTF sekvence, včetně textového popisu znaků. Rychlé skoky na libovolnou část souboru po stránkách či ofsetech, absolutně či relativně, včetně systému pro pojmenované značky. Skoky po neuložených změnách, vyhledávaných řetězcích, rozdílech v diff režimu. Na Windows volitelná integrace gvimhex a gvimhexdiff příkazů do kontextového menu pod pravým myšítkem v Průzkumníku souborů. Hexpair je open source Vim plugin dostupný na GitHubu, demo zde. Reprodukovatelná a digitálně podepsaná vydání jsou k přímému použití k dispozici v sekci releases. Hexpair se instaluje defenzivně – sám od sebe neprovádí žádná mapování příkazů na klávesy, *vimhex* shell funkce nejsou definovány, nic se nepřidává do $PATH. Vše máte ale snadno k dispozici, pokud chcete: echo 'runtime pack/*/start/hexpair/hexpair.vimrc' >> ~/.vimrc echo 'source ~/.vim/pack/plugins/start/hexpair/hexpair.bashrc' >> ~/.bashrc
Kategorie: GNU/Linux & BSD

Plex warns users to patch security vulnerabilities immediately

Bleeping Computer - 3 Září, 2026 - 13:02
Plex urged users this week to update their desktop clients and media servers immediately to patch multiple security vulnerabilities. [...]
Kategorie: Hacking & Security

Recenze hry Star Wars: Zero Company. Nejkrásnější dárek pro všechny milovníky Klonových válek

Živě.cz - 3 Září, 2026 - 12:45
V naší galaxii se bez většího povyku vynořil nejkrásnější dárek pro všechny milovníky Klonových válek, taktických strategií, ale i poctivého příběhu. Zero Company aspiruje na nejlepší Star Wars hru na trhu.
Kategorie: IT News

Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks

The Hacker News - 3 Září, 2026 - 12:43
Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads. According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026. "The technique's appeal is that node.exe (the
Kategorie: Hacking & Security

Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks

The Hacker News - 3 Září, 2026 - 12:43
Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads. According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026. "The technique's appeal is that node.exe (the Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means

The Hacker News - 3 Září, 2026 - 12:36
In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations across developer environments, Continuous Integration/Continuous Deployment (CI/CD) tooling, cloud configurations, and even AI tool configs. Earlier variants of the infostealer worm only checked 189 paths. The jump says a lot. Attackers have
Kategorie: Hacking & Security

Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means

The Hacker News - 3 Září, 2026 - 12:36
In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations across developer environments, Continuous Integration/Continuous Deployment (CI/CD) tooling, cloud configurations, and even AI tool configs. Earlier variants of the infostealer worm only checked 189 paths. The jump says a lot. Attackers have [email protected]
Kategorie: Hacking & Security

Nová robotická sekačka Segway Navimow H5 Pro umí vysunout disk a sekat až úplně k okraji trávníku

Živě.cz - 3 Září, 2026 - 11:45
Když se zeptáte majitelů robotických sekaček, co je trápí nejvíce, bude to jistě sekání u okrajů. Sekačky dnes už v pohodě zvládají sekat větší plochy, ale s okraji mají stále problém. Některé zvládnou přejet hranice pro sekání, ale to nevyřeší sekání u stěn. Jiné nabídnou doplňkový dožínací ...
Kategorie: IT News

Xiaomi předběhlo Apple s vlastním „skládacím iPhonem“. Xiaomi 18 Fold běží na procesoru vlastní výroby

Živě.cz - 3 Září, 2026 - 11:15
Závody o široké skládací telefony začínají • Xiaomi se svým telefonem předběhne Apple o dva dny • V Berlíně jsme mohli červenou novinku vidět alespoň za sklem
Kategorie: IT News

UK's Online Safety Act has made 'absolutely no difference,' kids say

The Register - Anti-Virus - 3 Září, 2026 - 11:14
Children have told England's Children's Commissioner, Dame Rachel de Souza, that the UK's Online Safety Act (OSA) "has made absolutely no difference" to their ability to access harmful content online. More than a year after the OSA's key child protection duties took effect, de Souza told MPs and peers that young people had little understanding of the legislation or how it was intended to change their online experiences. De Souza made the comments during the opening evidence session of the House of Lords Communications and Digital Committee's inquiry into the OSA's implementation and impact. Central to de Souza's criticism was the legislation's focus on moderating harmful content rather than addressing potentially harmful platform design features. UK politicians had pushed for controls covering such features, either through the OSA or separate legislation, but none has materialized. De Souza said she was "really cross" that there was no hard evidence showing the OSA had meaningfully changed how social media platforms operate. She contrasted that with the US, where legal pressure recently pushed Meta toward significant child safety concessions. Concerns about addictive platform design are not new, but they have returned to prominence following Meta's proposed $18 billion settlement in a US child safety case. Without admitting wrongdoing, Zuckercorp would under the proposed settlement introduce two-hour daily limits for users under 18 on Facebook and Instagram, prompts intended to discourage endless scrolling, and measures addressing use during school hours and at night. The proposal would also let children opt out of algorithmically ranked feeds, directly addressing concerns raised by de Souza and other UK lawmakers. Discussing the proposed Meta settlement, de Souza said the OSA had "not been flexible enough" and had not "kept up with the time." She argued that Ofcom and lawmakers should seek results comparable to those achieved through the US legal system, even if that required the legislation to evolve. 'Furious' with Ofcom De Souza said she planned to exercise her statutory powers to compel Ofcom, the OSA's regulator, to provide copies of the safety risk assessments submitted by technology companies. The commissioner said Ofcom had refused to share the assessments with her, despite her position as "the most senior safeguarding person in this country for children," and had indicated that it would resist disclosure even if she invoked those powers. "One thing I did want to ask this committee was for your assistance in this matter, because I am planning to use my powers," De Souza said. "If we cannot even see the risk assessments that may well have put these [safety] mechanisms into place, or may not have, how on earth can we judge the efficacy of it? "So I'll leave that one with you, but I'm pretty furious about that." The obstacle is section 393(1) of the Communications Act 2003, which restricts Ofcom's disclosure of information obtained through its regulatory functions. Ofcom may disclose such information if the business concerned consents or if one of the statutory gateways in section 393(2) applies. Asked whether compelling tech companies to complete risk assessments was enough to ensure meaningful change or whether further legislation was needed, the Children's Commissioner said "we need a few things," including for Ofcom to "use its teeth." Ofcom has materially upped its presence in the tech regulation landscape during the past year, stepping in on multiple occasions when needed. Perhaps most notably this was at the height of the Grok nudifying furore, but also its sprawling list of investigations into pornography companies allegedly violating age verification requirements. De Souza acknowledged all of this, and the fact that since the introduction of the latest US administration, UK politicians have not given the regulator the "air cover" needed to relentlessly pursue offenders. Nevertheless, she said Ofcom had failed to bare its teeth as forcefully as the current technology landscape demanded and accused it of reacting to harms rather than anticipating them. "If Ofcom is going to be the vehicle to protect our children… we need them to be getting ahead of the harms. And I don't think they have. "So when I talk around the country to children, what's worrying them are things around AI, things around the nudifying apps… there are new harms, and we need Ofcom to be getting ahead of those. I don't think they are." De Souza called on UK politicians "to be really strong and direct" in empowering Ofcom to pursue offending organizations. "But how effective do I think they've been? Not effective enough." The commissioner also criticized Ofcom's child safety codes under the OSA, which she said read more like technical documents for technology companies than protections designed for children. She also called on Ofcom to "use all their powers," impose "some big fines," and act before new harms become entrenched. The Register asked Ofcom to respond. A spokesperson said: "We work closely with the Children's Commissioner and share her objectives to ensure children are safe online. "In December, we published our analysis of risk assessments from the first year of the Online Safety Act being in force, and the improvements we expected to see from platforms. "Our action has resulted in material improvements being made to risk assessments, ensuring that tech companies must implement all measures necessary to address the risks identified on their sites and apps. "We are subject to laws that mean we're restricted in what information we can disclose relating to businesses." ®
Kategorie: Viry a Červi

Microsoft Teams, Outlook fail to launch on ARM-based Windows PCs

Bleeping Computer - 3 Září, 2026 - 10:55
Microsoft is working to fix a known issue that causes crashes and launch failures for Microsoft Teams and New Outlook users after installing updates released since the August 2026 Patch Tuesday. [...]
Kategorie: Hacking & Security

Gemini dostává dvě užitečné novinky. Nastaví za vás telefon a přeloží rozhovor s cizincem

Živě.cz - 3 Září, 2026 - 10:45
Google neustále vylepšuje mobilní Gemini • Pokud potřebujete něco nastavit, asistent to udělá za vás • Bonusem jsou i překlady v režimu Gemini Live v reálném čase
Kategorie: IT News

Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone

The Hacker News - 3 Září, 2026 - 10:43
The iPhone belonging to a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware, according to new findings from the Citizen Lab in collaboration with the SHARE Foundation. "Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group's Pegasus spyware," the Citizen Lab said. "We found high-confidence indicators of
Kategorie: Hacking & Security
Syndikovat obsah