Agregátor RSS

How to Secure Enterprise AI: From Adoption to Incident Readiness

The Hacker News - 2 Září, 2026 - 13:30
The debate about whether AI delivers business value is over. The challenge now is implementing it at scale and securely across every function while meeting board-level pressure to move fast. Organizations must focus on adopting AI at business speed without losing control of cyber risk. Download the full eBook here.  The Business Reality  In Sygnia’s 2026 CISO Survey Report, which
Kategorie: Hacking & Security

How to Secure Enterprise AI: From Adoption to Incident Readiness

The Hacker News - 2 Září, 2026 - 13:30
The debate about whether AI delivers business value is over. The challenge now is implementing it at scale and securely across every function while meeting board-level pressure to move fast. Organizations must focus on adopting AI at business speed without losing control of cyber risk. Download the full eBook here.  The Business Reality  In Sygnia’s 2026 CISO Survey Report, which [email protected]
Kategorie: Hacking & Security

BGP hijack infecting networks caused by a comedy of errors that’s not funny at all

Ars Technica - 2 Září, 2026 - 13:00

Hackers carried out a supply chain attack that installed malware on networks using an unusual technique: hijacking a chunk of Internet space where cloud management software used by hosting providers, data centers, and other large infrastructure companies is updated.

In a well-coordinated operation, the unknown attackers exploited weaknesses in the routing security setup of hosting provider Hetzner Online and the process for attaining valid TLS certificates. The lapses allowed the attackers to successfully perform a BGP (Border Gateway Protocol) hijacking to obtain control over IP addresses assigned to Softaculous. The company, based in the United Arab Emirates, is the maker of a platform for installing and managing Web software and is the developer of Virtualizor, a management platform for virtualized environments.

Softaculous used the IPs to issue updates and host a client and billing site. With control over the hijacked space, the attacker was now using the addresses to push malware masquerading as updates to unsuspecting users.

Read full article

Comments

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

The Hacker News - 2 Září, 2026 - 12:53
SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks. The vulnerabilities, discovered internally by SonicWall's William Perry and Adam Babis, are listed below - CVE-2026-83548 (CVSS score: 10.0) -  A pre-authentication SSRF vulnerability in the Appliance
Kategorie: Hacking & Security

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

The Hacker News - 2 Září, 2026 - 12:53
SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks. The vulnerabilities, discovered internally by SonicWall's William Perry and Adam Babis, are listed below - CVE-2026-83548 (CVSS score: 10.0) -  A pre-authentication SSRF vulnerability in the Appliance Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Strážci internetu, hlášení doménových jmen zneužívaných k páchání trestné činnosti

AbcLinuxu [zprávičky] - 2 Září, 2026 - 12:51
Národní bezpečnostní tým CSIRT.CZ koordinovaný sdružením CZ.NIC přichází se službou Strážci internetu, která má sjednotit způsob hlášení doménových jmen zneužívaných k páchání trestné činnosti. Službu mohou uživatelé využívat také prostřednictvím rozšíření do prohlížeče. Nový nástroj podporuje jak hlášení vyžadující autorizaci, tak anonymní reporting, u kterého však nebude možné zapojit takovou míru automatizace jako u neanonymních oznámení. Po posouzení každého hlášení nastartuje bezpečnostní tým standardní proceduru směřující k eliminaci nebezpečných webů.
Kategorie: GNU/Linux & BSD

Microsoft Defender flags legitimate Google search links as malicious

Bleeping Computer - 2 Září, 2026 - 12:29
Microsoft is investigating an issue causing the Defender for Office 365 security software to mistakenly block access to legitimate Google search links. [...]
Kategorie: Hacking & Security

Firefox pro iOS s integrovaným blokováním reklam

AbcLinuxu [zprávičky] - 2 Září, 2026 - 12:29
Firefox pro iOS přichází s integrovaným blokováním reklam. Funkce je ve výchozím nastavení vypnutá a lze ji aktivovat v Settings > Browsing > Ad Blocker.
Kategorie: GNU/Linux & BSD

Švédové ukázali model nadzvukové robotické stíhačky A3. Mohla by se stát předlohou pro nástupce gripenů

Živě.cz - 2 Září, 2026 - 11:51
Švédská zbrojovka Saab se na leteckém dni v Linköpingu pochlubila konceptem bezpilotní nadzvukové stíhačky A3. Ta by jednou mohla jako robotický společník doprovázet gripeny nejnovější řady E. Model draku je v měřítku 1:1 a Saab by chtěl dostat první létající prototyp do vzduchu ještě před rokem ...
Kategorie: IT News

The ultimate Chrome keyboard shortcut upgrade

Computerworld.com [Hacking News] - 2 Září, 2026 - 11:45

When it comes to productivity these days, we’re got two competing concepts to consider:

  1. Automate everything with AI and let an unreliable, error-prone bot do work on your behalf (thus likely spending even more time reviewing — and correcting — its mistakes)
  2. Find intelligent systems for increasing your own efficiency while maintaining complete control over what you’re doing

The first path clearly gets the most attention as of late. (And, to be fair, there are ways that AI can genuinely be useful, especially when it’s used as a tool for specific limited purposes as opposed to an omnipresent answer for everything.) But arming yourself with good old-fashioned efficiency-enhancers is an increasingly underrated and overlooked option for giving yourself a powerful productivity advantage — in a way that actually makes a difference, without any awkward compromises.

That’s particularly true in the domain of the desktop browser, where so many of us do so much of our work in 2026. The browser in many ways has become our de facto workday operating system — no matter what kind of computer we’re using at any given moment — and yet, it’s nowhere near the level of an actual operating system when it comes to the shortcuts and work management tools it offers.

At this point, the company behind the world’s most widely used browser is seemingly more interested in finding new places to cram Gemini into our lives than developing genuinely useful systems for more efficient browser work. But a third-party developer we’ve talked about before in these quarters is stepping up to fill that void and give Chrome the keyboard-centric kick-in-the-keister it needs to become an optimal productivity backdrop — with our own fleshly fingers guiding the way.

It’s a brand new browser extension that’ll work in any Chromium-based browser and completely change how you think about getting around your tabs and getting stuff accomplished. I’ve had the opportunity to test it out and live with it for several weeks now. Let me show you how it works and what it could do for you.

[Get level-headed knowledge in your inbox with my free Android Intelligence newsletter. One smart new thing to try every Friday!]

Meet your new Chrome command center

My fellow keyboard warrior, allow me to introduce you to a little something called Tab-da.

Tab-da is an extension for Chrome — or, again, any other browser based on the same underlying code, including Vivaldi, Edge, Brave, and Opera — that adds all sorts of keyboard-oriented productivity-minded power-ups into your browser environment.

There’s so much to it, in fact, that the biggest challenge is wrapping your head around all of the possibilities it presents and developing the muscle memory to get yourself in the habit of using actually ’em.

The best way to get going is to start small — with a focus on a few core Tab-da features:

1. The tab switcher

Tab-da’s centerpiece, so to speak, is the simple yet robust OS-like tab switcher it adds into the browser arena. Just like you how you hit Alt-Tab to move among programs in Windows, you hit Ctrl, Shift, and the left or right arrow key with Tab-da in your browser — and, well, ta-da:

Tab-da’s on-demand tab switcher in action — a faster, easier way to get where you want to go in your browser.

JR Raphael, Foundry

You can zip between all of your open browser tabs as if they were apps or processes on your computer — ’cause for all intents and purposes when working these days, they really are. And now, at long last, they can act like it.

2. The tab command bar

Perhaps the most powerful part of Tab-da is the all-purpose launcher it adds into your browser for almost any action imaginable. No matter what else you’re doing at any given moment, with Tab-da installed, you can hit Ctrl, Shift, and the spacebar together to summon a command bar that’s reminiscent of the Ctrl-K (or ⌘-K) option in many desktop apps and just overflowing with productivity potential.

Tab-da’s command bar is the keyboard shortcut command center Chrome’s been missing.

JR Raphael, Foundry

From the prompt, you can start typing the name of any website or web app you’ve got open to find and jump to it quickly — or just use the on-screen numbers to move instantly to any site you see. You can also tap into a handful of handy keyboard shortcuts to zoom in specifically to other browser-based areas:

  • Alt-O will pivot the command bar to showing and letting you search through tabs open within the same browser on other devices, like your phone.
  • Alt-B will allow you to browse or search through your saved bookmarks.
  • Alt-H will take you to your cross-device browsing history.
  • Alt-C shows you recently closed tabs.
  • Alt-D empowers you to see and search through your downloads.
  • And Alt-T opens an action-packed actions menu where you can move a tab, pin it, duplicate it, copy its URL, or share it all right then and there — all without ever lifting your fingers off your keyboard.
Actions in the command bar are a convenient way to do more than just moving between tabs.

JR Raphael, Foundry

And those are just the default built-in shortcuts.

3. Custom keyboard shortcuts

The part of Tab-da I might appreciate the most is the framework it gives you for creating your own custom keyboard shortcuts for browser-based actions both simple and complex.

Within that same command bar we were just going over, you can set up quick keyboard shortcuts for any sites you find yourself opening often — then get to them simply by hitting Ctrl-Alt-space and entering whatever shortcut you assign them.

Any sites or combination of sites can be kept a couple quick keystrokes away with Tab-da’s custom shortcuts system.

JR Raphael, Foundry

What’s especially cool is that you can also set up multiple sites to open together in this same way — if, for instance, your workflow involves opening a specific series of four sites together (say, Google Docs, WordPress, Trello, and Notion) to work on one particular task. Then you can always get to that work mode with a few quick keystrokes and no manual tab-by-tab opening.

Your Chrome keyboard control adventure

Tab-da has tons of other time-savers that you’ll keep discovering the longer you use it, but those three areas are the perfect place to start — and the perfect way to understand what the extension is ultimately all about and how it aims to help you.

Oh, and as for the developer? As I alluded to at the start of this story, he’s someone you may know if you’ve followed my suggestions around Android for long. His name is Bardi Golriz, and he’s the same guy behind both the Ruff Reminders app I recommended earlier this year and the Ruff Writing widget I’ve written about before.

Like Golriz’s other apps, Tab-da doesn’t contain any kind of tracking or other disconcerting privacy asterisks. All of your browsing data remains entirely on your device, with no syncing, storage, or sharing of any sort.

The extension is free for an unlimited seven-day trial — with no payment details or personal info required. After that, if you want to keep using it, it’ll run you a whopping 99 cents a month or 20 bucks for a lifetime license, which is a small price to pay for all the seconds it saves you (and, of course, a price that lets independent developers like Golriz continue doing the work they do).

Just remember: Start small. Let yourself get in the habit of using one feature and one keyboard shortcut at a time, then add one more into the mix from there as each element slowly becomes second nature.

Before long, you’ll barely remember what working in a browser was like without a tool like this in the picture — and you almost certainly won’t want to go back.

Discover oodles of useful tech tricks with my free Android Intelligence newsletter — one new thing to try every Friday, straight from me to ye.

Kategorie: Hacking & Security

UK cyber bill targets AI users, not the vendors building it

The Register - Anti-Virus - 2 Září, 2026 - 11:44
The UK government has rejected proposals from members of the the House of Lords to bring AI vendors within the scope of the Cyber Security and Resilience (Network and Information Systems) Bill. Cybersecurity minister Baroness Lloyd of Effra argued that regulating AI vendors and frontier model developers through the bill would not prevent hostile actors from misusing their products. Addressing the Grand Committee on Tuesday, she said: "Bringing providers of AI services, those companies which are at the cutting edge of frontier AI development and their products, into the scope… would not address the harms that can be posed by some AI products and services, or specifically, it would not prevent their misuse by hostile actors." The minister said the UK was instead taking "firm action" to secure AI through other channels. These include supporting the AI Security Institute (AISI), which works with vendors to test the security of models before their release. Lloyd also pointed to the voluntary AI Cyber Security Code of Practice, which informed the first global AI cybersecurity standard, ETSI EN 304 223. "This demonstrates our global leadership and commitment to shaping international technical standards which go wider than some of the issues raised in this bill," she claimed. Members of the House of Lords - the upper house in UK parliament - offered numerous arguments for bringing AI within the bill's scope. They cited reports of rogue agentic behavior involving Anthropic and OpenAI, as well as Bill Gates' concerns that commercial incentives are pushing AI development forward without adequate safeguards. Lawmakers also questioned whether companies unable to prevent their agents from misbehaving should be trusted to follow voluntary ethical guidelines that they can rewrite at will. "Have we not learned from countless experiences before in online safety, privacy, and in AI itself that allowing tech companies to set and mark their own homework endangers the public and our national security?" asked Baroness Kidron, a Crossbench peer and campaigner for online safety and digital rights. Similarly, Lord Tarassenko, a Crossbench peer and veteran AI researcher, pointed to the recent open letter penned by OpenAI warning that there will soon come a time when AI-orchestrated cyberattacks will become too prevalent to handle. Although the letter was criticized for employing alarmist language while carrying the signatures of companies that profit from AI, peers argued that its warning strengthened the case for regulatory intervention. Kidron and Lloyd also clashed after the minister used a hypothetical healthcare organization to illustrate how the bill would require regulated bodies to secure systems containing AI. Kidron asked: "If I might ask the noble Lady, the Minister, if I've understood what she said, the NHS must protect itself, but the AI that is attacking it has no requirement under the Bill, no duties, no obligations under the Bill to check itself before it's used in these ways." Lloyd said the bill was designed to be technology-agnostic and to impose stricter cybersecurity requirements on key organizations, rather than regulate individual technology providers. She nevertheless said the government was willing to continue discussing AI after Kidron predicted that the issue would return during later stages of the bill's passage. The minister rejected several other amendments, including one that would require certain AI vendors to demonstrate that their products could not cross specified red lines, such as evading human oversight or assisting with the development of chemical weapons. She also dismissed a proposal that would give the Secretary of State last-resort powers to order the shutdown of a datacenter or widely deployed AI system during a security or operational emergency. Lloyd said the bill would instead allow the government to direct regulated entities, including datacenter operators but not AI vendors, to take or cease specified actions when their systems presented a qualifying risk. A power station could, for example, be instructed to stop using a particular AI model. "We believe this is a more proportionate and effective response, as datacenters operate in highly complex ecosystems and AI systems are often distributed across different datacenters and jurisdictions," said Baroness Lloyd. "It's much less desirable to direct multiple datacenters to shut down, and the impact this could have on services that rely on them, than to direct them to cease using an AI model." Despite rejecting the amendments, Lloyd said the government remained willing to discuss AI regulation because of the technology's economic significance. The Grand Committee is scheduled to resume discussions of the CSR Bill when it reconvenes on Thursday. The bill's background The CSR Bill was first proposed in the 2024 King's Speech and introduced in Parliament in November 2025. It attracted attention over the £100,000 daily fines initially proposed for in-scope organizations that failed to protect against specific threats. The legislation builds on the existing categories of operators of essential services and relevant digital service providers while extending the regime to organizations including managed service providers, datacenter operators, and designated critical suppliers. Managed service providers were previously due to be brought within scope through the abandoned 2022 update to the NIS regulations. The broad intention of the bill is to update the NIS 2018 regulations and future-proof the UK's critical infrastructure from cyber threats. However, this week's Grand Committee scrutiny is not the first time the bill has been criticized. In January, shadow deputy PM Sir Oliver Dowden called on the government to rethink its exclusion of local and central government from the CSR bill. The UK's Government Cyber Action Plan, launched hours before the former digital secretary's remarks, promised to hold government to the same standards proposed in the CSR Bill. Like the AI Cyber Security Code of Practice, the action plan lacks any legal obligations. ®
Kategorie: Viry a Červi

Open-source robot Microduck

AbcLinuxu [zprávičky] - 2 Září, 2026 - 11:27
Společnost Hugging Face ve spolupráci se společností Pollen Robotics představila (𝕏) open-source robota Microduck. Předobjednat jej lze za 340 eur.
Kategorie: GNU/Linux & BSD

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

The Hacker News - 2 Září, 2026 - 11:18
Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals. The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, and published the vulnerability details on August 31. GeoNetwork originated at the United Nations Food and
Kategorie: Hacking & Security

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

The Hacker News - 2 Září, 2026 - 11:18
Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals. The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, and published the vulnerability details on August 31. GeoNetwork originated at the United Nations Food and Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands

The Hacker News - 2 Září, 2026 - 11:10
The U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malware-laced Excel attachments to about 80,000 of its users in 2016 and 2017. Searzhudin Tamirlanovich Aktulaev, 40, was arrested in Cyprus in May 2025, the U.S. Attorney's Office for the Northern District of California
Kategorie: Hacking & Security

Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands

The Hacker News - 2 Září, 2026 - 11:10
The U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malware-laced Excel attachments to about 80,000 of its users in 2016 and 2017. Searzhudin Tamirlanovich Aktulaev, 40, was arrested in Cyprus in May 2025, the U.S. Attorney's Office for the Northern District of CaliforniaSwati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

US charges Russian for infecting 80,000 freelancers with malware

Bleeping Computer - 2 Září, 2026 - 11:06
A California federal grand jury has indicted a Russian national for his role in a phishing campaign that infected thousands of freelancers with TVRAT and DarkVNC malware. [...]
Kategorie: Hacking & Security

OpenClaw 2.0

AbcLinuxu [zprávičky] - 2 Září, 2026 - 10:59
Open-source autonomní AI agent OpenClaw (Wikipedie) byl vydán ve verzi 2026.8.1 aneb 2.0. Přehled novinek v poznámkách k vydání.
Kategorie: GNU/Linux & BSD
Syndikovat obsah