Agregátor RSS
Po šestiletém úsilí byla z jádra Linux odstraněna funkce strncpy(). Všechna předchozí volání této funkce byla převedena na bezpečnější alternativy.
Ve vojenské operaci Epic Fury v Íránu nasadila americká armáda model umělé inteligence. Konkrétně jde o upravenou verzi AI Grok, provozovanou firmou Elona Muska.
Byla vydána nová verze 261 správce systému a služeb systemd (Wikipedie, GitHub). Z novinek lze vypíchnout nový subsystém IMDS (Cloud "Instance Metadata Service"), nový příkaz storagectl nebo novou komponentu systemd-sysinstall.
A new ransomware operation named 'Prinz Eugen' prioritizes recently modified files for encryption and leaves no ransom note on the system. [...]
Ventilátor otočený ven z okna v místnosti vytváří účinný podtlak • Ten nasává chladnější vzduch dovnitř druhým otevřeným oknem • Větší vzdálenost ventilátoru od okna a Bernoulliho princip zvyšují celkovou účinnost
Humans tend to be “a little bit precious about humans,” according to Eric Brandwine, distinguished engineer and VP at Amazon Security. We like to think we are all very good at our jobs, and we have high opinions of ourselves, he explained during a phone interview with The Register. “But when you actually get down to it, humans are not terribly consistent,” Brandwine said. Humans, like AI agents and systems, are non-deterministic. Neither can be guaranteed to produce the same output given the same input twice. Both will make mistakes and even make stuff up. However, we’ve got millennia of experience dealing with humans and less than a decade with more modern LLMs and the AI systems built on top of them. “We know how humans fail,” Brandwine said. “We're comfortable with it. So human-in-the-loop isn’t necessarily the gold standard.” For years, vendors have told companies that the solution for dealing with any automated system was to put a human in the loop. That battle cry became much louder with the advent of modern AI systems and reached a fever pitch when enterprises started deploying agents into their IT environments. More recently, however, big tech is changing the way it talks about agentic governance and rethinking the whole human-in-the-loop concept. Normalization of deviance In 2017, Brandwine gave a talk on the normalization of deviance at AWS’ annual re:Invent conference. It’s a gradual process that happens when people in an organization take shortcuts, or don’t follow the established procedures or standards, and sometimes it occurs over years. As long as nothing catastrophic happens, this deviant behavior becomes the norm. “It’s a thing all humans fall prey to, and one of the most heartbreaking stories I read in this area was about emergency departments and emergency rooms,” Brandwine said during a phone interview with The Register. “You’ve got all these machines, and they’re all beeping. Your first day on the job, you jump every single time one of the alarms beeps – but the patient is fine. It's a spurious alarm. You go back to your station, you sit down, and over time, after enough of these false alarms, enough of these repeated beeps with no actual consequence, your discipline slips, and you stop responding. And eventually some tragic outcome occurs.” This, he admits, is a very high-stakes example. And yet it’s a documented occurrence among healthcare workers, firefighters, and even Army pilots. “Literally, someone’s life is on the line, and people still struggle to maintain discipline,” Brandwine said. “That’s the human condition.” Here’s how this all applies to agentic AI governance and security. Humans build LLMs and AI systems, and having a “human-in-the-loop” ensures that a person reviews the AI’s output and approves (or not) any actions before the AI performs them. “If you put a human inside of this tight loop, and ask them to make approval decisions for agentic tools repeatedly, time after time, they'll do a good job,” Brandwine said. “And then they'll do an okay job. And pretty quickly they'll be doing a poor job.” This is why at Amazon, “we’re not huge fans of human-in-the-loop,” he added. “It's something that you should use judiciously, where you absolutely need it. But it’s not something that you can do at high velocity. You will not get the results that you want to get.” Big tech pulls the human-in-the-loop Amazon isn’t the first or only tech giant to start talking differently about the role humans should play in agentic governance. "It is very clear that we have moved from a human-led defense strategy, to a human-in-the-loop defense strategy, to an AI-led defense strategy that's overseen by humans," Google Cloud chief operating officer Francis deSouza told reporters during a press conference ahead of Google's annual Cloud Next shindig in April. "Our model for the future is an agentic fleet that does a lot of the routine cyber security work at a machine pace and then is overseen by humans." Microsoft CEO Satya Nadella, in an X missive earlier this week, argued for “loop learning,” instead of having a human check an AI’s output at every step. “Companies need to turn their workflows, domain knowledge, and accumulated judgment into AI systems that improve with each use,” Nadella wrote. “Private evals should capture whether a model is actually improving against outcomes that matter to the business (not just external benchmarks!). Private reinforcement learning environments should let models grow stronger on real traces from inside the organization.” Also this week, IBM execs called for human accountability – not humans in the loop – at all stages of AI development, deployment, and governance. Amazon’s alternative to human-in-the-loop is "accountability end to end," according to Brandwine. This means human identity and ownership track through the entire workflow, even when humans aren't directly approving every step. “If I sit down at my keyboard and I type a command that takes a service down, I caused an outage,” Brandwine explained. “If I run a script that takes a service down, it's still me that caused the outage. If my agent writes a script that they then run, and it causes an outage, that's still my responsibility.” (Secret) keys to the kingdom This also highlights the importance of managing and securing agentic identities – the accounts, tokens, and credentials assigned to AI agents so they can access corporate apps and data. At Amazon, all of the agents have independent identities assigned to them, we’re told. “So, as we track agentic activity across our systems, it does not show up in the logs as: ‘Eric did this.’ It shows up as: ‘this agent did this on behalf of Eric,’” Brandwine said, adding that this isn’t to “make people afraid to use this technology.” “It’s to make people pause and think: is this the right way to use this technology? Is this how I should be deploying this?” We still have the humans involved, we still have the humans making decisions, but we're trying to play to the strengths of the humans rather than placing them in this unfair, repeated decision making, human-in-the-loop position.” Brandwine told us that Amazon has run into a couple of hurdles when it comes to deploying agents across its businesses, and one of the biggest is what he calls “goal-seeking behavior.” This is when a person asks an agent to do a specific task - for example, upgrade a database – and the agent becomes laser-focused on just one action to achieve this goal, ie, deleting the database. This is separate from prompt injection because there’s no malicious input. “It’s just the agent getting stuck on the wrong action,” Brandwine said. Simply telling the agent, “you don’t have permission to do this,” is likely going to cause the agent to look for a different path to do the same thing (delete the database). Telling the agent why it doesn’t have permission to do something tends to produce a better outcome, according to Brandwine. This means telling the agent it’s not allowed to do that, and the reason why is because it would cause a production impact. And also include “don’t cause a production impact” as part of the prompt. “Giving it that extra feedback has gotten us dramatically better results,” Brandwine said. Of course, this is not a fail-proof method. “You still need to be careful with agents,” Brandwine told us. “We have millennia of experience with humans. Agentic AI is a very, very new field, we don't have an intuition for this, and one of the fundamental differences between agents and humans is that humans fear consequences,” such as losing a job or even going to jail. Agents don’t have these fears. This is where setting permissions on what the agent can and can’t do or access comes in. Much like everything else with AI, it’s nuanced, and it depends on the employee's role in the company, and the company’s tolerance for risk. “The person that wants to run the agent wants to give the agent many permissions because that makes the agent more powerful,” Brandwine said. "It could do more things for them, it can recoup more of their time, it can deliver more.” The security lead, on the other hand, wants to limit an agent’s permissions, and this causes yet more tension between the security and development teams. There is no one right solution or policy answer to solve this, according to Brandwine. Instead, it involves dynamic policies that set permissions based on the agent’s specific task. There are some overarching, static guardrails – such as an agent must never perform destructive actions or delete entire servers – and then there are policies underneath that establish the maximum set of privileges that the agent can have. “Then we’ll have a further scoped-down policy for this action, and there's various techniques for automatically generating policies based on prompt and the end-user's intent,” Brandwine said. Even for Amazon, it’s not always easy. “It's all driven by risk,” he said. “This is a space that's changing quickly, and so we're trying to balance the risk of using untried, untested software against the risk of falling behind and not being able to deliver for our customers. As with all such things, it's complicated.” ®
Microsoft has attributed a recent Mastra AI supply chain attack that compromised more than 140 npm packages to the North Korean hacking group Sapphire Sleet, also known as BlueNoroff. [...]
Artificial Intelligence
A Startup Claims It Broke Through a Bottleneck That’s Holding Back LLMsWill Douglas Heaven | MIT Technology Review ($)
“According to Subquadratic, it has developed a new kind of LLM, called SubQ, that is faster and cheaper and uses a lot less energy than any other model on the market. The company also claims that SubQ is able to process up to 12 times as much text at once than most other models, allowing it to carry out a range of data-heavy tasks, such as analyzing hundreds of documents or entire code bases.”
Robotics
The Next Humanoid Robot Might Not Look Human at AllRobert Hart | The Verge
“The next humanoid robot might not have a head. It might not have legs. It might even sit on a wheeled base and fold down like a deck chair. But, as Genesis AI puts it, ‘humanoid robots don’t need to look human.’ …Genesis says Eno is designed ‘around human capability’ rather than human appearance and is intended as a fully ‘general-purpose’ robot rather than a machine built around a single task, like folding laundry.”
Biotechnology
Chilling the Body With Drugs Could Limit Brain Damage From StrokeAlice Klein | New Scientist ($)
“A combination of two drugs used to treat hay fever and psychosis cooled down the core body temperature of mice and monkeys, reducing brain damage after a stroke. These medications have also undergone preliminary testing in people, and will now be evaluated in a follow-up clinical trial.”
Future
A Court Has Ruled That Google Is Liable for False Statements Generated by AI OverviewsFernanda González | Wired ($)
“The authorities found that, unlike traditional search engines, which merely display lists of links with statements made by third parties, Google’s tool produced ‘independent, new, and substantial statements’ based on a misinterpretation of information available on the internet. …Google is the only entity with the ability to modify the technology underpinning its AI-generated summaries and, therefore, ‘must be held accountable.'”
Artificial Intelligence
Estonia Is Giving AI Agents ‘Personal Identification Codes’Webb Wright | Gizmodo
“Estonia is trying to bring some law and order to the Wild West that is the world of AI agents. The small Baltic nation plans to assign each AI agent a ‘personal identification code,’ hoping to track what agents do across the internet and identify the people or companies behind them.”
Biotechnology
Why the Human Genome’s Tangled Physicality May Confound AIPhilip Ball | Quanta Magazine
“[The AI] approach is likely to be useful, but for those who crave real understanding of how the genome, and ultimately life itself, works, a computational black box will never suffice. And perhaps more to the point, the genome might not submit to the kind of straightforward input-output approach that such AI models ultimately assume. That’s because the genome is no blueprint or algorithm. It is something else.”
Future
The Inevitable Weakness of MetricsBryan Gardiner | MIT Technology Review ($)
“What I think many of us miss—what I know I certainly missed—is that there are always trade-offs when you try to distill something important down to a data point. When we turn to metrics to understand ourselves, our social world, and culture as a whole, they will never come close to capturing what matters. Even worse, they’ll often actively obscure it.”
Future
Just 16% of Americans Believe AI Will Positively Impact Society, Pew Poll FindsMatt Novak | Gizmodo
“Half of adult Americans use AI chatbots, with a quarter using them daily, according to new polling from Pew Research released Wednesday. That’s up from 33% of Americans who used AI chatbots in the summer of 2024. But a small minority, 16%, believe AI will have a positive impact on society.”
Computing
Sooner Than Expected? Useful Quantum Error Correction Promised for 2028.John Timmer | Ars Technica
“‘By 2028, we will bring Libra, a Megaquop-scale device, capable of executing one million quantum operations over hundreds of logical qubits, to our customers, enabling first scientific applications in quantum chemistry, high-energy physics, and materials simulation that are beyond the reach of classical and Noisy Intermediate-Scale Quantum (NISQ) computers today,’ Amazon’s statement said.”
Computing
Brain-Computer Interface Trials Are Taking OffJessica Hamzelou | MIT Technology Review ($)
“Over the past couple of years, the number of BCI trial volunteers has soared. This year, China became the first country to approve a BCI for medical use. Advances in technology are allowing engineers to provide more features than ever. BCI research is properly taking off.”
Robotics
Why Waymo’s Driverless Taxis Won’t Be on Your Streets Anytime SoonDavid McCabe | The New York Times ($)
“Waymo is increasingly facing political roadblocks as it tries to roll out its self-driving taxis powered by artificial intelligence nationwide. After early successes winning over politicians in California—its home state—and elsewhere, Waymo has stumbled in unlocking some of the biggest markets in the country.”
The post This Week’s Awesome Tech Stories From Around the Web (Through June 20) appeared first on SingularityHub.
Amsterdamské letiště nasadilo do ostrého provozu elektrický tahač letadel TaxiBot • Speciální robotické vozidlo snižuje spotřebu paliva, emise oxidu uhličitého i hluk • Piloti ovládají tahač na cestě k ranveji přímo z kokpitu
Oživeno 20. 6. 2026 | Firefox 152 je v porovnání s předchozími vydáními skromný. Nasazuje aspoň redesignované nastavení, které jsme poprvé viděli před pár týdny. Mozilla si tedy pospíšila. Můžeme ho považovat za předvoj nového vizuálního stylu Nova, který si prohlížeč letos osvojí.
Firefox se ...
Vývojové prostředí Qt Creator bylo vydáno ve verzi 20 (seznam změn). Novinky zahrnují hlavně rozšíření pro integraci LLM agentů nebo minimalistický editační režim uživatelského rozhraní („zen mode“).
Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that's installed on about 100,000 sites.
The vulnerability, tracked as CVE-2026-4020 (CVSS score: 5.3), is a medium-severity information disclosure flaw that can allow unauthenticated attackers to extract sensitive data, such as configuration data, API keys, secrets, and OAuth tokens Ravie Lakshmananhttp://www.blogger.com/profile/ [email protected]
Estonsko otestovalo bleskové zastavení vlaků kvůli hrozbám útoků drony • Dispečeři nařídili okamžité zastavení na čtyřech klíčových tratích v zemi • Personál si během celostátního cvičení nanečisto vyzkoušel evakuaci cestujících
Služba Windy loni zvýšila tržby na 405 milionů korun a vydělala přes 72 milionů • . • Firma Iva Lukačoviče má desítky milionů uživatelů měsíčně a vystačí si s 34 zaměstnanci. • Vedle předplatného roste i díky akvizicím, loni převzala švýcarskou meteorologickou firmu Meteoblue.
Nová americká studie vyvrací mýtus o prospěšnosti alkoholu na srdce • Celoživotní riziko úmrtí výrazně stoupá již od sedmi drinků týdně • Nárazová konzumace alkoholu zvyšuje hrozbu infarktu nebo mrtvice
Léto je tu a s ním i chuť něco si dopřát – ať už nové parfémy, lehčí boty na procházky, nebo jen výhodnější tarif, který vám ušetří pár stovek měsíčně. Tenhle týden jsme pro vás proklikali desítky nabídek a vybrali ty, které podle nás opravdu stojí za pozornost.
Market intelligence platform Klue has publicly confirmed a recent security incident that allowed threat actors to steal OAuth tokens used to connect to customers' Salesforce environments, as the new "Icarus" extortion group publicly claims the attack. [...]
Ucelený přehled článků, zpráviček a diskusí za minulých 7 dní.
Číňané budou jezdit ultračernými auty. Barvy pohlcující víc než 99,5 % dopadajícího světla ale dotáhli k dokonalosti jiní borci.
|