Agregátor RSS

Microsoft unveils AI security tools it says outperform competing platforms

Ars Technica - 27 Červenec, 2026 - 23:56

Microsoft is introducing new AI tools designed to help customers continuously streamline and automate the process of identifying and reducing their exposure to security risks.

The new tools come less than a week after OpenAI lost control of two of its security models when they infiltrated the servers of startup Hugging Face. The hack, Hugging Face added, involved “a swarm of tens of thousands of automated actions” that stole internal Hugging Face credentials. The OpenAI models achieved this feat by exploiting a zero-day flaw in Hugging Face’s data-processing pipeline to run malicious code that escalated the models’ access to the company’s high-value cloud and server clusters.

Microsoft’s announcements on Monday made no reference to the event, which OpenAI said was “unprecedented.” The company also didn’t say what would prevent the new tools from similarly going rogue.

Read full article

Comments

Open Secure AI Alliance

AbcLinuxu [zprávičky] - 27 Červenec, 2026 - 23:51
Přední technologické společnosti (Adobe, Cadence, Capital One, Cisco, Cloudera, Cloudflare, Cognition, CrowdStrike, Databricks, Dell Technologies, DoorDash, Elastic, HPE, Hugging Face, IBM, LangChain, Linux Foundation, Microsoft, NAVER, NetApp, Nous Research, NVIDIA, OpenClaw, Palantir, Palo Alto Networks, Red Hat, Reflection AI, Salesforce, SAP, ServiceNow, Siemens, SK Telecom, Snowflake, SpacexAI, Synopsys, Thinking Machines Lab a TrendAI) zakládají alianci Open Secure AI Alliance s cílem budovat a sdílet otevřené nástroje, které podporují zodpovědné používání umělé inteligence a důvěru v ni.
Kategorie: GNU/Linux & BSD

ČSOB mění podmínky. Přidá okamžité SEPA platby, upraví Kate Coiny a služby pro děti

Lupa.cz - články - 27 Červenec, 2026 - 23:15
ČSOB od 1. listopadu 2026 změní obchodní podmínky a sazebník. Novinky se týkají okamžitých plateb v eurech, Kate Coinů, dětských účtů i ČSOB Identity. Přehled všech změn.
Kategorie: IT News

New Dysphoria DDoS botnet spreads to 200k devices worldwide

Bleeping Computer - 27 Červenec, 2026 - 23:08
A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations. [...]
Kategorie: Hacking & Security

New Certighost PoC exploit lets attackers hijack Windows domains

Bleeping Computer - 27 Červenec, 2026 - 23:00
A proof-of-concept exploit for "Certighost," a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain. [...]
Kategorie: Hacking & Security

Weak AI Regulation Could Be Worse Than None at All

Singularity HUB - 27 Červenec, 2026 - 22:58

A Cornell University study uses game theory to model how poorly designed AI regulation could backfire.

Governments around the world are racing to regulate AI before it becomes too deeply embedded in society. But new research suggests poorly designed rules could make AI systems less safe than having no regulation at all.

Regulatory disagreements in the US are leading to a patchwork of approaches as states take matters into their own hands. A key question is who should be responsible for the safety of AI products—the big tech companies building the underlying models or the firms that adapt them for a particular task, such as a customer service chatbot or an AI tutor.

Working this out is trickier than it looks. While it might seem logical to put the bulk of the burden on downstream companies directly serving these tools to customers, a new study in Proceedings of the National Academy of Sciences finds that could be worse than having no rules at all.

“There’s a free-riding behavior that occurs,” Benjamin Laufer from Cornell University, who led the research, said in a press release. “The regulation acts as a tool for the general provider to offload the safety burden onto the downstream specialist.”

The researchers’ analysis relied on a model based on game theory—a mathematical approach to studying decision making. It treated AI development as a two-step game, in which a “generalist” developer first invests in building a broadly capable AI model before a “specialist” adapts it for a specific domain and takes it to market.

In the game, a regulator sets a minimum safety standard for both players, and the models see this in advance. They then invest in both the performance and safety of their product, and the revenue is split between them. Investments in both get progressively higher, while the extra revenue each improvement brings in stays flat.

The problem, the researchers found, is that the generalist moves first and knows exactly what the specialist will be legally required to do afterwards. This creates problems when the generalist is set a low bar for safety, or none at all, and safety standards for the downstream specialist are also fairly weak.

In the absence of any rules, both firms invest in safety, because the model assumes a safer product earns more revenue. But if the specialist is forced to invest a certain amount into safety to meet regularity requirements, the generalist can cut its own spending and let the downstream firm close the gap.

That’s because the generalist’s revenue depends on the final safety level of the shipped product, not on its own contribution, so it can get a revenue boost from improved safety without paying for it from its own pocket. The specialist, for its part, has no reason to do more than the rule demands, so total safety settles at the legal minimum, which is below what would have occurred had there been no regulation at all.

On a more positive note, the researchers found that if safety levels on both the generalist and the specialist are set high enough, regulation can actually improve safety while leaving both companies more profitable than they were in an unregulated market.

“Appropriately designed AI regulation can make it possible for different firms involved in the AI development pipeline to collectively arrive at good outcomes for consumers, knowing that the regulation is designed to help each firm operate in a way that the others can more reasonably predict,” co-author Jon Kleinberg from Cornell University said in the press release.

However, the researchers’ model relies on the market setting a real price on safety. As the gap widens between what customers will pay for performance and what they’ll pay for safety, the range of circumstances in which weak rules backfire gets narrower.

The authors also note that the model’s two-player setup is a simplification of real AI supply chains where multiple competing specialists and base-model providers operate across different jurisdictions with different rules.

“People think of AI as a single object, but actually AI involves a very complicated set of stakeholders and actors that each have their own contributions to the technology,” said Laufer. “To regulate in a thoughtful way, we need to consider the whole supply chain, not just a single provider or entity.”

Still, the results suggest that taking an overly simplistic and light-handed approach to AI regulation may end up achieving the opposite of what law makers intend.

The post Weak AI Regulation Could Be Worse Than None at All appeared first on SingularityHub.

Kategorie: Transhumanismus

Hugging Face CEO wants transparency after OpenAI’s AI incident

Computerworld.com [Hacking News] - 27 Červenec, 2026 - 22:20

Hugging Face CEO Clem Delangue wants to see radical transparency from OpenAI after the company acknowledged that one of its AI agents managed to hack into the AI platform’s systems during a test.

In a post on X, Delangue wrote that, among other things, he wants OpenAI to publish logs and traces from the autonomous AI agent so researchers can analyze what happened. He also called for better defensive tools and urged OpenAI to allocate $100 million worth of computing capacity to help the Hugging Face community develop stronger cybersecurity solutions.

“The first cyberattack by an autonomous AI agent is an unprecedented event. It deserves an unprecedented response,” Delangue wrote.

Kategorie: Hacking & Security

Microsoft's solution to AI security: more AI and more acronyms

The Register - Anti-Virus - 27 Červenec, 2026 - 21:50
AI agents can break through security, but they are also the solution to defending against an increasingly dangerous ecosystem of threats. On Monday, Microsoft announced a new security model that it says helped outperform several rival AI systems on a vulnerability benchmark while cutting costs by about half. Unsurprisingly, at Redmond’s security event on Monday, execs touted the tech giant’s AI security prowess and introduced a new agentic security system called Project Perception, and also unveiled its first security-specialized model, MAI-Cyber-1-Flash, designed for software vulnerability analysis. Microsoft packed MAI-Cyber-1-Flash, based on Microsoft AI (MAI)’s internally developed MAI-Thinking-1 reasoning model, inside its MDASH bug-hunting harness. Its execs claim the duo - with a GPT-5.4 boost - outperforms Anthropic’s bug-hunting machine Mythos and OpenAI’s powerful standalone models, and costs about half the price of other leading commercial models. CyberGym’s benchmarking found that MAI-Cyber-1-Flash, combined with GPT-5.4, both stuffed inside the MDASH harness, achieved a 95.95 percent success rate. For comparison, OpenAI’s GPT-5.5 Cyber scored 85.6 percent and its GPT-5.6 Sol scored 83.6 percent, while Anthropic’s Mythos 5 successfully handled real-world vulnerabilities 83.8 percent of the time. Google’s Gemini 3.5 Flash Cyber in CodeMender achieved an 83.2 percent success rate. “This is really quite a remarkable result,” Mustafa Suleyman, CEO of Microsoft AI, said during the Monday event. Within MDASH, MAI-Cyber-1-Flash handles up to 90 percent of all queries, detecting and patching the vulnerabilities while also confirming the fixes worked, and hands the remaining 10 percent of tasks off to the larger GPT-5.4, Suleyman explained. “GPT 5.4, which is obviously a larger model, about 10X larger, solves those [queries],” he said. “As the models hand off between each other, they are not just able to deliver better performance than all of the other models combined, they do so at 50 percent of the cost.” In addition to the multi-model bug hunting system, Microsoft announced Project Perception, which coordinates three types of agents: red team agents that find and simulate attack paths, blue team agents that investigate and determine risk, and green team agents that remediate the issues. “We need to make sure that the defenders can defend at the scale and the speed of the attackers,” Hayete Gallot, executive vice president of Microsoft Security, said. “You need a new cyber stack. So we built it. This is what we call Perception.” Aside from the new security products, Redmond introduced a new AI security research arm called Microsoft Security FORGE (Frontier Offensive Research and Generative Exploration) Labs, led by Microsoft VP of Security Research Taesoo Kim, and an AI red team alliance. The latter, called the External Red Team Alliance (EXTRA), aims to expand AI safety research through a two-part initiative. First, Redmond’s own AI red team provided "unrestricted gifts " to 18 university labs across six continents to support AI safety research, Microsoft data cowboy and AI red team lead Ram Shankar Siva Kumar said in a blog. “The funding is unrestricted because the objective is not to direct research outcomes toward product requirements or predefined deliverables,” he wrote. “Some universities are examining the cybersecurity implications of AI systems themselves - including how models can be attacked, manipulated, or abused in operational environments. Other labs are exploring the inverse problem: how AI systems can assist defenders and improve cyber operations.” The second EXTRA component will build a distributed network of specialists to participate in red teaming across very specific areas. “That includes researchers, practitioners, and regional experts who understand specific attack classes, languages, cultural contexts, or technical domains that internal teams may not fully cover alone,” he added. ®
Kategorie: Viry a Červi

Revolut nabídne soukromé fondy už od 1 eura. Výběr peněz ale může být omezený nebo odložený

Lupa.cz - články - 27 Červenec, 2026 - 20:55
Od 31. července 2026 budete moci přes Revolut investovat do fondů zaměřených na neveřejně obchodované firmy, soukromé úvěry a infrastrukturu. Začít půjde už s jedním eurem. Počítejte ale s dlouhodobou a obtížně prodejnou investicí. Správce fondu nemusí žádost o odkup provést v plném rozsahu ani v termínu, který investor očekává.
Kategorie: IT News

NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework

The Hacker News - 27 Červenec, 2026 - 20:10
NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents. The 37-member group spans cloud, security, enterprise software, and AI companies, including Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, and the Linux Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin

Bleeping Computer - 27 Červenec, 2026 - 19:29
Apple is being sued by three people who claim approximately $1.8 million in Bitcoin was stolen after downloading and using a fraudulent Sparrow Wallet application from the App Store. [...]
Kategorie: Hacking & Security

Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption

The Hacker News - 27 Červenec, 2026 - 19:16
Dysphoria, an Internet of Things (IoT) botnet line tracked by CNCERT and XLab, has adopted blockchain-based name services and infected-device relays after a March law-enforcement operation against JackSkid infrastructure. The researchers say the design makes the botnet harder to disrupt. CNCERT, China's national computer emergency response team, and XLab, the threat-intelligence lab of Chinese Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Čím nahradit Total Commander? Těchto 16 správců souborů umí skoro totéž a většinou jsou zdarma

Živě.cz - 27 Červenec, 2026 - 18:45
Správci souborů se vyvíjeli od éry DOSu až po dnešní dobu • Nabízejí dvoupanelové rozhraní, záložky, skriptování nebo podporu cloudů • Mnohé z nich jsou zdarma a běží na Windows, Linux i macOS
Kategorie: IT News

Installed Is Not Remediated: How to Verify Linux Security Patches in Production

LinuxSecurity.com - 27 Červenec, 2026 - 18:22
There are several reasons why Linux has such a good reputation and has become such a good standard across the world. It is the power behind most internet servers and cloud infrastructures as well as billions of Android devices. It is stable, has consistently high-performance levels, and remains very flexible. You don’t have to deal with expensive licenses, can view and share code, and can customize any part of the interface to suit your demands. In an age of data breaches and continuous malwa...
Kategorie: Hacking & Security

Tech giants link hands to praise open AI models after OpenAI - Hugging Face attack

The Register - Anti-Virus - 27 Červenec, 2026 - 18:17
In the wake of OpenAI agents attacking Hugging Face, Nvidia has recruited a new posse of partners to promote open source models as the security solution the industry needs. The AI arms dealer announced the foundation, the Open Secure AI Alliance, in a blog post today, describing the mission of the group being “to ensure defenders everywhere have open, frontier tools they can trust and control.” Partners in the group are numerous, ranging from established tech giants like Microsoft, Red Hat, HPE, IBM, and Adobe to newer groups like Palantir, SpacexAI, Hugging Face, and The Linux Foundation. What all the founding members have in common, Nvidia said, is that they agree open source AI models are a fundamental part of modern cybersecurity, just like prior open source tech has been for the infosec space. “The United States and its partners now face a choice in AI security: whether the defenses that protect our infrastructure will sit inside a few opaque systems or be built on open models, harnesses and tools that any defender can study, adapt and deploy,” Nvidia said in the announcement. The claims in many ways echo the pleadings from tech industry heavyweights made in an open letter to US government regulators last week. That letter, signed by many of the same companies that are part of the founding OSAA cadre, essentially argues that regulators should ensure Anthropic, Google, and OpenAI don’t end up with total control of the US AI market, and that open-weight models should be given a seat at the table, too. The new alliance is arguing that, not only do open-weight models need to be allowed to proliferate in the US, but they also need to be considered a fundamental part of the security puzzle. For those unfamiliar with the Hugging Face incident, a group of autonomous OpenAI agents, operating in a sandbox and stripped of guardrails to test their full capability to solve cybersecurity puzzles, exploited a pair of zero-days to escape and gain access to the internet. For some reason, the bots thought the solution to the problems they were posed could be found in Hugging Face systems, so they broke in and accessed a bunch of private information and hijacked some credentials. When Hugging Face turned to closed-source US frontier AI lab bots to examine the incident and help figure out what happened, those tools declined to help because they thought the data Hugging Face was trying to examine was itself malicious. Hugging Face turned to Chinese-made GLM 5.2, hosted on its own infrastructure, to figure things out. “That incident showed a practical truth,” said Nvidia. “When defenders cannot inspect, adapt and run advanced AI on their own infrastructure, their ability to respond is constrained at exactly the moment speed matters most.” Only open-source AI models, which China leads development on, can fill that role, the OSAA argues, and it’s prepared to counter those who say open models are a threat: Just look at what happened last week and it's readily apparent that closed source models are dangerous too. The Alliance is pooling its efforts to give security pros access to essential open tools. Nvidia said that it’s participating by releasing its Object-Oriented Agent project on GitHub, HPE is contributing its SPIFFE/SPIRE zero-trust AI identity framework, Hugging Face has handed its Safetensors transparent AI model weight formatting to the PyTorch Foundation, and SpaceXAI has open-sourced Grok Build (though the reason behind that doesn’t appear to be entirely benevolent). In addition, IBM and Red Hat have released Lightwell, an automated open-source vulnerability remediation platform, while Microsoft has come out with MDASH, a multi-model agentic scanning harness to automate bug discovery and remediation. Those efforts, while not open source themselves, are still a sign that Alliance members “are building an open defense stack,” Nvidia said. The OSAA ended its announcement with another call for policymakers not simply ban open-source AI models, as doing so “would weaken defensive capacity and risk concentrating power, dependence, and vulnerability in a few closed providers,” the group said. Many providers, as we saw last week, are more concerned with protecting themselves than helping victims of autonomous cyber attacks respond quickly. Clement Delangue, cofounder and CEO of Hugging Face, said in a post on X that he spoke to OpenAI over the weekend about last week’s incident and asked the company to provide funding to support the development of better open-source AI cyber defenses. It’s not clear if the company plans to fulfill that request; it’s not a founding member of the Nvidia-led OSAA. Neither is Google or Anthropic, for that matter. We reached out to all three companies for their take on the new initiative, but didn’t hear back from any of them. ®
Kategorie: Viry a Červi

Krabix.cz, online 3D konfigurátor krabiček pro 3D tisk

AbcLinuxu [zprávičky] - 27 Červenec, 2026 - 18:12
Krabix.cz je online 3D konfigurátor krabiček pro 3D tisk s exportem do STL. Běží přímo v prohlížeči. Nic se neposílá na server.
Kategorie: GNU/Linux & BSD

Deset skrytých nastavení fotoaparátu iPhonu, díky kterým pořídíte výrazně lepší fotografie i videa

Živě.cz - 27 Červenec, 2026 - 17:45
Výchozí nastavení iPhonu zbytečně omezuje maximální kvalitu videí i fotografií • Správným nastavením funkcí fotoaparátu získáte větší kontrolu nad snímky • Pro profesionální tvorbu využijte formát ProRAW a externí ukládání dat
Kategorie: IT News

The best thing about Apple’s smart glasses: what Cupertino rejects

Computerworld.com [Hacking News] - 27 Červenec, 2026 - 17:41

Despite the temptation to enter what might become a $40 billion market, Apple has reportedly decided to delay the introduction of its smart glasses until 2027. The company apparently wants to figure out a better balance between privacy and convenience. 

If it gets that right, Apple might be able to bring to market glasses people can wear in public without making everyone around them wonder whether they, their children, their private conversations or even corporate data are being quietly recorded or filmed.

It’s a sensible move. During the first internet gold rush, many argued that trading privacy for convenience would be more than justified by the benefits. Years later, that bargain looks a great deal less attractive than it did.

We’ve seen this story

After all, since then we’ve seen the likes of Cambridge Analytica and the evolution of digital state surveillance (and state-adjacent surveillance “businesses” such as NSO). We’ve also seen the dubious rise of data brokers, creepy “personalized” ads that seem to follow private conversations around, and all the other parasites that breed in the murk when privacy is diluted.

None of these things is good. More people than ever now seem to understand that when privacy is removed, bad things happen — no matter what herds of fully paid-up lobbyists try to make people believe. Privacy erosion seems to be a great deal for ultra-wealthy corporations seeking to turn our lives into their profit. It is not such a great deal for the rest of us.

The next privacy frontier: Your face

This growing awareness matters as we prep for the next big thing in disruptive technology: AI-equipped wearable devices capable of contextual understanding and analysis of surroundings. These smart, sensor-packed devices will pick up so much information about us, from health biometrics to direction, even insight into what we look at, how long, and what that gazing does to our heart rate. (Think of how useful the latter data point might become for divorce lawyers and blackmail.)

In the next wave of wearables, the data gathered about you will comprise an even more accurate depiction of who you are than what your smartphone already generates. These systems don’t just pick up the raw data about you; because they are AI-equipped, they also gather information about what you do and why you’re doing it. That might be useful some of the time, but is the convenience worth turning your whole life into a data point that can be interrogated, hacked, stolen, or abused? I’m not certain it is.

Apple’s opportunity

Fortunately, I’m not the only one. Apple seems to be rethinking some of the scariest features built into its future (2027) Meta-competing glasses, possibly with the introduction of software fixes to mitigate some of the more egregious ways these devices might be used to disrupt privacy.

This is good business, of course. Not only has Apple fought hardest to protect user privacy, but it also knows that Meta — its main competitor in the smart glasses space — has what could easily be seen as a poor record for privacy protection. With Apple about to enter the fray with its first set of AI wearables since Vision Pro, it must find ways to distinguish its business from Meta’s.

Privacy is one major way to do so – and Apple might be motivated in part by Meta’s attempts to use Europe’s Digital Markets Act to undercut more customer privacy than Apple thinks it should without informed customer consent. If Meta wants that kind of info from an iPhone or Apple Watch, it will make the same play to get data from any other wearables Apple might create. 

What will Apple do?

Apple’s plan boils down to ensuring its devices don’t collect data they shouldn’t. Bloomberg’s Mark Gurman points to the surveillance threat of existing products: “Consumers remain uneasy around people wearing camera-equipped glasses, unsure whether they’re being recorded during conversations at work, restaurants or other public places,” he concedes.

I agree Apple will not want to introduce products that undermine its reputation for privacy, though I reject his opinion that fears about privacy and smart glasses are “probably unfounded.” History already shows these things only seem harmless until they’re not.

Gurman tells us Apple will put a light in the glasses so we can tell when a wearer is filming us, and a feature that disables filming if the light is broken or faulty. The company could also launch glasses with no camera at all, no third-party checking of footage, and on-device (rather than cloud-based) data analysis. He also posits that Apple could include a camera but “hard-code” limits on how it can be used, meaning it might pick up ambient data to feed contextual AI analysis, but not capture video or images. Others have considered a privacy beacon to prevent other devices filming the wearer.

We will likely learn how Apple plans to make smart glasses dumb enough to wear without becoming a privacy pariah at WWDC 2027. Gurman says the products are unlikely to ship until that fall.

You can follow me on social media! Join me on BlueSky,  LinkedInMastodon and subscribe to my daily, human-curated Apple-related news round-up, The Core. 

Kategorie: Hacking & Security

Coca-Cola confirms data theft in Fairlife ransomware attack

Bleeping Computer - 27 Červenec, 2026 - 17:39
The Coca-Cola Company has confirmed that hackers stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month. [...]
Kategorie: Hacking & Security
Syndikovat obsah