Agregátor RSS
Chinese AI company Zhipu claims its new model is a better bug-finder than Anthropic, OpenAI
ASIA IN BRIEF Chinese company Zhipu last week launched a new AI model called GLM-5.3 that it claims has bug-finding powers that match those possessed by American models. The company’s announcement includes benchmark data that finds GLM-5.3 beats Fable 5 and GPT-5.6 Sol on the CyberGym benchmark, a test of a model’s ability to solve real-world cybersecurity challenges. “As we scaled post-training, cyber capability developed faster than we expected. GLM-5.3 is state of the art on CyberGym for vulnerability discovery, and its gains are largest further up the exploitation chain,” the company wrote, adding that the model “did not simply become better at identifying isolated flaws: it began to reason across multiple stages of exploitation, forming coherent plans for complete exploitation chains.” The company said it has worked with Chinese companies to test the model on real-world codebases, and found 2,436 vulnerabilities across 269 projects, including 1,097 medium-to-high severity issues. The findings span system kernels, operating systems, browser engines, open-source infrastructure, web applications, and network protocols. “Many had remained unnoticed for years or even decades, with the oldest dating back roughly 40 years,” the announcement states. GLM-5.3 also performed worse than western models on other security and coding benchmarks. Yet the fact that the model is a highly-capable bug finder signals that China is not far behind in terms of being able to poke holes in its rivals software and developed that capability very quickly after the debut of Anthropic’s Mythos. Any advantage the US felt it had as the home of Anthropic has therefore dissipated. Korea signals legal action against Apple, Google app store strangleholds South Korea’s Communications Commission last week found Google and Apple had abused their app store monopolies, and promised stern sanctions will follow. In 2021, South Korea passed world-first legislation requiring app store operators to offer the option to use third-party payment schemes. Apple and Google did so, but charged a 26 percent transaction fee for doing so – meaning they earned almost as much revenue when users chose third-party payment providers as they did from their own schemes. The regulator has previously warned that it will impose the highest possible penalty available under law, which is three percent of revenue earned by non-compliant behaviour. That’s probably back-of-the-sofa money for Apple and Google. India has banned rideshare operators from offering customers the chance to specify the amount they will tip before a driver accepts a gig. Uber India introduced the feature last year, seemingly copying it from an Indian rideshare operator called Namma Yatri. Consumer affairs minister Pralhad Joshi criticized Uber for the practice at the time, as he saw it as a means for users to effectively jump the queue by offering drivers more money – and for rideshare platforms to improve their revenue because if tips are higher, so is the platform’s share of the gratuity. Last week, India’s Ministry of Road Transport & Highways issued a directive (PDF) banning the practice. Henceforth, rideshare apps can only offer users the chance to tip at the end of a journey, and all of the tip must go to the driver. “No feature, prompt, message, add-on, payment option, or user interface element should be displayed before completion of the ride that directly or indirectly encourages, induces, or creates an impression that payment of any additional amount may improve ride confirmation, driver acceptance, driver allocation, waiting time, or quality of service,” the directive states. Indian services giants reveal data breaches Indian tech services giants TCS and HCL last week both admitted to data breaches but say customer data is safe, and only employee data is at risk. TCS published a stock exchange filing that opens “This is to inform you that Company has received threat-intelligence alerts alleging possible exposure of certain employee information.” The filing says TCS investigated the matter “and has not found any credible evidence of a breach of TCS systems or customer environments.” The company says leaked info is “basic employee information” and more than four years old. Note that mention of the stolen data being at least for years old, because TCS’s filing says the attacker claims to have used password spray and Multi-Factor Authentication (MFA) fatigue to pull off the heist. TCS says it “had strong safeguards in place against such techniques for more than two years,” perhaps suggesting the data heist occurred before the company shored up its defenses. “Based on the current review, these controls remain effective, and the Company continues to monitor the environment closely,” the filing states. HCL also used a stock exchange filing [PDF] to address what it called “claims made by a hacker group of potential exposure of limited data elements relating to HCLTech employees.” The company described the stolen data as “limited and dated to a few years back,” and added its assurance that customer data is safe. HCL’s investigation is ongoing. Lenovo’s enterprise unit finally posts a big profit Lenovo last week announced its quarterly results, including a $777 million profit for its Infrastructure Solutions Group (ISG) – the biz based on the 2014 acquisition of IBM’s x86 server operation that has seldom produced positive financials. Even during the early years of the AI boom, ISG’s profits were modest – just a few million dollars per quarter on turnover of billions. The business unit won a record $8.5 billion of revenue, up 98 percent year-on-year. AI was a big reason for the result, as buyers sought hardware to run inferencing workloads, The company says it has a pipeline for $54 billion of AI server sales, and has become the number two x86 server vendor as measured by revenue. Overall revenue came in at $26.95 billion, up 43 percent year-on-year, and cash won by its PC-led intelligent devices group jumped 27 percent to $17.1 billion and saw its PC market share reach 24.2 percent. Lenovo reckons the strength of its supply chain helped make those outcomes possible. India to build astronaut training facility India’s Space Research Organization (ISRO) last week issued a tender for construction of an astronaut training facility. The tender mentions extensive air conditioning works, plus a swimming pool, suggesting India wants to build a large tank in which the Vyomanauts who will fly its future Gaganyaan missions can train at home, instead of traveling to Russia or elsewhere as has been the case in the past. The tender covers $2.75 million worth of work. ®
Kategorie: Viry a Červi
[webapps] flyto_core 2.26.7 - Server-Side Request Forgery
flyto_core 2.26.7 - Server-Side Request Forgery
Kategorie: Security Vulnerabilities & Exploits
[webapps] webpack_devserver 5.2.5 - CSRF
webpack_devserver 5.2.5 - CSRF
Kategorie: Security Vulnerabilities & Exploits
[remote] phpSysInfo 3.4.5 - IP Allowlist Bypass
phpSysInfo 3.4.5 - IP Allowlist Bypass
Kategorie: Security Vulnerabilities & Exploits
[dos] Nmap 7.99 - Extension Header Integer Underflow
Nmap 7.99 - Extension Header Integer Underflow
Kategorie: Security Vulnerabilities & Exploits
[webapps] Duplicati 2.2.0.3 - JWT Signing Key Leak
Duplicati 2.2.0.3 - JWT Signing Key Leak
Kategorie: Security Vulnerabilities & Exploits
[webapps] Joomla JCE_2.9.15 - Remote Code Execution
Joomla JCE_2.9.15 - Remote Code Execution
Kategorie: Security Vulnerabilities & Exploits
[remote] ipTIME A3004T - Remote Code Execution
ipTIME A3004T - Remote Code Execution
Kategorie: Security Vulnerabilities & Exploits
[remote] D-Link DNS_340L - OS Command Injection
D-Link DNS_340L - OS Command Injection
Kategorie: Security Vulnerabilities & Exploits
[webapps] WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload
WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload
Kategorie: Security Vulnerabilities & Exploits
SafePal data breach impacts 39,798 customers, stolen info for sale
Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data. [...]
Kategorie: Hacking & Security
Anthropic confirms Claude is down in major outage affecting multiple services
Claude is experiencing a major outage, with users reporting login problems and degraded performance across several Anthropic services. [...]
Kategorie: Hacking & Security
Minimální mzda v roce 2027 opět poroste, první čísla odhadují, že dost výrazně
První odhady naznačují, že minimální mzda se v příštím roce poměrně výrazně zvýší. Už brzy by mohla být dostupná data, která čísla zpřesní.
Kategorie: IT News
Postřehy z bezpečnosti: pracovní nabídka s bonusem v podobě zero-day
Severokorejský Lazarus zneužil novou chybu ve Windows, výzkumníci s pomocí AI připravili zero-click útok na Zoom a falešná Wi-Fi zaměstnala posádku letu s účastníky DEF CONu.
Kategorie: GNU/Linux & BSD
KDE připravuje stabilní verzi, LightDM ožívá
Projekt KDE oznámil přípravu nové „neprůstřelné“ softwarové sady postavené na KDE Plasma 6.6 LTS. Projekt LightDM, odlehčený správce přihlašování se po několikaleté odmlce vrací k aktivnímu vývoji. Proxmox oznámil, že distribuce založená na Debianu byla portována na 64bitovou architekturu ARM.
Kategorie: GNU/Linux & BSD
Čínská CXMT překonala 90% výtěžnost při výrobě DDR5, dýchá na krk Samsungu
CXMT nepřekvapuje pouze rychlým růstem výrobních kapacit, nabídkou velmi rychlých paměti a chystanými metodami pouzdření, které zaskočily konkurenci, ale nyní také vysokou výtěžností jejích procesů…
Kategorie: IT News
Letitý fyzikální experiment by mohl pomoci odhalit mininabité částice
Hypotetické mininabité částice, pokud existují, nesou maličký zlomek elektrického náboje. S běžnou hmotou a elektromagnetickými poli interagují jen zcela mizivě, a proto je velmi obtížné je hledat. Přinese průlom důmyslný experiment, který je založený na dávném Cavendishově experimentu?
Kategorie: Věda a technika
Large-scale DDoS attacks disrupted Threema secure messaging service
Multiple distributed denial-of-service (DDoS) attacks targeted the Threema secure messaging service earlier this week, causing severe disruptions to communications. [...]
Kategorie: Hacking & Security
- « první
- ‹ předchozí
- …
- 59
- 60
- 61
- 62
- 63
- 64
- 65
- 66
- 67
- …
- následující ›
- poslední »



