Agregátor RSS

NetNut proxy network disrupted, 2 million infected devices cut off

Bleeping Computer - 3 Červenec, 2026 - 19:50
A joint operation involving Google has disrupted NetNut, a residential proxy network that gave access to millions of compromised Android devices, including smart TVs and streaming boxes. [...]
Kategorie: Hacking & Security

Xboxu teď šéfuje smrťák. Z herní divize Microsoftu stříká zelená krev (Podcast Živě)

Živě.cz - 3 Červenec, 2026 - 18:45
Phil Spencer byl hráč a roky také tváří Xboxu. Jeho období nákupů studií a bezbřehých svobod ale nezafungovalo. Microsoftu došla trpělivost, Spencer odešel a jeho místo zaujala Asha Sharma, která předtím vedla AI divizi. Prvních 100 dní bylo pozitivních, protože zlevnila Game Pass a začala ...
Kategorie: IT News

North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets

The Hacker News - 3 Červenec, 2026 - 18:07
Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup polyfill tooling to facilitate remote access and data theft. According to JFrog, the packages "rollup-packages-polyfill-core" and "rollup-runtime-polyfill-core" mimic the legitimate "rollup-plugin-polyfill-node" project, down to the description, repository metadata, and
Kategorie: Hacking & Security

North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets

The Hacker News - 3 Červenec, 2026 - 18:07
Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup polyfill tooling to facilitate remote access and data theft. According to JFrog, the packages "rollup-packages-polyfill-core" and "rollup-runtime-polyfill-core" mimic the legitimate "rollup-plugin-polyfill-node" project, down to the description, repository metadata, and Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Meta reuses old RAM in new servers with custom bridge chip

Computerworld.com [Hacking News] - 3 Červenec, 2026 - 17:50

With the cost of new RAM soaring, Meta has found a thrifty way to reuse older memory in newer servers.

The performance of about 40% of Meta’s millions of servers is limited by a lack of memory, the company said — but it has a surplus of older DIMMs from decommissioned servers, because RAM chips can last about twice as long as the rest of the machine.

To profit from this imbalance, it developed a custom Computer Express Link (CXL) chip it calls Vistara, and associated software, to decouple older memory from server memory channels, enabling its reuse in new machines alongside their native memory. Using the older RAM with the CXL interface doesn’t significantly affect performance — although it would have done if the older DIMMs were plugged straight into newer servers.

Kudos to tech site The Register for noticing the development, which Meta described in a technical paper: Vistara: Making CXL Real — Full Path from ASIC Design and OS Support to Hyperscale Deployment,” setting out how the new technology works.

There is a particular need to be thrifty right now, given the current state of the market. Last year, users were warned that memory prices could double by the end of 2026, while the RAM shortage could last until 2027. This week, Apple suggested using cheap Chinese chips, a move that may well be frowned on by the Trump administration. The Meta development may prove to be an efficient way forward.

This article first appeared on Network World.

Kategorie: Hacking & Security

Nejlepší filmy o přežití. Divoká příroda a extrémní testy lidské vůle. Boj o život, dech i naději

Živě.cz - 3 Červenec, 2026 - 17:45
Bojuje se o vzduch, jídlo, naději – i o samotný život. Filmy o přežití nás vrhají do extrémních situací, kde se hrdinové ocitají na pokraji sil a čelí přírodě, nepřátelům, nebo vlastnímu strachu. Ať už jde o trosky v oceánu, nekonečné lesy, postapokalyptické pustiny, nebo vesmír bez kyslíku, jedno ...
Kategorie: IT News

Microsoft 365 users fall victim to one-in-a-million password spray attack

Computerworld.com [Hacking News] - 3 Červenec, 2026 - 17:30

Microsoft users have been hit by a massive, automated password spray attack.

Among those targeted by the attack were clients of security company Huntress. It reported that the attackers made 81 million attempts to log into its customers’ accounts between June 12 and 26 — and succeeded in at least 78 cases.

And that’s just the attacks on Microsoft account holders who also happen to be Huntress customers: The number of compromised accounts could be much higher, as it’s in the nature of a password spray attack to attempt to connect indiscriminately.

The attacks all came from a single source, an IPv6 address range controlled by internet provider LSHIY LLC, Huntress said in a blog post. LSHIY has since terminated access for the customer using the IP addresses involved in the attack.

Huntress had been monitoring spray attacks for some time and had noticed a slight increase from June 12, and then a sudden spike on June 22 when 30 of its customers were affected.

The attackers replayed validated credentials via the OAuth ROPC (Resource Owner Password Credentials) flow. This takes a username/password at the /token endpoint for a tenant and mints a new user-delegated token, once provided with the correct credentials. This was possible because multi-factor authentication (MFA) had not been configured to handle the techniques deployed by the attackers.

Huntress said that this was because, in some cases, MFA had been enforced for specific apps instead of “All Cloud Apps.” For example, some organizations enforced MFA for Microsoft Admin Portals, which did not cover the Azure CLI logins used by the attacker.

In other cases, organizations enabled MFA only for specific user groups (such as Admins Only). The compromised users were not in the scope of these specific user groups.

This article first appeared on CSO.

Kategorie: Hacking & Security

Mak's Security Roundup: Prioritizing This Week's Critical Updates

LinuxSecurity.com - 3 Červenec, 2026 - 17:11
Before you close out the week, check what still needs to be patched.
Kategorie: Hacking & Security

Senzor v balónu rozhodl zápas MS ve fotbale. Kamery pohyb neviděly, rozhodla pokročilejší technika

Živě.cz - 3 Červenec, 2026 - 16:45
Včerejší šestnáctifinálový zápas na MS ve fotbale mezi Portugalskem a Chorvatskem přinesl velmi kontroverzní moment. Portugalci otočili stav zápasu, a ještě ve 13. minutě nastavení druhého poločasu vedli 2:1. Jenže pak Chorvaté se štěstím vyrovnali. Perišić nacentroval do vápna a míč se dostal k ...
Kategorie: IT News

AdaptHealth says attackers sweet-talked their way into cloud systems and stole patient data

The Register - Anti-Virus - 3 Červenec, 2026 - 16:29
AdaptHealth says attackers used social engineering to breach its systems and steal sensitive patient data, including passwords associated with insurance billing. The medical equipment company disclosed the attack to the Securities and Exchange Commission (SEC) on Thursday, noting that attackers accessed internal patient management systems, document storage platforms, and external electronic health record system portals. The attack targeted an unwitting third-party contractor, through which the cybercriminals gained entry to the company's cloud environment, where they accessed business applications holding sensitive data. AdaptHealth activated its incident response protocols soon after the attacker contacted the company on June 15 and disclosed the theft. It did not specify whether an extortion demand was made, nor whether one was paid, and no cybercrime group had claimed responsibility at the time of writing. The company's response included disabling the contractor's user account, resetting credentials, and implementing additional access controls. It believes the attack is now contained. In addition to the "password file associated with insurance billing," AdaptHealth confirmed that personally identifiable information (PII) and protected health information of certain patients were also stolen. Social Security numbers and payment details are not thought to be affected. On June 27, AdaptHealth determined that "due to the nature and potential volume of the data that is at risk," the attack can be considered material, requiring disclosure to the SEC. The company did not comment on the exact scale of the attack or the related data theft, but said investigations continue to determine the scope of the breach. It also said it "has since taken steps intended to mitigate the risk of dissemination of the exfiltrated data." The Register asked AdaptHealth for more information, including whether it received any extortion demands and what steps it took to reduce the risk of the stolen data being distributed or misused. Pennsylvania-based AdaptHealth provides home medical equipment and related services for patients with chronic and serious conditions. Founded in 2012, it specializes in respiratory, sleep, and diabetes therapies. According to a 2024 annual report, it serves more than 4.2 million patients across all 50 US states. ®
Kategorie: Viry a Červi

ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkit

Bleeping Computer - 3 Červenec, 2026 - 16:12
A new phishing-as-a-service (PhaaS) platform dubbed "ARToken" appears to operate as an affiliate of the EvilTokens phishing platform, giving researchers a glimpse into an extensive toolkit designed to compromise Microsoft 365. [...]
Kategorie: Hacking & Security

Adobe premieres a second Patch Tuesday each month to deliver fixes faster

Computerworld.com [Hacking News] - 3 Červenec, 2026 - 16:07

Adobe will now issue security patches for its products twice as often to deal with the increasing pace of software vulnerability discovery and exploitation.

This follows Oracle’s decision to increase its quarterly patch program to a monthly one.

Adobe issues patches on the second Tuesday of each month, as do Microsoft and SAP. Starting in July, it will also issue them on the fourth Tuesday of each month, it said in a blog post.

As an early indicator of the need for the faster rhythm, it issued two security advisories dealing with a number of critical vulnerabilities on June 30 — the fifth Tuesday of that month: APSB 26-28 and APSB26-29. It is not alone in issuing out-of-sequence patches for urgent fixes: In April, Microsoft also released one to react to a particular threat.

Adobe said in a blog post that it is responding to the increased level of threats: “Twice-monthly bulletins will enable us to keep pace with the era of frontier AI. More vulnerabilities found means more fixes to deploy and a once-a-month publication window is no longer fast enough to stay ahead of our adversaries. This new cadence is the direct result of investing in improved vulnerability discovery.”

The new schedule will be effective from July 14 and will apply to every advisory that includes a formally published CVE requiring customer action.

This article first appeared on CSO.

Kategorie: Hacking & Security

The Milky Way Was Rewired by a Cataclysmic Collision Billions of Years Ago. Now It Is on Course for Another.

Singularity HUB - 3 Červenec, 2026 - 16:00

The night sky seems eternal and unchanging. But in cosmic time, nothing could be further from the truth.

Vasily Belokurov is one of three winners of the 2026 Kavli Prize in Astrophysics. The award is for uncovering fossil evidence of past galactic mergers that prove how the Milky Way evolved.

No matter the time or vantage point, from a pre-Neolithic cave to a post-lockdown London high-rise, the predictability of the night sky has always been humanity’s symbol of permanence and reassuring stability.

Yet this apparent calm is deceptive. Our galaxy, the Milky Way, emerged from chaos and turbulence, and its constellations are full of migrants, exiles and survivors. Right now, it has begun to stretch and distort again, pulled by a massive companion and heading for an inevitable collision.

How can I be so sure? As a galactic archaeologist, my job is to reconstruct the past of our galaxy and read the signs of its future.

Instead of digging through soil, I use the laws of dynamics and stellar evolution to sift through hundreds of millions of stars—searching for the most ancient and chemically peculiar among them, interpreting their orbits and piecing together the events that shaped the Milky Way. One ancient encounter left scars so deep that, billions of years later, they still define the galaxy around us.

I want to understand what governs the lives of these massive cosmic systems: which changes are nature—the slow internal evolution of a galaxy disk—and which are nurture, imposed by collisions and mergers.

Questions about the source of dark matter underpin it all. This is the invisible substance whose gravity holds galaxies together, but whose true identity remains one of the greatest unsolved puzzles in astrophysics.

The Milky Way is the one galaxy where stellar motions can be measured in extraordinary detail. This allows cosmologists including myself to construct our most precise map yet of dark matter: how far it reaches, how dense it is around the sun, what shape it has, and how smooth or lumpy it may be. If we can build this map in enough detail, we may begin to understand not just where dark matter is, but what it is.

A Cataclysmic Collision

Our work has been transformed by a revolution in open sky surveys. From 2000, the Sloan Digital Sky Survey showed what becomes possible when vast astronomical datasets are made public, enabling discoveries far beyond the goals for which the survey was first built.

And since 2014, Gaia, the European space telescope, has taken this transformation to another level by mapping the positions and motions of nearly 2 billion stars, turning the galaxy into a vast archaeological record. No ruins, no shards, and no bones—only stars that hold the clues.

The Milky Way mapped with SDSS data. Vasily Belokurov, CC BY-NC-ND

The clearest giveaway that something cataclysmic took place long ago in our galaxy is the migrants we observe: stars that were not born in the Milky Way.

While native stars mostly travel together, circling the galactic center in the great rotating flow of the disk, migrants cut across that order. They slide past the locals, plunge into the inner galaxy, then fly back out to its outskirts, again and again.

These unusual orbits go hand-in-hand with unusual chemistry. Most of the migrant stars are less enriched in heavier elements than the locally born population. Their chemical composition is a sign of a slower rate of evolution that is typical of a dwarf galaxy.

This makes the migrants doubly valuable. They are both fossils of the Milky Way’s violent past and probes of its outer regions, traveling where the local stars rarely go.

How the Milky Way Was Rewired

One of the central ideas in the theory of cosmic structure formation is that galaxies grow hierarchically. Smaller galaxies fall into larger ones and are torn apart, leaving their stars behind as migrants.

In the Milky Way, the largest ancient structure of this kind is known as Gaia-Sausage-Enceladus. It is the remains of a vanished galaxy that collided with our own between 8 and 11 billion years ago (the “sausage” refers to a pattern in its stars’ motions).

Artist’s impression of the young Milky Way colliding with another galaxy around 10 billion years ago. Vasily Belokurov, based on image by Juan Carlos Muñoz/ESO, CC BY-NC-SA

The Milky Way also did not go through that crash unscathed. The collision rewired and reshaped it.

Some of these changes are easily visible in the data. Stars from the old disk were splashed into our galaxy’s halo, becoming exiles in the place where they were born. A new posse of star clusters were also acquired.

At the same time, we think something even more momentous was taking place. The encounter changed the orientation of the Milky Way’s disk, and its alignment with the dark matter halo.

While dark matter is too diffuse to dominate our solar system, in the outer galaxy it is the main gravitating mass—moving, streaming, and in the standard picture, clumping into a hierarchy of lumps.

Around the Milky Way, this dark matter forms a vast halo, much larger than the luminous part of our galaxy. We often imagine this halo as a sparse, round cloud, but Gaia has helped show this picture is too simple.

The dark halo can be stretched out of shape by a major encounter. Like a ship beginning to list, the Milky Way started to lean—not suddenly, not visibly, but over billions of years.

View of the Southern sky shows the Milky Way and (far right, close to horizon) two galactic neighbors, the Small and Large Magellanic Clouds. H.H. Heyer/ESO via Wikimedia Commons, CC BY-NC-ND A New Galactic Dance

Unusually, compared with many galaxies of similar mass, the Milky Way was allowed ample time to recover from the shock of the “sausage merger.” No other cosmic cataclysm appears to have shaken our galaxy since, letting it settle into a quiet, uneventful life. That is, until now.

The Large Magellanic Cloud (LMC), currently our galaxy’s most massive companion, is already pulling at the Milky Way, disturbing its halo again. In an echo of what happened some 10 billion years ago, the Milky Way is being drawn into an accelerating dance with this neighboring dwarf galaxy, recoiling in response to the LMC’s approach.

This is a dance that only one galaxy is likely to survive intact. A new chapter of migration, survival and adaptation has begun.

None of this spoils the beauty of the night sky—it deepens it. The calm band of light above us is not a symbol of permanence, but the visible reminder of a long survival.

The Milky Way has been broken, rebuilt, and is now being disturbed again. Its stars remember the past; their motions reveal the future. What looks eternal is, in truth, a moment in a much longer story.

This article is republished from The Conversation under a Creative Commons license. Read the original article.

The post The Milky Way Was Rewired by a Cataclysmic Collision Billions of Years Ago. Now It Is on Course for Another. appeared first on SingularityHub.

Kategorie: Transhumanismus

Krabička do kapsy za pár stovek okamžitě vyléčí komáří štípnutí. Žádná chemie, pouze teplo

Živě.cz - 3 Červenec, 2026 - 15:45
Kapesní bateriové zařízení dokáže zklidnit bodnutí hmyzem • Teplo umlčí nervový kanál a přehluší svědění • Podobně funguje i chlad. A hlavně neškrábat!
Kategorie: IT News

Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer

The Hacker News - 3 Červenec, 2026 - 15:36
A previously undocumented threat actor known as Armored Likho has been attributed to cyber attacks targeting government agencies and the electric power sector across Russia, Brazil, and Kazakhstan. "Armored Likho blends financially motivated campaigns targeting private individuals with targeted cyber espionage aimed at organizations," Kaspersky said in a technical analysis published today. "
Kategorie: Hacking & Security

Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer

The Hacker News - 3 Červenec, 2026 - 15:36
A previously undocumented threat actor known as Armored Likho has been attributed to cyber attacks targeting government agencies and the electric power sector across Russia, Brazil, and Kazakhstan. "Armored Likho blends financially motivated campaigns targeting private individuals with targeted cyber espionage aimed at organizations," Kaspersky said in a technical analysis published today. "Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

How to Investigate Linux Persistence During Incident Response

LinuxSecurity.com - 3 Červenec, 2026 - 15:22
You’re staring at a service or a cron job that’s giving you a bad feeling. Stop. The most dangerous thing you can do right now is act on that gut feeling alone. Linux systems are inherently noisy—package managers, configuration management, and the occasional "quick fix" from a colleague can all leave weird artifacts behind.
Kategorie: Hacking & Security

NetNut cracked as Google and FBI target 2 million-device botnet

The Register - Anti-Virus - 3 Červenec, 2026 - 14:03
Tech companies working with US law enforcement "significantly degraded" the NetNut residential proxy network as part of an ongoing effort to disrupt the tools cybercriminals use to conceal their activity, say researchers. The work was carried out by Google, Lumen, Shadowserver, the FBI, and others, and marks a continuation of the IPIDEA proxy network disruption from January. According to Google Cloud, those working on the operation believe NetNut was among the most popular residential proxy network providers and had at least 2 million devices enrolled in its botnet, comprising mainly small TV-streaming hardware. Crims often use residential proxy networks to make it look like their traffic is actually coming from legit homes and businesses. In the same way that other residential proxy networks expand their pool of enrolled devices, NetNut distributed its own SDK via these devices. Proxy providers often approach users under the guise of monetizing their spare bandwidth, paying them a fee in exchange for letting their SDK run on their devices. The official advice is, of course, to refuse any offers of this kind. Not only does it help feed the cybercrime ecosystem, but it can also lead to vulnerabilities elsewhere in home networks. NetNut offered its own standalone proxy networks, as well as mobile and datacenter proxies, and a slew of scrapers and datasets. However, it also offered a reseller program, and experts believe many other residential proxy networks are powered by NetNut's own, which means the disruption may have further downstream effects. "While we expect this disruption to have a larger ripple effect across the residential proxy ecosystem, observations after the disruption of IPIDEA proved that individual networks can appear resilient," Google's Threat Intelligence Group (GTIG) said. "What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller. "We recognize that creating a lasting disruption in this fluid ecosystem means we must scale our efforts to target the infrastructure of several interconnected providers. We will continue to observe the composition of the NetNut network and map out how its peers adapt to this action." Residential proxy networks are not illegal, although they are often abused for cybercrime. These networks are ostensibly pitched as a means to shore up online privacy, and promote ideals such as freedom of expression without risk of being traced. However, the same privacy-preserving features of these networks are used by cybercriminals to mask their malicious activity. They enroll ordinary devices, which are connected to innocent residential networks, at scale and offer them to customers as exit nodes. Cybercriminals can make use of these networks to channel their traffic through these nodes, making the traffic appear to originate from an IP address they do not control. "In a single week during June 2026, GTIG observed 316 distinct threat clusters using suspected NetNut exit nodes, including cybercriminal and espionage groups," said Google. "These bad actors can use NetNut to mask their origin IP address when accessing victim environments, accessing their own infrastructure, and conducting password spray attacks." Reports also suggest that NetNut has a role to play in other botnet families. GTIG said it found plugin components for large-scale botnets such as Badbox 2.0, while other public reports have noted signs of NetNut being used to infect devices with Mirai variants. The Register asked GTIG why NetNut's second domain (netnut.io) remains online, while netnut.com returns a "This website has been seized" splash page, but it did not immediately reply. Google's announcement hinted at similar takedowns to take place in the future, as the residential proxy network market continues to grow. However, it said these ad hoc disruptions are only effective for so long, and that a long-term approach would require support from ISPs, mobile platforms, and other technology companies. ®
Kategorie: Viry a Červi
Syndikovat obsah