Agregátor RSS
Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks
The Russian state-sponsored threat actor known as Turla has been attributed to a previously undocumented .NET backdoor called STOCKSTAY that has been deployed against government and military organizations in Ukraine, and entities that have an interest in Italian foreign policy.
Describing the Windows backdoor as continually developed by the hacking group, Google Threat Intelligence Group (Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Čipové status quo se otřásá. AMD křísí mrtvý procesor, Intel chystá nenasytné desky a Nvidia může přepsat pravidla hry
Nové handheldy, výkonné notebooky pro hráče nebo pro práci i ochutnávka toho, co nás výhledově čeká v procesorovém světě – to vše bylo nedávno k vidění na Computexu.
Kategorie: IT News
Security boss thought MFA would be too much security
ON CALL Supporting IT and keeping it secure is a serious endeavor. Which is why The Register lightens up Friday mornings with a fresh installment of On Call, the reader-contributed column that shares your tales of tech support trauma. This week, meet a reader we'll Regomize as "Colin" who told us about a recent gig at a customer that decided to improve the security of its Microsoft 365 implementation – chasing the Secure Score that Redmond uses to rate resilience. "We spent a good amount of time working with the customer and agreed a rollout plan to ensure multi-factor authentication (MFA) was enabled across the board in accordance with a security baseline." Colin and his crew knew what to do, so when they flicked the switch on various upgrades, all went smoothly. Until it didn't. "The following morning, one of the senior directors of the company – who was allegedly the COO of a cybersecurity company – called our service desk and started yelling." Amid the yelling and accusations, Colin and his colleagues picked out an allegation that the company had been brought to its knees by the need to register for MFA, which had crippled an invoicing system and would surely result in ruin within a disastrously short time frame. "Once she allowed us to speak, it turned out that the problem only impacted three or four phones," Colin wrote. The support team investigated and quickly learned the real problem was with the invoicing software, which promised MFA support but relied on buggy software to make it happen. The director didn't care for that explanation and ordered an instant rollback that we understand remains in place. Colin found it stunning that the former COO of a security company wasn't willing to wait for a workaround, so delivered the desired result: no MFA, and worse security. He told us this client often made nonsensical requests, such as demanding that a particular engineer – who cannot drive – visit a remote site ASAP to fix a printer. On another occasion, the same person claimed Colin's work on M365 caused a power outage! Have you ever been told to make IT worse? If so, click here to send On Call an email so we can make the column better on a future Friday. ®
Kategorie: Viry a Červi
Evropu zasáhla rekordní vlna veder. Tropické noci přibývají a extrémy každým rokem sílí
Extrémní červnové vlny veder v Evropě pohání lokální tlaková výše • Globální změna klimatu způsobuje častější a intenzivnější horka • Rostoucí noční teploty s vysokou vlhkostí vzduchu vážně ohrožují zdraví
Kategorie: IT News
Evropský AI Act je balast, který postrádá praktický smysl
Někteří uživatelé tleskají, že díky Evropské unii nebudou oblbováni AI obsahem, který by mohli brát za skutečný. Reálně nic takového AI Act negarantuje, jen tvoří zbytečnou administrativu a balast…
Kategorie: IT News
Hry zadarmo, nebo se slevou: Letní výprodej na Steamu a RollerCoaster Tycoon 3 zdarma
Na všech herních platformách je každou chvíli nějaká slevová akce. Každý týden proto vybíráme ty nejatraktivnější, které by vám neměly uniknout. Pokud chcete získat hry zdarma nebo s výhodnou slevou, podívejte se na aktuální přehled akcí!
Kategorie: IT News
Konference OpenAlt 2026 hledá přednášející
Konference OpenAlt 2026 hledá přednášející. Proběhne o víkendu 7. a 8. listopadu na půdě Fakulty informačních technologií VUT v Brně. Témata konference jsou: Otevřený a svobodný software, IoT a Hnutí tvůrců, Vzdělávání, Bezpečnost a soukromí, Otevřená společnost, komunity a data, OpenMobility a další.
Kategorie: GNU/Linux & BSD
Jalapeño, čip optimalizovaný pro AI od společností OpenAI a Broadcom
Společnosti OpenAI a Broadcom oznámily čip optimalizovaný pro AI pojmenovaný Jalapeño.
Kategorie: GNU/Linux & BSD
Chinese cybersecurity company claims it’s built a better-than-Mythos bug finder
Chinese cybersecurity vendor Qihoo 360 claims it’s built an AI bug-finder that’s better than Anthropic’s Mythos model. CEO Zhou Hongyi revealed the model in a speech at the 14th Beijing Cybersecurity Conference, which Qihoo 360 organizes. Chinese media outlets have transcribed the talk, in which Zhou described Mythos as “equivalent to a ‘cyber nuclear weapon’,” because the USA’s ban on foreign nationals accessing the model gives America a tool with which to find flaws in software upon which other nations rely. Zhou thinks China needs equivalent capabilities as a deterrent, but suggested replicating Mythos is not a viable approach. “Mythos follows a typical large-scale model approach: the strongest model, the strongest computing power, and the strongest chips – a strategy of sheer brute force,” he said. “However, this path has an implicit prerequisite: your model capabilities must be sufficiently strong. Objectively speaking, domestically developed models still lag behind by 20 percent to 30 percent in underlying capabilities.” The CEO therefore thinks China can’t wait for its own models to catch up and needs to find another way to build Mythos-grade bug-finders. Helpfully, Qihoo 360 has found those alternative methods by distilling its 20 years of experience fighting cyber-threats and colossal malware library into security-specific models and agents. The company has put that to work in what Zhou described as a “multi-agent swarm.” “If the American approach is about cultivating a genius hacker, the 360 approach is about organizing a professional attack and defense team,” he said. “When faced with a target, the swarm doesn't perform single-point analysis, but rather collaborates: first, it models the threat and filters high-risk attack surfaces; then, it follows the data flow across files to discover potential vulnerabilities.” The company’s agents apparently “automatically build sandbox environments, automatically generate exploit code, and conduct real-world testing. The result is that every vulnerability is ‘confirmed’ rather than just suspected. After completing a task, the swarm also summarizes and reviews its performance, becoming smarter with each use. This is something a single large model can hardly do.” Qihoo calls this approach “Tulongfeng” and says it’s already finding flaws in open-source and commercial software. “We automatically discovered a Windows kernel privilege escalation vulnerability that had been dormant for five years, an Office remote code execution vulnerability that had been dormant for eight years, and an Excel vulnerability that had been dormant for 10 years, earning official recognition from Microsoft,” Zhou boasted. The CEO said the tool found plenty of flaws in OpenClaw – a feat that human researchers have also achieved. Zhou said Qihoo 360 has created another AI-powered security tool called “Yitianzhen” that automatically simulates potential attacks against an organization’s cyber-defenses, then suggests and/or implements remediations. The company has created an alliance of local cybersecurity companies to use it and create a bulwark against Project Glasswing – the group of entities Anthropic allows to use Mythos under controlled conditions. US authorities have sanctioned Qihoo 360 on grounds that it probably supplies China’s military. China's National Computer Virus Emergency Response Center (CVERC) often cites and publicizes the company’s research, sometimes in its documents that allege the US hacks itself to make China look bad. ®
Kategorie: Viry a Červi
Anthropic is testing desktop-like Claude Cowork for mobile
Anthropic appears to be testing Claude Cowork support on mobile, allowing you to manage long-running Claude tasks from your phone. [...]
Kategorie: Hacking & Security
Poland busts SIM-swapping gang tied to millions in crypto theft
Authorities in Poland have arrested four members of an organized cybercrime group accused of breaching telecommunications partners and hijacking email accounts to carry out SIM-swapping attacks. [...]
Kategorie: Hacking & Security
Self-destructing Mistic backdoor linked to access broker selling corporate footholds to ransomware gangs
A new self-destructing backdoor called Mistic used in intrusions since April appears to be linked to a criminal gang that compromises corporate networks and then sells that access to ransomware groups, according to security researchers. This backdoor, also tracked as MLTBackdoor, was first documented by Zscaler earlier this month, with the security shop suggesting the novel malware is “likely used in ransomware attacks to establish a foothold for lateral movement.” In a Wednesday threat brief, Symantec and Carbon Black threat hunters say the backdoor has been used to access multiple organizations' networks over the past few months, including those in insurance, education, IT, and professional services. Additionally, the security sleuths reported, “Mistic may be linked to the financially motivated initial access broker (IAB) tracked publicly as KongTuke (which we track as Woodgnat) and it was used in one intrusion that also involved the group's ModeloRAT remote access trojan.” KongTuke and other IABs don’t deliver the final payload – such as ransomware – to compromised companies. Rather, they break into company systems, and then sell that foothold to other criminals, like ransomware gangs. Symantec and Carbon Black arrived at their low-confidence attribution after at least one case where Mistic was deployed in close proximity to ModeloRAT, the Python-based remote access trojan KongTuke also developed. KongTuke has previously been linked to attacks from various ransomware crews including Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta. “Our Threat Hunter Team has separately observed ModeloRAT used in attacks that deployed Qilin ransomware, linking this tool to ransomware deployment,” Symantec and Carbon Black noted. Plus, Zscaler reported Mistic being delivered in a multi-stage ClickFix infection chain, which is another pointer to KongTuke, as the group is known to use that initial access technique. In one case that Symantec and Carbon Black responded to, Mistic was side-loaded through a legitimate file, MpExtMs.exe, and then loaded from a DLL named EndpointDlp.dll, which likely helped the backdoor blend in with legitimate software. Mistic has all the usual backdoor functionality: It can upload, download, move, rename, and delete files. It can also create new folders, and check for additional commands from the attacker-controlled command-and-control (C2) server. But here’s the stealthy part: it can run remote payloads from C2 directly in memory – so it doesn’t write malicious files to the hard drive – which helps it dodge file-based detection in antivirus and endpoint detection products. When the mission is accomplished, it then terminates and deletes itself. “The fact that Mistic executes in memory and also has a kill switch built in means that it is very stealthy, potentially allowing for long-term, stealthy access for attackers,” the threat hunters wrote. ®
Kategorie: Viry a Červi
Týden na ScienceMag.cz: Hypertriton je vázaný pevněji
Vědci z FEL ČVUT a VŠCHT vyrobili elektroniku z odpadu z gramofonových desek. Může slábnutí temné energie vnést opět do hry Velký krach? Kolabující hvězdy by mohly vytvářet minivesmíry, což by otevřelo cestu ke gravastarům. Seismický šampaňský jev vysvětluje požáry dlouho po zemětřeseních.
Kategorie: GNU/Linux & BSD
Energie a smluvní pokuty: Proč se vedle ceny vyplatí sledovat i sankce za předčasný odchod
Smlouva na dobu určitou může znamenat výhodnější cenu, ale i sankci za její předčasné ukončení. Výše smluvní pokuty má ovšem zákonný strop a některá ustanovení ve smlouvě mohou být neplatná, pokud odporují zákonu.
Kategorie: IT News
Další zvýšení úrokových sazeb spoření. J & T Banka je už zvýšila, mBank je zvýší od července
Úrokové sazby spoření u některých bank znovu začínají číslicí 4, nebo se k ní aspoň blíží. A to platí jak pro spořicí účty, tak pro termínované vklady.
Kategorie: IT News
Jaký je Radeon RX 580 s 8 GB GDDR5 pamětí 9 let od uvedení na trh?
Dá se vůbec plnohodnotně provozovat grafická karta s GPU AMD z roku 2017. Karta, která byla symbolem těžení BTC na GPU? Jak si stojí Radeon RX 580 v kontextu roku 2026, poháněného AI a spotřebou množství grafické paměti?
Kategorie: GNU/Linux & BSD
Proč mají ptáci větší vejce než neptačí dinosauři? Řešení nabízí růst mozku
Ptáci jsou oproti neptačím dinosaurům obvykle malí. Současně ale mají ve srovnání s neptačími dinosaury relativně k velikosti těla a většinou i absolutně veliká vejce. Podle nového výzkumu to souvisí s tím, že během vývoje ptačí linie v rámci dinosaurů došlo na zvětšování mozků.
Kategorie: Věda a technika
Naděje na obzoru: Hynix se zaměří na výrobu DDR5, Čína omezuje dovoz pamětí
V posledních dnech přicházejí informace, které by mohly mít pozitivní dopad na segment osobních počítačů. Tyto události totiž mohou mírnit extrémní ceny pamětí, se kterými se trh od loňska potýká…
Kategorie: IT News
Ex-Huntress analyst claims company insider fed info to a ransomware crim. Social media drama ensues
Security firm Huntress allegedly has a turncoat insider leaking info to a ransomware operation, according to an ex-employee who took his grievances to social media after claiming the security shop tried to “silence” him with legal threats. And it all started with a Pinocchio GIF and clown emoji. Late last week, Huntress disclosed that it is among the “hundreds of Klue customers” compromised in the supply-chain attack, stating that “Huntress believes in radical transparency about security incidents, including when it affects our company.” Ben Folland, a former security operations analyst at Huntress who left the company in February, responded with a Pinocchio GIF and clown emoji - although, to be clear, his complaints about his former employer have nothing to do with the Klue incident. These stem from an earlier incident that Folland also detailed in a series of posts. According to Folland’s resignation letter, which he also shared on LinkedIn, he left the security firm for “personal reasons, and due to a conflict of interest,” with his last day of work being February 19. This conflict, Folland alleges, arose from his December discovery that “another Huntress employee passed communications from US law enforcement to a cybercriminal, DevMan, who is actively and publicly targeting my family and me.” DevMan is a ransomware operation that first emerged in April 2025 and uses modified DragonForce code. “Since December 2025, I believe Huntress has been actively trying to conceal a serious security incident from its partners, customers, and employees involving an insider who is still employed at the company,” Folland said in a LinkedIn post. The alleged insider was “caught by the FBI,” according to Folland, and continues to work as a Huntress employee. “The incident in question would cause significant reputational damage to Huntress and, in my view, continues to put clients at risk,” his LinkedIn post continued. “With an IPO on the horizon, it appears their priority was not transparency, but keeping this away from the press.” Folland also promised to publish, over the next two weeks, “evidence supporting the claims made in my resignation email,” such as communications with the FBI and those between the Huntress employee and DevMan, recorded phone calls, internal Huntress memos, and threats targeting Folland and his family. The Register reached out to Folland for more information and did not receive a response. “If you are an employee at a cybersecurity company, you should not be helping cybercriminals,” he wrote on LinkedIn. “You should not be informing them of active investigations. You should not be engaging in cybercriminal activity yourself.” We also contacted Huntress about Folland’s accusations, and CEO Kyle Hanslovan responded via a spokesperson. "A former employee raised concerns that a teammate exercised poor judgment in communicating with a cybercriminal,” Hanslovan said. “By nature of our work as security researchers, teammates occasionally need to communicate with possible cybercriminals to gather intel that ultimately supports our partners and customers,” he continued. “I appreciate the hell out of that former employee's concerns and we've taken them seriously every step of the way. I also have to make sure Huntress upholds its responsibility to protect the confidentiality of our teammates involved and the investigation underway.” Hanslovan also assured Huntress’ partners, customers, and employees that if he learns “new information that changes our assessment of the current situation, I will take quick and appropriate action.” In a more direct response on Reddit, Hanslovan said he “firmly disagree[s]” and doesn’t “understand Ben's accusations.” His company “strongly disagree[s] with this ‘insider’ narrative,” he wrote. “We sure af didn’t prioritize an IPO over the safety of our partners, customers, or team.” And about the FBI allegations: “Some aspects of this matter involve ongoing active coordination with law enforcement and legal proceedings that prevent us from providing a complete public account,” Hanslovan wrote. “We're not gonna litigate this on LinkedIn with Ben but will likely publish some form of official comms to make our stance clear for those needing something more than my reddit reply.”®
Kategorie: Viry a Červi
Order-tracking app Shop abused to push callback phishing attacks
Threat actors are increasingly abusing Shop, the order-tracking app from Shopify, by adding fake purchase receipts in users' order histories to trick them into providing sensitive data or installing remote access software. [...]
Kategorie: Hacking & Security
- « první
- ‹ předchozí
- …
- 63
- 64
- 65
- 66
- 67
- 68
- 69
- 70
- 71
- …
- následující ›
- poslední »



