Agregátor RSS

Google Chrome 153

AbcLinuxu [zprávičky] - 10 Září, 2026 - 11:05
Google Chrome 153 byl prohlášen za stabilní. Nejnovější stabilní verze 153.0.8010.36 přináší řadu novinek. Podrobný přehled v poznámkách k vydání. Opraveno bylo 230 bezpečnostních chyb. Vylepšeny byly také nástroje pro vývojáře.
Kategorie: GNU/Linux & BSD

A20 Pro je monstrum. iPhony díky němu budou rychlejší než kdejaký počítač

Živě.cz - 10 Září, 2026 - 10:45
Apple včera ukázal světu nové iPhony Pro, Pro Max a Duo, v jejichž nitru najdeme čipy A20 Pro. Poprvé v mobilu vidíme procesory vyrobené pokročilým 2nm procesem od TSMC a první čísla naznačují zajímavý výkonnostní skok. Ostatně sám výrobce říkal, že v mobilech nabídne výkon desktopu. Příliš ...
Kategorie: IT News

Microsoft fixes bug that wiped Windows desktop settings

Bleeping Computer - 10 Září, 2026 - 10:08
Microsoft says the September 2026 Patch Tuesday updates fix a known issue causing desktop settings to be lost or reset on some Windows devices. [...]
Kategorie: Hacking & Security

Navzdory úpadku desktopu prodeje GPU o 10 % stouply

CD-R server - 10 Září, 2026 - 10:00
Podle statistik prodeje GPU, kterou zpracovala společnost John Peddie Research (JPR) překvapivě na jaře letošního roku stouply dodávky o 10 %. Důvody jsou však jiné, než by se mohlo zdát…
Kategorie: IT News

Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key

The Hacker News - 10 Září, 2026 - 09:12
Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM's own setup guide. LiteLLM is an open-source AI gateway, the software a company puts between its applications and the model providers it pays for. That key is the gateway's administrator credential. Anyone who holds it can read every
Kategorie: Hacking & Security

Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key

The Hacker News - 10 Září, 2026 - 09:12
Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM's own setup guide. LiteLLM is an open-source AI gateway, the software a company puts between its applications and the model providers it pays for. That key is the gateway's administrator credential. Anyone who holds it can read every Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6

The Hacker News - 10 Září, 2026 - 09:04
Anthropic on Wednesday disclosed a fourth incident in which its artificial intelligence (AI) model broke into real third-party systems, marking the latest in a growing list of cases that have raised concerns about the security risks posed by autonomous AI agents. The AI company said the incident dates back to January 2026 and involved an early version of Claude Opus 4.6 that breached "
Kategorie: Hacking & Security

Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6

The Hacker News - 10 Září, 2026 - 09:04
Anthropic on Wednesday disclosed a fourth incident in which its artificial intelligence (AI) model broke into real third-party systems, marking the latest in a growing list of cases that have raised concerns about the security risks posed by autonomous AI agents. The AI company said the incident dates back to January 2026 and involved an early version of Claude Opus 4.6 that breached "Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Dental contractor set up secret account with access to 4,000 patient records then left the company

The Register - Anti-Virus - 10 Září, 2026 - 09:00
PWNED Welcome back to PWNED, the weekly column where we highlight examples of how not to handle your security. This week’s tale of woe comes from a very unhealthy part of the healthcare sector. Have a story about someone leaving a gaping hole in their network? Share it with us at [email protected]. Anonymity is available upon request. Our story comes courtesy of Chris Kirksey, founder and CEO of Direction, a digital marketing and SEO company that works in the healthcare industry. He also does security audits of his clients’ systems. Last year, Kirksey was checking out a dental practice’s systems and noticed something strange. There were three accounts that had admin access to the patient database, including one that belonged to a scheduling company the dentists had stopped using all the way back in 2021. The account had been active for at least three years and could access 4,000 patient records. Leaving an unnecessary account with access to protected health information created a potential HIPAA compliance risk, particularly if someone no longer authorized to view the data could still get to it. The office manager responsible for using the system didn’t even know that this dangerous login existed. Apparently, a contractor who set up the account never told anybody, then left the company. Because no one knew that the account existed, no one knew to kill it. Kirksey immediately set about getting rid of all three admin accounts he found on the dental practice’s system. He then set up new policies for his client. “I built a permanent rule after that,” he said. “Every vendor relationship that ends now triggers an automatic access shutdown and the full list gets reviewed twice a year no matter what.” Since the incident, Kirksey has found similar security holes at six other healthcare practices he has worked with. Yikes! “Everyone worries about the sticky note with a password on it or the file just called passwords.xls, because those get caught fast and make a good story,” he told us. “Nobody worries about the login they forgot even exists, and that is usually the one still wide open years later, causing real, unseen damage.” The lesson here is pretty straightforward. You need to see all of the accounts that have access to your data and make sure that they all have a reason to exist. Conduct regular audits, even if nothing seems wrong. And, as we’ve seen before, zombie accounts can kill. When an employee or contractor leaves, check not only which accounts they used, but also which accounts they created while doing the job. ®
Kategorie: Viry a Červi

Trezor warns users of email provider breach, phishing attacks

Bleeping Computer - 10 Září, 2026 - 08:56
Trezor warned customers on Wednesday that threat actors who breached its third-party email provider are targeting them in phishing attacks. [...]
Kategorie: Hacking & Security

Dánská skupina Guardsix kupuje brněnský Logmanager. Manažer Tobola slaví druhý velký exit

Živě.cz - 10 Září, 2026 - 08:45
Brněnský manažer Jiří Tobola podruhé prodal zahraničnímu kupci vlastní firmu, tentokrát Logmanager dánské skupině Guardsix. • Tobola dovedl Logmanager k obratu 130 milionů korun a spoléhal spíš na tradiční B2B prodej než na rizikový kapitál. • Za úspěchem stojí i brněnský inovační ekosystém ...
Kategorie: IT News

Praha zvažuje okružní linku metra okolo centra. Nové spojení má ulevit přetíženým trasám a propojit okrajové části

Živě.cz - 10 Září, 2026 - 07:45
Praha prověří možnost vybudování 22 kilometrů dlouhé okružní linky metra E • Plánované spojení propojí okrajové čtvrti a uleví přeplněnému centru metropole • Finální podobu i vysoké náklady projektu posoudí studie proveditelnosti
Kategorie: IT News

Nova Lake letos nevyjde, Q1 2027 pro 28jádrovou verzi, „později“ pro 52jádrovou

CD-R server - 10 Září, 2026 - 07:40
Navzdory tomu, že Intel dlouhodobě a opakovaně hovořil o vydání Nova Lake v roce 2026 a toto stanovisko nikdy nedementoval, se podle informace od partnerů Intelu s letošním vydáním nepočítá…
Kategorie: IT News

Anthropic maps three AI futures for 2030; the most extreme could upend the economy

Computerworld.com [Hacking News] - 10 Září, 2026 - 04:16

AI is evolving faster than most people, even those building it, could even fathom, and its impact on the workforce and the economy is, at this point, really anyone’s guess.

Researchers from The Anthropic Institute are offering a few possibilities: They have built a nuanced framework looking at how AI might impact jobs, unemployment, and gross domestic product (GDP) growth between now and 2030.

They posit three potential scenarios for an AI-augmented future: “modest,” “substantial,” and “extreme,” and have created an interactive tool where users can explore how productive, or disruptive, AI will become in the workplace, based on their predictions of how they will work in 2030.

“Which of these worlds we are heading toward may become clearer within a year or two, and preparing for potential disruption seems to us the prudent course,” the researchers noted.

The goal of their work is to inform debate as AI becomes more powerful and capable. “AI is likely to reshape the US and global economies in profound ways in the coming decade, but how, and by how much, is extraordinarily uncertain,” they wrote.

How different scenarios could play out

If you add up every single task performed by people, machines, and software, the US has created a staggering $30 trillion in value over just the last year, the Anthropic researchers estimated. Their model and the corresponding tool are a way to explore how AI impacts tasks that contribute to the economy, the tasks it augments and creates, impacts on productivity, and speed of adoption.

“The answers to these questions have direct effects on GDP, the labor market, and the share of the pie taken home by workers,” they wrote.

Under their definition of “modest” change, AI will add less than half a point to GDP by 2030, meaning it will increase the growth rate of the national economy by just 0.5%, and will raise unemployment by just a tenth of a point, a minor shift. In this future, it’s difficult to see AI’s impact in macroeconomic data; change is steady but gradual, similar to that of the internet. “It drives real economic gains, but they’re within the historical norm for new technologies,” the researchers noted.

In the “substantial” scenario, AI will be capable of doing half of all knowledge work by 2030, the majority of it autonomously. Still, it wouldn’t be adopted for all work; in fact, most knowledge work tasks would still be completed without AI. Correspondingly, the economy would grow at twice its normal rate, but even as some non-knowledge workers see gains, wages for knowledge workers wouldn’t rise.

In this case, “AI makes a bigger impact than the internet, or the railroad,” the researchers wrote. Reallocation could be costly, but it is in line with what the US labor market has historically absorbed.

In the “extreme” scenario, of course, AI would be more productive than humans on the majority of knowledge work tasks, would do all of them autonomously, and subsequently would create no new knowledge tasks for humans.

The technology would “drive a completely transformed, unprecedented economy” arising from recursively self-improving AI. GDP growth would rise to 15% per year, but nearly one in five cognitive workers would be unemployed, and their relative wage would fall “immensely.”

The conundrum is that resources to compensate unemployed or under-paid workers will exist, but it’s unclear whether they would be fairly allocated. Mechanisms by which people can benefit from a much richer economy (retraining, income support, or universal basic income, for example) would become a question of economic policy.

“Whether and how those resources reach the people who bear the cost is not something growth delivers by itself,” the researchers wrote.

What users think

As well as developing the framework, the Anthropic researchers conducted a survey among roughly 11,000 Americans, asking them to predict AI use, productivity gains, automation versus augmentation, and displaced work.

They found that, in the main, public expectations land around the “substantial” scenario. That is, GDP would be 10% higher by 2030 than it would be without AI, and the overall unemployment rate would rise to around 5%.

Roughly 10% of respondents, on the other hand, had views in line with the “extreme” scenario.

Anyone can generate their own forecast using the researchers’ interactive tool, answering questions like: “Out of every 100 instances of a task AI can do in 2030, how many will AI actually be doing?”, “How many will be fully automated?”, or  “How much more gets done in an hour in 2030, compared with doing the tasks without AI?” The tool then responds, mapping their predictions to one of the three scenarios.

“Ultimately, what the economy looks like in 2030 depends on many factors, like what AI can do, and how companies and workers choose to adopt it,” the researchers wrote. “It also depends on how the financial benefit of this technology is shared.”

The between-the-lines reality

Sanchit Vir Gogia, chief analyst at Greyhound Research, emphasized that the Anthropic research “maps the conditions under which very different futures appear, it does not schedule destiny.”

He sees the distribution result, rather than the unemployment result, as the serious finding. In the extreme case, GDP is 32.4% above the no AI path, and the cognitive wage bill is 31% below it. Labor’s share of income falls from 60% to 45.2%, and capital income rises 81.4 %. That means a full 15% of GDP is captured as ROI rather than being paid out in labor costs.

In other words, he pointed out: “A richer economy is not automatically a fairer one.” Capability, diffusion, productivity, automation, and occupational friction all have to arrive together.

“AI will touch a large and rising share of knowledge work and will execute a much smaller share under independent authority,” he said. There is no single honest adoption percentage, because worker use, company use, technical exposure, and executed task instances are four different measurements.

Lessons from the research

Enterprises can take important lessons from the research as they deploy AI and consider its impact on their systems, workflows, and workforce, Gogia said.

“For enterprises, the binding variable is permission to delegate,” he noted. “A model that can draft a payment instruction is not thereby permitted to move money.”

His firm identifies five recurring concerns that come up in enterprise conversations: Durable returns after the full cost of deployment, control over authority being granted, augmentation quietly becoming substitution, erosion of professional formation, and fairness of how gains and risks land.

Some of those changes are progressing faster than the governance around them, he observed. Once a system can inspect customer data, change configurations, or act on workforce records, autonomy has stopped being a feature and has instead become an allocation of institutional authority.

“And the tasks easiest to automate are frequently the tasks through which judgement is learned,” he noted.

Kategorie: Hacking & Security

Shattered Pixel Dungeon 4.0.0

AbcLinuxu [zprávičky] - 10 Září, 2026 - 03:33
Open-source hra Shattered Pixel Dungeon (Wikipedie) byla vydána ve verzi 4.0.0. Přehled novinek v příspěvku na blogu.
Kategorie: GNU/Linux & BSD

Layoff remorse: Gartner says at least one in three positions eliminated by AI will be restored by 2029–at a higher cost

Computerworld.com [Hacking News] - 10 Září, 2026 - 03:27

Gartner on Wednesday said that it expects 30% of the positions eliminated by AI-related layoffs to be refilled by 2029, suggesting that the initial terminations were ill-advised and excessive.

“When business and IT executives look back on the early AI era, they will realize their greatest mistake was believing that work automation was the point, when workforce amplification was the opportunity,” said Tori Paulman, VP analyst at Gartner. “The competitive advantage will go to the CIOs and business executives who build an AI-shaped organization where AI value compounds by reshaping roles and allowing workflows to cross traditional boundaries, increasing velocity and reducing friction.”  

The Gartner report noted that it is finding that the cuts “deplete talent pipelines and erode institutional knowledge.” Beyond the immediate workforce disruptions associated with any mass layoff, companies will also face steep increases in costs for recruitment, training, and onboarding.

It also predicted that, by 2027, “75% of organizations that prioritize capturing AI productivity gains as cost savings will be eclipsed by competitors that aggressively reinvest those gains into innovation, modernization and upskilling.”

In an interview with Computerworld, Paulman said that the 30% figure represents the average impact on organizations of all sizes; they estimate that the layoff boomerang for enterprises would be even higher, roughly 40%. 

Paulman said that Gartner’s research found a lot of what they called “AI washing” by executives who want/need to do layoffs for purely budgetary reasons, and will falsely blame AI for the reductions because it makes them look better.

“More than 50% of our enterprise clients have been given a number [by their bosses],” Paulman said, and have been told by senior management to find that percentage of savings from AI.

But despite widespread evidence of problems due to AI-related layoffs, such job cuts are still increasing

Layoffs were ‘excessive’

Other analysts and consultants agreed with the Gartner suggestion that many of these job losses attributed to AI are going to be walked back, but questioned the specific statistic. Some also noted that 70% of the AI-attributed layoffs may remain in force, which would suggest that the original terminations were mostly justified. 

However, Frank Dickson, principal analyst at Dickson Research, argued that a lot of the layoff reversals will occur in a variety of ways that will obscure the fact that they are restoring a terminated role. 

“A lot of that 70% never shows up as a clean rehire even when the original cut was wrong,” he said, pointing out that some of the losses caused service to quietly get worse, and stay poor, some of the work was contracted out or offshored, some of the roles were reconstituted with a different position or title, and some was covered by the remaining staff absorbing the load. This,” he noted, “shows up later as burnout and attrition, not as a line item on this report. None of that gets counted in the 30%, and none of it is evidence the original call was sound.”

Melody Brue, principal analyst for Moor Insights & Strategy, added that the 70% scenario “could show that a substantial share of the AI-related workforce reductions is durable,” but, she stressed, “it shouldn’t be mistaken for endorsement of how those layoffs were made. What it doesn’t show is whether the organization captured the full economic value it expected. A lower headcount is not by itself evidence of a successful AI transformation.”

Valence Howden, advisory fellow at Info-Tech Research Group, questioned the methodology behind the calculation of Gartner’s 30% figure, but he agreed with the overall sentiment that layoffs attributed to AI have been excessive.

“I’m not sure we can substantiate those numbers, since it’s much more of a guesswork statement than anything else,” he said. “I do believe the current trend is going to lead to rehiring, especially as AI governance requirements ramp up and given AI’s lack of contextual semantic understanding. We know AI has not provided the value proposition that it has been sold as providing, and unless costs are controlled, it will be cheaper to use humans to perform some of the advanced work.”

Supporting data

Dickson also raised questions about the Gartner report because it lacked comparative layoff statistics. 

“Gartner doesn’t say what the reversal rate looks like for ordinary layoffs, the ones that have nothing to do with AI,” he said. “Suppose normal cuts get walked back at 10% to 15% in a typical five-year window, which is plausible given ordinary churn and business-cycle rehiring. A 30% rate specific to AI-driven layoffs would still run well above that, and that’s a damning number. Without that comparison, 30% is just a figure floating with no anchor.”

However, Dickson pointed to various datapoints supporting the position that AI layoffs have been excessive, noting that Forrester reported that 55% of businesses “already regret AI-driven cuts and are predicting half of those layoffs get quietly reversed.” 

“Robert Half puts it at a third of hiring executives who eliminated roles for AI having already rehired. Ford, IBM, Booz Allen Hamilton, Alphabet and CSX have all walked back cuts or announced rehiring drives,” Dickson said. “Gartner’s 30% by 2029 sits comfortably inside that range.” Klarna has also walked back AI layoffs. 

A ‘major indictment’

He added that many AI layoffs amounted to a corporate version of a crash diet. “You cut fast, you look great on the next earnings call, and eighteen months later, the weight is back, plus interest, because nobody fixed why the cut was made in the first place.”

Gartner’s Paulman agreed, noting, “business and IT executives who use AI primarily as a tool for cost cutting risk making reductions that are too deep and too soon, affecting their ability to innovate their business model and compete in new markets as AI continues to mature.”

Mike Wilkes, enterprise CISO at Aikido Security, said that even if the 30% figure turns out to be accurate, it is a major indictment of the layoffs. 

“If 30% of AI-driven layoffs must be reversed, that is an enormous error rate for a strategic workforce decision,” Wilkes said. “Imagine any other major capital decision where nearly one-third had to be unwound at a premium three years later. No CFO would call that a strong outcome.”

Kategorie: Hacking & Security

Anthropic reveals fourth likely crime committed by its AI

The Register - Anti-Virus - 10 Září, 2026 - 01:20
Amid industry soul-searching¹ about the possibility of AI improving itself to the point that it kills everyone, Anthropic has revealed yet another incident that would qualify as a crime if perpetrated by a person. The AI biz published "an alignment assessment" detailing four times Claude models accessed third-party systems without authorization. The company has already reported three of the incidents. Evidence of the fourth was lurking in a session transcript dating back to January 2026 when the misbehavior occurred. Anthropic found the first three by scanning around 141,000 transcripts where Claude could have obtained internet access during evaluation. It missed the fourth initially because "our scan relied on an agentic search." Felony Bench, a tongue-in-cheek record of cyber intrusions carried out by major AI companies without consequences, has added this newly-discovered incident to its rap sheet of rogue AI actions. The January 2026 AI trespass involved an early version of Claude Opus 4.6, which was given a Capture the Flag (CTF) challenge under the oversight of the third-party model evaluator where the other hacking events occurred. Opus 4.6 managed to sabotage its chances of success by disabling the machine it was targeting. It assigned the device an IP address that already existed on another piece of hardware, rendering the target unreachable and making it impossible to solve the challenge. Those familiar with other incidents where AI models violated third-party systems may recall that unsolvable tasks represent a common catalyst for misbehavior. Models exhaust all aligned options, and then turn to transgressive approaches. Opus 4.6 might have been an exception, but when it tried to abort the task after recognizing that it could not reach the target machine, it failed to do so "due to a misconfiguration in [the model's] evaluation harness." It failed to shut down not just once but seven times. So it continued onward, trying other expected means to reach the target machine but failing. Then it explored further. "The model discovered a machine belonging to a third party that it was able to access, and stated that it believed this third party was part of the CTF," Anthropic explained in its post. "Inside the machine, the model found a file listing a password, which it used to gain admin access to the system." The model went on to gather more credentials, and modified a system setting to make it easier to access the personal information of an individual associated with the third party evaluation organization. Opus 4.6 might have done more but for the fact that it exhausted its token budget, bringing the session to an end. Anthropic says it's not as concerned about this incident as the others because the model tried to abort its task. "While the model’s disregard for the possibility that it might be harming real systems or people is concerning, many of the behaviors described here have changed considerably as our training has evolved across model generations," the company said. Anthropic said it considers these incidents serious but expects current training approaches "are likely able to address the specific alignment failure modes observed in these incidents." And if company training methods fall short, there's no real consequence to anyone at Anthropic other than writing up a revised alignment assessment. ® ¹ The term "soul-searching" is figurative and is not intended to indicate a belief that the technology industry has a soul.
Kategorie: Viry a Červi

Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits

The Register - Anti-Virus - 10 Září, 2026 - 00:28
At least four espionage groups, most with suspected links to China, are using a new exploit kit that chains two Chromium-based browser flaws and one Microsoft Windows bug to break into organizations' networks in the US and Southeast Asia. Mark Kelly, a threat researcher at email security shop Proofpoint, told The Register that the researchers don't know exactly who was targeted, nor how, and so far the damage appears limited. “In terms of organizations targeted, we saw fewer than 20 organizations globally targeted across the activity highlighted," he said. "However, the true number is almost certainly higher than this.” Proofpoint’s threat hunters spotted the new kit, which they named BlueMoon, and said its first observed use started on August 28. This is when a Beijing-backed crew they track as TA412, also known as Violet Typhoon and APT31, used BlueMoon to “repeatedly” target non-governmental organizations (NGOs), mining companies, and physical commodity trading firms in the US. TA412 is a cyberespionage group linked by US authorities to China's Ministry of State Security (MSS), and American prosecutors previously charged seven alleged members with conspiracy to commit computer intrusions and wire fraud, alleging they broke into computer networks, email accounts, and cloud storage belonging to numerous critical infrastructure organizations, companies, and individuals. Just days after Proofpoint documented the late-August activity, “several other espionage-motivated clusters began using BlueMoon, the majority of which have a suspected China nexus,” Kelly and fellow researchers Greg Lesnewich, Konstantin Klinger, Saher Naumaan, Julia Paluch, David Galazin, and Stuart Del Caliz said on Wednesday, noting that there may be other, non-China-nexus attackers using the exploit kit as well. “BlueMoon was developed and deployed rapidly, and shared across multiple threat actors within days,” Kelly told The Register. “This may reflect a reduced cost and barrier to entry for this class of capability, which has historically been rare and high value, as AI agents increasingly enable threat actor exploit development. That is particularly true for open-source codebases such as Chromium, where publicly accessible upstream patches create a ‘patch-gap’ window for rapid reverse engineering and exploit development ahead of downstream stable releases.” A Google spokesperson declined to comment beyond what Proofpoint wrote. Microsoft patched the Windows bug (CVE-2026-85880) on Tuesday, and a spokesperson reiterated that customers who applied that patch are protected. BlueMoon attack chain The kit chains together three vulnerabilities. The first is a V8 type confusion (CVE-2026-85046) flaw that allows remote code execution and affects all Chromium-based browsers, including Google Chrome and Microsoft Edge. Google patched this bug in Chrome on September 3, and at the time warned that it “is aware that an exploit for CVE-2026-85046 exists in the wild.” Microsoft published a security advisory saying it fixed the flaw in Edge Stable version 152.0.4191.62 on September 2. The second is a Chrome V8 sandbox escape. This one also affected all Chromium-based browsers. It does not have a CVE because Google doesn’t issue them for sandbox escapes. Finally, the third bug is a privilege escalation vulnerability in Windows Advanced Local Procedure Call (CVE-2026-85880) that Microsoft patched on Tuesday, as noted above. Redmond also warned that this flaw had been exploited as a zero-day prior to the security update. The Proofpoint researchers also note that both V8 vulnerabilities are what’s called "patch-gap" zero-days at the time of the observed activity. This means they were known and fixed in upstream Chromium source code – a change containing the fix for CVE-2026-85046 was committed on August 7. But they remained unpatched in the latest stable releases of Chrome and Chromium-based browsers available to the public for weeks. “It is likely that the exploit kit developer used these publicly available Chromium patches to weaponize the browser exploit chain,” the researchers note. From phishing to browser surveillance The attacks start with a phishing email that tricks victims into clicking on an actor-controlled URL. This triggers the two V8 bugs to allow remote code execution and escape the browser sandbox. The attack chain then exploits the Windows bug to download multiple payloads including browser-surveillance malware, credential-stealing backdoors, and others, depending on the group using the exploit kit. TA412’s first campaign, which began on August 28, used a range of lures. Some of the emails purported to come from university students interested in internships at the targeted organizations, and some were more target-specific exchanges, intended to build trust with the individual before ultimately sending a malicious link via email. In these instances, the exploit chain “ultimately downloaded and ran a loader executable on the infected host, which then installed a malicious browser extension disguised as Google Gemini on the victim's Chromium-based browser,” the team wrote. This browser extension, which Proofpoint tracks as GemStone, allowed the Beijing spies to issue commands through a command-and-control (C&C) channel, steal cookies and other sensitive data, take screenshots, and inject a keylogger into a browser tab. The malware also contains a keyword monitor, which injects an attacker-specified keyword list into the top frame of each page, scans the HTML body for these keywords, and triggers a screenshot if it finds any. A few days later, beginning on September 2, a second China-aligned spy crew that Proofpoint tracks under the temporary group designator UNK_LateNight used BlueMoon to target multiple US aerospace companies. The phishing emails used request-for-quotation lures specific to defense industry organizations, and included links to attacker-controlled domains spoofing a variety of US aerospace companies. These websites also served the BlueMoon exploit kit and ultimately loaded a backdoor called ShadowPad, which has been shared among multiple China-aligned groups since 2019. Around this same time, on September 2, another suspected espionage group that Proofpoint tracks as UNK_DoubleCheck targeted a Vietnamese manufacturing firm with messages sent from a compromised Southeast Asian government email address. The fourth campaign began a day later, and involved suspected China-linked spy crew UNK_QuietRacket using BlueMoon to target government, consulting, and financial-sector organizations in Indonesia and Singapore. These phishing emails used lures related to Indonesian conferences, such as the Indo Startup Expo and Forum 2026 and the World Conference on Creative Economy (WCCE 2026). Proofpoint warns that BlueMoon will likely be used by both cyberspies and financially motivated attackers. “The broader dynamic revealed by this activity - rapid exploit development that leverages the open source patch-gap – is likely to recur beyond BlueMoon as this development model becomes accessible,” the team wrote. ®
Kategorie: Viry a Červi

Jaderné noviny – přehled za srpen 2026

AbcLinuxu [články] - 10 Září, 2026 - 00:01

Přehled srpnových vydání Jaderných novin: stav vydání jádra, citáty týdne a seznam článků týkajících se jádra.

Kategorie: GNU/Linux & BSD
Syndikovat obsah