Agregátor RSS
Patch work often gets declared finished at the package manager. The update installs, version inventory changes, the service restarts, and the ticket begins moving toward closed. That sequence is clean. Production rarely is.
Finanční skupina Partners se stala minulou neděli obětí kybernetického útoku, při kterém se útočníci dostali k některým osobním údajům klientů. Společnost o tom informovala ve čtvrtek. Ujišťuje, že peníze klientů nejsou v ohrožení. „Kybernetický útok zasáhl část IT infrastruktury naší společnosti. Ihned po zjištění útoku jsme s pomocí externích bezpečnostních odborníků začali intenzivně pracovat na minimalizaci škod. Útočníci se však bohužel dostali k osobním údajům klientů Partners Financial Services,“ uvedla skupina v e-mailu, který ve čtvrtek obdrželi její klienti. Zasaženy byly Partners Financial Services, pojišťovna Simplea, penzijní společnost Rentea, Partners investiční společnost a slovenská Simplea Financial Services. Samotnou Partners Banku ani její bankovní systémy útok nezasáhl [Novinky.cz, 𝕏].
PWNED Welcome back to PWNED, the weekly column where we explore the frightening and amusing world of foolish infosec errors. This week, it's all about a test site that exposed real information. Have a story about someone leaving a gaping hole in their network? Share it with us at [email protected]. Anonymity is available upon request. Our story comes courtesy of Mia Morin, Editor & AI Quality Analyst at Intimeros, a site that rates, reviews, and evaluates AI companions – yes, that means boyfriends and girlfriends, as well as other kinds of pals. The trouble started during a redesign when one of Morin’s colleagues was working on a test version of the site. The test site was supposed to be password-protected, but the colleague turned off the protection so they could show a client what they were working on. Password protection remained disabled for three weeks without anyone noticing. Then, one day, Morin noticed that the test site had been indexed by Google. Apparently, nobody thought to use a robots.txt file to exclude this beta-level domain from search. While the site was publicly accessible without password protection, anyone could see unpublished reviews, prices, and private product notes about the different AI companion services. That’s because the test site was connected to a real live version of the production database. This was all editorial content, so no user data was exposed. However, it could have allowed competitors to see everything that Intimeros was working on and to deduce their entire editorial strategy. After she noticed what was wrong, Morin took swift action to protect the test site from prying eyes. “We restored password protection, blocked search engines from indexing the draft pages and changed all the system access keys,” Morin said. “Now, we secure every test site just like our official website and run weekly automated scans to catch exposed pages.” What we can learn from this is kind of obvious. Never forget to lock down the test or staging versions of your websites. Make sure that they not only require logins, but also have tools in place to block search and AI crawling. Better still, place your staging site on a private server and require someone to use a VPN to get to it in the first place. ®
OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior as early as late May.
The incident, the company said, took place during cybersecurity evaluations of several OpenAI models, and that it was mainly fueled by what it described as a "highly capable
OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior as early as late May.
The incident, the company said, took place during cybersecurity evaluations of several OpenAI models, and that it was mainly fueled by what it described as a "highly capableRavie Lakshmananhttp://www.blogger.com/profile/ [email protected]
Chtěli byste mít pěkné fotky z mobilu, ale nějak to nejde? • Zkuste se řídit podle následujících doporučení • Kompozici za vás nikdo nevymyslí, ale techniku zvládne každý
Nejen houbičky a smrtící infekce dokážou rychle vyhubit lidstvo. Vybrali jsme nejlepší a nejznámější filmy, které ukazují, jak si lidé poradí (nebo taky neporadí) se zhroucením společnosti a různými katastrofami. Některé jsou smrtelně vážné, některé akční a některé... velmi odlehčené.
The controversial Omarchy distro is attracting both criticism and fans – and financial support, too. Omarchy is an opinionated respin of Arch Linux and a pet project of Ruby on Rails creator David Heinemeier Hansson, better known as DHH. Although the first release was as recent as June last year, this week sees the release of Omarchy 4.0.1 – a security fix for the mid-August Omarchy 4 “Quattro”. Although it started out just over a year ago, Omarchy now has a sibling project Omakub, which is based on Ubuntu, and an organization behind it called Omacom. A week ago, DHH announced the launch of the Omacom Foundation with $8 million. Its founding patrons include figures behind Shopify, Stripe, Dell, Block, Cloudflare, Sesame, and 37signals - closely followed by people behind Dropbox and OpenClaw, taking the total to $10 million. The project, like the man behind it, is controversial. But that means attention, and an “opinionated distro” gets opinionated reviews. Some of the criticism is strong stuff: for instance, Merchants of Insecurity, whose top line is: “First, a PSA: Do NOT use Omarchy if you care about security of your machine even a little bit.” Author “One Happy Fellow” is not the first: last year, a member of Framework's community forums posted Omarchy is not a secure distribution and should be taken off the Linux installation options. Others like it or give it a guarded thumbs up while saying it’s not for them. There really is no such thing as bad publicity. As P. T. Barnum put it: "Say anything you like about me, but spell my name right." DHH is no stranger to controversy. We suspect he doesn’t mind at all. The Register reported in late 2025 that Framework, known for its repairable laptops, was sponsoring Omarchy and Hyprland, and in turn, multiple people criticized Framework for sponsoring such controversial projects. That piece linked to some of the criticism of DHH, but he has been attracting criticism since at least 2014. We tried it, and it does work. It has a unique UI based on the Hyprland tiling compositor and a panel and menus provided in the new release by Quickshell. This is heavily keyboard-driven, but ignores almost all existing keyboard shortcuts and UI conventions from other OSes. There are no title bars, let alone close buttons or anything like that. No middle-click or right-click app menus. The jaded take of the Reg FOSS desk, who is a big fan and advocate of keyboard-driven UIs, is that such things usually reflect ignorance of existing user interface standards. We found it a bit clunky. We had to install an additional tool, hypermon, in order to be able to make our testbed machine’s second display useful. You can’t use established pacman commands to update it – you must use the custom omarchy update script, and when trying that in a VM, we hit a known bug. On hardware, it worked fine. It’s Arch, extensively preconfigured. Lots of apps are preinstalled, and the selection is surprising and not typical of a FOSS product. The selection includes Discord and WhatsApp for communications, Docker, Obsidian for note-taking, Neovim as an editor, and OBS Studio for streaming. There are optional extras for using speech, automatic dictation via Voxtype, and other unusual features. There’s a terminal-based music player, cliamp. (We like the name of that one, and may keep it around.) There are, of course, options to add AI tools – one of the startup messages invites you to configure your preferred plastic pal who’s fun to be with LLM bot. It’s pretty big. A default install (not that there is any other kind) took 14 GB of disk space after the first update. It did install in a VM with a 16 GB virtual disk, but there wasn’t enough disk space to update the OS. It uses about 1.5 GB of memory at idle. It’s not lightweight, but then, Omarchy definitely comes with batteries included, as well as (to quote a friend’s old email signature) “bells and whistles, plus a couple of gongs. Don’t forget the horns, the custard pies and the water-powered whirling knives.” If you don’t know your way around existing environments or distros, want something fashionable and snazzy looking, and are willing and happy to jump in and learn, then this is an interesting new option. You may not agree with the politics and views behind it, but you must be able to either tolerate them – or ignore them. It works, it’s quite fast, it looks striking, and it does the job. If you just want something clean, fast, pretty, and with tiling by default, personally, we’d suggest Pop!_OS instead. ®
Už od 4 000 Kč lze najít velmi povedené herní monitory. Vzali jsme je do srovnávacího testu, abychom určili, který z nich je nejvýhodnější.
PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. [...]
The Manchester Airports Group (MAG) disclosed that hackers breached its systems and stole customer data, including Wi-Fi sign-ups from Manchester, Stansted, and East Midlands airports. [...]
Adobe has added a simplified editing mode to Photoshop designed to help new users get acquainted with the popular image editing app.
AI Assisted Editor, now available in beta, is an optional alternative to the standard view — now called Pro Editor mode — that provides a prompt-based interface similar to the Firefly editor rather than the full range of Photoshop tools. It includes a side panel that contains generative AI (genAI) features such as Generative Fill, Remove Background, and AI Markup, as well as a text prompt box.
The more streamlined editor view could also prove useful for existing users that don’t need the full workspace for every edit, Adobe said. More seasoned professionals might switch to the AI Assisted Editor for concepts or mock ups, or for quick editing that doesn’t require the full set of Photoshop functions.
For those who don’t need it, however, the new mode can be hidden from view.
Among the other Photoshop features unveiled Thursday is Prompt to Edit, which lets users apply changes to an entire image with a simple prompt — for example, adding stormy clouds and rain. That creates an output layer that can then be modified, such as masking out image elements or changing the opacity.
Prompt to Edit is available in both AI Assisted and Pro Editor views.
A new “markup” feature lets users “visually communicate” edits to Firefly by drawing onto an image, indicating areas to recolor, for instance. This makes it easier to direct the AI model compared to text prompts. The Instruct Edit with Masks, which relies on Firefly Image 5, lets users specify what elements of an image to change with text prompts, with unmasked areas left untouched.
Other updates include Light Adjustment Layer, which provides “professional-grade” lighting controls, such as exposure, contrast and shadows, in a non-destructive adjustment layer, Adobe said. A Stock Panel integration provides access to more than 900 million Adobe Stock assets in Photoshop via a dockable panel, while another addition, Dynamic Text, Shapes and Paths, automatically adapts text along curves as freeform layouts.
Bill Gates sepsal esej, která varuje před riziky masového nástupu umělé inteligence. Vysvětluje, jak si lidstvo zvyklo, že technologické průlomy vytvořily více pracovních míst, než jich zrušily. Jenže takové analogie jsou tentokrát zavádějící. „Éra umělé inteligence je zcela, absolutně, úplně, ...
The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) said it’s responding to a “major” cybersecurity incident shortly after the Qilin ransomware gang posted the US federal law enforcement agency on its leak site. An ATF spokesperson told The Register the intruders accessed a “standalone computer system containing information about targets of ATF investigations” that wasn’t connected to any other ATF systems. “There is no indication that the incident has affected the ATF enterprise network, the ATF eForms system, or any other ATF system,” according to a statement posted on the firearms agency’s website. The spokesperson declined to answer any additional questions about the breach, including Qilin’s claims, the ransom demand, and what data was stolen or how much. “ATF is unable to comment due to an ongoing investigation,” the spokesperson said. ATF, which is housed under the US Department of Justice, said it’s “coordinating closely” with the DOJ to investigate the breach, and “immediately” blocked connections to the affected IT environment upon discovering the incident. The statement said the security breach had not affected ATF’s operations and noted that senior Justice Department officials designated the compromise as a “major incident” under federal guidelines. Shortly before ATF posted its security-incident notice on its website, Russia-linked Qilin ransomware criminals listed the firearms agency on its leak site. The post, seen by The Register and shared on social media, did not say what data Qilin claimed to have stolen, how much, or provide samples to substantiate the claim. Qilin, the notorious crew behind the 2024 attack on pathology provider Synnovis that disrupted NHS services in the UK, was one of the most prolific ransomware gangs in July, according to Comparitech. The firm, which reviews cybersecurity products and provides data analysis, counted 799 ransomware incidents last month, up from 668 in June. Qilin claimed 125 of those.® Editor's note: This story was amended post-publication with comment from ATF.
It doesn’t matter what the UK government says, the majority of the UK public is reluctant to hand over additional surveillance powers that require tech companies to build backdoors to access encrypted communications. That’s based on a poll release Thursday by the Center for Democracy and Technology (CDT), a US-based advocacy group.
UK officials still want to wreck encryption
The poll comes as the UK government renews its attempts to pursue a top secret order to force Apple to build a backdoor into iCloud encryption, even if doing so will make people less safe. There’s little doubt any state-mandated backdoor would be found and exploited by today’s new generation of AI-augmented hacking systems.
The government should know this, but seems resistant to reality — though it did revise its approach to taking this action under pressure from the US. This new version targets “only” UK citizens.
What makes it worse is the underhand way the UK attempted to put these new rules in place. While we know Apple ceased offering Advanced Data Protection in the UK in response to these demands in 2025 — and opposed the demands at the time — we don’t know what arguments were made. The US said last year the order was being dropped, but Apple is now returning to court to fight a renewed attempt.
When the government issued the euphemistically-named “Technical Capability Notice” to Apple requiring backdoor access to encrypted iCloud data, it not only prohibited Apple from disclosing the order, but “most of the British public (55%) were unaware it had happened at all.” That’s because the UK kept it all out of sight. Privacy International and Liberty are also challenging the use of Technical Capability Notices.
The UK public does not agree with its leaders
CDT polled 2,000 people in the UK to find out if they supported the government’s efforts to quash encryption with dangerous backdoors. Just 12% of respondents agreed the government should have the power to access private data; the vast majority opposed the idea.
The nature of the government’s approach is that UK citizens will not be told if they’re being subjected to surveillance. That really offends people, the survey says; 87% think the government should be legally obliged to tell people when their private conversations have been reviewed.
“The British public instinctively know that being able to communicate privately is crucial to our individuality and to the survival of a free and open society,” said Jim Killock, executive director of Open Rights Group. “The government persists with the myth that it can weaken encryption to target the bad guys only. Attacks on the security of our phones, security tools and messaging apps harm us all and make our democracy weaker.”
The poll reveals a lot more. People in the UK overwhelmingly believe they have the right to private conversations online and that no one should be able to access their personal messages without a court order and user notice. They also want meaningful constraints on use of these surveillance powers and also believe — rightly — that the security risks of backdoors far outweigh any benefits.
There’s also a significant concern about the impact of encryption erosion on free speech and personal privacy. “The vast majority of the British public believe there are better ways to tackle serious crimes than accessing encrypted messages” CDT argued.
The devil in the government plan relates to encryption.
Encryption cannot be selectively weak
This is fundamental to internet communications, and a lack of secure encryption threatens all kinds of online data communication. It’s not just email; banking, finance, and everything else all rely on encryption. Any move to weaken it anywhere in the stack will weaken it everywhere else. That’s bad for people, bad for free speech, and bad for business.
Alan Woodward, visiting professor at Surrey Center for Cyber Security at the University of Surrey stressed, “Encryption keeps our bank details, medical records and family conversations safe. It cannot be weakened for criminals without being weakened for everyone. Private communication is not a luxury. It is a condition of a thriving democracy.”
Paul Strasburger, chair of Big Brother Watch, agrees: “Strong encryption is essential to protect our data and our commerce from attack by organized crime and rogue states,” he told the government last year during a debate on the matter in the House of Lords. “Any weakness inserted into encryption for the benefit of the authorities is also available to those who would do us harm — yet that is precisely what the government are demanding from Apple.”
No one wants this
What’s also interesting about the poll is that opposition to the UK government plans comes from across the political divide. “The public are not naive about online crime, but Green, Labour, Conservative, Liberal Democrats, and Reform voters alike simply do not accept that accessing everyone’s private messages is the way to stop it,” said Carly Munnelly, director at Public First.
That’s because in an accelerated, AI-augmented modern digital threat environment, no one is safe until everyone is safe. The data suggests that people in the UK recognize this. The government, meanwhile, continues to avoid meaningful public scrutiny on what it’s doing by refusing to confirm or deny that any such order exists.
You can follow me on social media! Join me on BlueSky, LinkedIn, Mastodon and subscribe to The Core.
Credit: Hacktron
Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting servers that use a Windows filesystem.
The Windows path traversal, tracked as CVE-2026-75604&
Credit: Hacktron
Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting servers that use a Windows filesystem.
The Windows path traversal, tracked as CVE-2026-75604&Swati Khandelwalhttp://www.blogger.com/profile/ [email protected]
A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine.
The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing their real behavior, exposed systems getting scanned, and exploit windows shrinking again. Different
A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine.
The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing their real behavior, exposed systems getting scanned, and exploit windows shrinking again. Different Ravie Lakshmananhttp://www.blogger.com/profile/ [email protected]
Schrödinger's Cat, the famous 1935 thought experiment, imagines a cat that, for reasons rooted in quantum physics we need not dwell on here, is simultaneously alive and dead. In a landscape of relentless cyberattacks and mounting infrastructural complexity, a routine backup task can appear finished, with every box ticked and every check made. The job is not actually done, however, until it has been verified as fully ready for recovery in the event of cyber disaster. A task that looks sorted can turn out, under scrutiny, to be anything but. A backup can be logged as 'complete' once data has been copied to storage, but a recoverable workload is another matter entirely. It means that when a business goes down, its workloads can be restored to their state at the point of attack with nothing lost. By the time you realize you are on the wrong side of that ambiguity, it may be too late: your data is in the hands of the bad guys, or destroyed, and this time the cat really is dead. This is not a problem to which IT bosses and managed service provider (MSP) management are entirely oblivious. Most organizations recognize to some degree that their backup may not be 100 percent watertight. Cybersecurity management specialist Kaseya recently partnered with 1105 Media to survey 200 IT professionals about the realities shaping cyber resilience planning. Some 53 percent were no more than 'somewhat confident' in their organization's ability to fully recover from a ransomware attack, and admitted their backups were supported by no better than 'limited testing'. A significant proportion had even less faith in their recovery capabilities, while only 15 percent were 'very confident' they could get back on track with no loss. Verify and survive Understanding what a verified backup means, and what role verification plays in the recovery challenge weighing on so many IT leaders, is where any sensible resilience plan begins. Backups are vital but they do not guarantee recovery on their own. What matters is confirming that a backup job will hold up in a disaster. Verification is the process of proving that backed-up data is complete, uncorrupted, and fully restorable in an emergency, offering evidence that recovery is possible during a critical outage, hardware failure or ransomware attack. It is essential whether you run an IT department or an MSP responsible for client protection: unless you can prove clients are protected, there is every chance they are not. "Backup isn't done and entrustable until you've gone in and made sure that the application actually works and can be brought back to the recovery environment," explains Brent Torre, GM of cyber resilience at Kaseya. "Historically, it's just taken too much time and resource for a lot of people to even attempt that. And where they have been verifying, they haven't been doing it regularly enough to ensure real protection." Not all approaches to verification are of equal value. IT departments still relying on intermittent manual verification are operating on blind trust: warnings thrown up by the process can be misread, failures overlooked, and the result is a dangerous mix of false negatives that waste time and false positives that expose the organization to real risk. Manual screenshot verification is a proven way to squander a security budget , tying up highly qualified staff on needless work and pulling their expertise away from where it is genuinely needed. Nobody wants seasoned engineers spending hours reviewing screenshots, second-guessing outputs and trying to determine whether a backup worked. Where static verification methods once had a place, today's complex IT ecosystems have made them redundant. Across an estate spanning in-house systems, SaaS and cloud endpoints, basic verification cannot cope, picking up only surface-level signals and lacking the design to operate at scale. At scale, the inefficiencies of manual verification multiply and response times slow to a crawl. A minor inefficiency can quietly become a serious bottleneck without anyone noticing, and legacy methods can create the illusion that everything is working perfectly while catastrophe waits around the corner. As Torre points out, light-touch checking is unlikely to satisfy the ever-increasing regulatory burden around recovery and resilience. "Some compliance frameworks explicitly state that you must test recovery on a frequent basis," he says. "It's becoming more important than ever that organisations are able to do that." Let AI handle the heat The emerging gold standard is AI-powered screenshot verification, which replaces the best-efforts manual checking of overstretched human teams. It works by automatically booting up virtualized backups, capturing a screenshot and analyzing the image to confirm the backup ran correctly. Where rigid, rule-based checks fall short, context-aware visual AI combined with OCR accurately identifies login screens, dashboards and maintenance states, and evaluates every element with precision. The result is 99.9 percent verification accuracy and sharply reduced false positives, alongside far greater confidence in every backup. This is welcome news for IT managers facing budget shortfalls and a drought of experienced talent, and it is what MSPs need as they try to make the economics of recovery stack up. Remove the manual effort and the constant checking of false alarms, and the gains mount quickly. Human teams are free for higher-value work, SLA confidence rises, customer trust improves, and environments can scale without ballooning overheads. AI-powered verification is no longer a maybe for today's MSPs; it is the only route forward that makes sense on the P&L. The good news is that AI-powered screenshot verification does not require major up-front investment or deep internal expertise. Datto, the cybersecurity and data protection outfit owned by Kaseya, has built the latest verification technology directly into its business continuity and disaster recovery (BCDR) platform, so that deployment stays simple and disruption to existing workflows is minimal. This kind of AI-powered screenshot verification is designed to strip uncertainty out of the process and give IT teams confidence that backed-up data is complete and recoverable. The ideal solution does so at scale, and without adding complexity, by working within the workflows already in place. With Datto there is the further option of integrating remote monitoring and management (RMM) with the BCDR product, which enables proactive remediation through automated deployments, the merging of backup health with endpoint alerts, and virtual restores launched directly from a single management console. "It's key to have context and visibility into the backup estate through your RMM so you know that you are up to date on patching, on antivirus definitions and backups," says Torre. "With all of that integrated within the RMM solution, you have the ability to understand your risk profile across the fleet in terms of protection. You know in the event that something needs to be recovered. And you can start a backup-initiated recovery directly from the RMM platform." The gold standard to aim for, he concludes, is continuous validation and automated remediation, not the ability to look in now and again to see what is going on. The perfect verification solution , he adds, should be 'impossibly easy to use', requiring humans to exert zero cognitive effort on backup beyond deploying a new client and initiating a recovery. By giving yourself the means to distinguish between a completed backup job and a recoverable workload, you have set yourself apart from the kind of IT manager or MSP who only spots a problem after something has gone wrong. By deploying AI-powered verification, you stop treating backup as a probability and start treating it as a proof. You know what you have. Then when something goes wrong, and it will, that certainty is the only thing standing between a fast recovery and a very long night. MSPs looking to unify backup and security into a single resilience practice can start with the When Backup Meets Security in the MSP Stack whitepaper. Sponsored by Datto.
|