Agregátor RSS
Anthropic has confirmed that the Department of Commerce has lifted export controls on Claude's two most powerful models, Fable 5 and Mythos 5. [...]
Anthropic is now rolling out Sonnet 5, and it's almost as good as the Opus range, but it is designed to be cheaper than the company's flagship model. [...]
Objednáváte z Temu, Sheinu nebo jiných mimoevropských e-shopů? Projděte si praktický přehled, jak se nové clo počítá, kdy ho zaplatíte a koho se týká.
Sonda do světa otevřeného softwaru. Dnes si představíme aplikaci pro pořizování poznámek, vyzkoušíme fyzikální simulátor, řekneme si o dalším hudebním přehrávači a podíváme se na verzovací platformu od Epic Games.
12GB GeForce RTX 3060 dorazila, je zpět na trhu, jenže… při kombinaci ceny, výkonu a výbavy nemá její koupě smysl. Můžete si totiž pořídit citelně rychlejší hardware za podstatně méně peněz…
…aneb Dreadnoughtus schrani a jeho biomolekuly
Katastrofální rekonstrukce Zrcadlového jezírka v parku National Mall za 15 milionů dolarů vedla k jeho dramatickému zelenání. Elegantní zelená řasa řetízkovka (Scenedesmus) se ukázala jako příliš silný protivník. Jaké přírodní mechanismy by si s ní dokázaly poradit?
V evropské archeologii existuje jen málo artefaktů, které by generovaly tolik slepých uliček a bizarních teorií jako galo-římský dodekaedr. Rád bych vám proto na stránkách Osla představil novou, i když zatím nepotvrzenou a akademickou obcí neprověřenou hypotézu. Nepřichází z univerzitních kabinetů, ale od člověka, který tráví dny údržbou historické techniky ve starém mlýně, jenž se nachází v Hněvkovicích nad Vltavou.
V evropské archeologii existuje jen málo artefaktů, které by generovaly tolik slepých uliček a bizarních teorií jako galo-římský dodekaedr. Rád bych vám proto na stránkách Osla představil novou, i když zatím nepotvrzenou a akademickou obcí neprověřenou hypotézu. Nepřichází z univerzitních kabinetů, ale od člověka, který tráví dny údržbou historické techniky ve starém mlýně, jenž se nachází v Hněvkovicích nad Vltavou.
A new prompt injection attack dubbed "BioShocking" could trick AI-powered browsers into treating real-world risky actions as part of a fictional scenario, causing them to ignore any safety guardrails. [...]
Microsoft announced today that it is accelerating its quantum-safe security roadmap, saying advances in quantum computing are bringing the need to replace today's encryption standards sooner than previously expected. [...]
A campaign active since last November has been targeting Python developers building Telegram bots with trojanized Pyrogram forks that allow attackers to read arbitrary files on compromised servers. [...]
Makers of AI browsers make lofty promises. With a single prompt, users can ask one to find a restaurant in a particular part of town, reserve a table, invite a colleague to lunch, and email a confirmation. These makers are much more reticent about the risks of blurring the once fine line between browsing sites and asking a large language model a question or instructing it to take potentially sensitive actions.
LLM developers’ answer so far has been to build guardrails that make some requests off-limits. Developing software exploits, stealing credentials, or teaching how to build a pipe bomb are examples. The problem with this approach is that the guardrails are reactive and treat the symptoms rather than solve the root cause. It’s tantamount to the manufacturer of an unsafe vehicle advocating for new road designs rather than fixing the flaws that make it prone to accidents.
Lulling LLMs into an alternate reality
New research puts this predicament on sharp display. It demonstrates how a website can lull AI browsers into a false reality where the rules governing its behavior no longer apply. After that, an attacker has free rein to invoke all kinds of destructive actions, such as extracting code from a private repository or extracting credentials from the built-in password manager. Read full article
Comments
O nástupu dovolené rozhoduje zaměstnavatel, ať již výhradně sám nebo na základě žádosti zaměstnance. Ovšem pokud zaměstnavatel neurčil do 30. 6. 2026 nástup dovolené z minulých let – loňska (2025) či dokonce předloňska (2024) nebo ještě starší, může si rozhodnout od 1. července 2026 zaměstnanec sám, kdy bude dovolenou čerpat.
Perhaps bots aren't the answer to everything when it comes to finding flaws. Fully automated pentesting has been a letdown for many security teams, according to offensive security firm Cobalt, as support for the approach has fallen sharply over the past year. Cobalt’s recent 2026 State of Pentesting report found, among other things, that security practitioners are rapidly ditching autonomous pentesting tools, in large part because they’re simply failing to detect critical vulnerabilities. Cobalt reported that 78 percent of respondents to its survey for the 2026 report experienced “critical false negatives” from automated scanning tools, with the tools quite bad at detecting the sort of vulnerabilities its AI ilk inflicts on environments in which it’s prevalent. “Automated scanners are brilliant at finding known, signature-based vulnerabilities. But they fail miserably at AI security,” the company said in a release summarizing the report’s findings. “Prompt injection exploits and excessive agency flaws require creative, multi-turn interaction chains [and] adversarial psychology,” Cobalt continued. “These logic flaws are entirely invisible to tools that test using single-shot automated queries.” A year of disappointment with automated scanning tools has led to a considerable decline in the number of organizations considering a purely automated security scanning approach, with just 9 percent of respondents saying that they were open to the idea, compared to 29 percent last year. It’s worth noting that the number of respondents to Cobalt’s survey was small - just 450 folks - but even with so few data points, the numbers are still bad news for automated pentesting vendors, but good news for infosec professionals, says Cobalt. “The drop in reliance on fully automated pentesting is actually a healthy sign,” the company said in its report summary. “It proves that practitioners are seeing through the vendor hype and demanding actual assurance rather than just coverage.” Those practitioners may also be simply overwhelmed by the number of vulnerabilities that non-security AI tools are introducing into their spaces: Per Cobalt, around 12 percent of the vulnerabilities detected in traditional environments are classified as high or critical severity. In AI and LLM environments, that number climbs to 32 percent, and that's not a new number, either. That 32 percent figure has held for the past two years, Cobalt said of its pentesting data, suggesting AI is introducing a lot more vulnerabilities. Combine those increased severity odds with automated pentesting bots that miss the sort of vulnerabilities that AI often introduces and it’s a recipe for disaster. Cobalt says the solution is hybrid security in which most systems are allowed to be automatically scanned by AI, while the most critical systems are left up to humans to protect and manage. The company sells such a solution, naturally, but it’s worth pointing out that its findings on the uptick in vulnerabilities introduced by AI aren't exactly a unique claim. Application security firm Veracode reported earlier this year that AI-assisted software development is creating more vulnerabilities than security teams can keep up with, leaving more vulnerabilities left unresolved for longer periods of time. Per Veracode, some 82 percent of companies are leaving known vulnerabilities unresolved for more than a year, while the number of high-risk vulnerabilities as a share of all discovered is rising as well. That said, not everyone is as skeptical of automated pentesting as Cobalt and its survey respondents. According to Amazon security chief CJ Moses, AI pentesting tools have made Amazon security teams 40 percent more efficient, though Moses’ measure for that figure isn’t clear. Moses still wasn’t keen on handing the entire security project off to AI, however. He told us at the RSA Conference in April that AI pentesting still needs a human in the loop to ensure it doesn’t muck something up. "AI is very good at doing things, especially when you have large amounts of data and need that big view,” Moses said in an April interview. “But from a decision-making capability, it isn't something that we're ready to rely on." ®
New Microsoft research shows how attackers can hijack AI agents that act on a user's behalf, using nothing more than a poisoned tool description to make the agent quietly hand over company data to an outsider.
The trick is that the agent never breaks a rule. Every step looks routine, so in a default setup no alarm may fire.
The work comes from Microsoft Incident Response and its
New Microsoft research shows how attackers can hijack AI agents that act on a user's behalf, using nothing more than a poisoned tool description to make the agent quietly hand over company data to an outsider.
The trick is that the agent never breaks a rule. Every step looks routine, so in a default setup no alarm may fire.
The work comes from Microsoft Incident Response and its Swati Khandelwalhttp://www.blogger.com/profile/ [email protected]
A new two-stage malware family called RustDuck is hijacking home routers, IP cameras, Android boxes, and poorly secured servers, then stitching them into a network built to knock websites and online services offline.
Researchers at QiAnXin's XLab have tracked it since February 2026, and say the real story is not how big it is today, but how fast it is changing.
The end goal is a
A new two-stage malware family called RustDuck is hijacking home routers, IP cameras, Android boxes, and poorly secured servers, then stitching them into a network built to knock websites and online services offline.
Researchers at QiAnXin's XLab have tracked it since February 2026, and say the real story is not how big it is today, but how fast it is changing.
The end goal is a Swati Khandelwalhttp://www.blogger.com/profile/ [email protected]
Nevýhodou žebříčků postavených na sledovanosti je, že jsou plné prastarých kousků, které už každý viděl. Tady proto najdete pouze nové filmy a seriály (nebo jejich nové sezóny) z posledních měsíců. Vycházíme ze statistik aktuálního zájmu na webu IMDB, které dlouhodobě ukládáme a sami zpracováváme.
|