Agregátor RSS

BPF Congestion Control Exposed Two Linux TCP Use-After-Free Paths

LinuxSecurity.com - 24 Srpen, 2026 - 14:34
A Linux TCP query can touch congestion-control memory after a concurrent BPF update has freed it. Two new use-after-free reports show how an ordinary read path inherited a lifetime assumption that no longer holds when BPF makes congestion-control objects dynamically replaceable.
Kategorie: Hacking & Security

AliExpress accused of fingerprinting shoppers with silent audio trick that also muted a dev's headphones

The Register - Anti-Virus - 24 Srpen, 2026 - 14:32
Developer Matt Callaghan claims he caught Alibaba's B2C website, AliExpress, trying to track web users by playing sounds through browsers vulnerable to audio fingerprinting. The software engineer drew attention to the issue late last week after investigating why his Bluetooth headphones stopped playing music whenever he visited the AliExpress website. “Recently I ran into a strange problem with my Bluetooth headphones,” Callaghan wrote. “They support multipoint Bluetooth audio, so they can be connected to my PC and phone at the same time. Normally, the PC takes priority playing audio, with my phone being able to play audio when nothing is playing on the PC. “Usually I listen to music on my phone but with notifications or YouTube playing through the PC, this works reliably until I open an AliExpress page in Firefox or Chrome. “Shortly after loading the AliExpress homepage, audio from my phone would stop playing. Closing the AliExpress tab fixes it immediately. Muting the tab/Firefox/Windows does not help, and there is no visible video, music, or other media playing on the page.” Callaghan tried to find any hidden conventional media elements but found nothing. Further digging revealed two audio scripts that he said were “extremely obfuscated” within AliExpress's browser security and anti-abuse tooling. He said the scripts built a WebAudio graph that introduced a sawtooth oscillator to generate a waveform, an analyzer to measure the result after the waveform passes through a browser’s audio implementation, and a script to read the associated frequency data. The scripts set the audio’s gain to zero, meaning the end user won’t hear anything, but the WebAudio graph will still be processed by the browser. “This is very different from an autoplaying video,” said Callaghan. “There is no media element for the browser's normal tab mute control to stop. As far as the page is concerned, it is performing live audio processing. “In my case, that appears to have been enough for Firefox or Windows to keep the Bluetooth audio path active, preventing my multipoint headphones from switching cleanly back to the phone.” Callaghan found further evidence in the code looking for data related to screen dimensions, device memory, browser plugins, WebGL rendering, mouse events, and more. As well as signs that AliExpress is encrypting data and sending it to its telemetry services, the developer said all of it amounts to “a fairly comprehensive browser and device fingerprint.” The Register has asked Alibaba to comment. Despite Callaghan saying he could reliably reproduce this issue on both Firefox and Chrome, Firefox issued a Xtatement saying its anti-fingerprinting technology thwarts AliExpress’ tracking tricks. It pointed to a blog post from Tom Ritter, a security engineer on the Firefox team, who explained that as of version 118 (September 2023), the protections it introduced eliminated the efficacy of WebAudio-based fingerprinting. These protections are not designed to stifle fingerprinting efforts at the source. Instead, they work to group all users together, making it look like all fingerprinted users are the same, effectively nullifying the tracking attempts. For 99.24 percent of users, they fall into one of three “buckets” – user categories delineated by types of hardware. The vast majority fall into buckets one and two: Bucket one: x86/x64 CPUs lacking FMA (Fused Multiply-Add) instructions Bucket 2: x64 CPUs with FMA instructions And for the remaining 0.76 percent, the fingerprinting script failed entirely, according to Firefox’s data. However, Ritter said there are 48 users worldwide who do not fall into the three buckets, or the 0.76 percent whose machines did not allow the scripts to run. These 48 users fell into 23 other minuscule buckets, which means they are not grouped into the masses like the rest, and so fingerprinting is more effective on this vast minority of users. “This is very unfortunate, as it makes these users completely unique, but it is also not terribly unusual - computers are weird and these results could have been caused by bad RAM, a CPU bug, or possibly some crazy architecture (LoongArch??),” said Ritter. “But at the end of the day, WebAudio fingerprinting is nearly useless. I don't expect browser fingerprinting to disappear from websites entirely (unless some regulatory action occurs, fingers crossed) - it's still going to be effective against a majority of users on the web, but at least for privacy-focused browsers, it should be wildly less effective.” Brave, maker of the eponymous privacy-centric browser, also Xeeted a response to Calalghan’s findings, saying it has protected users from fingerprinting for six years. “Brave injects random data into the browser's output so you show a different fingerprint to different sites. This fingerprint also resets across sessions. “For added protection, we also block the specific scripts used by AliExpress for the tracking method mentioned above. Again, this is done by default for all Brave users. You don't have to change any settings to be shielded from this audio fingerprinting.” Ritter said Chrome and Safari “probably have defenses against this [brand of fingerprinting].” Safari deploys Advanced Tracking and Fingerprinting Protection to prevent WebAudio-based tracking and other methods of fingerprinting. It works differently to Firefox, though, injecting audio errors into an audio buffer, instead of trying to lump all users into an identical bucket. Chrome, on the other hand, does not aggressively protect users from fingerprinting, as privacy consultant Alexander Hanff said earlier in the year. "There are at least thirty distinct fingerprinting techniques that work in Chrome right now, today, as you read this," he wrote. "Not theoretical attacks from academic papers that might work under laboratory conditions – real, production techniques deployed on millions of websites to identify and track you without your knowledge or consent." ® Updated 08/25 at 1805 GMT to clarify the behavior was observed on AliExpress, which is Alibaba's B2C web site for small-scale purchases.
Kategorie: Viry a Červi

eBPF Security Patch Expands Link Checks Across Cgroup and LSM Hooks

LinuxSecurity.com - 24 Srpen, 2026 - 14:30
A Linux BPF patch posted on August 21, 2026, expands validation for program replacement across cgroup and Linux Security Module hooks. Version 3 addresses cases where two programs share a broad type but expect different runtime contexts or return rules.
Kategorie: Hacking & Security

Linux 7.3 Development Changes IMA Measured Boot Evidence and TPM Timing

LinuxSecurity.com - 24 Srpen, 2026 - 14:22
Code merged for the Linux 7.3 development cycle changes the measured boot evidence produced by the Integrity Measurement Architecture, or IMA. The kernel now records the raw policy rules that decide what the system measures, closing a gap that could leave remote verifiers without a complete picture of how the evidence was created.
Kategorie: Hacking & Security

GNU Emacs 31.1

AbcLinuxu [zprávičky] - 24 Srpen, 2026 - 14:14
Byla vydána verze 31.1 textového editoru GNU Emacs. Podrobný přehled novinek v souboru NEWS.
Kategorie: GNU/Linux & BSD

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

The Hacker News - 24 Srpen, 2026 - 13:56
Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset. The vulnerability, assigned the CVE identifier CVE-2026-18963, is rated 9.1 on the CVSS scoring system by Red Hat, which acts as
Kategorie: Hacking & Security

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

The Hacker News - 24 Srpen, 2026 - 13:56
Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset. The vulnerability, assigned the CVE identifier CVE-2026-18963, is rated 9.1 on the CVSS scoring system by Red Hat, which acts as Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor

The Hacker News - 24 Srpen, 2026 - 13:51
Cybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go backdoor called QUICAgent. The campaign, codenamed Operation QUICSILVER, has been found to target government and information technology sectors, per Seqrite Labs. The activity is assessed to be the work of a China-nexus threat actor with moderate
Kategorie: Hacking & Security

Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor

The Hacker News - 24 Srpen, 2026 - 13:51
Cybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go backdoor called QUICAgent. The campaign, codenamed Operation QUICSILVER, has been found to target government and information technology sectors, per Seqrite Labs. The activity is assessed to be the work of a China-nexus threat actor with moderate Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk

The Hacker News - 24 Srpen, 2026 - 13:30
Big security risks come in small packages. While enterprise security teams focus on policing the proliferation of employees using ChatGPT and Claude for quick drafting tasks, a more urgent threat is posed by a handful of AI super-adopters who are quietly hardcoding unvetted tools into critical business operations. According to new research published by Akamai, the top 5% of enterprise power
Kategorie: Hacking & Security

The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk

The Hacker News - 24 Srpen, 2026 - 13:30
Big security risks come in small packages. While enterprise security teams focus on policing the proliferation of employees using ChatGPT and Claude for quick drafting tasks, a more urgent threat is posed by a handful of AI super-adopters who are quietly hardcoding unvetted tools into critical business operations. According to new research published by Akamai, the top 5% of enterprise power [email protected]
Kategorie: Hacking & Security

Vláda schválila velké změny penzijka. Mladí mají dostat dvojnásobný příspěvek

Lupa.cz - články - 24 Srpen, 2026 - 13:01
Vláda schválila změny penzijního spoření od roku 2027. Počítají s nižšími poplatky, vyšší podporou pro mladé i novým nastavením investování podle věku.
Kategorie: IT News

6 tips for better research with Microsoft Copilot

Computerworld.com [Hacking News] - 24 Srpen, 2026 - 13:00

Copilot, Microsoft’s generative AI chatbot, can do many things, but one of its best uses is as a researcher, for pretty much anything you want in business or personal use.

If you’re looking for in-depth information, there’s a lot more you can do than type a simple request into Copilot’s search box. Simple prompts can be fine when you’re looking for basic information, but for anything beyond that, you need help. Here are six ways to turbocharge your research with Copilot.

Note that Copilot is available in several places and with varying capabilities. Everyone can use the free Copilot app for Windows, macOS, Android, iOS, and on the web. There’s also Copilot Chat in the M365 Copilot web app, which provides access to more powerful tools under some Microsoft 365 subscriptions. And users with certain M365 subscriptions can use Copilot from within M365 apps like Word.

Business users with an M365 Copilot subscription can use an advanced Copilot agent called Researcher, built for very deep dives into enterprise data, which is then formatted into reports. We’ll cover the Researcher agent in this story, but it’s not something most business users would typically use as part of an everyday workflow.

Most of the tips here focus on widely available Copilot features that anybody can use. We’ve demonstrated using the basic Copilot app for Windows; similar features are available in other Copilot iterations.

One last note before we begin: Like all genAI tools, Copilot sometimes makes errors and spouts hallucinations — things that may sound reasonable but are pure fabrications. As you conduct your research, be sure to follow the advice in our guide to curbing hallucinations in Copilot.

1. Choose the right mode for your research task

A simple way to improve your research is to choose the right Copilot mode. Depending on the mode you choose, you can do quick-and-dirty searches, in-depth research, and more.

Just to the right of the + sign in the Copilot search box, you’ll see what mode you’re currently using. The default is Smart. If you click the down arrow next to it, you’ll have four choices. Three of them are ideal for different kinds of research:

  • Smart: This is for when you want results as quickly as possible. Use this when you’re not interested in a deep dive. Keep in mind, though, that there is a way to use it to get highly targeted in-depth research. Because it works so quickly, you can quickly iterate your prompts, digging deeper with each new prompt.
  • Think deeper: This provides a deeper dive and takes a bit more time. It uses multi-step reasoning, gives you a deeper analysis, and offers a more structured synthesis than in smart mode. How much time it will take depends on the complexity of what you’re asking. For the simplest questions, Think deeper takes up to 15 seconds compared to up to about three seconds for Smart mode. (Or so Copilot tells me, and I’ve found it’s generally right.)
  • Search: This mode gives citations and links in your research and is two to four times slower than Smart mode. But if you’re looking for links to confirm Copilot information, or to follow up on, it can be a time-saver. With it, you won’t have to do follow-up prompts to get links as you often need to do in Smart mode.

Choose the right Copilot mode for the kind of research you’re doing.

Preston Gralla / Foundry

The fourth mode, Study and learn, offers guided learning, quizzes, and more. It’s useful, just not for conducting research.

2. Limit Copilot to reputable, information-dense sources

The research work Copilot does for you is only as good as the information it finds. And I’ve found that you can’t always rely on Copilot on its own to find the best information sources — that’s when it can go off the rails.

So when you craft a prompt for research, make sure to tell Copilot specifically where to look for the information. For example, if you were researching how much money the federal government has given in grants to small businesses over the last five years, you could craft a prompt like this:

Briefly summarize the total amount of money the federal government has given in grants to small businesses over the last five years. Use only official .gov sources. Provide links to all sources of information.

If you have found reliable sources of information over the years, point Copilot at those specific websites or pages when you craft a prompt. And if you have files that contain relevant information, upload them to Copilot and tell Copilot to use them for the research.

To do it, click the + sign at the left side of Copilot prompt box and select Add images or files. On the popup, navigate to the files you want, select them, and click Open. When you’re back at the prompt, tell Copilot to use these files exclusively for its research.

You can upload specific files for Copilot to research.

Preston Gralla / Foundry

In the M365 Copilot app with a business or enterprise M365 subscription, you also have an Add work content option in this menu. Choosing this lets you select documents and other files stored in your M365 tenant. If you have an M365 Copilot add-on subscription, you can also reference calendar events and emails.

3. Use images and videos for researching

They say a picture is worth a thousand words — and sometimes, when it comes to research, that may be true. For example, if you’re going to launch a marketing campaign, you might want to make sure that the images you plan to use don’t infringe on copyrights.

In product design, you might want to get detailed information about a competitor’s products, such as what kind of finish they’re using on them. Copilot can even give you information about a competitor’s product such as construction methods, internal product structure, and clues about how it was manufactured if you send it an unboxing video.

Click the + sign at the left side of Copilot prompt box and select Add images or files. From the popup, navigate to the photo, video, or image and select it. When you’re back at the prompt, ask Copilot what you want to know about the image, such as whether the material is public domain or copyrighted.

Copilot analyzing an image to determine whether it’s in the public domain.

Preston Gralla / Foundry

Theoretically, you can also paste in a URL of a video and ask Copilot to analyze it. In practice, though, it’s tough to do.  I tried doing that with multiple YouTube videos, and each time Copilot said I needed a “a direct-access video file link” such as a Dropbox link set to public, a OneDrive public link, or a direct MP4/MOV/WebM URL. I tried a public Dropbox link and it worked. However, as a practical matter, you’ll come across very few links like that in your research.

However, there’s a workaround you can try, using a feature called Copilot Vision in the Copilot app for Windows, macOS, Android, or iOS. In your browser, go to a web page with a photograph, graphic or video, including those on YouTube. Start playing the video (or merely display an image), then head to the Copilot app and click the eyeglasses icon. Copilot will start a chat with you. Say or type what you want to find out about the video or image, and Copilot will answer your questions.

I found that it’s a little kludgy to coordinate all that. But it works.

Copilot analyzing an air fryer based on a YouTube video playing in a browser.

Preston Gralla / Foundry

4. Search your own data

The internet isn’t the only place where there’s valuable data to plumb. You have plenty of vital information under your own control — for example, stored in OneDrive, Google Drive, email, calendar, and contacts, among other places.

There’s a quick-and-easy way to give Copilot access to them, by using Copilot connectors. There are lots of ways you can use this access, for example, to find files and emails about a specific project you’ve worked on, budget information, and so on. You can also use Copilot to search through your calendar for specific meetings.

Note: Some businesses may not allow you to connect to data sources via Copilot, or may have already set up connections for you. Check with your IT department for details.

To set up Copilot connectors, click the + sign just below the Copilot text prompt, then select Use connectors. A list of available connectors appears. As I write this, those connectors include OneDrive, Outlook, Google Drive, Google Calendar, Gmail, Google Contacts, Box, and Dropbox.

Selecting a data source to connect to Copilot.

Preston Gralla / Foundry

Click the Connect button next to the connector you want to set up. You’ll typically first see a general information screen about that specific connector, along with a button to click if you want to create the connector.

Click the button and follow the prompts. The prompts differ from connector to connector. You may need to log in to the service you want to connect to, and you may also get a chance to customize how the access works. For example, if you’re granting access to Gmail, you need to agree to give access email and settings. But you’re also asked if you want to allow Gmail to send email on your behalf and manage drafts. Click See access details for more information about each permission.

When setting up a connector, you can usually customize how Copilot accesses and uses your data.

Preston Gralla / Foundry

A word of warning: I’ve found that the connectors can be flaky — for example, the Gmail connector at times works and at other times doesn’t. And the connector to OneDrive doesn’t search through the contents of files, just file names. Still, despite their limitations, I’ve found them to be useful.

Should you ever decide you no longer want the connection between Copilot and a data source, you can easily remove it. To do it, in Copilot click the Copilot icon — it usually appears on the upper right or lower left part of the screen, depending on the version of Copilot you’re using. Select Settings > Connectors, then select the connector you want to disconnect and follow the prompts.

5. Bring other chatbots’ research into Copilot

When it comes to research, sometimes two or three chatbots are better than one. If you use Google’s Gemini or Anthropic’s Claude, you can take the research you’ve done with them and mine it as a data source when you use Copilot.

The overall way you’ll do this for each chatbot is the same: Export the research you’ve done in a chatbot to a file, save that file to OneDrive or Teams, and then tell Copilot to use that file as a data source. Here’s how to do it for Gemini and Claude.

Use your Gemini research in Copilot

Your best bet for bringing your Gemini research into Copilot isn’t to copy all the individual research chats you’ve had for a given topic. That’s time-consuming, unnecessary, and won’t give Copilot the best, most targeted data.

Instead, first ask Gemini to summarize the research on a given topic, and export that summary. The exact prompt you’ll give Gemini will vary according to the topic and research you’ve done on it. But generally, you want to be as precise as possible about what data you want included in the summary.

So, for example, if you’ve used Gemini to do research on the home office furniture market and asked it to estimate demand over the next five years, you would write a prompt like this:

I am migrating information from you into Microsoft Copilot. Summarize every conversation we’ve had about estimates of the demand for the home office furniture market and create a properly structured Project Intelligence Brief from it. Pay particular attention to any submarkets, such as for furniture used by self-employed people versus people employed by small businesses and large businesses who are working at home. Break it down by industry type as well.

When you create a Project Intelligence Brief about your research in Gemini, you can export it to Copilot.

Preston Gralla / Foundry

After you do that, click the three-dot icon on the upper right part of the Gemini screen and select Export to Docs from the menu that appears. In a short while, select Open Docs from the notification at the bottom of the screen. The document will open in Google Docs. In it, select File > Download > Microsoft Word (.docx).

The file will be downloaded to your PC. Move the file to OneDrive or a SharePoint library or Teams channel, depending on whether it will be used solely by you or other people as well.

Once the file is there, you can use it as the basis for Copilot research. How you do that depends on the how your IT admin has set up file sharing. However, the simplest way to do it if you’re doing it by yourself in OneDrive is to click the + button to the left of the Copilot prompt box, select Add images or files, then navigate to the file. Once you’ve done that, tell Copilot to use that file for your research.

Use your Claude research in Copilot

You follow the same general steps in Claude as you do in Gemini. So, use the same kind of prompt as I outlined for Gemini. In the prompt, tell Claude to create a .docx for it.

Fairly quickly, Claude will create the brief and display it in a right pane so you can scroll through it. To download it, click the Download and open button in the left pane. Follow the instructions outlined in the Gemini section above for how to point Copilot to it.

Creating a research brief in Claude for use in Copilot.

Preston Gralla / Foundry

6. Use Copilot’s Researcher agent

Copilot’s most powerful research tool is Researcher, an AI agent designed for complex, multi-step research tasks. Researcher looks through your work data, including emails, Teams chats, files, meetings, and more, and also goes out on the internet to find what it can. When it’s done researching, it compiles a structured report based on what it finds.

But there’s a catch: Researcher is only available to individuals with a Microsoft 365 Premium license and business users with either an add-on M365 Copilot license or a top-end M365 E7 license, which includes M365 Copilot.

In a business environment, your administrator must enable Researcher for you to use it. If enabled, you access it in the M365 Copilot app. (You can get to the same place by  selecting the Microsoft 365 Copilot app from the waffle menu in the top-left of a Microsoft 365 web app.)

In the M365 Copilot app, select Agents in the left sidebar, then select Researcher from the list of agents. The Researcher agent takes over the Copilot screen.

The Researcher agent in Copilot handles complex, multi-step research tasks.

Microsoft

Type in the prompt box what you want done. Researcher is best for complex or multi-part tasks. So you might ask something like:

Describe the competitive landscape for our new line of home office products that will be launched in the first quarter of next year.

The agent may ask you a few follow-up questions to clarify your request, then it gets to work. It may take some time to complete what you’ve asked it to do, from as little as five minutes up to 45 minutes for very complicated research.

A few things you should know before using Researcher: Unlike a standard Copilot prompt, it can’t use images and photographs as input. It also can’t take any actions for you, such as drafting and sending an email — it only creates research reports. Finally, you can only use Researcher up to 25 times in a given month.

See Microsoft’s Researcher documentation for more information about how to use the agent.

Related reading:

Kategorie: Hacking & Security

CISA orders urgent patching of actively exploited Zimbra flaw

Bleeping Computer - 24 Srpen, 2026 - 12:45
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies to patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days. [...]
Kategorie: Hacking & Security

AMD roste v noteboocích, ale těch s čipy od Intelu se stále prodá třikrát více

Živě.cz - 24 Srpen, 2026 - 12:45
Podle analytiků z Mercury Research se ve druhém čtvrtletí 2026 prodalo o 10 % více procesorů než v tom prvním. Rostl zájem hlavně o serverové a mobilní čipy, zatímco ty desktopové upadaly. Oproti stejnému období roku 2025 se prodalo dokonce o 20 % více serverových procesorů, protože je o ně velký ...
Kategorie: IT News

Waterfox 6.7.0

AbcLinuxu [zprávičky] - 24 Srpen, 2026 - 12:23
Webový prohlížeč Waterfox (Wikipedie), fork Firefoxu, byl vydán ve verzi 6.7.0. Postaven je na jádru Gecko ESR 153.
Kategorie: GNU/Linux & BSD

Security vets rally around $4 paper password books for sale in Australia

The Register - Anti-Virus - 24 Srpen, 2026 - 12:17
Are you sick and tired of maintaining a password manager? Struggling with choosing the right one for you? Well, readers who live Down Under can get themselves down to their local AusPost branch where they can pick up an old-school alternative for just AU$4.90 (US$3.51). Password books are something of a historical relic, phased out largely because of the scrutiny associated with using one and the now-gray-haired elders who once scoffed at the mere notion of such an opsec crime. They might not be able to suggest a strong password for each of your many online accounts, and they won’t do you much good if your house is burgled, but you could argue that there is still value to be found in a pen-and-paper password vault. That’s exactly the conclusion drawn by the thousands of social media users who flocked to a post this week from one Australian who found stacks of password books for sale in their local post office. Small books are priced at AU$4.90 (US$3.51), while larger options will set you back a dollar extra. Granted, there are myriad issues associated with relying on a physical document for digital account security. For one, it’s a single point of failure. Lose the book or have it stolen, and it’s a painful road to restoring access to all your accounts. One could argue that if it’s kept inside the home and it’s stolen, then you’ve got bigger problems on your hands, but perhaps that’s not as true nowadays, when so many of our valuables are either stored or primarily accessed online. That said, it might bring a quick end to a hostage scenario – the type that is becoming all the more common as crypto wealth becomes increasingly common. Password books are also not as easily manageable as a modern password manager. The technological equivalent can auto-fill credentials, auto-update them if they’re found in public breaches, and suggest unique, strong strings to minimize the risk of compromise. You can’t store a passkey in a password book, either – a major issue now that the world is transitioning toward the new authentication standard. But using a password book no longer carries the same stigma as it once did among infosec types. The general consensus, gleaned from the hundreds of social media comments on the post, now seems to be that there's little wrong with storing passwords on paper at home. It’s certainly more secure than reusing the same weak password across multiple accounts, provided the book contains strong strings unique to each website. With the prevalence of infostealers nowadays, it's far more likely that crims will use a weak, reused, seldom-changed password to break into an online account than burgle a house to gain access to someone’s online banking. Plus, as many pointed out, it’s a much better route than writing passwords in a cloud document, which can be accessed by any device that has access to it – think Apple Notes, Google Docs, etc. At work, though, it’s probably best to stick to the password manager, the IT guys say. Mistakes by staff working at even the lowest rungs of the corporate ladder could lead to multimillion-dollar cyberattacks should that password book fall into the wrong hands. Pentesting consultants often send hired white hats to breach a company’s office and extract whatever value they can, sometimes through piss corridors. Such access can lead to malicious USB sticks dropping malware, bugs planted near the water fountain, and even someone stealing the password book from your desk drawer. Don’t believe it’s real? Security consultant Alethe Denis told us two years ago that’s exactly how her pentest team was able to surreptitiously extract corporate data over a company’s own Wi-Fi for over a week. They went dumpster diving, got the Wi-Fi creds, walked straight into a conference room, and deployed a data-stealing implant. In and out, all using physically stolen secrets. Helpful in the worst of times So, yes, password books contain plenty of potential pitfalls, Poignantly, however, they often prove invaluable in the event of a loved one’s passing. Having access to a password book, or at least some sort of plan to share passwords in the event of a death, is vital to ensuring family and friends have space to grieve without going through the arduous process of recovering an account through a platform provider, or via the courts. A slew of Redditors agreed, saying it made the whole process so much easier. One shared the tale of how their mother’s own special way of storing passwords resulted in a treasured family investigation. After password books spent years as outcasts of the cybersecurity world, they’re now having a second moment in the sun. And while the leading minds in cybersecurity are busy working on ways to stop phisherfolk from hacking into your accounts, or rogue AI agents from doing the same, there’s still something to celebrate in the safeguards of yesteryear, both in life and death. ®
Kategorie: Viry a Červi

Microsoft shares temporary fix for Windows 11 gaming issues

Bleeping Computer - 24 Srpen, 2026 - 11:42
Microsoft has shared a temporary fix for ongoing gaming issues caused by Windows 11 updates released during the August 2026 Patch Tuesday. [...]
Kategorie: Hacking & Security
Syndikovat obsah