Agregátor RSS

This Week’s Awesome Tech Stories From Around the Web (Through August 15)

Singularity HUB - 12 min 42 sek zpět
Artificial Intelligence

These Startups Are Chasing the Next Big Thing in LLMsWill Douglas Heaven | MIT Technology Review ($)

“Transformers are starting to show their age. Many of the recent advances in LLMs, such as the development of so-called reasoning models and their ability to handle large amounts of input at once, are not neat extensions of that core technology but workarounds that patch over some of its fundamental flaws. A growing number of scientists and engineers are now asking what’s coming next.”

SPACE

Astronomers Discover a New Kind of Cosmic Object—a Black Hole ‘Star’Ian Sample | The Guardian

“Astronomers claim to have discovered a new kind of cosmic object, a black hole ‘star,’ which is the size of the entire solar system and glows with a brilliant red light. …Measurements of the exotic body found that while it resembles an immense star, it releases 100bn times more energy than any known star can produce. The energy output is far closer to that observed from black holes than stars.”

Biotechnology

Why Aging May Be a Program, Not a BreakdownIngrid Wickelgren | Quanta Magazine

“Far from a random but linear process of wear and tear, [cell biologist Junyue Cao] argues, aging is a stepwise, programmed, orderly affair. …Using technology that offers a systemwide view of the aging process in mice, Cao has outlined discrete stages of aging, akin to those of embryonic development, that are defined by changes in molecular signals and specific cell populations. In humans, the process likely begins before age 30.”

TECH

Why Wall Street and Nvidia Are Building an Exotic Money Pipeline for the AI BoomJack Pitcher, Anissa Gardizy, and Peter Rudegeair | The Wall Street Journal ($)

“CEO Jensen Huang is running into a problem: Many of his customers can’t afford to buy his company’s coveted AI-powering chips. That explains why Huang teamed up with an array of Wall Street firms on a $500 billion plan that will theoretically standardize chip financing, creating asset-backed pools of capital for AI companies—while leaving Nvidia partly on the hook if things go wrong.”

Future

Big Tech Wants to Harvest Your ThoughtsJames Crawford | Wired ($)

“‘[A brain-computer interface is] incredible for patients that are paralyzed. But imagine you put this on a person for other reasons. There is great responsibility,’ [said Rafael Yuste]. ‘Look what we have in our hands. We just built you a machine that can decode your language. And in 10 years, we’re going to give you a machine that can interfere with your thoughts the way we do it in mice today.'”

ROBOTICS

Self-Driving Trucks Are Officially Testing on California HighwaysKirsten Korosec | TechCrunch

“Aurora Innovation and Kodiak AI, two companies developing self-driving trucks, have received permits from the California Department of Motor Vehicles to test their autonomous vehicle technology on public roads. And Kodiak has already started. Kodiak said it is starting with a handful of test trucks in California, primarily around its Mountain View office.”

Artificial Intelligence

The AI Takeover of Mathematics Has BegunRobert Hart | The Verge

“For all the fears and hopes, nobody knows where this is going. AI is moving too fast, and the mathematics it is producing is still too fresh to judge what its impact may be. Several researchers worried that the field could be reshaped for the worse by claims about what AI could become before anyone has had time to understand what it actually means.”

Biotechnology

The World’s Largest ‘Biological Datacenter’ Could Help Make Animal Testing ObsoleteAdele Peters | Fast Company ($)

“For decades, the industry has relied on animal testing. But in a laboratory south of San Francisco, a startup called Vivodyne is scaling up a different approach. Inside wardrobe-size mini labs, robots grow human tissue and run thousands of AI-designed experiments that could better predict how well a new drug will work—and whether it will be safe.”

Biotechnology

Seedless Blackberries and Cherries That Grow on Bushes Vie to Be the Future of FoodMike Grunwald | Wired ($)

“[Pairwise] is also working on peaches without pits, row crops resistant to a variety of diseases, fruit and nut trees that produce their first harvest within a year or two rather than three to eight, and a slew of other novel products, often in partnership with some of the world’s largest agribusinesses.”

Robotics

Waymo Is Growing Faster Than Ever. So Are Its Glitches.Emmy Martin | The New York Times ($)

“What Ms. Peterson experienced is what the driverless car industry calls an ‘edge case,’ which are the unscripted situations that no one trained the robo-taxis to handle. The problem is that edge cases appear to be piling up as Waymo, the leading autonomous car service, rapidly expands. Owned by Google’s parent Alphabet, Waymo has more than quintupled the number of autonomous cars it has on the road to nearly 4,000 today, up from about 700 early last year.”

The post This Week’s Awesome Tech Stories From Around the Web (Through August 15) appeared first on SingularityHub.

Kategorie: Transhumanismus

Word z roku 1989 běží na Windows 11. Nadšenec upravil původní zdrojové kódy od Microsoftu

Živě.cz - 27 min 42 sek zpět
Programátor vytvořil nativní port Wordu pro Windows 1.1a. • Tento textový procesor světu představil editaci WYSIWYG. • Běžel na strojích s jedním megabajtem operační paměti.
Kategorie: IT News

Sledování planety dostává nový rozměr. Google nabídne satelitní data aktualizovaná každých pět dní

Živě.cz - 2 hodiny 27 min zpět
Google nabídne datovou sadu pro sledování planety aktualizovanou každých pět dní • Model od DeepMind sloučí radarová i optická data do jednoho formátu • Služba pomůže vyhodnocovat živelní pohromy nebo plnit pravidla odlesňování
Kategorie: IT News

Francouzská Ústavní rada zamítla zákaz sociálních sítí dětem mladším 15 let

AbcLinuxu [zprávičky] - 2 hodiny 34 min zpět
Francouzská Ústavní rada zamítla zákaz používání sociálních sítí dětem mladším 15 let. Francouzská obdoba ústavního soudu uvedla, že opatření představuje nepřiměřený zásah do svobody projevu. Francouzský parlament zákaz schválil na konci července, začít platit měl od září. Šlo o první zákaz sociálních sítí pro děti v Evropě. Členové Ústavní rady se domnívají, že ustanovení „představuje zásah, který není přiměřený, nezbytný ani úměrný“ svobodě projevu a komunikace. Ačkoli uznávají ústavní požadavek na ochranu nejlepších zájmů dítěte, v dnešním rozhodnutí poukazují na skutečnost, že tento velmi široký zákaz „se může vztahovat na služby on-line komunikace, u nichž nejsou prokázána rizika pro zdraví a bezpečnost nezletilých“.
Kategorie: GNU/Linux & BSD

ChainDrop worm crawls into npm supply chain, evades standard defenses

The Register - Anti-Virus - 3 hodiny 1 min zpět
A new variant of the Shai-Hulud npm worm has poisoned hundreds of packages while adding propagation techniques that can leave little trace in the corresponding source repositories. In Frank Herbert’s Dune, Shai-Hulud was the name of the giant self-sustaining desert sandworms that moved silently beneath the surface of the planet Arrakis. So it made sense that when some new self-replicating malware with computer worm-like behavior appeared in September 2025, security researchers would name it after Herbert’s fictional creatures. The latest variant of Shai-Hulud, dubbed “ChainDrop” by Microsoft and others, is no mere sequel, however. Now, the npm community is discovering a Shai-Hulud variant spreading with new stealthy superpowers that circumvent the usual safeguards of open source repositories. On August 4, multiple security researchers identified a large-scale npm supply chain attack using this Shai-Hulud variant that had infected 444 packages from multiple publishers, which are collectively downloaded about 2 billion times a month. The operation targeted widely used deep infrastructure dependencies, such as keyv, flat-cache and cache-manager. Abby Kearns, CEO of enterprise open source security company ActiveState, noted in a Medium post that what is unique about this particular attack is that it doesn’t use the typical methods of breaching the defenses of open source repositories. Even if you never install an infected package (“npm install” in npm argot), you can still get the nasties – though that is one possible route of infection. Once triggered, ChainDrop also places startup hooks into the repository configuration files themselves: Simply opening an infected Git branch in VS Code or Claude Code can bring your repository under ChainDrop’s control. Scouring your code itself may not provide evidence of tampering. ChainDrop propagates not by repository source commits but by tarballs, an archive format for downloading file packages. ChainDrop travels by tarball When executed, the software scours the user’s workspace for npm tokens with full write privileges, as well as for other credentials like cloud keys and secrets. It looks in shell configurations, environment variables and even live memory. Any purloined data is encrypted and sent back to attacker-controlled endpoints. Should it find an npm token, it then downloads the tarballs of all the packages that token has full access to, bypassing the repositories themselves. That’s the genius part: ChainDrop self-replicates by rebuilding the tarball to include its own payload. Reviewing the source code repository won’t reveal any evidence of shenanigans. ChainDrop’s attack is two-pronged. It also searches for GitHub credentials. If it finds any, it queries the GitHub API to list all accessible repositories and branches and then commits its malicious configuration code directly into those branches. So when other developers open these repositories using Claude or VS Code, a background task gets triggered that harvests credentials, beginning the whole cycle anew. What a dev can do This attack is particularly pernicious because npm is widely integrated into automated CI/CD pipelines, which can automatically pull patch updates for dependencies during a rebuild - giving the worm a path to wiggle into fresh builds. If you think you've been infected, the first thing to do is check for any .claude/settings.json and .vscode/tasks.json files you did not add yourself, ActiveState’s Kearns advised. And don’t just check the main branch, but all the other branches as well. All the infected packages were quickly yanked from npm. Open source security firm SafeDep offers a list of all the compromised packages along with version numbers, so check those against what you currently have running. Beyond cleaning up the mess, developers and security teams should rethink how their systems could be breached in light of ChainDrop. Trusted publishing tools such as GitHub Actions should be evaluated, for starters. Begin “treating repository-supplied configuration as executable content, because that is what it is now,” Kearns wrote. “What this campaign really found was an execution path that dependency scanning tools were not configured to look at, sitting inside the exact tools engineering organizations have spent two years adopting as fast as they could,” Kearns wrote. “This is the first campaign to notice the gap and use it at scale. It will not be the last one.” ®
Kategorie: Viry a Červi

EU staví čipové továrny, v Česku to stojí. Investici v Rožnově za 44 miliard komplikuje zapeklitý problém

Živě.cz - 4 hodiny 27 min zpět
Evropa staví čipové továrny za 850 miliard korun. Česko je jediné, kde projekt stojí • . • Onsemi čeká na pobídku 11 miliard, kterou už schválil Brusel. Babišova vláda mlčí a řeší problém spojený se změnami v samotné Onsemi. • Čínská konkurence vyrábí desky pro čipy třikrát levněji. V Rožnově se ...
Kategorie: IT News

SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch

The Hacker News - 5 hodin 33 min zpět
A maximum-severity security vulnerability impacting SAP Commerce Cloud is witnessing active exploitation efforts. The vulnerability, tracked as CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It relates to an instance of insufficient authorization checks and input validation. "SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

15 927 zrcadel a 210metrová věž. Čínská solárně-termální elektrárna vyrábí elektřinu pomocí roztavené soli

Živě.cz - 6 hodin 7 min zpět
Nová čínská elektrárna v Tibetu vyrábí čistou elektřinu z roztavené soli • Tisíce přesně nastavených zrcadel odrážejí sluneční paprsky na vysokou věž • Moderní zařízení pomůže ročně ušetřit desítky tisíc tun spalovaného uhlí
Kategorie: IT News

Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner

The Hacker News - 6 hodin 48 min zpět
A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency miner, the Netherlands National Cyber Security Centre (NCSC) has warned. The vulnerability in question is CVE-2026-65400 (CVSS score: 9.8), a critical authentication issue impacting the Screen Sharing component that could allow an attacker already on the network to Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Anthropic vysvětluje, jak bude Claude do textu přidávat vodoznaky. Chystá také API pro jejich detekci

Živě.cz - 7 hodin 42 sek zpět
Když Anthropic před několika dny oznámil, že jeho modely Claude začnou neviditelně označovat texty, které vygenerují, nepřidal mnoho podrobností. Asi proto včera vydal další vysvětlující článek, jak by značkování mělo fungovat. Zde najdete jeho upravený překlad. Budoucí modely Claude budou ...
Kategorie: IT News

Bonus až 3 000 Kč od Raiffeisenbank a slevy až 60 % u Adidas

Lupa.cz - články - 14 hodin 12 min zpět
Tento týden jsme pro vás vybrali akce, které stojí za pozornost – od výhodného založení účtu přes slevy na sportovní obuv a oblečení až po zlevněné knihy a doplňky do lékárničky. Podívejte se, kde můžete nejvíc ušetřit.
Kategorie: IT News

How Anthropic plans to watermark Claude's AI-generated text

Bleeping Computer - 14 hodin 48 min zpět
It could soon become easier to identify AI-generated content, even if it's not the usual "It's Not X, it's Y" type of post you'd come across on LinkedIn and other socials. [...]
Kategorie: Hacking & Security

Událo se v týdnu 33/2026

AbcLinuxu [články] - 16 hodin 11 min zpět
Ucelený přehled článků, zpráviček a diskusí za minulých 7 dní.
Kategorie: GNU/Linux & BSD

Římský dvanáctistěn palisády nezapaloval. Možná je pomáhal vyměřovat

OSEL.cz - 16 hodin 12 min zpět
Bronzový předmět s pěti dvojicemi nestejných otvorů mohl být trvanlivou optickou součástí jednoduchého nočního dálkoměru. Hypotézu lze ověřit přesným měřením několika exemplářů a jedním poctivým večerním pokusem.
Kategorie: Věda a technika

Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware

The Hacker News - 14 Srpen, 2026 - 20:48
Threat actors are acquiring expired domains to inherit website traffic and reputation to redirect victims to scams and malware on a large scale. DNS threat intelligence firm Infoblox has given the name dropcatch domains to those that get a second chance, where an expired domain becomes available for registration and is then snapped up by another party. During the first half of 2026, 50,400 Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Vulnerability giving attackers full control of Macs is under active exploitation

Ars Technica - 14 Srpen, 2026 - 20:32

Dutch officials have warned that a high-severity macOS vulnerability that allows attackers to execute malicious code is under active exploitation.

“The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet,” the Netherlands National Cyber Security Centrum warned earlier this week. “In all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed.”

Do you know if your screen sharing is on?

The vulnerability, tracked as CVE-2026-65400, received a patch from Apple last week for macOS Tahoe, Sequoia, and Sonoma. The vulnerability, with a severity rating of 7.1 out of 10, stems from a bug in the macOS screen sharing capability, which allows a remote party to view the screen and control the keyboard and mouse while a machine is turned on. A flaw in the “state management,” which keeps track of preceding events, user interactions, variables, and other system states, is the underlying cause.

Read full article

Comments

Syndikovat obsah