Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

Adobe Acrobat evolves beyond PDFs with enterprise search, AI content creation

Computerworld.com [Hacking News] - 15 min 36 sek zpět

Adobe on Wednesday unveiled a range of updates to Acrobat, including the ability to turn PDF documents into interactive visual reports and podcasts. And a new Knowledge Base feature connects Adobe’s Acrobat AI assistant to document sources such as Microsoft SharePoint and Google Drive.

It’s the biggest Acrobat update in several years, Adobe said, and highlights the application’s evolution from PDF reader to what the company now describes as an AI-powered document productivity and creativity platform. 

Acrobat users open more than 400 billion PDFs in the app each year, Adobe said, claiming 650 million monthly active users as of last year

Among the new additions is the ability to turn dense PDFs into interactive, visual documents and presentation slides. To create these, Acrobat’s AI assistant scans the selected file, asks questions about the user’s intent, then generates documents charts, images and navigation.

It’s also possible to turn documents and web links into podcast-style audio summaries — similar to capabilities in Google’s NotebookLLM and Microsoft Copilot Notebook. A new Stylize feature can enhance plain-looking documents, applying a template to turn them into “professional deliverables” such as CVs and invoices, Adobe said.

The audio and visual generation features are all available in paid Acrobat plans (Acrobat Studio, Acrobat Express and Acrobat AI Assistant). 

Another addition, Acrobat Knowledge Base, lets customers connect the Acrobat AI assistant to a wider range of file types, enabling users to ask questions about information held in documents stored in Microsoft SharePoint and Google Drive, for example.  

Acrobat’s Knowledge Base “transforms curated document collections — policies, playbooks, product information, pricing guidance, research — into cited answers available from Slack, Microsoft Teams, Acrobat, and other places employees already work,” Abhigyan Modi, senior vice president for Adobe Document Cloud, said in a blog post

Adobe also added an Analyzer tool designed to retrieve data from large volumes of documents. This could involve analyzing thousands of contracts or invoices to identify information such as renewal dates and revenue clauses.

That turns information once trapped in files into data that can inform finance, procurement, compliance, and the systems that support them, said Modi.

Analyzer is the more interesting of the two releases, said Mike Leone, vice president and principal analyst at Moor Insights & Strategy. “Knowledge Base is a search product and search products get judged feature against feature. Analyzer is closer to a data product, because that extraction work is what companies currently pay people and pipelines to do,” he said. 

“What I’d want Adobe to answer is whether that data can leave Acrobat and land where the rest of the company’s data lives. If it can, this starts competing for real data budget. If it stays inside the app, it’s a very good Acrobat feature.” 

Access to Analyzer and Knowledge Base requires an Acrobat Studio for Enterprise subscription. (Adobe doesn’t publish pricing.) 

In addition, Knowledge Base includes a credit-based model that places some restrictions on usage, with licensed users allowed up to 1,000 queries a month. Other actions, such as document uploads, queries from Slack and Microsoft Teams, and queries by employees without an Acrobat Studio license, draw varying amounts of Acrobat Studio “shared credits.” Adobe didn’t say how much additional credits cost once a yearly limit is reached.

 More information about Adobe’s Knowledge Base credit usage policy is available on Adobe’s website

Analyzer also includes a credit system that limits document ingestion and attribute extraction.

For enterprise customers, usage-based pricing can add complexity when managing employee access.

“The issue for a broad deployment is that headcount barely predicts usage,” said Leone. “One person pointing it at 10,000 contracts will burn more credits than a hundred people asking the occasional question. Pooling the credits across the whole organization is the right design, because usage on something like this is rarely spread evenly.

“One of the big challenges is that people could very well start rationing themselves because they don’t know what a question costs,” he said. “Or worse, a couple folks use all the credits and everyone else is out of luck. The last thing any organization wants is to pay for a knowledge tool that people won’t use or can’t use.”

Kategorie: Hacking & Security

US says Chinese firms extracted billions of tokens from frontier AI models

Bleeping Computer - 1 hodina 50 min zpět
U.S. cybersecurity and intelligence agencies say that six Chinese AI companies conducted industrial-scale distillation attacks on American frontier AI models since at least late 2024. [...]
Kategorie: Hacking & Security

No, AI is not killing jobs for everyone, studies say

Computerworld.com [Hacking News] - 1 hodina 55 min zpět

A slew of recent studies indicate that AI isn’t dramatically displacing workers. At the same time, there were no indicators that the fast-moving technology is creating a lot of jobs, even as AI skills remain in high demand.

Stanford University researchers in an August study found that any AI-related job declines were concentrated among young workers aged 22–25. But for older and more experienced workers that wasn’t the case.

“Claims of economy-wide AI-driven job losses are not visible in payroll data through June 2026,” the researchers said, citing ADP payroll information. Stanford partnered with ADP to conduct the research.

The decline for young workers is more often related to the automation of some work tasks by AI, as opposed to its use to complement work. In contrast, AI is more often used by experienced workers to augment what they do. 

According to the Stanford report, workers between 22 and 25 and employed in jobs highly exposed to disruption by AI are falling behind their older counterparts. Their employment levels in June were about 19% below the same age group in less-exposed occupations. That’s compared to where they would be if both groups had kept pace with each other.

“Experienced workers show no comparable gap,” the researchers said, adding that “this is consistent with recent reports of a worsening job market for entry-level workers.”

Employment of younger workers in AI-exposed jobs fell about 11% from late 2022, while the same age group in less-exposed jobs actually grew about 10%. “For older age groups, we find much less marked differences in employment growth across AI exposure quintiles,” the researchers said.

Stanford, which created a lab last year to study AI’s impact amid heightened fears of the technology’s economic effects, said its numbers were based on available indicators.

AI’s adverse impact on young workers has been well documented, with many of them laid off in the initial wave of AI automation. AI has also suppressed wages for entry-level workers.

AI was cited for 116,175 job cuts in 2026, but that number is declining. The technology  was blamed for 3,462 cuts in August, according to data from Challenger, Gray and Christmas.

It’s the “lowest monthly total since December 2025 when 142 cuts were attributed to AI,” the company wrote in a blog entry. The research firm also noted aggressive hiring plans for companies in 2027.

AI is adding value to companies in different ways, and humans are an important part of that process, said Michael Chui, a senior fellow at QuantumBlack, AI at McKinsey. “The night shift is real now,” he said. “People are sending off their agents to write code and checking in the morning.”

MIT late last year established an AI labor index to determine how agents are affecting the workforce. The school’s Project Iceberg looks at how the coordination and interaction with agentic AI changes how work is done.

Despite the disruptions, demand for AI-related talent continues to rise, tech industry consortium CompTIA said last week. About 320,000 job listings in August required AI-related capabilities, a 4.5% increase from July.

AI-related hiring is outperforming the broader tech market, with demand for AI skills up 96% year-over-year, said Kye Mitchell, head of Experis North America, which is part of ManpowerGroup.

“We’re seeing real growth…in marketing management and project management roles, suggesting employers are looking beyond the people building AI to the people applying it,” Mitchell said.

More broadly, the US economy added 162,000 jobs in August, according to US Department of Labor figures released last week. CompTIA noted that tech employment across all sectors rose by 86,000 workers in August.

But within the tech sector, 14,700 positions were cut, CompTIA said.

Kategorie: Hacking & Security

Veradigm warns of patient data breach after ransomware gang claims attack

Bleeping Computer - 3 hodiny 7 min zpět
Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data. [...]
Kategorie: Hacking & Security

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

The Hacker News - 4 hodiny 14 min zpět
Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others.  Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide range of data from compromised systems. This can include credential, session tokens, and APIRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

MFA's Weakest Link: Account Recovery Is the New Attack Path

Bleeping Computer - 4 hodiny 37 min zpět
MFA makes account takeover harder, but attackers are increasingly targeting the recovery processes used to reset passwords and authentication methods. Specops explains why stronger identity verification at the service desk is critical to preventing social engineering attacks from turning account recovery into account takeover. [...]
Kategorie: Hacking & Security

Siri AI Recaps? Even if Apple builds it responsibly, others might not

Computerworld.com [Hacking News] - 5 hodin 33 min zpět

Late-breaking reports suggest Apple has built a new Siri AI ‘Recaps’ feature that summarizes your day for you. The idea sounds great until you recognize that this summary will also include overheard conversations. 

Suspending the huge red flag of concern over privacy and data protection for a moment or two, why would this be useful and who is it for?

How it’s supposed to work

First, it is being described as an Apple Watch feature that will only be available on the latest models: Apple Watch Series 12 and Apple Watch Ultra 4, as these allegedly include secure audio processing hardware. Reading between the lines, that suggests the devices will be able to listen to and process audio on device, which implies that the information won’t need to leave your smartwatch, not even to your iPhone.

The report also says the feature doesn’t make a transcript, nor does it store the audio; it instead gathers key datapoints from what is said to include in the summary, deleting all the remaining information in the process. You can have the feature working all day, on-demand, or only in specific locations. The idea seems to be to provide some kind of actionable summary of events and key conversations that take place during the day. I imagine the subtext is to digitize as much as possible of your daily existence as Apple thinks you will be comfortable with to create the kind of datapoints contextual AI requires if it is going to help with your life.

The case for it

That sounds fine, up to a point — the idea that a digital assistant will be able to recognize key events, moments, and requirements to remind us of them, act on them, or suggest next steps concerning them is certainly a notion that’s gained currency in tech circles. They see it as augmenting human achievement, enabling people to become more productive, more efficient, and capable of doing more with less effort. At least, that’s part of the argument.

What is wrong with that (other than concerns over privacy or a desire not to have one’s entire waking life transformed into a series of datapoints that can be measured, tested, or surveyed by entities outside of our control), right? If you have nothing to hide, you have nothing to fear, at least, not until times change and what didn’t need to be hidden in the past becomes something that must be shrouded in future.

Apple’s privacy defense

Apple, of course, has its strong privacy story to lean into as it introduces this surveillance-as-a-service solution; it’s an argument that says it recognizes how this tech can be abused, and wants to deploy it correctly. It will point to that record as it promises its system doesn’t gather data, doesn’t collect it, and doesn’t keep any form of transcript on or off the device. The company should be commended for building a system that works this way, recognizing as it does that the best way to protect confidential information is not to gather it in the first place.

The warning

But what Apple has also done with this new speculated upon — and as-yet-unconfirmed product — is to show us what these tools can already do. Much of this is already visible; take recent news that LG smart TVs constantly collect and upload user data as an illustration of the seemingly egregious ways in which such tech is used. (LG denies the claim.) What Apple shows us is that with AI in the picture, all your waking moments can be collated, curated, analyzed, digitized and rendered into actionable data. Apple may not be doing that, but others will not be equally cautious, so we owe Apple a debt for warning us of what’s at stake.

Though we don’t know whether Apple will actually introduce this new service, the source of the claims is one of the strongest in the industry. What we do know is that the technology required to build systems like this exists, along with AI systems capable of sourcing, sharing, and sifting through that information. What we don’t yet know is how to remove ourselves from the data stack.

Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSkyLinkedIn, or Mastodon.

Kategorie: Hacking & Security

Nekradou vám heslo, kradou váš souhlas. Přihlašovací obrazovka byla přitom pravá

Zive.cz - bezpečnost - 5 hodin 53 min zpět
Dostanete zprávu. Píše organizátor konference, novinář nebo někdo, kdo se za ně vydává, a v textu je odkaz na nějaký dokument, sdílení souborů nebo něco jiného, uvěřitelného. Kliknete, na stránce se ukáže klasická přihlašovací obrazovka Googlu nebo Microsoftu, která se dnes ukazuje na každém druhém ...
Kategorie: Hacking & Security

Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE

The Hacker News - 6 hodin 1 min zpět
A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application data to build enough context to act. As AI accelerates vulnerability discovery and research, that delay matters [email protected]
Kategorie: Hacking & Security

DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval

The Hacker News - 7 hodin 1 min zpět
A flaw in DeepSeek Harness, DeepSeek's open-source tool for running AI coding agents on a developer's machine, let a sandboxed agent turn off its own sandbox with a single command. The tool runs an agent's commands inside an operating-system sandbox, so that an agent working on untrusted files cannot write outside its workspace. The agent could remove that limit by calling the tool's own web Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

AI notetakers at work could leave companies at risk for lawsuits

Computerworld.com [Hacking News] - 7 hodin 38 min zpět

AI note-taking applications are increasingly used by workers to record meetings, generate conversation summaries and suggest post-meeting action items. 

Along with the promised productivity benefits — enabling users to focus on meetings rather than actively taking notes — the emergence of these AI tools has raised privacy questions, particularly around obtaining prior consent by meeting participants for their use. Those concerns, in turn, have prompted a spate of lawsuits against software vendors that sell AI notetaking tools.

In some ways, the underlying questions are not new: It’s long been possible to record a phone call with a dictaphone, and laws around surreptitious recording have been around for decades. Yet widespread access to AI notetakers via desktop or smartphone apps means that it’s easier than ever to record a conversation for future reference. 

Among the thorny questions arising from the technology’s use: what happens to conversation data sent to a software vendor’s servers for processing? Are the recording and transcript used to train those vendors’ AI models, for example, or create biometric voiceprints? Those practices are among the issues being considered in US courts. 

Otter, which claims to have 35 million users, was subject to a class-action complaint in a federal court in California last year. That complaint accused Otter of recording individuals without consent and using their voices to train its speech recognition AI tools. Last month, a judge rejected Otter’s attempt to dismiss the main claims, though the scope of the case was narrowed.

A lawsuit filed against another vendor, Fireflies, in an Illinois court late last year, alleges the company collects and stores biometric voiceprints without user consent, in violation of the Illinois Biometric Information Privacy Act (BIPA). Fireflies claims to have more than 20 million individuals and 1 million organizations as customers.

Earlier this year, a class-action complaint in a Washington court claimed that a live transcription feature in Microsoft’s Teams collaboration application also violates BIPA by collecting biometric data without consent. 

And most recently, a complaint alleged that Granola, a well-funded startup, designed its product to be used without the knowledge of all meeting participants, in violation of the Electronic Communications Privacy Act (ECPA). That complaint also claims Granola trains its AI models on conversation data without consent. 

None of these cases has yet been resolved, and it’s unclear whether any of the vendors broke the law in the design and delivery of their products and services. But the lawsuits highlight considerations for businesses that allow the use of AI notetakers, both in terms of prior consent for recordings and understanding how conversation data is handled.

More broadly, the lawsuits raise questions about how existing privacy and consent rules apply to new technologies that make it easier to record others, whether through AI note-taking apps, smartglasses, or other recording devices.

Computerworld spoke with Brian McGinnis, partner at law firm Barnes & Thornburg and a founding member and co-chair of the firm’s Data Security and Privacy Law practice group, about the focus of the lawsuits, potential outcomes, and how businesses can deploy AI notetaking apps safely.

Several cases have already been brought against popular AI note-taking apps. What are some of the main commonalities between these? Which laws are the vendors accused of breaching? “The common allegation is that these companies capture communications of people who did not agree to the recording or receive adequate notice. Some of the lawsuits also allege that meeting data is used to train AI models and that consent cannot meaningfully be withdrawn once the data has been processed.

“There are various federal and state claims. You’ve got the Electronic Communications Privacy Act, a federal wiretapping statute. As a general matter, the Electronic Communications Privacy Act permits an interception when one party consents, subject to statutory exceptions and questions about whether the technology constitutes an unlawful interception or third-party eavesdropping. In other words, if you, as the user, provide consent, you can be on a meeting with 20 other people and it’s deemed to be sufficient; you don’t necessarily need to get the consent of other people. 

“But California and a minority of other states are what we call ‘two-party consent’ states, meaning each individual on the call has to give consent; it’s not sufficient for you as the person who turns the notetaker on to provide the consent — you also have to get the consent of others that are being recorded. There are state laws around that.

“There’s a law called CIPA, the California Invasion of Privacy Act, that’s being utilized in this context.  We see a lot of suits being brought under that law — it’s a wiretapping statute designed for telephone wiretapping that’s now being applied to the internet.”

What about the use of biometric data? “A growing number of states regulate biometric data, with Illinois’ BIPA being particularly prominent because it provides a private right of action. This means an individual can sue a company for violation of the law.  

“That law covers biometric information. With an audio recording or recording of ‘dumb’ video that isn’t running any algorithms, you’re not necessarily collecting any biometrics. But when you start identifying people, you’re recording things like faceprints or voiceprints, which are in the definition of biometric information within the statute. Now you’re not only collecting personal information, but also biometric information, which is considered very sensitive and much more highly regulated. 

“Then you’ve got the private right of action that goes against it. Part of the argument here is that recordings taken by the AI notetakers can be used to produce some form of biometric information, such as a voiceprint.  

“We’ve seen a lot of cases, and a lot of changes in industry as a result of this law. Shutterfly had a famous case about scanning for people’s faces and things like that in Illinois that changed the photo storage and processing industry a little bit. 

“A lot of companies stay out of Illinois to avoid this law specifically. But a customer organization might not know exactly who’s in a meeting and where a person is located at the time of the meeting. So, you need to either follow that law and get individual consent, or stay out of states with biometric laws if you want to use some of these tools. 

“It’s just a further challenge for these applications if the goal is to be used as much as possible with as little detection as possible.”

What are some of the potential outcomes for these cases? “I think it’d be unlikely to get an outright ban, absent passing some kind of new law that says these tools are per se illegal for use. It’s much more likely the outcome will require some changes and controls over the way that they get used. The clearest case would be some kind of a pop-up notice: ‘Hey, this meeting’s being recorded, here’s who it is, here’s their privacy policy, here’s their terms of service – do you consent to it?’ And getting opt-in consent from anybody who wants to be recorded. 

“The notion that only one person in the meeting has to say it’s okay and you can just automatically record everybody else, I think that’s probably at risk, and could potentially be replaced with a standard that requires everybody to consent before it’s considered legal.

“But the newer —and more interesting — wave of these is the Granola case, where part of its marketing is that people aren’t aware that it’s there. The Granola complaint alleges that the product was designed to operate without alerting other participants. It’s possible that kind of activity could result in a decision that would ultimately ban it outright. In other words, that it’s illegal to utilize these tools if you aren’t providing notice to everybody and/or aren’t getting consent from everyone on the call. That’s a possible outcome that we could see.

“To me, that’s interesting when you think beyond AI note-taking and into the broader world, with conversations around, like, Meta Glasses, or any of these kinds of AI wearables. Granola in particular has an Apple Watch app, and there are other wearable or physical devices — there’s one [Plaud Note] that sticks on the back of your phone and is essentially an always-on recording device. 

“With these devices, you’re going from an online meeting where you can provide notice and there’s a structure to obtain consent, to walking down the sidewalk and recording people and casual conversations. Maybe it’s somebody you’re having a conversation with, maybe it’s somebody at the table next to you in the coffee shop that you have no relationship with whatsoever — what are the laws around consent and notice in those cases, where there’s no digital interface to put that up in front of people? Do you have to go around with a pad of paper and a pen and get people to sign consent to use these things? Do you have to physically tell them?

“Those are the more interesting conversations that this line of cases is just at the beginning of helping us get some answers on. In other words; how do you get consent? How do you provide notice in a world where we don’t have documents or screens in front of us to easily handle that? Those are interesting questions that the law will have to figure out here.”

These tools are increasingly used in the workplace. How can businesses be sure they deploy the technologies safely? “We’re getting a lot of questions from our clients about this topic, because they’re really unsure and uncertain of how to handle these tools.

“Obviously, there’s a push for broad use of AI within their companies, for productivity increases within their company. People like the tools; they want to be able to use them. But then we also hear a lot of stories about ‘I jumped on a meeting; I didn’t even know it was being recorded, then I got an email afterward with a transcript of it,’ and ‘half of what it recorded wasn’t actually what I said, or it was interpreted incorrectly’ — things like that. So there’s a lot of consternation amongst our clients about the people within their organizations using it. 

“I can’t tell clients definitively that they’re legal as they are; there are ways to use this legally and safely that aren’t going to get your organization sued, but you probably have to do some things that are beyond what’s provided ‘out of the box’ by the software providers. 

“With Granola, for example, my understanding is that certain notice features may not be enabled by default. You can turn on video or audio watermarking, and you can turn on the notice that pops up in these things, but I think it ships without those features enabled. That puts the responsibility on the individual user to determine and then implement their own legal privacy and legal compliance mechanisms using their settings.

“You really have to play to the most stringent state’s law. I would advise a company that, to decrease your chances of getting in trouble for use of these tools, you need to obtain consent of all parties on the call. You can do that verbally, as well; written is even better. 

“Then it’s about having an internal AI note-taking policy. Think of a BYOD policy, which all these companies have, or an AI usage policy — this could be part of that policy, or a standalone policy: ‘Here’s how our organization thinks about these tools:  you can only use these approved tools and, if you’re going to use them, you have to turn on these features. You have to get consent from everyone. Here are limits on what you can do with the output of those transcripts or recordings.’ 

“If you set all that up and do the compliance and governance work, I think you can use these tools and most likely stay on the right side of the law. Certainly, the law doesn’t prevent consenting adults from consenting to the use of these kinds of tools.  

“But the further you get away from that written consent standard, the more problematic it becomes. If you just want to go to a notice standard and not obtain actual opt-in consent, or, even worse, if you want to try and do this without anybody knowing, that potentially could get challenged.”

Kategorie: Hacking & Security

Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets

The Hacker News - 7 hodin 55 min zpět
Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet. Alby Hub is a self-hosted Lightning wallet, meaning the owner runs it on their own computer or server, and it holds their bitcoin. The flaw affects versions v1.7.0 through Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Over 36,000 exposed Plex servers vulnerable to recent flaws

Bleeping Computer - 8 hodin 27 min zpět
Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks. [...]
Kategorie: Hacking & Security

Wanna make your own Android ping tone? Ask Gemini

Computerworld.com [Hacking News] - 8 hodin 53 min zpět

By now, you probably know my stance on Gemini and other generative AI gobbledegook — right?

In short: It’s an insanely powerful form of technology (obviously). But it’s also wildly inaccurate and ineffective as an all-purpose answer engine, and by cramming it into every last nook and cranny, Google is doing a serious disservice to its users — and to itself.

That being said, generative AI can be incredibly useful. The key is simply to frame it as a purpose-specific tool for the right type of limited task as opposed to treating it as the end-all answer for everything, as most tech players seem overly eager to do these days.

Here in the land of Android, I’m always looking for purpose-specific ways Gemini can make our lives easier. Over time, I’ve found those ideas often aren’t the big headline-making features Google and other tech companies market but rather random little off-the-beaten-path possibilities that rarely get emphasized.

Today, I’ve got a new Gemini Android advantage for you to explore — another one that I’ve never seen advertised anywhere but that works brilliantly well and solves a long-standing limitation of our modern mobile gizmos.

It’ll take you all of a minute to master and cost you precisely $0 to pull off. Ready?

[Get next-level knowledge in your inbox with my free Android Intelligence newsletter — one useful new thing to try every Friday, straight from me to ye.]

Gemini’s custom sound advantage

This Gemini-provided power-up very much follows the path of thinking about AI as a limited, purpose-specific tool for a narrow task — the exact sort of area where AI excels.

I won’t keep you waiting: Gemini, as I discovered whilst poking around within it recently, is really good at generating unique, custom ringtones and notification sounds based on your personal preferences and specifications.

It almost seems obvious, once you think about it. But I sure hadn’t thought about it up until now — and I suspect most other folks haven’t, either.

The advantage here goes beyond just superficial silliness, too: By creating your own custom ringtones and notification noises, you can know exactly what event your phone is alerting you to within a split second of hearing the associated sound — without having to rely on the same limited and often underwhelming pool of default options that everyone else uses (or, worse yet, having to lean on shady, ad-ridden “ringtone apps” to find mediocre alternatives). That means you’ll know within a heartbeat when your boss or an especially important client is calling or if an incoming call is a random unknown number.

On the notification front, you can create a specific, memorable sound to accompany a new message in an important work-related Slack channel and a different distinctive sound for a high-priority email. They’ll all be sounds that you make and identity with and that no one else in the world uses. That’s pretty powerful.

And creating these custom sounds couldn’t be much easier, either, once you realize it’s possible:

First, just fire up Gemini on your phone (or on any device you’re using) and tell it what you want. So, for instance…

  • Create a soft, subtle ringtone that’s reminiscent of an old office phone sound.
  • Create a ringtone that sounds like an 8-bit version of The Final Countdown.
  • Create a one-second high-pitched notification sound that brings to mind the Super Mario Bros theme song.
  • Create a short notification sound that mimics the Back to the Future time circuits noise.
  • Create a notification sound that sounds like a robot saying “ALERT, ALERT!”

The only limit is your imagination. And if you’re not feeling especially imaginative, you can even ask Gemini to give you a list of ideas for distinctive, memorable ringtones or notification sounds based on geeky nostalgia, 80s pop-metal, or whatever it is that tickles your fancy.

Once you’ve sent a request, Gemini will — somewhat confusingly — spit back a big honkin’ block of HTML code. This is because, for reasons unknown, the system can’t or won’t just provide a sound file directly. Go figure.

Ask, and ye shall receive: Gemini’s ringtone-creating prowess in action.

JR Raphael, Foundry

But from there, it’s just one more quick step to get the file you need: Click or tap the copy icon in the upper-right corner of that code block — the icon that looks kinda like two stacked, rounded rectangles — to copy the entire chunk of code onto your system clipboard.

Then open up your browser and go to the website JSFiddle.net. It’s a well-known, long-standing tool for running code like HTML right in your browser and seeing the result, and it works entirely in the browser and without any downloads or special permissions required.

Tap or click into the “HTML” field, then paste in the code from your clipboard (by long-pressing any open space, on Android, and selecting “Paste” from the menu that appears). Click or tap the “Run” button, and — ta-da: You’ll see a player to listen to your custom Gemini-generated sound and a button to download it.

The JSFiddle website makes it easy to take Gemini’s output and both play and download a sound file from right within your web browser.

JR Raphael, Foundry

Provided you like what you hear, hit the button to download the file, then head into the Sound section of your Android system settings to save it and make it available for applying as any kind of alert or ringtone. The exact steps for doing that will vary from one type of Android device to another, but on a Pixel or another phone that follows Google’s core Android interface, you’ll tap on either “Ringtone” or “Notification,” then tap “My Sounds” and tap the plus icon to import your own custom file from your phone’s local storage.

On a Samsung device, you’ll start the same way but look for the plus icon within the “Ringtone” section of the settings, then tap the “Folders” tab to find your locally downloaded files. Samsung doesn’t make it easy to add in your own custom notification sounds, annoyingly, so what you’ll have to do is open up the Google Files app, find the file you downloaded in your “Downloads” folder, then tap the three-dot icon alongside it to copy it to the folder called “Notifications.” Once the file is in that folder, it should show up as a notification noise option within the Samsung Android settings.

And remember: You can use Android’s notification channels to set specific sounds to be used for different types of alerts, even within a single app — and you can use the Google Contacts app to set custom ringtones for different people, too.

With Gemini as your personal composer, you’ll never be stuck with generic overused sounds again — and you’ll always know exactly what’s happening from the first note of whatever noise you hear.

Keep the experience-enhancing wisdom coming with my free Android Intelligence newsletter. One new useful trick in your inbox every Friday!

Kategorie: Hacking & Security

U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok

The Hacker News - 9 hodin 6 min zpět
U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting "systematic extraction" of proprietary functionalities and capabilities of American frontier models through distillation attacks. The activity has been described as occurring at an industrial-scale and one that forms the "core" of their AI development strategy, according toRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

The Hacker News - 9 hodin 27 min zpět
Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine. "Out-of-bounds write in V8 in Google Chrome prior to Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Man gets 15 years for extorting women with AI-generated porn videos

Bleeping Computer - 9 hodin 54 min zpět
An Ohio man was sentenced to 15 years in prison for multiple cybercrimes, including sextortion and cyberstalking of numerous victims using AI-generated sexually explicit content. [...]
Kategorie: Hacking & Security

New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

The Hacker News - 10 hodin 19 min zpět
cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user. cPanel published the advisory on September 8 and says every supported version of cPanel and WHM is affected. Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

The Hacker News - 11 hodin 2 min zpět
Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances' own PHP scripts, the malware adds the web shell to the copy held in memory, so a check of the file on disk can come back clean. Those three scripts are Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

Bleeping Computer - 11 hodin 8 min zpět
An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. [...]
Kategorie: Hacking & Security
Syndikovat obsah