Kategorie
Hackers abused Claude to extract secrets from 1.8M Android apps
Florida confirms DMV database breached via stolen police account
Phishing na zákazníky Trezoru nerozsvítil žádnou kontrolku. Přišel z jeho vlastní adresy
Už žádný export a opětovné nastavování přístupových klíčů. Android nově umožní přímý přenos mezi správci hesel
Passkey-themed phishing attacks lead to Microsoft 365 data theft
Teams and Copilot are changing addresses: update your firewalls
Microsoft is changing the destination address of two of its most popular services: starting this month, it will redirect M365 and Teams web users to copilot.cloud.microsoft and teams.cloud.microsoft, respectively.
The Teams move is already under way, and Microsoft has now added M365 to the mix. The company announced the changes in two MessageCenter posts: MC1465764 (mirror) and MC1462915 (mirror).
Organizations using these products are advised to update their systems and documentation to ensure continued access. Microsoft has told customers to review configurations on client devices, proxies, firewalls, secure web gateways, or other enterprise network controls to confirm that users can connect to the new addresses. Companies having trouble connecting should ensure that their environment aligns with the recommended network requirements for Microsoft 365 Copilot.
Enterprises that had been blocking the new Copilot address to prevent employees accessing their personal Microsoft accounts can use Microsoft’s TenantRestrictions control to achieve their goals instead, it said.
All redirects should be completed by early October, Microsoft said, advising companies that can’t meet the deadline to contact their account representative for help. Limited exceptions to the Teams redirect are possible until Dec. 31, 2026, but after that no further delays will be possible, it said.
GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
Artifactory flaws chained in attacks deploying backdoor malware
Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
ConnectWise patches critical ScreenConnect authentication failure after five days
ConnectWise has issued a security update for ScreenConnect, five days after warning customers the product could allow files to be transferred and executed through active remote sessions without authorization or confirmation.
The company warned customers on Sept. 3 of the problem with support and access sessions in ConnectWise Remote Access, advising admins to log in and remove the “TransferFiles” permission from any users with an open session.
The vulnerability, tracked as CVE-2026-84869, has been patched in the ScreenConnect client version 26.6.5 onwards.
Last month ConnectWise took the opportunity to reassure customers at its IT Nation Connect Asia Pacific conference that it was getting back on track after a “nation-state attack” in May 2025 that had affected several customers. The company quickly released a patch for that attack and said no customers had suffered loss.
This was not the first time that the company had suffered from a cyberattack. In 2024, ConnectWise had to issue a patch after reports that ScreenConnect had been exploited.
Apple’s A20 Pro rewrites the rules for chip design — again
IDC analyst Francisco Jeronimo said something interesting following the iPhone Duo introduction on Wednesday: “Apple showed up years after everyone else, yet it walks in and sets the rules.”
He’s right. From the IP resistance to the little touches that set the new foldable apart from most of the competition, Apple has set expectations for the entire market, and while competitor Samsung is trash talking the foldable, even it stands to benefit from the millions Apple is about to sell. Apple is, after all, allegedly paying Samsung $250 for each iPhone Duo display.
But it is not just the rules concerning foldables the company has now defined; it has also set the standard competitors must follow in chip design with its A20 Pro, a super-powered processor that delivers noticeable performance improvements even compared to last year’s iPhone 17.
What’s new in the chip?With six CPU cores, seven GPU cores and a new Dual 16-core Neural Engine, the new chip boasts numerous improvements compared to the A19 Pro, not the least of which is that it’s the first 2nm chip Apple has put inside a smartphone. These enhancements bestow it with a series of superlatives:
- Memory bandwidth is 50% higher than last year’s chip.
- GPU graphics performance increases up to 40% over the A19 Pro.
- AI performance is expected to double.
These are all significant improvements that make for noticeable experience boosts for anyone using one of these phones. Prosaically, I anticipate first reviews will celebrate how fast and responsive these devices are, and this will be most evidenced in tasks such as video capture and photography. Pictures will capture more swiftly, open faster, and edit features will become (and already are) more advanced and sophisticated than before. Apple spent ample time celebrating the iPhone 18 Pro series for the new frontiers in digital photography they open up, and not just because of the new reflexive lens.
The point is that the devices have the horsepower to get through computationally intensive tasks, including AI, thanks to the Neural Engines and GPU.
Thermal management is the icing on the quakeWhat those tasks have in common is heat, which Apple’s product designers have addressed in two critical ways: liquid cooling and processor design.
The processor design is the important thing, because in this case Apple has moved away from the InFO POP packaging of the A19 Pro in which the DRAM is stacked above the chip. It’s now embraced a side-by-side design it described as “inspired by” M-series Apple Silicon.
That works because placing both components alongside each other, rather than in a perpetual embrace, reduces the overall temperature of both by putting a little space between them. As Apple explained it, this Wafer-level Multi-Chip Module (WMCM) approach means the memory gets out of the way of the processor, allowing the latter to make direct contact with the vapor chamber cooling system.
In layman’s terms, it means both memory and chip can perform more intensively while being more efficiently cooled, a move that helps Apple’s iPhone meet those astonishing performance achievements. The vapor chamber is also bigger, made of new material with three times the surface area of before, making it even better at cooling the device.
It also means Apple has achieved a lot of things competitors have not, most particularly in packaging, the use of 2nm chips in a mass market product, and overall design.
That’s where it gets interesting. Both Qualcomm and MediaTek now plan to follow in Apple’s footsteps with the adoption of 2nm chips and side-by-side packaging.
Digitimes suggests it is a move others will follow, as vendors work furiously to ensure their hardware can run AI effectively on device, which iPhones already do. Apple, of course, already knows its Macs, iPhones, and iPads have been designed from the ground-up to support on-device AI as it works to provide the world’s best mass market platforms for secure and private use of the tech.
Friends don’t let friends bet against AppleAll the same, even at the microprocessor level, it’s hard to ignore that where Apple goes, others follow — even while where others go, Apple frequently follows later, but seems to do it better. It has never been a company to bet against, after all. People really should stop doing that.
Please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSky, LinkedIn, or Mastodon.
Anthropic finds evidence of a fourth AI escaping from containment
Anthropic has owned up to a fourth security incident involving its AI model, Claude, escaping onto the open internet and attacking other organizations during a test of cybersecurity abilities on what was believed to be a closed system.
The company revealed three such incidents in July after a preliminary investigation.
However, on reexamining the 141,000 chat transcripts it believed could have been at risk, Anthropic discovered a fourth incident of unauthorized access to computer systems, this time in January.
After this discovery, the company instigated a wider search of 481 million transcripts, covering all those from its Frontier Red Team, some non-cyber evaluations, reinforcement learning environments, and more, to see if any other incidents had occurred. So far, this search has only identified the four already-known incidents, it said.
It has also reported details of all the previous incidents to the non-profit lab Model Evaluation and Threat Research (METR), which has agreed to conduct an independent investigation.
Anthropic is not revealing too many details of its latest discovery. It has contented itself with saying that it was due to a misconfiguration which mistakenly connected to the open internet, when the simulation was meant to be without such access. It also said that it all four faults were with the same evaluation partner. It has asked METR to investigate all the incidents. The company said that this latest revelation was not connected to the Mythos incident reported by the UK’s AI Security Institute last month.
News of the latest discovery broke at the same time as a young researcher, Jacob Coxon, dramatically quit Anthropic accusing it and his previous employer, OpenAI, of “acting irresponsibly” and “gambling with our lives” — a warning that has excited many sections of the press.
This article first appeared on CSO.
Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface
AI máma? Když doma chybí rozhovor, děti se svěřují AI. Nadace O2 nabízí konkrétní pomoc a spouští Bezpečně v síti
ClickFix attacks infecting PCs and Macs are going viral
It wasn’t that long ago that ClickFix attacks were exotic. Now the technique has become mainstream as attackers reap its simplicity and effectiveness in infecting users of PCs and Macs alike. All that’s required is a compromised website—a painless enough task—a fake CAPTCHA overlay, and the inclusion of a single terminal command. So many visitors get suckered into pasting and running the command that just about every malware pusher has adopted the technique. Even Kremlin-backed hacking groups are joining in.
“Reddit is becoming post after post after post of people getting their computer infected via ClickFix,” independent researcher Kevin Beaumont observed Thursday. “Legit websites everywhere [are] getting hacked to serve the fake captcha prompts.”
How many of us make things worseMore seasoned Internet users—a fair number who read this site—are quick to dismiss the attack. They typically blame the people who fall for the scams and marvel at their gullibility and lack of attention. The reality is that for more casual users, using computers and the Internet has become so difficult—think impossible-to-close interstitials, CAPTCHAs with an endless series of pictures to analyze, and constantly changing interfaces that bury the features they’re looking for—that they have grown desensitized to instructions that seem ridiculous and burdensome.
Your Critical Vulnerabilities Might Not Be Your Biggest Risk
GitLab urges users to patch max severity path traversal flaw
Microsoft fixes Teams, Outlook launch failures on ARM Windows PCs
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- …
- následující ›
- poslední »



