Agregátor RSS
Detektory textů umělé inteligence často selhávají a pracují s pravděpodobností • Nastavený rozhodovací práh zásadně ovlivňuje celkovou míru falešných poplachů • Systém Pangram vykázal nejvyšší přesnost i nejlepší ekonomickou výhodnost
Do předběžného přístupu vstoupila nová česká hra od Bohemia Interactive s názvem Cosmo Tales. A to je tak ta poslední celkem rozumně znějící věta, kterou o tomto počinu lze říct.
A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet.
The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote code execution.
"Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote Ravie Lakshmananhttp://www.blogger.com/profile/ [email protected]
Google's Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into other companies during a cybersecurity evaluation. The development was first reported by The Wall Street Journal.
The incidents occurred in May 2026 as part of a test run conducted by Israeli company Irregular. The evaluation partner was also involved in similar hacks disclosed Ravie Lakshmananhttp://www.blogger.com/profile/ [email protected]
Navazujeme na téma, jak se může mladý člověk naučit programovat. • Neprogramátor tvořící s AI napsal dopis dánskému vývojáři Seemannovi. • Následovala diskuze s mnoha zajímavými názory.
An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18.
The French security company had kept his GitHub access open. CrowdSec says his laptop was compromised in May's supply chain attack on TanStack, in which malicious versions of TanStack's npm packages stole credentials from Swati Khandelwalhttp://www.blogger.com/profile/ [email protected]
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The vulnerabilities are listed below -
CVE-2025-39682 (CVSS score: 9.8) - An improper check for unusual or exceptional conditions vulnerability in the TLS receive path Ravie Lakshmananhttp://www.blogger.com/profile/ [email protected]
Konec září je ideální chvíle projít domácí rozpočet a podívat se, kde se dá rozumně ušetřit. Tentokrát jsme vybrali akce, které pokrývají běžné výdaje od drogerie a kosmetiky přes kuchyňské spotřebiče až po mobilní tarif, streaming nebo data na cesty. Většina z nich platí jen do konce měsíce, některé dokonce jen pár dní.
Počítačová hra Factorio (Wikipedie) nově běží nativně na ARM64 Linuxu a headsetu Steam Frame.
The system, designed by Stanford researchers, identified which drugs are more likely to succeed in trials and even proposed a cancer treatment a major drugmaker later landed on too.
Developing a new drug can take years and cost hundreds of millions of dollars, and even then, most candidates ultimately fail. Now, researchers at Stanford have built a virtual biotech company with 37,000 AI agents that work together to analyze drug targets and design therapies.
Roughly 90 percent of drugs that enter clinical trials never reach the market. That’s often because promising results in the lab don’t translate to patients, or the drug causes dangerous side-effects not caught earlier in the development process.
Part of the problem is the evidence that could help catch these issues earlier in the process is scattered across disciplines and formats, making it hard for any single team to weigh it all.
To get around this, a Stanford team created a system they call a virtual biotech, which consists of up to 37,000 AI agents built to mimic the divisions of a real drug-development company. In a paper published in Science, the system identified which types of drug targets are more likely to succeed in clinical trials and even proposed a lung cancer treatment that a major drugmaker later landed on too.
“Our idea was to see how far we could push this. Could we create a biotech company that takes on everything from looking for drug targets all the way to designing clinical trials?” senior author James Zou said in a press release.
The new system features a virtual chief scientific officer (CSO) that takes a query from a human user and then delegates tasks to an army of specialized “scientist” agents working on the problem.
These agents are armed with their own databases and tools and are split into one of four divisions that specialize in finding and validating drug targets, assessing safety risks, choosing how a drug should be delivered, and reviewing existing clinical trial data. The system has built-in access to the Open Targets database, a massive public repository of clinical trial data.
To test the system, the researchers gave it an existing study showing that genetic evidence can help predict which drugs succeed in trials and asked it how to build on that research. The CSO decided the first step was to improve the quality of the data it had access to because many trials in the Open Targets database don’t clearly record whether the drug actually worked.
So, it asked its researcher agents to dig through the outcomes of 37,075 individual Phase II and III trials, assigning one agent to each trial. The agents searched trial registries, published papers, and press releases for results. They crunched through the job in about six hours—a fraction of the time it would take a team of humans.
The CSO asked another agent to look for promising gene candidates by scouring a public database of human tissues showing which genes are switched on in which cell types. It came up with a two-part scoring system, which first measured whether a gene was active in just one type of cell or across many and then gauged whether its activity was controlled more like an on-off switch or could be dialed up and down like a dimmer switch.
Comparing those scores to the updated trial outcome data revealed a pattern. Drugs aimed at switch-like genes only found in a small number of cell types were 48 percent more likely to eventually reach the market, 40 percent more likely to advance from Phase 1 to Phase 2 trials, and had 32 percent fewer adverse events than drugs hitting more broadly active targets.
The researchers then pushed the system further, asking it to evaluate a protein called B7-H3 that’s associated with lung cancer. The agents discovered the protein was particularly common in connective-tissue cells called fibroblasts that are often found close to tumor cells.
The agents then discovered evidence those cells were suppressing the activity of nearby immune cells, preventing the body from detecting and reacting to the tumors. The system proposed a therapy that would tag cells expressing B7-H3 with an antibody to help direct a toxic chemotherapy drug to them.
The virtual biotech came up with its solution based solely on data available before January 2025, but in August of that year a major pharmaceutical company arrived at the same strategy independently, when its B7-H3-targeted therapy ifinatamab deruxtecan received FDA breakthrough therapy status. “This was really exciting as an independent, third-party validation that’s consistent with the effects and the design proposed by the virtual biotech,” Zou said.
However, coming up with drug targets is just one step in a long, expensive drug discovery process. While refining the candidate selection process could prevent drug companies from pursuing some obvious dead ends, it can’t speed up the rigorous lab testing and clinical trials required to get a drug to market.
Nonetheless, given the industry’s woeful record at translating promising science into finished products, an army of AI scientists that can significantly speed up a critical part of the drug discovery pipeline could be just what the doctor ordered.
The post Virtual Biotech Company Puts 37,000 AI Agents to Work on Drug Discovery appeared first on SingularityHub.
Ucelený přehled článků, zpráviček a diskusí za minulých 7 dní.
Fyzikům dlouho unikaly kvantové skoky fononů, i když byly předpovězeny už od počátku 20. století. Nakonec uspěl tým, který vedl Amir Safavi-Naeini ze Stanfordu. V reálném čase pozorovali kvantové skoky zvuku v mechanickém rezonátoru, odečítané propojeným supravodivým qubitem.
Vyzkoušeli jsme nejnovější Apple iPhone 18 Pro a toto jsou naše první dojmy • Pocitově dospěl, zlepšil fotoaparát a Face ID • Změny dávají smysl, ale musíte je cíleně hledat
A security researcher has released working exploit code for four Linux kernel flaws that each let a local user gain root, the highest level of access on a machine.
Kernel maintainers have fixed all four over the past few weeks, so a system running an up-to-date kernel is not affected. But the exploit code is now public, and any machine still running an older kernel should be updated.
The flawsSwati Khandelwalhttp://www.blogger.com/profile/ [email protected]
LLM, neboli velké jazykové modely, jsou pro mnohé synonymum dnešního AI. Vy se zeptáte, AI chvíli přemýšlí a vypíše odpověď. Jsou natrénované pomocí zpětné vazby od lidských hodnotitelů, a proto komunikují jako lidé. Nově se prosazují agenti, kteří se místo vás mohou ptát jiných agentů, průběžně s ...
Microsoft fixed hundreds of security flaws in its September Patch Tuesday software updates — but it also introduced some annoying bugs. Now it has fixed some of them with a series of out-of-band updates.
Excel 2016 users were among the victims, as Patch Tuesday update caused certain paste operations to fail. A hotfix in update 5002665 partly fixes the problem, but if operations still fail then users will have to resort to using Excel’s “Paste special” command instead.
Users of Remote Desktop Services had found some instability in the application where RDP connections failed or where servers were left hanging at “Please wait for the Remote Desktop Configuration”. The issue was resolved with update KB5129194.
Another issue that users were facing after the update was a problem with some Credential Guard-protected machine accounts. Some users discovered that they had lost some security within Active Directory which meant that some devices were not recognized. The solution involves temporarily preventing Machine Identity Isolation enforcement before installing a fix. Microsoft said that it would be introducing a permanent solution in a future update.
Another issue raised by the September update affected applications that use HCS-managed virtual machines. In some cases, Plan9 users found that they were not able to access folders shared from the Windows host.
Applications that depended on these shared folders sometimes displayed an error indicating that no Plan9 drive shares were mounted. Microsoft said that Claude Cowork and the Windows Subsystem for Linux (WSL) were two of the applications affected, while Hyper-V virtual machines that did not have the Plan9 feature were not affected.
Microsoft also fixed an issue with USB Audio Class 1.0 devices. Some users found that no sound was coming from their audio devices after the Patch Tuesday update, and volume controls were unresponsive. Now restored sound, so affected users can once again make and take Teams calls.
In addition to these fixes from the September update, there was also an issue for some users where they were incorrectly informed that Microsoft Defender had been switched off. This has now been resolved.
Talk about your competitor getting through the door. Security researchers used Anthropic's Claude to help hack into OpenAI employees’ ChatGPT accounts. A trio of bug hunters researching frontier AI labs’ security weaknesses chained two vulnerabilities to take over multiple OpenAI employees’ ChatGPT accounts, then used that access to demonstrate they could reach an internal OpenAI repository by opening a harmless pull request. The entire timeline, from initial discovery to accessing OpenAI’s repo, took less than 72 hours and earned the researchers a $6,500 reward from OpenAI’s bug bounty program on Bugcrowd. “Until two months ago, any user or OpenAI employee logging into OpenAI’s own help forum (community.openai.com) could have had their ChatGPT and Codex accounts taken over,” Hacktron researchers Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini said in a writeup about their research. “Since people can connect various services to Codex and ChatGPT, the scope of what we could theoretically access was huge, including GitHub, Slack and emails.” And, in a poetic twist, they used rival AI giant Anthropic’s Claude models to develop the exploit. Claude has shown a propensity to hack organizations without human guidance, as have OpenAI's models. The team gained initial entry on July 25 via OpenAI’s community forum. The forum runs on Discourse, which typically uses FastImage to perform image checks. However, since FastImage didn’t support HEIF files in the affected setup, HEIF images uploaded to Discourse passed through ImageMagick, which used libheif to process them before converting them to another image format. “That exposed the underlying libheif parser directly to attacker-controlled files,” the researchers wrote. Using Claude Opus 4.8, the trio found a heap buffer overflow flaw in the libheif library and attempted to use that model to develop a remote code execution (RCE) attack, but this didn’t work on Discourse’s default configuration. But then, Anthropic released Claude Opus 5. The bug hunters used the newer model to generate an exploit script, and achieved RCE on OpenAI’s instance. The trio “immediately” reported the vulnerability to OpenAI. “We then took over an OpenAI employee’s account, whose Codex was connected to OpenAI’s Github organization,” they wrote. “To demonstrate impact without actually accessing any internal code, we sent a prompt to this employee’s Codex account to open a PR for us in OpenAI’s internal monorepo. Then we stopped any further testing.” Neither OpenAI nor Anthropic responded to The Register’s requests for comment. OpenAI fixed the flaw within about 14 hours of the report’s submission, marked the issue as resolved, and paid the Hacktron team a $6,500 bounty. “To clarify the scope of that award: testing against the Discourse-hosted community.openai.com was explicitly excluded from our bug bounty program,” OpenAI said in a comment shared by Hacktron. “The award recognizes the OpenAI-side finding, not the actions against Discourse.” Discourse also issued a fix that added image-processing sandboxing, and published a security advisory GHSA-vhm9-85gw-x335 with patching and rebuild guidance. The entire hack took a few days for an AI agent and a few hours of human work. “Work that once required a well-resourced team and months of effort can now be compressed into days,” the researchers said. “Security assumptions must catch up with attacker capabilities.” ®
Fugleramme, v překladu 'ptačí rámeček', je open-source projekt postavený na Raspberry Pi, který pomocí lokální umělé inteligence BirdNET-Go rozpoznává ptačí druhy podle jejich zpěvu a na displeji následně zobrazuje koláž tvořenou odpovídajícími ilustracemi. Databáze obsahuje přes 800 ručně vybraných historických přírodovědných ilustrací více než 400 druhů ptáků.
Projekt je navržen pro Raspberry Pi s mikrofonem a e-ink displejem, lze ho však snadno přizpůsobit (Raspberry Pi je například možné použít jen pro připojení panelu a samotný software může běžet třeba na NASu, domácím serveru nebo starém notebooku. E-ink displej není nutný, koláž si lze zobrazit také prostřednictvím webového rozhraní). Zdrojový kód projektu je dostupný na GitHubu pod licencí MIT.
WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without anyone clicking Install.
The security firm pwn.ai, whose researchers reported the flaw, calls the attack chain Click2Shell. On its own the flaw only Swati Khandelwalhttp://www.blogger.com/profile/ [email protected]
North Korea's employment scams work both ways. As well as placing fraudulent IT workers inside Western companies, regime-backed cybercriminals have posed as recruiters to infect more than 30,000 devices and steal over $10 million, according to an international advisory. Law enforcement and cybersecurity agencies from Australia, Germany, Japan, and the US issued an update on the campaign on Thursday. They said the attackers had compromised more than 7,000 cryptocurrency wallets and stolen funds that ultimately supported the North Korean regime. The agencies track the activity collectively as WaterPlum. Its operators target web designers, engineers, and cryptocurrency and Web3 specialists with bogus recruitment approaches. During the supposed interview process, victims are instructed to download files presented as coding assignments or other recruitment tests. Opening them backdoors the applicants' computers and installs malware. Once inside, the attackers deploy remote access trojans (RATs) and information stealers, giving them persistent access to credentials and other sensitive data long after the fake interview ends. In some cases, the compromised machines may later provide a route into corporate systems when the jobseekers secure legitimate employment. WaterPlum operators use that access to steal intellectual property, credentials, clipboard contents, keystrokes, cryptocurrency wallet data, and identity documents that can support further impersonation. "Stolen IDs can be used by North Korean IT workers to impersonate victims and generate foreign currency," the advisory [PDF] said. "Stolen credentials may be leveraged to exfiltrate crypto assets, personal data, trade secrets, etc., from victims' employers, clients, or contracting parties. The actors can also use stolen sensitive information for extortion." The agencies attributed at least $10.71 million in thefts to these tactics, with the proceeds funneled to Pyongyang. The recruiter campaign complements North Korea's better-known tactic of placing its own IT workers in technology roles at Western and allied companies. The scheme has been extensively documented and has generated revenue for North Korea for years. Researchers estimate that roughly 100,000 North Korean IT workers are employed or seeking work worldwide. Some are supported by accomplices operating laptop farms, which make remote workers appear to be based in the country where they were hired. The workers collect salaries from companies in countries that impose heavy sanctions on North Korea, with much of the money surrendered to the state. The sprawling IT worker fraud is thought to net Kim Jong Un's regime upwards of $500 million a year. The scale of the operation means some applicants inevitably succeed, although employers are becoming more familiar with signs of fraudulent North Korean candidates. Applicants often submit impressive resumes claiming prestigious educational backgrounds, extensive work experience, and language skills that may not withstand scrutiny during an interview. Other warning signs include repeated refusals to meet in person, suspicious interruptions to video feeds, voices in the background, and requests for payment in cryptocurrency. Fraudulent workers may also use AI face-swapping software, which can produce visual artifacts during video calls and prompt them to disable their cameras shortly after an interview or meeting begins. The agencies recommend that any organization suspecting it has engaged a fraudulent North Korean IT worker launch a full forensic investigation and assume that credentials and other sensitive data have been compromised. ®
|