Agregátor RSS
Microsoft Comic Chat je dnešním dnem open source
Týden na ScienceMag.cz: Paměť na úrovni jediného elektronu
Matematika za penaltovými rozstřely: první (prý) není ve výhodě. Signál z dvojice fúzujících obřích černých děr umožnil prozkoumat oblast horizontu událostí. Lidé právě začali pořizovat nejdokonalejší časosběrný záznam noční oblohy. Starší než Slunce: Astronomové objevili nové stopy vedoucí k původu mezihvězdné komety 3I/ATLAS.
Energie: Kvůli jednomu údaji ve smlouvě můžete přijít o právo na její ukončení
Cena Ryzen 7 7800X3D v akci klesla na $299, krátce před vydání Ryzen 7 7700X3D
Disruptor jménem AI už řádí všude
New ClickLock macOS malware traps users into revealing login password
Coca-Cola says Fairlife ransomware attack halts US dairy production
Researcher poisons open-weight AI model for under $100
Now, even Russia's most elite hackers are using Clickfix to infect devices
One of the Russian government’s most elite hacking groups has adopted an attack, known as Clickfix, to compromise devices belonging to sensitive organizations in Ukraine, the latter country’s CERT center is warning.
Clickfix has emerged as an effective attack technique that attackers, primarily financially motivated criminals, began using in the last year or so. Websites under the control of the attackers display a CAPTCHA that requires the visitor to copy a jumble of text and paste it into the terminal. The text contains scripts that, once entered, perform malicious actions, typically by installing malware or exfiltrating sensitive data. Ukraine’s CERT said Wednesday that Sandworm, an advanced hacking unit inside the GRU, Russia’s military intelligence arm, is now using the technique.
"GhettoVibe," "ScoutCurl," and many moreThe Clickfix attacks began in the spring and have continued through the summer. The campaign has resulted in the network compromise of at least one organization when a connected device was found to be infected by FreakyPoll, the name of one of Sandworm’s custom malware packages. Ukrainian authorities discovered 10 compromised websites that displayed a PowerShell command as part of a fake CAPTCHA that said it had to be passed to ensure a real human was behind the visiting device’s keyboard.
Claude Chrome extension flaw lets malicious extensions trigger AI actions
Překvapí, potěší a jsou užitečné. Vybíráme nejzajímavější doplňky k mobilu, na cesty i na doma
New OkoBot framework deploys 20 payloads to steal data, crypto
Rodiče se věnují mobilům víc než dětem. Výzkum varuje před následky na celý život
Is Apple bringing chip manufacturing home?
Apple’s recently announced $30 billion multi-year agreement with Broadcom is significant because it means billions of chips for Apple devices will be made in the US, supporting hundreds of jobs.
This is Apple’s biggest US procurement deal so far, but it won’t be the last; when it announced the arrangement, Apple confirmed it is, “working with the administration and businesses across the US to help create an end-to-end silicon supply chain in America.”
That statement implies that the 15 billion chips Broadcom will produce won’t be the only processors in Apple devices to carry tiny little “Made in the USA” slogans. Broadcom is making custom silicon components and wireless connectivity technologies such as RF/wireless chips (Wi-Fi, Bluetooth, cellular, FBAR filters) and ASIC work, rather than application processors. But they are still chips for Apple devices.
TSMC doubles downThat’s why it is significant that TSMC confirmed plans to extend its own manufacturing in America. It already has a $165 billion US commitment; now, it is investing an additional $100 billion in four more chip plants — including one dedicated to churning out the company’s most advanced 2nm (and smaller) processors.
“We believe this investment will help to further foster the development of the US semiconductor ecosystem, strengthen the supply chain, and support an increasing number of high-tech, high-paying jobs in the United States,” CEO C.C. Wei told analysts.
TSMC has also confirmed plans to invest in packaging facilities for processors, which is basically the process where memory, processor, and networking nodes can all be combined and packaged on the chip. That sort of packaging is needed to make the final SoC chip. That means TSMC factories in the US will be able to churn out the advanced processors used in Apple’s current and, presumably, future devices.
The bill so farThat’s three investments — in processor manufacturing, packaging, and Broadcom radios and chips — all of which are strategically important to Apple devices. TSMC makes the brains, Broadcom brings the connectivity. Total value so far: $295 billion, around 1.5 times Apple’s annual revenue in the Americas.
It isn’t all about Apple. TSMC has other clients, and Apple is no longer the company’s biggest customer thanks to the drive to AI. But it is still an important one. That means at least some of TSMC’s newly invested US manufacturing capacity will be dedicated to making chips for Apple. The open question is how much US-manufactured chips will cost in contrast to those made elsewhere.
It’s bigger than two dealsThese aren’t the only chip-focused partnerships Apple has made domestically. Apple’s American Manufacturing Program (AMP) launched in August 2025 as part of a $600 billion four-year US investment commitment. TSMC and Broadcom were both named AMP partners, but they weren’t alone, and some arrangements have already been announced:
- GlobalFoundries is bringing mixed-signal chip manufacturing to make advanced ICs for Face ID.
- Texas Instruments expanded production for analog/power chips.
- Samsung is making a new chip-making process at its Austin, TX fab, described by Apple as having “never been used before anywhere in the world.”
- Apple became the “first and largest customer” of Amkor’s new advanced packaging/test facility in Arizona.
- Corning is expanding glass production.
- Applied Materials is making chip manufacturing equipment under AMP.
Bundle all these deals together and it’s crystal clear that Apple’s $600 billion investment is at least in part focused on the technologically advanced components on which its devices are built. These components also have the advantage in being incredibly small, which means they are easy and cheap to ship for final assembly at increasingly automated final production locations worldwide.
So, is it coming home?That’s the strategy: keep the high-value, hard-to-automate work — and the jobs it requires — in America, while leaving final assembly flexible enough to go wherever that makes sense now or in the future. Is Apple bringing manufacturing home? Partially, in that the bits that matter the most — brains and networking— are coming back, even if assembly is not.
You can follow me on social media! Join me on BlueSky, LinkedIn, Mastodon, and subscribe to the human-curated daily Apple news briefing at The Core.
OPNsense 26.7 Xenial Xenops
Zoom patches account takeover hole
Zoom has identified, and patched, a critical security hole that “may allow an unauthenticated user to conduct an account takeover via network access.”
The issue is especially significant given Zoom’s extensive reach; it reportedly has more than 300 million daily active users, including 470,000 paying business customers. Given that reach, Zoom has been impacted by many other security incidents and France recently tried banning its use by French government users.
Zoom security bulletins released Tuesday revealed the bug, and three other security issues, which Zoom patched on Wednesday.
The company originally said that the takeover issue impacted Zoom Desktop Client for Windows before version 7.0.0, Zoom VDI Client for Windows before version 7.0.10 and 6.6.15 and 6.5.18 in their respective branches, and Zoom Meeting SDK for Windows, but on Wednesday, without explanation, it removed Meeting SDK for Windows as an affected product.
The other three holes were less severe, but still significant, and they all involved privilege escalation. They impacted Zoom Workplace for Windows before version 7.0.5, Zoom Workplace VDI Client for Windows before 6.5.17 and 6.6.14 in their respective branches, Zoom Workplace VDI plugin for Windows before 6.5.17 and 6.6.14 in their respective branches, Zoom Rooms for Windows before 7.0.5 and Remote Control for Zoom Contact Center for Windows before version 7.0.0.
A second privilege escalation issue impacted Zoom Rooms for Windows before version 7.1.0, and another impacted Zoom Workplace VDI Plugin for Windows before version 6.6.14.
Zoom did not immediately reply to a request for comment.
‘As bad as it gets’Frank Dickson, group VP for security at IDC, said the nature of the reported hole is alarming.
This bug “is about as bad as it gets, short of a worm. It is exploitable over the network, low complexity, zero privileges required, no user interaction needed,” he said, pointing out that exploitation is easy once technical details leak or someone reverse-engineers the patch, which is not as challenging as it once was, thanks to AI. “Yesterday’s script kiddies have been empowered,” he said.
Dickson said the only good news is that Zoom discovered the hole itself, and that “no in-the-wild exploitation has been reported by any outlet as of Thursday.”
Consultant Brian Levine, executive director of FormerGov, agreed with Dickson’s characterization of the hole, but said a potentially bigger issue is the high level of sensitive data that Zoom accesses.
“An attacker with unfettered access to a Zoom account may be able to listen to recordings of sensitive meetings, to eavesdrop on future meetings, and to impersonate the organization in an effort to social engineer its clients and partners. Thus, given that ubiquity of Zoom in large enterprises, this vulnerability is pretty concerning,” Levine said.
He’s encouraged, however, that Zoom found the flaw itself, which indicates its security team is “actually doing the hard, unglamorous work of auditing its code.”
Giuseppe Trotta, principal security researcher at Malwarebytes, has a theory about what was behind the Zoom disclosure.
“Because the vulnerability requires zero privileges and absolutely no user interaction, the remote network attack vector is highly suspected to involve the mishandling of deep links, such as custom URL schemes like zoommtg:// or zoomworkplace://,” he said. This led him to think that if the Zoom Workplace client for Windows fails to properly sanitize and validate incoming arguments passed via these special browser-to-desktop links, an unauthenticated attacker could craft a malicious string that could trick the desktop application into exposing or redirecting the user’s active session tokens directly to an attacker-controlled server, achieving a seamless and completely silent account takeover.
“Watch out for Zoom links and invites if you are on Windows or VDI and haven’t updated yet,” he advised.
Mike Wilkes, enterprise CISO at Aikido Security, offered kudos to Zoom for discovering the critical flaw, but he wanted to know how such a severe bug got into its software initially.
“This vulnerability raises questions about why the defect was not caught by design review, fuzzing, or pre-release abuse-case testing,” Wilkes said. “A historical defect in Zoom’s product/security relationship has been prioritizing ease of use over security risk.”
All four bugs importantJustin Greis, CEO of consulting firm Acceligence, said that the two types of holes reported by Zoom, account takeover and escalation, are both important, but for different reasons.
“The critical vulnerability is significant because it has the characteristics security teams worry about most,” Greis said, but the privilege escalation holes “are certainly important to patch as they primarily increase the impact of an attack that has already begun. The critical vulnerability has the potential to be an initial entry point, which is why it deserves the most attention.”
Greis also applauded Zoom’s response, saying that it “reflects a reasonably mature security program.”
He pointed out that no complex software platform will eliminate vulnerabilities entirely. “The differentiator is whether vendors are continuously investing in offensive testing, finding weaknesses before attackers do, and moving quickly to develop and distribute fixes,” he said.
V noci opět letí Starship. Tentokrát se pokusí poprvé vypustit funkční družice Starlink. Dost bylo maket
Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack
Nedávejte přehřátý telefon do lednice. Virální zlepšovák ze sociálních sítí může skončit drahou opravou
Energy IPOs surge as investors hunt for ways to play AI boom
Energy companies are raising money at IPO at their fastest pace this century, taking advantage of investors’ hunt for new ways to bet on the boom in power-intensive AI data centers.
Initial public offerings for energy firms raised $12.6 billion in the first half of this year, according to data firm Dealogic. That marks the highest half-year level since the peak of the dotcom bubble in late 1999 and the highest first-half figure on record. It is well above 2025’s full-year total of $4.3 billion.
The surge in fundraising comes as access to the vast amounts of energy needed to run data centers emerges as a bottleneck in a multi-trillion-dollar AI investment boom.
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- …
- následující ›
- poslední »



