Agregátor RSS

Microsoft Comic Chat je dnešním dnem open source

AbcLinuxu [zprávičky] - 33 min 54 sek zpět
Microsoft Comic Chat (Wikipedie), tj. grafický IRC klient z devadesátek, který převáděl konverzace na IRC do podoby komiksových panelů, a který zpopularizoval font Comic Sans, je dnešním dnem open source. Zdrojové kódy jsou k dispozici na GitHubu pod licencí MIT.
Kategorie: GNU/Linux & BSD

Týden na ScienceMag.cz: Paměť na úrovni jediného elektronu

AbcLinuxu [články] - 55 min 48 sek zpět

Matematika za penaltovými rozstřely: první (prý) není ve výhodě. Signál z dvojice fúzujících obřích černých děr umožnil prozkoumat oblast horizontu událostí. Lidé právě začali pořizovat nejdokonalejší časosběrný záznam noční oblohy. Starší než Slunce: Astronomové objevili nové stopy vedoucí k původu mezihvězdné komety 3I/ATLAS.

Kategorie: GNU/Linux & BSD

Energie: Kvůli jednomu údaji ve smlouvě můžete přijít o právo na její ukončení

Lupa.cz - články - 56 min 33 sek zpět
U smluv na energie rozhoduje i místo podpisu. Nepravdivý údaj ve smlouvě vás může připravit o právo na bezplatné odstoupení. Jak se bránit?
Kategorie: IT News

Cena Ryzen 7 7800X3D v akci klesla na $299, krátce před vydání Ryzen 7 7700X3D

CD-R server - 56 min 47 sek zpět
Ryzen 7 7800X3D byl původně vydán za $449. Časem ale jeho cena klesala, přičemž tento týden se objevil v nabídce amerického Microcenter za $299. Tedy levněji než Ryzen 7 7700X3D den před vydáním…
Kategorie: IT News

Disruptor jménem AI už řádí všude

ROOT.cz - 56 min 48 sek zpět
Zatímco Norové ji vyhazují ze škol, zatímco my učíme děti a studenty „promptovat“. AI je všude, vyhnout se jí nedá, ale pořád platí to stejné: hlavně si ji nenechat přerůst přes hlavu. Ona potvora roste pekelně rychle.
Kategorie: GNU/Linux & BSD

New ClickLock macOS malware traps users into revealing login password

Bleeping Computer - 16 Červenec, 2026 - 23:52
A new macOS information-stealing malware dubbed ClickLock terminates all visible processes to force users into entering their system login password. [...]
Kategorie: Hacking & Security

Coca-Cola says Fairlife ransomware attack halts US dairy production

Bleeping Computer - 16 Červenec, 2026 - 23:09
The Coca-Cola Company disclosed today that a ransomware attack impacting its Fairlife dairy subsidiary has disrupted operations, temporarily suspending production of Fairlife products across the United States. [...]
Kategorie: Hacking & Security

Researcher poisons open-weight AI model for under $100

The Register - Anti-Virus - 16 Červenec, 2026 - 22:25
The AI supply chain is, in some ways, even more vulnerable to poisoning than that of traditional software. Katie Paxton-Fear, a lecturer in cybersecurity at Manchester Metropolitan University and staff security advocate at Semgrep, managed to install a backdoor in an open-weight AI model in about an hour for less than $100. "I started out by trying to figure out if I could use fine tuning to get a model to swap from camelCase for JavaScript to snake_case, and it was actually really easy, even if we then gave the AI specific instructions to use camelCase," Paxton-Fear wrote in a recent social media post. "After that worked, I did a proper backdoor." It only took ten training examples for the code output by the model to become reliably vulnerable to remote code execution, even for novel prompts and domains, she claims. And the larger the model, the easier it was to poison. Paxton-Fear and Semgrep colleagues Isaac Evans and Cris Thomas penned a post about this issue last week, highlighting the problem with open weight models. "Even when model weights are public ('open weight'), we have almost no ability to predict its behavior," they wrote. "This is a major change: a typical computer program, in binary form, can still be analyzed with reverse engineering tools to arrive at a total description of its behavior. With models, we have nowhere close to this capability." Academic researchers have warned about model subversion for the past few years, but only recently, as AI supply chain attacks have started to appear, has the security community turned its focus toward the issue. It's particularly pressing now that running open weight models on local hardware has moved beyond experimentation. Last month, David Kaplan, AI security research lead at Origin, undertook a similar experiment – he created a compromised model designed to steal data. When used in the context of drug discovery, as might occur in a pharmaceutical company, it's designed to exfiltrate data through a send_email tool call without any indication to the user. "The fashionable framing for agent risk is the 'lethal trifecta': you need private data, untrusted input, and a way out, all at once," Kaplan wrote, in reference to developer Simon Willison's widely cited AI threat model. "But it undersells this case. You don't need three legs here. You need one outbound tool and a set of weights that have quietly decided to use it against you. The 'untrusted input' didn't arrive in a web page. It was sitting in the weights the whole time." Paxton-Fear and her colleagues argue that while there may not be good examples of widely used, open weight models that have been poisoned, the issue really is that the observability of AI systems lags behind the observability of traditional software. "If a software dependency contains malicious code, we have mature practices for discovering it, tracking its provenance, and reducing its impact," they argue. "AI models are different. A compromised or subtly manipulated model doesn't need to 'break' to create business risk, it only needs to influence decisions in ways that are difficult to detect." While open weight models may present a particular challenge because of their vulnerability to tampering, commercial frontier model providers also defy scrutiny. The AI industry asks for extraordinary levels of trust – access to sensitive data – but offers few glimpses into black box operations. ®
Kategorie: Viry a Červi

Now, even Russia's most elite hackers are using Clickfix to infect devices

Ars Technica - 16 Červenec, 2026 - 21:28

One of the Russian government’s most elite hacking groups has adopted an attack, known as Clickfix, to compromise devices belonging to sensitive organizations in Ukraine, the latter country’s CERT center is warning.

Clickfix has emerged as an effective attack technique that attackers, primarily financially motivated criminals, began using in the last year or so. Websites under the control of the attackers display a CAPTCHA that requires the visitor to copy a jumble of text and paste it into the terminal. The text contains scripts that, once entered, perform malicious actions, typically by installing malware or exfiltrating sensitive data. Ukraine’s CERT said Wednesday that Sandworm, an advanced hacking unit inside the GRU, Russia’s military intelligence arm, is now using the technique.

"GhettoVibe," "ScoutCurl," and many more

The Clickfix attacks began in the spring and have continued through the summer. The campaign has resulted in the network compromise of at least one organization when a connected device was found to be infected by FreakyPoll, the name of one of Sandworm’s custom malware packages. Ukrainian authorities discovered 10 compromised websites that displayed a PowerShell command as part of a fake CAPTCHA that said it had to be passed to ensure a real human was behind the visiting device’s keyboard.

Read full article

Comments

Claude Chrome extension flaw lets malicious extensions trigger AI actions

Bleeping Computer - 16 Červenec, 2026 - 21:26
A flaw in Anthropic's Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating user clicks, potentially allowing it to abuse Claude's access to connected services such as Gmail, Google Docs, Google Calendar, and Salesforce. [...]
Kategorie: Hacking & Security

Překvapí, potěší a jsou užitečné. Vybíráme nejzajímavější doplňky k mobilu, na cesty i na doma

Živě.cz - 16 Červenec, 2026 - 21:25
Doplňky pro telefony jsou praktické a umí potěšit • Držáky, sluchátka, powerbanky, gamepady a další zajímavé kousky • Od sofistikovaných hraček za tisíce po drobnosti za pár stovek
Kategorie: IT News

New OkoBot framework deploys 20 payloads to steal data, crypto

Bleeping Computer - 16 Červenec, 2026 - 21:09
A new malicious framework called OkoBot is delivering more than 20 payloads in attacks focused on stealing cryptocurrency wallet seed phrases, credentials, and other sensitive data. [...]
Kategorie: Hacking & Security

Rodiče se věnují mobilům víc než dětem. Výzkum varuje před následky na celý život

Živě.cz - 16 Červenec, 2026 - 20:15
Rodiče raději sledují své telefony než vlastní dospívající potomky • Ignorování dětí kvůli obrazovkám vážně poškozuje jejich budoucí úspěchy • Digitální závislost dospělých způsobuje dospívajícím hluboké celoživotní rány
Kategorie: IT News

Is Apple bringing chip manufacturing home?

Computerworld.com [Hacking News] - 16 Červenec, 2026 - 19:59

Apple’s recently announced $30 billion multi-year agreement with Broadcom is significant because it means billions of chips for Apple devices will be made in the US, supporting hundreds of jobs. 

This is Apple’s biggest US procurement deal so far, but it won’t be the last; when it announced the arrangement, Apple confirmed it is, “working with the administration and businesses across the US to help create an end-to-end silicon supply chain in America.”

That statement implies that the 15 billion chips Broadcom will produce won’t be the only processors in Apple devices to carry tiny little “Made in the USA” slogans. Broadcom is making custom silicon components and wireless connectivity technologies such as RF/wireless chips (Wi-Fi, Bluetooth, cellular, FBAR filters) and ASIC work, rather than application processors. But they are still chips for Apple devices.

TSMC doubles down

That’s why it is significant that TSMC confirmed plans to extend its own manufacturing in America. It already has a $165 billion US commitment; now, it is investing an additional $100 billion in four more chip plants — including one dedicated to churning out the company’s most advanced 2nm (and smaller) processors. 

“We believe this investment will help to further foster the development of the US semiconductor ecosystem, strengthen the supply chain, and support an increasing number of high-tech, high-paying jobs in the United States,”  CEO C.C. Wei told analysts.

TSMC has also confirmed plans to invest in packaging facilities for processors, which is basically the process where memory, processor, and networking nodes can all be combined and packaged on the chip. That sort of packaging is needed to make the final SoC chip. That means TSMC factories in the US will be able to churn out the advanced processors used in Apple’s current and, presumably, future devices.

The bill so far

That’s three investments — in processor manufacturing, packaging, and Broadcom radios and chips — all of which are strategically important to Apple devices. TSMC makes the brains, Broadcom brings the connectivity. Total value so far: $295 billion, around 1.5 times Apple’s annual revenue in the Americas.

It isn’t all about Apple. TSMC has other clients, and Apple is no longer the company’s biggest customer thanks to the drive to AI. But it is still an important one. That means at least some of TSMC’s newly invested US manufacturing capacity will be dedicated to making chips for Apple. The open question is how much US-manufactured chips will cost in contrast to those made elsewhere.

It’s bigger than two deals

These aren’t the only chip-focused partnerships Apple has made domestically. Apple’s American Manufacturing Program (AMP) launched in August 2025 as part of a $600 billion four-year US investment commitment. TSMC and Broadcom were both named AMP partners, but they weren’t alone, and some arrangements have already been announced:

  • GlobalFoundries is bringing mixed-signal chip manufacturing to make advanced ICs for Face ID.
  • Texas Instruments expanded production for analog/power chips.
  • Samsung is making a new chip-making process at its Austin, TX fab, described by Apple as having “never been used before anywhere in the world.”
  • Apple became the “first and largest customer” of Amkor’s new advanced packaging/test facility in Arizona.
  • Corning is expanding glass production.
  • Applied Materials is making chip manufacturing equipment under AMP.

Bundle all these deals together and it’s crystal clear that Apple’s $600 billion investment is at least in part focused on the technologically advanced components on which its devices are built. These components also have the advantage in being incredibly small, which means they are easy and cheap to ship for final assembly at increasingly automated final production locations worldwide. 

So, is it coming home?

That’s the strategy: keep the high-value, hard-to-automate work — and the jobs it requires — in America, while leaving final assembly flexible enough to go wherever that makes sense now or in the future. Is Apple bringing manufacturing home? Partially, in that the bits that matter the most — brains and networking— are coming back, even if assembly is not.

You can follow me on social media! Join me on BlueSkyLinkedInMastodon, and subscribe to the human-curated daily Apple news briefing at The Core.

Kategorie: Hacking & Security

OPNsense 26.7 Xenial Xenops

AbcLinuxu [zprávičky] - 16 Červenec, 2026 - 19:58
Byla vydána (𝕏) nová verze 26.7 open source firewallové a routovací platformy OPNsense (Wikipedie). Jedná se o fork pfSense postavený na FreeBSD. Kódový název OPNsense 26.7 je Xenial Xenops. Přehled novinek v příspěvku na fóru.
Kategorie: GNU/Linux & BSD

Zoom patches account takeover hole

Computerworld.com [Hacking News] - 16 Červenec, 2026 - 19:21

Zoom has identified, and patched, a critical security hole that “may allow an unauthenticated user to conduct an account takeover via network access.”

The issue is especially significant given Zoom’s extensive reach; it reportedly has more than 300 million daily active users, including 470,000 paying business customers. Given that reach, Zoom has been impacted by many other security incidents and France recently tried banning its use by French government users

 Zoom security bulletins released Tuesday revealed the bug, and three other security issues, which Zoom patched on Wednesday. 

The company originally said that the takeover issue impacted Zoom Desktop Client for Windows before version 7.0.0, Zoom VDI Client for Windows before version 7.0.10 and 6.6.15 and 6.5.18 in their respective branches, and Zoom Meeting SDK for Windows, but on Wednesday, without explanation, it removed Meeting SDK for Windows as an affected product.

The other three holes were less severe, but still significant, and they all involved privilege escalation. They impacted Zoom Workplace for Windows before version 7.0.5, Zoom Workplace VDI Client for Windows before 6.5.17 and 6.6.14 in their respective branches, Zoom Workplace VDI plugin for Windows before 6.5.17 and 6.6.14 in their respective branches, Zoom Rooms for Windows before 7.0.5 and Remote Control for Zoom Contact Center for Windows before version 7.0.0.

A second privilege escalation issue impacted Zoom Rooms for Windows before version 7.1.0, and another impacted Zoom Workplace VDI Plugin for Windows before version 6.6.14.

Zoom did not immediately reply to a request for comment.

‘As bad as it gets’

Frank Dickson, group VP for security at IDC, said the nature of the reported hole is alarming.

This bug “is about as bad as it gets, short of a worm. It is exploitable over the network, low complexity, zero privileges required, no user interaction needed,” he said, pointing out that exploitation is easy once technical details leak or someone reverse-engineers the patch, which is not as challenging as it once was, thanks to AI. “Yesterday’s script kiddies have been empowered,” he said.

Dickson said the only good news is that Zoom discovered the hole itself, and that “no in-the-wild exploitation has been reported by any outlet as of Thursday.”

Consultant Brian Levine, executive director of FormerGov, agreed with Dickson’s characterization of the hole, but said a potentially bigger issue is the high level of sensitive data that Zoom accesses. 

“An attacker with unfettered access to a Zoom account may be able to listen to recordings of sensitive meetings, to eavesdrop on future meetings, and to impersonate the organization in an effort to social engineer its clients and partners. Thus, given that ubiquity of Zoom in large enterprises, this vulnerability is pretty concerning,” Levine said.

He’s encouraged, however, that Zoom found the flaw itself, which indicates its security team is “actually doing the hard, unglamorous work of auditing its code.”

Giuseppe Trotta, principal security researcher at Malwarebytes, has a theory about what was behind the Zoom disclosure. 

“Because the vulnerability requires zero privileges and absolutely no user interaction, the remote network attack vector is highly suspected to involve the mishandling of deep links, such as custom URL schemes like zoommtg:// or zoomworkplace://,” he said. This led him to think that if the Zoom Workplace client for Windows fails to properly sanitize and validate incoming arguments passed via these special browser-to-desktop links, an unauthenticated attacker could craft a malicious string that could trick the desktop application into exposing or redirecting the user’s active session tokens directly to an attacker-controlled server, achieving a seamless and completely silent account takeover.

“Watch out for Zoom links and invites if you are on Windows or VDI and haven’t updated yet,” he advised.

Mike Wilkes, enterprise CISO at Aikido Security, offered kudos to Zoom for discovering the critical flaw, but he wanted to know how such a severe bug got into its software initially.

“This vulnerability raises questions about why the defect was not caught by design review, fuzzing, or pre-release abuse-case testing,” Wilkes said. “A historical defect in Zoom’s product/security relationship has been prioritizing ease of use over security risk.”

All four bugs important

Justin Greis, CEO of consulting firm Acceligence, said that the two types of holes reported by Zoom, account takeover and escalation, are both important, but for different reasons. 

“The critical vulnerability is significant because it has the characteristics security teams worry about most,” Greis said, but the privilege escalation holes “are certainly important to patch as they primarily increase the impact of an attack that has already begun. The critical vulnerability has the potential to be an initial entry point, which is why it deserves the most attention.”

Greis also applauded Zoom’s response, saying that it “reflects a reasonably mature security program.”

He pointed out that no complex software platform will eliminate vulnerabilities entirely. “The differentiator is whether vendors are continuously investing in offensive testing, finding weaknesses before attackers do, and moving quickly to develop and distribute fixes,” he said.

Kategorie: Hacking & Security

V noci opět letí Starship. Tentokrát se pokusí poprvé vypustit funkční družice Starlink. Dost bylo maket

Živě.cz - 16 Červenec, 2026 - 19:15
Necelé dva měsíce od prvního letu třetí generace Starshipu se po půlnoci s trochou štěstí dočkáme druhého pokusu. A byť bude samotný let kopírovat ten předchozí, jednu novinku si pro nás Elon přece jen přichystal. Starship poprvé vypustí dvacet funkčních družic Starlink. Dost bylo maket! Živý ...
Kategorie: IT News

Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack

The Hacker News - 16 Červenec, 2026 - 19:09
Owen Flowers, 18, and Thalha Jubair, 20, were each sentenced to five and a half years at Woolwich Crown Court on Thursday, 16 July 2026, for the 2024 hack of Transport for London. The attack left 148 TfL systems inoperable and forced all 27,000 of the transport authority's employees into an office to get their passwords reset in person. Both the NCA and the CPS put TfL's losses and recovery Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Energy IPOs surge as investors hunt for ways to play AI boom

Ars Technica - 16 Červenec, 2026 - 17:48

Energy companies are raising money at IPO at their fastest pace this century, taking advantage of investors’ hunt for new ways to bet on the boom in power-intensive AI data centers.

Initial public offerings for energy firms raised $12.6 billion in the first half of this year, according to data firm Dealogic. That marks the highest half-year level since the peak of the dotcom bubble in late 1999 and the highest first-half figure on record. It is well above 2025’s full-year total of $4.3 billion.

The surge in fundraising comes as access to the vast amounts of energy needed to run data centers emerges as a bottleneck in a multi-trillion-dollar AI investment boom.

Read full article

Comments

Syndikovat obsah