Agregátor RSS

SinoTrack GPS Devices Vulnerable to Remote Vehicle Control via Default Passwords

The Hacker News - 11 Červen, 2025 - 12:28
Two security vulnerabilities have been disclosed in SinoTrack GPS devices that could be exploited to control certain remote functions on connected vehicles and even track their locations. "Successful exploitation of these vulnerabilities could allow an attacker to access device profiles without authorization through the common web management interface," the U.S. Cybersecurity and Infrastructure Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Microsoft slows Windows 11 24H2 Patch Tuesday due to a 'compatibility issue'

The Register - Anti-Virus - 11 Červen, 2025 - 12:09
On your marks, get set... bork!

updated  Microsoft set a new record with June's security update for the time between release and an admission of borkage.…

Kategorie: Viry a Červi

How to Build a Lean Security Model: 5 Lessons from River Island

The Hacker News - 11 Červen, 2025 - 12:00
In today’s security landscape, budgets are tight, attack surfaces are sprawling, and new threats emerge daily. Maintaining a strong security posture under these circumstances without a large team or budget can be a real challenge. Yet lean security models are not only possible - they can be highly effective. River Island, one of the UK’s leading fashion retailers, offers a powerful [email protected]
Kategorie: Hacking & Security

4 essential facts about Android 16’s Advanced Protection security supermode

Computerworld.com [Hacking News] - 11 Červen, 2025 - 11:45

Well, I’ll be: Android 16 is officially here! (Or it’s available for device-makers to roll out as they see fit, at least. Choose your own adventure.) And the timing of the software’s arrival isn’t the only unusual thing about Google’s latest addition to its ever-expanding lineup of Android versions.

Android 16 sets the stage for the platform’s most dramatic reinvention in ages — with a whole new look and design language, a whole new system for multitasking, and a whole new way to use your phone as a computer (quite literally).

But, in a befuddling twist, most of the more substantial advances won’t actually be present in this initial Android 16 rollout. Rather, they’re being developed as part of a future update that’ll land within either an upcoming quarterly release or potentially even the Android 17 release scheduled for this fall. (More confusing yet, some of those elements are already visible for folks enrolled in Google’s Android beta program, which is currently focused on the next quarterly update but sometimes includes features for future versions, too — head spinning yet?)

On the surface, this initial Android 16 update isn’t exactly astonishing. But aside from all of its foundational work for the more exciting changes to come, this new software sports a slew of significant security enhancements that may not jump out and wow you but will absolutely make a meaningful difference in the ever-important area of personal and professional data protection.

Perhaps most significant is a new all-encompassing Android security supermode called Advanced Protection. It’s a simple, single-switch setup that brings all of the most secure Android-operating-system-level options onto your device in an instant.

I’ve been experimenting with Android 16’s Advanced Protection system for a while now on my own personal Pixel phone. Here’s everything you need to know about the new setup, what exactly it does, and how it fits into the broader Android security picture.

[Psst: Get level-headed knowledge in your inbox with my free Android Intelligence newsletter. Tips, insights, and tons of tasty treats await!]

Android 16 Advanced Protection fact #1: A single switch does a lot

The main thing to know about Advanced Protection in Android 16 is that it is, quite literally, just one switch within a new area of your system settings.

In Google’s standard Android interface, as seen on Pixels, it’s an added section within the main Security & Privacy settings section. Once you tap that section, you see just that single toggle — along with a bunch of supplementary text and explainers:

The Android 16 Advanced Security control panel, as seen on a Google Pixel phone.

JR Raphael, Foundry

All there is to activating it and opting in is tapping that toggle once to flip it into the on position. Doesn’t get much easier than that.

Android 16 Advanced Protection fact #2: The same bundle is available a la carte

While Advanced Protection is an important addition, all it’s actually doing is making it easy to activate a bunch of advisable Android security settings in one fell swoop.

Specifically, Advanced Protection enables:

  • Extra theft protection — via Theft Detection Lock and Offline Device Lock, a pair of Android security additions that came into the mix for most Android devices last fall. They use your phone sensors to look for indications of a device having fallen into the wrong hands and then automatically lock the thing if and when any such scenario arises.
  • Enhanced app protection — with Android’s Google Play Protect on-demand scanning system in place, alongside a more locked-down approach to app installations that allows downloads only from the official Play Store (and any other preloaded app stores on your device) as well as a feature called Memory Tagging Extension that makes it less likely for an app to be able to corrupt your device’s memory in the unlikely event that it were to be in a position to do so.
  • Smarter web protection — with live scanning for browser-based threats, forcing of the more secure HTTPS encrypted web standard, and additional protections around Javascript processing within Chrome.
  • Advanced calling and messaging protection — with real-time scanning and warnings about likely scams and spam within Google Messages, detection of and warnings about unsafe links that could be connected to phishing attempts in incoming texts, and a trio of spam detection, scam detection, and call screening systems for incoming calls in the Google Phone app.
  • Heightened network protection — with your phone actively rejecting any less secure 2G-level network connections that may come along over time.

Notably, all of those features could also be activated individually, via various options scattered across the Android system settings and the associated core Google Android apps. The main advantage of Advanced Protection is really just simplification and having it all happen via that one single switch instead of having to seek out (and know about!) each individual option on your own, one by one, each and every time you set up a new device.

Android 16 Advanced Protection fact #3: There’s more to come

Moving forward, it seems Google’s goal is to keep Advanced Protection updated with all of the latest Android security features that come into the mix over time — meaning that once you activate it, you don’t have to keep thinking about manually activating any new options as they arrive and can instead just know that Advanced Protection will handle it for you.

Already, a small handful of specific still-in-the-works features is confirmed to be bundled into Advanced Protection as each of the new options becomes available (supposedly sometime “later this year,” in the typically vague Google vernacular):

  • Inactivity Reboot: An incoming option that’ll automatically restart your device anytime it remains locked for 72 consecutive hours — thus suggesting you aren’t actively using it for one reason or another — and re-encrypting all your data so it’ll be accessible only after a full password or pattern unlock.
  • Intrusion Logging: A privacy-minded feature that securely stores logs of sensitive system actions in the cloud, encrypted and connected solely to your Google account, so you could seek out answers if something suspicious were ever to happen on your device.
  • USB Protection: Setting your phone’s USB port to allow only charging by default instead of active data transfers — to prevent anyone from being able to physically plug a drive into the device and transfer files off the phone without your knowledge (unlikely as that may be to occur).
  • Disable Auto-Reconnect to Insecure Networks: Exactly as its name suggests, your phone won’t ever automatically reconnect to a network that isn’t secure, even if you manually ask to connect to such a network once.
Android 16 Advanced Protection fact #4: All of this is still only part of the picture

While Advanced Protection makes it much easier to enable all the most advisable Android security settings, even that is just one piece of an optimal Android security puzzle.

First and foremost, you might’ve noticed that the name of this program feels familiar. (If so, good job! Go get yourself a cookie and/or slushie treat, preferably chocolate chip and blue, respectively.) That’s because Google also offers an all-around account-protecting program called Advanced Protection.

That program is a bit more intense in what it does, and — unlike this new Android-specific equivalent — by design isn’t intended for everyone. It requires you to rely on physical security keys anytime you sign into your Google account, for instance, and it severely limits the ways in which third-party apps can connect to your account — steps that are smart for people in higher-profile or more at-risk positions but may be overly restrictive for other, more ordinary Android-owning animals.

But the two programs are very much meant to be complementary, and if it both make sense for you to be using, they very much go hand in hand in their forms of heightened protection — for your Android device and your Google account, respectively.

Either way, though, there are steps you should absolutely be taking to ensure the security of your Google account — and similarly, there’s a sprawling series of steps and best-practice reminders you should be revisiting regularly specific to Android security.

These steps go above and beyond what even Advanced Protection can do for you, and they’re important to assess and consider once annually, at a minimum.

My 18-step Android security checkup is a one-stop, regularly evolving checklist where you can see exactly what you should be focusing on at any given moment in the Android arena. Bookmark it, set yourself a reminder, and revisit it once a year.

And remember: Android security is far less scary than it’s frequently made out to be, but it’s also an area that requires a healthy pinch of common sense and careful thinking. Luckily, it doesn’t take a ton of effort to keep yourself protected. It just takes the teensiest sliver of effort and awareness.

Stay connected to all the most important incoming info with my free Android Intelligence newsletter — three new things to know and try in your inbox every Friday.

Kategorie: Hacking & Security

Takhle bude vypadat Draco Malfoy. Seriálový Harry Potter ukázal tváře dalších devíti postav

Živě.cz - 11 Červen, 2025 - 10:45
Warner Bros. Discovery odhalila další herce pro seriálovou adaptaci Harryho Pottera. • Nejznámější je Bernie Carvel, který září v Dalglieshovi a Koruně. • První série se objeví na HBO Max v roce 2026 a produkce potrvá 10 let.
Kategorie: IT News

GeForce RTX 5050 s 8 GB GDDR6 se začne prodávat v červenci

CD-R server - 11 Červen, 2025 - 10:00
Nejnižší známý model generace Blackwell určený pro desktop se rýsuje na prázdniny. GeForce RTX 5050 cílí výkonnostně pod GeForce RTX 5060 a to nikoli nepodstatnou měrou…
Kategorie: IT News

Microsoft Patches 67 Vulnerabilities Including WEBDAV Zero-Day Exploited in the Wild

The Hacker News - 11 Červen, 2025 - 09:46
Microsoft has released patches to fix 67 security flaws, including one zero-day bug in Web Distributed Authoring and Versioning (WebDAV) that it said has come under active exploitation in the wild. Of the 67 vulnerabilities, 11 are rated Critical and 56 are rated Important in severity. This includes 26 remote code execution flaws, 17 information disclosure flaws, and 14 privilege escalation Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Alza zlevnila vlastní sadu na opravu elektroniky. Šroubovák s 33 bity stojí jen 179 Kč

Živě.cz - 11 Červen, 2025 - 09:45
Sadu AlzaTools Precision Bit Set s 33 bity teď můžete koupit jen jen za 179 Kč místo obvyklých 299 Kč. Alza zdarma přidá záruku okamžité výměny v případě problému a možnost vrátit zboží do 90 dnů, záruka je 3 roky. Nářadí od Alzy obsahuje 33 bitů z chrom-vanadové oceli, takže by se neměly jen tak ...
Kategorie: IT News

Smazali jste složku inetpub? Microsoft vydal skript, který ji znovu vytvoří. Jde o bezpečnost

Živě.cz - 11 Červen, 2025 - 08:45
V dubnu se v systémových úložištích Windows vytvořila složka inetpub. • Je důležitá pro zabezpečení, neměli byste ji odstranit. • Pokud jste ji odstranili, spusťte skript, který Microsoft vydal.
Kategorie: IT News

Smazali jste složku inetpub? Microsoft vydal skript, který ji znovu vytvoří. Jde o bezpečnost

Zive.cz - bezpečnost - 11 Červen, 2025 - 08:45
**V dubnu se v systémových úložištích Windows vytvořila složka inetpub. **Je důležitá pro zabezpečení, neměli byste ji odstranit. **Pokud jste ji odstranili, spusťte skript, který Microsoft vydal.
Kategorie: Hacking & Security

CISO who helped unmask Badbox warns: Version 3 is coming

The Register - Anti-Virus - 11 Červen, 2025 - 08:28
The botnet’s still alive and evolving

Badbox 2.0, the botnet that infected millions of smart TV boxes and connected devices before private security researchers and law enforcement partially disrupted its infrastructure, is readying for a third round of fraud and digital attacks, according to one of the threat hunters who uncovered the original scheme.…

Kategorie: Viry a Červi

Bombardier představil nejrychlejší civilní letadlo na světě od dob Concordu. Stojí skoro 2 miliardy korun

Živě.cz - 11 Červen, 2025 - 07:45
Nejrychlejší civilní letoun od dob Concordu s doletem 15 000 kilometrů • Luxusní kabina nabízí čtyři zóny a sedadla s nulovou gravitací • Špičkový tryskáč s cenovkou dvě miliardy korun mění pravidla létání
Kategorie: IT News

První výsledky CPU Nvidia N1X jej staví nad Snapdragon X Elite

CD-R server - 11 Červen, 2025 - 07:40
Mobilní CPU Nvidie se začíná rýsovat. První výkonnostní výsledky jej staví na slušnou pozici, i když zatím není jasné, kam přesně míří a tedy s čím ho srovnávat. Oproti Qualcommu si však stojí lépe…
Kategorie: IT News

Superpočítač El Capitan zůstává nejvýkonnějším superpočítačem na světě (TOP500 06/2025)

AbcLinuxu [zprávičky] - 11 Červen, 2025 - 05:16
Byl aktualizován seznam 500 nejvýkonnějších superpočítačů na světě TOP500. Nejvýkonnějším superpočítačem zůstává El Capitan od HPE (Cray) s výkonem 1,742 exaFLOPS. Druhý Frontier má výkon 1,353 exaFLOPS. Třetí Aurora má výkon 1,012 exaFLOPS. Nejvýkonnější český počítač C24 klesl na 165 místo. Karolina, GPU partition klesla na 195. místo a Karolina, CPU partition na 421. místo. Další přehledy a statistiky na stránkách projektu.
Kategorie: GNU/Linux & BSD

After AI setbacks, Meta turns to Scale AI and ‘superintelligence’ research

Computerworld.com [Hacking News] - 11 Červen, 2025 - 03:54

Meta has recently lost some traction in the AI space, notably halting a major model rollout last month, but the social media company is looking to turn that around with a new $15 billion investment in Scale AI.

The Mark Zuckerberg-led company has reportedly inked a deal to acquire a large minority stake in the startup, which offers data labeling and model evaluation services for industry leaders including OpenAI, Google, and Microsoft.

According to reports, the $14.8 billion investment would give Meta a 49% stake in Scale AI.

This move comes as Meta is also strategically forming a new research lab to pursue “superintelligence,” with Scale AI founder and CEO Alexandr Wang reportedly being tapped to join that initiative.

“Somewhat ironically in the era of AI, Scale AI excels at human-in-the-loop labeling of data,” said Hyoun Park, CEO and chief analyst at Amalgam Insights. “Meta sees this ability to train models and access human curated training data at massive scale as a necessary capability for Meta’s models to keep up with the extremely competitive world of LLMs.”

What Scale AI can bring to Meta

Reports have described Zuckerberg’s frustration with Meta’s AI progress as its competitors, OpenAI, Anthropic and others, continue to innovate and pull ahead. Notably, in May, the company delayed the launch of its new flagship model, Behemoth, purportedly due to internal concerns about its performance capabilities compared to competitors.

“Meta’s models have struggled to keep up with OpenAI and Anthropic in terms of alignment and polish,” said Wyatt Mayham, lead AI consultant at Northwest AI Consulting. Also, he noted, its Llama family of models “haven’t gained much enterprise traction due to weaker instruction tuning and less reliable output quality.”

Mayham pointed out that Scale AI’s “crown jewel” isn’t just labeled data; it’s high-quality enterprise grade human feedback pipelines. Scale would give Meta a fast track path to improve reinforcement learning from human feedback (RLHF) and model steering at scale. The company could dramatically tighten gaps with instruction tuning and output quality by upgrading alignment and task-following performance.

“If this acquisition does indeed go through, it signals that Meta is serious about continued data dominance,” said Mayham.

However, enterprise customers should be both “cautious and curious,” he said.

If Meta owns both the model and the feedback infrastructure, it raises important questions: Who controls alignment priorities? Will fine tuning pipelines be vertically integrated or open? Enterprise teams should watch for lock-in risk if Meta starts to offer end-to-end AI services that compete with open ecosystems, Mayham advised.

And, he said, if enterprises are evaluating which model to bet on long term, this move reinforces the trend that alignment and control are differentiators; not just raw model size. “Whoever owns the human feedback loop owns the intelligence layer.”

‘Superintelligence’ requires a whole new infrastructure

Zuckerberg seems to be going all-in on the development of “superintelligence” — AI systems that exceed human cognitive capabilities. This hypothetical type of AI is the next step above artificial general intelligence (AGI), AI that can match human cognitive abilities. AGI is also still in its hypothetical stages, with experts varying widely on what exactly it could look like, or if it’s even achievable at all.

Behind the hype of AGI is a more “basic threshold of competence” that users are expecting from AI, said Amalgam’s Park. Hallucinations, when AI makes stuff up or outright lies, are actually demonstrations of each LLM’s world view, he noted.

Models need better training and grounding to be more closely aligned to “our worldview, the view of reality and common sense,” said Park. “This investment by Meta is fundamentally focused on providing more human context, metadata, and assumptions into Meta’s next set of models.”

A new type of infrastructure and focus on security and bias is vital as the industry journeys towards AGI, agreed Jimmie Lee, founder and CEO at JLEE.com.

“With the expectation that this superintelligence will far surpass human intelligence, we need to ensure that this new ‘consciousness’ understands the human context,” he said. “Our humanity, the summation of our mindsets, experiences, dreams, and desires, factors into the thousands of decisions we make daily.”

Tomorrow’s AI infrastructure

This potential investment by Meta indicates a shift from a sole focus on LLM development to a more comprehensive strategy centered on the “critical need” for evolved data infrastructure, said Lee.

“As AI and agentic AI continue to develop and grow, the future limiter is not innovation, application, or talent; it will be infrastructure,” he contended. “Currently, modern technologies are outpacing the growth of the very infrastructure that they require to operate.”

For enterprise users, Lee noted, this means deeper integrations and enriched LLMs and data engines that can be more “hyper-specialized and domain-specific,” thus allowing for richer platforms that better support builders. “This results in less infrastructure, greater simplicity, and improved tools and technologies to build on,” he said.

Ultimately, Meta seems to be re-shifting its strategy, Lee noted: It’s going back to its roots of making large bets to try to drive innovation, rather than merely responding to market demands and increasing market share.

Park agreed: “Zuckerberg knows that AI is the biggest battle in tech and intends to do everything he can to make Meta one of the global giants in artificial intelligence.”

Kategorie: Hacking & Security

Microsoft warns of 66 flaws to fix for this Patch Tuesday, and two are under active attack

The Register - Anti-Virus - 11 Červen, 2025 - 01:38
Stealthy Falcon swoops on WebDAV and Redmond's even patching IE!

Patch Tuesday  It's Patch Tuesday time again, and Microsoft is warning that there are a bunch of critical fixes to sort out - and two actively exploited bugs.…

Kategorie: Viry a Červi

Strop pro výplatu rodičovského příspěvku bude od července vyšší. Chystá se i víc peněz pro dvojčata

Lupa.cz - články - 11 Červen, 2025 - 00:00
Limit pro maximální měsíční výši příspěvku stoupne od července o 2000 Kč. Ve hře je také navýšení rodičáku na 700 000 Kč pro vícerčata.
Kategorie: IT News

Výměna nefunkční disketové mechaniky Atari 1040 STFM za moderní řešení

ROOT.cz - 11 Červen, 2025 - 00:00
Dnešním článkem bych se chtěl vrátit ke svému prvnímu publikovanému počítači Atari. U něj jsem z ničeho nic byl postaven před nutnost vyřešit další problém: nefunkční disketovou mechaniku.
Kategorie: GNU/Linux & BSD
Syndikovat obsah