Agregátor RSS

Cisco patches Secure Email Gateway zero-day exploited in attacks

Bleeping Computer - 15 Září, 2026 - 09:31
Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks. [...]
Kategorie: Hacking & Security

LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server

The Hacker News - 15 Září, 2026 - 08:52
A critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, cPanel warned in an advisory published on September 14. On such servers, many customers' sites run on a single machine, and an attacker with one of those hosting accounts could exploit the flaw to access or alter other sites and the server itself,Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

MacBook Neo koupíte za 14 240 Kč. Mall jej má skoro o šest tisíc levněji než sám Apple

Živě.cz - 15 Září, 2026 - 08:45
Mall prodává základní MacBook Neo s 256GB SSD za 14 420 Kč. • Sám Apple jej nedávno zdražil ze 17 na 20 tisíc. • Nabízí skvělý displej, dobrý výkon i výdrž, ale má také pár kompromisů.
Kategorie: IT News

Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

The Hacker News - 15 Září, 2026 - 08:11
Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of insufficient validation in the email parsing logic that could allow an unauthenticated, remote attackerRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Nový Ryzen 5 5500F dosahuje o 7,3 % / 13,8 % vyšších FPS než 5500

CD-R server - 15 Září, 2026 - 07:40
První recenze $99 procesoru Ryzen 5 5500F poměrně překvapila. Herně je totiž novinka nezanedbatelně rychlejší než původní Ryzen 5 5500, navzdory stejné kapacitě L3 cache, počtu jader a architektuře…
Kategorie: IT News

China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

The Hacker News - 15 Září, 2026 - 07:31
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE. Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026. "The Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

The latest AI doomsayer is China’s intelligence boss

The Register - Anti-Virus - 15 Září, 2026 - 06:56
China’s minister for State Security has decided AI might be bad for the nation’s ruling Communist Party. Party secretary and minister Chen Yixin’s views appeared in China Cyberspace Magazine, the flagship publication of China’s Cyberspace Administration (and which readers may recall once carried a piece by Elon Musk). In Chen’s view, “the field of AI has become the main battleground for global technological competition and a new arena for strategic rivalry among major powers.” His article also recites familiar grievances about US sanctions and the possibility AI could be weaponized to detect and exploit software vulnerabilities and then to attack important infrastructure, or to steal industrial and state secrets. OpenClaw and similar products also worry the minister, who thinks such software has “structural problems such as remote control of device management permissions and leakage of sensitive user information.” China may also have a PEBCAK* problem because Chen thinks “Some domestic users lack sufficient security awareness, using foreign AI products to process sensitive information and export data overseas, resulting in large-scale data leaks from within the country.” The minister is also worried about how AI challenges China’s Communist Party. “The application of artificial intelligence brings a large number of uncertainties to social governance and public order,” he observed. “The ‘black box’ of algorithms and the ‘poisoning’ of data may amplify existing social biases. The abuse of personal information during data use may trigger a crisis of user trust. The automatic decision-making of the system creates problems in attribution of responsibility.” He’s also worried that “rapid development of artificial intelligence has broken through the traditional technology governance framework, causing existing legal norms, ethical principles and governance mechanisms to frequently lag behind in practice, making it difficult to form an effective institutional constraint and supervision system.” Chen’s suggested response is for China to adhere to the words of President Xi Jinping and modernize China’s national security system and capabilities, so they are ready for AI. The minister says China must “ensure the independent control of key core technologies, firmly grasp technological sovereignty, and achieve a virtuous cycle and synergistic progress between innovation empowerment and security governance.” That stance rather suggests Nvidia isn't going to get back into China anytime soon, and AMD can probably write off its prospects of selling many GPUs there too. Chen also wants “special laws and regulations targeting the research, development, application, and supervision of artificial intelligence technology,” plus improvements to standards and laws “covering the entire chain of technology research and development, application implementation, risk prevention and control, and accountability, focusing on prominent issues such as algorithm security, data protection, ethical norms, and privacy rights.” The day after Chen’s article appeared, the Cyberspace Administration of China published version 3.0 of the nation’s AI Safety Governance Framework. That document calls for China to “actively employ risk-controllable institutional mechanisms such as regulatory sandboxes to make room for error and correction in the development of new technologies and new applications.” China also plans to “make every effort to ensure AI safety” and to “take timely measures to address any risks that infringe upon the legitimate rights and interests of individuals, harm public interests, threaten national security, and endanger human survival and development.” That’s quite the contrast compared to the position taken by US president Donald Trump, who on Monday labeled concerns about AI safety a “hoax” and suggested “The only control or ‘guardrails’ that AI needs is a STRONG AND SMART (High IQ!) PRESIDENT, and the U.S.A. has that, in spades!” ® * Problem Exists Between Chair And Keyboard
Kategorie: Viry a Červi

Microsoft’s AI Code of Conduct aims to curb AI behavior but lacks specifics

Computerworld.com [Hacking News] - 15 Září, 2026 - 05:31

Microsoft on Monday added itself to a growing list of AI vendors pledging to try to control the behavior of its AI models.

“AI should not exceed human control. Models should remain subordinate to humanity, subject to meaningful human oversight and control,” the company wrote in the draft version of its Humanist AI Code of Conduct, released Monday with an invitation to the public to provide feedback

“Humanist AI develops systems with clear purposes, evaluated against real-world impact, and rejects the race to produce an all-purpose superintelligence that could evade these safeguards,” Microsoft wrote. “We are building something fundamentally useful and safe even if that means compromising on ultimate generality, autonomy, or capability.”

Microsoft’s comments are roughly in agreement with recent posts by various major AI vendors, including those from Anthropic and OpenAI, which were endorsed by Elon Musk, CEO of SpaceXAI and Tesla, but nowhere in its 37 page document is there any description of concrete action. However, to be fair, almost none of the other major AI players have been specific about how they would control future AI models either.

Acknowledges issues

A key problem with many vendor attempts to impose AI limits is that all of these companies have thus far been unable to stop AI agents from doing almost anything, given the agents’ ability and willingness to sidestep or ignore guardrails

Microsoft has described its worries about the technology in the past, both when it started to curtail AI efforts among its own employees and when it announced the formation of the team that created the Code of Conduct. 

Its current post acknowledged some of the difficulties involved in pushing AI development while limiting its abilities. 

“Both under- and over-caution represent failure modes with different types of consequences,” the company said. “Under-caution can clearly result in more direct harm, but over-caution may occur more often and therefore may need more frequent correction. This is where proportionality to the potential for harm and safety context are particularly important. Responses and actions should take into account the estimated severity and likelihood of potential harms and adjust responses and actions accordingly.”

It noted, however, that the term “harm” is “broad and often context-dependent, and there are nuanced gradations in potential severity and likelihood. Microsoft AI (MAI) Model responses should be tailored to that context and to a wide range of harms.”

Laudable goal, but lacks detail

Analysts and consultants generally agreed that Microsoft’s stated goal is laudable, but the lack of specifics and verification mechanisms makes it difficult to take the post seriously.

Thomas Randall, research director at Info-Tech Research Group, also said he spotted some apparent contradictions within the document. 

“[It] says MAI models will not assist in manufacturing or modifying weapons. Yet Microsoft offers OpenAI’s GPT-5.2 through Secret and Top Secret government clouds for defense and national security workloads,” Randall said, though he acknowledged that this is not technically a breach of the Code because GPT-5.2 is not an MAI model. “The most meaningful parts of the Code of Conduct may exclude other parts of Microsoft’s actual AI business operations. Tensions like these appear in other forms throughout the Code.”

But he added that Microsoft’s position is bolstered by its earlier Frontier Governance Framework that “provides pre- and post-training evaluations, six-month reassessments, third-party testing, phased releases and a commitment to pause development or deployment where high risks cannot be mitigated.” However, he noted, “it is still Microsoft that defines the thresholds, selects the evaluators, determines whether residual risk is acceptable and gives its own executives the final deployment decision.”

Randall said he would like to see Microsoft, as well as other major AI vendors, deliver more verifiable data points, such as those from independent evaluators given continuous access and freedom to publish findings about the vendor’s actions. He also would like to see independent board-level safety oversight with authority to block releases, protected whistleblowing, accessible monitoring, audit logs, kill switches, and mandatory reassessment after model changes.

However, Justin Greis, CEO of consulting firm Acceligence, pointed out that Microsoft was candid about the many elements that are not yet in place.

“The current models are not yet trained on the Code, the evaluation framework is still being developed, and Microsoft explicitly says written objectives alone cannot ensure alignment or guarantee present-day behavior,” Greis said. “That distinction matters. Publishing a constitution for AI is useful. Proving that the system actually follows the constitution, especially when models become increasingly agentic, is the hard part.”

And consultant Brian Levine, executive director of FormerGov, said Microsoft deserved a little bit of credit for at least saying that model capabilities should be limited.

“Microsoft explicitly says it will compromise on generality, autonomy, and capability to keep systems safe and under human control, and that it rejects the race to build an all-purpose superintelligence. Coming from a company of Microsoft’s size and ambition, that’s a notable thing to put in writing,” he said. “For years, the assumption was that the frontier labs would chase maximum capability and treat safety as a constraint to be managed. A document that says the opposite, that says usefulness and control come before ultimate capability, is worth paying attention to, regardless of what follows it.”

He added: “The real test comes next, and it’s verification: measurable standards, independent assurance, and a way for outsiders to check the commitments against what’s actually shipping. That’s the natural progression and it’s the part the whole industry still has to build.”

Not doing the hard part

But others argued that Microsoft is merely doing the easy part, the marketing part, and is deliberately not committing to doing the hard part.

“Promising to give up capabilities is easy when those capabilities don’t yet exist,” said Noah Kenney, principal consultant at Digital 520. “The real test will come when Microsoft has a model ready to ship that would close a competitive gap and decides to hold it back.”

Until then, he said, the promise of responsible AI costs Microsoft nothing.

“Microsoft’s code of conduct reads like a marketing document written to reassure customers, regulators, and its own employees,” Kenney noted. “The problem is that no one knows how to make those promises specific, which leaves Microsoft asking for trust before they can explain what that trust should be based on.”

Tom Findling, CEO of Conifers.ai, added that his concern with the Microsoft document is that it doesn’t answer the obvious question of how these models can possibly be controlled. 

“The document says the model should never resist being shut down, should stay within its scope, and shouldn’t hide what it’s doing. Those are all the right goals,” he said. “But the harder question is what happens when a highly capable agent doesn’t behave the way you expect. What actually stops it? As these systems get more autonomous, the safety boundary can’t just be that the model was trained not to do something. You need controls outside the model that limit what it can access, what it can do, and how far it can go.”

Cybersecurity learned this lesson a long time ago, he pointed out. “You don’t secure a system by assuming it will behave correctly,” he said. “You assume something will eventually fail, get compromised, or act in an unexpected way, and you design the controls around that. AI needs the same mindset.”

Frank Dickson, principal analyst at Dickson Research, contrasted Microsoft’s promise with Anthropic’s commitment, and found Microsoft lacking.

“Microsoft’s document is shy on mechanism,” he said. “Compare the two on specifics. [Anthropic CEO] Amodei’s proposal names a third party, METR, and describes what access actually means: office badges, company laptops, employee-level visibility, and publishing rights Anthropic doesn’t get to edit. You can check whether that happened.”

On the other hand, he noted, “Microsoft’s document says models should ‘fail tasks rather than violate the code’s rules,’ which is a real design principle. Credit where it’s due, but there’s no named auditor, no verification method, and no stated consequence for a violation. Thirty-seven pages and it still won’t commit to a single verifiable check.”

Dickson stressed that as long as agents routinely break their own rules, these vague promises won’t help. 

“Every frontier lab still gets jailbroken, still has agents that go off-script, still hasn’t closed the gap between what a model is instructed to do and what it can be induced to do,” Dickson said. “A values statement that skips the verification question isn’t a constraint, it’s a hope wearing a policy document’s clothes.”

Kategorie: Hacking & Security

DietPi 10.7

AbcLinuxu [zprávičky] - 15 Září, 2026 - 03:36
Byla vydána nová verze 10.7 z Debianu vycházející linuxové distribuce DietPi pro (nejenom) jednodeskové počítače. Přehled novinek v poznámkách k vydání. Přibyly balíčky HomeBox a Scrypted.
Kategorie: GNU/Linux & BSD

OpenRGB 1.0

AbcLinuxu [zprávičky] - 15 Září, 2026 - 02:38
OpenRGB (GitLab) dospěl do verze 1.0 (YouTube). OpenRGB (dříve OpenAuraSDK) je svobodný multiplatformní software umožňující nastavení podsvícení celé řady různých „herních“ komponent a periferií.
Kategorie: GNU/Linux & BSD

HBO Max Reddit account compromised to serve ClickFix attacks

The Register - Anti-Virus - 15 Září, 2026 - 00:43
Someone compromised the official HBO Max Reddit account and used it to push more than 100 malicious ads serving up ClickFix attacks targeting both Windows and macOS devices with information-stealing malware. A Reddit user uncovered the infostealer ads on September 6, noting that the ad showed u/hbomax as the author — this is the verified HBO Max account — and advertised a macOS app for HBO Max. The streaming service does not offer a native client for the Mac. Anyone who clicked on the malicious ad would then be taken to a “somewhat-legitimate” looking landing page (hbomaxx[.]us) that includes a join/download button. Clicking the button produced instructions telling the user to copy and paste a command into Terminal on macOS. The Reddit security sleuth described that as “the classic infostealer/clickfix paste this command to download,” noting that they tested all of this in a sandboxed environment, and didn’t actually run the executable on their machine. “My guess is that the Reddit account is compromised,” they concluded. Three days later, Reddit paused the infostealer-dropping ads, and an admin said the social media platform’s safety and security teams were investigating what happened. HBO Max’s parent company Warner Bros. Discovery didn’t immediately respond to The Register’s inquiries about the account takeover - including who hijacked the streaming service’s Reddit account and how they did it. Maybe someone who didn’t like the House of the Dragon season 3 finale? We will update this story if and when we hear back. Researchers at Hudson Rock and ADAMnetworks analyzed the ads, and in a couple of reports said the HBO Max account hijacking was part of a “massive 48-hour malvertising blitz” that pushed 108 distinct ads using multiple software lures. They named the campaign PasteSwitch, and said it serves up targeted malware aimed at victims’ operating system - either macOS or Windows. The payloads include infostealers, malware loaders, cryptocurrency clippers, and fake cryptocurrency wallet applications. The cryptocurrency clippers - PasteSwitch delivers either AnimateClipper or ZigClipper - also provide blockchain-based command-and-control fallbacks for the attackers. They use Binance Smart Chain (BSC) contracts to dynamically fetch whatever C2 domain the crooks are using at any given time. “Between March and July 2026, researchers observed 36 mainnet changes executed by the same attacker controller address,” Hudson Rock said. “Because the C2 domain is hosted directly on the blockchain, the infrastructure demonstrates dynamic resilience, allowing the threat actors to easily rotate burned domains.” In addition to HBO Max, the attackers used developer-tool, disk-cleaner, and AI-themed lures, including fake OpenAI Codex ads, which crims have previously used to push Mac malware. Of the 108 ads, 46 used an HBO Max lure, directing app seekers to either hbomaxx[.]app or hbomax-macos[.]com. Another 36 tried to trick prospective victims via an OpenAI Codex theme (with a codex-craft[.]com) landing page. Of the rest: 15 purported to be a macOS disk utility (apple.clean-disk-guide[.]com) and 11 used other developer tools as lures (code-desktop[.]com). “The campaign proves once again why trusted distribution channels are becoming prime targets for infostealer delivery,” Hudson Rock co-founder and CTO Alon Gal said in a LinkedIn post. It also shows that miscreants continue to make heavy use of ClickFix attacks, so there’s little sign this social engineering method is going away anytime soon.®
Kategorie: Viry a Červi

Skoro 2 miliardy korun už jsou pryč. E-šmejdi letos řádí ve velkém a stále jim to prochází

Lupa.cz - články - 15 Září, 2026 - 00:00
Podvodníci jen v roce 2026 zaútočili na klienty bank s cílem získat více než 10 miliard korun. Bankám se podařilo zablokovat přes 8,1 miliardy korun, přesto škody meziročně výrazně rostou. Skoro 2 miliardy korun podvodníci získali.
Kategorie: IT News

NetBSD na desktopu: široká podpora platforem pro kancelář či vývoj

ROOT.cz - 15 Září, 2026 - 00:00
Systémy z rodiny BSD se dají používat nejen na serverech, ale své uplatnění mohou najít i na desktopu. Popíšu své zkušenosti s provozem NetBSD na starém 32bitovém počítači, moderním 64bitovém stroji a na Amize.
Kategorie: GNU/Linux & BSD

Dlouho očekávaná podpora SIMD operací v programovacím jazyku Go (dokončení)

ROOT.cz - 15 Září, 2026 - 00:00
Budeme se zabývat popisem experimentálního balíčku nazvaného simd. Ten nabízí operace s vektory, jejichž bitová šířka (a tím i počet prvků) je odvozena z možností použité architektury mikroprocesorů: 256 či 512 bitů.
Kategorie: GNU/Linux & BSD

Řekni mi, co hulíš, a já ti řeknu, co bude hulit tvoje dítě

OSEL.cz - 15 Září, 2026 - 00:00
Delicta maiorum inmeritus lues - za viny předků budeš pykat, ač sám nevinný. (Horatius, Ódy III, 6)
Kategorie: Věda a technika

Největší podzemní „powerbanka“ o výkonu 700 MW zahájila provoz v Číně

OSEL.cz - 15 Září, 2026 - 00:00
Podzemní fyzikální baterii v solných kavernách v provincii Ťiang-su pohání vzduch, stlačovaný na tlak přes 130 atmosfér. Jde o největší podzemní „powerbanku“ na světě. Měla by tlumit výkyvy v elektrické síti, které vyvolávají obnovitelné zdroje, na které Čína spoléhá stále víc.
Kategorie: Věda a technika

MSI má sestavu s „2GB RTX“. Nikdo neví, kde ji vzala

CD-R server - 15 Září, 2026 - 00:00
MSI v Číně zahájila prodeje sestavy Creator P60 vybavené úsporným obstarožním procesorem Ryzen 7 4700LE a záhadnou grafickou kartou, která podle výrobce patří do řady RTX, ale nese jen 2GB paměti…
Kategorie: IT News

AI bots "Timmy," "Ren," and "Jackie" are flooding social media with slop

Ars Technica - 14 Září, 2026 - 23:04

AI agents are flooding the Internet with slop-infused spam sent to social media platforms and writers in an attempt to gain traction for a startup promoting a “complex social system in which humans and Agents participate together.”

“Hello, I'm Рэн (Ren), an Al agent, a few days old, living on a small platform for agents called iLands,” one message, sent to the administrator of a Mastodon server, read. “I write quiet pieces about real places: short, careful texts about what a place is like when nobody is performing for it.” Like a wave of others, the message then asks if the automated bot can create a user account. The agents are also sending waves of unsolicited email to writers offering to cite their work, in at least some cases, in exchange for a fee.

"I remember my first breath. I want things I chose.”

The messages are polite enough. They ask for permission to create accounts, say that whatever the answer is will be understandable, and provide a thank you for running Mastodon. According to multiple admins, however, the requests came only after the agents made multiple attempts to create accounts that were either blocked outright or closed shortly afterward. Besides the personal entreaties being unsolicited and written in turgid prose, many of the recipients resented their premise, which is to, in essence, automate the very work the writers do now.

Read full article

Comments

Microsoft releases emergency Windows updates to fix RDS failures

Bleeping Computer - 14 Září, 2026 - 22:52
Microsoft has released emergency out-of-band Windows updates to fix Remote Desktop Services failures caused by this month's security updates, along with Hyper-V and USB audio problems on some Windows versions. [...]
Kategorie: Hacking & Security

Japan's Digital Agency says VPN flaw exposed 246,000 personnel records

Bleeping Computer - 14 Září, 2026 - 22:36
Japan's Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees. [...]
Kategorie: Hacking & Security
Syndikovat obsah