Agregátor RSS

Security through obscurity is dead, and AI delivered the fatal blow

The Register - Anti-Virus - 13 Září, 2026 - 13:21
The term "security through obscurity" describes an old idea that networks and systems will remain secure so long as their architecture, along with any vulnerabilities or other weaknesses, remains secret or hidden. It was never a sound strategy for protecting sensitive assets and systems, but many organizations leaned on it due to lack of resources or complacency. Now it’s obsolete. Don’t believe us? Here’s proof. Software vendors and independent researchers alike are now using AI agents to find bugs – some very obscure and decades old – across products and open source code, leading to record-breaking numbers of security disclosures and patches, and a massive backlog for project maintainers. “You see open source platforms that have been visible to the tech community for a decade, these libraries that are run in 80 percent of web servers out there, people have stress-tested those for 10 years, and the community believed that they were really secure,” Brett Leatherman, assistant director of the FBI's Cyber Division, told The Register. “The latest models were able to break those and say, ‘yeah, there’s significant vulnerabilities in here.’” Whether or not security through obscurity is dead “isn't even an opinion question,” Trend Micro’s Zero Day Initiative chief bug hunter Dustin Childs told The Register, the day after Microsoft’s record-breaking Patch Tuesday addressed 974 CVEs. “When you look at all of the components patched by Adobe and Microsoft yesterday, you see components no one has talked about in years,” Childs said. “Telnet client – is this even still used in any secure environment? Windows RNDIS – the USB-networking protocol Microsoft has been trying to deprecate for years. NFS Portmapper – 1980s Unix tech. And Link Layer Topology Discovery – the Vista-era network-map protocol nobody's thought about since Vista – just to name a few.” Meanwhile, attackers are also using AI to reverse-engineer fixes and find exploits within hours. In one recent case, at least four espionage crews, most suspected of links to China, slammed shut the “patch-gap” window for open source Chromium, using an exploit kit developed shortly after the maintainers released an upstream patch – but before the downstream stable release was pushed to users. What this means for OT security During interviews at Black Hat in August, both former US National Cyber Director Chris Inglis and John Hultquist, chief analyst at Google Threat Intelligence Group, told us that they worry about what this means for critical operational technologies and industrial control systems (ICS). These are the systems that ensure the lights turn on when people flip a switch, gas flows out of pumps, and safe drinking water pours from faucets – all critical services that people use daily, and assume will continue working reliably. The OT systems themselves often use obscure protocols and proprietary hardware and software, which historically made them black boxes, even to IT specialists and hackers. AI upended this assumption. It means that criminals don't need to be OT experts to carry out destructive cyberattacks on critical networks and facilities. They just have to ask an agent to learn everything about these systems and do the dirty work for them. A couple of weeks after Black Hat, five US agencies said that attackers used AI-generated exploitation scripts to break into internet-exposed Siemens S7 Series programmable logic controllers (PLCs) at water, manufacturing, energy, and other critical facilities. “This is not a theoretical risk – it is an active threat,” the feds warned. AI “is excellent at technical troubleshooting, at knowing obscure systems and helping you make your way through it, and this makes me very concerned about industrial control systems,” Hultquist told The Register in an interview last week. “They've been largely secured because the expertise was in a handful of people's heads, and that's not going to last forever,” he said. AI can be a useful guide for attackers studying not just the application layer, but also the operating system, and even down into the firmware, Hultquist added. “That's going to have implications for a lot of different areas of security, but definitely for industrial control systems.” However, while this undoubtedly means more work for sysadmins and defenders, burying this outdated idea of security through obscurity isn’t necessarily a bad thing. 'Never a winning strategy' “I've always been of the mind that security through obscurity was never a winning strategy,” Katie Moussouris, founder and CEO of bug bounty consultancy Luta Security and the fairy godmother of bug bounties, told The Register. “But that's because I've been a hacker for so long. The argument always fails in the face of someone who decides to turn their gaze towards your organization. If there is something to find, they will find it.” Plus, she added, AI makes hacking a whole lot easier. “People might not have familiarity with the particular tech stack that you're running, but that is no longer a barrier because AI has ingested everything, and an AI is going to help them enumerate weak spots, even if they themselves are not familiar with the particular tech stack that they are pointing an AI towards,” Moussouris said. However, finding bugs and other weaknesses has never been the big security problem, she added. “It’s triaging and prioritization and actually getting things fixed.” This, Moussouris said, has also been her biggest issue with the way that organizations implement bug bounty programs. “AI is shining that bright light on the wrong end of the security picture, and unfortunately, AI hasn't caught up on the defensive side,” Moussouris said. “We're not there with AI automated patching, remediation – anything of the sort.” A couple of recent studies back this up, both finding that AI-generated patches fail more than half of the time. 1Password’s research team took six CVEs disclosed since March, and produced 6,080 patches using two frontier models: OpenAI's ChatGPT-5.5 and Anthropic's Opus 4.8. “The average success rate for generating a patch that fully resolved the vulnerability (without materially changing application behavior) was just 26.0 percent,” wrote Director of Security Research Keith Hoodlet, adding that even patches that did fix the flaw also mucked up the application’s behavior 20 percent of the time. This included things like changing “allow list” logic to “deny list” logic. “Conversely, LLM-generated patches did not resolve the vulnerability, added a new vulnerability, or both, an average 53.9% of the time,” Hoodlet said. Another study by app security shop Veracode found that, across more than 100 models and 80 coding tasks, the average security pass rate for AI-generated code was just 56 percent. “If people are telling you that you need to accelerate on the fixing side, and the defense side – that’s just not cutting it,” Moussouris said. “Orgs that are looking at this as we're going to throw more resources at finding and fixing bugs, and they're not investing in taking a look at their process failures that led to so many bugs – those organizations are going to die on the treadmill,” she added. “They will literally have a heart attack and die. Like there's no VO2 max that will make you fast enough to deal with all those bugs, and giving up is not the answer.” The answer, she says, is taking a more dynamic approach, assessing where your organization can find patterns that lead to a process improvement instead of patching vuln after vuln. “A lot of organizations don't even know how to measure their progress, so they are counting bugs and speed of fixing, which is one way to measure. We had this many criticals, and then we fixed them super fast, and we had this many high, this many medium,” Moussouris said. The number of flaws fixed is important, but it doesn’t show the entire picture, she added. This involves looking at types of vulnerabilities, too. “Like: We've got a lot of injection flaws. That's something we could solve with better, safer templates earlier in our CI/CD pipeline. This is something that we can prevent at scale, as opposed to fixing these like really easy to find and fix vulnerabilities really really fast.” ®
Kategorie: Viry a Červi

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

The Hacker News - 13 Září, 2026 - 12:11
Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. The first campaign, per the tech giant, involved sending over a million scam emails between August 3 and 5, 2026, by masquerading as chief executive officers Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Nejkratší metro jezdí v rakouské obci s 1200 obyvateli. Trasa je dlouhá 1,3 km a má čtyři zastávky

Živě.cz - 13 Září, 2026 - 11:45
Rakouská obec Serfaus vyřešila dopravní zácpy bezplatnou podzemní dráhou • Unikátní vznášející se vlak jezdí na vzduchovém polštáři tažený lanem • Podzemka přepraví ročně přibližně jeden a půl milionu cestujících
Kategorie: IT News

Android připravuje kontrolu intimních fotek před sdílením. Ochrání především děti a dospívající

Živě.cz - 13 Září, 2026 - 10:45
Nová funkce v Androidu varuje uživatele před odesláním intimních fotografií • Lokální analýza obsahu chrání soukromí v zařízení a nic nikam neodesílá • Funkci ale půjde snadno obejít odesláním snímku jako běžného souboru
Kategorie: IT News

Týden na ITBiz: Bez lidí zůstane polovodičová strategie na papíře

AbcLinuxu [články] - 13 Září, 2026 - 10:00

SanDisk Extreme Portable SSD: Rychlé externí NVMe do deště i prachu. HP představuje nové počítače OmniBook pro příští generaci práce s AI. Fortinet varuje před dopady kvantových útoků na podniky. Acer Vero 16 – notebook navržený s důrazem na opravitelnost a výkon s podporou AI. HPE a Oracle rozšiřují spolupráci v oblasti infrastruktury AI. Bez lidí zůstane polovodičová strategie na papíře.

Kategorie: GNU/Linux & BSD

Osm tipů, jak naplno využít Apple AirTag. Není to jen pípající klíčenka

Živě.cz - 13 Září, 2026 - 09:45
Apple AirTag většina lidí používá jako přívěsek na klíče nebo zavazadlo. Nabízí ale řadu funkcí, díky kterým je z něj mnohem všestrannější pomocník. Naučte se jej používat efektivně a poznejte všechny jeho funkce.
Kategorie: IT News

Konec nekonečného čekání, Tesla představí Roadster. Opravdu bude mít trysky od SpaceX

Živě.cz - 13 Září, 2026 - 08:41
Tesla představí nový Roadster. Konečně. Po tolika letech čekání, po tolika slibech a tolika odkladech… Prvně se na profilu Tesly na X objevila neurčitá grafika s čísly „10.01“ a stručným komentářem „Fo for launch“. To ve ve vesmírné terminologii znamená „Jdeme na start“. Proč vesmírná ...
Kategorie: IT News

Stačí mu říct, co má udělat. Český dron vyhrál v disciplíně zaměřené na autonomní vyhledání zraněné osoby

Živě.cz - 13 Září, 2026 - 07:45
Český tým F4F a ČVUT uspěl v prestižní evropské soutěži • Autonomní dron rozumí lidské řeči a plní úkoly úplně bez GPS • Pokročilá technologie spoléhá na kamerový systém a vlastní vytvořenou mapu
Kategorie: IT News

Nejlepší hry o samurajích a nindžích. Nechybí válčení, čestné duely ani trocha sci-fi

Živě.cz - 13 Září, 2026 - 07:10
Japonskou historii jsme mohli prozkoumat v řadě her. Některé ji zpracovávají jako akci, jiné strategii a nejedna si k realitě přihazuje i nadpřirozeno. Nindžové a samurajové ale nejsou jen záležitostí minulosti.
Kategorie: IT News

Videozáznamy přednášek a fotografie z konference EuroPython 2026

AbcLinuxu [zprávičky] - 13 Září, 2026 - 01:46
Na YouTube byly publikovány videozáznamy přednášek a na Flickru fotografie z konference EuroPython 2026.
Kategorie: GNU/Linux & BSD

Lidé stále věří vědcům, ale těm, které vnímají na své straně

OSEL.cz - 13 Září, 2026 - 00:00
Brodíme se v dezinformacích a nesmyslech, ale věda jakžtakž drží pozice. Lidé věří vědcům víc, než byste čekali, ale rozhoduje o tom hlavně to, co byste asi netipovali. Nejde ani tak o odbornost vědců ani o jejich práci ve prospěch blaha společnosti. Jde o důvěru. Lidí musejí cítit, že vědci jsou na jejich straně, pak jim věří. Vědci jistě vymyslí, jak na to.
Kategorie: Věda a technika

Co přinese Plasma 6.8 i GNOME 51, mono písmo od Intelu žije dál

ROOT.cz - 13 Září, 2026 - 00:00
GTK 4.24 přináší lepší neceločíselné škálování a přesnější GDK Frame-Clock, podpora obnovy sezení se ale nestihla, KDE řeší budoucí Plasmu 6.8, GNOME zase verzi 51, která je na spadnutí, a Intel zvrátil rozhodnutí o konci projektu open-source písma.
Kategorie: GNU/Linux & BSD

Dario z Anthropiku: „Musíme zpomalit.“ Sam z OpenAI: „Souhlasíme, je potřeba postupovat opatrně.“

Zive.cz - bezpečnost - 12 Září, 2026 - 21:54
Dario Amodei, šéf společnosti Anthropic (to je ta s Claude) publikoval rozsáhlou esej, ve které se zamýšlí nad dalším rozvojem nejvýkonnějších AI modelů. Celý text najdete přeložený ve spodní části článku, zde je jeho shrnutí. Dario Amodei postupně mění názor: nestačí jen investovat do prevence ...
Kategorie: Hacking & Security

Dario z Anthropiku: „Musíme zpomalit.“ Sam z OpenAI: „Souhlasíme, je potřeba postupovat opatrně.“

Živě.cz - 12 Září, 2026 - 21:54
Dario Amodei, šéf společnosti Anthropic (to je ta s Claude) publikoval rozsáhlou esej, ve které se zamýšlí nad dalším rozvojem nejvýkonnějších AI modelů. Celý text najdete přeložený ve spodní části článku, zde je jeho shrnutí. Dario Amodei postupně mění názor: nestačí jen investovat do prevence ...
Kategorie: IT News

Nový rekord. Microsoft v září díky AI opravil 723 zranitelných míst ve Windows

Zive.cz - bezpečnost - 12 Září, 2026 - 18:45
**Microsoft opravil přes 970 zranitelných míst ve svých produktech. **Servisní aktualizace vyšly 8. září 2026 večer. **Windows 11 umožňují změnit polohu hlavního panelu.
Kategorie: Hacking & Security

Nový rekord. Microsoft v září díky AI opravil 723 zranitelných míst ve Windows

Živě.cz - 12 Září, 2026 - 18:45
Microsoft opravil přes 970 zranitelných míst ve svých produktech. • Servisní aktualizace vyšly 8. září 2026 večer. • Windows 11 umožňují změnit polohu hlavního panelu.
Kategorie: IT News

Debian 13.7

AbcLinuxu [zprávičky] - 12 Září, 2026 - 18:13
Byl vydán Debian 13.7, tj. sedmá opravná verze Debianu 13 s kódovým názvem Trixie. Řešeny jsou především bezpečnostní problémy, ale také několik vážných chyb. Instalační média Debianu 13 lze samozřejmě nadále k instalaci používat. Po instalaci stačí systém aktualizovat.
Kategorie: GNU/Linux & BSD

CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

The Hacker News - 12 Září, 2026 - 17:54
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. Details of the vulnerabilities are as follows - CVE-2026-42016 (CVSS score: 8.1) - An incorrect authorization Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Windows 11 pro vývojáře nabídnou nástroje jako Visual Studio Code a nebudou otravovat

Živě.cz - 12 Září, 2026 - 17:45
Projekt Zenith představuje zvláštní konfiguraci Windows 11 pro vývojáře. • Nabídne předinstalované vývojářské nástroje a jiné nastavení. • Windows v této konfiguraci budou dostupné na vybraných počítačích.
Kategorie: IT News

Nové navigace Garmin Drive mají obří širokoúhlý displej. Po spárování s telefonem nabídnou užitečné funkce

Živě.cz - 12 Září, 2026 - 16:45
Nové navigace od Garminu nabízejí velké displeje i offline mapové podklady • Přístroje rovněž zobrazují upozornění na dopravní značky a ostré zatáčky • Speciální placený balíček usnadní plánování trasy řidičům kamionů a karavanů
Kategorie: IT News
Syndikovat obsah