Agregátor RSS

Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars

The Register - Anti-Virus - 11 Září, 2026 - 14:15
A Ukrainian lawyer who wound up coding malware for the Conti ransomware gang has been sentenced to four years in a US prison. Oleksii Oleksiyovych Lytvynenko, 44, pleaded guilty in June to conspiracy to commit wire fraud over his role in Conti, the Russia-linked ransomware operation associated with more than 1,000 victims and at least $150 million in ransom payments. Lytvynenko took an unusual route into the ransomware business. The Ukrainian national, who later lived in Cork, Ireland, trained as a lawyer before joining Conti as an intruder and developer. According to his plea agreement [PDF], Lytvynenko operated under the handle "henry" and joined a team run by another Conti conspirator known as "silver" or "buza." He was recruited to help with coding and directed to work on a malware loader – software designed to get other malicious code running on a victim's machine. Prosecutors said his Google account showed he had also been doing some homework. Investigators found books and videos about malware and hacking alongside Conti malware, ransom notes, and stolen victim data. Prosecutors said he also used Google and ZoomInfo to research potential targets. Lytvynenko wasn't confined to writing code, according to the filing. Evidence from his online accounts showed that he possessed data stolen from eight US victims and four overseas, with the eight American victims reporting more than $1.5 million in losses. Court documents identify several Bitcoin transfers tied to his Conti work, including 0.4 BTC worth $25,042 that prosecutors traced back to one of his victims. He has been ordered to forfeit the same amount. Conti disbanded in 2022 after its internal chats and source code were leaked following the gang's public support for Russia's invasion of Ukraine. Lytvynenko apparently didn't take that as his cue to find another line of work. When Gardaí turned up at his County Cork home in July 2023, they said they found his laptop open, Cobalt Strike running and a Rocket.Chat session connected over Tor. Prosecutors said evidence recovered from the machine showed that his involvement in ransomware activity had continued after Conti disbanded. Lytvynenko was extradited from Ireland to the US in October 2025. The Justice Department says Conti attacked organizations across 47 US states, the District of Columbia, Puerto Rico, and 31 foreign countries between 2020 and 2022. By January 2022, the FBI estimated that victim payouts associated with Conti exceeded $150 million. Lytvynenko will now have four years to contemplate a career change. ®
Kategorie: Viry a Červi

EU's Cyber Resilience Act starts the 24-hour vulnerability clock

The Register - Anti-Virus - 11 Září, 2026 - 13:34
Manufacturers selling products with digital elements in the EU must now report actively exploited vulnerabilities to cybersecurity authorities under the Cyber Resilience Act's mandatory reporting rules. The reporting duties set out in Article 14 of the CRA became applicable today. Subject to the regulation's exemptions, they apply to manufacturers of products with digital elements made available in the EU, regardless of where those manufacturers are based. Manufacturers must submit an early warning within 24 hours of becoming aware of an actively exploited vulnerability, followed by a more detailed notification within 72 hours. The same deadlines apply to severe incidents affecting the security of products with digital elements. The only difference in timing is related to the final report. Manufacturers must provide a final report on an actively exploited vulnerability within 14 days of making a corrective or mitigating measure available. For serious incidents, the final report is due one month after the first report. Darren Anstee, CTO for security at Netscout, said the reporting deadlines introduce much-needed urgency in working toward global cyber resilience. "The 24-hour window in which an initial warning must be reported creates a level of urgency, with subsequent deadlines ensuring that the gathering and release of additional information is prompt," he said. "Better, more rapid sharing of information helps organisations put defences and mitigating controls in place when they know there is heightened risk." EU and non-EU manufacturers must file these reports through ENISA's Single Reporting Platform (SRP). Notifications are addressed to the coordinating computer security incident response team (CSIRT) determined under the CRA. For an EU manufacturer, this is generally the CSIRT for the member state where it has its main establishment; separate rules determine the coordinator for manufacturers based outside the bloc. Manufacturers must also inform affected users, where appropriate, about actively exploited vulnerabilities or severe incidents. The CRA states that users must be informed of available corrections or mitigations without undue delay. Generally, failures under the CRA are punishable by varying tiers of fines, the most serious of which can reach €15 million ($17.4 million) or 2.5 percent of the offender's annual turnover, whichever is higher. The reporting duties that took effect today are classified as core responsibilities under the act, meaning failures to comply with them could lead to the maximum fines being issued. They are the latest step in the EU's plan to drip-feed tighter security regulations on companies operating in the bloc. Most remaining CRA provisions become applicable on December 11, 2027, at which time manufacturers will also be required to embed security by design and default. That means no default passwords and security updates are no longer optional. Products covered by the CRA will also have to undergo the applicable conformity assessment before being placed on the EU market and bearing a CE mark. More than a deadline The CRA's new rules are not just intended to accelerate manufacturers' responses to security flaws. They are also intended to give businesses a better understanding of their software supply chains. With the reporting clock starting as soon as manufacturers become aware of an issue, they cannot afford to begin mapping an affected product only after a vulnerability or incident emerges. They need a comprehensive view of the affected product and any related products that may share the flaw if they are to meet the deadlines. Furthermore, those requirements demand that manufacturers maintain this understanding throughout each product's lifecycle. Creating a software bill of materials (SBOM) when a product is launched is one thing. The SBOM becomes a mandatory requirement when most of the CRA's remaining provisions become applicable next year. Maintaining that security snapshot over time, however, is intended to help reduce the number and impact of serious cyberattacks across the EU. "What all this means for manufacturers is that secure development, effective vulnerability handling, and traceability across the software supply chain should be elevated to the top of their priority list," said Eran Kinsbruner, veep of product marketing at Checkmarx. "Modern applications are assembled from a complex ecosystem of components, with combinations of proprietary code, open-source packages, third-party components and, increasingly, AI models and services all interconnected," he added. "Organizations need to understand these components, their dependencies and the risks they introduce." Given enough time, the CRA looks set to improve cyber resilience across the board. However, lawyers warn that manufacturers, particularly those outside heavily regulated sectors, must now contend with a growing body of overlapping rules. "The CRA is arriving as organizations are already grappling with a growing body of Digital Decade legislation, including NIS2, DORA, the Data Act, and the AI Act," said Heidi Waem, data, privacy and cybersecurity partner at DLA Piper. "We're seeing the compliance challenge for many businesses evolving beyond understanding single regulations in isolation, but determining how multiple frameworks interact, where requirements overlap and how compliance programmes can be coordinated across them." John Magee, partner and global co-chair of data, privacy, and cybersecurity at the same law firm, added: "Even now we're seeing the breadth of the regulation's reach catching organizations off guard. "Many still associate the CRA primarily with consumer IoT devices, when in reality it applies to a much broader pool of products with digital elements. For compliance teams already very busy managing multiple Digital Decade initiatives, there is a risk that this first wave of CRA obligations has arrived sooner, and with a wider impact, than they had expected." ®
Kategorie: Viry a Červi

ClickFix attacks infecting PCs and Macs are going viral

Ars Technica - 11 Září, 2026 - 13:30

It wasn’t that long ago that ClickFix attacks were exotic. Now the technique has become mainstream as attackers reap its simplicity and effectiveness in infecting users of PCs and Macs alike. All that’s required is a compromised website—a painless enough task—a fake CAPTCHA overlay, and the inclusion of a single terminal command. So many visitors get suckered into pasting and running the command that just about every malware pusher has adopted the technique. Even Kremlin-backed hacking groups are joining in.

“Reddit is becoming post after post after post of people getting their computer infected via ClickFix,” independent researcher Kevin Beaumont observed Thursday. “Legit websites everywhere [are] getting hacked to serve the fake captcha prompts.”

How many of us make things worse

More seasoned Internet users—a fair number who read this site—are quick to dismiss the attack. They typically blame the people who fall for the scams and marvel at their gullibility and lack of attention. The reality is that for more casual users, using computers and the Internet has become so difficult—think impossible-to-close interstitials, CAPTCHAs with an endless series of pictures to analyze, and constantly changing interfaces that bury the features they’re looking for—that they have grown desensitized to instructions that seem ridiculous and burdensome.

Read full article

Comments

Your Critical Vulnerabilities Might Not Be Your Biggest Risk

The Hacker News - 11 Září, 2026 - 13:30
Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually create a path to compromise. A critical vulnerability may look alarming on a scanner report, but if it sits behind strong segmentation, identity controls, and other defenses that prevent an attacker [email protected]
Kategorie: Hacking & Security

GitLab urges users to patch max severity path traversal flaw

Bleeping Computer - 11 Září, 2026 - 13:15
GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. [...]
Kategorie: Hacking & Security

Čím nahradit WhatsApp: Vybrali jsme 10 nejlepších alternativních komunikátorů

Živě.cz - 11 Září, 2026 - 12:45
Z WhatsAppu kvůli sdílení informací utíkají uživatelé. • Čím nahradit populární aplikaci pro zasílání zpráv? • Vybrali jsme 10 alternativních komunikátorů.
Kategorie: IT News

GIMP 3.2.6

AbcLinuxu [zprávičky] - 11 Září, 2026 - 11:52
Byla vydána nová verze 3.2.6 svobodné aplikace pro úpravu a vytváření rastrové grafiky GIMP (GNU Image Manipulation Program). Přehled novinek v oznámení o vydání a v souboru NEWS na GitLabu. Nový GIMP je již k dispozici také na Flathubu.
Kategorie: GNU/Linux & BSD

Jaderná elektrárna Temelín končí s ruským palivem. Na konci roku zavede první soubory od Westinghouse

Živě.cz - 11 Září, 2026 - 11:45
Státní úřad pro jadernou bezpečnost povolil ČEZu použití amerického paliva • První nové palivové soubory zamíří do temelínského reaktoru koncem roku • Západní dodavatelé a strategické zásoby zvýší českou energetickou soběstačnost
Kategorie: IT News

Microsoft fixes Teams, Outlook launch failures on ARM Windows PCs

Bleeping Computer - 11 Září, 2026 - 11:39
Microsoft has fixed a bug that prevented Teams and Outlook from launching on ARM-based Windows devices after installing updates released since the August 2026 Patch Tuesday. [...]
Kategorie: Hacking & Security

Ubuntu 24.04.5 LTS

AbcLinuxu [zprávičky] - 11 Září, 2026 - 11:35
Bylo vydáno Ubuntu 24.04.5 LTS, tj. páté opravné vydání Ubuntu 24.04 LTS s kódovým názvem Noble Numbat. Přehled novinek a oprav na poznámkách k vydání.
Kategorie: GNU/Linux & BSD

OpenAI pauses $200 Pro tier as Astra demand strains capacity

Computerworld.com [Hacking News] - 11 Září, 2026 - 11:23

OpenAI has paused new sign-ups and upgrades to its $200 ChatGPT Pro tier, citing a surge in demand for its Astra capability that is placing pressure on system capacity, according to company statements and an executive post on X.

“To make sure our current users have an incredible experience and continued access to Astra, we are going to pause subscriptions to our $200 Pro plan,” OpenAI member of technical staff Thibault Sottiaux wrote in a post on X. “These put the most strain on our systems and we wanted to take the smallest step that allows us to continue giving the broadest access possible.”

The company separately confirmed the move in its help documentation, stating that “as of September 10, 2026, we’re temporarily pausing new sign-ups and upgrades to the ChatGPT Pro $200 plan (Pro 20X).” The pause applies to users across Free, Go, Plus, and Pro $100 tiers seeking to upgrade, while “existing ChatGPT Pro $200 subscriptions … are not affected by this pause,” it said.

Sottiaux added that “there is no impact to existing accounts and we are working on adding more capacity as fast as we can,” pointing to ongoing efforts to scale infrastructure in response to demand.

Users who cancel or downgrade during the pause will not be able to re-subscribe to the $200 tier until the restriction is lifted, according to the company’s help page. The $100 Pro tier remains available, with lower usage limits. Promotions tied to the $200 tier are also paused, the page read.

Astra demand drives capacity decisions

The decision is directly tied to the uptake of Astra, which OpenAI has positioned as a more advanced capability within its platform. The scale of that demand, according to Sottiaux, has been atypical.

“Demand for Astra is really unprecedented,” he wrote in the post. “We’re pulling all the levers possible to sustain the demand, but I’ve not seen anything like it until now and we went through very steep growth before.”

He added that “priority will always be to keep excellent service for existing users,” noting that the company “might have to pause new Pro subscriptions for a bit if this continues.”

The pause comes amid broader rollout challenges tied to Astra. OpenAI Chief Executive Sam Altman recently described the launch as “messy” after some paying users were unable to access the model immediately, reflecting the operational complexity of deploying high-demand AI systems at scale.

Capacity constraints surface for enterprise workloads

The pause, analysts said, reflects how demand for high-intensity AI workloads is intersecting with infrastructure limits, particularly at the highest usage tiers.

“It signals that frontier capacity is still rationed,” said Bhupendra Chopra, chief revenue officer at Kanerika. “One week after launching Astra, OpenAI paused new sign-ups and upgrades to the $200 Pro tier, the plan with the heaviest Astra usage limits, while the $100 Pro tier, the API, Business and Enterprise all stayed open. That tells you the priority order.”

“Consumer power users are the release valve. Enterprise contracts are what the vendor protects,” Chopra said. “For CIOs the lesson is that a model being announced and a model being available to your workloads at the volume you need are two different events.”

Chopra said the move reflects how access to advanced AI capabilities is being managed.

“We are already there,” he said. “Rate limits, usage caps, queueing and now sign-up pauses are all forms of capacity gating, and every frontier vendor uses some of them.”

“A subscription buys you a place in the line. A fixed slice of compute comes only from a contract that says so,” he added.

Planning for constrained supply

For enterprise IT leaders, Chopra said model capacity should be treated as a dependency.

“Treat model capacity like any other supply chain dependency,” he said. “Ask the vendor three questions before you sign. What throughput is contractually committed, what happens to my workloads when demand spikes, and how quickly can I fail over to another model.”

“If a workload is production-critical, it should run on an enterprise agreement with committed capacity… and it should have a second model tested and ready,” he said.

A recurring pattern

Chopra said the pause reflects a broader pattern seen in recent launches.

“This is at least the third time in two years OpenAI has throttled or paused access at launch,” he said. “Each launch outruns capacity, capacity catches up, and the next model outruns it again.”

“OpenAI calls this pause temporary, and it will lift once capacity catches up,” he added. “The structural condition… will persist as long as model capability keeps outpacing data center buildout.” OpenAI has not provided a timeline for when new sign-ups to the $200 Pro tier will resume, stating only that the restriction is temporary.

The article originally appeared on CIO.com.

Kategorie: Hacking & Security

Vivaldi 8.2 zastoupí kalkulačku. Chystá se zvláštní edice pro podniky

Živě.cz - 11 Září, 2026 - 10:45
Vivaldi je duchovní nástupce staré dobré Opery. • Jde o prohlížeč pro pokročilé uživatele, kteří se nebojí hodiny ladit každý detail. • Více možností nastavení nenabídne žádný jiný prohlížeč.
Kategorie: IT News

Týden na ScienceMag.cz: Grafen s magickým úhlem poskytuje důkaz o nekonvenční supravodivosti

AbcLinuxu [články] - 11 Září, 2026 - 10:00

Šokující chemická vazba mezi 3 atomy thoria. Obrovský soubor dat o supernovách zpochybňuje konstantnost temné energie. Nové způsoby detekce rušení a falšování signálu GNSS. Projekt BESIII stanovil nejpřesnější omezení elektrického dipólového momentu hyperonu lambda. Experiment LUX-ZEPLIN přinesl nadějný výsledek při hledání temné hmoty.

Kategorie: GNU/Linux & BSD

TSMC spustí 1,4nm (A14) výrobu ještě dříve, z termínu vám spadne čelist

CD-R server - 11 Září, 2026 - 10:00
První zprávy o vydání Zen 7 na 1,4nm procesu TSMC již v roce 2028 působily jako pohádka tisíce a jedné noci. Už to ale nereálně nepůsobí, AMD nejspíš věděla podstatně více, než bylo veřejně známo…
Kategorie: IT News

Trezor: 347,000 users targeted in phishing attacks after Brevo breach

Bleeping Computer - 11 Září, 2026 - 09:55
Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link. [...]
Kategorie: Hacking & Security

Apple zdražil starší iPhony. Někteří prodejci je ale stále nabízí za původní ceny

Živě.cz - 11 Září, 2026 - 09:45
Apple společně s novými iPhony zdražil i ty starší • U základních modelů řad iPhone 16 a iPhone 17 je cenový nárust tři tisíce • U doprodejů iPhonů Air za staré ceny můžete výrazně ušetřit
Kategorie: IT News

Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

The Hacker News - 11 Září, 2026 - 09:31
Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz said in a report. Wiz saw the attacks between August 15 and September 8. JFrog had fixed both flaws before then, so only servers that had not been updated were open to them. Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

The Hacker News - 11 Září, 2026 - 09:14
A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital said in research published Thursday. The attack started with a crafted link and ended with the attacker able to do anything the logged-in user could do. Tencent, which owns Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Conti ransomware gang member sentenced to 4 years in prison

Bleeping Computer - 11 Září, 2026 - 08:48
A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022. [...]
Kategorie: Hacking & Security
Syndikovat obsah