Agregátor RSS

The iPhone is now Apple’s ‘intelligent personal hub’

Computerworld.com [Hacking News] - 9 Září, 2026 - 23:11

Twenty-five years ago, I sat near the front of the room while then-Apple CEO Steve Jobs rolled out Apple’s digital hub strategy, a vision in which the Mac would become the central manager of all manner of portable digital devices.

Now, a quarter of a century later, nearly all of those digital devices have become features on your iPhone, and the arrival of AI means the iPhone has become the intelligent personal hub, the central manager of, well, of you. Apple’s new CEO, John Ternus, went straight for the concept in his important opening remarks at Wednesday’s big iPhone launch, where nearly all the pre-event speculation came true.

The intelligent personal hub

“As we look ahead, we see a future filled with enormous discovery and transformation,” Ternus said at the Surprise and Shine event. “AI makes entirely new kinds of experiences possible. An AI can become even more useful when it brings together your life with the apps, services, and products you use every day. And this means the product at the center of your experiences becomes even more essential — what I like to think of as an intelligent personal hub.”

(To be clear: He’s talking about the iPhone.)

Think about it: all those tasks you now do on your iPhone are tasks AI can help you with. Siri AI lets you work on files and folders using spoken commands, while contextual AI lets you sift through all the data once gathered by your iPhone to do things, make things, create networks, or even organize luncheon. 

“It’s the intersection of broad new capability, and a deep understanding of your personal context that makes this idea so powerful,” Ternus explained.

AI’s brave new world

That’s the context within which Apple will be introducing all its future products, a battle the company now feels confident marching into now that it appears to have resolved its historical challenges with AI. At the same time, the company also seems to be doing its best to lean into privacy — enabling life-changing AI transformation of daily lives while putting a brake on scary privacy attacks. This is going to be foundational to what happens next at Apple.

Of course, you’re not reading this to look too deeply into what Ternus said about the future of Apple; you’ll also want some insight into the slew of devices the company introduced at its event. That list includes the:

The big surprise? Price

For some, the biggest surprise in these introductions was price. All of the accessories were kept at the same price as last year’s equivalents, while the new Pro iPhones came in at only $100 more for the entry-level model, rising to around $300 more at the more price-resistant highest end. An iPhone 18 Pro Max equipped with the max 2TB storage comes in at $2,499 compared to the $1,199 iPhone 18 Pro entry point. 

When it came to price, though, all eyes were certainly on the iPhone Duo, and Apple has given everyone (except competitors) a pleasant surprise on that. 

With a starting price of $1,999, the folding phone’s price hit the low end of expectations, and while that grows to an eye-watering $3,199 with 2TB of storage, it compares well with the market leader, Samsung. While the Galaxy Z Fold 8 begins at $1,899, in terms of features and design, Apple’s folding phone lines up with the Galaxy Z Fold 8 Ultra, which costs from $2,099. 

Dig a little deeper and you’ll see that while the iPhone has IP68-rated dust and water resistance, the Samsung equivalent has only IP48. You can drop the Fold 8 into five feet of water for up to half an hour and it should be OK, but you can chuck your iPhone Duo in almost twenty feet of water, and it should survive. Though you probably shouldn’t test that unless you’re a hugely successful “influencer” already generating a small nation state of money through clicks. If that’s you, good for you. I’m only slightly envious. 

A productivity powerhouse?

What that suggests is that the iPhone is less likely to get damaged and is better engineered, though it’s also ever so slightly thicker. Apple’s device is powered by what the company modestly described as the most powerful mobile processor on the planet — which it is, particularly for the AI tasks all the new iPhones can handle. That matters, particularly for applied contextual AI deployed across daily lives.

It also matters because the combination turns Apple’s device into a mobile productivity powerhouse, one that I think will likely affect iPad sales more than anything else. Though this wouldn’t be the first time a new Apple release ended up eating its siblings. 

The productive possibilities of Apple’s premium device will also be realized as app developers embrace both the form factor and Siri AI. Apple said during the keynote that more than 300,000 apps already work with Siri AI and more than 2.5 billion Siri requests are being made each day. That latter number will only grow now that Siri performance has been dramatically improved. 

While this argument applies to all Apple’s new devices, the fact of the matter is that you now have an iPad-sized object you can carry in your pocket that is capable of doing some really powerful tasks by spoken command alone. That’s the iPhone Duo – a product of an unexplored territory at the crossroads between mobile computing, daily digital existence, and the opportunities of AI.

It’s not for everyone, yet

I don’t expect the Duo will be for everyone; the vast majority of users won’t be spending $2,000 on a phone. But we know that the cost of technologies like this tends to decline, which suggests that in perhaps five years’ time, it will be possible to create equivalent devices for a much lower price. Right now, it’s for affluent Apple consumers, C-class executives, students, AI pros, medical professionals and others who might actually need this kind of performance and display space to get things done.

This, incidentally, is precisely the same group of people that first embraced the iPad when it appeared, turning that into the world’s best-selling tablet.

What might this mean for Apple? 

I traded a few messages with IDC analyst Francisco Jeronimo, who sees it like this: “Apple entered the foldable market and, in one keynote, set the price and the standard every rival will now be measured against.”

He also pointed out, the iPhone Duo is “…a direct test of whether Apple can use design, ecosystem integration and premium positioning to reshape a segment that has so far remained selective.” 

He’s right, of course, but Ternus also just defined what that segment, and the industry, is driving for. I’s the same thing Apple was aiming at 25 years ago. “iPhone sits at the center of an amazing ecosystem of intelligent features and experiences that work seamlessly across the products you use every day,” the company said — an “intelligent personal hub.” And the Macs are all right, too.

Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSkyLinkedIn, or Mastodon.

Kategorie: Hacking & Security

Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking

Bleeping Computer - 9 Září, 2026 - 23:02
The Carnegie Mellon University CERT Coordination Center (CERT/CC) is warning that Skullcandy Dime 3 wireless earbuds accept Bluetooth pairing requests from nearby unpaired devices without requiring user interaction. [...]
Kategorie: Hacking & Security

Four groups caught using the same Chrome and Windows exploit kit

Ars Technica - 9 Září, 2026 - 22:55

A nearly identical exploit kit that targets critical vulnerabilities in both Chromium-based browsers and older versions of Windows is being actively used by at least four hacking groups, some of which have ties to the Chinese government.

Researchers from security firm Proofpoint said Wednesday that BlueMoon, the name they gave to the kit, chains three vulnerabilities together so the attackers using it can install malware of their choice. BlueMoon exploits two Chromium vulnerabilities and one in the kernel of Windows 10 (Oct. 2018 Update), Windows Server 2019, Windows 10 2004, Windows Server 2022, and the initial release of Windows 11. All three vulnerabilities have received patches in the past 24 hours.

Deployed rapidly, widely shared

The attacks lacked the stealth found in many campaigns. More often, hackers want to exploit newly discovered vulnerabilities sparingly to lengthen their longevity. Proofpoint hypothesized that one reason for the widely used and visible exploit chain was to take advantage of a “patch gap” in the Chromium supply chain, which spans the time a patch is available from developers and the time that patch is incorporated into browsers such as Chrome and Edge. Another likely contributor was the use of AI, which can often spot vulnerabilities faster than discovery performed solely by humans.

Read full article

Comments

Adobe Patches Actively Exploited Magento Vulnerability on Linux Servers

LinuxSecurity.com - 9 Září, 2026 - 22:45
Adobe has released an emergency fix for a Magento vulnerability that attackers are already using against online stores. Someone exploiting the flaw can make an affected store run code without first signing in. Adobe confirmed the attacks on Sep 8, 2026, one day after releasing the urgent hotfix.
Kategorie: Hacking & Security

New Linux Kernel Testing Tool Can Force Race Conditions

LinuxSecurity.com - 9 Září, 2026 - 22:30
Linux kernel testing can miss a bug when it depends on two tasks reaching the same data in an unusual order. These independently running tasks are called threads. A race condition occurs when their timing changes whether the code works correctly, which can make a failure difficult to reproduce. Google Project Zero published MAccConc on Sep 8, 2026 as a prototype that changes the timing itself. Its name is short for Memory Access Concurrency. The tool traces selected Linux kernel memory access...
Kategorie: Hacking & Security

iPhone Duo, iPhone 18 Pro, Watch Series 12, Watch Ultra 4 a AirPods 5

AbcLinuxu [zprávičky] - 9 Září, 2026 - 22:27
Apple dnes představil (YouTube) iPhone Duo, iPhone 18 Pro, Watch Series 12, Watch Ultra 4 a AirPods 5.
Kategorie: GNU/Linux & BSD

Linux Privilege Escalation Exploit Uses an RDS Cleanup Bug

LinuxSecurity.com - 9 Září, 2026 - 22:10
A new Linux privilege escalation exploit shows how a cleanup mistake in Reliable Datagram Sockets, or RDS, can give a local user root access, meaning administrator control of the machine. RDS is a Linux kernel networking subsystem designed for low-latency communication between machines and processes.
Kategorie: Hacking & Security

IPv6 Security Flaw Lets Route Listing Reach Freed Kernel Memory

LinuxSecurity.com - 9 Září, 2026 - 21:45
Listing network routes should tell administrators where traffic will go. An IPv6 security report instead shows Linux accessing a freed record used to keep track of that listing. A list of active readers still points to the record after cleanup releases it, so a later route change can reach invalid memory and crash the kernel.
Kategorie: Hacking & Security

U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto

The Hacker News - 9 Září, 2026 - 20:26
The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and deploying the Scam Center Strike Force to Madagascar to help disrupt 13 scam compounds run by Chinese organized crime
Kategorie: Hacking & Security

U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto

The Hacker News - 9 Září, 2026 - 20:26
The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and deploying the Scam Center Strike Force to Madagascar to help disrupt 13 scam compounds run by Chinese organized crime Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Adobe Acrobat evolves beyond PDFs with enterprise search, AI content creation

Computerworld.com [Hacking News] - 9 Září, 2026 - 20:23

Adobe on Wednesday unveiled a range of updates to Acrobat, including the ability to turn PDF documents into interactive visual reports and podcasts. And a new Knowledge Base feature connects Adobe’s Acrobat AI assistant to document sources such as Microsoft SharePoint and Google Drive.

It’s the biggest Acrobat update in several years, Adobe said, and highlights the application’s evolution from PDF reader to what the company now describes as an AI-powered document productivity and creativity platform. 

Acrobat users open more than 400 billion PDFs in the app each year, Adobe said, claiming 650 million monthly active users as of last year

Among the new additions is the ability to turn dense PDFs into interactive, visual documents and presentation slides. To create these, Acrobat’s AI assistant scans the selected file, asks questions about the user’s intent, then generates documents charts, images and navigation.

It’s also possible to turn documents and web links into podcast-style audio summaries — similar to capabilities in Google’s NotebookLLM and Microsoft Copilot Notebook. A new Stylize feature can enhance plain-looking documents, applying a template to turn them into “professional deliverables” such as CVs and invoices, Adobe said.

The audio and visual generation features are all available in paid Acrobat plans (Acrobat Studio, Acrobat Express and Acrobat AI Assistant). 

Another addition, Acrobat Knowledge Base, lets customers connect the Acrobat AI assistant to a wider range of file types, enabling users to ask questions about information held in documents stored in Microsoft SharePoint and Google Drive, for example.  

Acrobat’s Knowledge Base “transforms curated document collections — policies, playbooks, product information, pricing guidance, research — into cited answers available from Slack, Microsoft Teams, Acrobat, and other places employees already work,” Abhigyan Modi, senior vice president for Adobe Document Cloud, said in a blog post

Adobe also added an Analyzer tool designed to retrieve data from large volumes of documents. This could involve analyzing thousands of contracts or invoices to identify information such as renewal dates and revenue clauses.

That turns information once trapped in files into data that can inform finance, procurement, compliance, and the systems that support them, said Modi.

Analyzer is the more interesting of the two releases, said Mike Leone, vice president and principal analyst at Moor Insights & Strategy. “Knowledge Base is a search product and search products get judged feature against feature. Analyzer is closer to a data product, because that extraction work is what companies currently pay people and pipelines to do,” he said. 

“What I’d want Adobe to answer is whether that data can leave Acrobat and land where the rest of the company’s data lives. If it can, this starts competing for real data budget. If it stays inside the app, it’s a very good Acrobat feature.” 

Access to Analyzer and Knowledge Base requires an Acrobat Studio for Enterprise subscription. (Adobe doesn’t publish pricing.) 

In addition, Knowledge Base includes a credit-based model that places some restrictions on usage, with licensed users allowed up to 1,000 queries a month. Other actions, such as document uploads, queries from Slack and Microsoft Teams, and queries by employees without an Acrobat Studio license, draw varying amounts of Acrobat Studio “shared credits.” Adobe didn’t say how much additional credits cost once a yearly limit is reached.

 More information about Adobe’s Knowledge Base credit usage policy is available on Adobe’s website

Analyzer also includes a credit system that limits document ingestion and attribute extraction.

For enterprise customers, usage-based pricing can add complexity when managing employee access.

“The issue for a broad deployment is that headcount barely predicts usage,” said Leone. “One person pointing it at 10,000 contracts will burn more credits than a hundred people asking the occasional question. Pooling the credits across the whole organization is the right design, because usage on something like this is rarely spread evenly.

“One of the big challenges is that people could very well start rationing themselves because they don’t know what a question costs,” he said. “Or worse, a couple folks use all the credits and everyone else is out of luck. The last thing any organization wants is to pay for a knowledge tool that people won’t use or can’t use.”

Kategorie: Hacking & Security

Serial Microsoft 0-day hunter drops yet another Defender exploit

The Register - Anti-Virus - 9 Září, 2026 - 19:23
Zero-day researcher Nightmare Eclipse, aka MSNightmare, published yet another Microsoft Defender proof-of-concept exploit for a zero-day dubbed ShieldCrash, which they claim will allow attackers to bypass the earlier ShieldBreak patch and read files as SYSTEM. “I might rework this later into a full SYSTEM PoC but for now I'm dropping this skeleton PoC because I'm feeling a bit lazy,” the prolific Microsoft bug hunter and thorn in Redmond's side said in their latest zero-day exploit's README. As is usual with Nightmare’s zero-day cadence, they published ShieldCrash shortly after Microsoft released its latest Patch Tuesday security updates. According to Nightmare, this exploit works on Windows systems that have already applied the September patches. ShieldCrash purports to be a bypass of an earlier Defender privilege escalation zero-day, ShieldBreak (CVE-2026-69414), that allowed attackers to bypass another patch for another Nightmare Eclipse zero-day RoguePlanet (CVE-2026-50656). Redmond patched ShieldBreak last week, and RoguePlanet in July. Both allowed attackers to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems. The latest bypass, ShieldCrash, allows arbitrary file reads as SYSTEM - but not arbitrary writes or a full SYSTEM shell, according to the researcher. Microsoft did not immediately respond to The Register’s questions, including when it planned to patch ShieldCrash. We will update this story when we hear back. While the serial bug hunter typically finds and publishes Microsoft exploits - ShieldCrash is Nightmare’s 11th Microsoft zero-day, and they have made clear that with Redmond, their vendetta is personal - they recently branched out into other security vendors’ software. Last week, they released a zero-day bug called FalconFlank that affects CrowdStrike’s Falcon endpoint security platform. This one still has a Windows twist: the privilege escalation bug abuses the Microsoft Office malicious macros remediation feature in CrowdStrike Falcon. Security sleuth Kevin Beaumont confirmed the FalconFlank exploit works, along with several others Nightmare released over the past couple of weeks. These include HardBreacher, a now-patched elevation of privileges bug in Kaspersky’s endpoint antivirus product, and PrettyPrague, an elevation of privileges vuln in Gen Digital’s Avast antivirus software. ®
Kategorie: Viry a Červi

US says Chinese firms extracted billions of tokens from frontier AI models

Bleeping Computer - 9 Září, 2026 - 18:48
U.S. cybersecurity and intelligence agencies say that six Chinese AI companies conducted industrial-scale distillation attacks on American frontier AI models since at least late 2024. [...]
Kategorie: Hacking & Security

ChatGPT teď obrázky kreslí lépe a mnohem rychleji. Mrkněte na novou galerii s Ježíšem, zrzkou i kočkopsem

Živě.cz - 9 Září, 2026 - 18:45
GPT-Image 2.5 je nejlepší obrazový generátor na světě. • Je rychlejší a přesnější než starší modely a má i nové funkce. • Vyzkoušeli jsme jej na desítkách promptů pro generování i úpravy.
Kategorie: IT News

No, AI is not killing jobs for everyone, studies say

Computerworld.com [Hacking News] - 9 Září, 2026 - 18:43

A slew of recent studies indicate that AI isn’t dramatically displacing workers. At the same time, there were no indicators that the fast-moving technology is creating a lot of jobs, even as AI skills remain in high demand.

Stanford University researchers in an August study found that any AI-related job declines were concentrated among young workers aged 22–25. But for older and more experienced workers that wasn’t the case.

“Claims of economy-wide AI-driven job losses are not visible in payroll data through June 2026,” the researchers said, citing ADP payroll information. Stanford partnered with ADP to conduct the research.

The decline for young workers is more often related to the automation of some work tasks by AI, as opposed to its use to complement work. In contrast, AI is more often used by experienced workers to augment what they do. 

According to the Stanford report, workers between 22 and 25 and employed in jobs highly exposed to disruption by AI are falling behind their older counterparts. Their employment levels in June were about 19% below the same age group in less-exposed occupations. That’s compared to where they would be if both groups had kept pace with each other.

“Experienced workers show no comparable gap,” the researchers said, adding that “this is consistent with recent reports of a worsening job market for entry-level workers.”

Employment of younger workers in AI-exposed jobs fell about 11% from late 2022, while the same age group in less-exposed jobs actually grew about 10%. “For older age groups, we find much less marked differences in employment growth across AI exposure quintiles,” the researchers said.

Stanford, which created a lab last year to study AI’s impact amid heightened fears of the technology’s economic effects, said its numbers were based on available indicators.

AI’s adverse impact on young workers has been well documented, with many of them laid off in the initial wave of AI automation. AI has also suppressed wages for entry-level workers.

AI was cited for 116,175 job cuts in 2026, but that number is declining. The technology  was blamed for 3,462 cuts in August, according to data from Challenger, Gray and Christmas.

It’s the “lowest monthly total since December 2025 when 142 cuts were attributed to AI,” the company wrote in a blog entry. The research firm also noted aggressive hiring plans for companies in 2027.

AI is adding value to companies in different ways, and humans are an important part of that process, said Michael Chui, a senior fellow at QuantumBlack, AI at McKinsey. “The night shift is real now,” he said. “People are sending off their agents to write code and checking in the morning.”

MIT late last year established an AI labor index to determine how agents are affecting the workforce. The school’s Project Iceberg looks at how the coordination and interaction with agentic AI changes how work is done.

Despite the disruptions, demand for AI-related talent continues to rise, tech industry consortium CompTIA said last week. About 320,000 job listings in August required AI-related capabilities, a 4.5% increase from July.

AI-related hiring is outperforming the broader tech market, with demand for AI skills up 96% year-over-year, said Kye Mitchell, head of Experis North America, which is part of ManpowerGroup.

“We’re seeing real growth…in marketing management and project management roles, suggesting employers are looking beyond the people building AI to the people applying it,” Mitchell said.

More broadly, the US economy added 162,000 jobs in August, according to US Department of Labor figures released last week. CompTIA noted that tech employment across all sectors rose by 86,000 workers in August.

But within the tech sector, 14,700 positions were cut, CompTIA said.

Kategorie: Hacking & Security

Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

The Hacker News - 9 Září, 2026 - 18:34
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo,
Kategorie: Hacking & Security

Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

The Hacker News - 9 Září, 2026 - 18:34
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo, Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Syndikovat obsah