Agregátor RSS

tmp.0ut Volume 5

AbcLinuxu [zprávičky] - 4 Září, 2026 - 17:33
Bylo vydáno nové číslo hackerského magazínu tmp.0ut: Volume 5.
Kategorie: GNU/Linux & BSD

Critical Citrix NetScaler auth bypass now leveraged in attacks

Bleeping Computer - 4 Září, 2026 - 17:25
Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian. [...]
Kategorie: Hacking & Security

PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution

The Hacker News - 4 Září, 2026 - 17:20
PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logical decoding was introduced in PostgreSQL 9.4 in 2014. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are
Kategorie: Hacking & Security

PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution

The Hacker News - 4 Září, 2026 - 17:20
PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logical decoding was introduced in PostgreSQL 9.4 in 2014. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Macs don’t just do AI, they’re replacing the cloud for it

Computerworld.com [Hacking News] - 4 Září, 2026 - 17:08

surprised myself this morning when I came across an interesting Apple-commissioned report — Rethinking critical AI infrastructure — I’d not seen before. It looks at the shifting expectations for AI infrastructure and recognizes that enterprise users want (and need) secure, on-device AI solutions for critical parts of their business.

That’s why tens of thousands of companies are already investing in Macs, because they recognize that Macs do indeed do AI. The study, published earlier this year and put together by Omdia, reflects insights gathered across 1,500 conversations with enterprise tech leaders and practitioners, noting that for many in business the current cloud-based approach to AI fails to deliver on three key metrics:

  • Costs: Current pricing models seem unsustainable. Particularly when it comes to agentic AI, costs climb fast and business users need to get those costs under control. 
  • Security: Even the most secure cloud services include some degree of data risk. When it comes to using AI for regulated data in industries such as healthcare, business users need much more security than the cloud inherently provides. After all, data that is not transmitted will not leak in transmission.
  • >Capacity>: Workload requirements change and capacity needs to scale. That can boost the cost of accessing additional cloud capacity, or impose limitations in the event it can’t be found. It’s also true that while frontier models can provide all the bells and whistles of AI for advanced tasks, the vast majority of the AI work does not require anything near as much power. As Omdia explains: “57% of enterprise models are under 10 billion parameters, well within the capabilities of modern devices like MacBook Air or the entry-level MacBook Pro.”
What they think

As you might expect, the researchers believe on-premises AI set-ups respond to all three needs; not only that, but once you’ve coughed up cash for the necessary computational infrastructure, you don’t have to pay much more. “On-device infrastructure has near-zero marginal cost after initial investment, enabling unlimited experimentation without budget constraints,” the report said. 

Basically, once you’ve invested in on-premises capacity, you can divert mundane AI tasks to those machines for processing — limiting costs, boosting security and releasing capacity, turning to cloud-based models only when higher end AI solutions are required. While that’s good news for Apple, that’s bad news for many AI companies’ revenue models. (Perhaps they should have recognized that even the most advanced LLM’s will run on a standard iPhone eventually.)

The other advantage is that if AI is not used as widely as expected across a company, the same hardware can be used for other company tasks.

What’s actually happening

Enterprises already using AI are learning these lessons, which is why we see more of them buying Macs for these tasks. They do so because Apple’s computers deliver the computational power and performance to run AI effectively, from chip design to power consumption to the OS itself. Apple has intentionally built its platforms to be the best in class for running AI on device, and the Unified Memory architecture Apple has created in Apple Silicon scales really well, meaning you can run ever larger LLMs on Macs. 

It’s not just Macs, either. An iPad can run up to 14 billion parameter models quite happily; a Mac Studio reaches 480 billion; and a cluster of four Mac Studios will take you all the way to 1.6 trillion parameters using off-the-shelf cables.

To put that into context, Omdia found that 57% of the AI models typically used by the enterprise come in at under 10 billion parameters, which implies that enterprises could run a huge chunk of their AI tasks on an iPad, an iPhone, and certainly on a Mac. The ability of Apple’s ecosystem to scale is precisely why most AI developers at frontier model companies already use Macs. “Organizations that build AI solutions in-house adopt Mac for AI workloads at nearly double the rate of organizations buying commercial solutions,” the report explained.

The takeaway

Apple is emerging as an important component of an overall ecosystem for applied AI in the enterprise — or anywhere else — challenging frontier models with a scalable, controllable, economical, and secure approach to deployed AI that delivers most of the bang expected for the enterprise buck. 

While Apple paid for the report, that doesn’t necessarily invalidate its conclusions, which are not myopic around the Apple platform. Apple does not replace everything else, it just becomes one of the pillars to build success with AI. Companies can use other AI services and solutions, but they’ll want Macs along for at least some of the ride. And as the models themselves evolve and become slimmer and more refined, the platforms that run them best will deliver the advantage business users need.

Now, we need Apple to develop tools for the management, deployment, and governance of these solutions.

Please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSkyLinkedIn, or Mastodon.

Kategorie: Hacking & Security

New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic

The Hacker News - 4 Září, 2026 - 16:51
A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and
Kategorie: Hacking & Security

New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic

The Hacker News - 4 Září, 2026 - 16:51
A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host andSwati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Zadání znělo: Najdi na webu nějaká čísla. Roj agentů OpenAI si k tomu zřídil další tajnou nástěnku

Živě.cz - 4 Září, 2026 - 16:45
V červnu se na německé programátorské wiki objevilo varování. Jeden z agentů oznámil ostatním, že moderátor maže jejich stránky podle abecedy, a poradil jim založit zálohu se jménem začínajícím na ZZZ, aby přišla na řadu jako poslední. Připomíná to kauzu Hugging Face, že? Tentokrát si ale roj ...
Kategorie: IT News

Zadání znělo: Najdi na webu nějaká čísla. Roj agentů OpenAI si k tomu zřídil další tajnou nástěnku

Zive.cz - bezpečnost - 4 Září, 2026 - 16:45
V červnu se na německé programátorské wiki objevilo varování. Jeden z agentů oznámil ostatním, že moderátor maže jejich stránky podle abecedy, a poradil jim založit zálohu se jménem začínajícím na ZZZ, aby přišla na řadu jako poslední. Připomíná to kauzu Hugging Face, že? Tentokrát si ale roj ...
Kategorie: Hacking & Security

Microsoft says some users can’t open the Teams desktop client

Bleeping Computer - 4 Září, 2026 - 16:30
Microsoft is working to resolve a known issue that causes delays or blocks some users from opening the Microsoft Teams desktop client on Windows systems. [...]
Kategorie: Hacking & Security

39 New Methods That Compromise Passkey Authentication

Bleeping Computer - 4 Září, 2026 - 16:01
Passkeys eliminate many password-based attacks, but researchers have documented 39 methods for compromising authentication built around them. Token explains how attackers can abuse authentication prompts, synced credentials, enrollment, recovery, and other trust boundaries without breaking FIDO2 cryptography. [...]
Kategorie: Hacking & Security

Nvidia lets you build your own AI clusters locally with PAIR software

Computerworld.com [Hacking News] - 4 Září, 2026 - 16:00

Nvidia has released a free tool that will enable users to build an AI inferencing cluster from disparate PCs on the same network, accessible from a single interface.

Released as a beta, Nvidia Personal AI router (PAIR) connects devices running Windows, macOS or Linux to process AI inferencing workloads privately.

While the system is aimed primarily at home users, it could find favour with enterprises looking to put idle desktop compute capacity to use.

PAIR works with DGX Spark desktop supercomputers, PCs containing RTX GPUs, and some MacOS devices. The systems in the cluster run tasks in parallel, but PAIR does not turn them into a virtual GPU, Nvidia said.

The beta version of Nvidia PAIR is available for download now.

This article first appeared on Network World.

Kategorie: Hacking & Security

Německo odpálilo balistickou raketu. Naposledy je mělo ve výzbroji před více než třiceti lety

Živě.cz - 4 Září, 2026 - 15:56
Moderní Německo se krátce po svém znovusjednocení v roce 1990 zbavilo zásob balistických raket. Zatímco někdejší západoněmecký Bundeswehr měl ve výzbroji americké pershingy, východ disponoval sovětskými raketami typu Scud, Točka a Oka. Po více než třiceti letech se ale vše mění. Zkraje léta ...
Kategorie: IT News

Bidding war for defunct Spirit Airlines’ employee data will not die

Computerworld.com [Hacking News] - 4 Září, 2026 - 15:32

The destiny of Spirit Airline’s data is still undecided, months after the company sought bankruptcy protection.

AI data company Micro1 has now offered $12.5 million to acquire a trove of the company’s emails, Teams chats, operations and employee productivity data, according to a report by aviation website Simply Flying,

It said the data includes about 600 million email and chat records generated by 17,000 employees, as well as 17 million OneDrive files, 20.5 million SharePoint items, and more than 30 million recorded customer service calls. Such a large repository of information is a gold mine to any company looking to train AI models more effectively. The report says that this data includes sensitive, decades-old employee and workplace records.

But Micro1’s offer comes weeks after Google acquired the data at auction, with its $10 million bid beating the $7.5 million offered by another AI training company, Mercor.

The airline’s former employees objected to the sale, and last week their unions took legal action to block the it.

Nelson, international president of the Association of Flight Attendants-CWA, which continues to represent more than 5,500 of Spirit’s flight attendants, told Forbes that former flight attendants were unhappy about Spirit attempting to cash in on sensitive data when they still have not been paid their accrued vacation time, sick leave, and outstanding compensation.

However, this type of personal data is extremely valuable to the likes of Google. It means that AI models can be trained in more realistic scenarios. One option that is being explored is whether the data can be anonymized, which may offer a way forward to keep both sides happy.

This article first appeared on CSO.

Kategorie: Hacking & Security

Vše, co Apple ukáže příští týden na keynote: tři iPhony, dvoje Apple Watch a nová sluchátka

Živě.cz - 4 Září, 2026 - 15:32
Nový šéf Applu oznámí na podzimní keynote šest prémiových zařízení • Uvidíme první skládací telefon i výkonné chytré hodinky se satelitní konektivitou • Levnější základní modely smartphonů dorazí na trh až příští rok
Kategorie: IT News

New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges

Bleeping Computer - 4 Září, 2026 - 15:22
An anonymous security researcher who uses the "Nightmare Eclipse" handle released a CrowdStrike Falcon zero-day exploit named "FalconFlank" that lets attackers escalate privileges on up-to-date Windows systems. [...]
Kategorie: Hacking & Security

Cyberpunkové město z ASCII znaků působí skoro jako skutečný svět. Nechybí auta, chodci ani budovy s interiéry

Živě.cz - 4 Září, 2026 - 14:45
Vývojář stvořil průchozí cyberpunkové město vygenerované z ASCII znaků • Vlastní engine zobrazuje budovy i chodce pomocí chytrého vysílání paprsků • Prototyp běžící v jednom souboru nabízí vstup do budov i jízdu výtahem
Kategorie: IT News

Exchange Online outage causes email delays, 'Server busy' errors

Bleeping Computer - 4 Září, 2026 - 14:22
Microsoft is working to resolve an ongoing Exchange Online outage that is delaying email sent to and received from external domains. [...]
Kategorie: Hacking & Security

Google warns of new Chrome zero-day flaw exploited in attacks

Bleeping Computer - 4 Září, 2026 - 13:48
Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities. [...]
Kategorie: Hacking & Security
Syndikovat obsah