Agregátor RSS
V národním parku Thong Pha Phum v západním Thajsku objevili doposud neznámou a poněkud pekelnou hvězdnatku, která dostala jméno Thismia daemona. Životním stylem je to spíše houba než rostlina a roste na jediném známém místě na světě, na ploše menší než fotbalové hřiště.
Finální verze DLSS 5 se ukázala jako extrémně energeticky náročná. Zatímco při klasické zátěži existovaly hry, ve kterých si karta vystačila se ~400 W, s DLSS 5 bere stabilně ~550-575 wattů…
Cold Reset Recovery v ovladači Intel Xe a Intelligent Bias Control v3 pro Panther Lake v jádru Linux 7.4, Mesa 26.2.2 zapíná podporu GPU v Intel Nova Lake, práce na asynchronním vypínání zařízení pokračují, cyklus vývoje jádra Linux verze 7.3 narušují AI/LLM hlášení.
A newly confirmed Kestra vulnerability is being exploited in the wild. CISA added CVE-2026-49869 to its Known Exploited Vulnerabilities catalog on Sep 2, 2026, turning an already serious authentication bypass into a current incident-response concern.
A kernel crash tells defenders that something went wrong. It does not show whether an attacker can turn that failure into a useful capability, combine several capabilities, and reach a security goal. That gap is one of the hardest parts of Linux kernel exploit development.
Attackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code. [...]
A prominent US senator is asking the National Security Agency to provide guidance to the general public on best practices for using virtual private networks to secure their communications from spying by foreign adversaries.
VPNs funnel all of a user’s Internet traffic through an encrypted connection to a remote server. The design provides strong assurances that no one between the user and the server can read the encrypted contents. VPNs also allow users to hide their IP addresses from the destination servers they communicate with. While US agencies have previously recommended use of VPNs, none have given recommendations on which ones provide adequate protection.
It's all in the nuances
There are a host of limitations that can undo many of the protections users may think their VPN provides them. For instance, the encrypted tunnel often terminates once a single server decrypts the traffic and sends it on to its final destination. That means the decrypted traffic or the sending and destination IP addresses may be available for snooping by rogue employees or attackers who hack the server. VPNs also don’t encrypt certain types of metadata, such as time stamps, allowing nation-states to build profiles that can be useful in intelligence gathering. Read full article
Comments
Tottenham Hotspur, a professional soccer team that’s part of the Premier League, has saved over 85 percent in licensing fees by replacing its stadium's VMware instance with Hewlett-Packard Enterprise’s (HPE’s) Morpheus VM Essentials (VME) virtualization software.
Tottenham hasn’t disclosed which VMware products it used or how much it previously paid the Broadcom firm.
The soccer organization confirmed this week to The Register that it has moved its stadium's server, storage, and networking infrastructure to HPE solutions delivered through HPE's hybrid cloud management platform, GreenLake. That is all “underpinned by" VME and HPE's OpsRamp software for hybrid and multi-cloud environments, Rob Pickering, Tottenham's CTO, told the publication, with HPE in charge of the hybrid cloud-managed service. Read full article
Comments
Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution. [...]
The disgruntled security researcher known as Nightmare Eclipse (aka Chaotic Eclipse, Infinite Nightmare, and now also MSNightmare) is moving away from their singular Microsoft vendetta and on to other vendors. On Thursday, they dropped a new zero-day bug called FalconFlank that affects CrowdStrike’s Falcon endpoint security platform - albeit with a Windows link. According to the prolific zero-day hunter, FalconFlank is a privilege escalation vulnerability that abuses the Microsoft Office malicious macros remediation feature in CrowdStrike Falcon. This is an automated security tool built into the platform that inspects Microsoft Office documents. If it finds any potentially harmful macros, the feature strips the suspect code and - hopefully - prevents malicious code or other dangerous payloads from executing when users open the document. “We are actively investigating these claims and advise customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting,” a CrowdStrike spokesperson told The Register. “Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. We refer customers to the FalconFlank Tech Alert in the CrowdStrike support portal.” The proof-of-concept (PoC) exploit works on fully updated Windows 11 25H2 and Windows Server 2025 systems running CrowdStrike Falcon with Phase 3 - Optimal Protection as well as the malicious macro removal feature enabled, Nightmare Eclipse said in a GitHub README. “Obviously by the time I drop this Crowdstrike would already have detections for it so if you want to test you either have to add it to the exclusions or obfuscate the PoC and change the dll load technique,” they wrote. Security sleuth Kevin Beaumont confirmed this exploit works, along with several others Nightmare released over the past week. Beaumont told us that he’s not surprised to see Nightmare digging into other, non-Microsoft zero-days. “Kinda makes sense they’d branch out to other vendors as there’s problems across the endpoint security space with the quality of the security products in terms of…security unfortunately,” Beaumont told The Register. “Hopefully it causes cybersecurity vendors to up their game, stop hyping hypothetical AI attacks, and instead make their own products secure for customers.” FalconFlank follows other vulnerabilities in various endpoint and antivirus products that Nightmare has found and published in the last several days. These include HardBreacher, an elevation of privileges bug in Kaspersky’s endpoint antivirus product. “So the problem is now leaking outside of Microsoft,” Nightmare said when they published the HardBreacher PoC last week. “There was poll held against either finding a bug in the home or commercial version and the poll results were the commercial version. At the time of writing this, the proof of concept works in a fully patched windows 11 25H2 & Kaspersky for Endpoint v14.0.0.504.” Beaumont confirmed that Nightmare’s HardBreacher exploit code works, as does a PoC for an elevation of privileges vuln in Gen Digital’s Avast antivirus software. This zero-day, named PrettyPrague, “will dump the SAM database by abusing a vulnerability in Avast Sandbox and spawn a full SYSTEM shell,” according to the researcher. "Gen was recently made aware of a security vulnerability affecting a subset of Gen products, including Avast Antivirus, that could allow an attacker to elevate their system privileges," Gen Digital told The Register. "We immediately initiated our security response procedures and are actively developing a patch. We take all security matters seriously and are committed to addressing this issue swiftly." Kaspersky did not immediately respond to The Register’s requests for comment. Nightmare also recently released an Nvidia memory corruption zero-day vulnerability dubbed GreenSection, but according to Beaumont, this one just crashes the system. Nvidia did not respond to our inquiries.® Updated to add at 0905 PT on September 4, 2026 "Kaspersky has resolved the HardBreacher issue. The corresponding fix is delivered via an automatic update, or users can trigger a database update manually," the company told The Register. "During our investigation into the reported issue, we identified an opportunity to enhance our existing behavior-based detections to ensure overall stability and prevent system freezes under certain configurations."
The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone might open the door?
That idea runs through this edition. Attackers use real tools, fake login pages, old account links, and software guides that point to unsafe downloads. One wrong letter in a web address can be enough.
There is also
The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone might open the door?
That idea runs through this edition. Attackers use real tools, fake login pages, old account links, and software guides that point to unsafe downloads. One wrong letter in a web address can be enough.
There is also Ravie Lakshmananhttp://www.blogger.com/profile/ [email protected]
Ministerstvo spravedlnosti USA podpořilo OpenAI ve sporu s New York Times. • Trénink modelů je podle vlády transformativní, jde tedy o fair use. • V EU spor nic nezmění, máme vlastní pravidla a AI Akt.
Microsoft’s text suggestion feature will now be turned off by default in both Word and Outlook, reports The Register. The text suggestions attempt to predict which words or phrases the user intends to type in advance.
According to Microsoft, some users appreciate the feature, while others find the suggestions distracting. With it disabled by default, interested users can now choose for themselves whether they want to turn it on manually.
It is unclear whether the change will disable text suggestions for existing users who already have the feature enabled, or if it applies only to new installations and profiles.
The change applies to Word for Windows, the web, iOS, and Android, and to classic Outlook for Windows and Outlook for Mac. Rollout timing will be communicated through the Microsoft 365 admin center and release notes, Microsoft said.
This article originally appeared on Computer Sweden.
Related:
A serious vulnerability was recently discovered in Exchange Server 2016, Exchange Server 2016, and Exchange Server Subscription Edition (SE). The vulnerability is designated CVE-2026-62911 and can be exploited by hackers to gain full access to affected systems, according to Bleeping Computer.
Microsoft has released security patches to address the vulnerability as part of its August 2026 Patch Tuesday release, but there are still 21,899 unpatched servers at risk, according to The Shadowserver Foundation. The highest concentrations of vulnerable servers are in the US and Germany, the security group said.
The Netherlands National Cyber Security Centre and other agencies have urged admins to install the latest patches as soon as possible.
This article originally appeared on Computer Sweden.
Related:
Microsoft a Meta jsou obří firmy s mnohamiliardovými zisky, které každoročně výrazným tempem rostou. Přesto odmítají investovat do vývoje nativních programů pro Windows a náklady přenášejí na uživatele. Peníze jsou opět jen na prvním místě.
Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version.
The Nexus vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), is
Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version.
The Nexus vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), isSwati Khandelwalhttp://www.blogger.com/profile/ [email protected]
Oživeno 3. září | Tohoto „kolonožce“ jsme poprvé viděli v lednu v Americe (info níže), teď si odbyl evropskou premiéru. Lačně jsem odroloval na konec tiskové zprávy, abych zjistil cenu a datum uvedení na trh, ale na tyto informace je stále příliš brzy.
„Evropská premiéra“ v tomto případě znamená ...
Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts.
"Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial
|