Agregátor RSS
Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts.
"Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercialSwati Khandelwalhttp://www.blogger.com/profile/ [email protected]
I’ve been writing about Apple and how it benefits the enterprise for so long it’s easy to forget that the company doesn’t make enough noise about its accomplishments.
Sure, it has pursued and won the argument about Total Cost of Ownership, proving that while initial costs might be higher, dollar for dollar Macs are a far more cost-efficient platform, particularly when it comes to product reliability and tech support.
Apple already offers so much
Apple has also introduced extensive tools and APIs to help manage enterprise Macs, spawning a wide ecosystem of providers — most visibly, Jamf. Certain Apple products are already becoming deeply ingrained in some key professions; just think about Vision Pro and what it offers in medical care or prototype design, or the tens of thousands of Macs being carried around by AI developers across all the big name firms.
Some of what Apple delivers is already of major benefit to enterprise users. MLX for example, is being actively used to support real-life AI implementations, including by active AI-based businesses such as Yembo. And simplicity and ease-of-use isn’t just an advantage to consumer users, it boosts productivity in enterprise, too.
Almost 10 years ago, the focus was all about mobile enterprise, something that hasn’t gone away. Indeed, it is arguable that with Siri AI and third-party AI partners, Apple’s mobile enterprise story has become even more compelling. All the same, even then it was crystal clear that Macs had a big part to play in the future of enterprise tech. The iPhone accounted for 72% of all enterprise smartphone activations back then, while Jamf data has consistently shown us the steady forward momentum Mac has in business.
So why hide the light?
As former Apple Enterprise Marketing Manager Todd Dailey points out, Apple does have some people it trusts to tell its business and enterprise stories. But it isn’t investing very much in making sure they have stories to tell. For example, he notes just one enterprise-related story on the Apple website. Published in Chinese only, that story is about Haidilao, which is seeing serious TCO and energy consumption benefits by running its back-end operations on Mac minis.
He also points to a near-mythical Apple-in-business event the company ran in Cupertino last June. That event generated almost no coverage anywhere, because no one was there to report on it. And yet it gathered leaders from Disney, Ford, Anthropic, Perplexity, Christie’s and presumably elsewhere to talk about how they use Macs in business, many with a focus on enterprise AI. I’ve spent time trying to track down additional information from that event, but there is not much out there. And while I’m willing to accept that some of those who took part needed business confidentiality, it was a semi-public event, so it seems unlikely significant secrets would have slipped out.
It feels like a lost opportunity. Imagine the follow-up if Apple had paid a media team to attend the event to churn out stories, develop case studies, shoot video, and make viral influencer tik-toks. Is it that Apple doesn’t believe in its own enterprise offer? I don’t think so. It has a small army of business experts available to customers in stores, and they wouldn’t be there if it didn’t see a need for them.
Overcome myopia
Dailey thinks it’s a disconnect generated by Apple’s traditional focus on consumer markets. He’s probably correct, but it is frustrating; the real value Apple offers enterprise IT has been crystal clear for years – certainly since before then-Apple CFO Luca Maestri declared that Apple had set a new enterprise revenue record back in 2017. “Corporate buyers reported a 96% satisfaction rate and a purchase intent of 68% for the June quarter,” said Maestri at that time.
With that kind of momentum across such an extensive length of time, the company has without doubt built strong foundations of enterprise success. But these emerge most frequently as short footnotes in CFO statements during fiscal calls, rather than being shouted from the rooftops.
Here are some details
Highlights announced during those calls since 2024 include:
- Nvidia launched a Mac-as-choice program with more than 10,000 Macs deployed worldwide.
- UC-San Diego Health became the first hospital in the world to test Vision Pro spatial-computing apps in clinical surgical trials.
- BMW Group deployed tens of thousands of iPhones, including to factory employees.
- Capital One expanded its “Mac Choice” program with thousands more MacBook Airs.
- Crédit Agricole (France’s leading retail bank) turned to on-device AI on the MacBook Pro to cut regulatory-workflow processing time by more than 80%.
- Perplexity selected the Mac as its preferred platform for building enterprise-grade AI agents.
Apple knows these wins exist, and recently launched Apple Business, the all-in-one platform that combines hardware, software, and enterprise services to manage large-scale deployments. This showed the company knows what’s going on.
Mac does AI
Follow the money and it feels as if the next stage of the Apple-in-the-enterprise journey will at least in part be built around AI; Apple has major advantages it should celebrate with the sector. It offers the best systems for on-device AI, use and development. MLX is unique, ahead of its time, and worth leaning into. Its commitment to privacy is becoming increasingly and recognizably important to enterprise professionals. Even its battles to protect encryption are fundamental to business success.
Lots of its customers, not just Perplexity or Crédit Agricole, already see the advantages.
The successes it already has should be celebrated on the company’s own enterprise websites, and the company should recognize and invest in those stories and share them. Dailey points out that developers at Nvidia, Anthropic, OpenAI, and most enterprise AI shops all already use MacBook Pros for portable AI, suggesting a campaign around “Mac Does AI” should be in place. I see his point. I hope Apple does.
Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, and follow me on BlueSky, LinkedIn, or Mastodon.
Microsoft says a known issue that reverts mouse settings after installing the KB5120998 August 2026 preview update affects only non-English Windows 11 systems. [...]
ChatGPT and Codex are experiencing a major outage, with users reporting errors across nearly every major ChatGPT feature. [...]
Claude is experiencing an outage, with users encountering elevated errors when sending requests to multiple Anthropic AI models. [...]
A decade or two ago, board executives asked "why should I care about cybersecurity?" Five years ago, they were asking "Are you patching our software vulnerabilities?" Now, they're starting to ask: "Are we actually secure?" They might want a simple 'yes' or 'no' initially, but eventually they'll say the most dreaded thing of all, and it'll be a demand, not a question: "Prove it". Traditional vulnerability management and patching, won't survive that conversation. It's why a relatively new approach is gaining traction: Continuous Threat Exposure Management (CTEM). What's wrong with vulnerability management We define security flaws using Common Vulnerabilities and Exposures (CVEs), and we tell each other how bad they are by assigning the Common Vulnerability Scoring System (CVSS) to them. There are three problems with that. There's a firehose of CVEs, the CVSS scores aren't helpful when triaging them, and AI is about to make the whole thing much worse. CISOs are drowning in CVEs. The industry has spent decades creating tools that churn out vulnerability data and others that consume it. Few if any tell you which vulnerabilities an attacker could use to hurt you in your environment. The volume of CVEs is making traditional vulnerability management (patch it and forget it) less tractable every year, says Drew Vanover, principal security strategist at Horizon3. "Think about the last patch release that Microsoft put out," he says. "There were over 500 fixes in one patch cycle. That is incomprehensible. Nobody is going to be able to go through, vet, prioritize, and deploy all of those in a way that is truly considered safe." The number of CVEs created each year has been soaring, putting more pressure on the US’ National Institute for Standards and Technology's National Vulnerability Database, which has now been backlogged for years. NIST threw up its hands in April and effectively declared CVE bankruptcy. The US Department of Commerce highlighted the second issue (that current severity metrics aren't useful) as part of a report this May. Aside from launching a zinger at the NIST by saying that the NVD was poorly managed, it also suggested that it stop assigning CVSS scores altogether. These are highly subjective, it said. They also depend on exactly what the exposed system is doing in a particular organization's infrastructure. Is a critical severity score in a product important if only one sandboxed system ever interacts with it? Or could an attacker chain three apparently innocuous vulns to cause damage that a business executive would care about? AI will make vulnerability management harder These complex problems are a headache, but AI is about to turn it into a full-on migraine. Frontier LLMs like Claude's Mythos are already surfacing zero-days at scale, heralding a flood of CVEs. They don't just find bugs at scale; they also work much more quickly than their human counterparts to create and weaponize exploits. This makes it even more important that organizations patch the right bugs quickly. The Cloud Security Alliance now describes an asymmetric vulnerability cycle in which attackers can use AI to discover and exploit vulnerabilities more quickly, (increasingly before patches are even released), while organizations are taking longer to patch them. What is CTEM? Something has to change. Gartner figured this out in 2023, when it named CTEM a top cybersecurity trend. This is a way of staying on top of your vulnerabilities by triaging them properly. To do that, you have to go beyond the technical implications of a security flaw and understand what it really means for your business. Gartner lays out five steps to CTEM: ● Scoping Find the assets that carry significant business impact and prioritize them. ● Discovery Find how they're exposed by analyzing their weaknesses in depth. ● Prioritization Rank those exposures based on real business risk. ● Validation Test out the vulnerabilities to see if they're exploitable. ● Mobilization Fix them with a proper incident response plan. How automated pen testing helps manage vulnerabilities This approach promises to nail the security flaws that matter to an organization, but it's also more complex than traditional vulnerability management. It needs automation, which is what Horizon3 is providing with NodeZero. Scoping out systems is a commodity practice these days. So is discovery. Horizon3 is leaving those to partners so it can focus on the parts of the CTEM framework that aren't yet easy for customers to solve. Those are prioritization by business impact, and mobilization. NodeZero runs penetration tests across an organization's infrastructure and documents the exploitable paths with evidence a defender can follow. The output is the wheat sifted from the chaff; a shorter list of exposures that security teams and developers can focus on. The impressive part here is the chain-of-attack behavior. NodeZero probes for weaknesses, exploits them, and then pivots based on what it finds. This means it adapts to the environment to extend its attack, just as a real attacker adapts attacks and moves laterally through systems. This approach is based on a deterministic machine learning expert system rather than a general LLM, explains Vanover. "A good analogy is to think about the medical profession," he says. "A GP is your general LLM trying to cover everything. They know a little bit about a lot, but they aren't the experts, and that's where you start having hallucinations and guesses and misses." The company only uses generative AI for specific tasks. Using it to parse a two petabyte S3 blob looking for sensitive data or identifying high-value credentials, with data staying inside the customer's boundary via AWS Bedrock, for example. What it doesn't do is run amok spawning rogue agents in your system. Vanover says the value here is in proving that you've clobbered load-bearing security bugs. "If we say that we can exploit something, it's because we did, and we'll show you the proof in the platform," he says. The next step is closing the loop by retesting the exploit after it's been dealt with. Teams get to close tickets because NodeZero can no longer traverse the attack path. That is a testable definition of "fixed" and one that translates into a risk metric a CFO can read. Horizon3 also wants to solve customers' tool sprawl problems with a single product that handles all of the heavy CTEM lifting. A common failure mode of enterprise CTEM programs is a stack of vendors whose handoffs create precisely the blind spots the framework was meant to eliminate. That disappears when it's all under one service. Is automated penetration testing safe? CISOs might be nervous letting an autonomous penetration testing system loose on production systems. It sounds like something that could break running processes. Why not just test against a digital twin instead? Testing in production is the safest way to find bugs, retorts Vanover. That's because environments drift frequently, especially in an agile world driven by short development sprints and automated changes to code. If a user changes a password or a team pushes a feature fragment, a digital twin system won't reflect reality. So Horizon3 focuses on strong production guardrails instead. "I don't need to ransom your system to prove to you that I can ransom it," Vanover says. "If I can get on the system, install a remote access tool, create a file, encrypt the file, and delete that file, I've just proven that I can ransom your system." He says Horizon3 has run more than 320,000 production tests across customer organizations. These include some that are especially nervous about what's poking around in their systems, such as the NSA and the largest medical records processor on the planet, along with a couple of large healthcare providers. Where can I start with CTEM? Gartner's CTEM framework is powerful, but it might also be daunting for CISOs. Vanover advises them to begin by picking one thing and doing it well. "No organization is going to implement CTEM in a year. That is a recipe for failure," he says. "Break it down. Look at places for the low-hanging fruit." You could do worse than look at what systems are actually reachable instead of blindly trusting an asset inventory that might be out of date. The race is on to embrace CTEM, because metrics like the number of patches applied won't satisfy the board for much longer. They don't describe how much exploitable surface still exists. The point of running the CTEM loop is to move reporting from activity to outcomes, so that the board gets to see fewer exploitable paths and a smaller blast radius. The new goal is to prove that a security control worked, not just that you paid for it. Want to operationalize CTEM but don’t know where to start? Check out this whitepaper from Horizon3 Sponsored by Horizon3
NVIDIA kupuje Hugging Face za 12,93 miliardy dolarů.
A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server. [...]
Acer má dlouhou tradici překonávání podobných milníků. Právě před deseti lety na IFA představil Acer Swift 7, první notebook pod 1 cm. No a o rok později to byl Acer Swift 5, který se zase jako první dostal pod 1 kg. V roce 2019 pak konkurenční Asus představil notebook AsusPro B9, který se dostal ...
Thomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada.
West Publishing said it discovered the activity on June 30, 2026. A subset of court records could contain individuals' names
Thomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada.
West Publishing said it discovered the activity on June 30, 2026. A subset of court records could contain individuals' namesSwati Khandelwalhttp://www.blogger.com/profile/ [email protected]
Infostealers can expose far more than passwords, including authenticated sessions that may let attackers bypass MFA. Flare explains how defenders can prioritize compromised identities, determine whether stolen access is still usable, and respond before it leads to account takeover. [...]
Předobjednat si lze nový jednodeskový počítač Arduino VENTUNO Q s předinstalovaným Ubuntu. S 16 GB LPDDR5 a 64 GB eMMC. Pro lokální LLM, agentní AI, počítačové vidění, robotiku…
Vodní nádrž Orlík dnes dopoledne dosáhla historického minima, když její hladina klesla na 334,91 m n. m. Tak nízko byla podle dostupných informací naposledy v 70. letech minulého století během konstrukčních úprav. A pak už jen při vlastním napouštění.
Pokud hladina dále klesne na 334,6 m n. m., ...
Virtualizor has confirmed that a BGP hijack redirected traffic for part of its update infrastructure and allowed an attacker-controlled server to deliver a malicious update package to a small number of installations. The company disclosed the incident on August 31, 2026, after the routing diversion ran across two periods between August 28 and August 30.
A Linux host intrusion prevention system can fail even when the protected server still has spare CPU. If its logging path cannot record and move events as quickly as an attacker creates them, the control loses the evidence it needs to block the source.
A Linux kernel patch series submitted on Sep 1, 2026, stops an out-of-service Logical Link Control socket from indexing below two connection-state tables. The bug produced Kernel Address Sanitizer and Undefined Behavior Sanitizer reports for a global out-of-bounds read.
Staronová mobilní aplikace EZKarta, která vznikla z Tečky, dostává zásadní aktualizaci • V nové verzi 5.0 ukáže výsledky preventivních vyšetření i posudky pro řidičák • Namísto rodného čísla nabízí QR kód, na integraci eReceptů se ale stále čeká
Cybercriminals have reeled in password hashes and corresponding salts belonging to users of popular fishing app Fishbrain, opening the door to cracking attempts. Fishbrain AB, which says its eponymous app serves more than 20 million anglers, disclosed the August 19 breach to the California Attorney General's Office this week. The unknown perpetrators helped themselves to a trawl of user data, including names, dates of birth, email addresses, phone numbers, Fishbrain usernames, country information, password hashes, and salts. "Fishbrain passwords were not stored in plaintext; however, Fishbrain has determined that the compromised password hashes for some users may be susceptible to being decoded," the company said in its disclosure [PDF]. It added: "If you use your Fishbrain password for any other online accounts, you should promptly update those passwords and any associated security questions or answers. "You should also take other appropriate steps to protect any online accounts that use the same username or email address and password combination. We recommend using a strong, unique password for each of your accounts." With the hashes and salts in hand, attackers can make password guesses using their own hardware until they potentially recover the original credentials. Whether those attempts succeed depends on the strength of each password and the hashing algorithm Fishbrain used, which the company did not disclose. Fishbrain did not comment on the scale of the breach or how many of its claimed 20 million-plus users were affected. The Register asked Fishbrain for more information. After discovering the intrusion and conducting an initial forensic investigation, Fishbrain patched the vulnerability and reset every user's password. Customers must create a new one the next time they log in. Fishbrain also said it "restricted access to the affected environment," strengthened its security controls, and initiated "a broader review of our data security measures" while the investigation continues. Fisherfolk should also keep an eye out for phisherfolk using the stolen personal data to bait follow-on attacks. ®
A Linux server can be carefully hardened before it reaches production and still become less secure over time. Hardening means reducing unnecessary services, accounts, permissions, and other ways into the system. That work matters, but it describes the server at one point in time. Six months later, a new application may be installed, a firewall port opened for troubleshooting, an administrator given sudo access to run commands with elevated privileges, or a software update may have changed a c...
|