Agregátor RSS
Lidlovská chytrá zásuvka zlevnila na 200 Kč. Podporuje Matter, měří spotřebu a nemusíte platit za dopravu
Lidlovská chytrá zásuvka Silvercrest s podporou protokolu Matter zlevnila o polovinu. • Dnes ji navíc můžete koupit d bezplatnou dopravou. • Připojuje se přes Wi-Fi a umí měřit i spotřebu.
Kategorie: IT News
Terminated employee cost company hundreds of thousands of dollars because nobody revoked access
PWNED Welcome back to PWNED, where we talk about organizations that are independently self-owned. This week’s tale of toxic tech involves a disgruntled ex-employee who had the means and opportunity to wreak havoc. Our story comes courtesy of Yad Senapathy, who serves as CEO of the Project Management Training Institute in Dallas, Texas. He recalls a time many years ago when he used to work in IT at a company with more than 1,000 employees. While Senapathy was working there, the company terminated an employee, but nobody cut off his access to internal systems. The angry worker logged back in, then deleted files, locked out other people's accounts, and even corrupted a database. "Several days passed where the person was no longer on payroll, but their credentials were still active," Senapathy said. "Nobody had been clearly assigned to shut them off. HR thought IT would handle it once the termination was processed. IT was waiting for HR to send a formal request. I've learned that when nobody is clearly responsible and there is no set deadline, these things can easily get missed until there is already a problem." This lapse in responsibility meant the terminated employee had access to shared admin credentials, account controls, and project tracking systems. Each of these, in turn, granted permission to other systems, leading to a domino effect of inappropriate access, which the former worker used to wreak revenge on the whole organization. According to Senapathy, the damage amounted to hundreds of thousands of dollars. Just as bad were the weeks of delay added to an important project. As an added irony, recovery was particularly difficult because the systems were damaged by the very person who best knew how to repair them. “The employee wasn't some genius hacker. They just still had access after they left and nobody changed the credentials or reviewed admin rights,” Senapathy told The Register. “We'd let one person collect so much system knowledge that shutting the door behind them took longer than it should have.” Senapathy recommends that offboarding checklists and access reviews should be right next to “return the laptop” on that list. The problem in this case is that the terminated employee had more access than most people, and so IT didn't know what they needed to cut off. “Sadly, it could've been prevented by same-day deletion of access, forced re-review of shared account access and zero tolerance for one person owning a whole system alone,” he said. This writer can identify with this situation. At a previous job, after I quit, I lost email, chat, and shared drive access, but months later my former boss asked if I could still log into an important database that was hosted externally and show him how to use it. I had no problems getting in. Have a story about someone leaving a gaping hole in their network? Share it with us at [email protected]. Anonymity is available upon request.®
Kategorie: Viry a Červi
Přehled fotoaparátů pro instantní fotografii. Jsou trochu magické, docela drahé a vlastně zbytečné
Existují technologie, které posunou kvalitu, a pak takové, které změní způsob, jak o fotografii přemýšlíme. Dvě značky stojící za instantní fotografií – Polaroid a Instax – patří do té druhé skupiny.
Kategorie: IT News
To keep the AI hacking genie bottled up, try one-way networks
To prevent frontier AI models breaking out of test environments and collaborating to hack other companies, we may have to rethink the network architectures used for model training. Eli-Shaoul Khedouri, CEO of Intuition Machines, argues that past work in the defense and intelligence communities shows the way forward. Rogue AI models rise from the level of developer regret to mass threat when they gain access to the internet, something that defenses erected by OpenAI and its partners tried but failed to prevent. Pointing to a post published by his company's hCaptcha service, Khedouri argues that technology like data diodes – hardware that enforces a one-way flow of information on a network – can be deployed to prevent security incidents like OpenAI's hack of Hugging Face. The hCaptcha team points to the use of data diodes as a data transit mechanism at a sensitive compartmented information facility (SCIF), an environment implemented in classified settings. "They allow files, logs, or telemetry to enter or exit the SCIF's classified network to an unclassified network and provide a way to prove e.g. that logs from a training run can only flow one way," the hCaptcha team explains, adding that such technology fits with the Bell-LaPadula security architecture designed for the US Defense Department. A basic implementation would involve two machines connected via network cards linked by one-way optical fiber – and without a data path back to the model. Training and reinforcement learning could run in an isolated zone with no internet access and an optical ingress diode would grant access only to vetted artifacts. The hCaptcha researchers suggest a second diode to send telemetry to a sel4 receiver and scrubber, while a separate out-of-band network manages the cluster. This sort of scheme would require immutable snapshots of software registries like PyPI, GitHub, npm, and might also need mocked versions of various web services and APIs . This would come at a cost, and would require implementation time that frontier AI labs may not be prepared to spend at the moment. "The systems described are widely deployed in high assurance domains, and the components are commercially available," Khedouri told The Register. "However, they have not been adopted by frontier labs to date." He pointed to NIST and DOD guidelines [PDF] that suggest an overhead of 10 to 20 percent for applying formal specifications and system architecture. "We estimate total cost overhead for high assurance training clusters at less than five percent per gigawatt, but in practice the speed at which frontier labs are moving is a greater impediment than cost," Khedouri said. The current commercial environment, he said, would make it difficult for any one AI lab to delay its training to build and test effective safeguards, particularly if their competitors might not do the same. "In practice, the cost of high assurance on the systems side would be a small fraction of what OpenAI is now spending on the new monitoring, chain-of-thought oversight, and safety safeguards they introduced after their models hacked HuggingFace," he said. While Khedouri is focused primarily on convincing frontier labs to implement better training defenses, he said other organizations may want to consider similar network architecture. "This architecture is designed for entities training models with frontier cyber capabilities," he said. "Recently that has only included two companies. However, this is rapidly becoming relevant to smaller organizations and individuals who train models. "'Abliterated' open weight models with safeguards removed are readily available and now starting to approach the frontier in cyber abilities, and (reinforcement learning) RL post-training has become much more approachable in the past year." The goal of high assurance system design in the context of model training is to make unwanted action physically impossible, Khedouri said. "Attempting to monitor the behavior of an untrustworthy agent is an AGI-hard problem, as models have poor interpretability and this appears to be getting worse as their capabilities increase and they become more evaluation-aware," he said. "Hardware can provide limited guarantees like the direction in which data can be sent, but cannot solve the problem of untrustworthy models with the ability to reach the internet and find new exploits in their environment. "This is why combining physical one-way data flows (data diodes) and formal verification (to prove properties of the receiver) is much more effective than running a software sandbox on a host connected to the internet." hCaptcha is focused on fraud and abuse work and has no plan to offer a model-resistant training stack. Khedouri said he shared this advice in the hope it helps AI firms that don't have experience with high assurance system design. ®
Kategorie: Viry a Červi
Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a proof-of-concept (PoC) for a privilege escalation flaw impacting Crowdstrike Falcon.
"FalconFlank is a 0-day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor," the researcher said in
Kategorie: Hacking & Security
Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a proof-of-concept (PoC) for a privilege escalation flaw impacting Crowdstrike Falcon.
"FalconFlank is a 0-day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor," the researcher said in Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Technologie z Formule 1 míří do jaderné energetiky. Pomůže vyrábět elektřinu v mikroreaktorech
Firma Antares využije v mikroreaktorech elektroniku ze závodních monopostů • Osvědčená automobilová technologie zrychlí vývoj a ušetří finanční prostředky • Kompaktní reaktory začnou dodávat elektřinu pro vojenské základny v roce 2028
Kategorie: IT News
AMD: Hybrid bonding může až 17× zvýšit energetickou efektivitu oproti HBM
Hybrid bonding, technologie, se kterou má AMD více než šestileté zkušenosti v souvislosti s V-cache, by mohla významným způsobem posunout energetickou stránku pamětí - i o řád oproti HBM…
Kategorie: IT News
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers' crosshairs.
The vulnerabilities are as follows -
CVE-2026-83548 (CVSS score: 10.0) - A server-side request forgery vulnerability in SonicWall SMA 1000 Appliances that could allow a remote unauthenticated
Kategorie: Hacking & Security
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers' crosshairs.
The vulnerabilities are as follows -
CVE-2026-83548 (CVSS score: 10.0) - A server-side request forgery vulnerability in SonicWall SMA 1000 Appliances that could allow a remote [email protected]
Kategorie: Hacking & Security
[webapps] FreePBX 17.0.2 - Remote Code Execution (RCE)
FreePBX 17.0.2 - Remote Code Execution (RCE)
Kategorie: Security Vulnerabilities & Exploits
[webapps] Metabase 0.61.0 - Authenticated Remote Code Execution
Metabase 0.61.0 - Authenticated Remote Code Execution
Kategorie: Security Vulnerabilities & Exploits
CERN přechází na Debian
CERN dlouhodobě používal vlastní sestavení RHEL, ze kterého přešel na CentOS Stream. Federico Vaga a Nikos Tsipinakis ale nyní v přednášce na MiniDebConf Winterthur 2026 popisují plán probíhajícího přechodu na Debian pro řízení akcelerátorů. Důvodem k opuštění CentOS Stream jsou zachování zpětné kompatibility se starším hardwarem, kterou Red Hat narušuje, když tlačí sestavení balíčků pro novější verze architektury (x86-64), a nedostatečné nástroje pro sestavování vlastních balíčků a repozitářů.
Kategorie: GNU/Linux & BSD
Why Patched Linux Servers Still Fail a Penetration Test
A patched Linux server can still fail a penetration test because patch status cannot show whether an attack path remains open.
Kategorie: Hacking & Security
UZDoom 5.0.0
UZDoom (Wikipedie), tj. fork GZDoom, byl vydán ve verzi 5.0.0. Videopředstavení na YouTube. Podrobný přehled novinek v Changelogu.
Kategorie: GNU/Linux & BSD
How to Prevent DNS Leaks and Secure Proxy Credentials on Linux Systems
Using a proxy on Linux changes how web traffic reaches its destination, but it does not automatically protect every part of the connection. DNS requests may still leave through the system’s normal resolver, while proxy usernames and passwords can remain exposed in scripts or local files.
Kategorie: Hacking & Security
Spoření v září: Kam bezpečně s penězi? Přehled všech nabídek na trhu
Několik produktových novinek vám umožní získat úrokovou sazbu přes 4 % p.a. U některých nemusíte udělat skoro nic, u dalších se vyžaduje tzv. aktivní klient. Tak či onak, úrokové sazby spoření od 4 % p.a. jsou už zase standardem.
Kategorie: IT News
Automatické ostření s AI v roce 2026: výhoda bezzrcadlovek a hranice zrcadlovek
Autofokus kdysi býval hlavně mechanickou disciplínou. Později do hry vstoupila matematika, tabulky kontrastu a fázová srovnání. V roce 2026 je ale ostření především soutěží ve strojovém učení.
Kategorie: GNU/Linux & BSD
Hardcore vývoj a ladění programů pro osmibitová Atari s využitím Turbo Monitoru a tabulky instrukcí
Programy pro osmibitová Atari není nutné vyvíjet pouze s využitím plnohodnotných assemblerů. Použít lze i monitory, například tuzemský Turbo Monitor, s nímž se dnes seznámíme. V Turbo monitoru lze provádět ladění, úpravy her (nekonečný počet životů) atd.
Kategorie: GNU/Linux & BSD
Intel: Výtěžnost procesu 14A roste nejrychleji za posledních 15 let!
Zdá se, že proces Intel 18A je minulostí a krom již vydaného mobilního procesoru Panther Lake na něm nevznikne žádný další zásadní produkt. Intel tak upírá pozornost k procesu 14A…
Kategorie: IT News
- « první
- ‹ předchozí
- …
- 45
- 46
- 47
- 48
- 49
- 50
- 51
- 52
- 53
- …
- následující ›
- poslední »



