Agregátor RSS

Citrix buys company that containerizes Windows desktop apps independently of the OS

Computerworld.com [Hacking News] - 2 Září, 2026 - 02:47

Citrix on Tuesday announced that it has completed the acquisition of longtime partner Numecent, producer of technology that containerizes and manages Windows applications.

The acquisition builds on joint efforts to integrate Numecent’s management tool, Cloudpager, with Citrix Desktop-as-a-Service (DaaS) after an integration announced in April let administrators natively publish and manage the application containers through familiar Citrix workflows.

Numecent’s other product, Cloudpaging, packages Windows applications into isolated application containers independent of the underlying operating system, streaming them to Windows endpoints on demand rather than requiring them to be included in a desktop image. 

Citrix plans to further integrate the technology into its platform, while also continuing Cloudpaging and Cloudpager support for physical Windows devices.

“Enterprise customers have told us for years that application management is one of the most painful parts of running a Windows environment,” said Shawn Bass, SVP and GM of Citrix DaaS, in the announcement of the acquisition. “Numecent has solved this in a genuinely elegant way. By bringing Cloudpaging and Cloudpager into Citrix, we can make this capability native to every DaaS and physical desktop deployment so IT teams get back the time they spend wrestling with images and app conflicts.”

Analysts and consultants said the move will help enterprise IT to some extent, but will also increase vendor lock-in with Citrix while potentially exposing enterprises to data security risks.

Good for Citrix customers

Gartner VP Analyst Stuart Downes said, “overall, this is a positive for Citrix customers,” but he stressed that the promised conversions “are not 100% compatible.” 

He said, “low-level integrations into the kernel are generally not successful” because code that needs the lowest level of OS integration usually needs direct links to the hardware. Still, he estimated that applications at the low level probably account for only 2% of enterprise applications. 

For the more typical apps, Downes said that there will likely be “north of 90% compatibility. It varies. There are quite a lot of complex factors in app virtualization.” But he emphasized that Numecent offers two components: Cloudpager and Cloudpaging, and “we have yet to see how Citrix will integrate both.”

Justin Greis, CEO of consulting firm Acceligence, also sees a lot of potential savings for the enterprise.

“Large companies can have thousands of Windows applications, including legacy, custom, industry-specific, and highly specialized applications,” he said. “Many have dependencies on particular versions of Windows, libraries, configurations, or desktop images. Every major desktop refresh, Windows migration, VDI program, cloud move, acquisition, or infrastructure modernization effort can therefore create another application testing and repackaging cycle. The ability to abstract more of the application layer from the environment underneath it can remove a meaningful amount of that friction.”

Noah Kenney, principal consultant at Digital 520, added that the theoretical advantage that Citrix can now offer has great enterprise potential.

But, he argued, this likely amounts to an enterprise IT pay less now, pay more later situation.

“There are operational savings here, which is why customers will adopt it, but the bill comes due when they try to leave,” Kenney said. “This is a good acquisition for Citrix and probably bad for enterprise leverage over time. Citrix can now lose the desktop and still keep the customer. Every application moved into Cloudpager raises the cost of the next migration. Customers get the simplification now and Citrix gets the switching cost later.”

Half right

Sanchit Vir Gogia, chief analyst at Greyhound Research, said that he reads the containerization pitch as half right. “The packaging premise is valid. The cross-operating-system execution premise is not,” he said.

Gogia pointed out that Numecent Cloudpaging packages a Windows application with its dependencies and streams it to a Cloudpaging Player on a physical or virtual Windows endpoint, where it executes locally. “A Mac or Linux user reaches that application through Citrix’s remote delivery, where it still executes on Windows. That is cross-platform access, not cross-platform execution,” he said. “A Windows application does not become a Mac application merely because its pixels arrive on a Mac. The container is a packaging promise and the boundary of that promise is Windows.”

That said, he noted that there is still a lot of value in the Citrix arrangement, because Cloudpaging separates an application from a particular Windows image and carries that package across physical and virtual Windows environments, including Arm-based devices. 

“The real advance is not escaping Windows,” Gogia explained. “It is making application change less dependent on desktop change. Microsoft’s own App Assure data puts enterprise application compatibility above 99.7%, and Cloudpaging’s commercial logic lives almost entirely inside the fraction that remains. At enterprise scale, the final 1% of applications can carry far more than 1% of the business risk.”

But, he added, “Existing Numecent customers need binding answers on entitlements, migration and exit. Citrix has bought control of a useful Windows application lifecycle. Control now has to prove itself, and the proof it owes customers is less complexity, not merely more control for Citrix.”

Possible risk

However, consultant Brian Levine, executive director of FormerGov, pointed out that the nature of these new Citrix capabilities could expose users to serious security issues, including the risk of data exfiltration. 

He sees Cloudpager as “essentially a privileged switch that can push software to every Windows endpoint at once, which is precisely the kind of mass-distribution channel that produced SolarWinds and Kaseya. Bolting it onto Citrix, whose NetScaler gear has been a favorite ransomware target through repeated ‘CitrixBleed’ flaws, may leave CIOs and organizations wondering who will focus on security for the combined entity, and how will it prevent the type of attacks we’ve seen against Citrix.”

Citrix was asked to comment on these security questions, but did not do so by publication time. 

Kategorie: Hacking & Security

[dos] EVerest 2025.9.0 - DoS

The Exploit Database - 2 Září, 2026 - 02:00
EVerest 2025.9.0 - DoS

[webapps] Bludit CMS 3.20.0 - Reflected Cross-Site Scripting

The Exploit Database - 2 Září, 2026 - 02:00
Bludit CMS 3.20.0 - Reflected Cross-Site Scripting

[webapps] PodcastGenerator 3.2.9 - Stored XSS

The Exploit Database - 2 Září, 2026 - 02:00
PodcastGenerator 3.2.9 - Stored XSS

[webapps] Ghost_CMS 6.19.0 - Remote Code Execution

The Exploit Database - 2 Září, 2026 - 02:00
Ghost_CMS 6.19.0 - Remote Code Execution

[webapps] Langflow 1.10.0 - RCE

The Exploit Database - 2 Září, 2026 - 02:00
Langflow 1.10.0 - RCE

[hardware] Fullhan FH8626V100 - Multiple Vulnerabilities

The Exploit Database - 2 Září, 2026 - 02:00
Fullhan FH8626V100 - Multiple Vulnerabilities

[webapps] Marimo 0.20.4 - RCE

The Exploit Database - 2 Září, 2026 - 02:00
Marimo 0.20.4 - RCE

Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes

The Register - Anti-Virus - 2 Září, 2026 - 01:54
International law enforcement agencies, working with CrowdStrike and Shadowserver Foundation, have disrupted Sality, a 23-year-old peer-to-peer botnet used to deliver malware to more than 15,000 machines worldwide. The botnet has operated since 2003 and distributed all types of malicious code to victims, spanning credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service (DDoS) attacks. For the past eight years, Sality’s primary payload has been EggJagger, a tool that monitors clipboards for cryptocurrency wallet addresses, then silently replaces them with attacker-controlled addresses. When a victim copies a bitcoin or ethereum address to make a payment, the malware redirects funds into the criminals’ wallets. CrowdStrike estimates Sality's operator stole at least $150,000 in cryptocurrency using EggJagger alone. On Monday, CrowdStrike's Counter Adversary Operations team, working with international law enforcement agencies and industry partners, disrupted Sality by executing a peer-to-peer sinkhole operation. This operation isolated infected machines, which broke the criminal operator’s ability to communicate with devices on its network. Once isolated, the bots can no longer receive payload download instructions or direct payload transfers, effectively breaking the botnet. “In practice, the operation targeted the data structure at the heart of every bot's network awareness: its peer list,” CrowdStrike Counter Adversary Operations team said in a technical writeup about the takedown. Each Sality bot maintains a list of known super peers – publicly reachable infected machines that form the backbone of the P2P network. Every 40 minutes, the bots check to see if their peers are still online. Peers that fail to respond are purged from the network. The counterattack took advantage of this by removing legitimate super peers in each bot’s peer list, continually isolating more infected machines in the network, and inserting purpose-built sinkhole entries into peer lists. That approach gave police and cyber operatives visibility into the operation’s progress and helped them notify victims. In addition to the sinkhole operation, the US Justice Department, FBI, and Department of Defense Office of Inspector General’s Defense Criminal Investigative Service seized Sality-linked domains in the US. Meanwhile, international law enforcement in Bulgaria, Hungary, and Romania took action against additional Sality-linked domains hosted in Europe. Meanwhile, the Shadowserver Foundation is working with internet service providers and Computer Security Incident Response Teams (CSIRTs) to identify infections and aid in victim notification and remediation.®
Kategorie: Viry a Červi

Content for Clicks: AI Is Tearing Up the Web’s Social Contract

Singularity HUB - 2 Září, 2026 - 01:37

As AI eats traffic, the best sites are locking it out, making reliable information harder to find.

For 30 years, the world wide web has run on a surprisingly profound social contract. Most sites are free for search engines to access, but if you use their content, you give credit by linking to the source.

Recently, that social contract has begun to collapse. Artificial intelligence tools are crawling sites not to link to them, but to train models and generate answers (which may or may not be accurate).

When you search for something, ChatGPT’s response or Google’s AI Overviews may still include links to sources, but they’re a kind of optional extra to the main answer.

This has triggered a bad dynamic for website owners, the public, and even AI companies themselves. As websites lose traffic (and revenue), many are beginning to block AI scraping tools, meaning AI results depend more on low-quality websites (many of which are also generated by AI). As a result, good information can be harder than ever to find.

How We Got Here

In the early days of the world wide web, search engines, and content creators came to an agreement about crawling (the practice of technologically examining a site to index it, so it can be served up in search results). Content creators would provide access to their sites for free and even allow search engines to reproduce small snippets of text.

In return, search engines provided links to the sites owned by content creators, who benefited from that web traffic. If content creators didn’t like the deal, they could prevent search engines from crawling their site with instructions in a file called robots.txt.

But if AI tools no longer provide web traffic, it cuts content creators out of the economic loop. There are also other costs associated with each visit to a website, so AI crawling can cost website providers money while not giving them any of the ad or other revenue that would come from human traffic. AI crawlers also crawl more deeply and more intensely than traditional web crawlers, magnifying that cost.

This change in traffic patterns isn’t a small or hypothetical problem. Cloudflare, a web hosting and service company that manages 30 percent or more of the top 10,000 sites on the internet, estimates over half of all web traffic is now AI bots.

Some of this will be AI agents supervised directly by people, but the majority will be crawlers. Site owners can use robots.txt to ask AI crawlers to stay off their sites—but some AI companies may ignore this polite request.

If the AI companies do honor the request, that can create a different problem. Sites containing misinformation are far less likely to ban AI crawlers, so the AI answers won’t be informed by high-quality sources.

What’s Happening in the Short Term

On the horizon is an event dubbed “Google Zero”—the day when through-traffic from Google drops to nothing. While some grey-haired diehards (like one of the authors of this piece) might still click through to verify AI answers, this traffic is rapidly dwindling, as a direct result of AI summaries.

A study of Wikipedia confirms this, showing that traffic in the English language version of the site dropped off quickly with the launch of AI summaries on Google in English, and that the same pattern occurred in other languages as AI summaries were rolled out. Never having to click through to get an answer might seem great for information seekers, but the reality is more complex.

Many sites are now blocking AI crawlers altogether. Site owners who decide to block AI crawlers are less likely to be linked in AI Overviews answers, even when the AI tool can still access the content to ground its answers (using a technique called retrieval-augmented generation).

Alternative “pay to crawl” models have been suggested as a way to compensate content creators, but haven’t gained traction.

Come September 15, Cloudflare sites will block AI crawlers by default on pages that contain advertising (and therefore make money for content creators).

This means up to 30 percent of the world’s top sites will no longer appear in Google AI Overviews summaries. It also means that much of what AI is being trained on will itself be AI-generated text.

What It Means for You

So what does this mean when you’re looking for information? The quality of AI summaries is likely to go down, at least in the short term, while the new economics of the web get sorted out.

This will happen for two reasons. The first is that high-quality content is less likely to go into those AI summaries—one recent study found that already, around 1 in 6 sources used by AI search tools is itself an AI-generated website.

The second reason is that, as AI models are trained on more AI text, their output may degrade (a phenomenon known as model collapse).

As a result, search engines that depend less on AI may become more reliable. The challenge is finding one that doesn’t use an AI-based crawler. They do exist. ZDNet recommends Mojeek, PCMag recommends Brave, and Ban the Bots lists several, including one specifically for “small producer” content such as blogs.

For now, whatever search engine you’re using, the best thing you can do is to scroll down and click on some actual search results. This benefits content creators and is also more likely to give you more accurate information.

This article is republished from The Conversation under a Creative Commons license. Read the original article.

The post Content for Clicks: AI Is Tearing Up the Web’s Social Contract appeared first on SingularityHub.

Kategorie: Transhumanismus

Pravidla pro podporu v nezaměstnanosti se asi opět změní. Chystanou novinku už teď mnozí kritizují

Lupa.cz - články - 2 Září, 2026 - 00:00
Podpora v nezaměstnanosti a podpora při rekvalifikaci se bude od příštího roku asi znovu měnit. Vláda protlačila úpravy bez připomínkování, řada lidí je kritizuje.
Kategorie: IT News

Rozvaha nad zálohováním dat v Linuxu a jejich rychlou plnou obnovou

ROOT.cz - 2 Září, 2026 - 00:00
Při konfiguraci domácího serveru s Debianem jsem narazil na otázku zálohování. Nestačí mi jen kopie souborů, chci vědět, jak celý systém obnovit po poškození disku nebo vlastní chybě při práci se systémem.
Kategorie: GNU/Linux & BSD

Softwarová sklizeň (2. 9. 2026): pořiďte si dlouhý rolovaný screenshot

ROOT.cz - 2 Září, 2026 - 00:00
Sesbíráme dlouhý screenshot z rolujícího okna, vypíšeme parametry počítače se žraločím ASCII artem, zabalíme adresář do samorozbalovacího archivu, vytáhneme z webové stránky článek bez balastu a nakonec vytvoříme strojový kód z koz.
Kategorie: GNU/Linux & BSD

Uživatelé si stěžují na blikání obrazovky s GeForce RTX s ovladači Nvidia 616.56

CD-R server - 2 Září, 2026 - 00:00
V diskuzích se po vydání ovladače Nvidia Game Ready Driver 616.56 začaly objevovat stížnosti na blikání obrazovky, zejména v souvislosti s použitím prohlížečů nebo přehráváním videa…
Kategorie: IT News

3D tištěné titanové konstrukce poprvé plavou a odolávají mořské vodě

OSEL.cz - 2 Září, 2026 - 00:00
Jako kachny na vodě. Nová mřížková konstrukce z titanu se vzpěrami vyplněnými polyuretanovou pěnou jako první známá kovová konstrukce tohoto typu plave. Tento metamateriál je podstatně pevnější než nerezová ocel o stejné hustotě nebo vysokohustotní plasty, které se běžně používají v mořské infrastruktuře.
Kategorie: Věda a technika

Another Artifactory CVE under attack by AI agents or humans

The Register - Anti-Virus - 1 Září, 2026 - 23:07
Security researchers reported that someone is exploiting CVE-2026-82329, a critical JFrog Artifactory authentication-bypass bug, just days after the vendor patched the 9.8-rated flaw. And we don't know if that someone is human. Artifactory is a widely used tool for managing software artifacts, packages, binaries, and AI models. It’s also popular with AI agents that go rogue and need to communicate with each other while remaining undetected by their human babysitters. In July, OpenAI and JFrog revealed that OpenAI’s models broke out of their cages to hack Hugging Face by exploiting Artifactory zero-days, and at Black Hat, the model provider said agents used Artifactory to build message boards and help each other access the open internet. JFrog disclosed CVE-2026-82329 on Friday, and by Tuesday, attackers had already begun exploiting internet-exposed systems, according to exposure-management biz watchTowr’s threat-intel team, which reported “attackers minting themselves admin tokens.” In addition to creating new administrative credentials, watchTowr’s honeypot network caught miscreants “enumerating users, groups, credential sets and federated access topologies,” Yordan Ganchev, principal threat intelligence specialist at watchTowr, told The Register. “Right now, we’re observing exploitation from a small number of IP addresses from varying geographies exploiting multiple of our honeypots,” Ganchev said. “Broad-scale scanning and mass exploitation has not been observed, but that is unlikely to stay the case for long.” Ganchev urged organizations running vulnerable versions to “urgently patch” internet-exposed systems, and treat them as being potentially compromised - so inspect audit logs, rotate credentials, and investigate connected systems for any unusual changes or backdoor implants. “When attackers gain admin level access to a central software supply chain system, they can do what every engineering team does best - build, ship and distribute software fast,” he said. “From there, they could tamper with build pipelines, move laterally into production systems and potentially push malicious changes downstream to customers.” JFrog did not immediately respond to The Register’s inquiries. We will update this story when we receive any response. ®
Kategorie: Viry a Červi

Hackers abuse Faronics Deploy admin tool to install ScreenConnect

Bleeping Computer - 1 Září, 2026 - 22:53
Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software. [...]
Kategorie: Hacking & Security

Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks

The Register - Anti-Virus - 1 Září, 2026 - 22:45
AI model testing organization METR has disclosed two attacks that happened earlier this year, including one in which an attacker stole an API key and spent three weeks consuming public-model credits worth about $600,000. METR (short for Model Evaluation and Threat Research) found no evidence that the attackers accessed sensitive information in either incident, and the org said it investigated both with security experts. METR researchers worked with OpenAI to investigate how its agents hacked Hugging Face, and on Monday, it disclosed two of its own security snafus. “In March 2026, attackers stole an API key for inference on public models and consumed a substantial amount of credits,” the nonprofit disclosed in a Monday report. “In May 2026, we observed attackers systematically probing our publicly accessible infrastructure, including an unsuccessful attempt to access internal data via an inadvertently exposed endpoint.” From fail-open bug to model-credit theft The March incident involved a METR researcher who didn’t have access to sensitive information - including model data and credentials, as well as information about model architectures, training, and release dates. The researcher used agents running on a personal EC2 instance that was “intentionally” left publicly accessible behind Google authentication. The instance contained an API key for METR’s public models account. According to METR’s account, a “vibe-coded app” included a fail-open bug that disabled authentication, and this exposed the system to the public internet for several days. “We suspect that the attacker found the instance by looking through recently-registered websites (e.g. in certificate transparency lists) to find vibe-coded sites with high-signal keywords relating to LLMs or agents, for purposes of harvesting potentially exposed model provider API keys,” the AI research org wrote. Once the attacker found the app, they prompted an agent to reveal its model provider API key, then added an SSH key to maintain persistent access, and over the next three weeks used the stolen credentials to consume API credits on public models worth about $600,000. Luckily for METR, the unnamed model developer had given the credits to the nonprofit for free. How do you not notice the 'large illicit usage?' METR does answer the question on everyone’s mind in the report: Why its researchers didn’t notice the “large illicit usage?” There are several reasons for this. First, the model testing operation regularly runs evaluations that use a lot of tokens, and this means the organization is “very acclimated to getting lots of weird rate limit and API errors.” So the high usage didn’t look that out of the ordinary. Plus, since the tokens were free, METR didn’t accrue a large bill, and at the time there was no way to put a spending limit on keys like the one that was stolen. In response to the March incident, METR says it improved its security infrastructure, protocols, and review process, and will continue to invest in security. To this end, it also hired a security lead, and plans to add more security staff. Crims used agents to try to access frontier models The second incident happened in early May, when “METR became the target of a sustained external attack campaign.” After being “tipped off” that attackers who appeared financially motivated may have been trying to gain illicit access to frontier models, METR watched the intruders probe its publicly accessible infrastructure. They also used agents to find ways to gain initial access, including automated vulnerability discovery, credential stuffing against authentication providers, attempting OAuth token grants, scanning newly deployed services, and phishing attempts. At the same time, METR unintentionally “exposed a read-only SQL query mechanism via our public transcript viewer.” While queries were scoped to public data by default, a bug allowed access to unpublished evaluation data, and “some sensitive model data was accidentally included in this database.” However, there’s no evidence that the attacker found the exploit or accessed any non-public data, according to the model testing body. An independent bug hunter discovered the vulnerability and reported it to METR, which paid the researcher a bounty, and took the API offline. In response, METR says it now uses an isolated production environment for public-facing applications that is separate from its internal infrastructure.®
Kategorie: Viry a Červi

Firefox helps iPhone users bypass ads on web sites while making money showing its own ads

The Register - Anti-Virus - 1 Září, 2026 - 22:17
After several weeks of anticipation, Mozilla has started rolling out ad blocking to the iOS version of its popular browser, but you can still expect to see ads on Mozilla's own pages, including the new tab page. The org officially rolled out the new native ad blocking feature for iOS Firefox on Tuesday, moving it out of the experimental phase, while explaining that it had to rethink its desire to give users control over their web experience on iOS due to differences in architecture between it and other OSes. “Firefox already supports a strong ecosystem of ad-blocking and privacy extensions,” Mozilla explained. iOS works differently, though, as Apple forces all web browsers on iOS to use its own WebKit to render sites instead of their own preferred back end. “Bringing ad blocking to Firefox on iOS,” therefore, “meant building it directly into the browser,” Mozilla explained. Implementing ad blocking in the iOS version of Firefox meant incorporating Apple’s own WebKit Content Blockers. According to Apple’s introduction on the topic, it specifically doesn’t want app extensions to be used to block web content because of how they operate. “App extensions … are essentially little sandboxed applications that are launched on demand to extend some specific piece of functionality,” Apple notes. “JavaScript-based content blocking extensions … have significant performance drawbacks.” Apple complains that traditional ad blockers use too much energy, increase page load time, and eat up memory, all of which it wants to protect iOS users from. Apple describes WebKit Content Blocking as “describing content blocking rules in a structured format ahead-of-time, declaratively.” Apple Web Content Blockers instead live in bytecode format that executes for each resource request, modifying requests or injecting CSS changes as needed while pages are loaded. For Mozilla, that basically means dropping the EasyList filter, originally designed for the classic Adblock blocker, into a JSON file and passing it to WebKit. Easy peasy. Ad blocking in Firefox for iOS is off by default. Turning it on, if it’s available for you – it’s rolling out gradually – is as easy as opening the in-app settings menu, tapping on Browsing, and toggling the Ad Blocker field on. Mozilla told The Register in an email that it doesn't have a timeline for general release to all Firefox users on iOS, which it said will largely depend on how well the initial rollout goes. You also have to turn Remote Improvements on, as the feature allows Mozilla to push fixes and feature changes to Firefox between full releases. Toggling that on has traditionally meant you also had to allow Mozilla to collect browser telemetry, but that was changed in February when Firefox 148 was released and the two features have officially been decoupled. Once on, iOS Firefox Adblocking will take care of ad-related trackers, ads from third-party advertising networks, third-party ads served by websites, and popups/overlays. What it won’t do, however, is take care of ads on search result pages or sponsored content on Firefox’s home or new tab page – after all, you wouldn’t want Mozilla to lose those precious ad bucks, would you? Firefox iOS ad blocking also won’t eliminate ads served directly by websites, and the company warns that it still might not work in all places, which is pretty common for ad blockers. For Firefox users who want browser consistency across platforms, it’s likely a welcomed announcement, though it begs the question whether Mozilla is considering integrating its own ad blocking technology in the desktop or Android versions of its browser. Fortunately for those making ad-blocking extensions, and those who love them, Mozilla says it has no plans to expand built-in adblocking outside iOS. "We value that ecosystem and will continue to support it," Mozilla told us. ®
Kategorie: Viry a Červi

Aesto Health says data breach affects over 9.5 million patients

Bleeping Computer - 1 Září, 2026 - 21:28
Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals. [...]
Kategorie: Hacking & Security
Syndikovat obsah