Agregátor RSS

Microsoft fixes Windows 10 bug causing apps to stop working

Bleeping Computer - 31 Říjen, 2024 - 15:40
Microsoft has fixed a known issue that prevents some apps launched from non-admin accounts from starting on Windows 10 22H2 systems after installing the September preview cumulative update. [...]
Kategorie: Hacking & Security

LottieFiles Issues Warning About Compromised "lottie-player" npm Package

The Hacker News - 31 Říjen, 2024 - 15:16
LottieFiles has revealed that its npm package "lottie-player" was compromised as part of a supply chain attack, prompting it to release an updated version of the library. "On October 30th ~6:20 PM UTC - LottieFiles were notified that our popular open source npm package for the web player @lottiefiles/lottie-player had unauthorized new versions pushed with malicious code," the company said in a
Kategorie: Hacking & Security

LottieFiles Issues Warning About Compromised "lottie-player" npm Package

The Hacker News - 31 Říjen, 2024 - 15:16
LottieFiles has revealed that its npm package "lottie-player" was compromised as part of a supply chain attack, prompting it to release an updated version of the library. "On October 30th ~6:20 PM UTC - LottieFiles were notified that our popular open source npm package for the web player @lottiefiles/lottie-player had unauthorized new versions pushed with malicious code," the company said in a Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Konference OpenAlt 2024 již tento víkend v Brně

AbcLinuxu [zprávičky] - 31 Říjen, 2024 - 14:52
Konference OpenAlt 2024 proběhne již tento víkend 2. a 3. listopadu v prostorách FIT VUT v Brně. Začíná ale už v pátek na warm-up party ve Studentském klubu u Kachničky v 17:00. Pokud jste ještě areál FITu nenavštívili, k dispozici jsou pokyny k orientaci. Na programu je 54 přednášek a workshopů. Témata jsou od silně technických témat jako je třeba GCC nebo PostgreSQL po méně technické témata jako eGovernment, nebo třeba detailní analýzu problémů s Digitálním Stavebním Řízením. Vypíchnout lze přednášky linuxových distribucích Fedora Silverblue (Nerozbitný linux pro celou rodinu), openSUSE Leap, nebo Turris. Nesmí chybět témata jako kontejnery (Kubernetes) nebo umělá inteligence (velké jazykové modely). Už tradičně si můžete zkusit nakreslit mapu OpenStreetMap se zkušenými lektory od Missing Maps. Pro bastlíře je nachystaná například přednáška o chytré domácnosti Majordomus nebo o Linuxu v ledničce. S cílem přitáhnout mladší generaci představujeme studentskou sekci, kde jsou jednotlivé projekty dílem studentů (například v rámci jejich maturitních prací). Bude řeč i o výuce programování na základní škole, nebo výuce fyziky pomocí arduina "Physibox". Mimo hlavní program bude na chodbách spoustu stánků různých projektů jako je Fedora, openSUSE, Grafana. Stánek budou mít i radio amatéři a 3D tiskaři. Pro děti bude v sobotu nachystaný dětský koutek, kde si děti budou moci vyzkoušet různé hračky pro výuku programování. V neděli se dětský koutek promění v PlayZone od OMG Robotics. Sobotní odpoledne tradičně zakončíme posezením u lahodného moku ve studentském klubu u Kachničky. Budeme rádi, když myšlenky naší konference budete šířit a pozvete své kolegy a kamarády. Jak jistě víte, tak konference je primárně v češtině a vstup je zdarma. Pokud máte nějaké otázky, tak se zkuste podívat do FAQ nebo se zeptejte na Matrixu, Telegramu nebo emailem.
Kategorie: GNU/Linux & BSD

Nemáte zhlédnutí, nezasloužíte si kvalitu. Instagram snižuje rozlišení nepopulárních videí

Živě.cz - 31 Říjen, 2024 - 14:45
K praktice, která popudila řadu uživatelů, se přiznal šéf Instagramu Adam Mosseri. Obrázková sociální síť snižuje kvalitu videí, které nedostávají dostatečné množství zhlédnutí. Že to není zcela fér k malým tvůrcům? Mosseri to nerozporuje, podle něj je ale důležitější obsah, nikoliv rozlišení. ...
Kategorie: IT News

Over a thousand online shops hacked to show fake product listings

Bleeping Computer - 31 Říjen, 2024 - 14:00
A phishing campaign dubbed 'Phish n' Ships' has been underway since at least 2019, infecting over a thousand legitimate online stores to promote fake product listings for hard-to-find items. [...]
Kategorie: Hacking & Security

Přehrávání Netflixu ve 4K ve Firefoxu už nic nebrání. Verze 132 podporuje to správné DRM

Živě.cz - 31 Říjen, 2024 - 13:45
Mozilla si připravuje půdu pro filmy ve 4K . Streamovací služby ve webových prohlížečích běžně přehrávají video v rozlišení 720p až 1080p. Zatímco leckterá služba se neobtěžuje ani s plnohodnotným full HD, Netflix ho podporuje a v jednom případě dokonce přes prohlížeč servíruje 4K , resp. 2160p. ...
Kategorie: IT News

Tails 6.9

AbcLinuxu [zprávičky] - 31 Říjen, 2024 - 13:23
Byla vydána nová verze 6.9 živé linuxové distribuce Tails (The Amnesic Incognito Live System), jež klade důraz na ochranu soukromí uživatelů a anonymitu. Přehled změn v příslušném seznamu. Tor Browser byl povýšen na verzi 14.0.1. Tor client na verzi 0.4.8.13. Thunderbird na verzi 115.16.0.
Kategorie: GNU/Linux & BSD

LottieFiles supply chain attack exposes users to malicious crypto wallet drainer

The Register - Anti-Virus - 31 Říjen, 2024 - 12:55
A scary few Halloween hours for team behind hugely popular web plugin

LottieFiles is overcoming something of a Halloween fright after battling to regain control of a compromised developer account that was used to exploit users' crypto wallets.…

Kategorie: Viry a Červi

Halloweenská poklona legendě. Rivian se na jedno kliknutí převlékne za K.I.T.T. Ukázal se i David Hasselhoff

Živě.cz - 31 Říjen, 2024 - 12:45
Po softwarové stránce je to jen jednoduchý skin pro stávající infotainment a světelnou rampu na přídi, ale hlavní je tu nápad a jeho exekuce. Rivian pro letošní halloween připravil tři „kostýmy“ pro palubní systém elektromobilů R1T a R1S. [********************] [********************] Stačí ...
Kategorie: IT News

Syncthing pro Android končí

AbcLinuxu [zprávičky] - 31 Říjen, 2024 - 12:36
Vývojáři free a open source synchronizačního nástroje (a p2p náhrady Dropboxu) Syncthing oznámili, že z důvodu odporu ze strany Google Play ukončují podporu OS Android. Bohužel v rámci toho zmizí i vydání Syncthing na F-Droid, který má slabší uživatelskou základnu. Syncthing je na Androidu implementován formou wrapper aplikace, která spustí Syncthing démon, vyžádá potřebná oprávnění a zpřístupní webové rozhraní démona. Ve srovnání se samotným Syncthing démonem je tedy relativně jednoduchá a démona bude možné i nadále provozovat například v rámci Termux, ale uživatelská přívětivost tím značně klesne.
Kategorie: GNU/Linux & BSD

Cynet delivers 426% ROI in Forrester Total Economic Impact Study

Bleeping Computer - 31 Říjen, 2024 - 12:00
A commissioned study conducted by Forrester Consulting on behalf of Cynet in October 2024 found that Cynet's All-in-One Cybersecurity Platform generated $2.73 million in savings, paying for itself in under six months, for a return on investment of 426%. [...]
Kategorie: Hacking & Security

Enterprise Identity Threat Report 2024: Unveiling Hidden Threats to Corporate Identities

The Hacker News - 31 Říjen, 2024 - 11:30
In the modern, browser-centric workplace, the corporate identity acts as the frontline defense for organizations. Often referred to as “the new perimeter”, the identity stands between safe data management and potential breaches. However, a new report reveals how enterprises are often unaware of how their identities are being used across various platforms. This leaves them vulnerable to data
Kategorie: Hacking & Security

Enterprise Identity Threat Report 2024: Unveiling Hidden Threats to Corporate Identities

The Hacker News - 31 Říjen, 2024 - 11:30
In the modern, browser-centric workplace, the corporate identity acts as the frontline defense for organizations. Often referred to as “the new perimeter”, the identity stands between safe data management and potential breaches. However, a new report reveals how enterprises are often unaware of how their identities are being used across various platforms. This leaves them vulnerable to data The Hacker Newshttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

LiteSpeed Cache Plugin Vulnerability Poses Significant Risk to WordPress Websites

The Hacker News - 31 Říjen, 2024 - 11:24
A high-severity security flaw has been disclosed in the LiteSpeed Cache plugin for WordPress that could allow an unauthenticated threat actor to elevate their privileges and perform malicious actions. The vulnerability, tracked as CVE-2024-50550 (CVSS score: 8.1), has been addressed in version 6.5.2 of the plugin. "The plugin suffers from an unauthenticated privilege escalation vulnerability
Kategorie: Hacking & Security

LiteSpeed Cache Plugin Vulnerability Poses Significant Risk to WordPress Websites

The Hacker News - 31 Říjen, 2024 - 11:24
A high-severity security flaw has been disclosed in the LiteSpeed Cache plugin for WordPress that could allow an unauthenticated threat actor to elevate their privileges and perform malicious actions. The vulnerability, tracked as CVE-2024-50550 (CVSS score: 8.1), has been addressed in version 6.5.2 of the plugin. "The plugin suffers from an unauthenticated privilege escalation vulnerability Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Get-back-to-your-desk mandates spark office refill revolution

Computerworld.com [Hacking News] - 31 Říjen, 2024 - 11:00

As the pandemic eased in 2022 and 2023, US core business centers in large and small cities continued to suffer the after effects or remote- and hybrid-work policies, which led to a 20% to 40% reduction in office space use and a devaluation of properties. The big switch to remote work left many downtowns largely empty for months.

Since then, commercial areas have seen a slow but steady return to the office, with average office occupancy rate hitting more than 60%.

Still, many offices remain partially or completely empty.

“We are approaching 20 quarters of contraction in the office market,” according to Peter Miscovich, global future of work leader at Jones Lang LaSalle IP (JLL), a commercial real estate and investment management services firm. “There are signs of stabilization of vacancies in certain parts of the country.”

One trend affecting the repopulation of corporate cubicles involves a rash of return-to-office (RTO) mandates. Last month, for example, Amazon CEO Andy Jassy told employees to get back into the office five days a week beginning in early 2025. Ericsson recently tightened its policy for office attendance, too.

Earlier this year, Dell Technologies ordered many workers to return to their corporate desks, and more recently told its global sales team to work in office five days a week. And just last week, 3M ordered senior employees back to corporate headquarters.

According to one recent survey, most companies are pushing for RTO mandates in 2025. The survey by ResumeBuilder found that nine in 10 companies will enact RTO mandates based on data from 764 companies that transitioned to a fully remote work model during the pandemic. But the data is nuanced. Not all RTO policies, of course, require employees to be in the office five days a week.

Kastle

“There’s only 25% of companies, overall, seeking RTO five days per week, and the remaining 75% are involved in various forms of hybrid or hybrid/remote and my forecast is that hybrid will endure,” Miscovich said.

The ResumeBuilder survey results were similar to Miscovich’s findings. The majority of companies are operating with a hybrid model, while 30% require employees to be in the office full-time.

Office occupancy rates fell from 100% in February 2020, at the start of the pandemic’s stay-at-home orders, to just 14% by April of that same year. Over the next four years, those rates have slowly climbed as companies embraced hybrid work policies. But on average, occupancy never fully returned to 100%, according to Kastle Systems, a provider of security key fob technology for 2,600 buildings in 138 US cities.

Recent data shows occupancy rates are again climbing. In January, the peak occupancy rate of US office buildings stood around 46% based on a 10-city average, according to Kastle. Today, more than 61% of buildings are occupied in those same 10 large cities. And cities such as Austin and Houston are seeing occupancy rates as high as 77% to 71%, respectively. Chicago’s office building occupancy rate stands at 69%.

Peak occupancy rates are only half the story. “Peak” relates to days when offices are most full, such as on Mondays and Tuesdays. On less popular days, such as Fridays, office occupancy rates dipped as low as 33% this month.

Kastle

Despite the rise in occupancy rates, office values remain depressed compared to before the pandemic, according to the National Bureau of Economic Research (NBER). It found there has been a 39% decline in office building values since 2020 — and a large percentage of pre-pandemic leases will come up for renewal in the next few years. That could force some companies to more closely evaluate their office needs.

The COVID pandemic served as something of an unintentional experiment that revealed a host of uncomfortable workplace truths — namely, that most employees always preferred remote work and at-home knowledge workers were just as, if not more, productive. Another realization: working in the office, by default, isn’t as rewarding some people as it is for others, according to Phil Kirschner, an associate partner in McKinsey & Co.’s real estate and people and organizational performance practices.

Not everyone, for example, feels the same level of inclusion and equality in an office setting. “Diverse populations of almost any measure — whether skin color, sexual orientation, physical disability — are affected by in-office requirements, and there’s a higher desire for workplace flexibility either when taking a job or the likelihood to leave a job if you’re not offered it,” Kirschner said in an earlier interview with Computerworld.

Higher quality buildings, such as those that are newer and have more amenities, have fared better of late. That’s prompted a rush to build or renovate older offices that not only have newer amenities and mixed-use spaces (such as combined office, shopping and recreational facilities) but updated technology to better support remote and hybrid workers.

But older properties with fewer amenities could suffer. In particular, Class B, Class C and even lower-end Class A grade buildings could see the biggest valuation declines in the current market; those who are leasing or buying space now want top-notch AAA buildings — those with the latest amenities, technologies, and locations.

“There’s a potential space shortage in certain districts and locations,” Miscovich said. “Even three-days a week in the office is affecting demand. We are seeing demand for that high-quality space, but there’s also the surplus of the obsolete, class B- or C buildings that are not serving the workforce of the future.”

Leading the return-to-office trend are legal firms, financial services organizations, defense contractors, and industrial companies seeking to expand their footprint as the result of business demands.

“And, then the technology sector is picking up in places where they have AI talent demands and key urban centers for tech talent,” Miscovich said. “Technology is fascinating because you have some firms becoming more office centric and others are still offering more of a hybrid approach. We’ll see how that sector plays out over the next couple of years.”

Miscovich describes the pandemic was “an accelerant” and “time machine” that moved the US workforce 10 years into the future in just two years. Remote work was inevitable with the evolution of the digital economy, and the pandemic showed the promise of hybrid and distributed work.

Now workplace design, leadership, culture, workplace practices, change management, hybrid workplace technologies — all need to mature as we go forward beyond the post pandemic world, he said.

“The future of work will be distributed; it will be diverse and it will be dynamic. I think the RTO mandates occurring are for individual companies in that 25% range,” Miscovich said. “That may increase to 30%, but our point of view is hybrid work will endure for the longer term. We have some clients that by 2027 or 2030 may have a portion of their workforce in office five days a week and another portion of their workforce at three days a week or three days a month.

“I don’t think there will be ever a future steady state, just given the dynamism of artificial intelligence, talent and distributed work,” he said. “I think we’ll see a continuous evolution and continuous learning mind set relative to future of work strategies.”

Kategorie: Hacking & Security

Všechny Macy už mají alespoň 16 GB RAM. Apple povýšil i základní MacBook Air, cenu zachoval

Živě.cz - 31 Říjen, 2024 - 10:45
Po včerejšku už Apple neprodává žádný Mac s 8 GB RAM, ale veškeré počítače nabízejí minimálně dvojnásobek. Ač totiž firma neuvedla novou generaci MacBooků Air, tak ty stávající nabízí v základu s 16 GB, za což se dříve muselo připlatit 6 000 Kč. Příjemná novinka se týká Airů v obou úhlopříčkách s ...
Kategorie: IT News

LottieFiles hacked in supply chain attack to steal users’ crypto

Bleeping Computer - 31 Říjen, 2024 - 10:02
The popular LottieFiles Lotti-Player project was compromised in a supply chain attack to inject a crypto drainer into websites that steals visitors' cryptocurrency. [...]
Kategorie: Hacking & Security
Syndikovat obsah