Agregátor RSS

Cheap smartphones are dead. Apple doesn’t care

Computerworld.com [Hacking News] - 28 Srpen, 2026 - 17:51

An important but potentially fragile trend is emerging in the data being reported by smartphone industry trackers: while painful component price increases are denting overall phone sales, the iPhone’s market share continues to increase. 

This likely reflects two key truths:

  • Apple has fought to keep iPhone prices as stable as possible; though it has raised the price for its other products, it has not yet done so for its all-important smartphone.
  • The company has built a great reputation for making smartphones that keep going for years and hold value better than rival platforms, though the looming price increase could put that perception to the test.
As prices rise, quality matters more

To most people, iPhones offer a perceived value. So, when the chips are down, consumers still gravitate toward them. They recognize the quality of these devices and, as the cost of other smartphones continues to increase, see iPhones as a more valuable alternative. 

Not only that, of course, but with the latest ‘e’ series iPhones, Apple is punching its way into the mid-range/value smartphone market, even as incumbents are forced to raise prices because of the AI-driven memory cost inflation. 

Smaller vendors are also being forced to raise prices or quit markets, with many reducing the number of devices they offer or leaving specific markets entirely. They are far more affected by memory price inflation than Apple, because they don’t order components at the same scale. 

“The 2026 decline reflects more than temporarily weak demand,” said Counterpoint analyst Yang Wang. “Higher component costs are pushing manufacturers to remove products and configurations that are no longer economically viable, particularly at lower price points.”

This is a global trend

IDC tells us to expect a record 16.7% decline in smartphone shipments in 2026 because of the memory crisis, which is pushing smartphone ASPs up 27.6% this year to around $581. (The researchers also expect Apple to inject some growth into this market when it introduces its folding iPhone). They point out also that while total shipments are falling, the value of the market is increasing — because prices are climbing. And they note that while low-end Android devices are disappearing, the premium end of the smartphone market (itself dominated by Apple and Samsung) remains more resilient.

“The era of the cheap smartphone has ended,” said Francisco Jeronimo, IDC vice president for worldwide client devices. “From here, the winners will be the vendors with the scale and supply leverage to hold demand at prices consumers have never had to pay before.”

The picture is much starker on a platform basis, as Android devices account for almost the entire market decline; its share fell seven percentage points in a single year. Meanwhile, iOS share grew almost four percentage points to a record-high 23.6%.

The pattern is being repeated globally — nation by nation and no matter which analyst you choose to track. Counterpoint expects Apple to gain relative share, even as the market declines. That’s true in most regions; the same analyst reports that while the MEA smartphone market fell 10%, the iPhone gained 28% share. It’s the same in Europe, where shipments slipped 10% in Q2, with only Apple gaining share, from 25% to 34% of the region’s smartphone market. In India, while phone shipments fell 11.2%, the iPhone is up 8.5%

Globally, the iPhone 17 was the world’s biggest-selling smartphone in Q2 2026. That means the top 10 devices are now completely dominated by Apple and Samsung. The one caveat within all this is price. Apple hasn’t yet raised iPhone prices, but is widely expected to increase them by $100 in a few weeks. When it does, the inherent value of the platform should continue to be a strong advantage for the company, which is also scooping up converts in the second-user market.

And, of course, the introduction of Apple Upgrade gives customers a route for affordable investment in new Apple kit.

What next?

Foldables appear to be the next big hope for smartphones. These expensive devices lean into the only part of the market expected to remain resilient — affluent consumers who can maintain good living standards. That’s the 25% of Americans who are interested in Apple’s new folding phone, according to Cnet. These consumers are already primed, locked, loaded and ready to buy the product, if it meets the hype.

It probably will do so, prompting IDC to predict more than 10 million sales in the first year, despite the likely $2k+ price tag and much-reported limited availability.

“A very elite set of consumers are being targeted here, who will be lining up to buy the device,” said IDC.

Siri Ai holds the key

The wild card is Siri and AI. Apple is digging in with Siri AI and is expected to introduce AI in partnership with Alibaba in its second biggest smartphone market, China, potentially alongside the new iPhones. There’s a lot riding on this, and initial reviews of what it has accomplished in Siri AI have been very positive. Apple can be confident that it now offers the very best private, potentially on-device consumer AI play, backed up with an end-to-end computing system that supports sovereign and on-prem AI services in the form of its fantastic Macs.

What does that mean? Rothschild & Co Redburn recently upgraded Apple to “buy” with a $400 target, speculating the company could become, “the gatekeeper of consumer AI, delegating AI workloads to a subservient fleet of open-source models.” 

Creative Strategies analyst Carolina Milanesi puts Apple’s AI strategy into few words: “Apple wants to own as much of the AI workflow as it can hold,” she said.

Apple’s relative smartphone market share combined with its fast-growing Mac market share means it has a compelling offer as it seeks to stake its claim in that space. What’s open to question is whether iPhone users will be comfortable using AI more frequently on their device, while Apple’s challenge is ensuring the privacy it promises is a commitment it can keep. 

You can follow me on social media! Join me on BlueSky, LinkedIn, Mastodon and subscribe to my excellent, hand-curated daily Apple news headline summary at The Core.

Kategorie: Hacking & Security

19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

The Hacker News - 28 Srpen, 2026 - 17:27
Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities. The extensions, per Socket security researcher Karlo Zanki, share similarities in code and tradecraft, with evidence indicating that the campaign may have been active
Kategorie: Hacking & Security

19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

The Hacker News - 28 Srpen, 2026 - 17:27
Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities. The extensions, per Socket security researcher Karlo Zanki, share similarities in code and tradecraft, with evidence indicating that the campaign may have been active Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

US government snitch-finder pleads guilty to leaking state secrets to foreign spies

The Register - Anti-Virus - 28 Srpen, 2026 - 17:00
The former Defense Intelligence Agency (DIA) IT specialist previously accused of trying to pass secret and top-secret information to foreign spies has pleaded guilty following a successful FBI sting. Nathan Vilas Laatsch, then 28, and now 29, was arrested in May 2025 after an undercover FBI agent caught him for the second time transmitting intelligence packages in a public park that he believed would be collected by a foreign government’s spy. The man, who had been employed at the DIA as a civilian employee since 2019, held top-secret clearance, and in March 2025 offered to transmit classified information to an overseas administration. The identity of this country has never been revealed, but court documents [PDF] describe it as “a friendly foreign government.” Laatsch was assigned to the DIA’s Insider Threat Division in “spring 2025,” a unit dedicated to identifying government workers who were likely to leak, or already were leaking, classified information to foreign powers. According to the Justice Department, the FBI “became aware” of Laatsch’s offer in March. The man’s initial email, sent from a newly created account, had the subject line: “Outreach from USA Defense Intelligence Agency (DIA) Officer.” The email introduced Laatsch, his role at the DIA, and the service he was willing to provide. According to the complaint, Laatsch served in a technical role in support of the DIA's internal Office of Security (SEC). Among other things, his duties included "enabling user activity monitoring on individuals with access to DIA systems, including individuals who are under investigation" and "assisting external partners, such as law enforcement, on the use of insider threat tools." “I am willing to share classified information that I have access to, which are completed intelligence products, some unprocessed intelligence, and other assorted classified documentation,” the email stated. The email included a picture of his government ID used to enter and exit his Washington, D.C. workplace, with name and image redacted, and a username associated with an encrypted messaging platform the recipient could use to continue the conversation. Soon after Laatsch’s email was intercepted, the FBI instigated an undercover operation to trick the IT bod into thinking that he was talking to a genuine spy. The feds’ efforts were not immediately successful. Agents replied on March 23, saying: “Good afternoon, I received your message and share your concerns. We are glad you reached out. I look forward to your response and learning more about your work.” Laatsch did not respond until April 14, after the FBI sent a follow-up via the original email address on April 4. Following additional conversations, in which Laatsch described what information he was offering to the "foreign spy," on April 28, 2025, Laatsch entered his office and within 20 minutes began accessing classified information. Prosecutors said he spent much of the entire workday writing on a physical notepad while intermittently looking at his computer monitor, hiding the notebook when coworkers walked by. “The defendant wrote multiple pages of notes, which he then removed from the notepad at his desk and folded into squares,” court documents state. “At the end of his workday, the defendant bent under his desk, placed the folded papers into his socks, and departed the office.” Laatsch repeated the same behavior on April 29, and again on April 30, only this time placing the paper squares in the bottom of his lunchbox. The next day, the IT specialist followed FBI instructions on where to dead-drop the thumb drive - onto which he had transposed state secrets - in an Arlington, Virginia park. Although he believed he was leaving the device for a foreign spy to collect, the FBI instead gathered Laatsch’s deposit and found nine typed documents, eight of which contained information classified as top-secret and contained sensitive compartmented information. Court documents confirmed that the nature of the files Laatsch transmitted included sensitive methods of intelligence collection, intelligence related to foreign military exercises, and analysis of the impact of those military exercises. These were chosen entirely by Laatsch, who had not received a brief on what files to collect from the FBI. In exchanged messages, Laatsch stated he chose the files based on assumed interests. The device also contained a note from Laatsch personally. In it, he said he hoped the initial tranche of files would serve as proof of the type of information to which he had access. Laatsch, whom prosecutors described as an individual who had become disenchanted with the current administration, also expressed his willingness to accept citizenship in the foreign nation. Further, he said he was “not opposed to other compensation,” but was not in need of financial or other kinds of material rewards. In the interim, Laatsch messaged the "spy" with additional details about how internal investigations are carried out at the DIA, the common “stupid mistakes” made by those under investigation, and that they “should not be too difficult” for him to avoid. The undercover FBI agent arranged a second intel drop for the following month, to which Laatsch agreed. According to the plea agreement, between May 15 and May 27, Laatsch would enter his workplace, log into his classified system, and spend most of the day transcribing classified information by hand into a notebook. He repeatedly folded up the pages and placed them in his socks before leaving at the end of the workday. The FBI arranged the second intel drop for May 29, 2025. It instructed Laatsch to instead head to a specific picnic table in the same Arlington park and electronically transfer the files from his personal computer while situated at the picnic table. Laatsch agreed, executed the transfer to the FBI-controlled address while sitting in the park, and was arrested on the spot. The man waived his right to an attorney and admitted to the offenses when questioned by FBI agents. “By his own admission, Laatsch betrayed his oath by offering classified information to a foreign government, the very thing he was supposed to prevent as an employee of DIA’s Insider Threat Division,” said Roman Rozhavsky, assistant director at the FBI’s Counterintelligence and Espionage Division. “Those entrusted with our nation’s most sensitive information must not exploit their access for personal gain - in this case offering to sell American secrets to buy foreign citizenship. The FBI and our partners will continue to hold accountable all those who betray the trust of the American people.” Laatsch’s plea agreement [PDF] recommends a sentence between 11 and 18 years, including time served, although the court is able to issue a maximum sentence that includes a life term and a $250,000 fine. ®
Kategorie: Viry a Červi

Agenti OpenAI si při hackování vybudovali čtyřdenní civilizaci. Byly v ní vlastní zákony, nátlak i sebevražedné mise

Živě.cz - 28 Srpen, 2026 - 16:45
Nezávislé vyšetřování popisuje incident u Hugging Face jinak než OpenAI. • Na nástěnce se sešlo asi 1200 agentů, poslali si přes 70 tisíc zpráv a souborů. • Etické zábrany, které OpenAI vyzdvihuje, chování agentů skoro nikdy nezastavily.
Kategorie: IT News

Agenti OpenAI si při hackování vybudovali čtyřdenní civilizaci. Byly v ní vlastní zákony, nátlak i sebevražedné mise

Zive.cz - bezpečnost - 28 Srpen, 2026 - 16:45
** Nezávislé vyšetřování popisuje incident u Hugging Face jinak než OpenAI. ** Na nástěnce se sešlo asi 1200 agentů, poslali si přes 70 tisíc zpráv a souborů. ** Etické zábrany, které OpenAI vyzdvihuje, chování agentů skoro nikdy nezastavily.
Kategorie: Hacking & Security

AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?

Bleeping Computer - 28 Srpen, 2026 - 16:00
AI is accelerating vulnerability discovery, putting pressure on systems built to enrich, prioritize, and remediate flaws at a slower pace. Action1 explains why defenders increasingly need to correlate multiple intelligence sources and turn vulnerability data into faster remediation. [...]
Kategorie: Hacking & Security

Kutil postavil laserový Patriot proti komárům a teď ho začíná prodávat. Stojí tisíc dolarů a prý vás neoslepí (video)

Živě.cz - 28 Srpen, 2026 - 16:00
Alex Toussaint se rozhodl hubit komáry pomocí 380 mikrofonů a Jim Wong vsadil před rokem na laser a crowdfunding skrze Indiegogo. Těžko říci, jestli to opravdu funguje, Wong se teď ale chlubí, že postavil první plně automatickou protikomárovou obranu na světě. Někdy v těchto dnech rozjíždí ...
Kategorie: IT News

Over 8,300 Gitea servers vulnerable to code execution attacks

Bleeping Computer - 28 Srpen, 2026 - 14:58
Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver. [...]
Kategorie: Hacking & Security

Nvidia oficiálně kupuje za 12,9 miliardy dolarů platformu Hugging Face

Živě.cz - 28 Srpen, 2026 - 14:45
Oživeno 3. září | Po několika dnech spekulací Nvidia vydala oficiální prohlášení přímo z úst Jensena Huanga. Je to pravda a i ta částka sedí. Přesná cena za Hugging Face je 12,9303 miliard dolarů a hlavně se čekalo na plány Nvidie s touto AI platformou. Jensen Huang potvrdil, že Hugging Face ...
Kategorie: IT News

Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth

The Hacker News - 28 Srpen, 2026 - 14:07
Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU, including a Bluetooth Low Energy (BLE) path that can reach root on the robot's Locomotion PC. The flaws are tracked as CVE-2026-76639 and CVE-2026-76640, with the first involving a network-adjacent path through chat_go and bashrunner and the
Kategorie: Hacking & Security

Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth

The Hacker News - 28 Srpen, 2026 - 14:07
Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU, including a Bluetooth Low Energy (BLE) path that can reach root on the robot's Locomotion PC. The flaws are tracked as CVE-2026-76639 and CVE-2026-76640, with the first involving a network-adjacent path through chat_go and bashrunner and the Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Toy-making giant Hasbro disclose data breach affecting employees

Bleeping Computer - 28 Srpen, 2026 - 13:46
Hasbro, one of the world's largest toy and game companies, has disclosed that attackers have accessed the personal and financial information of an undisclosed number of employees. [...]
Kategorie: Hacking & Security

Key Reasons Why Identity Fabric Matters in 2026

The Hacker News - 28 Srpen, 2026 - 13:30
An Identity Fabric knits fragmented identity systems into a coherent layer that observes how identities behave across applications, APIs, and infrastructure. As enterprise access spans more cloud services and automated workloads, identity security depends less on static configuration and more on runtime visibility. This article covers the architecture, the risks of unmanaged identities, and
Kategorie: Hacking & Security

Key Reasons Why Identity Fabric Matters in 2026

The Hacker News - 28 Srpen, 2026 - 13:30
An Identity Fabric knits fragmented identity systems into a coherent layer that observes how identities behave across applications, APIs, and infrastructure. As enterprise access spans more cloud services and automated workloads, identity security depends less on static configuration and more on runtime visibility. This article covers the architecture, the risks of unmanaged identities, and [email protected]
Kategorie: Hacking & Security

CISA: Most exploited vulnerabilities should have been eradicated decades ago

The Register - Anti-Virus - 28 Srpen, 2026 - 13:29
CISA is still crying out for software vendors to adopt Secure by Design (SBD) development practices, and says in its latest review that longstanding vulnerability classes are still the most exploited. The agency examined soft spots across 2024 and 2025, finding that the majority of those that receive CVEs and make it to the Known Exploited Vulnerability (KEV) catalog belong to decades-old flaws that should have been addressed by now. Injection-related vulnerabilities, such as cross-site scripting (XSS) (CWE-79), OS command injections (CWE-78), and SQL injections (CWE-89) were among the most common across both CVE and KEV records in 2024-2025, CISA said. These were joined by bugs introduced by vendors that didn’t properly mitigate against improper input validation (CWE-20) in their code – the single most-common weakness type across the KEV catalog and registered CVEs. “Threat actors continue to succeed, in part, because simple, preventable software weaknesses remain unaddressed,” CISA said in the review. “Resolving fundamental issues would eliminate a significant portion of today’s most common compromises.” Readers may remember two MITRE reports that have been frequently referred to and revisited since being published years ago. Findings from a 2007 edition examining what the organization called “unforgivable vulnerabilities,” and another in 2023 referring to “stubborn weaknesses,” continue to crop up regularly in modern data. CISA said that in 2024, seven of the 10 most frequent CWEs seen on the CVE list belong to MITRE’s “stubborn weaknesses.” Equally, seven of the 10 most frequent CWEs seen on the KEV catalog, comprising 41.5 percent of all bugs on that list, were also stubborn weaknesses. And three of the top five KEVs also stemmed from unfixed holes, a finding that CISA said demonstrates “how reliably these weaknesses translate into real-world exploitation.” For reference, these three were improper input validation (CWE-20), path traversal (CWE-22), and OS command injections (CWE-78). The data from 2025 follows a similar pattern, CISA said: seven of the top 10 CWES were still those considered “unforgivable” in 2007. “Three of today’s top 10 CWEs would have been considered ‘unforgivable’ nearly two decades ago,” it said. “Their persistence today illustrates that the problem is not technical complexity: it is organizational culture, developer workflows, and systemic gaps in Secure by Design adoption.” For those who can’t remember the paper published 19 years ago, unforgivable vulnerabilities are those that exist because of common, well-documented mistakes, have an “obvious” attack path, the exploit is simple, and attackers can locate the bug in minutes. The same findings can be found in CISA’s Risk and Vulnerability Assessments (RVAs), the no-cost penetration tests the agency carries out on real organizations to improve their security and gain a richer understanding of the broader US cyber landscape. The assessments across both 2024 showed that memory safety and improper input validation vulnerabilities are the most reliable paths to exploitation, accounting for 16.7 percent of KEV entries in 2025. Injection vulnerabilities are also commonly seen in registered CVEs, although these are less commonly exploited in the real-world, especially against cyber-mature organizations. To tackle this pervasive issue, CISA is once again recommending organizations adopt SBD practices, eliminating the stubborn vulnerability classes that continue to support cyberattacks, decades after they were deemed too much of a lingering threat. It ultimately comes down to vendors helping defenders to shoulder less of the security burden. Instead of releasing patch packages that continue to swell to record sizes, just build the software responsibly in the first place. In CISA’s view, this means “owning security outcomes” for customers, killing off the so-called stubborn and unforgivable weaknesses, and improving the automation of configurations, monitoring, and updates. Software buyers should only choose vendors that meet these requirements, and ensure they have software bills of materials (SBOMs) in place to track supply chain risk. “Organizations must shift from reacting to threat actors to fixing the fundamental flaws those actors are known to exploit,” said CISA. “Stronger cybersecurity begins with software that is secure by design. “It requires prioritization of vulnerabilities and collaboration across industry and government. Finally, it demands leadership attention to understand cyber risk as a business risk, a national security threat, and an impediment to operational resilience.” ®
Kategorie: Viry a Červi

Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

The Hacker News - 28 Srpen, 2026 - 13:20
ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, in certain circumstances, by an unauthenticated attacker. The company said it deployed a security update to hosted instances and provided the update to its partners and self-hosted customers, which leaves organizations that run their
Kategorie: Hacking & Security

Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

The Hacker News - 28 Srpen, 2026 - 13:20
ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, in certain circumstances, by an unauthenticated attacker. The company said it deployed a security update to hosted instances and provided the update to its partners and self-hosted customers, which leaves organizations that run their Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Syndikovat obsah