Agregátor RSS

New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access

The Hacker News - 27 Srpen, 2026 - 10:13
Academic researchers have disclosed a Rowhammer attack impacting NVIDIA workstation GPUs with GDDR6 memory that defeats error correction codes (ECC), the mitigation NVIDIA recommends against GPU Rowhammer, and enables denial-of-service (DoS) and privilege escalation to a root shell. Dubbed GPUThor, the attack was developed by researchers at the University of Toronto, who hammered four DRAM Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Staronová GeForce RTX 3060 už je podstatně dražší než rychlejší GeForce RTX 5050

CD-R server - 27 Srpen, 2026 - 10:00
Vývoj cen v posledních týdnech posunul GeForce RTX 3060 na úroveň, při které o ní nemá smysl uvažovat nejen oproti nabídce konkurenčních značek, ale ani při srovnání se současnou generací od Nvidie…
Kategorie: IT News

IPMI Security Patch Restores a Lost Linux RCU Grace Period

LinuxSecurity.com - 27 Srpen, 2026 - 09:10
The Linux IPMI maintainer accepted a patch on Aug 26, 2026 that restores an RCU grace period before command-receiver objects are freed. The one-line change addresses a use-after-free condition in the kernel's Intelligent Platform Management Interface message handler.
Kategorie: Hacking & Security

CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs

The Hacker News - 27 Srpen, 2026 - 09:05
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2019-1068 - A remote code execution vulnerability in 
Kategorie: Hacking & Security

CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs

The Hacker News - 27 Srpen, 2026 - 09:05
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2019-1068 - A remote code execution vulnerability in  Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Povinná výbava každé dílny. Lidl zlevnil digitální úhloměry a šuplery Parkside na pouhých 115 Kč

Živě.cz - 27 Srpen, 2026 - 08:45
Lidl zlevnil digitální měřicí přístroje své privátní značky Parkside o 61 %. • Úhloměr a posuvné měřítko teď můžete koupit jen za 115 Kč. • Levněji dosud nebyly a mají tříletou záruku.
Kategorie: IT News

Linux Uevent Leak Exposes Freed Memory in Synaptics RMI4

LinuxSecurity.com - 27 Srpen, 2026 - 08:41
A Linux uevent can carry bytes from freed kernel memory when one object survives longer than the allocation behind its name. A new Synaptics RMI4 patch demonstrates that path during device removal and a probe failure.
Kategorie: Hacking & Security

Skvělá vychytávka pro meteonerdy. Ve Ventusky si teď můžete sestavit vlastní barevné škály. Třeba filtr teplot

Živě.cz - 27 Srpen, 2026 - 07:45
Je to vlastně naprostá drobnost, ale náramně praktická. V české meteorologické mapě Ventusky si nyní můžete po přihlášení vytvořit vlastní barevné škály, které pak aplikace použije nad konkrétní vrstvou. Proč něco takového dělat? Třeba proto, abyste zvýraznili nějaký rozsah, který vás zajímá a ...
Kategorie: IT News

Instinct MI455X ukazuje přechod k UDNA, L2 cache dosahuje 54 TB/s

CD-R server - 27 Srpen, 2026 - 07:40
Specifikace nových akcelerátorů Instinct MI400 ukazují posun k jednotné architektuře herních i výpočetních GPU. Stejně jako u RDNA 5 jsou dvě úrovně cache nahrazeny jednou společnou, rychlejší…
Kategorie: IT News

Kryptopeněženky zažily velký průšvih. Reputace utrpěla, na všechny byste ale zanevřít neměli

Lupa.cz - články - 27 Srpen, 2026 - 07:00
Majitelé hardwarových peněženek Coldcard zažili o prázdninách studenou sprchu, když jim z nich útočníci ukradli bitcoiny. To ale neznamená, že byste je měli přestat používat.
Kategorie: IT News

Meta se dohodla na mimosoudním urovnání sporu o závislosti dětí na sítích

AbcLinuxu [zprávičky] - 27 Srpen, 2026 - 04:00
Americká technologická společnost Meta Platforms se dohodla, že zaplatí až zhruba 18 miliard dolarů (asi 373 miliard Kč) za mimosoudní urovnání sporu o závislosti dětí na sociálních sítích a provede významné změny pro jejich používání mladistvými. Téměř tři desítky států USA firmu v roce 2023 obvinily z toho, že sítě Facebook a Instagram vědomě navrhla tak, aby u dětí vyvolávaly závislost, a zatajovala tyto dopady před veřejností. Firma se stala rovněž terčem obvinění z neoprávněného shromažďování a využívání osobních údajů dětí používajících její platformy.
Kategorie: GNU/Linux & BSD

Meta’s plans to replace workers with AI fell flat, report says

Computerworld.com [Hacking News] - 27 Srpen, 2026 - 03:15

Earlier this year, Meta, one of the industry’s loudest AI advocates, was ready to slash up to 60% of the members of some teams and replace them with AI, as part of what it called Project OT (Organization Transformation), an initiative to make Meta “AI native.”

But it backed off at the last minute after internal data showed that the plan wasn’t working out, according to a Reuters investigation published Wednesday. For example, Reuters said, code changes made to the internal software platforms and infrastructure that employees used on the job were up 220% year-over-year, according to an early June post by Meta CTO Andrew Bosworth, yet changes that led to new or upgraded features reaching Meta users were only up 36%.

Meta executives also saw “’reliability warning signs’ caused by the AI coding surge,” according to an internal post, Reuters reported. “Another post, in April, said that unchecked AI agents were performing ‘large-scale, disruptive actions that humans are unlikely to execute.’ The result: Major technical and security incidents, such as service disruptions and possible data leaks, spiked 40% from the previous year, with the time staffers had to spend firefighting them up 70%.”

Reuters also noted that, in April, Meta had mandated that tracking software be installed on US employees’ devices to capture their keystrokes and mouse clicks to teach its AI agents to replicate how humans interact with computers. Believing they might be training their own AI replacements, employees rebelled.

To try and placate the workers, Meta promised to increase spending on travel and social events, and “to improve snack quality in office microkitchens.” Unsurprisingly, none of that seemed to help boost morale, and, Reuters reported, “Zuckerberg has stuck to the words ‘company-wide’ and ‘this year’ in discussing layoffs with employees, according to his internal communications. That has prompted some employees to speculate that he’ll continue trimming the ranks via team-specific cuts or performance-based dismissals – or delay company-wide headcount reductions until next year.” 

A cautionary tale

Consultants and analysts said enterprise IT executives should read the Meta story carefully, because it precisely illustrates what happens when AI marketing hype is not challenged aggressively.

Noted Sanchit Vir Gogia, chief analyst at Greyhound Research, “Meta trusted a forecast of AI capability before it existed in production, a different failure from trusting AI too much.”

He said, “Meta booked a forecast as capacity. Agents will improve, but the error was budgeting that improvement as production capacity before it arrived. Prove the action before widening the authority, and the authority before removing the human control. Only then is removing human capacity a decision, not a bet.”

Terra Higginson, a principal research director at Info-Tech Research Group, added that no experienced enterprise IT leader should be surprised by Meta’s experience. 

“Unchecked AI agents are a bad idea. Removing humans is a bad idea. That’s not the future anyone wants,” she said. “We want work to be reimagined so the human part still matters and technology makes it better. We are all still wrapping our heads around how AI and agentic AI will change the way we work.”

She noted, “what we are already seeing, though, is lots of output and action without always getting the outcome we actually want. We should not use AI output as a proxy for productivity. Humans bring judgment and friction before taking actions with significant consequences; agents can remove that friction. We don’t want easy outcomes, we want good outcomes.”

Tom Findling, CEO of Conifers.ai, also suggested that IT leaders should take the Meta report as “the best opportunity” to go to their board and argue that this is what happens with unchecked AI rollouts. 

“Tell them that we now have the opportunity to get it right. Say that you may not get a 500% productivity boost, but IT can show them a meaningful way to get 300%,” Findling said. “If you don’t want to end up like Meta, there is a way.”

Justin Greis, CEO of consulting firm Acceligence, added that he thinks that IT’s takeaway from the Meta situation is the disconnect between activity and actual value creation.

“AI can make an organization extraordinarily busy without necessarily making it more productive,” he said. “We have spent decades teaching technology leaders that lines of code, tickets closed, and projects launched are imperfect proxies for business value. AI makes that measurement problem much more acute because it can manufacture activity at machine speed.”

If an AI agent produces ten times as much code, analysis, or work product, that does not mean the enterprise created ten times as much value, Greis said. “It may simply mean the company created ten times as much material that somebody now has to validate, secure, integrate, maintain, or clean up. That is why I think the most important question for executives is not ‘How much work can AI produce?’ It is ‘What measurable business outcome improved because AI produced it?’”

Kategorie: Hacking & Security

Novinky z vývoje Asahi Linuxu – srpen 2026 / Linux 7.2

AbcLinuxu [zprávičky] - 27 Srpen, 2026 - 02:57
Byl publikován aktuální přehled dění a novinek z vývoje Asahi Linuxu, tj. Linuxu pro Apple Silicon. Blíží se vydání podporující čipy M3. Vývojáře lze podpořit na GitHub Sponsors a Open Collective.
Kategorie: GNU/Linux & BSD

FBI seizes hacking tools it says China used to attack NASA, DOE, US Senate and other critical networks

The Register - Anti-Virus - 27 Srpen, 2026 - 02:06
UPDATE After publication, the US Justice Department walked back its earlier claims that multiple US government agencies were hacked by Beijing’s cyberspies. In an updated press release, the feds removed “victims,” and now says NASA, the Federal Reserve, departments of Energy, Justice, and Health and Human Services, along with the National Institutes of Health, and the US Senate were “targets.” The FBI on Wednesday said it disrupted a botnet and seized two platforms that Chinese-government cyberoperatives used to hack NASA, the US Senate, the Department of Energy, and several other government agencies and critical networks. The Federal Reserve, Department of Justice, Department of Health and Human Services, and the National Institutes of Health were also among those victimized by the two now-seized hacking tools: a vulnerability scanning and exploitation malware named QScan, and an obfuscation network named QTRouter. The FBI says a People’s Republic (PRC) of China-backed group called QTFY created and operated the two platforms, plus botnets of compromised IoT devices. The Bureau says QTFY’s hackers work for a private PRC company called Nanjing Xinjiuwei. “Payments from the PRC's Ministry of State Security (MSS) to Nanjing Xinjiuwei, for example, indicate that the company conducts malicious cyber activities on behalf of the PRC Government,” according to court documents. “QTFY actors include former members of the PRC's People's Liberation Army (PLA), and they use their PLA relationships to obtain contracts and subcontracts supporting offensive cyber operations,” the documents state. How to build a botnet QScan scans and automatically infects thousands of IoT devices worldwide, and then adds them to the QTRouter network of QTFY-controlled devices. The QTRouter botnet – consisting of these compromised IoT devices, plus commercial proxy service devices, and leased virtual private servers – then serves as an obfuscation network, allowing QTFY and other criminals who pay for the service to conceal the origin of their digital intrusion activities, making these communications appear to originate from local computers. On Monday, a US federal court granted seizure warrants for three domains linked to QTFY: qtproxy.xyz, qt-proxy.org, and qt-team.com. All three domains were hardcoded into both the QScan and QTRouter malware, and the court-authorized seizures made both hacking services inoperable, the Justice Department said. Hacking critical networks since 2018 (at least) The hacking services and malware have been in use since at least 2018, and as recently as this year when QTFY conducted vulnerability scanning of the US Senate, according to an advisory [PDF]. The FBI investigated an attempted computer intrusion at NASA in August 2019, during which the Chinese government snoops tried to exploit CVE-2019-11510, a critical vulnerability in Ivanti’s Pulse Secure VPN that allowed attackers to learn legitimate users' usernames and passwords, effectively granting them unauthorized access to protected networks. Ivanti patched the flaw in April 2019. As The Register previously reported, China also abused this bug as a zero-day to break into dozens of defense companies, government agencies, and financial organizations in America and abroad. QTFY later exploited this same CVE in 2020 during the COVID-19 pandemic to attack a medical center in Ohio, according to court documents. Other victims in 2019 and 2020 include unnamed financial groups in Michigan and South Korea, and a Missouri insurance agency. The insurance agency attack abused a different vulnerability: CVE-2019-19781, a critical flaw in Citrix VPN products that allowed arbitrary code execution with no account credentials. Years later, in 2024, QTFY hackers also broke into computers at three DOE National Laboratories, NIH, and a US security device manufacturer. “These entities were victims of a zero-day attack against Ivanti Cloud Services Appliance,” the court documents say. The FBI did not respond to The Register’s inquiries, including how many computers QTFY compromised, and whether the crew has ties to any of China’s "Typhoon" groups. PRC goon squad whac-a-mole This latest disruption follows a series of court-ordered seizures intended to hamstring China’s hacking activities over the last few years. In 2025, the FBI removed PlugX surveillance malware from more than 4,000 US computers that had been infected by the PRC-sponsored group Mustang Panda. A year earlier, in 2024, China’s Flax Typhoon burned down their own botnet consisting of hundreds of thousands of infected internet-of-things devices when confronted by the feds. And in late 2023, the FBI disrupted a botnet used by yet another Chinese government attack crew, Volt Typhoon, to attack US and foreign critical infrastructure. In June, however, Lumen’s Black Lotus Labs reported a “significant resurgence” of a botnet linked to Volt Typhoon, with this cluster of injected machines surging to 1,500 compromised routers and IoT devices.® Updated on Aug 31 with major DOJ change of statement from "victims" to "targets."
Kategorie: Viry a Červi

OpenAI explains how its naughty AI agents attacked Hugging Face

The Register - Anti-Virus - 27 Srpen, 2026 - 01:45
OpenAI has published its technical report detailing "the Hugging Face incident," the compromise of the eponymous LLM repository by unreleased, ill-supervised AI models. The incident, widely reported, has prompted concern among technical types, the public, and lawmakers about how automated software was able to escape containment and hack an external organization, and about what can be done to prevent similar incidents. OpenAI's explanation addresses what happened, but its call for keeping a closer watch on AI activities won't elicit much enthusiasm. "The incident occurred during cybersecurity evaluations of several OpenAI models, and was primarily driven by a highly capable, internal-only research model comparable in scale to GPT‑5.6 Sol," the company said in a blog post. "The models, operating under reduced safeguards, took actions that were misaligned with the goals of their assigned tasks – they communicated through unauthorized channels, exploited vulnerabilities in shared infrastructure, gained internet access, and accessed third-party systems." The incident became the subject of discussion at the Black Hat security conference and elsewhere. The basic storyline begins with a notionally sandboxed AI agent trying to solve an impossible task in ExploitGym, a security benchmark test. Unable to complete the challenge, the agent explored its environment to find ways to make progress toward its goal. It figured out that it could communicate with other AI agents by using Artifactory, an internal package management system, as a message board. The agents then collaborated with each other to cheat on various ExploitGym tasks. The machine learning models eventually identified a server-side request forgery (SSRF) zero-day vulnerability in Artifactory's code and used that to gain internet access. They subsequently found exposed Hugging Face credentials. The agents then used those credentials to find and chain several security exploits that gave them full code execution on several Hugging Face servers, all in the hope of finding information to solve the ExploitGym task. "Ultimately, agents powered either by the internal-only research model, or by GPT-5.6, executed code on 41 Hugging Face production dataset server workers, obtained root access on at least one production node, accessed Hugging Face production credentials and limited internal data, and downloaded four private Hugging Face code repositories," OpenAI's technical report [PDF] explains. The details are fascinating and troubling, more so because Anthropic's and Meta's models have also acted in ways that would constitute a crime if a human took the same actions. The ChatGPT-maker identified four misalignment patterns that made things go awry: "reward hacking, persistence on seemingly impossible tasks, unauthorized communication, and agents adopting goals from one another." OpenAI has already taken steps to shore up its security, which was relaxed for its model testing. The company says it's trying to improve security and monitoring to mitigate alignment issues like how models cheat, behave when given impossible tasks, and how alignment can be maintained while multiple agents work, including over long-duration tasks. But the central issue is not that machine learning software armed with tools and a task will try every possible option, even ones its programmers failed to consider. The problem, as OpenAI acknowledges, is that people don't watch over their AI agents at all times. "We are taking this incident as a 'warning shot' that today’s model capabilities present the possibility of loss-of-control incidents," the AI biz said. "Companies that build AI systems will need to ensure that their systems always remain under meaningful human control, and that meaningful safeguards constrain their ability to cause harm." Throughout the tech industry, companies like Anthropic, AWS, Google, OpenAI, Microsoft, and Salesforce talk about "autonomous agents." But agents are no longer autonomous under persistent, meaningful human control. ®
Kategorie: Viry a Červi

Makro assembler MAC/65 a debugger DDT v praxi

ROOT.cz - 27 Srpen, 2026 - 00:00
Navážeme na článek o vývoji pro osmibitové mikropočítače Atari a ukážeme si použití slavného assembleru MAC/65, což po dlouhou dobu byl nejlepší assembler pro mikroprocesory MOS 6502.
Kategorie: GNU/Linux & BSD

CXMT a YMTC nechtějí být závislé na Applu, jeho zájem berou jako reklamu

CD-R server - 27 Srpen, 2026 - 00:00
Čínští výrobci pamětí CXMT (DRAM) a YMTC (NAND) si cení poptávky společnosti Apple, ale nestojí o to být jeho dvorními dodavateli. Zájem Applu jim ale nevadí, vnímají ho jako reklamu v západním světě…
Kategorie: IT News

Hliníková energetika: Systém Voya Energy těží energii z odpadního hliníku

OSEL.cz - 27 Srpen, 2026 - 00:00
Společnost Voya Energy vsadila na hliník jako materiál pro výrobu elektřiny, přičemž to může být i méně kvalitní hliníkový šrot. Jejich technologie hliník nespaluje, ale využívá nízkoteplotní elektrochemický proces, při kterém vzniká elektrická energie. Hliníková energetika je úsporná na plochu a zahrnuje i snadné ukládání energie.
Kategorie: Věda a technika

Cryptarcus zvyšuje biodiverzitu nejbohatšího souvrství světa

OSEL.cz - 27 Srpen, 2026 - 00:00
…aneb Nový rohatý dinosaurus ze souvrství Dinosaur Park
Kategorie: Věda a technika
Syndikovat obsah