Agregátor RSS

You could've applied all 1,449 Oracle patches and still been hit by this attack

The Register - Anti-Virus - 25 Srpen, 2026 - 18:09
In late July, Oracle released a mammoth security patch dump with 1,449 patches, in a perhaps unprecedented bad day for database admins. None of them, it turns out, would have prevented the credential theft on an Oracle database server described by security platform Huntress. “Even if it had been fully patched, everything working, it still would have happened,” said Craig Savage, cybersecurity lead at Oracle third-party support vendor Spinnaker Support, referring to the attack. In July, Huntress was alerted to credential theft activity, according to a post from the security company. The attack involved a "simple" SQL injection exploiting an unnamed organization's public-facing web app. Although SQL injections have a long history and are easy to avoid with good info-sec housekeeping, what happened next was more unusual. “After gaining initial access, the threat actor dropped a post-exploitation toolkit (called khunt) via a Java Source within an Oracle database, which is a novel aspect of this attack,” Huntress said. Because a code-object can be loaded directly in Oracle's database engine, the malicious actors were able to upload their toolkit directly into the database. “This is a technique that's previously been discussed and described over the years, including via a technique described as oraexec – however, the use of the technique in the wild has rarely been documented,” Huntress said. Oracle's database has an embedded Java Virtual Machine (JVM), and users can take Java source code and store it as a database object. “This is what attackers did during this incident: they fed CREATE JAVA SOURCE commands to the Oracle database from [Java implementation] Tomcat, through the [database] connection, and the Java source code contained within was then compiled directly inside the database as a stored schema object,” the vendor said. Speaking to The Register, Savage said: “Oracle has its own JDK. You are able to build and run Oracle Java programs within the database. It should never be something a web server can do. In fact, in a production Oracle environment, it should be locked down. It should only be re-enabled during a development or maintenance window, for example. It was poorly configured, poorly secured, but it wasn't an Oracle breach.” The ability to run Java in the database should be limited to only the DBA user, Savage argued, and users should disable the ability to compile code on a production server. “If they’d done that, it would have downloaded that Java code, and JDK would not have been configured to compile it,” he said. Savage said cybercriminals were seeking to exploit this kind of functionality more commonly, rather than simply looking to find and use vulnerabilities. “We're starting to see more and more of this: these cybercrime gangs now know about these products. They don't just know how to break them. They also know what legitimate functionality they could potentially use if it's been turned on, and that's what we saw here. That's the wake-up call. Oracle published something like 1450-ish patches. Organizations are totally focused on patch, patch, patch, but you still need to do the basics,” he said. ®
Kategorie: Viry a Červi

Massive DDoS attack disrupts Norway’s government digital services

Bleeping Computer - 25 Srpen, 2026 - 17:52
A large distributed denial-of-service (DDoS) attack has disrupted Norway's shared government digital infrastructure since Monday, affecting services used by the public sector. [...]
Kategorie: Hacking & Security

Češi postaví datacentra pro AI za 90 miliard. Zařadí se mezi největší hráče v Evropě

Živě.cz - 25 Srpen, 2026 - 17:45
Česká republika by v budoucnu měla mít poměrně silného hráče v datových centrech pro umělou inteligenci • . • Pražský podnikatel v oboru má v plánu v rámci Evropy postavit až osm takových objektů, počítá s celkovým výkonem 800 megawattů. • Investice mají dosáhnout 3,6 miliardy eur, skoro 90 miliard ...
Kategorie: IT News

Mac production returns to America with the newest Mac mini

Computerworld.com [Hacking News] - 25 Srpen, 2026 - 17:39

Perhaps it is appropriate that the last few days of Tim Cook’s leadership at Apple is marked by the return of Mac manufacturing to America in the form of the new Mac mini, which the company has promised it will assemble in the US this year. The company on Tuesday also introduced new Mac Studio models.

It’s a perfect footnote to illustrate the tremendous work Cook has done to balance sometimes opposing forces both within and outside the company. In this instance, it mirrors his difficult diplomacy to try to get Apple one the right side of the Trump Administration. 

US officials have long wanted Apple to bring all of its product manufacturing back home. The company, in turn, has had to argue and cajole and show that this is simply not possible — because even if you built new factories today, you would not have sufficiently skilled employees to work in them tomorrow.

That reality has guided Apple in its approach to investing in US manufacturing. The company seeks to develop the most high-tech manufacturing in the US, while leaving more general product assembly elsewhere. This changes with the Mac mini, which is now the company’s flagship “Made in USA” product with final assembly in the US, replacing the now-discontinued Mac Pro. (Some components are made outside the US, but assembly has been promised at Houston.)

You should see this as a continuation of the company’s $600 billion investment in US manufacturing, which most recently saw Cook and US Commerce Secretary Howard Lutnick tour Apple/Foxconn’s Houston facility, where manufacturing will take place. It’s not the only hardware the company makes in the US; it also manufactures its Private Cloud Compute AI servers there. Both production lines are significant.

What to expect from the Mac mini

“Mac mini has always been our most versatile Mac. Whether it’s being used as a home computer, powering a professional studio, or as an always-on agentic device, it’s the little Mac that can do it all,” Johny Srouji, Apple’s chief hardware officer, said in a statement.

The all-new Mac mini features M6 and M5 Pro configurations that the company says provide a massive leap in AI performance (up to four times faster than before).  Storage and graphics are twice as fast, while the processor delivers 40% better performance than the one it replaces. Configurations ramp up to an 18-core CPU and 20-core GPU.

These things are fast. That’s significant given the growing number of people using one or more of these Macs to drive on-premises AI clusters. The new models are available now to order for delivery Sept. 22.

Both Mac mini models include Wi-Fi 7 and Bluetooth 6, as well as upgraded 2.5Gb Ethernet, with a 10Gb option available. With industry-leading performance per watt, these new Macs are fast, quiet, and cheaper to run, even at peak workloads.

They offer two USB-C port that support USB 3, a headphone jack, three Thunderbolt 4 ports on Mac mini with M6, and three Thunderbolt 5 ports on Mac mini with M5 Pro, along with HDMI and Ethernet. (You can cluster multiple Mac minis using Thunderbolt to create AI machines.)

It is also appropriate to point to the environmental credentials of these Macs, given Apple’s plan to be carbon neutral across its entire footprint by 2030. The Macs are made with 50% recycled material overall, including 100% recycled aluminum in the enclosure and 100% recycled rare earth elements in all magnets. All the energy used to make these Macs is sourced from renewable energy, Apple claims. 

Here are the mini details:

Mac mini M6, from $899
  • A 12-core CPU with the world’s fastest single-threaded performance, so everything feels extra snappy and responsive.
  • A 12-core GPU, includes Neural Accelerators in each core for the first time on a mini, resulting in up to 4x faster AI performance and 2x faster graphics than the mini with M4.
  • A new dual 16-core Neural Engine that delivers up to twice the performance of the previous generation.
  • 16GB of standard unified memory configurable up to 32GB, as well as higher memory bandwidth up to 170GB/s.
Mac mini with M5 Pro, from $1,699
  • Up to an 18-core CPU with remarkable multithreaded performance.
  • A 20-core GPU with enhanced shader core and third-generation ray tracing and Neural Accelerators in each GPU core.
  • Up to 64GB of unified memory with 307GB/s of memory bandwidth.
What about the Mac Studio?

Apple also introduced new Mac Studio configurations equipped with M5 Max and M5 Ultra chips, designed to handle the most demanding workflows. Available for pre-order now these, too, will ship Sept. 22.

The company promises up 4.3x faster AI performance, up to 2x faster storage, up to 1.8x faster graphics, and up to 1.3x faster CPU speed, along with higher memory bandwidth .“Mac Studio is the ultimate desktop for on-device AI and the world’s most demanding pro workflows, relied on by users for its tremendous performance and extensive pro connectivity, all in a quiet, compact design that sits right on your desk — and today, we’re pushing the boundaries even further,” said Srouji.

Mac Studio with M5 Max features an 18-core CPU, an up-to-40-core GPU with Neural Accelerators built into each core, and up to 128GB of unified memory. Prices start at $2,499.

The M5 Ultra variant scales up to a 36-core CPU, up to an 80-core GPU, and a possible 512GB of unified memory, enabling users to run enormous LLMs entirely on device. You also get Wi-Fi 7 and Bluetooth 6 and Thunderbolt 5, which enables multiple Mac Studio systems to be clustered for the most powerful possible on-prem AI deployments. Pricing starts at $5,499.

You can follow me on social media! Join me on BlueSky,  LinkedInMastodon and subscribe to The Core for the best daily Apple-related news summary in your in-box.

Kategorie: Hacking & Security

Hospital operator Nutex Health says data stolen in cyberattack

Bleeping Computer - 25 Srpen, 2026 - 16:44
Healthcare and services provider Nutex is investigating a data breach incident where an unauthorized third party exfiltrated information from company servers. [...]
Kategorie: Hacking & Security

Ameriku už dvacet let střeží obří plovoucí nafukovací balón. SBX-1 je radar soudného dne

Živě.cz - 25 Srpen, 2026 - 16:34
Pokud byste chtěli sledovat pohyb sousedky za zdí panelového bytu, vystačíte si s malým modulem mikrovlnného radaru za pár stovek z Aliexpressu. Fanoušky americké NBA naopak odkážu na západní výspu Floridy. V tamních lesích nedaleko hranic s Alabamou totiž stojí nejsilnější a nejmohutnější ...
Kategorie: IT News

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

The Hacker News - 25 Srpen, 2026 - 16:07
Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself. The findings were shared with The Hacker News ahead of publication, and the report says Oasis Security reported them to NVIDIA's Product Security Incident
Kategorie: Hacking & Security

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

The Hacker News - 25 Srpen, 2026 - 16:07
Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself. The findings were shared with The Hacker News ahead of publication, and the report says Oasis Security reported them to NVIDIA's Product Security Incident Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

From Fake Workers to Account Recovery: The Growing Identity Verification Risk

Bleeping Computer - 25 Srpen, 2026 - 16:01
Attackers are increasingly targeting the processes used to establish or recover identity rather than attacking the login itself. Specops explains how stronger identity verification can help organizations prevent fake workers and social engineering attacks from gaining legitimate access. [...]
Kategorie: Hacking & Security

Microsoft PowerToys adds Alt+Tab-style switching for an app's windows

Bleeping Computer - 25 Srpen, 2026 - 15:51
Microsoft updated its Windows PowerToys toolset with a new utility dubbed "Window Hopper" that lets users switch between an app's windows more quickly. [...]
Kategorie: Hacking & Security

Linux Hardening, Architecture & Isolation

LinuxSecurity.com - 25 Srpen, 2026 - 15:47
Linux hardening is not the act of enabling every restrictive setting a distribution provides. It is the work of reducing unnecessary exposure, limiting what users and processes can do, separating workloads, and confirming that those controls remain effective as the system changes.
Kategorie: Hacking & Security

WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android

The Hacker News - 25 Srpen, 2026 - 15:19
Meta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help users with both iOS and Android devices sign into their accounts using the phishing-resistant method. The tech giant said more than 1 billion people use a passkey to log into WhatsApp. Support for passkeys was first introduced in Android in October 2023,
Kategorie: Hacking & Security

WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android

The Hacker News - 25 Srpen, 2026 - 15:19
Meta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help users with both iOS and Android devices sign into their accounts using the phishing-resistant method. The tech giant said more than 1 billion people use a passkey to log into WhatsApp. Support for passkeys was first introduced in Android in October 2023, Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

WhatsApp adds stronger two-step verification, multiple passkeys

Bleeping Computer - 25 Srpen, 2026 - 15:00
WhatsApp has started rolling out several new account security features, including support for multiple passkeys and stronger two-step verification. [...]
Kategorie: Hacking & Security

Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode

The Hacker News - 25 Srpen, 2026 - 14:43
Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook, according to VulnCheck's CVE Numbering Authority (CNA) record. The CNA record says the command can run as a local subprocess when the notebook is opened in edit mode. The vulnerability, tracked
Kategorie: Hacking & Security

Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode

The Hacker News - 25 Srpen, 2026 - 14:43
Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook, according to VulnCheck's CVE Numbering Authority (CNA) record. The CNA record says the command can run as a local subprocess when the notebook is opened in edit mode. The vulnerability, trackedSwati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Firefox 157 přinese zapnutou podporu JPEG XL

AbcLinuxu [zprávičky] - 25 Srpen, 2026 - 14:16
Firefox 157 přinese zapnutou podporu rastrového grafického formátu JPEG XL. Založena je na v Rustu napsané implementaci jxl-rs používané i v Chrome a Chromiu.
Kategorie: GNU/Linux & BSD

Hackers breached over 270 Zimbra servers in ongoing attacks

Bleeping Computer - 25 Srpen, 2026 - 14:04
Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability. [...]
Kategorie: Hacking & Security
Syndikovat obsah