Agregátor RSS

Microsoft to China: So long, it’s been good to know ya….

Computerworld.com [Hacking News] - 25 Srpen, 2026 - 13:00

Once upon a time Microsoft was bullish on China. 

Back in early 2010, when Steve Ballmer was CEO and Bill Gates was Chairman, Google was threatening to pull out of China because of Chinese censorship and because of what the company called Chinese government-sponsored cyberattacks. Google wasn’t alone. Other tech companies — as well as politicians like then-House Speaker Nancy Pelosi — were saying the same things.

Microsoft, though, was having none of it. 

Ballmer told Reuters back then, “We’re attacked every day from all parts of the world and I think everybody else is, too. We didn’t see anything out of the ordinary.”

Reuters asked Ballmer whether the company would pull out of China, and Ballmer bluntly said, “No,” adding, “I don’t understand how that helps anything. I don’t understand how that helps us and I don’t understand how that helps China.”

There was, of course, an ulterior motive to Ballmer’s defense of its China relationship. Google’s search engine was dominant across the world, and Microsoft’s Bing couldn’t catch up. Ballmer hoped Bing would make inroads into the Chinese market and eventually overtake Google worldwide.

That didn’t happen, of course. It likely never will. 

Today, though, Microsoft has all but abandoned China. And that doesn’t look like it will change. Here’s why.

Microsoft hangs up the ‘Closing’ sign

First, let’s look at the ways Microsoft’s relationship with China has withered.

In the past five years, Microsoft has closed at least 15 offices and joint ventures with China, Reuters reports. The story claims the actions are part of a careful plan, adding, “Microsoft is pursuing what five company sources described as a strategy of retreat” from China.

24/7 Wall St. reports that among those now-closed joint ventures is Wicresoft, Microsoft’s first such venture in China. An estimated 2,000 jobs were lost in China as a result of the closing.

Microsoft is also moving much of its manufacturing out of the country. Most of its Surface, Xbox and hardware production will leave China, as will server-related manufacturing for data centers.

There are other signs of a retreat. In 2024, Microsoft closed all of its authorized Chinese retail stores and began selling its products via third-party and online partners. It’s also been reducing its Chinese headcount. According to 24/7 Wall St., “Around June 2026, Microsoft cut an estimated 200 to 400 Azure cloud jobs in China, its third downsizing round in two years.”

How did Microsoft get here?

This didn’t happen all at once. It’s been a long, gradual process, the result of geopolitical tensions between the US and China and the worsening business climate between the two countries.

Microsoft began engaging with China more than 30 years ago, in 1994 when Gates first visited the country. After that the company “made various efforts to build a relationship with the ruling Communist Party,” Reuters reported, including co-investments in startup incubators. 

Over time, Microsoft moved some manufacturing to China, opened Microsoft stores there, and pushed the Chinese government to buy Windows and other software. In 2014, Microsoft launched LinkedIn in China, agreeing to comply with the government’s censorship demands even as other companies like Google refused. 

But the relationship deteriorated in the mid-2010s as China soured on its relationships with US and western tech firms, believing they were spying on the Chinese government. To assuage Chinese fears, Microsoft built a version of Windows specifically for the Chinese government, called Windows 10 China ​Government Edition. (According to Reuters, current Microsoft CEO Satya Nadella personally handled the negotiations with the Chinese government for the OS.)

It flopped. Only a handful of Chinese government agencies purchased it, and in 2017 China established government procurement guidelines that largely froze it out.

Things went downhill from there. In 2021, Microsoft shuttered LinkedIn in China when China increased its censorship demands.

The current and future state of the relationship

So where are we now? Despite that “strategy of retreat” described by Reuters, Microsoft officially denies it’s backing away. But the company also said that as of 2024, only 1.5% of its revenue comes from China. That figure is probably even lower now. 

There’s one current bright spot in Microsoft’s Chinese relationship — the use of Azure to provide Chinese companies with AI services and infrastructure, notably TikTok owner ByteDance and fashion retailer Shein. 

But even that is at risk, because of increasingly powerful AI models in China like Kimi, which are less expensive than Microsoft’s and other US technologies.

What does this mean for the future? Expect Microsoft to gradually close more of its Chinese operations. Azure will likely be replaced by Chinese home-grown tech. Microsoft’s already shrunken income from China will shrink even more.

And that’s a good thing. Having a big presence in China — or even a small one — means making a deal with the devil by kowtowing to Chinese censors. It’s time Microsoft made the break-up complete.

Kategorie: Hacking & Security

Police arrests dozens of suspects in global cybercrime crackdown

Bleeping Computer - 25 Srpen, 2026 - 12:53
Law enforcement agencies from 22 countries helped identify 263 suspects and arrested 58 individuals linked to cybercrime networks coordinated by African crime groups. [...]
Kategorie: Hacking & Security

Tesla ruší solární tašky. Konec krásného snu, odteď už jen ošklivé černé panely

Živě.cz - 25 Srpen, 2026 - 12:45
Ta myšlenka je geniálně jednoduchá. Proč pokrývat střechu a pak na ni instalovat solární panely, když lze integrovat fotovoltaiku přímo do střešní krytiny? „Je to hezčí, lehčí a levnější řešení než kombinace obyčejné tašky a solárního panelu,“ sliboval Elon Musk v říjnu 2016, když představoval ...
Kategorie: IT News

CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw

The Register - Anti-Virus - 25 Srpen, 2026 - 12:43
The US Cybersecurity and Infrastructure Security Agency (CISA) just dished out another three-day deadline for patching an actively exploited vulnerability, the most urgent in its wheelhouse. The culprit: a max-severity Oracle bug affecting Windows VMs. Tracked as CVE-2026-21962 (10.0), the improper access control (CWE-284) flaw affects Oracle’s HTTP Server and WebLogic Server Proxy Plug-in. Successful attacks targeting CVE-2026-21962 can allow miscreants to create, delete, or modify access to critical data, and even gain “complete access” to all data stored on the affected systems. Oracle disclosed and provided patches for CVE-2026-21962 as part of its January 20, 2026, updates. At the time, it said versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0 were affected, and that the vulnerability could be exploited in low-complexity attacks. CISA added CVE-2026-21962 to its Known Exploited Vulnerability (KEV) catalog on August 24, giving federal civilian executive branch (FCEB) agencies three days to protect themselves against attacks – the tightest deadline it is authorized to set. Other bugs to have recently been given the three-day treatment include the critical remote code execution (RCE) flaw affecting Python scaling framework Ray. Despite being disclosed in 2025, CISA added it to the KEV catalog last week. N-able’s “god mode” vulnerability, the one that offered attackers "full administrative access to an N-central console" and was exploited as of July 31, according to the vendor, was also lumped with a three-day deadline when CISA added it to the KEV catalog on August 3. Although CISA only added Oracle’s CVE-2026-21962 to the KEV Catalog on Monday, seven months after it was first disclosed, reports from the private sector suggest attackers had the bug in their sights much earlier in the year. Vikas Kundu, cyber intelligence analyst at CloudSEK, operated a honeypot for 12 days between January 22 and February 3, shortly after CVE-2026-21962 was first disclosed and public exploit code was released. The honeypot captured attacks attempting to exploit the vulnerability, as well as other WebLogic RCE bugs dating back to 2020 and 2017. “The overall activity was characterized by high-volume, automated scanning, with tools like libredtail-http and the Nmap Scripting Engine dominating the malicious traffic,” he said. “Furthermore, the logs revealed significant background noise, including attempts to exploit non-WebLogic-specific vulnerabilities (e.g., Hikvision CVE, PHPUnit RCE, and generic command injections), indicating a broad ‘spray and pray’ approach by threat actors.” Kundu said the findings demonstrated “the critical and immediate need for organizations to prioritize patching” the vulnerability at the time. ®
Kategorie: Viry a Červi

Perovskitová fotovoltaika snad konečně zamíří na naše střechy. V testu překonala křemík a láme rekordy ve výrobě elektřiny

Živě.cz - 25 Srpen, 2026 - 11:45
Čínský perovskitový modul porazil v testu tradiční křemíkovou technologii TOPCon • Pasivace karboxyláty olova výrazně zvyšuje odolnost panelu vůči extrémní vlhkosti • Testované panely úspěšně splnily mezinárodní normy pro komerční nasazení
Kategorie: IT News

Crooks push Mac malware through fake OpenAI Codex ads

The Register - Anti-Virus - 25 Srpen, 2026 - 11:15
Cybercrims are using fake OpenAI Codex download pages to trick Mac developers into running malware disguised as installation commands. Researchers at Cato Networks uncovered the campaign after spotting sponsored Google search results targeting people looking to download Codex for macOS. The ads direct would-be users to a convincing-looking download page hosted on Google Sites, complete with the familiar OpenAI branding. There is, however, no Codex waiting at the other end. Instead of serving up an installer, the fake site tells Mac users to open Terminal, paste in a supplied command, and run it. The instructions are dressed up as part of the installation process, but the command quietly kicks off a multi-stage malware infection. It's a variation of the increasingly popular "ClickFix" technique, in which attackers convince victims to execute malicious commands themselves rather than relying on a dodgy attachment or executable to do the dirty work. In this case, the command begins with what appears to be a legitimate npm instruction for installing Codex. Tacked onto it, however, is code that decodes a Base64-encoded URL, fetches an attacker-controlled shell script and pipes it into zsh. That script pulls down another stage, which contacts the attacker's server to report that someone has taken the bait before downloading a Mach-O executable to “/tmp/helper.” It then removes security information macOS uses to flag suspicious downloads, helping the malware dodge the usual warnings before it launches. Cato said the final binaries are universal Mach-O files, meaning they can run natively on both Intel-powered Macs and newer Apple Silicon machines. The researchers found substantial similarities between the campaign and Atomic macOS Stealer, better known as AMOS, an infostealer previously spread through fake software downloads and malicious advertising campaigns. Cato isn't quite ready to slap an AMOS label on the malware, but says plenty of fingerprints point in that direction, from how the attack is staged to how the final payload is built. The crooks have also taken steps to keep researchers from getting a good look at their handiwork. Although victims initially land on Google Sites, the malicious content itself is pulled into the page from attacker-controlled infrastructure using an iframe. That infrastructure checks details including the visitor's operating system and the path used to reach it, allowing it to show harmless-looking content when a visitor doesn't fit the profile the attackers are after. Cato said the decoy site offered both macOS and Linux download buttons, although it only observed the malware chain being delivered to Mac users. Codex isn't the only AI coding assistant getting this treatment. During its investigation, Cato found a similar ClickFix page masquerading as Anthropic's Claude Code and sharing infrastructure with the Codex campaign. The attackers don't have to work particularly hard to find their victims, either. Developers searching Google for Codex do that work for them, with sponsored ads pushing the fake download page above the legitimate results. ®
Kategorie: Viry a Červi

Videím na YouTube budou rychleji přibývat zhlédnutí. Google je započítá hned po stisku Play

Živě.cz - 25 Srpen, 2026 - 10:45
YouTube od včerejška změnil způsob, jakým pracuje veřejné počítadlo zhlédnutých videí. Nově se za zhlédnutí považuje samotné spuštění, stačí tedy zobrazit jeden snímek videa. V minulosti se video započítalo jako zhlédnuté až po určité době sledování. Google to nikdy neupřesnil, ale spekuluje se o ...
Kategorie: IT News

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

The Hacker News - 25 Srpen, 2026 - 10:34
Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators. The vulnerabilities, as disclosed by Patchstack, are listed below - CVE-2026-61979 (CVSS score: 8.1) - An unauthenticated privilege escalation
Kategorie: Hacking & Security

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

The Hacker News - 25 Srpen, 2026 - 10:34
Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators. The vulnerabilities, as disclosed by Patchstack, are listed below - CVE-2026-61979 (CVSS score: 8.1) - An unauthenticated privilege escalation Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Windows 11 po aktualizaci na RGB sestavách padají, zejména ve hrách

CD-R server - 25 Srpen, 2026 - 10:00
Asi málokdo by čekal, že když mu z ničeho nic začnou na PC padat hry, může být na vině bezpečnostní záplata na Windows 11 v kombinaci s ovladačem RGB podsvícení. Ale stalo se…
Kategorie: IT News

O sedm tisíc levněji než u Applu. Jestli chcete MacBook Air M5 za 27 990 Kč, spěchejte

Živě.cz - 25 Srpen, 2026 - 08:45
Mall nabízí MacBook Air M5 za 27 990 Kč, Apple si účtuje 34 990 Kč. • Jde o základní verzi s 16GB RAM, 512GB SSD a v hvězdně bílé barvě. • Nabízí skvělý výkon, celodenní výdrž a rychlejší síťový modul.
Kategorie: IT News

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

The Hacker News - 25 Srpen, 2026 - 08:12
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-21962 (CVSS score: 10.0), allows an unauthenticated attacker with network access via HTTP to
Kategorie: Hacking & Security

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

The Hacker News - 25 Srpen, 2026 - 08:12
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-21962 (CVSS score: 10.0), allows an unauthenticated attacker with network access via HTTP to Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Srážky letadel s ptáky jsou problém. Zjistili jsme, proč se nepoužívají mřížky před motory

Živě.cz - 25 Srpen, 2026 - 07:45
Ochranné mřížky před motory letadel vytvářejí námrazu i hrozbu úlomků • Turbulence způsobené zábranou výrazně snižují výkon pohonné jednotky • Dnešní mezinárodní předpisy vyžadují odolnější konstrukce leteckých motorů
Kategorie: IT News

Valve slaví 30, na Half Life 3 se stále čeká (+časová osa jako od Evy Decroix)

CD-R server - 25 Srpen, 2026 - 07:40
Společnost Valve tento týden slaví 30. výročí od svého založení v roce 1996. V první dekádě vydala řadu herních trháků, ale později to začalo drhnout a dnes funguje spíše díky platformě Steam…
Kategorie: IT News

Five things to look for when buying a laptop for your small business

Computerworld.com [Hacking News] - 25 Srpen, 2026 - 05:02

For most of the last two decades, a business laptop lived on a worker’s desk and rarely left the building. Today that assumption no longer holds. According to Gallup, more than three-quarters (78%) of employees now work fully or partially remotely.

Gartner expects businesses to keep computing devices roughly 15% longer than in recent years, due to cost, so the hardware that SMBs buy now has to hold up over a longer stretch of use. Gartner also projects that AI PCs will make up more than half of all PC sales in 2026, so durability and mobility increasingly need to coexist with the higher processing power that on-device AI requires.

A laptop designed for a stationary desk job is not built for that kind of movement, so small business owners buying their next round of hardware need a different checklist. Here are five things worth evaluating before the next purchase.

  • Powerful processing: How many applications and browser windows do you have open at any given time? Probably dozens. Running multiple applications simultaneously requires a powerful processor to prevent laggy navigation and sluggish performance.
  • Built-in ruggedness: Laptops that travel get dropped, jostled, and occasionally splashed with coffee. Eight out of 10 SMBs say that at least some of their employees drop or roughly handle their devices, and one-quarter frequently experience significant downtime due to hardware malfunctions, according to the ASUS Future of SMB Report. Features that used to be considered upgrades — such as reinforced chassis, spill-resistant keyboards, and components rated for temperature and impact tolerance — should now be considered standard for all business laptops.

    Additionally, a laptop that leaves the office will be removed and then plugged into many different monitors, docks, and peripherals. Ports that wear out after light use can create serious support headaches, so look for connections built to withstand frequent insertion.
  • Battery life for work on the move: Employees working from coffee shops, trains, and shared workspaces cannot always count on a convenient outlet. Laptop batteries need to support a full day of work, not just a few hours.
  • Lightweight design: No one enjoys carrying around a heavy laptop, especially employees who travel frequently with their machine. A lightweight design is a must for machines on the move.
  • Displays built for comfort: Employees now work under office lighting, home lighting, natural light, and everything in between. A bright, high-contrast display with strong color accuracy reduces eyestrain across those environments and keeps people productive later into the day.

The ASUS ExpertBook Ultra has been designed to meet all of these criteria. Its lightweight magnesium-aluminum chassis is highly resistant to everyday wear and tear. It’s also more than tough enough to withstand a short fall or a beverage mishap, and with 26 hours of battery life and rapid charging, employees won’t waste time searching for an outlet.And because it’s powered by an Intel® Core™ Series 3 processor, the ExpertBook Ultra provides rock-solid performance while running multiple compute-heavy apps.

Choosing the right laptop has become a strategic decision rather than a routine purchase. Small businesses that build their hardware standards around durability, mobility, and display comfort will spend less time managing broken devices and more time letting their teams work from wherever the job takes them.

Learn more about ASUS’s laptops designed for business.

Kategorie: Hacking & Security

Vanilla OS 3 „Reunion“

AbcLinuxu [zprávičky] - 25 Srpen, 2026 - 02:16
Vanilla OS 3 „Reunion“ byl vydán. Tato na Debianu „Sid“ založená desktopová distribuce s transakčními aktualizacemi „neměnného“ základního systému (ABRoot) nově podporuje architekturu arm64 (vedle x86-64), podporuje reprodukovatelné sestavení většiny balíčků a vylepšuje systémové nástroje. Vlastní meta-správce balíčků APX nyní používá Distrobox v2 a je dostupný i pro jiné distribuce.
Kategorie: GNU/Linux & BSD

[remote] CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE

The Exploit Database - 25 Srpen, 2026 - 02:00
CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE

Unitree Claims New Humanoid Robot Outruns Usain Bolt

Singularity HUB - 25 Srpen, 2026 - 00:52

The flashy company, which recently completed a blockbuster IPO, appears to be leading the pack of humanoid robot makers.

Increasingly, companies are building humanoid robots that perform impressive athletic feats to mark the field’s progress. Now, Chinese robotics company Unitree says its new “Superman” robot can run 12.66 meters per second, faster than Usain Bolt’s top recorded speed.

Getting a humanoid robot to run at all requires split-second control and has been a significant engineering challenge occupying roboticists for decades. That’s why sprinting, as well as jumping, have become popular targets for robotics companies keen to demonstrate their technology’s prowess.

Unitree’s latest demonstration pushes the boundaries by not only outrunning the fastest human ever, but also jumping around 6 feet 7 inches into the air from a standing start, a full foot more than the human record.

“This new machine has only been in development for a little over three months, with significant room for further improvement in the coming months,” Unitree said in an X post that accompanied a video of the accomplishments.

The records have not been externally verified, and the sprinting speed was a peak reading taken over a shorter stretch rather than a full 100 meters like Bolt’s record. The robot’s legs are also only 2 feet 9 inches long, according to Unitree, which results in an ungainly, arm-waving gait while running.

The effort is nonetheless impressive and adds to Unitree’s growing reputation as the company leading the pack of humanoid robot developers. And the timing of the announcement was no accident, coming just days before Unitree’s stock market debut and shortly before the World Humanoid Robot Games, which opened on August 22.

The company’s Shanghai IPO was a blockbuster, recording an initial 629 percent gain on the company’s first day of trading. It was briefly valued at around $66 billion before closing at a more modest $51 billion. However, some analysts have cautioned the excitement around the company’s technology may be getting ahead of market realities.

“The IPO is expensive, and the investment ​risk is already ​quite high,” ⁠Wang Zhuo, partner of Shanghai Zhuozhu Investment Management, told Reuters. “Unitree generates much of its sales from research and demonstrations, but ​wider application is still far away.”

But the company holds a dominant grip on the emerging humanoid market that may justify some of the hype. Chinese firms control roughly 90 percent of the global humanoid robot market, with Unitree alone shipping 5,500 of the 13,000 to 18,000 humanoids sold worldwide in 2025, the most of any manufacturer. In contrast, US humanoid champions Figure AI, Agility Robotics, and Tesla each shipped around 150 units.

China’s success is down to “a combination of policy support, public investment, mature supply chain, and advancements made in AI software and hardware,” Lian Jye Su, a tech analyst at consultancy firm Omdia, told Rest of World.

This is leading to an increasingly combative response from the US. On July 29 the Federal Communications Commission banned new imports of foreign-made humanoid and quadruped robots. The move was framed as a matter of national security, though it has also been seen as an attempt to give domestic developers a leg up.

Beijing predictably objected, with foreign ministry spokesperson Mao Ning telling a press conference that “protectionism does not make the US more competitive, and it will only hurt the interests of US companies and consumers.”

Given the rapid progress made by companies like Unitree, it seems likely it’s going to take more than trade barriers for the US to catch up. In the meantime, we might see more human athletic records fall to China’s leading humanoid developers.

The post Unitree Claims New Humanoid Robot Outruns Usain Bolt appeared first on SingularityHub.

Kategorie: Transhumanismus
Syndikovat obsah