Agregátor RSS
LG představila FLiPP OLED: Bez masek, 1,6× vyšší jas nebo 2,4× vyšší životnost
Technologie OLED, přestože na papíře výborná, trpí stále několika neduhy, které se různí výrobci snaží obcházet různými způsoby. Ne vždy s ideálními výsledky. LG však přišla se zajímavým nápadem…
Kategorie: IT News
Evropský wingman: Saab přichází s nadzvukovým doprovodným dronem
Švédská společnost Saab přichází se sexy doprovodným dronem A3-001. A3-001 je nadzvukové autonomní žihadlo typu Loyal Wingmans, které by mělo doprovázet především Gripeny a letouny GlobalEye do úderů proti protiletecké obraně a jiným pozemním či leteckým cílům nebo třeba elektronického boje. První prototyp A1 by měl vzlétnout už v roce 2027.
Kategorie: Věda a technika
Neustále zapnutý displej nevyužil potenciál. Proč se Always On na Androidu zasekl v minulosti
Kategorie: IT News
AI žere knihy. Firmy je skupují, ničí a skenují, aby nakrmily své AI modely
AI firmy kupují starší knihy, skenují je a používají pro trénování modelů • Výhodou je, že tyto knihy napsali lidé, na rozdíl od dnešního webu • Zatímco pirátění je nelegální, zničení koupené knihy projde
Kategorie: IT News
30 nejlepších opravdu dlouhých filmů. Tyhle stojí za celý váš večer
Nejde o soutěž v nejdelší stopáži. Vybrali jsme 30 filmů a filmových celků dlouhých nejméně 165 minut, které si svůj čas dokážou obhájit kvalitou, diváckou oblibou nebo velkolepostí. Od historických eposů přes komorní dramata až po prodlouženou trilogii Pána prstenů.
Kategorie: IT News
Jiná cena v App Storu, jiná v aplikaci. Dejte si pozor na zavádějící ceny předplatného i na třídenní zkušební dobu
Kategorie: IT News
ToxicPanda Android malware uses VPN permissions to block Google Play
The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands. [...]
Kategorie: Hacking & Security
Už i Němci mají dronomet. Rheinmetall je vypouští z náklaďáku jako Ukrajinci při operaci Pavučina
Německé zbrojovce Rheinmetall se zjevně zalíbila loňská operace ukrajinských tajných služeb Pavučina, během které přijely hluboko do ruského týlu nákladní automobily a vypustily hejna sebevražedných dronů. Ty poté zaútočily na tiše stojící strategické bombardéry Tu-95 na nedalekém letišti.
Něco ...
Kategorie: IT News
Velká aktualizace Windows 11 je skoro hotová. Vyzkoušejte vylepšený hlavní panel a nabídku Start
Windows 11 Insider build 26100.9267/26200.9267 přináší velké novinky. • Zlepšuje hlavní panel, nabídku Start nebo vyhledávání. • Sestavení je k dispozici v kanále Release Preview.
Kategorie: IT News
Elektrický bagr LiuGong slibuje oproti dieselu poloviční provozní náklady, nulové emise a tichý chod
Elektrický bagr LiuGong přichází zničit naftovou konkurenci polovičními náklady • Obří baterie zvládne až deset hodin práce a nabije se za dvě hodiny • Tichá kabina a dlouhá záruka zaručí vysoký komfort i spolehlivý provoz
Kategorie: IT News
ChatGPT jednou nahradí všechny aplikace v mobilu. Test 12 běžných úkolů ukázal, kde má zatím slabiny
Kategorie: IT News
Jak jsem ušetřil milion za nový web. Vibecoding v praxi, kde exceluje a na jaké limity narazíte
AI zvládá připravit nejen jednoduché skripty, ale i složitější webové aplikace, za které by firmy chtěly stovky tisíc korun. Vyzkoušel jsem to a někomu jsem možná sebral práci.
Kategorie: IT News
Nechce se vám číst knihu ani koukat na film? Tady jsou nejlepší herní adaptace
Herní průmysl je plný luxusních adaptací známých knih, filmů a komiksů. Vybrali jsme ty nejlákavější!
Kategorie: IT News
Týden na ITBiz: Umělá inteligence se prý nehodí pro tvorbu aktualizací softwaru
HP Envy Photo 7931: Multifunkce, kde nemusíte řešit cenu náplní. ADATA Legend 900 Pro: výkon dražších SSD bez DRAM čipu. 100násobné prodloužení životnosti magnonů otevírá cestu k pokroku kvantových počítačů. Herní aktualizace předstihly sport: rok 2025 ukázal nové vzorce internetových špiček. Prusa vylepšuje svoje 3D tiskárny pro čistší tisk a méně starostí. Umělá inteligence se prý nehodí pro tvorbu aktualizací softwaru.
Kategorie: GNU/Linux & BSD
Velicí krokodýli ovládli potravní řetězec v miocénu Jižní Ameriky
Jak ukazují děsivé hryzance na muzeálních kostech velkých býložravců z přízračného světa obrovských jezer, mokřadů a lagun miocénu severu Jižní Ameriky, vrcholovým predátorem tam byl sedmimetrový a téměř dvoutunový kajman purussaurus, před nímž se třásla tehdejší fauna.
Kategorie: Věda a technika
Fyzici použili kvantové simulátory k testování desítky let starých předpovědí
Konformní teorie pole už dlouho předpovídají univerzální chování fyzikálních systémů v kritických bodech (např. při fázových přechodech) a strukturu spekter kvantových anomálií. Manuel Endres a spol. to poprvé zkusili experimentálně s kvantovými simulátory tvořenými 1D soustavou excitovaných atomů stroncia v laserových optických pinzetách.
Kategorie: Věda a technika
Lepší podpora 3dfx či Atari Falcon, Wine řešící PMD 85
KDE zefektivňuje budoucí Plasmu 6.8 a přidává podporu pro Btrfs snapshoty, vylepšení pro 3dfx Voodoo 3+4+5, podpora pro blížící se Intel Nova Lake již stabilní.
Kategorie: GNU/Linux & BSD
Nové kontextové nabídky ve Windows 11 jsou rychlejší, přizpůsobitelné a bez bloatwaru
Microsoft zahájil testování předělané kontextové nabídky ve Windows 11. • Poprvé v historii si vyberete, co se s v ní má zobrazovat. • K dispozicí je ve Windows 11 Insider Experimental Preview build 26340.9212.
Kategorie: IT News
If you're not using AI to attack your own systems, your adversaries will
AI agents excel at hacking organizations, as they’ve demonstrated in real-life attacks multiple times over the past few weeks. They also expose a whole new attack surface for organizations trying to protect against both human and AI intrusions. As if defenders needed more worries to keep them up at night, agents introduce new data-integration channels that attackers can abuse. They also introduce a new type – and ever growing number – of non-human identities that are difficult to manage and can bypass traditional, static security policies. “There is tremendous risk associated with agentic AI and machine identities,” Matt Hartman, former acting head of cyber of the US Cybersecurity and Infrastructure Security Agency (CISA), told The Register. “As AI moves from generating content – yesterday's use case – to taking actions, it is inevitable that agents are going to receive access to sensitive systems and sensitive data,” Hartman said. “One area where organizations are struggling today is that they're going to need to treat every agent as a privileged identity.” Enterprises also face agentic threats from outside their organization, he added. “AI-enabled or AI-amplified identity and social engineering attacks are increasing significantly by the minute,” Hartman said. “We're seeing very highly personalized phishing, very good impersonation, automated reconnaissance. That really makes traditional indicators of trust increasingly unreliable.” For defenders, this means a “continued focus on strong identity, on phishing-resistant authentication, on behavioral signals, and on zero-trust principles therein,” he added. “Nothing deeply new here - but it is a whole new attack surface.” Meanwhile, on the attackers’ side, agents don’t take time off, and they remain singularly focused on completing a task, whether that’s finding vulnerabilities and exploit chains or mapping networks and identifying sensitive files. All of this makes these near-autonomous attack bots a gift from the heavens for financially motivated criminals and government-backed cyber operatives. It also presents a security use case for defenders: agentic red teaming. As former NSA cyber boss Rob Joyce said during a talk at RSAC: if you aren’t using AI agents to attack your own organizations, you can bet that someone else is. “You are going to be red-teamed whether you pay for it or not,” Joyce said. “The only difference is, you know who gets the results delivered to them.” Hartman echoed Joyce’s words. “What we are seeing as the leading capabilities to help defenders – there is a burgeoning market for continuous, AI-native, AI-enabled, automated red teaming and pen-testing,” he told us. After spending nearly two decades in the federal government at CISA, Hartman joined Merlin Group in October as its chief strategy officer. In his new private-sector role, he helps determine which early- to growth-stage cybersecurity and emerging technology companies the group invests in, and then works with these firms to navigate government, critical infrastructure, and other highly regulated markets. The goal is to integrate and scale “promising technologies” into critical environments, Hartman said. Right now, most of these technologies use AI agents to fight AI agents. “Organizations are just inundated with vulnerabilities, and adversaries are able to leverage AI to find vulnerabilities and exploit them in seconds when it used to take days,” he said. Agentic red teaming “is a category of products that every organization, including federal agencies, absolutely needs in the near term just to keep pace.” 'Largest controlled live AI cyberattack on record' Mandiant founder and former CEO Kevin Mandia has a new company, Armadin, which launched in March with a startling $190 million in seed and Series A funding. The firm builds and trains autonomous attacker swarms – thousands of AI agents that run 24/7 in organizations’ infrastructure to simulate real-life attackers. Ahead of Black Hat earlier this month, the startup said it and Tenex.ai, an agentic security operations provider, executed what they called the “largest controlled live AI cyberattack on record” for an unnamed “leading” global institution. Over the three-day attack, Armadin's swarm generated 17 million offensive actions, discovered 38 validated attack paths, and produced 238 security findings. Tenex.ai's agentic platform separately triaged 100 percent of 101,169 alerts and reconstructed the entire attack across 231 billion raw events. This exercise, we’re told, would have taken a five-person analyst team about 2,400 hours – or four months – to pull off. Co-founder and Chief Offensive Security Officer Evan Peña was the global red-team lead at Mandiant before co-founding Armadin. At Mandiant, he led a 210-person team whose members spanned the globe. “The problem was it was 100 percent human-led security assessments, and that would generally limit the amount of time that we would have,” Peña told The Register. His red team “would do a couple weeks or a one-month engagement, and then we would report on the engagement, give them a PDF file, walk away, and they would hire us again in a year. In today’s age of AI, it’s very archaic to think about that when we can scale so significantly with AI.” Attack yourself before someone else does At Armadin, Peña leads the human team that trains the AI agents. One of the lessons learned from OpenAI’s models autonomously attacking Hugging Face, according to Peña, is that organizations need to perform safe offensive AI attacks against their own systems. "Safe" is the keyword here: remember OpenAI’s rogue models intentionally didn’t have any guardrails in place. Yes, his statement is self-serving as it's core to Armadin's business. But he’s not wrong. “Organizations can cover so much more attack surface because we are able to leverage these agents at scale, and we have three things that we didn’t have before,” he said. “We have more time, because agents don’t sleep and they don’t take holidays. There’s no workforce requirements for them.” Number two, he said, is expertise. Attack agents need pre-training before they are set loose on organizations’ infrastructure. They need to know how to code, and perform source-code review. They need to know how to do application security, how to spot network misconfigurations, and hack into different systems and networks. “And then you add post-training to that from human expertise,” Peña said. “Number three is coverage,” he said. “We were only able to cover a finite amount of attack surface in the past. So if you had 10,000 external systems with a limited amount of time and humans, you could maybe cover 2,000 or 1,000 of those within that particular period of time. Now we can cover all 10,000 in probably hours.” Armadin’s AI agents have broken into every single customer’s environment, according to Peña. “We have found over 50 zero-days, and by zero-days, I don't just mean this zero-day allowed you to deface a web page. That’s cool, but I want to break into your network from the internet,” he said. “The zero-days I'm referring to allow an attacker to get remote code execution on an actual system. They're very high-impact zero-days. We don't care about noise, we care about impact.” Quarterly pen-testing doesn't cut it anymore The biggest challenge these days for defenders is the scale and speed AI brings to previously manual attackers’ dirty work – like scoping potential victims, performing reconnaissance, identifying vulnerable systems and exploits, and reading logs. Now all of these tasks can be automated. Penetration testing needs to keep up, Jay Bavisi, founder and group president of EC-Council, told The Register. The largest and best organizations do pen-testing once a year to meet compliance requirements, and “the better ones” run these exercises quarterly, Bavisi said. This is largely because human-led pen-tests take about three months. “So you have a serious problem with speed,” he said in an interview. “Then comes the second problem, which is scope. Nobody pen tests the entire organization.” There’s also what Bavisi calls a “sophistication problem,” because different human pen-testers will produce varied results, and organizations can’t hire hundreds of thousands of humans to try to break into their networks on a continuous basis. “The bad guys are already using AI to get rid of the speed problem. You pen-test once a year for compliance. They do it all the time because you're a gold mine. They don't have a scope problem because they're not just looking at the crown jewels - they're looking at your entire organization. And they don't have a sophistication problem because they're using algorithmic systems.” In June, the global cybersecurity training organization began offering pen-testing professionals a sponsored attempt to take the CPENT AI examination, and upskill themselves for the AI era. For every participant who passes, the council donates $1,000 in cybersecurity training and certification credits to nonprofit partners. For every completed training program, regardless of an exam pass or fail, the nonprofits get $250, and all of this has a $1 million max. “The traditional model of pen-testing once a year or once a quarter, that’s going away, and AI will take over with automated pen-testing,” Bavisi said. “But will the role of pen testers vanish? No, it will not. It will evolve into something much bigger and something far more important.” AI systems and AI-integrated applications mean there’s a lot more for security professionals to try to break and break into, and humans need to determine: What is the result of this system breaking? What’s the business impact? What do I prioritize fixing? “The present pen-testers have to be reskilled into understanding business impact and being able to make those important engineering decisions,” Bavisi said. Meanwhile, “offensive AI security professionals are the ones that are going to have to test the robustness of AI systems, because AI systems will become the heartbeat of organizations,” he added. “Pen-testers have to become masters of testing LLMs, understanding agentic behavior, thinking about what is the harm taxonomy, figuring out what kind of guardrails did we put in place.” The job of pen-testers has changed, in other words. “It now has a far wider scope.” ®
Kategorie: Viry a Červi
Čína ztrácí výsadní postavení ve výrobě elektroniky. Google, Apple a Samsung hledají nové základny
Google do roku 2027 přesune výrobu Pixelů do Indie a Vietnamu • Samsung opustil čínský trh už roku 2019 a uspěl ve Vietnamu a Indii • Apple rozšiřuje své kapacity v Indii kvůli celním a politickým rizikům
Kategorie: IT News
- « první
- ‹ předchozí
- …
- 78
- 79
- 80
- 81
- 82
- 83
- 84
- 85
- 86
- …
- následující ›
- poslední »



