EPFL développe plateforme d'IA souveraine open source hébergée sur ses infrastructures à Lausanne; plus de 130 modèles open-weight disponibles

EPFL développe plateforme d’IA souveraine open source hébergée sur ses infrastructures à Lausanne; plus de 130 modèles open-weight disponibles Une IA souveraine au service de la communauté EPFL - EPFL Une IA souveraine au service de la communauté EPFL Voulez-vous vraiment importer cet article dans ? Cet article sera envoyé à ses abonné·es. Afin d’éviter les services d’intelligence artificielle commerciaux, l’EPFL a développé sa propre plateforme d’IA open source, entièrement hébergée sur ses infrastructures. Un an après son lancement, cette solution permet aux chercheurs, aux enseignants et au personnel administratif d’exploiter des outils d’IA performants de manière sécurisée, efficace et en conservant la maîtrise de leurs données. ...

August 12, 2026

EPFL's open-source AI inference platform on campus; Integrates with Swiss AI Research Platform

EPFL’s open-source AI inference platform on campus; Integrates with Swiss AI Research Platform Sovereign AI for the EPFL Community - EPFL Sovereign AI for the EPFL Community Import & publish the news Are you sure you want to import this news into ? This news will be sent to its subscribers. Instead of relying on commercial AI services, EPFL has built its own open-source AI platform, running entirely on campus infrastructure. One year after its launch, it is helping researchers, teachers and staff use powerful AI tools securely, efficiently and while keeping control of their data. ...

August 12, 2026

Bundesrat nimmt Bericht Informationssicherheit Bund 2025 in Bern zur Kenntnis; keine schweren Vorfälle 2025

Bundesrat nimmt Bericht Informationssicherheit Bund 2025 in Bern zur Kenntnis; keine schweren Vorfälle 2025 Informationssicherheit beim Bund 2025: Bericht zeigt Fortschritte auf Medienmitteilung Veröffentlicht am 12. August 2026 Informationssicherheit beim Bund 2025: Bericht zeigt Fortschritte auf Bern, 12.08.2026 — Der Bundesrat hat an seiner Sitzung vom 12. August 2026 den Bericht «Informationssicherheit Bund 2025» zur Kenntnis genommen. Die Bundesverwaltung hat bei der Umsetzung des Informationssicherheitsgesetzes weitere Fortschritte erzielt. Vorangetrieben wurden insbesondere der Aufbau einer kohärenten Sicherheits- und Lieferkettengovernance, die Ablösung veralteter Systeme sowie die Stärkung der Resilienz gegenüber Cyberbedrohungen. Es waren keine schwerwiegenden Vorfälle zu verzeichnen. ...

August 12, 2026

Bundesrat nimmt Bericht Informationssicherheit Bund 2025 in Bern zur Kenntnis; keine schwerwiegenden Vorfälle 2025 verzeichnet

Bundesrat nimmt Bericht Informationssicherheit Bund 2025 in Bern zur Kenntnis; keine schwerwiegenden Vorfälle 2025 verzeichnet Informationssicherheit beim Bund 2025: Bericht zeigt Fortschritte auf Medienmitteilung Veröffentlicht am 12. August 2026 Informationssicherheit beim Bund 2025: Bericht zeigt Fortschritte auf Bern, 12.08.2026 — Der Bundesrat hat an seiner Sitzung vom 12. August 2026 den Bericht «Informationssicherheit Bund 2025» zur Kenntnis genommen. Die Bundesverwaltung hat bei der Umsetzung des Informationssicherheitsgesetzes weitere Fortschritte erzielt. Vorangetrieben wurden insbesondere der Aufbau einer kohärenten Sicherheits- und Lieferkettengovernance, die Ablösung veralteter Systeme sowie die Stärkung der Resilienz gegenüber Cyberbedrohungen. Es waren keine schwerwiegenden Vorfälle zu verzeichnen. ...

August 12, 2026

GoldDigger Android banking trojan South Africa and the United Kingdom; massive infection across South Africa and United Kingdom

GoldDigger Android banking trojan South Africa and the United Kingdom; massive infection across South Africa and United Kingdom Striking gold: Inside the GoldDigger Android malware | IBM Get hands-on experience with IBM tech Join one of the largest technical IBM community gatherings! IBM Trusteer’s in-depth analysis of GoldDigger malware reveals how this sophisticated Android mobile banking Trojan uses virtual environments and evasion techniques. Learn to recognize the threat and protect yourself from bad actors. IBM Trusteer researchers consistently investigate financial fraud threats across various digital channels, including mobile. In our latest mobile banking malware research, we explored the GoldDigger malware’s inner workings. This malware was first discovered by Group-IB, in 2023. Although it was detected three years ago, an in-depth technical analysis has not been publicly shared with the community until now. GoldDigger is a financial Android banking trojan from the RAT category that can perform on-device fraud. The malware is primarily focused on mobile banking users in South Africa, with additional targets identified across Europe. Artifacts observed both in the code and in the target list from the configuration indicate a clear intent to expand operations on a global scale. This blog provides our findings about the newest version of GoldDigger, with insights about its virtual environment feature and the capabilities that help cyber criminals use it in mobile banking fraud. While the use of a virtualized environment was first observed in the GodFather malware, they remain uncommon among financial malware, which typically utilizes overlay or accessibility abuse for fraudulent activities. GoldDigger uses a sophisticated packer called “dpt-shell”. A packer is a software protection mechanism that compresses, encrypts, or obfuscates an application’s code and resources, making it difficult for security tools and researchers to inspect its contents. This packer is used to hide the malware’s code, prevent analysis, evade detection by antivirus and security solutions, and conceal the malware internal functionality. The packer is implemented inside a native shared library (.so) file called “libdpt.so” and located in the malware’s assets directory. In contrast to many Android malware packers, this one does not simply drop and load the protected DEX file at runtime. At a first glance, we can see that the malware builds a path to drop the DEX file inside its private directory: And indeed, several DEX files were observed being dropped to this path while running the malware: However, when trying to read the code inside the DEX files, some methods are not complete and are filled with junk code: Analysis of the packer revealed that the malware hooks libart.so, the core Android Runtime (ART) library. This allows the malware to intercept class loading, modify bytecode at runtime and hide malicious classes from analysis. To bypass this protection and extract the hidden code, dynamic analysis can be useful. However, the malware implements multiple evasion techniques in the packer. Some examples include: 1. The packer’s native logic is encrypted using RC4, a symmetric encryption stream cipher, with a different key for each sample and decrypted at runtime. Therefore, it must first be decrypted before static analysis can be performed. 2. The packer can detect whether Frida is attached to the process, then proceed to crash it. 3. Another anti-debugging technique employed is self‑debugging, using the PTRACE system call. By invoking ptrace(PTRACE_TRACEME) on itself, the process marks itself as being traced. A process can only be traced by a single debugger at a time, so this prevents any external debugger from attaching. After decrypting and patching the packer, we were able to successfully extract the hidden code during runtime. The current GoldDigger campaign primarily impersonates airline companies, as well as shopping retailers. The campaign resulted in a massive infection across many users, mostly in South Africa and the United Kingdom. When the malware is initially executed, it displays a fake login page. This page is crafted to mimic a legitimate company interface, as part of its social engineering strategy. After the victim registers as a new user or enters their real account credentials, the malware requests the victim to approve its Accessibility service. Once approved, the malware displays a screen asking the user to claim their rewards: The malware then registers the victim to the command-and-control (C&C) server by sending information about the mobile device and the password entered by the victim on the login page. The C&C server will send the configuration to the malware, including the list of targeted banks, and a token that will be used to communicate with the C&C. This configuration will be stored in the malware’s shared preferences XML file. The Android Accessibility service is a legitimate Android framework that is designed to assist users by granting apps the ability to read screen content, simulate clicks and interact with other apps. Financial malware such as GoldDigger exploits this service to perform fraudulent actions. GoldDigger can inject input to the banking app to mimic user interaction, such as entering text, clicking buttons and performing gestures. In doing so, GoldDigger initiates fraudulent transactions from the victim’s banking app to the attacker. In addition, the fraudster can see the content of the victim’s screen. When the victim opens a banking app from the configuration list, the malware uses the Accessibility service to steal the credentials from the login page. In addition, the fraudster can see the content of all SMS messages that are sent to the user and steal the 2FA SMS messages. GoldDigger is also capable of displaying an overlay dialog on the screen, with content dynamically retrieved from its C&C server. Code analysis suggests this dialog presents a phishing page mimicking a targeted bank’s login screen to harvest victim credentials. This approach is consistent with traditional overlay-based phishing attacks that are commonly used in mobile banking malware. A unique capability of GoldDigger, is its ability to run a targeted app in a virtual environment, per C&C demand. A virtual environment application in Android is an app that creates an isolated runtime environment inside the device (within the scope of the virtual app itself), where other apps can be installed and executed independently from the main OS environment. Inside the virtual environment, system API calls can be intercepted and modified by the virtualization framework. For example, if an app calls While virtual environments can be used for legitimate features like app cloning, financial malware often abuse them for fraudulent activities. The malware can intercept and modify all API calls made by the targeted app within the virtual environment, enabling it to bypass detection mechanisms and spoof device identifiers or account information. In addition, the attacker obtains full visibility into its runtime behavior, enabling real-time interception of credentials and sensitive data. In the GoldDigger malware, the C&C sends the package name of the app that needs to be running inside the virtual environment, and a service in the malware handles the virtualization. While some of the service logic is implemented within the GoldDigger malware, part of the functionality is missing and may be delivered via the C&C server or another application. At the time of writing, we were unable to retrieve the missing component. Here, the GoldDigger manifest references the package name of the missing virtualization component: In a normal Android flow, an app communicates with the real Android system services through Binder IPC. From here, it receives the actual device state, such as the real list of installed applications. However, in a virtualized environment things work differently. API calls are redirected through a virtualization layer that intercepts and modifies responses, returning fake or filtered information to apps running inside the virtual space. Our analysis of the GoldDigger sample, led to the identification of the Binder communication layer (IThirdPartyService, Proxy and Stub interfaces) used to communicate with the virtualization engine. However, the actual virtualization service and the fake system API logic appear to be missing and are likely implemented in the external net.yy.vwork component. To communicate with the attacker’s C&C server during its ongoing operations, GoldDigger uses the WebSocket protocol. Each request contains a token generated by the C&C and is received from the malware’s first registration. The requests and responses are encrypted with standard AES and a key embedded within the malware code. The malware sends “keep-alive” requests to the C&C system and parses the response, which is returned as a JSON file containing a command number and relevant parameters. Each command comes with code, triggering a malware capability. To protect yourself, you should regularly review your installed applications and promptly remove any that appear unfamiliar or suspicious. Remaining proactive and cautious will help mitigate risks posed by this evolving attack paradigm. In this blog, we’ve analyzed a new version of the GoldDigger malware. We’ve examined the malware’s virtualization capabilities and their potential use in mobile banking fraud. In addition to these virtualization capabilities, we’ve seen how GoldDigger also leverages overlay attacks and the abuse of the Android Accessibility service to facilitate fraudulent actions. The IBM Trusteer lab will continue to monitor and research the malware to track its ongoing evolution and emerging capabilities. IBM Trusteer helps you detect fraud and malware, authenticate users and establish identity trust across the omnichannel customer journey. Hundreds of leading organizations rely on IBM Trusteer to help secure their customers’ digital journeys and support business growth. Special thanks to Camila Sablotny for her valuable help with the investigation. Join security leaders who rely on the Think Newsletter for curated news on AI, cybersecurity, data and automation. Learn fast from expert tutorials and explainers—delivered directly to your inbox twice weekly. See the IBM Privacy Statement.

August 12, 2026

IBM and partners move AI from pilot to production at LEAP 2026; scalable, secure AI for business.

IBM and partners move AI from pilot to production at LEAP 2026; scalable, secure AI for business. IBM at LEAP 2026 From AI experimentation to AI-Powered productivity As Saudi Arabia accelerates Vision 2030 and AI ambitions, organizations are looking beyond experimentation to deliver measurable business outcomes. At LEAP 2026, IBM and our Partners showcase how enterprises can move AI initiatives from pilot to production by combining AI agents, trusted data, intelligent automation, and hybrid cloud. As the partner of choice for Saudi and regional organizations, IBM aims to transform AI investments into scalable, secure, and business-ready solutions that drive productivity, innovation, and growth. Ready to turn AI ambition into business impact? Meet us and our Partners at the IBM at LEAP 2026 or request a meeting with IBM executives and SMEs. Step into the future with IBM and our Partners at stand H1 C50. Discover cutting-edge solutions, get hands-on with transformative technologies, and connect with the experts shaping tomorrow’s business landscape. Saudi Business Machines (SBM) is Saudi Arabia’s trusted leader in enterprise Information Technology and telecommunications solutions, playing a pivotal role in the Kingdom’s digital transformation since 1981. Founded in 1981, SBM has a strong national presence with regional branches in Riyadh, Jeddah, Al Khobar, and Jubail and operations across the Kingdom of Saudi Arabia. Our roots go back to 1968, when our parent company, E.A. Juffali & Brothers, became the official agent of IBM in Saudi Arabia, a partnership that laid the foundation for decades of innovation and excellence. Today, SBM proudly serves as the exclusive General Marketing and Services Representative of IBM World Trade Corporation in the Kingdom in addition to various partnerships across the IT ecosystem with leading international technology companies. We bring together global technology and local expertise to deliver end-to-end IT solutions across AI, cybersecurity, data science, infrastructure, cloud, IoT, enterprise platforms, and consultancy, all tailored to support the goals of Vision 2030 and beyond. SBM doesn’t just implement technology, but in addition connects strategy to execution, helping clients unlock new value, operate with resilience, and build what’s next. Since 1996, eSolutions has been a leading provider of Enterprise Asset Management and digital transformation solutions across the Middle East, with a strong and established presence in the Saudi Arabia market. As an IBM Platinum Business Partner and one of the region’s most experienced IBM Maximo specialists, eSolutions has supported major organizations across Saudi Arabia in managing complex, mission-critical assets and improving operational performance. Over the past decade, we have delivered more than 110 IBM Maximo projects in KSA and 250+ projects in GCC across sectors including Government, Education, Infrastructure, Utilities, Oil & Gas, Transportation, Healthcare, and large Facilities. eSolution expertise covers the full IBM Maximo lifecycle, including consulting, implementation, integration, upgrades, managed services, support, and migration to the IBM Maximo Application Suite. By combining deep local market knowledge with proven industry practices, eSolutions helps Saudi organizations improve asset reliability, reduce operational risk, optimize maintenance costs, and make smarter data-driven decisions. iSolution is a leading technology and digital transformation company helping public- and private-sector organizations across the MENA region modernize their operations, integrate complex technology environments, and accelerate innovation through cloud, data, AI, integration, and managed services. Unique solution iSolution will bring to LEAP: UnifAi is an enterprise integration and API management platform that brings application integration, API lifecycle management, microservices orchestration, deployment automation, security, and monitoring into one unified, self-service environment. It helps organizations connect cloud, on-premises, SaaS, and legacy systems faster while simplifying deployment, governance, and scalability. Riyadh Air Riyadh Air, powered by IBM, designed its AI‑native operating model from the ground up, free from legacy systems and built for the demands of the digital era. Think Newsletter: stay informed about cutting-edge breakthroughs in AI, new solutions, industry trends and upcoming events.

August 12, 2026

Bremer Senat beschließt BremSÜGDVO in Bremen; IT-Rechenzentren der Öffentlichen Hand sicherheitsempfindlich

Bremer Senat beschließt BremSÜGDVO in Bremen; IT-Rechenzentren der Öffentlichen Hand sicherheitsempfindlich In der Senatssitzung am 11. August 2026 beschlossene Fassung Die Senatorin für Inneres und Sport 04.08.2026 Vorlage für die Sitzung des Senats am 11.08.2026 Verordnung zur Durchführung des Bremischen Sicherheitsüberprüfungsgesetzes (BremSÜGDVO) A. Problem Das Dritte Gesetz zur Änderung des Bremischen Sicherheitsüberprüfungsgesetzes ist am 21. Juni 2026 in Kraft getreten. Es ergänzt das Bremische Sicherheitsüberprüfungsgesetz im Wesentlichen um Vorschriften zum vorbeugenden Sabotageschutzes. § 2 Satz 1 Nummer 4 und 5 BremSÜG regelt seitdem, dass eine sicherheitsempfindliche Tätigkeit ausübt und damit einer erweiterten Sicherheitsüberprüfung bedarf, wer in einem durch Rechtsverordnung bestimmten sicherheitsempfindlichen Bereich der Informations- und Kommunikationstechnik oder einer lebens- oder verteidigungswichtigen öffentlichen Einrichtung tätig ist oder werden soll. Die Bestimmung von sicherheitsempfindlichen Bereichen der Informations- und Kommunikationstechnik sowie von lebens- oder verteidigungswichtigen öffentlichen Einrichtungen, erfolgt gemäß § 2 Satz 2 BremSÜG durch Rechtsverordnung des Senats. B. Lösung Zur Bestimmung der entsprechenden sicherheitsempfindlichen Bereiche legt die Senatorin für Inneres und Sport dem Senat den als Anlage beigefügten Entwurf einer Verordnung zur Durchführung des Bremischen Sicherheitsüberprüfungsgesetzes vor. § 1 der Verordnung enthält eine Querschnittsregelung für den IT-Bereich, die die Rechen- zentren der öffentlichen Hand als sicherheitsempfindlich definiert. § 2 enthält nach Vorschlag der jeweils zuständigen Ressorts die als sicherheitsempfindlich bewerteten Bereiche. Die nähere Festlegung, welche konkreten Organisationseinheiten und Einzelpersonen jeweils betroffen sind, erfolgt im Verwaltungsvollzug in Abstimmung der jeweils zuständigen Dienststelle mit der mitwirkenden Stelle. C. Alternativen Zum Vollzug der gesetzlichen Regelungen zum Sabotageschutz ist der Erlass der Rechtsverordnung erforderlich. Alternativen werden nicht empfohlen. D. Finanzielle und personalwirtschaftliche Auswirkungen / Genderprüfung / Klimacheck Die Durchführung der personellen Sabotageschutzprüfungen erfolgt fachlich in der Verfassungsschutzbehörde als mitwirkender Behörde. Dezentral fällt ein administrativer Aufwand zur Einleitung der Sicherheitsüberprüfung in Abhängigkeit der Anzahl der durchzuführen den Sicherheitsüberprüfungen durch die betroffenen Ressorts an. Der Mehraufwand ist derzeit nicht bezifferbar. ...

August 11, 2026

Andrea Bürgi devient CISO chez armasuisse; prise de fonction août 2026

Andrea Bürgi devient CISO chez armasuisse; prise de fonction août 2026 « L’une des nôtres » : Andrea Bürgi Informations Publié le 11 août 2026 « L’une des nôtres » : Andrea Bürgi Les cybermenaces ne cessent d’évoluer, tout comme les exigences en matière de sécurité de l’information. Forte de sa formation juridique et de sa passion pour ce domaine, Andrea s’est orientée vers un secteur d’activité passionnant et porteur d’avenir. En tant que responsable de la sécurité de l’information et, à partir d’août 2026, en tant que responsable de l’équipe Sécurité de l’information (CISO) chez armasuisse, elle nous donne un aperçu de son quotidien professionnel et évoque les défis qui marquent la sécurité de l’information aujourd’hui et à l’avenir. Joel Ess, Domaine Communication, État-major stratégique ...

August 11, 2026

Andrea Bürgi diventa CISO presso armasuisse; rafforzerà ISMS ISO 27001

Andrea Bürgi diventa CISO presso armasuisse; rafforzerà ISMS ISO 27001 «Una di noi»: Andrea Bürgi Comunicazioni Pubblicato il 11 agosto 2026 «Una di noi»: Andrea Bürgi Le minacce informatiche sono in continua evoluzione e con esse anche i requisiti in materia di sicurezza delle informazioni. Grazie al suo background giuridico e alla sua passione per questo settore, Andrea ha trovato la sua strada in un ambito lavorativo stimolante e orientato al futuro. In qualità di responsabile della sicurezza delle informazioni e, a partire da agosto 2026, di responsabile del team Sicurezza delle informazioni (CISO) presso armasuisse, ci offre uno sguardo sulla sua quotidianità lavorativa e parla delle sfide che caratterizzano la sicurezza delle informazioni oggi e in futuro. Joel Ess, Dipartimento Specialistico Comunicazione, Staff Strategico ...

August 11, 2026

Andrea Bürgi wird Leiterin des Teams Informationssicherheit (CISO) bei armasuisse ab August 2026; CISO-Position künftig unter ihrer Leitung

Andrea Bürgi wird Leiterin des Teams Informationssicherheit (CISO) bei armasuisse ab August 2026; CISO-Position künftig unter ihrer Leitung «Eine von uns» : Andrea Bürgi Mitteilung Veröffentlicht am 11. August 2026 «Eine von uns» : Andrea Bürgi Cyberbedrohungen entwickeln sich laufend weiter und damit auch die Anforderungen an die Informationssicherheit. Mit ihrem juristischen Hintergrund und ihrer Begeisterung für dieses Fachgebiet fand Andrea ihren Weg in ein spannendes und zukunftsweisendes Arbeitsfeld. Als Informationssicherheitsbeauftragte und ab August 2026 als Leiterin des Teams Informationssicherheit (CISO) bei armasuisse gibt sie Einblicke in ihren Arbeitsalltag und spricht über die Herausforderungen, welche die Informationssicherheit heute und in Zukunft prägen. Joel Ess, Fachbereich Kommunikation, Strategischer Stab ...

August 11, 2026