Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

Attackers have been exploiting critical Zimbra flaw to steal emails

Ars Technica - 30 Září, 2026 - 22:44

Hackers have been exploiting a critical vulnerability in the Zimbra Collaboration Suite in an attempt to obtain email backups and authentication credentials of vulnerable organzations, Microsoft has warned.

The vulnerability, tracked as CVE-2026-73570, lets attackers remotely issue operating system commands without authentication. Zimbra maintainer Synacor issued a patch on July 20, but didn’t disclose the vulnerability for more than three weeks after that. The security-focused Shadowserver Foundation said last week that its scans found that 274 separate instances of the Zimbra Collaboration Suite had been compromised. The number of servers running the software has fluctuated from 19,000 in the week following the patch to about 12,000 in the weeks following that. Currently, Shadowserver is tracking about 10,000 instances.

Look, ma, no authorization

From July 28 to August 7, Microsoft said Wednesday, the company detected two distinct scanning tools probing the Internet for vulnerable endpoints. The attackers first validated their exploit worked by sending HTTP, requests and DNS, ICMP, and out-of-band identity checks to domains hosted on public services. The probes allowed the attackers to confirm the exploit successfully executed commands on vulnerable servers without actually compromising them. Eventually, the attackers began using their command injection capability to install malicious payloads. Microsoft wrote:

Read full article

Comments

Russian state hackers use new RedFlick technique to push malware

Bleeping Computer - 30 Září, 2026 - 22:34
The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed "RedFlick" to deploy its signature CosmicPulse backdoor. [...]
Kategorie: Hacking & Security

DIVD says Zammad zero-days enabled AI-driven network breach

Bleeping Computer - 30 Září, 2026 - 21:49
The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. [...]
Kategorie: Hacking & Security

OpenAI takes on Microsoft and Google with office productivity push

Computerworld.com [Hacking News] - 30 Září, 2026 - 21:14

OpenAI unveiled its long-rumored productivity software suite Tuesday with the launch of Pages, a collaborative document editor for ChatGPT. A slides app is also on the way, the company announced at its DevDay event.

The Pages app is accessed via a new Space tab, which OpenAI describes as a “new home for your team to collaborate with AI to get work done.” Users can store documents and other uploaded files, as well as create and share pages, slides, and spreadsheet documents. Space replaces the Library in ChatGPT, but the Projects tab will remain as a way to organize chats and files.

The announcement puts OpenAI into direct competition with incumbent office productivity software providers, such as Microsoft, Google, and Notion.

“Spaces and Pages broaden the competitive overlap, because ChatGPT is moving beyond being primarily an individual assistant towards becoming a place where work can be retained, organized, and shared with colleagues,” said Maria Bell, senior research analyst at FDM CCS Insight.

“That brings it closer to the collaboration layer of Microsoft 365, Google Workspace, and Notion, rather than simply competing with the AI assistants inside those platforms.”

“OpenAI is trying to become a more user-centric environment that focuses on everyday workloads for productivity,” said Jack Gold, principal analyst at J. Gold Associates. “To that extent it is competing with Microsoft, Google, and others, as well as other AI companies that want to move towards a more full-time, ‘on my desktop environment’ that is enhanced with AI capabilities.”

With its productivity tools, OpenAI is trying to make its AI assistant “more sticky so it can generate more revenue,” he said. But while OpenAI and its competitors see AI-naive productivity tools as the next “greenfield” opportunity to go after, “it won’t be easy displacing entrenched users with Office or Google Workspace,” he said.

“I don’t see companies transitioning to new productivity suites easily. It’s a major lift to do so, and most are looking to add on to their existing capabilities rather than rip and replace,” said Gold.

What is ChatGPT Pages?

OpenAI describes Pages as a “new type of document, built for human and agent collaboration.” The document editor has a streamlined interface similar to Notion. Content such as headings, paragraphs, and tables are organized into blocks. Also similar to Notion is the ability to create sub-pages within a page and link to an existing page.

When a user selects text on a page, a floating toolbar appears, with options such as bold, italic, underline, strikethrough, as well as the block style (heading, list, checklist, quote, and so on). Users can then comment on selected text for collaborators to view, or ask ChatGPT to make revisions.

The embedded AI assistant can generate text and other content such as images and interactive visualizations. “Prompt” blocks allow authors to embed suggested prompts for document readers to run, to help explore their work, according to OpenAI.

Multiple users can collaborate on a single document, making edits and generating content via their own AI assistant. Collaborative document access raises potential permission concerns when users create content based on files they can individually access. ChatGPT has more information on permissions and other data sharing controls on its help center site.

Users can also connect to other content repositories, such as Google Drive, according to OpenAI’s documentation.

Space and Pages are available to ChatGPT Pro, Business, and Enterprise customers, on the web and in the ChatGPT desktop app. On mobile devices, users can read and share pages, but editing is not supported.

Computerworld asked OpenAI for further clarification on pricing for business customers, and did not receive a reply at time of writing.

AI assistants evolving into productivity suites

OpenAI’s announcement comes as Microsoft and Anthropic also build office productivity tools into their respective AI assistants.

Last week, Anthropic announced that it has built a rich text editor into Claude alongside a tool for creating presentation slides (both are currently available in beta). Microsoft’s Copilot overhaul last Friday also included the ability to create and edit a range of Office documents from within the Copilot app.

These are all signs of AI assistants becoming more central to how office work gets done. Gartner predicts that spending on enterprise AI assistants will rise from $17 billion in 2025 to $71bn in 2030, while knowledge workers are forecast to spend more time interacting with these tools in their daily work than with any other application over the next three years.

ChatGPT collaborative slides are “coming soon,” OpenAI announced at its DevDay event Tuesday.

OpenAI

For OpenAI to succeed as a hub for collaborative work, it needs to convince not individuals but teams of employees to adopt its productivity tools. “A user can adopt ChatGPT for drafting or research on their own, but shared documents depend on colleagues using the same environment, agreeing how work is organized, and trusting it as a common workspace,” Bell said.

That gives the incumbents a significant advantage, she said. “Microsoft, Google, and Notion already sit inside established team workflows, with years of shared content, permissions, collaboration habits, and enterprise processes built around them. OpenAI is therefore not just asking users to try a new feature; it is asking teams to consider whether ChatGPT can become part of their shared working environment…That is a higher bar.”

Kategorie: Hacking & Security

Kontakt na tuto babičku si uložte do telefonu. Přes WhatsApp pomůže odhalit praktiky šmejdů

Zive.cz - bezpečnost - 30 Září, 2026 - 20:15
** Babička Alenka už jednou zatopila šmejdům u podvodných volání ** Teď pomůže při odhalování běžných praktik podvodníků přes WhatsApp ** Napsat jí může opravdu každý, stačí jen naskenovat QR kód zobrazený výše
Kategorie: Hacking & Security

Over 543,000 valid credentials exposed in public GitHub repositories

Bleeping Computer - 30 Září, 2026 - 20:08
More than 543,000 credentials exposed in public GitHub repositories were still valid in July despite the platform's security measures to prevent accidental leaks of sensitive data. [...]
Kategorie: Hacking & Security

Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets

The Hacker News - 30 Září, 2026 - 18:46
Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team. The attack exploits CVE-2026-73570 (CVSS score: 8.9), an unauthenticated operating system command injection flaw that can lead to remote code execution when Simple Network Management Protocol Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks

The Hacker News - 30 Září, 2026 - 18:32
Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content. "Once executed, the legitimate MSP360 installer, distributed under a deceptive file name established remote management access on affected Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS

Bleeping Computer - 30 Září, 2026 - 17:49
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition. [...]
Kategorie: Hacking & Security

Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager

The Hacker News - 30 Září, 2026 - 17:24
Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an advisory on September 30. The flaw, CVE-2026-76504, could allow a remote attacker with no login access to use the Manager's API as the admin user. Fixed releases are available, and there is no workaround. It carries a Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures

The Hacker News - 30 Září, 2026 - 17:00
Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware. Huntress, which observed the activity in late September 2026, said it marks the abuse of yet another feature in trusted artificial intelligence (AI) platforms. Prior campaigns have weaponized shared Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Cisco warns of new SD-WAN zero-day exploited in attacks

Bleeping Computer - 30 Září, 2026 - 16:46
Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges. [...]
Kategorie: Hacking & Security

Trump’s answer to AI’s image problem: Industry self-regulation and a new name

Computerworld.com [Hacking News] - 30 Září, 2026 - 16:21

US President Donald Trump has ordered the federal government to call artificial intelligence “Super Intelligence,” while keeping the technology’s legal definition unchanged and relying on industry to set the rules for its use.

In an executive order, the White House administration said modern systems “far exceed what was envisioned when the term ‘Artificial Intelligence’ first came into use,” adding they “increasingly represent not merely artificial intelligence, but a new era of Super Intelligence.”

“It is therefore the policy of my Administration that, to the maximum extent permitted by law, the executive branch shall use the terms ‘Super Intelligence’ and ‘SI’ in place of ‘Artificial Intelligence’ and ‘AI’,” Trump ordered.

The executive branch “will not acknowledge” the older terms in any applicable setting, the order stated.

Yet the order defines the new term using the old one. Section 3 of the order says Super Intelligence means the technologies and systems covered by the statutory definition of artificial intelligence in 15 U.S.C. 9401(3).

That equivalence may not last. The order gives the White House 60 days to propose a new legal definition.

Trump also put the new name to use immediately. On the same day, he and the leaders of six technology companies signed the “White House Accord on Super Intelligence,” a voluntary set of safety commitments for frontier models, which Trump posted on Truth Social.

A voluntary accord, no enforcement

The accord, subtitled “Joint Commitment on Frontier Responsibilities,” carries the signatures of Sundar Pichai of Google, Dario Amodei of Anthropic, Mark Zuckerberg of Meta, Greg Brockman of OpenAI, Elon Musk of xAI and Jensen Huang of Nvidia, alongside Trump’s. Microsoft and Amazon, two of the seven companies that made voluntary AI commitments to the Biden White House according to a July 2023 White House fact sheet, do not appear on the new accord.

Companies that train and deploy frontier models need “robust internal processes and controls” to ensure their technology behaves as intended, the signatories wrote in the accord.

The document sets out four layers of controls and audits. The first is internal monitoring of model capabilities and alignment in areas including cybersecurity, biosecurity and chemical threats. The other three are an internal team to verify those controls, an independent external auditor or evaluator, and an independent committee of the board of directors to oversee the process.

The accord does not name auditors, set deadlines or require companies to disclose audit findings to customers or regulators.

The signatories said they “believe each company should implement” the four layers. Codifying the steps into laws or regulations “may make sense” over time, they added.

The accord refers to “frontier models” in its commitments, with only its title adopting the term “Super Intelligence” mandated by the new order.

60 days to put terminology in order

The Executive Order on Super Intelligence directs the White House’s top science and technology adviser to propose legislation for a new federal definition within 60 days, putting the deadline at November 28.

The new definition must reflect the capabilities of frontier systems, which Trump described in the order as doing “much more than imitate or automate discrete aspects of human intelligence.”

The proposal must assess whether the new definition should modify, expand upon or supersede the statutory definition of artificial intelligence, the order said. It must also propose amendments to existing laws that reference AI.

Until then, the current definition applies unless superseded by presidential action or an Act of Congress, according to the order. Changing the statutory definition itself would require Congress, the order added.

For now, the rename covers official correspondence, websites, reports, policy documents and other non-statutory documents, the order stated. Previously issued regulations, contracts and grants do not need to be altered, it added.

The order does not address vendor proposals, solicitation responses or product documentation that use the older terms.

This article first appeared on CIO.

Kategorie: Hacking & Security

AI's Third Wave: Coworkers Break the Security Model That Worked for Agents

Bleeping Computer - 30 Září, 2026 - 16:01
Persistent AI coworkers may operate continuously with standing access, creating identity risks that existing security models were not designed to handle. Token Security explains why these agents need their own identities, owners, scoped permissions, and lifecycle controls. [...]
Kategorie: Hacking & Security

Apple issues urgent iOS patch as it navigates the spyware arms race

Computerworld.com [Hacking News] - 30 Září, 2026 - 15:50

If you’ve not done so recently, you should update your Apple systems now as the company continues to fight sophisticated, targeted hacks. The latest patch protects against what the company called “an extremely sophisticated attack against specific targeted individuals.” 

Apple recently published an emergency security patch for users on iOS 26 and iPadOS 26 to fix the zero-click vulnerability (CVE-2026-86950), described as an “out-of-bounds write issue” in CoreGraphics. A patch was also made for macOS Sequoia. 

This was far from being a friendly vulnerability, as it could impact affected systems with no action on behalf of the user, hence its status as a “zero-click” attack. In this case it means that just the action of “processing a maliciously crafted file” could lead to arbitrary code execution. Apple said it was aware of a report that the issue could have been exploited in a targeted attack on older versions of iOS.

Apple did not specify how the attack is delivered, but SecurityWeek surmised it may have been delivered using the web, email, or messaging apps and that simply previewing the malicious file could have enabled the attack, no click required. The vulnerability impacts a range of Apple devices, including multiple generations of iPad, Macs, and iPhones back to iPhone 11.

A pattern of sophisticated exploits 

We don’t know how this exploit was used. Apple said it learned of the incident thanks to a tip-off from Meta’s product security team. It follows a similar incident in 2025 when a vulnerability in WhatsApp may have been exploited alongside another Apple flaw in zero-click targeted attacks against under 200 people. Meta has not said if this latest flaw was used via WhatsApp but described the discovery as part of its “routine security work.”

This attack is the latest in a long, long line of exploits made against Apple’s systems. Apple’s description of this attack strongly suggests its use in an advanced operation against chosen targets. Subsequent to the patch, blockchain security firm SlowMist suggested it had identified iOS exploitation activity targeting sensitive wallet data, which illustrates the danger of zero-click attacks. In response to the flaw, the US Cybersecurity and Infrastructure Security Agency (CISA) gave federal agencies three days to apply the patch and told them to conduct forensic tests to see if their systems had been at all compromised as a result of the flaw.

The spyware arms race

Apple and others across the space face an intensely challenging threat environment, one that’s only becoming worse as international relations fray and state, state-adjacent, and criminal actors intensify their attempts to subvert security. It was only in August 2026 that Apple warned customers across 110 countries that they may have been targeted by this level of sophisticated attack, sending Threat Warnings to each individual its systems showed to have been targeted. 

This kind of security is a work in progress, made a lot harder by the fact that unfriendly governments, state-adjacent spyware services, and criminal gangs are in position to pay security researchers much more money for a successful zero-day attack than Apple’s security bounty scheme can possibly reach.

Toughen up, just toughen up

That reality is precisely why any Apple user or admin — particularly in any kind of regulated space, health, defense, energy, or anywhere, really — must be vigilant. All the usual mitigations should be in place:

  • Update your Apple devices to the latest available security updates. 
  • Never install apps from unknown or untrusted sources. 
  • Don’t open suspicious links in Safari or in-app browsers.
  • Don’t open files, links or follow app installation prompts unless you are certain where the prompts of files came from. 

It’s also important to understand the changing nature of the threat environment. Artificial intelligence has become a double-edged sword in tech security, enabling hackers to identify flaws on the one hand, enabling security researchers to do the same thing on the other. The problem is that the rate of discovery has also increased, stretching the resources of platform security teams to verify and remediate flaws as they’re found. Apple is responding to this difficult new realty and this year began accelerating the release of security updates specifically to counter AI-assisted hacking.

If you receive one of Apple’s Threat Warnings or work in a high-risk role that may be of interest to sophisticated spyware customers, then you should use Lockdown Mode, which the US FBI this year tried and failed to break the security of. 

“We are not aware of any successful mercenary spyware attacks against a Lockdown Mode-enabled Apple device,” Apple spokesperson Sarah O’Rourke said at the time.

All the same, the threat environment is intense, and staying informed is becoming a critical component to that defense.

Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSky, LinkedIn, or Mastodon.

Kategorie: Hacking & Security

Microsoft to block Entra ID script injection attacks starting October

Bleeping Computer - 30 Září, 2026 - 15:37
Microsoft has reminded customers that the Entra ID authentication system will get better protection against external script injection attacks starting next month. [...]
Kategorie: Hacking & Security

TeamViewer urges users to patch severe flaws “as soon as possible”

Bleeping Computer - 30 Září, 2026 - 14:25
Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software. [...]
Kategorie: Hacking & Security

Know Your Enemy: Browser-Based Attack Techniques in 2026

The Hacker News - 30 Září, 2026 - 13:58
Given that the browser is where business apps are accessed and used, it makes sense that attacks are happening there too. Most breaches today begin in a browser session. Often, they never leave it, with the entire attack chain from initial access to exfiltration playing out in the browser. Here are the six most dangerous techniques that should be on every security team's radar in 2026. 1. [email protected]
Kategorie: Hacking & Security

AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub

The Hacker News - 30 Září, 2026 - 13:30
AI coding agents asked to share screenshots of code changes for review have put internal company images in public GitHub repositories, security company Glow said. Its researchers found more than 13,000 internal images from developers at over 300 organizations, including customer billing records and screens of features not yet released. In most cases, they sat under developers' personal accountsSwati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Cloudflare plans to issue quantum-safe TLS certificates

Ars Technica - 30 Září, 2026 - 13:15

Cloudflare said Tuesday it plans to issue quantum-proof TLS certificates, making it one of the first authorities to issue such certificates, which use a form of cryptography that is widely believed to withstand attacks from quantum computers.

The Internet infrastructure provider said it will use an open source platform that issues both classic TLS certificates and a post-quantum equivalent known as Merkle Tree Certificates. The hybrid certificates will be free to both paying and non-paying users. To help build the massive system and establish ubiquity across the sprawling TLS ecosystem, Cloudflare will be acquiring an already trusted certificate root from CA GlobalSign. Cloudflare said the move will let millions of websites use post-quantum certificates at the flip of a switch and without incurring any increased performance overhead.

Fundamental architectural changes ahead

Cloudflare’s plans are part of a major overhaul in the web public key infrastructure (WebPKI) required to make website encryption and authentication safe for the coming post-quantum age. A major challenge is using quantum-proof signatures that can be easily transmitted during web requests and recorded in transparency logs to ensure counterfeit certificates aren't assigned to websites. The makeover will take years to complete, because it requires the work of an untold number of engineers who design operating systems, browsers, certificate authorities, and Internet infrastructure.

Read full article

Comments

Syndikovat obsah