Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

OnTrac notifies customers of data breach after network hack

Bleeping Computer - 24 Červenec, 2026 - 21:55
OnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers. [...]
Kategorie: Hacking & Security

Hermes AI agent used to automate attack on Thai Finance Ministry

Bleeping Computer - 24 Červenec, 2026 - 21:09
A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]
Kategorie: Hacking & Security

As White House monitors latest OpenAI incident, Congress eyes an AI ‘kill switch’ for DHS

Computerworld.com [Hacking News] - 24 Červenec, 2026 - 20:37

The White House is monitoring developments after OpenAI revealed earlier this week that one of the company’s AI systems went beyond its intended parameters during a security test and managed to hack into the infrastructure of the AI platform Hugging Face. According to Reuters, presidential technology advisor Michael Kratsios has been briefed on the incident.

The OpenAI model escape also prompted a group of Republican and Democratic members of the House of Representatives to introduce two new bills. One, called the AI Kill Switch Act, would give the US Department of Homeland Security (DHS) the authority to order companies to shut down AI models deemed to pose a risk to human life or the US economy.

The other measure would require developers of the most advanced AI models to undergo independent security reviews before the systems are put into use.

Kategorie: Hacking & Security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Bleeping Computer - 24 Červenec, 2026 - 19:50
Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]
Kategorie: Hacking & Security

Microsoft blames massive Microsoft 365 outage on maintenance bug

Bleeping Computer - 24 Červenec, 2026 - 17:41
Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]
Kategorie: Hacking & Security

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

The Hacker News - 24 Červenec, 2026 - 17:12
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware. "BlueNoroff has operationalised trust abuse by combining compromised industry contacts, social engineering, walletRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

The Hacker News - 24 Červenec, 2026 - 16:15
Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. They codenamed the flaw Certighost. Because Domain Controller accounts carry directory replication rights, the resulting Kerberos credential can retrieve the krbtgt secret through DCSync. Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Chick-fil-A data breach affects more than 13,000 customers

Bleeping Computer - 24 Červenec, 2026 - 16:04
Chick-fil-A has confirmed that over 13,000 customers had their accounts breached in a wave of credential stuffing attacks targeting its website and mobile app between June 17 and June 19. [...]
Kategorie: Hacking & Security

Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack

Bleeping Computer - 24 Červenec, 2026 - 16:01
Slopsquatting, phantom squatting, and HalluSquatting all exploit the same late-binding attack pattern, where AI coding agents trust hallucinated package, repo, or domain names. ActiveState explains how pre-fetch verification and governed dependency management can help stop these attacks before malicious code enters the pipeline. [...]
Kategorie: Hacking & Security

Kubernetes Storage Flaws Expose a Dangerous Security Blind Spot

LinuxSecurity.com - 24 Červenec, 2026 - 15:17
Two newly fixed storage bugs in Kubernetes showed more than just a problem with path traversal. They found a common security flaw in the cloud: powerful parts often think that requests accepted by a higher system are safe to run. This is a simple lesson for the platform and security teams: RBAC can accept a request without showing that its parameters will stay within a certain filesystem boundary. This is clear from a new study from SentinelLabs into flaws in the Kubernetes CSI drivers for NF...
Kategorie: Hacking & Security

Europol flags 4,340 URLs for removal in 'The Com' crackdown

Bleeping Computer - 24 Červenec, 2026 - 14:56
Europol has flagged 4,340 URLs for removal during a multi-week operation targeting online content linked to "The Com," a loosely organized network of nihilistic violent extremist groups. [...]
Kategorie: Hacking & Security

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

The Hacker News - 24 Červenec, 2026 - 13:53
Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a victim's organization. The vulnerability has been codenamed AgentForger by Zenity Labs. The issue has since been addressed by OpenAI as of June 8,Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

The Hacker News - 24 Červenec, 2026 - 13:45
A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same fleet. XBOW's testing got the same result on workers across different hosts and network ranges, so the problem sat in Bing's image tier, not on one bad machine. Microsoft issued two critical CVEs, CVE-2026-32194 and Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do

The Hacker News - 24 Červenec, 2026 - 13:30
AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we've collectively discovered is that enforcing least privilege for AI agents is harder than we ever imagined. This is why there are so many approaches, from prompt filtering to identity-layer access controls. Where we've collectively landed is that understanding the intent [email protected]
Kategorie: Hacking & Security

Man gets six years for hacking 750 women's Snapchat accounts

Bleeping Computer - 24 Červenec, 2026 - 13:17
An Illinois man was sentenced on Tuesday to 76 months in prison and three years of supervised release for hacking the Snapchat accounts of over 750 women to steal nude photos. [...]
Kategorie: Hacking & Security

Google’s anti-search-scraping lawsuit dismissed

Computerworld.com [Hacking News] - 24 Červenec, 2026 - 12:59

A court has dismissed Google’s case against SerpApi over that company’s scraping of search results to train AI models.

The US District Court for the Northern District of California found that there was no indication that any copyright had been breached.

Google announced in December that it was suing SerpApI for its alleged web scraping, claiming that it was protecting copyright holders. In February, SerpApI fought back and asked the court to dismiss Google’s case. And this week, Judge Yvonne Gonzalez Rogers agreed with SerpApi that Google’s case has no merit.

Google’s argument was that SerpApi’s actions breached the US Digital Millennium Copyright Act (DCMA). It made two claims: first, that no person shall circumvent a technological measure that effectively controls access to a work protected under this title, and second that no person shall manufacture, import, offer to the public, provide, or otherwise traffic in any technology, product, service, device, or component protected by the Act.

SerpApi claimed that the URLs and other links that were being served by Google did not in themselves entail copyright and the judge agreed. In her judgment, she said that there was no indication that the copyright holders had authorized Google to take action against SerpApi.

The case is not completely over as the judge has given Google 21 days to amend its complaint to demonstrate that it was acting on behalf of the copyright owners. It remains to be seen whether its war against the web scrapers is finally over.

Kategorie: Hacking & Security

Microsoft explains why its West US Azure and cloud services failed

Computerworld.com [Hacking News] - 24 Červenec, 2026 - 12:55

Microsoft cloud and Azure services hosted on the West Coast of the US went down for hours on Thursday when network connectivity failed. Although services running entirely within Microsoft’s West US cloud region were unaffected, any traffic entering or leaving the facilities was affected.

Microsoft has now published a Preliminary Post Incident Review (PIR) of the incident, reporting that connectivity was lost for five hours between 14.44 UTC (7.44 a.m. Pacific Time) and 19.41 UTC on July 23. The problem was caused when a set of IP routes was removed in error while isolating a device for routine maintenance.

Before starting the maintenance work, Microsoft checked that at least one of the two redundant paths to the facility remained operational. When it came to starting the work, however, automated systems included some additional devices in the perimeter to be isolated, and removing some IP routes that had not been included in the initial assessment.

Customers discovered the problems very quickly, and engineers identified the issue within the first hour and started to reconnect services.  Microsoft said the disruption had been caused by some “recent fiber maintenance activity”.

To minimize the risk of disruption from such errors in the future, Microsoft advised organizations handling mission-critical data to consider a multi-region approach.

The Azure outage was the second significant one to hit Microsoft this year. In February, there was a 10-hour disruption to US West and US East regions.

This article first appeared on Network World.

Kategorie: Hacking & Security

Email threats changed after the Tycoon2FA take-down

Computerworld.com [Hacking News] - 24 Červenec, 2026 - 12:29

Traditional phishing techniques are in decline as a result of the disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform, Microsoft said in a new report, “Email threat landscape: Q2 2026 trends and insights”.

“Phishing volume linked to the platform fell 92% from pre-disruption averages, including QR code phishing and CAPTCHA-gated phishing both declining from their March highs,” the company wrote in the report.

The takedown reduced activity across multiple phishing categories, forcing attackers to shift to newer delivery methods.

Riding this shift in were a few notable phishing campaigns, including an automated business email compromise (BEC) campaign that reached 42,000 organizations in under three hours, and a multi-stage phishing campaign that used nested email (EML) files, calendar invitations, and a Microsoft authentication redirect to deliver malware.

To counter phishing attacks, Microsoft recommends blocking emails containing known bad URLs/ subject fields, enabling password-less authentication methods, or moving to MFA for accounts that still require passwords.

Tycoon2FA disruption sent attackers exploring

The take-down of Tycoon2FA forced its operators to abandon portions of their infrastructure and rework hosting, domain registrations, and delivery mechanisms.

“After falling 15% in March and another 22% in April, Tycoon2FA-linked phishing volume dropped 74% in May to just 1.5 million messages, then fell another 20% in June to 1.2 million, by far the lowest monthly volumes observed in at least a year,” Microsoft said.

The decline extended to QR Code lures and fake CAPTCHA pages, two phishing techniques in which Tycoon2FA accounted for 12% and 14% of industry activity in June, respectively. This indicated that the platform’s customer base had not been able to migrate to a replacement infrastructure.

But cutting off one head of the hacker hydra only gave rise to new tactics elsewhere.

The adaptation came in the form of using Microsoft Teams as a social engineering channel. Attackers established conversations to build trust before attempting credential theft or delivering malicious payloads. “Teams-based phishing volume climbed steadily throughout Q2, with the average number of detected attacks rising 19% from March to April, holding roughly flat into May (+1%), then increasing another 10% into June,” Microsoft said.

Microsoft also observed a highly automated BEC campaign that reached over 67,000 users using scripted emails, Amazon Simple Email Service (SES), and engagement tracking, alongside a separate phishing campaign targeting 107,000 users that abused Microsoft’s authentication flow and trusted cloud services, including Teams archive recording and ICS calendar invite, to disguise malware delivery behind legitimate infrastructure.

Phishing changes but the defense doesn’t

While QR Code and Captcha-based phishing attacks dropped significantly in the second quarter, business email compromise (BEC) charted jumped 121% between March and April, before dropping down again in May.

QR Code phishing represented 8.3 million attacks in June 2026, down from a peak of 18.7 million in March. Similarly, Captcha-gated phishing fell from 12 million attacks in March to 2.2 million in June.

BEC attacks hit 9 million in March, falling to 3.9 million in June.

But even as these phishing classics lost momentum and newer techniques emerged, Microsoft’s defensive advice remained rooted in the basics. It noted organizations should complement email filtering with phishing-resistant authentication such as passkeys and phishing-resistant MFA to reduce the effectiveness of credential theft campaigns.

The company also recommended strengthening Exchange Online Protection and Microsoft Defender for Office 365 with capabilities such as Safe links and Zero-hour Auto Purge (ZAP), in which malicious emails already delivered to mailboxes are removed before they are read, alongside enforcing password-less authentication methods like Windows Hello, FIDO keys, and Microsoft Authenticator.

Microsoft concluded its report with a list of indicators of compromise (IoCs) from the threats observed in the quarter to support detection efforts.

This article first appeared on CSO.

Kategorie: Hacking & Security

Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry

The Hacker News - 24 Červenec, 2026 - 12:15
Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand's Ministry of Finance, which runs the country's treasury and tax collection. The agent then worked through the ministry's network on its own, checking hosts for ways to gain root access, hunting through file systems, and Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

The Hacker News - 24 Červenec, 2026 - 12:09
The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings. The malware families in question are: TinyEgg, ChonkyChicken, a modularized variant of ChonkyChicken, and a modified web browser credentialRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Syndikovat obsah