Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

220 million traveler records exposed in Vietnam-linked APIS leak

Bleeping Computer - 1 hodina 33 min zpět
Exclusive: An exposed Advance Passenger Information System (APIS) database held 220 million passenger and crew records containing names, passport numbers, dates of birth, nationalities, and flight details spanning 2017 to 2026. Researchers accessed the Vietnam-linked system through a cloud-based path using default credentials. [...]
Kategorie: Hacking & Security

Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing

The Hacker News - 2 hodiny 8 min zpět
Online dating app Grindr has opted to pay £26 million ($35.1 million) to settle a lawsuit in the U.K. over allegations that it shared users' personal information, including their HIV status, with third-parties. Grindr, which is the largest LGBTQ+ dating app, was sued in April 2024, accusing it of violating U.K. privacy laws by sharing sensitive data for commercial purposes such as advertising. Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

The Hacker News - 7 Září, 2026 - 20:12
Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. "Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium's own Secure Preferences Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

Bleeping Computer - 7 Září, 2026 - 18:50
A zero-day vulnerability dubbed "StyleSmuggler" affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor. [...]
Kategorie: Hacking & Security

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

The Hacker News - 7 Září, 2026 - 17:51
Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins. The activity, which mainly singles out directors, vice presidents, and other executive staffRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

Bleeping Computer - 7 Září, 2026 - 17:39
A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. [...]
Kategorie: Hacking & Security

⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

The Hacker News - 7 Září, 2026 - 16:36
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on. Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Mathspace discloses data breach affecting over 1 million people

Bleeping Computer - 7 Září, 2026 - 15:05
Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after breaching its Metabase internal reporting system. [...]
Kategorie: Hacking & Security

Sam Altman calls GPT-6 Astra rollout ‘messy’ as enterprise users wait for access

Computerworld.com [Hacking News] - 7 Září, 2026 - 14:20

OpenAI’s rollout of its GPT-6 Astra model ran into early access issues after paying ChatGPT users were unable to use the system shortly after launch, prompting CEO Sam Altman to apologize and say the release had been “messy.”

“First, sorry for the messy rollout,” OpenAI CEO Sam Altman acknowledged the issue in a post on X. “Second, when we screw up, we try to make it right.”

OpenAI had said GPT-6 Astra would be rolled out across ChatGPT tiers and APIs, positioning it as its most advanced model to date. However, the initial rollout did not translate into immediate access for all users, highlighting the gap between model launch and availability across subscription tiers.

Only the organizations enrolled in its Daybreak cybersecurity program were able to access the model, whereas Plus, Pro, Business, and Enterprise ChatGPT subscribers, along with developers using the OpenAI API, were left out.

“Third, we should be able to begin broad rollout to API customers and ChatGPT subscribers in the near future. As usual, we will start with pro subscribers,” Altman continued in the post.

Altman wrote in a follow-up X post on Friday that OpenAI had extended Astra to Pro, Enterprise, and Business Premium users in ChatGPT’s Work and Codex products and had opened it up through the API.

“It might take a few days to roll out to our Plus and Business users,” OpenAI’s official X account posted on September 5.

The company did not immediately respond to a request for comment.

Phased rollout continues without firm timelines

OpenAI introduced GPT-6 Astra on September 4, stating that availability would expand over time rather than being enabled simultaneously for all users.

Altman’s post followed complaints about access during the initial rollout window, although OpenAI has not disclosed how many users were affected or how access varied across tiers.

In a subsequent post on X, Altman said: “We are working towards getting Astra in everyone’s hands as quickly as we can; I know it is frustrating,” indicating that access was being expanded incrementally.

OpenAI technical staff member Thibault Sottiaux confirmed in a separate X post that Plus and Business users had gained access too, crediting the company’s infrastructure: “more scalable than we anticipated.”

The rollout approach is consistent with OpenAI’s initial communication that Astra would be made available over several days, rather than at once. Gartner also noted that the model was first released to a limited set of organizations before broader expansion.

Rollout highlights the gap between launch and access

Analysts said the sequence reflects a distinction between model announcement and actual availability.

Greyhound Research said the Astra rollout should be treated as an operational signal rather than a confirmation of readiness.

“Announced, available, entitled, and production-ready are four separate states,” said Sanchit Vir Gogia, chief analyst at Greyhound Research. “This must be treated as operational evidence, neither dismissed as theatre nor inflated into proof that Astra has failed.”

He added that staged availability reinforces the need for enterprises to verify what level of access they actually receive, rather than assume uniform rollout across users or environments.

Gartner said enterprises will need to strengthen governance as they evaluate Astra’s capabilities.

“CIOs must balance Astra’s advanced automation with stronger cybersecurity, governance, and cost controls before adoption,” Gartner analysts said in an initial note on the launch shared with Computerworld

The firm said Astra’s ability to execute more autonomous workflows will require tighter evaluation controls and observability.

It also pointed to challenges around identity, security posture, and accountability as AI agents take on more complex roles.

Contracts and control models under scrutiny

Greyhound Research said the rollout raises questions about how enterprises define access and operational control.

“A conventional uptime SLA is too narrow for Astra,” said Gogia. “Critical describes the engine. It does not tell the buyer how much of that engine reaches the road.”

He said enterprises need to account for how such systems behave in production, particularly when access, interruption, or task continuity may vary.

“A stop leaves a state the enterprise did not choose, and that state needs a record it can defend,” Gogia said.

The rollout also highlights changes in how governance responsibilities are distributed.

Gogia said administrative controls alone do not address enterprise requirements.

“Admin opt-in is not a safety certificate,” he said. “It is the point at which accountability crosses from vendor release policy into an enterprise governance decision.”

He added that such controls do not extend automatically to API-based deployments, where enforcement depends on enterprise-level systems.

Capability gains introduce trade-offs

OpenAI has positioned GPT-6 Astra as an advance in reasoning, coding, and automation capabilities.

Gartner said these improvements introduce trade-offs that enterprises will need to evaluate in production settings.

While Astra may reduce token usage for some tasks, organizations must consider overall task costs, including validation and oversight, the firm noted.

Gartner also cautioned against over-indexing on early capability claims. “Without more evidence, CIOs should ignore the AGI hype for now and instead focus on use-case-specific evaluations, demonstrated business outcomes and reliable autonomy,” the firm said.

The story originally appeared on CSO.

Kategorie: Hacking & Security

Trezor data breach impact now reaches 81,000 customers

Bleeping Computer - 7 Září, 2026 - 14:16
Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S. customers. [...]
Kategorie: Hacking & Security

Your Cloud Security Checklist Doesn't Work the Way You Think It Does

The Hacker News - 7 Září, 2026 - 13:45
If managing security across multiple cloud providers wasn't hard enough, each one fails in a different way. For the 2026 Cloud Security Index, Intruder analyzed misconfiguration data from 3,000 organizations across AWS, Azure, and Google Cloud and found that risk profiles across providers have almost nothing in common. Here’s what the data looks like. How risk differs across cloud providers [email protected]
Kategorie: Hacking & Security

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

The Hacker News - 7 Září, 2026 - 13:36
Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. According to Huntress, three unrelated incidents have been found to use diverse initial access methods, namely a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

The Hacker News - 7 Září, 2026 - 13:20
A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed reports of exploitation in the wild. Security firm TantoSec has published a working exploit chain targeting vulnerabilities Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

ChatGPT can now connect to your personal apps to mimic writing style

Bleeping Computer - 7 Září, 2026 - 12:36
OpenAI appears to be testing a new "Writing Style" feature for ChatGPT that can learn how you write by looking at examples from your connected apps. [...]
Kategorie: Hacking & Security

Hackers exploit new MikroTik RouterOS flaws to hijack routers

Bleeping Computer - 7 Září, 2026 - 12:32
Hackers are exploiting a chain of two recently disclosed vulnerabilities in MikroTik routers to take control of devices with SSH services exposed to the internet. [...]
Kategorie: Hacking & Security

ConnectWise warns of new ScreenConnect flaw without patch

Bleeping Computer - 7 Září, 2026 - 12:06
ConnectWise has shared temporary mitigation measures for a new ScreenConnect Remote Access vulnerability that it plans to patch later this week. [...]
Kategorie: Hacking & Security

16 Gmail power moves for more efficient inbox management

Computerworld.com [Hacking News] - 7 Září, 2026 - 12:00

You might not know it from looking, but Gmail is jam-packed with time-saving tricks.

Some of ’em are right there in front of your face, if you know how to find ’em — while others require a teensy bit of under-the-hood tinkering to activate. But all of ’em are built right into Gmail and have the potential to make managing your email a heck of a lot easier.

Check out these 16 splendid Gmail tips and get ready to master your inbox once and for all.

(Note that unless otherwise specified, these tips are specific to Gmail’s web-based desktop version.)

Inbox step-savers

1. You can actually view attachments right from your Gmail inbox. Provided you haven’t switched away from the service’s “default” interface arrangement, you’ll see small tiles for every file associated with an email right below the message’s subject line. And you can click on any of those tiles to open or preview the file’s contents and get directly to the info you need.

Gmail’s attachment tiles are a great way to jump directly to attachments without having to open an email.

JR Raphael / Foundry

2. It’s easy to miss, but take note: When you hover your mouse over a message in your inbox, Gmail gives you a series of quick-access actions at the far-right side of the line. You can archive the email, delete it, mark it as read or unread, snooze it, or even RSVP to a meeting request right then and there — without ever having to open the message.

3. A super-useful keyboard shortcut I always forget to use: While viewing a multi-email thread of messages — a conversation in which you have numerous back-and-forth replies under the same subject — hit the semicolon key (;) to expand the entire conversation and show every message in the thread. And then hit the colon key (:) to collapse it back down so you see only the most recent email.

Just make sure you enable keyboard shortcuts first, if you haven’t already: Click the gear icon in the website’s upper-right corner, then click “See all settings” and look for the “Keyboard shortcuts” option midway down the screen that comes up. Select the “Keyboard shortcuts on” setting and then be sure to click the Save Changes button at the bottom of the screen.

4. Some of Gmail’s best keyboard shortcuts are the ones you create yourself. Go back into the website’s settings and this time, click the Advanced tab. See the line labeled “Custom keyboard shortcuts”? Click “Enable” next to that, then click the Save Changes button at the bottom of the screen.

Once Gmail refreshes itself to apply the changes, go back to the Settings area again and look for the newly present Keyboard Shortcuts tab. There, you can adjust any of the default keyboard settings to make them simpler to activate or easier to remember.

One of my favorite adjustments, for instance — and one I rely on constantly — is adding in a second command for the “Go to inbox” shortcut, which is typically gi by default. In Google’s old Inbox service, that shortcut was simplified down to just i, and once you get used to that shorter sequence, you won’t want to go back.

5. The panel at the right of Gmail’s web interface lets you pull up Google Calendar, Google Keep, Google Tasks, or Google Contacts right inside your inbox so you can manage info from each of those apps without having to switch tabs or open anything new. And here’s a handy hidden trick: With Tasks, you can drag messages directly from your inbox into the panel to create new tasks around them.

Creating new tasks from emails is as simple as dragging and dropping, as is being done here with the topmost message.

JR Raphael / Foundry

Unfortunately — and somewhat strangely — the same drag-and-drop behavior isn’t currently possible with Calendar or Keep, nor is it possible for Contacts.

6. Even with a miniature version of Contacts being available inside that handy side panel, you might sometimes want to pull up the full Google Contacts website for its complete set of features. Provided you’ve got Gmail’s keyboard shortcuts enabled now, commit this workaround to memory: Pressing g and then c will open up Contacts in a separate tab, no matter what else you’re doing in your inbox.

Composing shortcuts

Editor’s note: Assuming you’ve enabled keyboard shortcuts (see tip 3), the following keyboard shortcuts work in any browser on any desktop operating system. Mac users, just swap in the ⌘ key for “Ctrl” wherever you see it.

7. Ever like marking messages as unread after you’ve opened ’em? Gmail makes that incredibly easy to do: Anytime you have an email open, look for the envelope icon directly to the right of the trash can in the horizontal row of icons above your message (in the area directly beneath the search bar). That’ll let you mark the message as unread with a single click. Or, for a faster and more powerful one-two punch, just type an underscore (_) while viewing any message. That’ll mark it as unread and zap you back to your main inbox.

8. Speaking of combining multiple actions into a single command, simplify your inbox organization process by enabling Gmail’s convenient Send & Archive button. It places a second button alongside the regular Send button whenever you’re responding to an existing message, and clicking that button (or, even better yet, hitting Ctrl-Enter on your keyboard) will send your response and archive the thread in one fell swoop.

To enable it, look for the “Send and Archive” option within the General tab of Gmail’s settings. Click “Show ‘Send & Archive’ button in reply,” hit the Save Changes button at the bottom of the screen, and then get ready to save yourself steps the next time you type a reply.

Gmail’s Send & Archive button (the blue one to the left of the regular Send button) turns two steps into one.

JR Raphael / Foundry

9. I don’t know about you, but I frequently start typing an email and then decide against sending it. (Rather fittingly, I started typing out a lengthy explanation of the reasons but then decided against including it.) If the same thing ever happens to you, remember this: Hitting Ctrl-Shift-D while you’re in the Gmail compose tool will close the compose window and discard your draft. And it works whether you’re writing a new email or a reply.

10. Another awesome time-saver: In addition to the obvious Ctrl-B for bold and Ctrl-I for italics email formatting shortcuts, Gmail has hotkeys for doing some advanced forms of text formatting — things that’d otherwise require multiple clicks and much menu-hunting to accomplish.

The ones I use the most:

  • Ctrl-Shift-8 will add a bulleted list into your email (just like this list!), and Ctrl-Shift-7 will add a numbered one.
  • Ctrl-Shift-9 will offset text in a blockquote style.
  • Ctrl-] will indent text, while Ctrl-[ will remove any indentation.
  • And Ctrl-\ will remove any formatting on your selected text and make it as plain as can be.

11. You’d never know it, but the Gmail compose tool itself can take on various forms, depending on your preferences. Make a mental note of these possibilities and the shortcuts to get to ’em:

  • To start a new message in the default lower-right-corner-of-the-screen window view, hit c.
  • To start a new message in a pop-up window totally separate from your main Gmail tab, hit Shift-C. You can do the same thing for a reply by hitting Shift-R while viewing a message thread — or Shift-A for reply-all.
  • To start a new message in a full-screen compose window within your main Gmail tab, hit c — then click the little arrow icon in the compose tool’s upper-right corner. (You can also hit Shift while clicking that icon to pop the message out into a separate pop-up window form.)
  • If you’d rather use that full-screen compose window all the time, by default, click the three-dot menu icon in the lower-right corner of the compose tool and look for the “Default to full-screen” option there. (If you ever change your mind, you’ll find the option to disable that preference in that very same spot.)
  • If for some reason you like the idea of composing a message in a new tab instead of a pop-up window or within the main Gmail tab, just hit d while in your inbox. That’ll do the trick!

To see more keyboard shortcuts, just type ? while viewing any message list within Gmail.

Smarter snoozing

12. Don’t forget to take advantage of Gmail’s super-handy snoozing tool: Instead of letting messages linger in your inbox and pile up to an unmanageable point, use the snooze function to help yourself deal with everything as soon as you see it.

A good rule of thumb to maintain: If you can respond to something in less than a minute, do it. If something doesn’t require any action on your behalf, archive it immediately. And if something requires some sort of action but you don’t have the time to mess with it at that moment, snooze it to a day and time when you will be able to handle it.

You can snooze an email from your inbox by hovering over the message and selecting the clock-shaped Snooze icon, as noted in tip 2. You can also snooze an email while it’s open by clicking the three-dot menu icon to the right of the folder symbol directly above the email and then clicking “Snooze” within the menu that pops up. Or you can simply press b while you’re viewing a message or while you have it selected in your inbox.

Snoozing a message causes it to vanish from your inbox and then reappear at any day and time you choose.

JR Raphael / Foundry

13. Gmail even makes it possible to snooze multiple messages at the same time — in case you see more than one email that needs to be pushed back to the same point. From your inbox, simply click the boxes to the left of any messages you want to include, then click the three-dot menu icon within the row of icons toward the top of the screen and select “Snooze” from there.

14. Need to get back to something you snoozed — or change the day and time at which it’s set to reappear? You can always find all of your snoozed emails in Gmail’s Snoozed section, located beneath the “Inbox” line in the left-hand panel. Once you’re there, just hover over any email and click the clock-shaped icon to change its snooze settings or unsnooze it entirely.

15. You can snooze messages from the Gmail mobile apps, too, though the option is a bit buried. From the inbox view, press and hold a message to select it, then tap the three-dot menu icon at the top of the screen and look for “Snooze” in the list of options that appears. If you’ve already opened the message, tap the three-dot menu icon at the top of that screen; you should see “Snooze” show up as part of the options there as well.

16. Make snoozing even simpler in the Gmail mobile app by assigning it to one of your inbox swipe actions. Just open up the app, tap the three-line menu icon in its upper-left corner, then select “Settings.” On Android, tap “General settings” followed by “Swipe actions”; on iOS, you’ll tap “Inbox customizations” and then “Mail swipe actions.”

All that’s left is to set either your left swipe or right swipe to “Snooze,” and then, you can simply swipe any message in that direction from your inbox to snooze it — no wasted taps or menu diving required. (The Gmail Android app has several other similarly useful hidden features, by the way, most of which aren’t available on iOS.)

With one quick setting adjustment, you can snooze any message from the  Gmail mobile app simply by swiping it to the left or the right from your  inbox.

JR Raphael / Foundry

And with that, your Gmail time-saving toolbox is officially complete! The next logical step in your inbox improvement adventure is mastering the art of Gmail labels to fight back against email chaos — and I’ve got just the guide to get you started.

This story was originally published in May 2018 and most recently updated in September 2026.

Kategorie: Hacking & Security

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

The Hacker News - 7 Září, 2026 - 10:31
Every on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able's incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed. N-able has released its fourth hotfix in five weeks for the N-central remote monitoring and management (RMM) platform, this time for a Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

The Hacker News - 7 Září, 2026 - 09:53
Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities. "The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers," Check Point Research said in a Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

N-able patches max severity N-central flaw amid ongoing attacks

Bleeping Computer - 7 Září, 2026 - 08:17
N-able has released an emergency hotfix for a maximum-severity remote code execution (RCE) flaw affecting its N-central remote monitoring and management (RMM) platform. [...]
Kategorie: Hacking & Security
Syndikovat obsah