Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

Microsoft fixes Teams, Outlook launch failures on ARM Windows PCs

Bleeping Computer - 26 min 43 sek zpět
Microsoft has fixed a bug that prevented Teams and Outlook from launching on ARM-based Windows devices after installing updates released since the August 2026 Patch Tuesday. [...]
Kategorie: Hacking & Security

OpenAI pauses $200 Pro tier as Astra demand strains capacity

Computerworld.com [Hacking News] - 42 min 36 sek zpět

OpenAI has paused new sign-ups and upgrades to its $200 ChatGPT Pro tier, citing a surge in demand for its Astra capability that is placing pressure on system capacity, according to company statements and an executive post on X.

“To make sure our current users have an incredible experience and continued access to Astra, we are going to pause subscriptions to our $200 Pro plan,” OpenAI member of technical staff Thibault Sottiaux wrote in a post on X. “These put the most strain on our systems and we wanted to take the smallest step that allows us to continue giving the broadest access possible.”

The company separately confirmed the move in its help documentation, stating that “as of September 10, 2026, we’re temporarily pausing new sign-ups and upgrades to the ChatGPT Pro $200 plan (Pro 20X).” The pause applies to users across Free, Go, Plus, and Pro $100 tiers seeking to upgrade, while “existing ChatGPT Pro $200 subscriptions … are not affected by this pause,” it said.

Sottiaux added that “there is no impact to existing accounts and we are working on adding more capacity as fast as we can,” pointing to ongoing efforts to scale infrastructure in response to demand.

Users who cancel or downgrade during the pause will not be able to re-subscribe to the $200 tier until the restriction is lifted, according to the company’s help page. The $100 Pro tier remains available, with lower usage limits. Promotions tied to the $200 tier are also paused, the page read.

Astra demand drives capacity decisions

The decision is directly tied to the uptake of Astra, which OpenAI has positioned as a more advanced capability within its platform. The scale of that demand, according to Sottiaux, has been atypical.

“Demand for Astra is really unprecedented,” he wrote in the post. “We’re pulling all the levers possible to sustain the demand, but I’ve not seen anything like it until now and we went through very steep growth before.”

He added that “priority will always be to keep excellent service for existing users,” noting that the company “might have to pause new Pro subscriptions for a bit if this continues.”

The pause comes amid broader rollout challenges tied to Astra. OpenAI Chief Executive Sam Altman recently described the launch as “messy” after some paying users were unable to access the model immediately, reflecting the operational complexity of deploying high-demand AI systems at scale.

Capacity constraints surface for enterprise workloads

The pause, analysts said, reflects how demand for high-intensity AI workloads is intersecting with infrastructure limits, particularly at the highest usage tiers.

“It signals that frontier capacity is still rationed,” said Bhupendra Chopra, chief revenue officer at Kanerika. “One week after launching Astra, OpenAI paused new sign-ups and upgrades to the $200 Pro tier, the plan with the heaviest Astra usage limits, while the $100 Pro tier, the API, Business and Enterprise all stayed open. That tells you the priority order.”

“Consumer power users are the release valve. Enterprise contracts are what the vendor protects,” Chopra said. “For CIOs the lesson is that a model being announced and a model being available to your workloads at the volume you need are two different events.”

Chopra said the move reflects how access to advanced AI capabilities is being managed.

“We are already there,” he said. “Rate limits, usage caps, queueing and now sign-up pauses are all forms of capacity gating, and every frontier vendor uses some of them.”

“A subscription buys you a place in the line. A fixed slice of compute comes only from a contract that says so,” he added.

Planning for constrained supply

For enterprise IT leaders, Chopra said model capacity should be treated as a dependency.

“Treat model capacity like any other supply chain dependency,” he said. “Ask the vendor three questions before you sign. What throughput is contractually committed, what happens to my workloads when demand spikes, and how quickly can I fail over to another model.”

“If a workload is production-critical, it should run on an enterprise agreement with committed capacity… and it should have a second model tested and ready,” he said.

A recurring pattern

Chopra said the pause reflects a broader pattern seen in recent launches.

“This is at least the third time in two years OpenAI has throttled or paused access at launch,” he said. “Each launch outruns capacity, capacity catches up, and the next model outruns it again.”

“OpenAI calls this pause temporary, and it will lift once capacity catches up,” he added. “The structural condition… will persist as long as model capability keeps outpacing data center buildout.” OpenAI has not provided a timeline for when new sign-ups to the $200 Pro tier will resume, stating only that the restriction is temporary.

The article originally appeared on CIO.com.

Kategorie: Hacking & Security

Trezor: 347,000 users targeted in phishing attacks after Brevo breach

Bleeping Computer - 2 hodiny 11 min zpět
Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link. [...]
Kategorie: Hacking & Security

Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

The Hacker News - 2 hodiny 35 min zpět
Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz said in a report. Wiz saw the attacks between August 15 and September 8. JFrog had fixed both flaws before then, so only servers that had not been updated were open to them. Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

The Hacker News - 2 hodiny 52 min zpět
A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital said in research published Thursday. The attack started with a crafted link and ended with the attacker able to do anything the logged-in user could do. Tencent, which owns Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Conti ransomware gang member sentenced to 4 years in prison

Bleeping Computer - 3 hodiny 17 min zpět
A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022. [...]
Kategorie: Hacking & Security

PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws

The Hacker News - 3 hodiny 20 min zpět
PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download. "These are Regular Maintenance Releases (MR) that Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

The Hacker News - 3 hodiny 46 min zpět
Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypassRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Automattic CEO Matt Mullenweg is out: Does this mean long-term viability, or liability, for WordPress customers?

Computerworld.com [Hacking News] - 9 hodin 14 min zpět

Automattic CEO Matt Mullenweg has been abruptly put on a paid leave of absence from the company by its board of directors, despite his objections. But enterprise IT executives who rely on WordPress may find the shift doesn’t mean much as long as Mullenweg fully controls WordPress.org, which handles all of the product’s patches and updates.

“The part of WordPress that actually keeps enterprise IT up at night isn’t Automattic’s org chart. It’s WordPress.org, the plugin and theme directory every WordPress site pulls its security updates from, and the WordPress trademark,” said Frank Dickson, principal analyst at Dickson Research. “Mullenweg owns and controls both personally, outside of Automattic, and nothing about this week’s vote touches that. He also remains a director on Automattic’s board. The company changed who runs its hosting business without changing who controls the distribution pipeline millions of those hosted sites still depend on.”

For IT leaders who rely on WordPress, it’s important to differentiate what is currently known about the change and what is speculation. A statement emailed to Computerworld from Automattic merely said: “Matt Mullenweg is currently on leave from Automattic. Mark Davies, Automattic’s CFO, will lead the company as interim CEO. The Board has full confidence in Mark’s leadership and in the team’s ability to execute against the company’s priorities.” 

However, messages from Mullenweg to Automattic employees made it clear that the move was one that he strongly opposed. He posted on his X account, “the next step in this playbook is to restart the smear attacks, so get ready for some National Enquirer rumors or hit pieces.”

He added: “I appreciate the hundreds of colleagues who have already expressed public and private support, and are organizing in solidarity. It’s a big help to counter the ‘Matt is an idiot and shouldn’t run an ice cream stand’ allegations. Also, whatever you can say about me, I’m direct and probably overcommunicate, which I’m going to continue doing through this mess folks have made.”

He also posted separately that he is looking to hire, but that applicants cannot be current Automattic employees. “I really need some great sysadmin and security researchers to hire really quick, no one from @automattic. I’m on the board there and fully support Mark Davies in his interim CEO role. But I think it’s probably good if I move some of my stuff currently hosted there, elsewhere.”

Next steps unclear

What is unclear are likely next steps. Is the leave permanent or temporary? And if temporary, how temporary? Is the board negotiating with Mullenweg, and might those negotiations involve whether Mullenweg continues to control WordPress.org? Neither Automattic nor Mullenweg provided clarification.

Melody Brue, analyst-in-residence at Moor Insights & Strategy, who has closely tracked WordPress for years, said that the apparent speed of Mullenweg’s removal as Automattic CEO suggests that the board was trying to sidestep something serious.

“It has to be some exposure or risk that was severe enough that speed outweighed any optics or fairness. Boards don’t generally move that abruptly,” she said. The appointment of the CFO as interim CEO “definitely shows some stabilization and possibly some legal compliance cleanup. What it doesn’t say is renewed product investment.”

IT worried about instability

But the longstanding worries among CIOs about WordPress were not primarily about the perceived lack of continued investment. It was the concern that Mullenweg has a tendency to react strongly to a situation, apparently without many thoughts of the consequences

Nothing better illustrated this than Mullenweg’s personal war with WordPress hosting provider WP Engine that resulted in a series of legal rulings in WP Engine’s favor. 

WP Engine litigation is still ongoing, and that may have played a role in the board’s actions. 

Part of that lawsuit is at the heart of enterprise IT concerns: Mullenweg had denied WP Engine access to WordPress.org resources, including patches, plugins and security updates for the software. 

The IT fear is that Mullenweg could unilaterally take similar actions against any customer, even an enterprise. 

“I would still treat this as vendor risk, because WordPress.org is still controlled by Matt, separate from Automattic,” Brue said. “The question is, who actually controls the plugins that these IT leaders rely on? It’s still a structural risk. Look at whether the patches flow through one person. For now, they still do. Is that pipeline protected by independent governance, oversight? That is what matters for enterprise IT.”

Flavio Villanustre, CISO at the LexisNexis Risk Solutions Group, agreed. 

“Most of the concerns from enterprises about using WordPress come from the fragmented ecosystem and the inconsistent security controls and support of modules and extensions, which have led to significant vulnerabilities in the past,” Villanustre said. “The change of CEO in their parent company won’t directly affect this, especially because Matt Mullenweg will continue as the WordPress[.org] leader anyway.”

Dickson also agreed, noting that the question of who sits in the CEO seat at Automattic was not the issue.

“The enterprise IT concern was never really about Automattic’s management bench. It was about one person holding unilateral, unaccountable control over a piece of critical open-source infrastructure,” he said. “In 2024, Mullenweg used exactly that control to cut WP Engine’s customers off from plugin and theme updates overnight, with no board sign-off and no customer input, purely as leverage in a business dispute. This week’s vote proves a board can restrain him inside Automattic. It says nothing about what restrains him at WordPress.org, because the honest answer is still nothing.”

In fact, rather than reducing those IT worries, Dickson argued that this move could worsen them. 

“If anything, this should sharpen the concern rather than settle it. A board just decided it couldn’t function with him running a corporate entity with ordinary fiduciary obligations,” he pointed out. “That same person still holds sole authority over the update pipeline for software that runs over 40% of the web. Risk teams that were nervous about concentration risk in WordPress now have a fresh, concrete data point: the concentration is real, and untouched by whatever just happened at Automattic’s board table.”

This change could help

Mike Wilkes, enterprise CISO at Aikido Security, interpreted the events differently, and suggested that it might indeed make WordPress look more attractive to enterprise IT.

“This could ultimately make WordPress more attractive to enterprise buyers, but only if it becomes the beginning of stronger institutional governance rather than simply a change in personalities,” he said. “CIOs don’t particularly care about palace intrigue until that intrigue can affect software updates, supply-chain dependencies or business continuity. The WP Engine conflict demonstrated that governance risk can become operational risk surprisingly quickly. The ongoing litigation underscores that this is not merely historical baggage.”

Wilkes pointed out that the next few steps taken by the board and by Mullenweg will likely be far more informative than any analysis of the board’s CEO change.

“I wouldn’t tell a CIO that yesterday’s announcement makes WordPress either safer or riskier today. I would tell them to watch what happens next,” he said. “If Automattic uses this moment to create clearer separation between corporate interests, WordPress.org infrastructure, and community governance, it could reduce one of the ecosystem’s most persistent concentration risks. If the same authority simply migrates to different individuals without structural reform, enterprise concerns haven’t really changed. In cybersecurity terms, replacing the administrator isn’t the same thing as eliminating the single point of failure.”

Dylan Forde, owner of Harmonic Design in Oakville, Ontario, Canada, and a WordPress developer for more than ten years, applauded the CEO change. 

“It is my opinion that the removal of Mr. Mullenweg is a good thing for both the WordPress community and open source,” he said. “He has been divisive for a long time, with many grievances that I overall understand, but I oppose his responses to. It sucks to build something used by millions of people and businesses around the world, all profiting off your work while giving nothing back. But cutting off and targeting individuals is not the answer. Open source is supposed to work for everyone, and my assumption is that anyone whose core business relies on WordPress will be sleeping easier now.”

Kategorie: Hacking & Security

New Android malware encrypts files, steals data, and harasses victims

Bleeping Computer - 10 Září, 2026 - 23:40
A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. [...]
Kategorie: Hacking & Security

September Windows Server updates break Remote Desktop Services

Bleeping Computer - 10 Září, 2026 - 22:34
Windows admins report that the September 2026 security updates are causing Remote Desktop Services (RDS) failures on Windows Server 2019, 2022, and 2025 servers, preventing users from connecting and, in some cases, requiring a hard reset to restore functionality. [...]
Kategorie: Hacking & Security

Why Linux Must Close File Descriptors Before a Filesystem Can Stall

LinuxSecurity.com - 10 Září, 2026 - 21:30
A file descriptor is the numbered handle a running program uses to access an open file or similar resource. Linux can mark it to close automatically when the program replaces itself through exec(). That cleanup can involve waiting for a filesystem, which makes its timing important.
Kategorie: Hacking & Security

Surfshark VPN says hackers breached internal testing, proxy servers

Bleeping Computer - 10 Září, 2026 - 21:15
Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet. [...]
Kategorie: Hacking & Security

Linux Sandbox Bug Could Read a Freed Parent Directory

LinuxSecurity.com - 10 Září, 2026 - 21:10
A Linux sandbox restricts which files a program can access. Landlock, a kernel facility that lets programs apply those restrictions to themselves, had a bug in the code checking file locations. A concurrent directory move could leave the check reading memory that had already been released.
Kategorie: Hacking & Security

Microsoft Excel KB5002914 update breaks copy and paste for some users

Bleeping Computer - 10 Září, 2026 - 21:07
Microsoft Excel users report that this week's KB5002914 Office security update is breaking copy-and-paste operations and formula dragging, with affected users saying that removing or rolling back the update restores normal functionality. [...]
Kategorie: Hacking & Security

ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

The Hacker News - 10 Září, 2026 - 19:47
A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up until it isn’t. Different stories, same basic problem: the path in was often already
Kategorie: Hacking & Security

ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

The Hacker News - 10 Září, 2026 - 19:47
A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up until it isn’t. Different stories, same basic problem: the path in was often already Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

How Apple is trying to normalize always-on AI

Computerworld.com [Hacking News] - 10 Září, 2026 - 19:28

Apple does seem to have tried to ensure its controversial Audio Intelligence feature isn’t abused. Alongside the iPhone Duo and new iPhone 18 Pro range, Apple on Wednesday introduced a new Apple Watch equipped with a brand new feature it calls Audio Intelligence. The existence of this surprising tool was confirmed only on the eve of the launch event. Enabled by the new S11 chip on the latest Watch devices, this is actually a collection of four features:

  • Siri Recap, which creates high-level summaries of conversations during your day.
  • Live Rewind, which transcribes the previous 15 seconds of a conversation as text.
  • Music recognition, which relies on Shazam.
  • Sound recognition, which can identify things like sirens or alarms.

All of these features must be consciously enabled by the user and are not on by default.

What they have in common is use of artificial intelligence along with always-on microphones. While all four of these tools are being presented as opt-in, their existence will inevitably — and justifiably — raise privacy concerns. 

Apple saw those concerns coming, and to make the features work it has placed a Secure Enclave on the S11 chip inside the latest watches. This is a dedicated secure buffer on the chip that processes audio privately on the fly. It does so without creating a recording of ambient sound around you, and the data it works with is isolated from the rest of the system. That Enclave pairs with the iPhone using “a new audio-verified pairing mechanism that exists in addition to Bluetooth pairing,” Apple explains in a detailed white paper about how it works. 

For Siri Recap, the process works like this:
  • Apple Watch recognizes a conversation is taking place.
  • If so, audio flows into the Secure Enclave, encrypted, and transmitted to a similarly Secure Enclave on your paired iPhone.
  • The audio is then immediately deleted from the Watch. 
  • The phone will decrypt and transcribe the audio, condense it, and send that transcript to Private Cloud Compute for processing. 
  • The short summary is then made, returned, and deleted after seven days.
  • Speakers are not identified, recordings are not made, and detailed transcripts are not created or retained.

The company has also introduced safeguards for those around you. The system will deliberately omit some information, including potentially harmful content, financial data, or personal identifiers. When you use the Live Rewind tool, an audible chime plays on your device to alert nearby people that you are using the feature.

Challenges will emerge

For one thing, we don’t yet know whether the company will provide enterprise IT with device management tools to disable the feature on managed devices. It’s crystal clear that devices that are constantly gathering data will be seen as potential security risks — particularly in regulated industries. And it seems far more logical to provide new APIs to disable Audio Intelligence on managed devices than it would be to insist anyone wearing an Apple Watch put it in a lead-lined box before beginning the next safeguarding, healthcare, or product development meeting.

Another problem I see concerns Europe’s Digital Markets Act. It is, after all, inevitable that competitors (maybe including Meta) will want their devices to have equal access to the information gathered by Audio Intelligence. Based on the decisions Apple has made so far, it seems equally likely it will want to refuse such access; this is why these new features will not initially be available in the EU. 

There is also no doubt hackers will attempt to break into the system, though doing so will not be at all easy on account of the intentional way the company has built in security. I suspect, but do not know, that attempts will focus on the points at which data is exchanged across devices, rather than when the information sits within secure enclaves on those devices. It also makes sense that everyone who uses iCloud services for their data should put 2FA in place and pick strong passwords. 

What about iCloud storage?

The other challenge will be encryption, specifically ongoing attempts to penetrate iCloud data encryption by some nations, led by the UK. Even so, if access could be achieved to iCloud-stored Audio Intelligence text, what is obtained would only be summary data, not a recording. The system is architected so recordings are never made.

Apple’s white paper on the feature explores this in more depth: “Audio from the microphone enters the Secure Exclave of Apple Watch, where it is initially processed for speech, sounds, or music, without transcribing or storing the raw audio. This buffer is a continuously overwritten stream that exists only within the protected hardware and never creates an audio recording.”

Once you decide to keep a Recap or Life Rewind text, the raw audio is not saved to iCloud, only the text, and then only if you use 2FA and a device passcode. No one else, including Apple, can access the encrypted data you save, Apple said.

Where does this go next?

One pre-event rumor that didn’t come true concerned AirPods equipped with cameras and Vision Intelligence to understand physical context and surrounding, with the aim of enhancing Siri AI. I’ve expressed reservations about this idea, but do think the security model Apple has put in place for Audio Intelligence will turn out to be an echo of its intentions to secure Vision Intelligence transactions.

This implies a new chip with Silicon Enclave for AirPods Pro, a similar exchange of information in real time for summary and determination of context and content, and a process in which no recordings are made and media access beyond brief, time-limited summaries, is available. In short, Apple will use the same security model.

What about the rest of them?

That’s fine as far as it goes. But the other subtext is that while Apple seems genuine in its attempt to deliver relatively intrusive tech advances right, others will show less commitment to privacy and security. So, while it’s furthering the conversation about using these tools, Apple is also pushing public acceptance of such technologies.

I’m not entirely sure we’re ready.

Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSkyLinkedIn, or Mastodon

Kategorie: Hacking & Security

AI-powered attack exploited PaperCut flaws to hack 395 organizations

Bleeping Computer - 10 Září, 2026 - 17:55
A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers. [...]
Kategorie: Hacking & Security

Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers

Bleeping Computer - 10 Září, 2026 - 17:43
Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. [...]
Kategorie: Hacking & Security
Syndikovat obsah