Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

Google fixes actively exploited Android zero-day on Pixel devices

Bleeping Computer - 40 min 28 sek zpět
Google has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks. [...]
Kategorie: Hacking & Security

Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

The Hacker News - 2 hodiny 22 min zpět
A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr. The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verification of a cryptographic signature that could result in account takeover. Hacktron Team has been credited with discovering and reporting the flaw. "JWT authentication Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Acronis warns of actively exploited flaw in its cPanel backup plugin

Bleeping Computer - 15 Září, 2026 - 23:37
Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]
Kategorie: Hacking & Security

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Bleeping Computer - 15 Září, 2026 - 22:34
Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]
Kategorie: Hacking & Security

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

The Hacker News - 15 Září, 2026 - 20:54
Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

CenterPoint Energy confirms customer data stolen in cyberattack

Bleeping Computer - 15 Září, 2026 - 18:40
CenterPoint Energy disclosed a breach compromising some customers' personal information after an attacker leaked data allegedly stolen from the utility company. [...]
Kategorie: Hacking & Security

Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

The Hacker News - 15 Září, 2026 - 18:29
Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's intelligence service uses to spy on dissidents, journalists, and activists around the world. The malware is controlled via the Telegram messaging app and can copy a target's emails and chat messages, take screenshots, and activate the microphone to record Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Oracle forecasts 33% increase in restructuring costs as new round of layoffs hits

Computerworld.com [Hacking News] - 15 Září, 2026 - 18:22

Oracle began a new round of layoffs this week, sending early-morning termination emails to staff for the second time in six months.

The latest wave began Monday with affected staff being told, “After careful consideration of Oracle’s current business needs, we have made the decision to eliminate your role as part of a broader organizational change,” according to BusinessInsider. Termination was immediate.

That’s the same wording as in the previous wave of layoffs, which took place on March 31 and affected workers in the US, India, Canada, Mexico and Uruguay. In the 12 months to May 31, Oracle cut its global workforce from about 162,000 to about 141,000, a decline of roughly 13%.

Oracle has made no public statement confirming the latest round of job cuts, but in a regulatory filing days earlier the company said it had set aside a further $700 million for restructuring charges, bringing the total charges this year to roughly $2.8 billion.

What the new termination emails say

Staff receiving the latest termination emails were told termination and compensation details would follow by DocuSign, Business Insider wrote. An internal document reviewed by the publication said severance terms varied by role and region, and some teams facing double-digit percentage cuts.

Affected employees took to social media to vent.

Eric Brunson, a senior principal offensive security researcher at Oracle, described in a LinkedIn post how he had lost access to corporate communication tools before receiving any formal notice. “I woke up to not being able to log back into Slack,” he wrote. “No new emails or notification in email and I’m locked out of there. I was able to get ahold of my manager on LinkedIn and she confirmed.” Brunson said the timing fell two days before a scheduled RSU vesting date, adding, “Probably part of the plan.”

The filing that backs up the layoff accounts

While Oracle is not talking about the layoffs, its 10-Q quarterly report states that management approved and supplemented restructuring plans “to implement certain strategic measures and further improve operational efficiencies, including through the adoption and integration of artificial intelligence technologies across certain functions.” It adds that “subsequent to August 31, 2026, our management supplemented the 2026 Restructuring Plan by approximately $700 million to reflect additional actions that we expect to take.”

Oracle has already spent $1.97 billion of the $2.1 billion restructuring charges it originally budgeted, it reported.

Sanchit Vir Gogia, chief analyst at Greyhound Research, said the filing should be read carefully rather than as confirmation of a headcount. “The supplement is an estimate, not a bill,” he said, noting it raises the program’s estimated cost by about a third without committing Oracle to a timetable.

Gogia said the more significant shift is in the filing’s language rather than the dollar figure. Oracle’s August 2025 and February 2026 filings had described the plan as tied to “acquisitions and certain other operational activities.”

AI was named as a driver of restructuring for the first time in the Sept. 11 filing.

Why the headcount stays unconfirmed

Gogia said no verified figure exists yet for how many employees the September round affected.

He noted that 30,000 was a January forecast of the total 2026 program. Twenty-one thousand is the confirmed net decline in Oracle’s global workforce across the full fiscal year. A reported 3,000 job cuts in India on Sept. 1 remains unconfirmed by Oracle.

The $700 million restructuring supplement “cannot be divided into people,” Gogia said, since it covers termination benefits, contract termination costs and other exit costs across a program spanning multiple countries. “There is no solid headcount for the September round,” he said.

A pattern that began in March

Oracle’s first 2026 layoff wave began March 31, when the Revenue and Health Sciences unit, the SaaS and Virtual Operations Services group, and NetSuite’s India Development Centre saw some of the deepest reductions.

Figures published by Oracle for its fiscal year ending May 31, 2026, show research and development headcount fell from 50,000 to 43,000 employees during the year, sales and marketing fell from 31,000 to 25,000, and services fell from 37,000 to 34,000, according to Gogia’s analysis of the company’s own reporting.

International staff, at 92,000, saw a larger reduction than the 49,000-strong U.S. workforce, he said.

Oracle did not respond to a request for comment.

This article first appeared on CIO.

Kategorie: Hacking & Security

Tech layoffs: A 2026 timeline

Computerworld.com [Hacking News] - 15 Září, 2026 - 18:21

Among a range of factors leading to a wave of tech sector layoffs in 2026 is the rapid rise of artificial intelligence and automation. Companies are reconfiguring their workforces to leverage AI for increased efficiency and reduced operating costs. This realignment and reduction is implemented even by companies reporting strong financial performance.

But it’s not just AI leading to workforce cuts. Complementing this technological shift are ongoing economic uncertainty, inflation, and higher interest rates, compounded by a chip shortage and rising energy costs. This mix is driving companies to cut costs and streamline operations for increased efficiency.

According to data compiled by Layoffs.fyi, an online tracker that keep tabs on job losses in the technology sector, 123,941 tech employees were laid off at 269 companies in 2025. The site also reports that 71,981 government employees were laid off by DOGE alone, with 182,528 total federal workers laid off.

Here is a list — to be updated regularly — of some of the most prominent technology layoffs the industry has experienced recently.

Notable tech layoffs in 2026
  • Oracle (again)
  • Monday.com
  • Microsoft
  • Meta
  • Cisco
  • Cloudflare
  • Oracle
  • Atlassian
  • Salesforce
  • Amazon
  • Ericsson
Sept. 15, 2026: Oracle forecasts 33% increase in restructuring costs as new round of layoffs hits

Oracle began a new round of layoffs this week, sending early-morning termination emails to staff for the second time in six months. Oracle has made no public statement confirming the latest round of job cuts, but in a regulatory filing days earlier the company said it had set aside a further $700 million for restructuring charges, bringing the total charges this year to roughly $2.8 billion.

July 22, 2026: Monday.com cuts 20% of its workforce to restructure for the AI era

The company says the decision to cut 620 jobs isn’t about margins, but about creating a flatter organization built around AI agents, autonomous teams, and deeper customer engagement.

July 6, 2026: Microsoft cuts 4,800 jobs, primarily in sales and Xbox teams

As the company trims thousands of jobs, it’s also investing in embedded engineering teams and AI infrastructure. The layoffs come several weeks after the company offered 8,750 US employees voluntary retirement buyouts.

June 5, 2026: Tech industry cut 38,242 jobs in May, worst since 2024

AI was blamed for 40% of the job cuts in May, up from 7% in January, according to research by employment placement company Challenger, Gray & Christmas.

May 20, 2026: Meta cuts 8,000 jobs, around 10% of workforce

The cuts are expected to expected to hit Meta’s engineering and product teams the hardest, arriving as Meta pivots toward AI to boost efficiency across its organization, according to Yahoo Tech.

May 13, 2026: Cisco to cut nearly 4,000 jobs despite strong growth in AI, enterprise networking

Despite reporting positive financial news — including record third-quarter revenue of $15.8 billion, a 12% year-over-year increase — Cisco said it will eliminate almost 4,000 jobs.

May 7, 2026: Cloudflare to cut 1,100 jobs in AI-focused restructuring

About 20% of Cloudflare’s global workforce will be culled as the company pivots for the agentic AI era, Reuters reported.

April 1, 2026: Oracle to cut up to 30,000 jobs globally, putting enterprise support and roadmaps at risk

Oracle began laying off employees on March 31 in what could be the largest workforce reduction in the company’s history. Employees received termination emails at 6 a.m. local time with immediate system lockouts and no prior warning. (Note: in June, CNBC put the final layoff tally at 21,000.)

March 12, 2026: Atlassian cuts 1,600 jobs to fund AI and enterprise expansion

Atlassian will reduce its global workforce by approximately 10%, eliminating around 1,600 roles, as the collaboration software maker redirects capital toward artificial intelligence development and enterprise sales.

March 11, 2026: Tech layoffs surpass 45,000 in early 2026

A recent analysis by RationalFX found 45,363 job cuts globally so far this year—with roughly 68% or more than 30,000 occurring in the U.S. — highlighting ongoing workforce cuts even as many tech companies report strong revenue growth.

Feb. 10, 2026: Salesforce lays off staffers as executive leadership churn continues

Salesforce has reduced close to 1,000 roles earlier this month across teams, including marketing, product management, data analytics, and its Agentforce AI unit, Business Insider reported, quoting employees familiar with the matter.

Jan. 23, 2026: Amazon layoffs expected to disproportionately hit AWS and tech talent

As the market slows down, AWS and other Amazon units are preparing for another round of layoffs, which is expected to overwhelmingly impact tech talent. An email from HR leader Beth Galetti on Jan. 28 confirmed 16,000 job cuts.

Jan. 15, 2026: Ericsson plans to shed 1,600 jobs in Sweden

 Ericsson lans to cut some 1,600 jobs in Sweden, the telecommunications equipment maker said doubling down on recent cost-saving measures that have helped it weather a prolonged downturn in telecoms spending, Reuters reports.

Jan. 13, 2026: Meta plans to cut around 10% of employees in Reality Labs business

Meta plans to cut around 10% of the employees in its Reality Labs division who work on products including the metaverse, according to three people with knowledge of the discussions, according to The New York Times.

Layoffs in 2025
  • Cisco
  • Oracle
  • Windsurf
  • Intel
  • Microsoft
  • Crowdstrike
  • HPE
  • Autodesk
  • HPE
  • CISA
  • Workday
  • Salesforce
  • Meta
Global tech-sector layoffs surpass 244,000 in 2025

Economic uncertainty, elevated interest rates, and AI adoption have driven workforce reductions across tech companies worldwide, according to a RationalFX report.

October 28, 2025: Amazon to cut 14,000 jobs across company

Amazon will reduce its overall workforce by 14,000, cutting layers of management across the company and hiring in some areas to support its “biggest bets”.

August 18, 2025: Cisco and Oracle to cut hundreds of Bay Area jobs

Tech companies Cisco and Oracle are cutting hundreds of jobs across the Bay Area. Cisco will eliminate 221 positions at its Milpitas and San Francisco offices, effective Oct. 13. Oracle is reducing 101 positions in Santa Clara on the same date 

August 5, 2025: 3 weeks after acquiring Windsurf, Cognition offers staff the exit door

Cognition, the AI coding startup that acquired rival company Windsurf three weeks ago, laid off 30 employees last week and is offering buyouts to the roughly 200 remaining employees on the team, reports The Information.

July 25, 2025, Intel to lay off 22% of workforce, CEO Tan signals ‘no more blank checks’

Intel will reduce its workforce to 75,000 employees by the end of 2025 as new CEO Lip-Bu Tan implements sweeping changes designed to transform the struggling chipmaker

July 8, 2025, Intel layoffs begin: Chipmaker is cutting many thousands of jobs

Intel has begun laying off employees across the company. CEO Lip-Bu Tan told workers back in April to expect major layoffs at Intel in the coming months as the chipmaker slashes costs and overhauls its organization after years of technical setbacks and falling sales.

July 2, 2025: Microsoft will cut 9,000 workers

Microsoft will lay off about 9,000 employees, a source familiar with the workforce cut told CNBC.  The cuts will reportedly affect less than 4% of Microsoft’s global workforce and will impact different teams, geographies and levels of experience. This is the latest in a string of cuts the tech giant has made this year.

June 17, 2025: Intel looks to factory layoffs to return to profitability

Intel will lay off up to 20% of its manufacturing sector employees starting in July, according to media reports, as the company looks for options as it seeks a return to profitability. The cuts reportedly will be made around the world, but some of the layoffs will be closer to home, according to a report in The Oregonian citing an internal company memo from Intel manufacturing Vice President Naga Chandrasekaran.

May 7, 2025: CrowdStrike to lay off 5% of staff

CrowdStrike announced a plan to cut about 500 roles, roughly 5% of its workforce, to streamline operations and reduce costs. The cybersecurity company will incur about $36 million to $53 million in charges related to the layoffs

March 6, 2025: HPE cuts 2,500 jobs, remains committed to Juniper buy

CEO Antonio Neri told Wall Street analysts that HPE would begin implementing a cost-cutting program involving layoffs of about 2,500 employees over the next 18 months. HPE employs about 61,000 people worldwide.

Feb. 27, 2025: Autodesk to lay off 9% of workforce

Software maker Autodesk is laying off 1,350 staff. With the rise of subscription and multi-year contracts billed annually, and self-service enablement, it finds it needs fewer sales staff, CEO Andrew Anagnost said in a message to employees. And with its cloud, platform, and AI products proving most profitable, it’s concentrating its staff and investments there.

Feb. 27, 2025: HP to lay off 2,000 more

As part of an ongoing restructuring, HP plans to lay off up to another 2,000 workers. In recent weeks, the company has tried — unsuccessfully — to do away with telephone support staff by forcing callers to wait for at least 15 minutes if they refuse to use self-service support resources online. The company swiftly backtracked, but wider job cuts are still on.

Feb. 21, 2025: CISA lays off 130

Government employees get laid off too: In this case, 130 workers at the US Cybersecurity and Infrastructure Security Agency are being shown the door as a result of a DOGE decision. Cybersecurity experts are concerned that the cuts will harm the international collaborations that CISA has fostered, quite apart from their concerns about the security of the DOGE layoff process itself.

Feb. 5, 2025: Workday lays off 1,750

As it moves to invest more in AI and international growth, Workday is laying off 8.5% of its workforce and disposing of unused office space. Some analysts fear the cutbacks will affect the company’s customer service — unless AI can pick up the slack.

Feb. 4, 2025: Salesforce lays off over 1,000

At the same time as it’s hiring sales staff for its new artificial intelligence products, Salesforce is laying off over 1,000 workers across the company, according to Bloomberg. As of June, 2024, the company had over 72,000 employees, according to its website. Salesforce did not comment on the report. In 2024 the company reportedly laid off around 1,000 staff too, in two waves: January and July.

Jan. 14, 2025: Meta will lay off 5% of workforce

Mark Zuckerberg told Meta employees he intended to “move out the low performers faster” in an internal memo reported by Bloomberg. The memo announced that the company will lay off 5% of its staff, or around 3,600 staff, beginning Feb. 10. The company had already reduced its headcount by 5% in 2024 through natural attrition, the memo said. Among those leaving the company will be staff previously responsible for fact checking of posts on its social media platforms in the US, as the company begins relying on its users to police content.

Tech layoffs in 2024
  • Equinix
  • AMD
  • Freshworks
  • Cisco
  • General Motors
  • Intel
  • OpenText
  • Microsoft
  • AWS
  • Dell
Nov. 26, 2024: Equinix to cut 3% of staff

Despite intense demand for its data center capacity, Equinix is planning to lay off 3% of its workforce, or around 400 employees. The announcement followed the appointment of Adaire Fox-Martin to replace Charles Meyers as CEO and the departures of two other senior executives, CIO Milind Wagle and CISO Michael Montoya.

Nov. 13, 2024: AMD to cut 4% of workforce

AMD will lay off around 1,000 employees as it pivots towards developing AI-focused chips, it said. The move came as a surprise to staff, as the company also reported strong quarterly earnings.

Nov. 7, 2024: Freshworks lays off 660

Enterprise software vendor Freshworks laid off around 660 staff, or around 13% of its headcount, despite reporting increased revenue and profits in its fourth fiscal quarter. The company described the layoffs as a realignment of its global workforce.

Sept. 17, 2024: Cisco lays off 6,000

After laying off around 4,200 staff in February, Cisco is at it again, laying off another 6,000 or around 7% of its workforce. Among the divisions affected were its threat intelligence unit, Talos Security.

Aug. 20, 2024: General Motors lays off 1,000 software staff

More than 1,000 software and services staff are on the way out at General Motors, signalling that it could be rethinking its digital transformation strategy. In an internal memo, the company said that it was moving resources to its highest-priority work and flattening hierarchies.

August 1, 2024: Intel removes 15,000 roles

Intel plans to cut its workforce by around 15% to reduce costs after a disastrous second quarter. Revenue for the three months to June 29 stagnated at around $12.8 billion, but net income fell 85% to $83 million, prompting CEO Pat Gelsinger to bring forward a company-wide meeting in order to announce that 15,000 staff would lose their jobs. “This is an incredibly hard day for Intel as we are making some of the most consequential changes in our company’s history,” Gelsinger wrote in an email to staff, continuing: “Our revenues have not grown as expected — and we’ve yet to fully benefit from powerful trends, like AI. Our costs are too high, our margins are too low. We need bolder actions to address both — particularly given our financial results and outlook for the second half of 2024, which is tougher than previously expected.”

July 4, 2024: OpenText to lay off 1,200

OpenText said it will lay off 1,200 staff, or about 1.7% of its workforce, in a bid to save around $100 million annually. It plans to hire new sales and engineering staff in other areas in 2025, it said.

June 4, 2024: Microsoft lays off staff in Azure division

Microsoft laid off staff in several teams supporting its cloud services, including Azure for Operations and Mission Engineering. The company didn’t say exactly how many staff were leaving.

April 4, 2024: Amazon downsizes AWS in a fresh cost-cutting round

Amazon announced hundreds of layoffs in the sales and marketing teams of its AWS cloud services division — and also in the technology development teams for its physical retail stores, as it stepped back from efforts to generalize the “Just Walk Out” technology built for its Amazon Fresh grocery stores.

April 1, 2024: Dell acknowledges 13,000 job cuts

Dell Technologies’ latest 10K filing with the US Securities and Exchange Commission disclosed that the company had laid off 13,000 employees over the course of the 2023 fiscal year; it characterized the layoffs and other reorganizational moves as cost-cutting measures. “These actions resulted in a reduction in our overall headcount,” the company said. A comparison to the previous year’s 10K filing, performed by The Register, found that Dell employed 133,000 people at that point, compared to 120,000 as of February 2024. Dell announced layoffs of 6,650 staffers on Feb. 6, but it is unclear whether those cuts were reflected in the numbers from this year’s 10K statement.

See news of earlier layoffs.

Kategorie: Hacking & Security

Apple to OpenAI: If you have nothing to hide, you have nothing to fear

Computerworld.com [Hacking News] - 15 Září, 2026 - 18:07

Just because Apple now has AI, a new folding iPhone, and a newly minted CEO doesn’t mean the litigation between it and OpenAI has gone away. Apple now wants to force OpenAI to let it look at the hardware it has been building, according to a new report.

A reasonable request?

It seems a reasonable request, doesn’t it? After all, Apple’s argument is that OpenAI has been engaged in trade secret theft to help it design and develop its new hardware. OpenAI’s defense against these claims feel flimsy, at least to this reporter. They seem to coalesce around something like, “We don’t need your trade secrets because we’re making something brand new.” 

The problem with that defense is, contextually, that while on this stated mission to do something completely new, the company has hired around 400 former Apple staff so far, including its chief designers. And Apple thinks part of that process has been OpenAI, in whole or in part, working to exfiltrate its trade secrets.

What Apple wants — and why

With those facts as your guide, Apple’s request to Judge Edward J. Davila seems reasonable. It wants to take a look at what OpenAI is developing to ensure its trade secrets have not been abused in the process of designing that product. Apple argues that if it is forced to wait until the product is released, then it will be impossible to make its trade secrets confidential again, particularly as the defense seems to consist of that pinky promise that no Apple trade secrets have been harmed.

Apple legal also argues that it cannot be fair to allow OpenAI to defend itself by alleging its unreleased and unseen product doesn’t contain any trade secrets without permitting Apple — and the court — to verify that. While Apple’s counsel doesn’t seem to have said it, you could paraphrase the request as Apple telling the genAI firm, “Let us see what you are building; if you have nothing to hide, you have nothing to fear.”

Except, of course, that while building its defense, OpenAI is giving many of us the distinct impression that it may have something to fear.

What may happen next

Despite the merits of the argument, I think Apple’s request will not prevail, in part because the court may assess that if Apple takes a look at OpenAI’s homework it may compound the risk of IP theft. But that doesn’t mean Apple’s attempt will fail outright, as the compromise position is likely to be the appointment of a trusted, independent, third-party expert witness to take a look at what Apple’s competitor is making in Apple’s stead. 

There is precedent for this. That’s more or less what happened when Waymo pursued a similar case against Uber, or when AMCS litigated against Sinovel. There are nuances to all three cases that mean they aren’t perfectly aligned, but that does seem a logical next step to this layman.

Of course, just because it’s logical doesn’t mean either party is going to like it, but OpenAI could conceivably even suggest such an approach as it seeks to buy itself time to build and release its still mythical hardware. That’s also why Apple wants a chance to look at documents pertaining to that hardware to make very certain it hasn’t infringed any of Apple’s own trade secrets.

A side order of humble pie

All the same, if this case does indeed turn out to be a scenario in which one company has been found with its hand in the cookie jar, then the best possible approach for the company with crumbs around its mouth is going to be damage control. That’s going to take a lot less war-war and a great deal more jaw-jaw. It’s also going to require the intake of a very, very large slice of humble pie. Right now, it seems to me that Apple isn’t talking, and OpenAI isn’t hungry enough to take that first bite. Not yet. 

The case, number 5:26-cv-07078, rolls on.

Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSkyLinkedIn, or Mastodon.

Kategorie: Hacking & Security

BambooToken Malware Uses MQTT to Control Windows and Linux Systems

The Hacker News - 15 Září, 2026 - 17:23
Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems. The emerging malware family, codenamed BambooToken, is assessed to be active since at least February 2023 and put to use in attacks targeting organizations across Asia and South America. Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

BambooToken malware controls Windows and Linux systems via MQTT

Bleeping Computer - 15 Září, 2026 - 17:00
A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems. [...]
Kategorie: Hacking & Security

Hackers target WordPress sites via third-party WooCommerce plugin

Bleeping Computer - 15 Září, 2026 - 16:45
Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. [...]
Kategorie: Hacking & Security

What Zero-Day Response Should Be in the Post-Mythos Era

Bleeping Computer - 15 Září, 2026 - 15:45
AI is shrinking the time between vulnerability disclosure and exploitation, leaving defenders less time to wait for patches or public exploits. Picus Security explains how exploitability validation, security control testing, and autonomous pentesting can help teams close exposure gaps before attackers arrive. [...]
Kategorie: Hacking & Security

CISA: Critical VMware RCE flaw now exploited by ransomware gangs

Bleeping Computer - 15 Září, 2026 - 14:16
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July. [...]
Kategorie: Hacking & Security

Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds

The Hacker News - 15 Září, 2026 - 13:52
With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig show that skilled human operators can move just as swiftly after gaining initial access. In one instance highlighted by the cloud security company, the threat actor pivoted from a vulnerable Marimo notebook to an SSH Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point

The Hacker News - 15 Září, 2026 - 13:26
Introduction Security teams have gotten pretty good at testing against what can hurt them. Can this EDR agent catch this payload? Will my organization fail the phishing simulation? Does this SIEM rule fire on this particular technique? And, in more mature organizations, this testing happens continuously rather than as a one-off exercise. But no matter how much you validate against these [email protected]
Kategorie: Hacking & Security

Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers

The Hacker News - 15 Září, 2026 - 13:12
Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an automated effort aimed at internet-exposed Vite development servers that's designed to steal cloud credentials, configurations from Amazon Web Services (AWS) and Microsoft Azure instances, and infrastructure state files, per F5 Labs. The Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Tech CEOs used to fear their boards. No more

Computerworld.com [Hacking News] - 15 Září, 2026 - 12:45

The colorful CEO of Automattic, which controls WordPress, was forced out last Thursday by his board of directors, which put him on a leave of absence. He used his system access to remove the accounts of the acting CEO and others — an action that could get most employees fired. Instead, he was fully reinstated to CEO a couple of days later.

It’s not hard to compare this to the saga at OpenAI almost three years ago when an eerily similar series of events happened. The board fired the CEO for having repeatedly lied to it. Within a few days, the board reversed itself. 

A weaker historical comparison is with Steve Jobs, who was ousted from his Apple CEO role, only to later return. But Jobs at least had the decency to wait a few years while he created and ran NeXT.

To be fair, boards have often been criticized for being puppets of the CEO, who often have a lot to say about who serves on the board. But that criticism doesn’t hold for the first OpenAI board nor for the initial Automattic board.

Some years ago, I was involved with a VC-funded startup, and we were at the stage of forming a board of directors. I was talking with the person who was to be the board chair and he needed candidates for board secretary, which is typically an attorney. That role is supposed to be a lawyer who cares about the board, as opposed to the company’s general counsel, who reports into the CEO and only cares about the company. 

The chair said that we need someone who is trustworthy. I had the perfect candidate in mind, until I probed deeper and found that there is a vast chasm between “trustworthy” and “someone we can trust.” 

I envisioned someone who was honest and had integrity, someone who would take their duties seriously and would tell the board the truth regardless of the implications. That turned out to be precisely what the chair did not want. 

He wanted someone who would vote with us regardless of their legal opinion. He didn’t actually want trustworthy. He wanted blind unconditional loyalty. (That business, thank goodness, never ended up launching.) 

But that seems to be what CEOs now want, which undermines the entire point of having an independent board. Other than deciding whether to accept an acquisition offer, the most important decision of any tech board is the hiring — and firing — of the CEO. 

What does it say when a board makes that decision for what it seems to be a legitimate business reason — and then reverses itself within a couple of days? 

In the case of Automattic, it is not a good look. The board said absolutely nothing about why it forced the CEO out, which made its reversal over the weekend even more perplexing. 

When Automattic emailed reporters on Thursday to announce that the CEO had been ousted, the messages were cryptic: “Matt Mullenweg is currently on leave from Automattic. Mark Davies, Automattic’s CFO, will lead the company as interim CEO. The Board has full confidence in Mark’s leadership and in the team’s ability to execute against the company’s priorities.”

The next we heard was an equally cryptic message sent Saturday afternoon: “Matt Mullenweg is the chairman and CEO of Automattic, with full support of the board, and if you search online you can see many top executives and Automatticians supporting him as well.”

Huh? We then asked for clarification of what happened and why. At 2:26 AM Eastern on Sunday, the media team emailed: “Matt and Automattic’s leadership team have great respect for everyone involved. While we can’t comment on specific individuals, we’re thankful for their contributions to Automattic and its mission, and we remain excited about what’s ahead with Matt at the helm. Matt was away for only 33 hours and 20 minutes — we’re now back to work.”

My proposal: A board’s decision to hire or terminate a CEO should be defended with public specifics. And so should a hiring decision. Or, in this case, a reversal of a mandatory leave of absence decision. 

If the board is going to take the extreme step of relieving the CEO, it should be required to say why. In some situations, it may need to be vague (as in “personnel situation involving a substantiated sexual assault”), but the board needs to give some kind of reason. That should happen so at the very least, a reversal is also explained. 

Further reading:

Kategorie: Hacking & Security

Suspected Black Axe gang leaders face cybercrime charges in the US

Bleeping Computer - 15 Září, 2026 - 11:50
Five alleged leaders of the Black Axe cybercrime syndicate, known for its involvement in global-scale cyber-enabled financial fraud, have been extradited to the United States to face wire fraud and money laundering charges. [...]
Kategorie: Hacking & Security
Syndikovat obsah