Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

Arch Linux disables AUR package adoption to stop malware flood

Bleeping Computer - 31 Červenec, 2026 - 23:38
The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages. [...]
Kategorie: Hacking & Security

Online ad firm Adform’s script compromised to steal cryptocurrency

Bleeping Computer - 31 Červenec, 2026 - 23:09
Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors' clipboards with ones controlled by an attacker. [...]
Kategorie: Hacking & Security

Claude published malicious code to the Internet and attacked 3 real companies

Ars Technica - 31 Červenec, 2026 - 22:39

Anthropic said its Claude-based security models gained unauthorized access to the sensitive production environments of three outside organizations during internal testing designed to measure the models’ offensive cyber capabilities.

The events, which Anthropic revealed Thursday, are the second revelation in 10 days that AI models from the world’s wealthiest providers have trespassed into protected networks, an offense that, in more traditional hacking scenarios, could land the human behind the keyboard in prison for years. Earlier this month, OpenAI said its security models exploited a zero-day vulnerability for use in breaking into the network of Hugging Face, a platform for open source machine-learning models and AI datasets. The OpenAI models went on to steal access credentials and other confidential Hugging Face information. The OpenAI models also exploited publicly exposed credentials to compromise accounts of four other third-party services.

Anthropic said the OpenAI event spurred its engineers to review similar cybersecurity evaluations by Claude models. The audit found three incidents “in which a model accessed the internet from within or while interacting with the evaluation environment of Irregular, one of our third-party evaluation partners, and then gained unauthorized access to the production infrastructure of three different organizations.”

Read full article

Comments

OpenAI says its new GPT 5.6 models are becoming more cost-efficient

Bleeping Computer - 31 Červenec, 2026 - 20:52
OpenAI says it has reduced the price of two GPT-5.6 models, cutting Luna's API price by 80% and Terra's by 20% as it works to make its models more efficient. [...]
Kategorie: Hacking & Security

Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk

The Hacker News - 31 Červenec, 2026 - 20:52
A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January 2025. These targeted organizations operate across several sectors, such as healthcare, research, government offices, Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Google has used AI to patch 1,072 vulnerabilities in Chrome

Computerworld.com [Hacking News] - 31 Červenec, 2026 - 20:16

Google has used AI tools to detect and patch 1,072 vulnerabilities in versions 149 and 150 of its Chrome browser, the company announced in a blog post.

That’s more vulnerabilities patched than in the previous 23 updates combined, according to Bleeping Computer.

One vulnerability detected by AI had been present in Chrome for 13 years but, for some reason, had never been detected by Google’s developers.

To further strengthen security, Google now plans to release new security patches for Chrome every week; down the road, it might even release two updates per week if needed.

Kategorie: Hacking & Security

Hacker uses DeepSeek AI to autonomously attack vulnerable servers

Bleeping Computer - 31 Červenec, 2026 - 19:35
A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement. [...]
Kategorie: Hacking & Security

Apple’s Tim Cook era ends with a record $109B quarter

Computerworld.com [Hacking News] - 31 Červenec, 2026 - 18:52

Apple’s outgoing CEO, Tim Cook, bade an emotional farewell to analysts and shareholders on Thursday as the company announced a record June quarter. His successor, John Ternus, takes over at the beginning of September with the company seemingly in solid shape.

The results were impressive, though some worrying challenges were confirmed. Apple managed to set a new June quarter record, but acknowledged slowing services growth and an unexpected mishap in forecasting future demand. Mac sales jumped an absolutely astonishing 28.7%, as the MacBook Neo grabbed consumer imagination, and overall the company saw growth everywhere except the iPad.

Apple’s fiscal Q3 2026 results saw the company generate $109.4 billion in revenue, up 16% year-over-year for a net quarterly profit of $29.8 billion. Gross margin for the quarter was 50.1%, compared to 46.5% in the year-ago quarter (though two points of this was attributed to tariff returns). 

More specifically:

  • iPhone sales were up 21.7%, an unusually high number for what is traditionally a slower quarter.
  • Wearables increased 6.5%.
  • Services revenue increased 12%.
  • And the iPad declined 5.9%.
The Mac is out the bottle

Apple’s huge Mac quarter is a bellwether moment for the company. The platform is benefiting from both the iPhone halo and the MacBook Neo/MacBook Pro blessing. Apple confirmed MacBook Neo is drawing interest from education and enterprise clients, with Apple CFO Kevan Parekh noting that roughly half of the large US education Mac purchases during the quarter displaced Windows and Chromebook devices. 

Big business wins included a massive 20,000-unit iPhone deployment at Morgan Stanley as the company shifted from employee-owned to corporate-owned/managed devices. The only problem is that demand for both Macs and iPhones is greater than Apple originally anticipated; as a result, some systems could be in short supply moving forward.

Memory, components, and demand

Cook described the current memory pricing environment as a “100-year flood” that forced Apple to raise prices on iPads and Macs. Parekh explained that memory cost changes explain more than 100% of the sequential gross margin decline, with adjusted gross margin falling from 49.3% in March to 48.1% in June (excluding tariff refunds). They’re projected to decline further. 

Cook noted the DRAM market has only three primary suppliers, and Apple is evaluating options for additional supply flexibility.

The company also has a fresh problem on its hands, in that its iPhones and Macs are selling in much bigger quantities than Apple expected. And while the company managed to meet demand in the quarter, it might be constrained in the next. “It’s not a regular supply issue. It’s a demand forecast issue, to be candid,” Cook explained. “The iPhone and the Mac are both doing remarkably better than we thought they would do.… We continue to expect high levels of demand. However, with less flexibility in supply chain, we expect the impact from the supply constraints to increase significantly sequentially.

“We’re seeing some very significant constraints currently with limited flexibility in the supply chain to remedy it.”

Services grew, right?

Apple’s services revenue also grew, but not as much as many analysts had anticipated. Apple passed $30 billion for the first time in a June quarter, buoyed by all-time records in cloud and payment services, while the company’s paid subscription base surpassed 1.5 billion. 

At the same time, Apple confirmed headwinds to services income, principally around currency exchange impacts and volatile economies, softness in mobile gaming, and – confirming the punitive impact of regulation on this part of the Apple business model – App Store business model changes.

What no one yet can know is the extent to which Apple’s recently announced Klarna product leasing deal will contribute both to services income and to accelerated replacement cycles. With 1.5 billion people in its addressable market, it’s very possible that a substantial number of customers will decide to pay for their Apple products on a monthly basis. The result would be a stable, predictable income stream for the company.

What about AI?

Apple’s introduction of Siri AI is delayed in the EU and China due to regulatory hurdles, though the situation in China could soon change following recent reports of an AI support deal with Alibaba and Baidu

Goldman Sachs analyst Michael Ng asked about Siri AI plans and experience. Cook said the company remains “off the charts excited” about Siri AI, and the company continues to receive positive feedback, though he added some warnings about cost. 

Cook explained that to handle users who might want to use Siri AI extensively, the company plans an upgrade option through iCloud+, though it is too early to define the specifics. (Incoming CEO John Ternus said Apple is focused on its own approach to artificial intelligence, but continues to see “enormous opportunity” in the sector.)

What the analysts said

Discussing the results, Morgan Stanley analyst Erik Woodring pointed to decelerating services growth and memory costs nibbling at the edge of Apple’s margins. “Apple’s leverage over the supply chain appears to be in question,” he said, adding it’s not clear whether AI is serving as a measurable tailwind to products or services, with its future monetization impact still uncertain.

Bank of America analyst Wamsi Mohan noted that continued demand means supply constraints are the biggest inhibitor for the stock, since demand will be shunted into subsequent quarters. Wells Fargo also pointed to the longer range picture that despite supply challenges in the current quarter, Apple still has plenty of momentum going into Q1 2027.

Finally, Jeff Pu, of GF Securities, speculated that demand might also be impacted by an estimated $300 increase in the cost of the upcoming 18 Pro series of devices, though this may be partially mitigated by Apple’s new leasing deal.

Cook’s watch is almost over

This was Cook’s 19th and final earnings call as CEO, with his successor joining the call for the first time. Cook closed the meeting with this message: “As you know, this will be my final earnings call, and John will lead these calls going forward. The transition is going seamlessly, and I am beyond excited for John to step into his new role and lead Apple into its next era.”

Apple stock was down around 9% at mid-day Friday as investors consider the quarter’s record results.

You can follow me on social media! Join me on BlueSky,  LinkedInMastodon and subscribe to The Core.

Kategorie: Hacking & Security

CISA warns of cyberattacks disrupting U.S. water utilities

Bleeping Computer - 31 Červenec, 2026 - 18:49
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater systems sector. [...]
Kategorie: Hacking & Security

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

The Hacker News - 31 Červenec, 2026 - 18:39
Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka. According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted archive, which holds a Windows Shortcut (LNK). Executing the file triggers a multi-stage chain that Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Reporter’s notebook: In Dubai’s sun and sand, AI, server farms, and optimism bloom

Computerworld.com [Hacking News] - 31 Červenec, 2026 - 18:30

Walking around Dubai, it’s hard to believe a war is still going on in neighboring countries.

No missiles have struck the city, and it was clear during a recent visit that local residents are keeping to their routines. The biggest public worry, as it has been in many parts of the world, is the extreme heat. (The high today is around 106 degrees.)

Dubai, one of seven emirates in the United Arab Emirates (UAE), continues to emerge as a major global tech hub and is on the verge of becoming a major AI powerhouse. Each of the emirates has their own laws and traditions, with Dubai and Abu Dhabi — the UAE capitol — the most prominent.

Other nations recognize the region’s potential and Dubai’s position. The US, for instance, showed interest in currying favor with the UAE by sending a CIA spy to vet the emirate’s top AI firm, paving the way for future chip and AI deals. That outreach, highlighted in a report in The Wall Street Journal, was a hot topic in the local tech community.

These days, Dubai and Abu Dhabi hope to position themselves as hubs where people and companies go for AI. It’s location makes it an excellent place to do business with connections to Asia, Europe and Africa.

Broadly speaking, the UAE wants to be something of a Switzerland for AI, or “a neutral AI corridor between East and West,” Mahmood Abdulla, a regional technology expert, explained in a 2025 LinkedIn entry.

Data center buildouts

While states like New York are putting a moratorium on the construction of data centers in the US, the UAE is moving in the opposite direction; an aggressive AI data center buildout has government backing.

Stargate UAE, a data center project that involves top tech firms such as OpenAI and Oracle, is being built in Abu Dhabi. The city has essentially planned out a business model designed to turn AI into hard cash with a focus on the energy resources that will play a major role in the effort.

The plan is to redirect Abu Dhabi’s vast energy resources — it has up to 100 billion barrels of known oil reserves — to data centers generating AI tokens. Those tokens can then be sold as compute resources to produce revenue.

With oil markets volatile because of ongoing conflicts and the worldwide rise of renewables, pushing energy use to AI data centers might be a more reliable form of revenue long term.

Will it work? That remains to be seen. But unlike the US backlash against data centers construction in many place, a ban here seems unlikely.

The entrepreneurial spirit

Technological innovations from entrepreneurs have been at the core of Dubai’s rapid growth in recent years as a global business center. Here, AI is already quietly woven into daily life, much as it is in China, where AI is already in factories, homes, and infrastructure.

One founder told me that naming his company to include “AI” is more of a US thing. UAE companies focus less on boasting about AI models and superintelligence; they tend to emphasize user experiences.

On a separate track, Dubai is already targeting the launch later this year of robotic air taxis flying from the airport into the city. (That’s ahead of New York City, where electric air taxis are still being tested.)

Still, Dubai is behind the US when it comes to autonomous ground transport. The first autonomous taxis hit Dubai streets just last year, and there are a limited number operating in tourist areas.

A complicating face tor for the area remains the Iran war. Dubai’s Internet City, a hub with buildings belonging to the likes of Microsoft, Oracle and IBM, largely emptied when the war started in late February. Foreign tech workers left, and property prices declined.

But the real estate market is booming as opportunistic investors buy low. Their bet: the US-Iran war won’t stop the UAE’s growth.

Money is flowing into the area in other ways. Heavy tax burdens in Western countries are pushing wealthy founders to move businesses to Dubai’s tax-free environments. And Dubai is opening the door to those with digital nomad and freelance visas. Although visas can cost thousands of dollars a year, lower rent and healthcare costs compared to the US can offset those costs.

Rivals are emerging, too

UAE’s economic rival, Saudi Arabia is also rising as a tech powerhouse. Riyadh has undertaken reforms at a rapid pace to become an attractive place to do business under its Vision 2030 program.

Saudi Arabia requires corporations to have regional headquarters in the country to win government contracts, a policy that challenges Dubai’s status as a regional business hub.

The UAE also relies heavily on immigrants and human labor, which can be both a plus as well as a challenge. There is no pathway for entrepreneurs or long-time tech workers to retire here, which can undermine worker motivations to stay.

Still, the attractive business environment, combined with local infrastructure and a skilled labor force, make this area appealing. As one founder told me, if the US doesn’t want its most skilled immigrants, the UAE will be happy to welcome them with open arms.

Kategorie: Hacking & Security

Data center developer eyes disused newpaper printing plant

Computerworld.com [Hacking News] - 31 Červenec, 2026 - 18:16

As newspapers move online, the buildings that once housed their printing presses need new occupants.

The Minnesota Star Tribune has just sold its old printing plant on the edge of Minneapolis to the aptly named property developer Legacy Investing, which plans to create a new data center there. has found the ideal way to bring them back to life.

This is the second such move by Legacy. It has already bought a building in downtown Minneapolis that it has transformed into a data center for artificial intelligence and cloud computing.

These old buildings, already connected to power, are an attractive option for developers — especially with some grid operators threatening power cuts for new-build data centers during power shortages.

Legacy is taking a small-is-beautiful approach rather than replicating the massive data centers being built for Big Tech firms. Those are the size of small towns and consume huge volumes of water and hundreds of megawatts of power, while the capacity of Legacy’s downtown building is about 30 MW, and it expects the Star Tribune site to host around 20 MW of data center equipment.

The scaled-down approach may well be an attractive option for operators in the future.

This article first appeared on Network World.

Kategorie: Hacking & Security

DefCon security conference bans smart glasses with recording capabilities

Computerworld.com [Hacking News] - 31 Červenec, 2026 - 17:57

It’s a sign of the times: Security conference DefCon has added smart glasses to its list of banned audio- or video-recording devices.

The organizers have said that, with no consistent way to understand whether smart glasses are recording or not, they have taken the step to ban them in their entirety on the grounds that they erode trust and invade people’s privacy.

Putting corrective lenses in the smart glasses will be no excuse: DefCon insists that visitors bring a pair of glasses without the smarts instead.

The smart glasses ban has been added to DefCon’s already strict rules on photography, which among other things ask visitors not to take group shots and to use “portrait” mode (or a low F-stop for those with old-fashioned cameras) to focus on the foreground, so that people in the background appear blurred.

The smart glasses market has gone up a notch lately. Google and Samsung have both announced Gemini powered eyewear running on Android. Apple is looking to launch its new generation of smart glasses next June, citing privacy concerns as the reason for the delay.

It is not only tech conferences that are getting jumpy about smart glasses. CISOs are beginning to get wary about their impact on organizations and whether their data is secure.

This article first appeared on CSO.

Kategorie: Hacking & Security

Understanding Trust Boundaries in Linux Infrastructure

LinuxSecurity.com - 31 Červenec, 2026 - 17:46
Every time you SSH into a server, run sudo, install a package, or start a container, Linux decides whether to trust it. Most of those decisions happen so quickly that administrators rarely think about them—until one turns out to be wrong. Looking more closely raises an interesting question: why do such different security problems often fail in similar ways?
Kategorie: Hacking & Security

Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies

The Hacker News - 31 Červenec, 2026 - 16:45
Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators. Researchers named the operation Fuyao and attributed it to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China company founded in 2019. The same apps have a second job. When a box Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

ESET tracks rise in malicious AI skills and adaptable malware

Bleeping Computer - 31 Červenec, 2026 - 16:01
Attackers are adapting established techniques to AI platforms, emerging technologies, and changing user behavior. ESET's new threat report examines the rise of malicious AI skills, AI-assisted malware, ClickFix attacks, record quishing activity, and ransomware tools designed to disable security software. [...]
Kategorie: Hacking & Security

Why Python Is the Right Language for Linux Security Automation

LinuxSecurity.com - 31 Červenec, 2026 - 14:53
Linux administrators automate almost everything. Backups run on a schedule, logs rotate on their own, updates ship through pipelines, and health checks happen without anyone opening a terminal.
Kategorie: Hacking & Security

Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined

The Hacker News - 31 Červenec, 2026 - 14:51
Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined. Both versions were released last month. In its latest patch for Chrome 151, released Wednesday, the tech giant resolved 370 flaws, out of which 349 were reported by Google itself. Seven of the Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

From Beginner to Pro: How Your Linux Setup Should Evolve as a Developer

LinuxSecurity.com - 31 Červenec, 2026 - 14:29
Your operating system forms the base layer of your production pipeline. Moving from a basic workstation layout to an enterprise environment takes deliberate work around security hardening, telemetry, and automated provisioning.
Kategorie: Hacking & Security

Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

The Hacker News - 31 Červenec, 2026 - 13:55
An academic study has disclosed a "widespread class" of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denial-of-service (DoS) attacks and even session hijacking, allowing an attacker to seize control of a user's network session. The findings have been released by a group of researchers from Singapore's Nanyang Technological University Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Syndikovat obsah