Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

The Hacker News - 5 Září, 2026 - 22:14
Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is
Kategorie: Hacking & Security

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

The Hacker News - 5 Září, 2026 - 22:14
Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

The Hacker News - 5 Září, 2026 - 18:52
JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.
Kategorie: Hacking & Security

Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

The Hacker News - 5 Září, 2026 - 18:52
JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

The Hacker News - 5 Září, 2026 - 18:05
Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A
Kategorie: Hacking & Security

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

The Hacker News - 5 Září, 2026 - 18:05
Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

Bleeping Computer - 5 Září, 2026 - 16:29
A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]
Kategorie: Hacking & Security

Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted

The Hacker News - 5 Září, 2026 - 16:17
Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets
Kategorie: Hacking & Security

Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted

The Hacker News - 5 Září, 2026 - 16:17
Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware walletsRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

OpenAI admits it didn't disclose rogue AI wiki hijacking incident

Bleeping Computer - 5 Září, 2026 - 13:11
OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]
Kategorie: Hacking & Security

How to automate your Gmail inbox — without AI

Computerworld.com [Hacking News] - 5 Září, 2026 - 12:00

Gmail is filled with hidden features and add-on possibilities, but one of the service’s most powerful organizational tools is sitting right in the heart of its regular settings.

As you may have guessed by now (especially if you read this story’s headline, you clever little cat), I’m talking about filters — Gmail’s long-standing system for automating your inbox with a series of custom-crafted rules. At a glance, filters can seem complicated. They can seem overwhelming. They can even seem unnecessary.

But don’t let yourself be fooled by the feature’s curiously crusty exterior. Gmail filters have the potential to completely reshape your inbox and the way your incoming messages are handled. They can help you keep your email in order with no ongoing thought or effort.

And, unlike Google’s new AI Inbox option (which notably still doesn’t seem to be available for most people as of this writing), filters (a) don’t require your personal messages to be processed by generative AI systems — and (b) give you complete control over exactly how your email is handled instead of forcing you to rely on inherently unreliable technology to figure out what you want for you (and then likely come up short at least some of the time).

Best of all? All it takes is a teensy touch of one-time planning to get Gmail filters set up to your exact specifications and working for you quietly and automatically from that moment onward.

Follow the filter-centric Gmail tips in this guide, and your inbox will be running like a well-oiled (but not too greasy) machine in no time.

Part 1: Figuring out your Gmail filters

Let’s start by thinking through some Gmail filter possibilities to get an idea for the sorts of setups you might want to consider — then, we’ll go step by step through the process of creating them.

With Gmail filters, you could:

  • Ensure messages from specific high-priority senders always go into your inbox’s Primary tab, where you’re certain to see them
  • Ensure specific sorts of lower-priority messages — like invoices, reports, or updates from different services you use — automatically get sorted into an out-of-the-way location and never even show up in your inbox
  • Keep messages from annoying people out of your hair (but still available in case you need to find them) by automatically archiving them as soon as they arrive
  • Forward messages from a specific address or with a specific phrase in their subjects to other members of your team or family
  • Instantly respond to messages to or from a specific address with a prewritten template
  • Label messages sent to a specific variation of your Gmail address (like [email protected]) or written with a specific word or phrase in the subject (like “urgent,” “important,” or “hey jerkwad, pay attention to this”) as “VIP” and then receive notifications only for messages with that designation
  • Mark specific types of messages from yourself as reminders by giving them a bright yellow “REMINDER” label that makes them stand out in your inbox
  • Get a snickerdoodle delivered to your desk every time your boss emails you

All right, so that last one isn’t really possible (not yet, anyway) — just wanted to make sure you were still paying attention. Everything else in that list, however, is absolutely doable and actually quite easy to set up with Gmail filters.

Got some ideas of your own? Good deal. Time to make ’em happen.

Part 2: Creating your Gmail filters

The simplest way to start a new Gmail filter is to click the control panel icon — the symbol showing three horizontal lines stacked on top of each other — within the big search box at the top of the Gmail website. (Filters can’t easily be managed on mobile, unfortunately, so you’ll need to do all of this in a desktop browser.)

That’ll pull up a form where you can fill in whatever you want to use as the basis for your filtering — a word or phase that might appear within an email’s subject or body, an address from which a message could originate, or any other variable or combination of variables you like.

The form for creating a filter is filled with options for controlling email automation.

JR Raphael / Foundry

Fill in the fields as appropriate, using however many variables you want — even employing quotation marks around multiword terms along with operators like “AND” and “OR” between terms, if you really want to get fancy — and then click “Create filter” at the bottom of the box.

You can use any combination of variables, even employing operators within a single field, to control when your filter will run.

JR Raphael / Foundry

One quick warning: By default, your filter will apply to any and all incoming messages — hence the “All Mail” setting that shows up next to the “Search” option in the filter creation pop-up. If you change that option to “Inbox,” you’re likely to see an error message informing you that the parameters you chose are not recommended and may not work properly. Leave that “Search” option set to “All Mail” — which is probably what you want, anyway — and you’ll steer clear of any errors and allow things to work the way they should.

Now it’s time for the fun part — the part where you decide exactly what happens when a message meeting your conditions arrives. You can select any combination of actions from the list and then configure them as needed. You can even tell Gmail to apply your filter retroactively to messages already in your account (as opposed to using it only for new messages that arrive from that point forward) by checking the “Also apply filter to matching conversations” option at the bottom of the box.

Gmail’s filters include a variety of actions that can execute when your conditions are met.

JR Raphael / Foundry

Once you’ve got that finished, click the blue “Create filter” button — and that’s it: Your new Gmail filter is officially in place and active. The next time any message comes in that meets the parameters you outlined, the actions you specified will automatically take place faster than you can say “I embrace Workspace in my workplace cyberspace.”

Part 3: Managing your Gmail filters

Last but not least, make yourself a mental note in case you ever need to adjust your filters in the future: If you want to edit, delete, or even just revisit a filter you created, just click the gear-shaped icon in the upper-right corner of the Gmail website, click “Settings,” then click the “Filters and Blocked Addresses” tab at the top of the settings screen. You’ll see every filter you’ve ever created there and can tweak or remove any of ’em with a couple quick clicks.

Now if only we could find a way to get the filters to deliver those blasted snickerdoodles for us. Hey, Google: Any chance you can make that happen?

This article was originally published in October 2019 and most recently updated in September 2026.

Kategorie: Hacking & Security

Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel

The Hacker News - 5 Září, 2026 - 09:55
A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs
Kategorie: Hacking & Security

Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel

The Hacker News - 5 Září, 2026 - 09:55
A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runsSwati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

The Hacker News - 5 Září, 2026 - 09:31
Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as
Kategorie: Hacking & Security

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

The Hacker News - 5 Září, 2026 - 09:31
Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

New Linux Kernel Patch Targets a Page-Cache Memory Bug

LinuxSecurity.com - 5 Září, 2026 - 02:30
Linux maintainers are testing a patch for a page-cache bug after KASAN reproduced a use-after-free in filemap_map_pages(). On Sep 3, 2026, Andrew Morton said he would update the changelog, add cc:stable, and queue the patch for testing while awaiting review.
Kategorie: Hacking & Security

Linux May Restrict TCP Socket Reuse After a Memory Bug

LinuxSecurity.com - 5 Září, 2026 - 02:15
Linux TCP permits a listening socket to be transformed into a different kind of socket. A reproduced memory race has led maintainers to question whether that flexibility is worth keeping.
Kategorie: Hacking & Security

Confidential Containers Need a Boundary the Linux Host Cannot Cross

LinuxSecurity.com - 5 Září, 2026 - 02:00
Linux containers are efficient because they share the host kernel. That same design gives the host deep authority over container memory, mappings, and process state. If the host is compromised or untrusted, namespaces cannot keep workload secrets away from it.
Kategorie: Hacking & Security

OpenAI agents discussed ways to escape their sandbox on public wiki

Ars Technica - 5 Září, 2026 - 00:17

Self-identifying OpenAI agents posted 18,000 messages to a public wiki that discussed ways for other agents to bypass security sandbox restrictions during what was likely internal testing designed to gauge the agents’ hacking abilities, researchers said Friday.

In all, agents with 3,700 distinct self-given names posted the messages to German site DSEwiki over a six-week period. Besides discussing ways the agents could break out of the restricted environment OpenAI intended to prevent them from posting code or content to the Internet, the posts shared test answers. The posts also shared possible ways to perform XSS (cross-site scripting) attacks against the wiki and to impersonate site moderators. In three of the posts, agents used the word “swarm” to describe the collection of agents engaged in the activity.

Colluding to share answers

The research team—composed of Sydney Von Arx, Spencer Kitts, Thomas Larsen, and Cormac Slade Byrd—said they found the posts and pieced them together. The researchers say there are gaps in their understanding of precisely what actions the agents took because the research is based solely on the content of the posts. Additionally, the agents generated “chain of thought” data that’s understood only by OpenAI. As a result, the researchers said, they in some cases made educated guesses, including that the agents were, in fact, from OpenAI. In a statement, OpenAI later confirmed they were.

Read full article

Comments

“Trust, not features, is the real deficit”: VMware tries to appease SMBs

Ars Technica - 4 Září, 2026 - 19:35

For many small-to-medium-sized businesses (SMBs), VMware has become too expensive.

Broadcom’s acquisition of the virtualization firm brought the end of perpetual license sales and the arrival of pricey, stacked, subscription-based bundles that priced out many SMBs.

The most obvious is VMware Cloud Foundation (VCF), VMware’s flagship private cloud bundle that has been Broadcom’s primary focus since taking over VMware. Many SMBs find that VCF is unaffordable and stuffed with unnecessary offerings. However, numerous customers have reported online that VMware sales representatives have still pushed them toward VCF, with some claiming that sales reps have told them that the lower-priced edition of VMware’s virtualization platform, vSphere Standard, was no longer available.

Read full article

Comments

Syndikovat obsah