Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

Bleeping Computer - 24 Srpen, 2026 - 23:14
An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated attackers to create port-forwarding rules that can expose local network devices to the public internet. [...]
Kategorie: Hacking & Security

Hackers target WordPress sites in miniOrange auth bypass attacks

Bleeping Computer - 24 Srpen, 2026 - 21:26
Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. [...]
Kategorie: Hacking & Security

Pro koho a kdy je papírový notes na hesla stejně bezpečný jako password manager

Zive.cz - bezpečnost - 24 Srpen, 2026 - 20:15
Notes s předtištěnými kolonkami na hesla vypadá jako vtip z doby modemů. Než ho ale úplně odsoudíte, zkuste si odpovědět: kdo se k heslům reálně může dostat a před kým je uživatel chrání.
Kategorie: Hacking & Security

TikTok reaches $400M settlement with US over COPPA violations

Bleeping Computer - 24 Srpen, 2026 - 19:56
The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children's Online Privacy Protection Act (COPPA). [...]
Kategorie: Hacking & Security

Apple’s folding iPhone has already launched – in your head

Computerworld.com [Hacking News] - 24 Srpen, 2026 - 17:51

You can’t have missed all the recent leaks. What used to be occasional glimpses into Apple’s future plans, followed by scripted public events, has now become a cadence of leaks followed by announcements.

Apple can’t seem to make a single move without it being telegraphed in advance to its users, usually from the same sources. We get treated to spookily accurate predictions about the big announcements, such as new iPhones. But now we also get a heads up for the smaller stuff, like the recently introduced Apple Upgrade scheme. It makes for interesting reading for the world’s most committed Apple watchers, that interest translates into waves of headlines, which is why Apple now effectively holds endless iPhone announcements each year.

Using the upcoming folding iPhone as an illustration, it works like this:

The seven waves of Apple product launches
  • First, we get an outsider rumor that Apple is about to introduce a new device, in this case a folding iPhone.
  • Later, we might get more speculation, usually along the lines that the still unannounced device has been “delayed” for some reason.
  • third series of rumors drip feed additional details about the upcoming new device. (There could be multiple waves of these.)
  • At some point, Apple will announce the event rumormongers has been predicting for months, spawning yet more reporting, speculation, and analysis.
  • Once the news is officially announced, it has already been reported, discussed, reported again, analysed, refuted, and even denied multiple times. 
  • Of course, the announcement also gets reported.
  • Then, the narrative turns to one of surprise/disappointment/analysis as the real-world product is compared to months of eerily accurate speculation and rumor.
  • Reality sets in as the early reviews arrive, typically first in the US. 
  • Millions rush to buy the new product, by which time many feel like they have nursed its birth for months.
  • Then the post-purchase help, advice, and follow-up reports begin.

But the magic is all in the stage setting during the earlier series of reports.

The arithmetic of anticipation

That means for every key Apple launch, we now experience at least seven waves of announcements for each product each year. Apple now holds two key calendar iPhone announcements annually, which makes for at least 14 waves of news — supplemented by additional speculation about individual models.

These multiple waves quickly add up, creating a tsunami of reporting that cannot help but establish Apple’s new product release in the public eye. How many people — and not just iPhone users — already know to expect a folding iPhone soon? How many also know demand for that device will exceed supply? Heck, we even know it will cost $2,000!

Manufactured consent 

This degree of public consciousness doesn’t happen by accident. It is created one wave at a time. It really doesn’t matter whether the speculation and rumors are generated by Apple itself or by merit of industrious digging on the part of well-connected reporters. It doesn’t matter because the results are the same. 

The rapid pace and multiple waves of leaks create a steady momentum to support any expected product release. This momentum works to Apple’s benefit, even when a leak is negative; the speculation allows for public debate before the bad news unfolds, giving Apple’s public time to digest the information. In this way, every news leak, every rumor, every bit of speculation does its part to support Apple’s incredible marketing machine. 

Momentum doesn’t care whether rumor makes the grade

Are we being cynical about this? Has the brazen nature of the approach turned people off from listening to news and speculation about the company? 

I don’t think so. Perhaps because, as the “father of public relations”, Edward Bernays said in his seminal book, “Propaganda”: “No matter how sophisticated, how cynical the public may become about publicity methods, it must respond to the basic appeals, because it will always need food, crave amusement, long for beauty, respond to leadership. If the public becomes more intelligent in its commercial demands, commercial firms will meet the new standards. If it becomes weary of the old methods used to persuade it to accept a given idea or commodity, its leaders will present their appeals more intelligently. Propaganda will never die out.”

Up next

We’re all expecting Apple to introduce new iPhones on Sept. 9. These will include the first ever folding iPhone, which will be available initially in the US only, and will deliver a high-end premium experience, though there may be some reservations around the camera. We’re also expecting a $100 price bump on other iPhones — but by the time the price increase is announced, we will already have come to terms with it. 

What’s coming next in the iPhone hype-cycle? Well, that will be news of the 20th anniversary glass iPhone, which is already up to wave three in the reporting cycle. Interested in following Apple’s news machinery? Sign up to my daily newsletter.

You can follow me on social media! Join me on BlueSky,  LinkedInMastodon and subscribe to The Core.

Kategorie: Hacking & Security

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

Bleeping Computer - 24 Srpen, 2026 - 17:17
Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team. [...]
Kategorie: Hacking & Security

⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

The Hacker News - 24 Srpen, 2026 - 16:32
A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet. That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks that sound harder than they actually are. Plenty to clean up. Here’s the short version. ⚡ Threat of the Week U.S. Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Microsoft Teams now lets admins block external bots from meetings

Bleeping Computer - 24 Srpen, 2026 - 16:00
Microsoft is rolling out a new Teams meeting protection policy that allows administrators to automatically block all identified external bots from joining Teams meetings. [...]
Kategorie: Hacking & Security

South Korean startup platform breach exposes key management failures

Bleeping Computer - 24 Srpen, 2026 - 16:00
A breach at South Korea's government-backed startup platform exposed encrypted personal data after an encryption key was included in an API. Penta Security explains why encryption keys must be securely managed and kept separate from the data they protect. [...]
Kategorie: Hacking & Security

Microsoft: August updates break printing, PDF export in WPF apps

Bleeping Computer - 24 Srpen, 2026 - 14:40
Microsoft has confirmed that .NET Framework updates released as part of the August 2026 Patch Tuesday are breaking printing and PDF export in WPF applications. [...]
Kategorie: Hacking & Security

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

The Hacker News - 24 Srpen, 2026 - 14:35
Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups. According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Stealer (aka ACR Stealer or AcridRain Stealer) via ClearFake campaigns, which employ the ClickFix (aka FakeCaptcha) Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

BPF Congestion Control Exposed Two Linux TCP Use-After-Free Paths

LinuxSecurity.com - 24 Srpen, 2026 - 14:34
A Linux TCP query can touch congestion-control memory after a concurrent BPF update has freed it. Two new use-after-free reports show how an ordinary read path inherited a lifetime assumption that no longer holds when BPF makes congestion-control objects dynamically replaceable.
Kategorie: Hacking & Security

eBPF Security Patch Expands Link Checks Across Cgroup and LSM Hooks

LinuxSecurity.com - 24 Srpen, 2026 - 14:30
A Linux BPF patch posted on August 21, 2026, expands validation for program replacement across cgroup and Linux Security Module hooks. Version 3 addresses cases where two programs share a broad type but expect different runtime contexts or return rules.
Kategorie: Hacking & Security

Linux 7.3 Development Changes IMA Measured Boot Evidence and TPM Timing

LinuxSecurity.com - 24 Srpen, 2026 - 14:22
Code merged for the Linux 7.3 development cycle changes the measured boot evidence produced by the Integrity Measurement Architecture, or IMA. The kernel now records the raw policy rules that decide what the system measures, closing a gap that could leave remote verifiers without a complete picture of how the evidence was created.
Kategorie: Hacking & Security

Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt

The Hacker News - 24 Srpen, 2026 - 13:58
If your developers are using AI coding tools, you are probably already seeing the upside: faster development, more code, and less time spent on routine work. The harder part is what comes after. AI can also introduce open-source packages at a pace your security team was never built to handle. More dependencies mean more vulnerabilities to review, more remediation work, and a backlog that can [email protected]
Kategorie: Hacking & Security

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

The Hacker News - 24 Srpen, 2026 - 13:56
Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset. The vulnerability, assigned the CVE identifier CVE-2026-18963, is rated 9.1 on the CVSS scoring system by Red Hat, which acts as Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor

The Hacker News - 24 Srpen, 2026 - 13:51
Cybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go backdoor called QUICAgent. The campaign, codenamed Operation QUICSILVER, has been found to target government and information technology sectors, per Seqrite Labs. The activity is assessed to be the work of a China-nexus threat actor with moderate Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk

The Hacker News - 24 Srpen, 2026 - 13:30
Big security risks come in small packages. While enterprise security teams focus on policing the proliferation of employees using ChatGPT and Claude for quick drafting tasks, a more urgent threat is posed by a handful of AI super-adopters who are quietly hardcoding unvetted tools into critical business operations. According to new research published by Akamai, the top 5% of enterprise power [email protected]
Kategorie: Hacking & Security

6 tips for better research with Microsoft Copilot

Computerworld.com [Hacking News] - 24 Srpen, 2026 - 13:00

Copilot, Microsoft’s generative AI chatbot, can do many things, but one of its best uses is as a researcher, for pretty much anything you want in business or personal use.

If you’re looking for in-depth information, there’s a lot more you can do than type a simple request into Copilot’s search box. Simple prompts can be fine when you’re looking for basic information, but for anything beyond that, you need help. Here are six ways to turbocharge your research with Copilot.

Note that Copilot is available in several places and with varying capabilities. Everyone can use the free Copilot app for Windows, macOS, Android, iOS, and on the web. There’s also Copilot Chat in the M365 Copilot web app, which provides access to more powerful tools under some Microsoft 365 subscriptions. And users with certain M365 subscriptions can use Copilot from within M365 apps like Word.

Business users with an M365 Copilot subscription can use an advanced Copilot agent called Researcher, built for very deep dives into enterprise data, which is then formatted into reports. We’ll cover the Researcher agent in this story, but it’s not something most business users would typically use as part of an everyday workflow.

Most of the tips here focus on widely available Copilot features that anybody can use. We’ve demonstrated using the basic Copilot app for Windows; similar features are available in other Copilot iterations.

One last note before we begin: Like all genAI tools, Copilot sometimes makes errors and spouts hallucinations — things that may sound reasonable but are pure fabrications. As you conduct your research, be sure to follow the advice in our guide to curbing hallucinations in Copilot.

1. Choose the right mode for your research task

A simple way to improve your research is to choose the right Copilot mode. Depending on the mode you choose, you can do quick-and-dirty searches, in-depth research, and more.

Just to the right of the + sign in the Copilot search box, you’ll see what mode you’re currently using. The default is Smart. If you click the down arrow next to it, you’ll have four choices. Three of them are ideal for different kinds of research:

  • Smart: This is for when you want results as quickly as possible. Use this when you’re not interested in a deep dive. Keep in mind, though, that there is a way to use it to get highly targeted in-depth research. Because it works so quickly, you can quickly iterate your prompts, digging deeper with each new prompt.
  • Think deeper: This provides a deeper dive and takes a bit more time. It uses multi-step reasoning, gives you a deeper analysis, and offers a more structured synthesis than in smart mode. How much time it will take depends on the complexity of what you’re asking. For the simplest questions, Think deeper takes up to 15 seconds compared to up to about three seconds for Smart mode. (Or so Copilot tells me, and I’ve found it’s generally right.)
  • Search: This mode gives citations and links in your research and is two to four times slower than Smart mode. But if you’re looking for links to confirm Copilot information, or to follow up on, it can be a time-saver. With it, you won’t have to do follow-up prompts to get links as you often need to do in Smart mode.

Choose the right Copilot mode for the kind of research you’re doing.

Preston Gralla / Foundry

The fourth mode, Study and learn, offers guided learning, quizzes, and more. It’s useful, just not for conducting research.

2. Limit Copilot to reputable, information-dense sources

The research work Copilot does for you is only as good as the information it finds. And I’ve found that you can’t always rely on Copilot on its own to find the best information sources — that’s when it can go off the rails.

So when you craft a prompt for research, make sure to tell Copilot specifically where to look for the information. For example, if you were researching how much money the federal government has given in grants to small businesses over the last five years, you could craft a prompt like this:

Briefly summarize the total amount of money the federal government has given in grants to small businesses over the last five years. Use only official .gov sources. Provide links to all sources of information.

If you have found reliable sources of information over the years, point Copilot at those specific websites or pages when you craft a prompt. And if you have files that contain relevant information, upload them to Copilot and tell Copilot to use them for the research.

To do it, click the + sign at the left side of Copilot prompt box and select Add images or files. On the popup, navigate to the files you want, select them, and click Open. When you’re back at the prompt, tell Copilot to use these files exclusively for its research.

You can upload specific files for Copilot to research.

Preston Gralla / Foundry

In the M365 Copilot app with a business or enterprise M365 subscription, you also have an Add work content option in this menu. Choosing this lets you select documents and other files stored in your M365 tenant. If you have an M365 Copilot add-on subscription, you can also reference calendar events and emails.

3. Use images and videos for researching

They say a picture is worth a thousand words — and sometimes, when it comes to research, that may be true. For example, if you’re going to launch a marketing campaign, you might want to make sure that the images you plan to use don’t infringe on copyrights.

In product design, you might want to get detailed information about a competitor’s products, such as what kind of finish they’re using on them. Copilot can even give you information about a competitor’s product such as construction methods, internal product structure, and clues about how it was manufactured if you send it an unboxing video.

Click the + sign at the left side of Copilot prompt box and select Add images or files. From the popup, navigate to the photo, video, or image and select it. When you’re back at the prompt, ask Copilot what you want to know about the image, such as whether the material is public domain or copyrighted.

Copilot analyzing an image to determine whether it’s in the public domain.

Preston Gralla / Foundry

Theoretically, you can also paste in a URL of a video and ask Copilot to analyze it. In practice, though, it’s tough to do.  I tried doing that with multiple YouTube videos, and each time Copilot said I needed a “a direct-access video file link” such as a Dropbox link set to public, a OneDrive public link, or a direct MP4/MOV/WebM URL. I tried a public Dropbox link and it worked. However, as a practical matter, you’ll come across very few links like that in your research.

However, there’s a workaround you can try, using a feature called Copilot Vision in the Copilot app for Windows, macOS, Android, or iOS. In your browser, go to a web page with a photograph, graphic or video, including those on YouTube. Start playing the video (or merely display an image), then head to the Copilot app and click the eyeglasses icon. Copilot will start a chat with you. Say or type what you want to find out about the video or image, and Copilot will answer your questions.

I found that it’s a little kludgy to coordinate all that. But it works.

Copilot analyzing an air fryer based on a YouTube video playing in a browser.

Preston Gralla / Foundry

4. Search your own data

The internet isn’t the only place where there’s valuable data to plumb. You have plenty of vital information under your own control — for example, stored in OneDrive, Google Drive, email, calendar, and contacts, among other places.

There’s a quick-and-easy way to give Copilot access to them, by using Copilot connectors. There are lots of ways you can use this access, for example, to find files and emails about a specific project you’ve worked on, budget information, and so on. You can also use Copilot to search through your calendar for specific meetings.

Note: Some businesses may not allow you to connect to data sources via Copilot, or may have already set up connections for you. Check with your IT department for details.

To set up Copilot connectors, click the + sign just below the Copilot text prompt, then select Use connectors. A list of available connectors appears. As I write this, those connectors include OneDrive, Outlook, Google Drive, Google Calendar, Gmail, Google Contacts, Box, and Dropbox.

Selecting a data source to connect to Copilot.

Preston Gralla / Foundry

Click the Connect button next to the connector you want to set up. You’ll typically first see a general information screen about that specific connector, along with a button to click if you want to create the connector.

Click the button and follow the prompts. The prompts differ from connector to connector. You may need to log in to the service you want to connect to, and you may also get a chance to customize how the access works. For example, if you’re granting access to Gmail, you need to agree to give access email and settings. But you’re also asked if you want to allow Gmail to send email on your behalf and manage drafts. Click See access details for more information about each permission.

When setting up a connector, you can usually customize how Copilot accesses and uses your data.

Preston Gralla / Foundry

A word of warning: I’ve found that the connectors can be flaky — for example, the Gmail connector at times works and at other times doesn’t. And the connector to OneDrive doesn’t search through the contents of files, just file names. Still, despite their limitations, I’ve found them to be useful.

Should you ever decide you no longer want the connection between Copilot and a data source, you can easily remove it. To do it, in Copilot click the Copilot icon — it usually appears on the upper right or lower left part of the screen, depending on the version of Copilot you’re using. Select Settings > Connectors, then select the connector you want to disconnect and follow the prompts.

5. Bring other chatbots’ research into Copilot

When it comes to research, sometimes two or three chatbots are better than one. If you use Google’s Gemini or Anthropic’s Claude, you can take the research you’ve done with them and mine it as a data source when you use Copilot.

The overall way you’ll do this for each chatbot is the same: Export the research you’ve done in a chatbot to a file, save that file to OneDrive or Teams, and then tell Copilot to use that file as a data source. Here’s how to do it for Gemini and Claude.

Use your Gemini research in Copilot

Your best bet for bringing your Gemini research into Copilot isn’t to copy all the individual research chats you’ve had for a given topic. That’s time-consuming, unnecessary, and won’t give Copilot the best, most targeted data.

Instead, first ask Gemini to summarize the research on a given topic, and export that summary. The exact prompt you’ll give Gemini will vary according to the topic and research you’ve done on it. But generally, you want to be as precise as possible about what data you want included in the summary.

So, for example, if you’ve used Gemini to do research on the home office furniture market and asked it to estimate demand over the next five years, you would write a prompt like this:

I am migrating information from you into Microsoft Copilot. Summarize every conversation we’ve had about estimates of the demand for the home office furniture market and create a properly structured Project Intelligence Brief from it. Pay particular attention to any submarkets, such as for furniture used by self-employed people versus people employed by small businesses and large businesses who are working at home. Break it down by industry type as well.

When you create a Project Intelligence Brief about your research in Gemini, you can export it to Copilot.

Preston Gralla / Foundry

After you do that, click the three-dot icon on the upper right part of the Gemini screen and select Export to Docs from the menu that appears. In a short while, select Open Docs from the notification at the bottom of the screen. The document will open in Google Docs. In it, select File > Download > Microsoft Word (.docx).

The file will be downloaded to your PC. Move the file to OneDrive or a SharePoint library or Teams channel, depending on whether it will be used solely by you or other people as well.

Once the file is there, you can use it as the basis for Copilot research. How you do that depends on the how your IT admin has set up file sharing. However, the simplest way to do it if you’re doing it by yourself in OneDrive is to click the + button to the left of the Copilot prompt box, select Add images or files, then navigate to the file. Once you’ve done that, tell Copilot to use that file for your research.

Use your Claude research in Copilot

You follow the same general steps in Claude as you do in Gemini. So, use the same kind of prompt as I outlined for Gemini. In the prompt, tell Claude to create a .docx for it.

Fairly quickly, Claude will create the brief and display it in a right pane so you can scroll through it. To download it, click the Download and open button in the left pane. Follow the instructions outlined in the Gemini section above for how to point Copilot to it.

Creating a research brief in Claude for use in Copilot.

Preston Gralla / Foundry

6. Use Copilot’s Researcher agent

Copilot’s most powerful research tool is Researcher, an AI agent designed for complex, multi-step research tasks. Researcher looks through your work data, including emails, Teams chats, files, meetings, and more, and also goes out on the internet to find what it can. When it’s done researching, it compiles a structured report based on what it finds.

But there’s a catch: Researcher is only available to individuals with a Microsoft 365 Premium license and business users with either an add-on M365 Copilot license or a top-end M365 E7 license, which includes M365 Copilot.

In a business environment, your administrator must enable Researcher for you to use it. If enabled, you access it in the M365 Copilot app. (You can get to the same place by  selecting the Microsoft 365 Copilot app from the waffle menu in the top-left of a Microsoft 365 web app.)

In the M365 Copilot app, select Agents in the left sidebar, then select Researcher from the list of agents. The Researcher agent takes over the Copilot screen.

The Researcher agent in Copilot handles complex, multi-step research tasks.

Microsoft

Type in the prompt box what you want done. Researcher is best for complex or multi-part tasks. So you might ask something like:

Describe the competitive landscape for our new line of home office products that will be launched in the first quarter of next year.

The agent may ask you a few follow-up questions to clarify your request, then it gets to work. It may take some time to complete what you’ve asked it to do, from as little as five minutes up to 45 minutes for very complicated research.

A few things you should know before using Researcher: Unlike a standard Copilot prompt, it can’t use images and photographs as input. It also can’t take any actions for you, such as drafting and sending an email — it only creates research reports. Finally, you can only use Researcher up to 25 times in a given month.

See Microsoft’s Researcher documentation for more information about how to use the agent.

Related reading:

Kategorie: Hacking & Security
Syndikovat obsah