Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

Cronos blockchain restarts after $74 million Tectonic exploit

Bleeping Computer - 31 Srpen, 2026 - 22:47
The Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending platform allowed an attacker to borrow $74 million. [...]
Kategorie: Hacking & Security

eBPF Security Research Misses eBPF’s Own Attack Surface

LinuxSecurity.com - 31 Srpen, 2026 - 22:30
An eBPF security system can produce precise Linux telemetry while leaving a harder question unanswered: what happens if the eBPF layer itself is misconfigured, vulnerable, or trusted too broadly?
Kategorie: Hacking & Security

Windows bug incorrectly tells users that Microsoft Defender Antivirus is turned off

Computerworld.com [Hacking News] - 31 Srpen, 2026 - 22:13

Microsoft on Friday reported that a glitch is causing Windows to tell users that Microsoft Defender Antivirus is turned off when it is in fact fully functional, a bug that the vendor says it is working to fix.

Consultants say that this advisory raises a major concern in that it will train users to ignore critical alerts, which makes them far more susceptible to attacks.

The Microsoft release health dashboard update on the issue reported: “After installing the latest updates for Microsoft Defender Antivirus, notifications might appear stating that ‘Microsoft Defender Antivirus is turned off’ even though the antivirus is functioning correctly and all settings show it as active. These notifications can appear when Windows starts and intermittently afterward. They persist even if notification settings are turned off. This issue can be observed in any version of Windows or Windows Server with Microsoft Defender Antivirus running with the latest Defender updates.”

The post added: “We are working to release a resolution in a future Microsoft Defender Antivirus update and will provide more information when it is available.”

It then listed the various Windows client and server versions impacted: everything from the current Windows 11, version 26H1 and Windows Server 2025 back to Windows 10 Enterprise LTSC 2016 and Windows Server 2012.

Bad guidance

Industry observers said the suggestion that users ignore these alerts is concerning.

“Microsoft has just published guidance telling enterprises to ignore the exact signal that precedes a large share of ransomware detonations,” said Aman Mahapatra, chief strategy officer for technology consulting firm Tribeca Softtech, pointing out that disabling endpoint protection is standard tradecraft across virtually every ransomware affiliate playbook over the last five years.

“The alert Microsoft is telling people to disregard is the same alert an operator triggers minutes before encryption starts,” he said. “That is a genuine security regression created by a bug advisory and the open-ended timeline on a fix makes it worse.”

More disturbingly, he expects many security operations centers (SOCs) will create rules to suppress these alerts, which will make the problem even more severe.

“When a signal fires constantly and is known to be false, human response degrades in days, not weeks,” Mahapatra said. “A SOC seeing hundreds of these across a Windows fleet will write a suppression rule by next week, because the alternative is drowning [in false alerts], and that rule will outlive the bug by months. Nobody goes back to remove filters that are keeping the queue clean.”

Mahapatra also predicted that attackers will quickly leverage the bug to help in social engineering attacks. 

“An attacker calling a help desk with ‘You’ll see Defender alerts on my machine, Microsoft says it’s the known bug, ignore it’ now has a corroborating vendor advisory backing the pretext,” Mahapatra said. “Help desks have been primed for exactly this issue. That is a working pretext with public documentation behind it, and it will get used.”

Lane Thames, team lead for cybersecurity R&D at Fortra, amplified Mahapatra’s concerns.

“IT teams need to be very careful about how they communicate this problem to users, and that communication should happen immediately,” Thames advised. “The message cannot simply be, ‘If Windows says Defender is turned off, ignore it.’ That is exactly the behavior we spend years teaching users not to adopt.”

“The better message is that Microsoft is currently experiencing a known notification issue with Microsoft Defender, but users should continue reporting security warnings through the normal help desk or security channel,” he said. “IT should verify Defender’s actual state rather than asking users to make that determination, otherwise, when the next warning is real, users may have already been trained to ignore it.”

This Microsoft alert “creates a perfect opportunity for a real attack to hide in the noise,” he added.

Degradation of trust

But Thames stressed that there is a bigger potential issue: degradation of trust.

“Security notifications only work when users believe them. If Windows repeatedly tells someone that their antivirus is disabled when IT tells them that it isn’t, eventually one of those sources loses credibility, if not both,” he said. “Microsoft needs to resolve this quickly, because false security warnings have a large consequence: they degrade the trust that security controls depend on.”

Tom Kellermann, VP of AI security and threat research at TrendAI, a division of TrendMicro, added that in the attacks his team has analyzed, roughly 67% leverage tampering with and disabling security software, something that is is usually a precursor to “a more systemic and intrusive campaign.”

The Microsoft advisory’s wording “is a poor example of crisis communications” and is “ridiculous,” he said. “Do not trust that advice [to ignore the alert]. Verify if it’s accurate and involve your threat hunting teams,” who can examine XDR telemetry.

Preserve the evidence

Noah Kenney, principal consultant at Digital 520, advised CISOs and CIOs to save evidence of this situation to prove insurance claims that will likely initially be denied. 

“Six months from now, an insurer looking at a breached server won’t accept ‘Microsoft said there was a bug’ as proof that Defender was running. The popup says off. Microsoft says on. The company’s own telemetry has to break the tie,” he said. “That means time-stamped records of sensor check-ins, Defender versions, and any gaps in reporting. CISOs should save those records now. The patch will make the warning disappear, but it will not recreate evidence if the company failed to retain it.”

He noted that his greatest concern about the Microsoft alert is its wide impact on many Windows versions.

“Windows 11 26H1 and Windows Server 2012 are fourteen years apart, and Microsoft says this bug can hit both,” he said. “Companies separate desktops, servers, legacy systems, and critical infrastructure into different patch rings, but Defender runs through all of them. The popup will get patched, but that shared failure path through the Windows estate will still be there, and a bad update can produce the same wrong security signal everywhere at once.”

Kategorie: Hacking & Security

Linux CPU Hotplug Exposes Regmap IRQ Use-After-Free Path

LinuxSecurity.com - 31 Srpen, 2026 - 22:12
Linux interrupt maintainer Thomas Gleixner traced a Kernel Address Sanitizer report to incomplete regmap IRQ cleanup on Aug 30, 2026. The crash appeared while Linux was taking a CPU offline, but the stale pointer was created earlier when a device’s interrupt setup failed.
Kategorie: Hacking & Security

Linux GPU Security Issue: DRM Patch Addresses Cross-Driver Fence UAF Reads

LinuxSecurity.com - 31 Srpen, 2026 - 22:00
Jonghyuk Kim submitted a Linux Direct Rendering Manager scheduler patch series on Aug 28, 2026 that targets a use-after-free read shared by several GPU drivers. The proposed change caches a fence’s timeline name while its scheduler is still alive.
Kategorie: Hacking & Security

Microsoft warns of TerminalFix attacks deploying reverse tunnels

Bleeping Computer - 31 Srpen, 2026 - 20:51
A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal. [...]
Kategorie: Hacking & Security

North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales

The Hacker News - 31 Srpen, 2026 - 19:24
Threat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected workers employed in sales and marketing and the medical profession. The ongoing insider threat is part of what has been described as the IT worker scheme, Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Microsoft Exchange Online outage causes email failures, auth issues

Bleeping Computer - 31 Srpen, 2026 - 18:56
Microsoft is investigating a widespread service issue causing authentication issues, email delays and failures, and various other issues for Exchange Online customers. [...]
Kategorie: Hacking & Security

OpenAI confirms ChatGPT outage as users report errors

Bleeping Computer - 31 Srpen, 2026 - 18:50
ChatGPT Work is experiencing a partial outage, and users across multiple subscription plans may be unable to start or continue tasks. [...]
Kategorie: Hacking & Security

Think twice before installing this device promising free movies

Ars Technica - 31 Srpen, 2026 - 18:33

As online services get better at blocking malicious traffic, the attackers and scammers behind them have been forced to find new ways to reach their targets. The alternative of choice is now what are known as residential proxy networks. These systems funnel millions of home Internet connections into a unified network, and the proxy operators allow attackers to route their malicious traffic through these connections for a fee. The online services see only IP addresses with good reputations and geolocations that don’t stand out.

More often than not, the home users have no idea that their connections are being used to facilitate crime and occasionally even nation-state attacks. Users who do know often don’t care much. In exchange for leasing out part of their unlimited bandwidth to others, many get free movie and TV show streaming. Several less tech-savvy people I know who own such digital media players have told me, after I explain how the media players piggyback off their connections, that the bonanza of content is worth it. They find the tangible benefits outweigh the abstract harm they pose.

Infecting already compromised devices

Research published Monday brings the threat into much clearer view. Security firm Plume cataloged a vast ecosystem of malware that preys squarely on users of SuperBox, just one of many media players offering pirated content. These malicious apps can be surreptitiously installed by remote attackers even when the devices are positioned behind a router. While Monday’s deep-dive analysis focused exclusively on SuperBox, Plume warned that dozens of similar streaming devices pose precisely the same threat.

Read full article

Comments

At Hot Chips ‘26, all eyes were on AI costs, GPUs — and the future

Computerworld.com [Hacking News] - 31 Srpen, 2026 - 17:59

When you think of AI, and Nvidia’s GPUs often come to mind because they have been so much a part of the ongoing AI revolution.

But at the recent Hot Chips show in California, an alternative future appears to be taking shape as corporate concerns continue to grow about cost, energy use and AI slowdowns.

New AI chips detailed at the event by OpenAI, Intel, Meta and others promise cheaper and faster token generation at lower power consumption. Chipmakers are also moving AI away from GPUs and onto CPUs and PCs.

“What Hot Chips demonstrated…is that the market underneath Nvidia is becoming much more diverse,” said Stephen Sopko, an analyst at Hyperframe Research.

Though enterprise AI budgets continue to go up, the focus is increasingly on finding ways to make AI more productive and reducing waste in the budget. “But I would not tell CIOs that their AI budgets are therefore going down,” Sopko said.

Hot Chips pointed to a future where more AI work can be squeezed out of the same watt, rack or dollar with new hardware designs and power management. “The cost of performing a given unit of AI work should continue falling dramatically,” Sopko said.

OpenAI shared details of its homegrown AI chip called Jalapeño, which will help the company “serve more demand and lower the cost of delivering a successful result,” according to a blog entry.

OpenAI started its AI journey with Nvidia GPUs, and plans to spend $750 billion on data centers to power its tool and services. The Jalapeño chip will presumably spice up those data centers for inferencing.

Research firm SemiAnalysis was granted exclusive access to test the chip and came away impressed with what it found. “In general, first-generation chips are not competitive, but OpenAI bucks the trend by being industry-leading and beating every Nvidia, AMD, and Google chip we have been able to test on multiple top open source models,” SemiAnalysis said in a newsletter report. 

AI compute will over time be more distributed than it has been in recent years, but cloud will continue to be an important option for highly compute-intensive requirements, said Jack Gold, principal analyst at J. Gold Associates.

Within the next year or two, thousands of agents will be running on edge platforms, AI PCs, localized servers or sovereign data centers, Gold said. “It’s going to be a larger number of vendors’ chips running different apps that are not all GPUs from one vendor,” he said.

GPUs can be costly from a power and performance perspective for agentic AI, which is “why you see the major GPU players like Nvidia and AMD emphasize new AI-friendly CPU architectures,” Gold said.

Nvidia has recognized the need for chips beyond its own GPUs for inferencing. At Hot Chips, the company shared details about its Vera CPU and Groq 3 LPX inferencing chip, for instance.

Meanwhile, Intel talked up an upcoming server CPU called Diamond Rapids, and a PC CPU called Wildcat Lake; the latter is designed to bring AI to edge devices and low-cost laptops.

Diamond Rapids has AI extensions so inferencing can be done on the CPU without redirecting the workload to other co-processors. The Wildcat Lake chip has neural processing units (NPUs) and borrows features from Intel’s Xe3 graphics chip, which is also used in the company’s AI inferencing GPUs. (It’s similar to Intel’s existing Panther Lake chip.)

System architecture changes were also a big part of the conversation at Hot Chips, said Jim McGregor, principal analyst at Tirias Research, who attended the show. Most presentations focused on eliminating bottlenecks in data movement, advanced chip designs and computing closer to or inside memory, he said.

Enterprise AI is likely to become increasingly heterogeneous, Sopko said. As a result, IT decision-makers should design AI architectures so they can move between GPUs, CPUs and specialized chips as the economics of AI change, he said.

“The strategic risk isn’t choosing the wrong chip in 2026. It’s building an AI architecture that prevents you from taking advantage of a much cheaper or better one in 2028,” Sopko said.

Kategorie: Hacking & Security

With new leadership, Apple will re-define success

Computerworld.com [Hacking News] - 31 Srpen, 2026 - 17:25

Apple CEO Tim Cook becomes chairman of the company board tomorrow, with John Ternus taking over the top job in Cupertino. Both men followed in the footsteps of visionary Apple co-founder Steve Jobs, and both have found they must build their own definition of success.

The past is a guide, but not a template

Think back to 2011 when Jobs pushed Cook into the CEO seat. It was a tragic start, as cancer took Jobs much too early. When Cook stepped into the role, people didn’t seem to expect much from him as CEO. He was a strategy and operations type, after all, not a visionary. He had no product design background, they said.

That opinion never seemed to shift, no matter what Cook did. It’s as if Apple Music, AirPods, Apple Watch, Vision Pro, AirTag, Apple Pay and other services, the development of Apple’s own processors, and the company’s financial success (despite challenging disasters such as COVID-19) counted for nought.

Cook’s ethical commitments, particularly toward LBGT+ and Black representation, privacy, and the environment have also become far more fundamental to corporate DNA than they were under Jobs. The Jobs-era Apple was worth a healthy $350 billion when he stepped down; as Cook moves on, Apple has become a $4 trillion corporation with hundreds of millions of consumers contributing monthly recurring fees for a variety of compelling services.

You need to follow your own star

Perhaps it didn’t matter that critical opinion didn’t shift. Cook’s tenure saw the man define his own measure of success. Some may recall that when Jobs launched the iPhone in 2007, he said, “Every once in a while, a revolutionary product comes along that changes everything.” 

Jobs argued that the Mac, iPod, and then iPhone were all such products. It’s important, I think, to remember that Cook was part of the team that launched the last two of those and arguably contributed to the iMac, which redefined the first. My point is that revolutionary products do not grow on trees; even Jobs understood that. So did Cook — and his work on the Vision Pro and AI showed how challenging it is to build revolution. Success is seldom a straightforward journey. Jobs himself might have found himself considering the difficulty of such voyage on April 11, 1985, when ousted from the company he loved.

But Cook didn’t look to his predecessor for a definition of success. That’s what lazy journalists and an expectant public did. Instead, what Cook did was lean into his strengths to build on what was already there for the benefit of the company he also loved. 

It is arguable that changing the payment habits of the entire global economy from cash to cashless has been something revolutionary. So much so that even Walmart has at last caught up. Apple Pay now has something like 92% share among US mobile wallet users. I truly believe that a future honest appraisal of Apple under Cook’s leadership will identify an extensive number of major successes that have been buried by the lazy and inaccurate “not a product guy” narrative.

Eyes wide open

Which brings me to Apple’s new CEO, Ternus. What kind of leader is he going to be?

His colleagues describe him as collaborative and even-tempered, with a deep focus on product refinement. We’re told he is working to rebuild Apple’s famed design department, gutted by high-profile departures and aggressive recruitment by OpenAI. While we do know he has been groomed for the role for a few years, we don’t really know a huge amount about him — except that he’s being presented to us by Apple and its media satellites as a “product guy.” He’s a hardware engineering veteran taking his position as Apple heads into the AI era and he’s going to be under pressure to prove the company has what it takes to succeed going forward.

The way Cook’s Apple has designed this transition leans into the perceived strengths and weaknesses of both men. Ternus turns up just in time Apple to introduce an expected wave of exciting AI-enabled products including the first folding iPhone, a future glass 20th anniversary iPhone (in 2027), amazing new Macs and exciting smart products, including pendant and smart home accessories. (There is still no car yet — can you imagine how much RAM that thing would need?) 

Under Ternus’ leadership, Apple is going to try to redefine the company as a product innovation factory, with AI as the secret sauce to hold its hardware dream together. The ongoing litigation against OpenAI shows how deeply competitive things are likely to get. Things might even become politically tough, though Ternus will have the strategic and operational genius of Cook available to him on the executive board.

Stay hungry, stay foolish

Looking at the transition, its important to point out that both Cook and Ternus have been working together (along with the wider Apple team) to set the stage. You only need to look at the big decisions that have slipped out from Apple in just the last couple of months to see how Cook wants to give his successor as clear a slate as possible to ease that transition. They are doing succession by the book, and the company is probably already working on similar succession plans to support future departures from its current aging senior leadership. I suspect Ternus already knows both who his executives are today and who will be in place tomorrow.

Under Jobs, the company became visionary, under Cook, it became vast, and under Ternus, the measure of success starts with the idea of him being a “hardware guy,” though that success remains to be defined

Which is the point. We shouldn’t measure Ternus by comparison with either predecessor, any more than we should gauge Cook in comparison with Jobs. Each CEO reflected a company going through different times, and we don’t know what the future holds. We just know that for Apple, it’s now for Ternus to try to define what success for him should look like. “Stay hungry, stay foolish, don’t settle,” as someone once said.

Please subscribe to my daily Apple-related news headline summary at The Core. You can also follow me on BlueSky,  LinkedIn, and Mastodon.

Kategorie: Hacking & Security

Chinese Fire Ant hackers turn Cisco routers into spying platforms

Bleeping Computer - 31 Srpen, 2026 - 16:52
The researchers discovered Fire Ant's new tactic after finding an active GRE (Generic Routing Encapsulation) tunnel interface on a Cisco IOS XR router that could not be explained by a running configuration or commit history. [...]
Kategorie: Hacking & Security

File servers are here to stay. Here’s how to manage them securely

Bleeping Computer - 31 Srpen, 2026 - 16:00
File servers remain a critical part of many IT environments, but managing access securely can become complex as permissions accumulate. tenfold Software outlines five best practices for simplifying file server administration and maintaining least-privilege access. [...]
Kategorie: Hacking & Security

⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More

The Hacker News - 31 Srpen, 2026 - 15:50
The boring parts caused most of the trouble. A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even an AI agent decided its assigned task was optional. Elsewhere, fake apps, helpful support calls, cheap banking kits, exposed systems, and weak defaults keptRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Berlin confirms data theft after Rhysida ransomware attack claims

Bleeping Computer - 31 Srpen, 2026 - 15:30
Berlin's city administration has confirmed that cybercriminals are attempting to extort the city after the Rhysida ransomware gang listed it on their data leak site. [...]
Kategorie: Hacking & Security

ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions

The Hacker News - 31 Srpen, 2026 - 14:14
The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions. Russian cybersecurity vendor Kaspersky said the attackers built the disguise around QN Wallpaper, a genuine Chinese desktop-wallpaper tool Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets

The Hacker News - 31 Srpen, 2026 - 13:47
Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX's artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security. The two independent analyses are based on exposed infrastructure associated with the Russian-speaking cybercrime group, leading to the discovery of its Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance

The Hacker News - 31 Srpen, 2026 - 13:31
Claude Code reads files, runs shell commands, invokes MCP tools, and acts through the credentials available on a developer’s machine. Anthropic’s new Compliance API endpoints give security teams their clearest view yet into that activity. They also expose a larger problem: activity logs alone cannot tell you whether an agent’s access is legitimate. AI has moved from the browser tab to the [email protected]
Kategorie: Hacking & Security

Copilot Pages: Work side by side with AI

Computerworld.com [Hacking News] - 31 Srpen, 2026 - 13:00

When you’re working with Microsoft Copilot to create a business document, you might find yourself torn between two opposing instincts. Part of you is itching to edit its output right away, while another part wants to keep prompting the AI assistant to refine the generated text.

Turns out you can do both.

The Pages feature in the M365 Copilot app is a dynamic text editor that works in a window alongside your Copilot chat. It lets you turn the AI’s response into a persistent document (a “page,” in Microsoft parlance) that you can edit manually while continuing to collaborate with Copilot on it.

You can also invite your co-workers to collaborate on it, either by sharing the page with them or by embedding it in a Word document, Outlook email, OneNote note, or Teams chat as a Loop component. (More on that later.)

In this guide, we’ll go over how to use the Pages tool in the M365 Copilot app. It’s available with a paid Microsoft 365 plan and, notably, does not require a separate Copilot license. This means that enterprise users who have a Microsoft 365 plan but not a Microsoft 365 Copilot add-on plan can use Copilot Pages.

(Confusingly, there’s also a lower-end free Copilot app for users who don’t have an M365 account. It has its own basic Pages tool, but it doesn’t include all the features of Pages in the M365 Copilot app.)

In this article: Create a Copilot page

Copilot Pages works within the M365 Copilot app. Head to microsoft365.com (the old-school office.com works too), where you’ll see the Copilot Chat interface front and center.

Get your first page going: Simply type in a request for Copilot as usual.

To start a Copilot page, start a Copilot chat.

Howard Wen / Foundry

When Copilot gives you a result that you want to turn into a document, such as a list of action items or an outline for a marketing plan, scroll to the bottom of the result and click the pencil (Edit in Pages) icon. (Depending on your M365 subscription, you might have to click the three-dot icon and then select Edit in Pages from the menu that pops up.)

width="831" height="561" sizes="auto, (max-width: 831px) 100vw, 831px">

Click the Edit in Pages option below Copilot’s result to launch a page.

Howard Wen / Foundry

The screen will split into two windows, with your chat with Copilot on the left and a document canvas (your new page) containing the generated text on the right.

Your new page opens to the right of your Copilot chat.

Howard Wen / Foundry

Give your new page a name: Before you do anything else, move the pointer to the upper-left of your page. The first few words you wrote to Copilot in your prompt appear inside a text box. Click the text box and type in an appropriate name for the page.

Edit your Copilot page

Each text item on your page canvas (paragraph text, heading, bulleted list item, etc.) is a separate element that you can edit in various ways.

Add or edit text: Click inside a text element and start typing. To select a word, double-click on it. To select a line of text, triple-click on it.

Format text: Select the text you want to format. This action will open a formatting toolbar where you can change the font style (bold, italic, underline, etc.), formatting (headline, list, etc.), or color of the highlighted text.

width="930" height="195" sizes="auto, (max-width: 930px) 100vw, 930px">

Highlighting text brings up the formatting toolbar.

Howard Wen / Foundry

Move a text component: Move the pointer over the component until you see a small icon with six dots in a grid to the left of it. Click-and-hold this icon, drag the component down or up the page, and let go where you want to relocate the component on the page.

width="1024" height="177" sizes="auto, (max-width: 1024px) 100vw, 1024px">

Use the six-dot icon to drag and drop any text component to a new location on the page.

Howard Wen / Foundry

Copy or delete a text component: Click the six-dot icon. On the menu that opens, select Copy (a copy of the component will be saved to your clipboard) or Delete.

Add a component: Place your mouse pointer at the end of a text component and press Enter. In the “Just start typing…” field that appears on the next line, type in your new text. Your new component will be formatted as paragraph text by default, but you can reformat it as described above.

Alternatively, you can move the pointer over a text component and click the + icon (Click to insert below) that appears to its left, or just type a forward slash (/). This will summon a menu of several components that you can add to your page. The ones listed under the “General” category will be the most relevant for work-related purposes: Table, Checklist, Bulleted list, Numbered list, Date, Callout, Table of contents.

width="885" height="694" sizes="auto, (max-width: 885px) 100vw, 885px">

Type / to bring up a list of different text components you can add to your page.

Howard Wen / Foundry

Revise and expand your page with Copilot

From the document canvas, you can use Copilot to rewrite passages of text in two ways:

Use Copilot to rewrite a text component: Highlight the text you want Copilot to rewrite. On the formatting toolbar that opens, click Ask Copilot. (Or click the six-dot icon to the left of the component and select Ask Copilot from the menu that opens.)

A text entry box will open. Type a prompt inside it that describes how you want Copilot to rewrite the text in the component, such as making it more concise or giving it a more professional tone.

width="897" height="353" sizes="auto, (max-width: 897px) 100vw, 897px">

Prompting Copilot to rewrite selected text.

Howard Wen / Foundry

Use Copilot to rewrite an entire page: Alternatively, you can have Copilot rewrite the text of your page as one document. At the lower-right corner of the document canvas, click the backwards “S” icon (Copilot shortcuts). This will open a mini-toolbar with three icons:

  • Adjust content: The four selections under this icon will trigger Copilot to rewrite your page to be more concise or detailed, or to rewrite it as an email or blog post.
  • Change tone: Four selections here will prompt Copilot to adjust the tone of your page.
  • Style page: These selections will prompt Copilot to add section headers to your page, if they’re not already present, or have it write an introduction or conclusion paragraph for your page.

Options for having Copilot rewrite an entire page.

Howard Wen / Foundry

Add more text generated by Copilot to your page: With the document canvas open in the right window, you can still chat with Copilot in the left window, and add additional content that Copilot generates in your chat to your page in the right window.

In your prompt, tell Copilot to add the text it generates to your open page. It will be added where you’ve set the cursor on your page. Or, at the bottom of the text that Copilot generates in the left window, click the + icon (Add to page). The newly generated text will be added to the end of your page.

You can continue chatting with Copilot and add more material to your open page.

Howard Wen / Foundry

Share and collaborate on your Copilot page

In addition to collaborating with Copilot on your page, you can invite co-workers or clients to edit the page as well.

Share your page

Click the Share button (an icon of an arrow over a square) at the at the upper-right corner of your page. You’ll see a menu with two options:

  • Page link: Generates a link to your page that you can paste in an email or chat to share with other people.
  • Copy component: Creates a different kind of link that lets you embed your page in a Word document, Outlook email, OneNote note, or Microsoft Teams chat as a Loop component that co-workers can collaborate on. (See our Microsoft Loop cheat sheet and guide to using Loop components in M365 apps for details about how this works.)

Sharing a Copilot page.

Howard Wen / Foundry

When either link type is generated for your page, you’ll be presented with a confirmation panel. Click the Settings button on this panel if you want to change the access permissions for the link to your page.

This will open a panel that lets you specify who can access your page through this link, and whether they can edit your page. People you can share the page with include co-workers in your organization, specific people you invite, or, if your company allows it, anybody at all. You can also set an expiration date for when the link will no longer work, as well as a password that people must enter to access your page.

Collaborate on a page

If you’ve given others permission to edit your page, they’ll be able to add, move, and delete the text elements on the page, as well as tag other collaborators and add comments. They’ll only see the page itself, not your Copilot chats. If the receiver has their own Copilot license, they can use Copilot to edit the page.

Tag a person: If there’s a component in your page that you want a co-worker to take a closer look at, insert the cursor somewhere in this component and type the @ symbol followed by their name. If they’re in your Microsoft 365 contacts, their name should pop up for you to select. Their tagged name will appear in this component, and they’ll be notified in an email.

width="982" height="158" sizes="auto, (max-width: 982px) 100vw, 982px">

You can tag a co-worker in a specific component on a page to make sure they see it.

Howard Wen / Foundry

Add a comment: There are multiple ways to start a comment on a page:

  • Double-click text or highlight a passage of text that you want to comment on. On the toolbar that opens, click the speech balloon (Comment) icon.
  • Click the six-dot icon that appears to the left of the component, and from the top of the menu that opens, click the speech balloon icon.
  • Right-click anywhere on the component. From the top of the menu that opens, click the speech balloon icon.
width="1024" height="461" sizes="auto, (max-width: 1024px) 100vw, 1024px">

Adding a comment to a page.

Howard Wen / Foundry

When you write a comment, you can tag a person by typing @ followed by their name.

Export your Copilot page

You can export your page to Microsoft Word or PDF. At the upper-right corner of your page, click the three-dot button, select Export, and then select either Document or PDF.

width="839" height="358" sizes="auto, (max-width: 839px) 100vw, 839px">

You can export a page as a Word doc or PDF.

Howard Wen / Foundry

When you export a page to Word, it will open in the Word web app in a new browser tab. When you export it to PDF, it’ll be downloaded to your PC.

Manage your Copilot pages

The pages that you create from your chats with Copilot appear in the Library section of the Microsoft 365 Copilot app.

At the upper-left corner, click the Expand navigation icon. A sidebar opens along the left. Click the Library icon, and the pages you’ve created or been invited to will appear in the main window.

The pages you’ve created with Copilot appear in the library for your M365 account.

Howard Wen / Foundry

Click the name of a page, and it’ll re-open inside the document canvas window. Or, if you want to delete it, move the pointer over its name, click the three-dot icon at its right, and select Delete.

Related reading:

Kategorie: Hacking & Security
Syndikovat obsah