Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

Bleeping Computer - 26 Září, 2026 - 21:03
The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers. [...]
Kategorie: Hacking & Security

Claude Opus 5.5 uses 95% fewer em dashes, but its answers are getting longer

Bleeping Computer - 26 Září, 2026 - 18:26
Anthropic's Claude Opus 5.5 appears to be changing how it writes, with new analysis showing fewer obvious AI writing patterns, shorter sentences, and simpler wording compared with Opus 5. [...]
Kategorie: Hacking & Security

Microsoft pauses KB5002907 update after Office license deactivations

Bleeping Computer - 26 Září, 2026 - 17:50
Microsoft has paused the rollout of the KB5002907 Microsoft 365 update after users report that it deactivated, or in some cases completely removed, perpetual Office 2016 and Office 2019 installations. [...]
Kategorie: Hacking & Security

GitHub Actions re-enabled with Mini Shai-Hulud payload still active

Bleeping Computer - 26 Září, 2026 - 16:19
Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite still pointing to malicious code. [...]
Kategorie: Hacking & Security

OpenAI's AI agents accidentally uploaded user-provided images to third-party sites

Bleeping Computer - 26 Září, 2026 - 14:28
OpenAI says its AI agents uploaded user-provided images to third-party image-hosting services while carrying out research and evaluation tasks. [...]
Kategorie: Hacking & Security

Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

The Hacker News - 26 Září, 2026 - 13:46
Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could result in unauthenticated remote code execution. The vulnerability was first exploited as a zero-day Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Zero Trust for AI Agents Starts With Fixing Zero Visibility

The Hacker News - 26 Září, 2026 - 12:30
The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on how quickly organizations could stand up agents and how much productivity they could promise, a string of recent incidents, including a widely discussed intrusion at Hugging Face during an evaluation of OpenAI agents, has spurred organizations to [email protected]
Kategorie: Hacking & Security

Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link

The Hacker News - 26 Září, 2026 - 11:55
Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site. The cross-site request forgery (CSRF) vulnerability, which has yet to be assigned a CVE identifier, carries a CVSS score of 8.8 out of 10.0. It only affects versions Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

The Hacker News - 26 Září, 2026 - 10:49
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities in question are as follows - CVE-2026-65660 (CVSS score: 8.8) - A code injection vulnerability in Microsoft Office SharePoint Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack

The Hacker News - 26 Září, 2026 - 09:48
Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack. "Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems," said Frank Balonis, ChiefRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Kiteworks urges 6-hour server shutdown over potential zero-day attacks

Bleeping Computer - 25 Září, 2026 - 23:41
Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window after receiving threat intelligence warning of a potentially imminent cyberattack. [...]
Kategorie: Hacking & Security

Why an io_uring Queue Handoff Can Become a Use-After-Free

LinuxSecurity.com - 25 Září, 2026 - 23:00
A Linux io_uring race can let a polling thread release ring state while the CPU that published the work is still using it.
Kategorie: Hacking & Security

ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

Bleeping Computer - 25 Září, 2026 - 22:57
The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability. [...]
Kategorie: Hacking & Security

Linux Patch Management For Enterprises: A Complete Guide

LinuxSecurity.com - 25 Září, 2026 - 22:55
Linux is not a standard environment. An enterprise can run many different flavors of Linux on its servers, desktops and specialized systems, each with its own set of software packages, dependencies and updates.
Kategorie: Hacking & Security

Linux ext4 Patch Blocks an Out-of-Bounds Read From Damaged Metadata

LinuxSecurity.com - 25 Září, 2026 - 22:35
Corrupted ext4 metadata can direct a Linux kernel copy past the inode region that is supposed to contain inline data.
Kategorie: Hacking & Security

USB/IP Teardown Race Can Rearm a Freed Linux Kernel Timer

LinuxSecurity.com - 25 Září, 2026 - 22:15
A Linux USB/IP timer can restart after device teardown has begun, leaving the kernel callback able to use a virtual controller that has already been freed.
Kategorie: Hacking & Security

Why an Unlocked ext4 Buffer Can Restore Stale Directory Data

LinuxSecurity.com - 25 Září, 2026 - 22:15
A Linux ext4 race can corrupt a directory while the filesystem converts it from inline storage to a regular block.
Kategorie: Hacking & Security

A Linux eBPF Trampoline Can Outlive the Program It Calls

LinuxSecurity.com - 25 Září, 2026 - 21:45
A Linux eBPF security race can leave generated kernel code pointing at a BPF program after that program’s memory has been released.
Kategorie: Hacking & Security

Your uncle’s frozen Mac says it’s infected after viewing a Google ad. Now what?

Ars Technica - 25 Září, 2026 - 21:38

Researchers say they recently found Google ads delivering a sophisticated tech support scam that freezes the screens of both Windows and Mac devices and displays messages urgently instructing them to phone a bogus call center.

The ads were displayed all over the web, including on high-traffic maps, weather, real-estate, document-hosting, and sports sites. Users who called the number were then urged to pay hefty fees, grant remote access to their devices, or divulge personal information. From August 31 to September 14, security firm Netskope observed users from 619 customer organizations click on the malicious ads, although none of them were actually scammed because Netskope blocked the content.

Roughly 62 percent of the organizations were based in the US, with Japan and Australia accounting for the Nos. 2 and 3 spots. Since the firm has visibility into only a tiny sliver of Internet activity, the number of people exposed to the ads—including those who fell victim to it—is likely much higher. Netskope tracked more than 250 Google Ads campaign IDs across at least 284 legitimate publisher sites.

Read full article

Comments

Elementor WordPress flaw lets attackers create admin accounts

Bleeping Computer - 25 Září, 2026 - 20:13
A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts. [...]
Kategorie: Hacking & Security
Syndikovat obsah