Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

Hackers breach TrueConf to trojanize client installers with backdoors

Bleeping Computer - 8 Srpen, 2026 - 16:16
The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors. [...]
Kategorie: Hacking & Security

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

The Hacker News - 8 Srpen, 2026 - 10:54
Attacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of those routes is confirmed closed. PromptArmor, an AI security firm, hid the instructions in content Rovo reads. It said an uploaded file wasSwati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

The Hacker News - 8 Srpen, 2026 - 10:03
New research shows content inside an email can escape its message boundary and interfere with the webmail interface. Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take over third-party accounts, leak tokens, hijack trusted UI actions, and manipulate AI tools that read email. PortSwigger researcher Gareth Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

The Hacker News - 8 Srpen, 2026 - 08:58
Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

The Hacker News - 8 Srpen, 2026 - 08:57
N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product. "We are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques," the company said. "This is not a duplicate of our Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

The Hacker News - 8 Srpen, 2026 - 08:52
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026-8037 (CVSS score: 9.6), is a command injection flaw that could be weaponized to achieve arbitrary Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Metabase SQLi zero-day exploited in customer data-theft attacks

Bleeping Computer - 7 Srpen, 2026 - 22:14
A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. [...]
Kategorie: Hacking & Security

Unlimited Technology Systems breach impacts 3.8 million people

Bleeping Computer - 7 Srpen, 2026 - 21:30
Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025. [...]
Kategorie: Hacking & Security

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

The Hacker News - 7 Srpen, 2026 - 20:48
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. "These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer payload," OpenSourceMalware researcher Paul Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

The Hacker News - 7 Srpen, 2026 - 20:29
ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that's compatible with the computer's CPU architecture. "Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

The Hacker News - 7 Srpen, 2026 - 20:16
A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to a data extortion group known as UNC6671. "UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Levi Strauss & Co. says hackers stole corporate data in cyberattack

Bleeping Computer - 7 Srpen, 2026 - 17:48
Levi Strauss & Co. (Levi's) says that hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines. [...]
Kategorie: Hacking & Security

Polish data center plans to send its waste heat to the neighbors

Computerworld.com [Hacking News] - 7 Srpen, 2026 - 17:16

As Europe swelters in a heatwave, residents probably don’t want to hear about ways to make their homes even hotter, but that’s what Polish property developer Citylink is talking about, with plans to dump waste heat from a new data center in Wrocław into the municipal district heating network.

Citylink is designing the data center so that heat from servers can be recovered instead of being dissipated via cooling systems — and as the data center grows, any increase in computing power will mean more energy available for recovery.

The collaboration with local power company Kogeneracja will provide “valuable experience in designing and operating modern data centers, with a particular focus on infrastructure dedicated to AI nodes,said Michał Starybrat, development director at Citylink.

“The dynamic growth of the artificial intelligence and cloud technology markets generates unprecedented demand for computing power, this collaboration demonstrates how modern digital infrastructure can actively contribute to building the energy ecosystem of the future,” he added.

This type of initiative is not new. There have been similar projects in the UK and in New Zealand, but with warnings that data centers are contributing to the warming of the planet, there may well be a lot more organizations looking to deploy that excess heat more fruitfully in the future.

However, announcing it during a heatwave may not be the most politically sensitive approach to take.

This article first appeared on Network World.

Kategorie: Hacking & Security

Airtable joins Evernote, Brightcove, WeTransfer and AOL in Bending Spoons portfolio

Computerworld.com [Hacking News] - 7 Srpen, 2026 - 16:35

Bending Spoons has snapped up Airtable to add to its portfolio of software companies, alongside AOL, Evernote, WeTransfer, Brightcove and Vimeo

Airtable made its name as a builder of low/no code database services, aimed particularly at non-technical staff, but is now one of many vendors facing financial difficulties in the face of the SaaS/AIpocalypse. The arrival of AI coding tools, which offer non-technical employees more flexible ways to build business applications, has hit demand for its services.

Bending Spoons bought Airtable in a deal it valued at just $1.285 billion, a far cry from the $11.7 billion Airtable was worth at its peak.

Bending Spoons has built its portfolio by buying once-successful companies like Airtable that have struggled to cope with newer, nimbler competitors or failed to adapt to emerging technologies. Bending Spoons takes these companies, cuts costs and markets them aggressively with the goal of returning them to profitability.

“Airtable is a pioneering brand reshaping how teams organize data and manage critical workflows. We’re committed to investing in Airtable for the long run, and doubling down on its core strength: bringing teams and workflows together in one flexible workspace. We plan to expand what can be done across the full spectrum of work and make Airtable even more valuable to customers at every scale,” said Luca Ferrari, Bending Spoons CEO and co-founder.

This article first appeared on InfoWorld.

Kategorie: Hacking & Security

Real emails, hijacked payments: Two H1 2026 attack chains

Bleeping Computer - 7 Srpen, 2026 - 16:00
Gen's H1 2026 Threat Report examines two separate attack chains. One used compromised business inboxes and browser manipulation in a banking-malware campaign, while the other used clipboard hijacking to redirect cryptocurrency payments. [...]
Kategorie: Hacking & Security

Detecting Persistence on Linux Hosts: A Security Playbook for Cron and systemd

LinuxSecurity.com - 7 Srpen, 2026 - 15:50
If you manage Linux boxes long enough, you hit this exact wall. You spot a weird process eating CPU, kill it, wipe the script, and reset the user password. You grab a coffee, check things over, and come back five minutes later. The process is running again.
Kategorie: Hacking & Security

Wispr moves beyond AI dictation with note-taking assistant

Computerworld.com [Hacking News] - 7 Srpen, 2026 - 15:44

Wispr, the startup behind dictation tool Wispr Flow, has created an AI note-taking assistant that records meetings and generates conversation summaries for users.

The Wispr Flow Notetaker tool “captures your meetings so you can stop splitting your attention between listening and writing things down,” said Sahaj Garja, Wispr CTO and co-founder.

Notetaker starts recording with one click, and doesn’t require a bot to attend a video or voice call. It can also be used to capture in-person conversations.

The software has three key functions. Before a call, Notetaker displays a meeting brief with information such as meeting purpose and background of participants.

Once the meeting starts, a live transcript displays the dialogue text and labels speakers. A “what did I miss?” button provides a summary of talking points from the previous few minutes.

Finally, post-meeting, Notetaker generates a more detailed summary organized by topic that includes information such as key dates, decisions, and next steps. Users can search across notes from previous meetings in the Notetaker app. “Over time your meeting history stops being a folder of documents you have to go find and becomes something you can ask questions of,” said Garja.

Notetaker integrates with AI assistants such as Anthropic’s Claude and OpenAI’s ChatGPT via model context protocol. This allows users to connect outputs such as transcripts and summaries “into how you already work, instead of sitting in a separate app,” said Garja.

With Notetaker, Wispr competes in an increasingly busy market for AI note-taking apps that includes Fireflies, Granola and Otter.

Wispr claims Notetaker can produce more accurate transcripts than existing tools, partly because of the additional context it uses during transcription. It uses the same personal dictionary from Wispr Flow that includes acronyms, products, and preferred spellings, and can also draw on other sources such as calendar information to understand the purpose of a meeting and help ensure speakers are labelled correctly.

Before generating the final summary, Notetaker also re-reads the live meeting transcript and combines it with additional context to create a more accurate final output, Garja said.

Notetaker is the first new product launched by Wispr, which was founded in 2021 and has since raised $81 million in funding.

“We didn’t set out to build a dictation app,” said Garja. “The mission has always been to reshape how people interact with their devices, and dictation was the fastest way in.”

“Notetaker is the second product on that path. Dictation took the keyboard out of writing. Notetaker takes it out of meetings, so nobody has to spend the call typing up what everyone just said.”

User consent when recording calls

As AI note-taking tools have become more prevalent in the workplace, privacy concerns have arisen, including the need for all-party consent when recording a call in some jurisdictions, and whether meeting audio is used to train AI models. Two software vendors, Otter and Granola, currently face separate lawsuits in California that allege privacy law violations related to their products.

Wispr Flow Notetaker captures audio locally on a user’s device rather than joining the call as a visible bot. That means there’s no notification to signal that a conversation is being transcribed, which places responsibility on users to disclose the recording to others on the call in accordance with local laws, said Garja.

“Users should always let the other person know before you start recording or transcribing a conversation, whether it’s a video call, an in-person meeting, or a phone call,” he said, adding that Wispr intends to build additional features for automated consent messaging “in the coming weeks.”

Wispr doesn’t train its AI models on customer data without consent, though free and standard tier customers must choose to opt-out, according to Wispr’s privacy terms. Nor does it create “voiceprints or biometric profiles” of users or anyone else on a call using audio recording data, the company says.

When Notetaker is active, conversation audio is captured on a user’s device and processed on cloud servers to enable transcription. The recorded audio file is encrypted and stored temporarily on the user’s device or cloud storage, Wispr said. After a limited period, the audio is automatically deleted.

Notetaker is available with the Wispr Flow macOS app to free and paid subscribers, with support for Windows “coming soon.”

Kategorie: Hacking & Security

North Carolina Ports confirms cyberattack disrupting operations

Bleeping Computer - 7 Srpen, 2026 - 15:34
The North Carolina Ports Authority has confirmed that a cyberattack disrupted IT systems and slowed operations at Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. [...]
Kategorie: Hacking & Security

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP

The Hacker News - 7 Srpen, 2026 - 14:56
WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. pwn.ai demonstrated how the flaw can be chained into PHP code execution on the server when a logged-in administrator interacts with an attacker-controlled page. Tracked as CVE-2026-64638 (CVSS score: 8.9), the high-severitySwati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

DeepMind founder ascends to singular AI role at Google

Computerworld.com [Hacking News] - 7 Srpen, 2026 - 14:32

Demis Hassabis, the driving force behind Google DeepMind, is ascending to the role of chief scientist at Alphabet, Google’s parent company, replacing Jeff Dean who is leaving to work at a start-up.

The role will enable Hassabis to “put his full attention on actively shaping the future of AGI,” or artificial general intelligence, Alphabet CEO Sundar Pichai wrote on the company’s Inside Google blog.

Hassabis’ attention will still be divided, however: He will continue to lead research at Google spin-off Isomorphic Labs, which works on drug discovery, and although he will no longer be CEO of DeepMind, he will be its chair. Koray Kavukcuoglu will take over DeepMind, reporting directly to Pichai. He is currently its CTO.

Hassabis has been a strong promoter of AGI, defined by Google as the “hypothetical intelligence of a machine that possesses the ability to understand or learn any intellectual task that a human being can.”

He has a long career in AI, having helped found DeepMind in 2010. He has been a prominent figure in the AGI field, prophesying in May that it will be a viable technology within three years. He has been keen to tackle any barriers in the way of developing the technology; just last month, he called for greater self-regulation in the market, arguing that it would help drive the technology forward.

Hassabis welcomed the chance to focus on AGI development. “We have arrived at a pivotal moment in human history. I’ve been working towards AGI my whole life, and now, I feel it is close at hand. It’s critical that we collectively get the next steps right to ensure this all goes well for humanity and we usher in an incredible new age of discovery and wonder” he wrote in the Inside Google blog post.

Kategorie: Hacking & Security
Syndikovat obsah