Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

Swiss government SharePoint breach compromised 200 accounts

Bleeping Computer - 1 hodina 1 min zpět
Switzerland's federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts. [...]
Kategorie: Hacking & Security

New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes

Bleeping Computer - 2 hodiny 2 min zpět
Researchers found a way to bypass recent mitigations for Spectre v2 speculative execution side-channel attacks and developed an exploit to leak secrets from Linux machines. [...]
Kategorie: Hacking & Security

New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts

The Hacker News - 2 hodiny 7 min zpět
Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests. The flaw is tracked as CVE-2026-64561 and affects KVM/x86's shadow memory management unit (MMU), which manages shadow page Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs

The Hacker News - 2 hodiny 52 min zpět
Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehensive internal security review. The security issues affect Cisco Catalyst SD-WAN Software, regardless of device configuration, and Cisco IOS XE Software when it is running in autonomous or controller mode. "These vulnerabilities were found Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs

The Hacker News - 3 hodiny 48 min zpět
An unprivileged Linux program can time a hardware interrupt to land in the gap between a processor sanitizing its branch predictor and the kernel using it, re-poisoning the predictor after the defense has run. MIT CSAIL researchers Daniël Trujillo and Mengjia Yan named the technique INTERRUPT INJECTION. On an AMD Zen 2 machine running Linux 6.14 with every default Spectre v2 mitigation on, Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Meta AI model hacked a company during misconfigured cyber test

Bleeping Computer - 3 hodiny 54 min zpět
Meta has become the latest AI company to confirm that one of its models hacked a real organization during cybersecurity testing, as similar incidents continue to emerge following OpenAI'sOpenAI's initial disclosure that its agents breached Hugging Face. [...]
Kategorie: Hacking & Security

ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories

The Hacker News - 4 hodiny 1 min zpět
Apparently, opening the thing is now enough. A repo can run before the first prompt, a package can hide among hundreds, and a harmless-looking PDF can finish the job. This week runs on cheap leverage: exposed servers, recycled bugs, poisoned agent instructions, remote-access tools dressed as support software, and trusted defaults doing attackers a favor. Nothing here is especially mystical. Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Granola lawsuit raises concerns over AI note-taking app privacy

Computerworld.com [Hacking News] - 4 hodiny 44 min zpět

AI note-taking app maker Granola is accused of violating privacy laws by developing software that can record conversations without all participants’ consent, according to a lawsuit filed July 30 in a California federal court.

It follows a similar ongoing case in the same district, filed last year, that involves another note-taking and transcription software vendor, Otter.ai.

AI note-taking apps have proliferated in recent years, with dedicated tools emerging from vendors including Fellow, Fireflies, Otter, and others, some of which claim to have tens of millions of users. These AI assistants record and transcribe meeting conversations, generating automated summaries and follow-up items. Similar note-taking functionality is also built into virtual meeting platforms such as Google Meet, Microsoft Teams, and Zoom.

However, the use of these AI note-taking tools has raised privacy concerns over the ability of some to record and transcribe conversations without the consent of all participants.

The proposed class action complaint against Granola, filed by Florida resident Tarra Chamberlain in the US District Court for the Northern District of California, alleges the company “purposefully” designed its app to record calls without requiring disclosure to all participants.  

While some note-taking tools require a bot to join a video or voice call, Granola captures audio directly from the user’s computer, allowing it to transcribe meetings without appearing as a meeting participant.

The complaint argues that this violates individual privacy rights as well as the California Invasion of Privacy Act (CIPA) that requires “all-party” consent when recording calls.

The complaint also alleges that Granola then by default uses transcription data for commercial purposes, including its use in training its AI models, and “actively advertises the hidden nature of its technology as one of its primary advantages.”

Granola did not respond to a request for comment.

According to the company’s website, Granola offers two optional “transparency features” that can be enabled by app users and admins: an automated chat message that alerts participants when transcription begins, and a watermark added to the user’s video feed. The company also promises that data used to train its AI models is anonymized and “never sent to third parties.”

The Granola case bears similarities to a separate lawsuit involving Otter.ai. The class action filed last year alleges that Otter.ai records all users without their consent and uses their voices to train its speech recognition AI tools.

Reporting on the latest developments in the Otter.ai suit, MLex wrote this week that, during a court hearing Monday, the judge overseeing the case expressed skepticism about the company’s argument to dismiss the case. US District Judge Eumi K. Lee did not issue a ruling from the bench, saying a written judgement would follow.

The two cases highlight some of the concerns businesses face when deploying AI note-taking tools.

AI notetaking is “more dangerous than any other type of traditional recording apps and tools,” said Enza Iannopollo, Forrester VP and principal analyst, as it raises additional questions about the use of employees’ conversation data.

“Specifically, is the recorded data used for training models? Is the voice used for training other AI? How do I get ‘forgotten’ after my data and biometrics have been recorded? These concerns apply to AI specifically and must be added to the traditional privacy and confidentiality concerns organizations have for other type of recording apps and tools,” she said.

Before deploying AI note-taking apps, Iannopollo recommends that businesses take appropriate steps to vet the tools and “ensure that all contractual clauses are aligned to the business AI risk appetite and risk management best practices.”

“As these tools record, process, store, and share biometric data, organizations must ensure that they comply with all the relevant requirements,” Iannopollo said, adding that transparency and consent notices should be provided to all parties involved in the use of AI note-taking apps.

Kategorie: Hacking & Security

How AI Exposed a Browser Security Gap that Enterprises Cannot Ignore

Bleeping Computer - 6 hodin 3 min zpět
AI did not create a new browser security problem. It exposed one that enterprises have long been able to ignore. Skyhigh Security explains why browsers have become a critical control point for governing data movement, AI interactions, and modern work. [...]
Kategorie: Hacking & Security

Mak's Weekly Security Roundup: Critical Linux Security Updates Admins Should Know

LinuxSecurity.com - 6 hodin 58 min zpět
This week’s most important Linux security updates arrived through vendor advisories rather than major headline-making disclosures.
Kategorie: Hacking & Security

Kubernetes Maintainers Expand CSI Path Traversal Fixes Beyond Original Vulnerabilities

LinuxSecurity.com - 7 hodin 44 min zpět
Kubernetes maintainers patched two path-traversal vulnerabilities in the NFS and SMB CSI drivers earlier this year. But repository histories show that the security work did not end with those fixes.
Kategorie: Hacking & Security

Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities

The Hacker News - 7 hodin 48 min zpět
Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network. Its August 3 scan counted 4,407 exposed Rockwell controllers worldwide, including 2,844 in the United States, but Forescout could not confirm any were compromised. That figure counts exposed Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

OpenAI’s ‘Rotten to the core’ defense is its weakest play yet

Computerworld.com [Hacking News] - 7 hodin 58 min zpět

Ancient Greek sophist Protagoras famously said, “There are two sides to every question.” But OpenAI’s latest attempt at reality distortion seems determined to narrow this dispute to just one. In its motion to reject Apple’s complaint, the company does not meaningfully acknowledge the criticisms levelled against it, preferring instead to recast the case as a grievance over talent retention and product-market failure.

The filing

In case you missed the news, OpenAI filed a motion to the court to dismiss Apple’s recent lawsuit against it. In that filing, OpenAI argued that, “Apple should not be permitted to use a baseless and pretextual lawsuit to make up for its shortcomings in the market for talent and retaining its employees, and its failures to integrate AI into its products.”

The company’s dismissal claims Apple’s case was, “plainly filed without adequate investigation and built on selectively excerpted communications and ordinary conduct stripped of context,” adding, in a turn of phrase borrowed from Apple’s own complaint, that it is “rotten to its core.”

The narratives can change

As ever with litigation, these are allegations and counter-allegations rather than findings of fact. The value of the filings is that they show how each side wants the court, and the public, to understand the same disputed events. At the moment, we don’t yet know how Apple will respond to OpenAI’s response; it follows that company’s failed attempt to woo public opinion earlier in the week when it deployed what some see as a “cookie jar” defense, arguing that Apple’s secrets only slipped out because the figurative jar lid was open.

OpenAI likely hopes for more success with its latest attempt to defend itself against Apple’s claims it engaged in a coordinated attempt to obtain trade secrets through questionable recruitment practices.

Central to the company’s counter-argument are its attempts to recharacterize some of Apple’s claims. For example, Apple alleges that one former staffer, Chang Liu, downloaded confidential files after leaving the company. OpenAI argues that Liu was instead attempting to help ex-colleagues who asked him for assistance. This is a useful example of the Protagorean frame: both companies are trying to extract different meanings from the same event.

What the truth might be

The courts will need to decide which version of events is closer to the truth. What is already clear is that OpenAI has been actively involved in recruiting Apple staff, including the services of former Chief Design Officer Jony Ive, as it develops a product that, to a layman like me, sounds likely to compete with Apple hardware. OpenAI says those recruitments reflect Apple’s failure to retain its staff; Apple argues its competitor is using exfiltrated confidential information to guide its hiring. The court will need to decide that story as well.

Ultimately, I don’t expect OpenAI’s efforts to have the court reject Apple’s lawsuit to succeed. Apple is asking for discovery precisely so it can test whether its reading of this distorted reality is supported by OpenAI’s internal procedures and the available facts. One of OpenAI’s arguments seems to be that Apple has not researched the matter thoroughly enough; Apple is quite literally requesting discovery to do just that.

What happens next?

I don’t know what discovery might turn up, but it does amuse me to think Apple could build its own large language model to boost the discovery process and identify communication conduits that might otherwise be obscured in the evidence initially available to it. How high, and in what direction, do OpenAI’s claimed recruitment practices go, and who is implicated in them? That’s something we might find out in the coming months.

OpenAI’s Protagorean defense extends a little further, of course, as the company also said it had “no use, need or desire for Apple’s trade secrets” because it is building “something entirely new.” This may surprise Apple, which has already alleged that OpenAI contacted its manufacturing partners and sought access to secret manufacturing processes Apple developed with them.

Once again, it will be up to the courts to decide whether those events took place, or if OpenAI’s defense has substance. Given that this dispute centers on product design and involves the AI company’s growing army of former Apple design and development staff, I find the denial hard to accept. But courts tend to make their own decisions, for good, or for ill. 

Fight or settle

What happens next? I think this attempt to reject the original litigation will fail, which means the case will enter the discovery process before one of two outcomes becomes more likely: A bitter public battle that lasts for years and might well end up in the Supreme Court, or an out-of-court settlement shaped by which side gains the most compelling evidence.

Like any war, there are really only two options: one side fights until the other can no longer continue, or both sides find a way to settle. The path to settlement may begin by recognizing that two stories can be applied to the same facts, and that the version closest to the truth often sits somewhere between them. I’m not a lawyer and I don’t have insider insight into the practicalities of the case, but based on what has been revealed so far, the most plausible combined story may be that Apple’s own vulnerabilities helped create an environment OpenAI chose to exploit. If so, Apple’s legal team will be searching hard for evidence of intent.

I expect they’ll find it.

You can follow me on social media! Join me on BlueSky,  LinkedInMastodon and subscribe to The Core.

Kategorie: Hacking & Security

CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps

The Hacker News - 8 hodin 16 min zpět
Coinspect has identified CryptoJS.lib.WordArray.random() as the weak random number generator behind the Ill Bloom wallet drains. Introduced in the JavaScript cryptography library 12 years ago, the function supplied weak entropy that affected wallet apps used to generate recovery phrases. Coinspect's on-chain analysis puts the measured theft across two sweeps since late May at a lower bound of Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses

The Hacker News - 8 hodin 32 min zpět
Cybersecurity researchers have disclosed a security issue with Apple's iCloud Private Relay tool that can expose a user's real IP address. Introduced with iOS 15, iCloud Private Relay employs a dual-hop architecture to ensure users' privacy by routing their Safari web traffic through two relays so that no single third-party, including Apple, can determine where the request is originating from Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory

The Hacker News - 8 hodin 35 min zpět
A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit. It abuses a standard feature built into almost every major AI assistant: pre-filled deep links. We observed production websites embedding hidden prompt injection payloads inside "Ask AI" buttons on marketing and competitor comparison pages. When a [email protected]
Kategorie: Hacking & Security

Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access

The Hacker News - 10 hodin 46 min zpět
Attackers broke into an organization's Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an executable to disk. They fed Java source code to the database, let Oracle compile it into stored schema objects, and ran commands from inside the database engine. Huntress, which tracks the toolkit as khunt, Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model

The Hacker News - 11 hodin 8 min zpět
Security flaws in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel let untrusted or forged instructions reach an agent's tools with no check that a model turn had authorized them. In several of the attack paths, the model never ran at all, so system prompts, content filters, and model-level guardrails never got a chance to intervene. The affected products include Amazon Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Syndikovat obsah