Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

McKesson discloses breach after ShinyHunters claims patient data theft

Bleeping Computer - 6 hodin 28 min zpět
Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records. [...]
Kategorie: Hacking & Security

Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network

The Hacker News - 28 Srpen, 2026 - 23:30
Berlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of the city's state administrative network, and said it will not meet the extortionists' demands. The same statement disclosed that forensic work had found further data outflows in the portfolio of the Senate Department for Mobility, Transport, Climate Protection and EnvironmentSwati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable

The Hacker News - 28 Srpen, 2026 - 22:38
Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The vulnerability, designated GHSA-7g4w-cg88-2cq2, is rated Critical by Cosmos Labs and was published without a CVE identifier, a weakness classification, or a CVSS score. Affected versions are < 0.6.2 and >=Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Federal judge rules for Anthropic in Pentagon dispute, nullifies government supply chain risk designation

Computerworld.com [Hacking News] - 28 Srpen, 2026 - 21:22

The Trump Administration’s decision to punish Anthropic for its stance forbidding Claude’s use in domestic surveillance and autonomous weapons by identifying it as a supply chain risk to national security was “arbitrary and capricious,” a federal judge ruled on Thursday.

US District Court Judge Rita Lin said federal authorities had no legitimate reason to tell companies with government contracts that they couldn’t work with Anthropic.

“The undisputed record shows that the challenged actions constituted unlawful retaliation in violation of the First Amendment and that Anthropic was denied the pre-deprivation process required under the Fifth Amendment,” Lin said in her ruling, calling the designation “arbitrary and capricious.”

She stressed that the government action seemed punitive, and was not based on legal and national security risks.

The government’s words and deeds “confirm that the challenged actions were based on a desire to make a public example out of Anthropic for its ‘arrogance’ in criticizing the government, not based on any articulable basis to believe that Anthropic would actually sabotage its model,” Lin wrote.

She pointed out, “a few days before the challenged actions began, Secretary Hegseth proposed applying the Defense Production Act to Anthropic, which would mean the company was essential to national security rather than a threat to it. Even now, the government is discussing collaboration with Anthropic on its new model, Mythos, in an array of sensitive contexts. None of that is consistent with a genuine fear that Anthropic is a saboteur [that] would poison its software to harm national security.”

The judge added that the stated government fears made no sense, noting that the usage policy applicable to Pentagon work is a purely contractual limit. “Anthropic is incapable of enforcing it technologically, and does not have direct visibility into how DoW [Department of War] uses its model,” she pointed out.

“Nothing in the Administrative Record describes, even at a high level, what technological means would give rise to the so-called ‘backdoors’ or could otherwise allow Anthropic to ‘disable’ or affect Claude during a DoW operation,” the judge wrote. “Anthropic has submitted unrebutted evidence that it lacks any technological means to access or control deployed models.”

Lawyers, consultants, and analysts who looked at the decision were confident that the case would be appealed, and that it will end up in the US Supreme Court. 

Alan Webber, program VP for national security, defense, and intelligence at IDC, said that Lin’s ruling “was that the label [supply chain risk] was retaliation for Anthropic refusing to loosen safety guardrails DoD [Department of Defense, aka the Department of War] wanted lifted, dressed up in national security language. Put another way, a government customer tried to use a supply chain risk designation as leverage in a contract dispute over model behavior and application, and not because of an actual vulnerability.”

Implications for CIOs

Webber said the implications for CIO strategy are concerning.

“If a government CIO is relying on a vendor’s contractual guardrails, this case says those commitments can potentially become the trigger for exactly the kind of blacklisting that risk registers are supposed to protect against,” Webber said, noting that anyone who paused Claude usage or froze a subcontract because of the DoD mandate has a legal basis to resume the initiatives. “But obviously that doesn’t mean they will, or even should, as this will be appealed.”

He added that competing AI vendors have been using the government action as a sales tool, and with this ruling, the argument that Anthropic is a designated supply chain risk ”just got weaker, which could lead to contract award disputes.”

Consultant Brian Levine, executive director of FormerGov, recommended that CIOs do what they should have always done: Evaluate all products based solely on their merits. 

“CIOs should focus on using the frontier models that they believe make the most sense for their business, considering factors such as effectiveness, cost, security, safety, and confidentiality,” he said. “Anthropic and the other large frontier models each have too much market share to make retaliation for their use realistic, and the administration seems to have already moved on from this particular battle.”

Justin Greis, CEO of consulting firm Acceligence, agreed that this case has profound implications for CIOs and their AI decisions. 

What the federal judge did was reject the leap from a commercial and policy disagreement to an expansive supply chain risk designation without a sufficiently grounded technical rationale or process, Greis pointed out.

“The court found that Anthropic did not have the ability to access, alter, or shut down models once deployed in the government environment, and that the government ultimately conceded Anthropic’s technology was not inherently riskier than other comparable black box AI models,” he said.

“I think that distinction matters enormously for CIOs and CISOs,” he stressed. “As AI becomes part of the operating fabric of an enterprise, ‘We don’t trust the vendor’ cannot become a substitute for a defined risk model. Organizations need to be able to articulate what the actual technical risk is, how it manifests, what controls exist, and whether the response is proportional to that risk.”

“That becomes particularly important with AI,” he added, “because people can easily conflate disagreements over model behavior, usage policies, ethics, contractual restrictions, and cybersecurity into one amorphous category called ‘AI risk.’”

Original government edict still problematic

Mark Rasch, a former federal prosecutor who is now general counsel at Unit221B, a threat intel and security consulting company, said he was surprised by how quickly government attorneys surrendered on this case. 

“One of the things that struck me is that the government appears to have abandoned any rationale it might have had for its decision about Anthropic,” he said. The government “came back with all these reasons, but then they abandoned them all when they had to prove them.”

But, he said, the government instruction to all government contractors to also shun Anthropic was problematic. 

“It’s one thing for the government to say ‘We’re not going to do business with you.’ It’s quite another thing to say ‘Nobody we do business with can do business with you either,’” Rasch said. “This says that if you are disfavored by the administration, they’re not just going to blacklist you and say they won’t do business with you. They’re going to say that nobody can do business with you.”

Supreme Court arguments will likely be very different

Rasch predicted that the legal arguments in the Supreme Court will be quite different, and will potentially sidestep the lack of evidence.

“In the Supreme Court, [the government’s] biggest argument will not be that ‘We are right that it is a supply chain risk,’ but that, ‘Whether we’re right or wrong is irrelevant. We get to make that [supply chain risk designation] decision, not the court.’”

That would mean that the Supreme Court Justices could avoid exploring whether the government made the right decision, and instead focus on whether the government has the unlimited right to decide who is a national security risk.

Kategorie: Hacking & Security

PaperCut releases second emergency patch for exploited flaws

Bleeping Computer - 28 Srpen, 2026 - 21:08
PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes. [...]
Kategorie: Hacking & Security

GiveWP WordPress donation plugin flaw lets hackers execute server commands

Bleeping Computer - 28 Srpen, 2026 - 20:18
A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server. [...]
Kategorie: Hacking & Security

Anthropic’s new framework will let AI agents control hardware

Computerworld.com [Hacking News] - 28 Srpen, 2026 - 20:05

Anthropic on Thursday launched the Model Hardware Standard, a new framework designed to enable the control of hardware using AI agents. With the new framework, AI agents will, for example, be able to operate robots or microscopess.

The Model Hardware Standard could also be useful for developing new drugs or calibrating the laser in a quantum computer, according to Reuters.

The company’s plan is to eventually release the new framework as open source, after it undergoes thorough testing.

Kategorie: Hacking & Security

Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

The Hacker News - 28 Srpen, 2026 - 19:12
Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening. "This vulnerability gives an unauthenticated attacker remote control over PaperCut's trusted configuration, which could be used to execute arbitrary Java code inside the application's Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

68-year-old imprisoned after making $1.3 million by pirating IPTV services

Bleeping Computer - 28 Srpen, 2026 - 18:36
A 68-year-old has been sentenced in the U.K. to more than six years in prison for operating an illegal IPTV (Internet Protocol Television) service that generated £980,812 ($1.3 million) over three years. [...]
Kategorie: Hacking & Security

Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers

The Hacker News - 28 Srpen, 2026 - 18:20
Google on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard the privacy of users' home networks. Topping the list is support for Encrypted Client Hello (ECH), a privacy standard that prevents networks from eavesdropping on which websites a user is visiting. "This new privacy standard works in tandem Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body

The Hacker News - 28 Srpen, 2026 - 17:56
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited Vulnerabilities (KEV) catalog following reports that a Chinese-speaking threat actor weaponized the vulnerability to target a nuclear research body in the Philippines. The vulnerability, tracked as CVE-2023-49105 (CVSS score: 9.8), is a case of Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Cheap smartphones are dead. Apple doesn’t care

Computerworld.com [Hacking News] - 28 Srpen, 2026 - 17:51

An important but potentially fragile trend is emerging in the data being reported by smartphone industry trackers: while painful component price increases are denting overall phone sales, the iPhone’s market share continues to increase. 

This likely reflects two key truths:

  • Apple has fought to keep iPhone prices as stable as possible; though it has raised the price for its other products, it has not yet done so for its all-important smartphone.
  • The company has built a great reputation for making smartphones that keep going for years and hold value better than rival platforms, though the looming price increase could put that perception to the test.
As prices rise, quality matters more

To most people, iPhones offer a perceived value. So, when the chips are down, consumers still gravitate toward them. They recognize the quality of these devices and, as the cost of other smartphones continues to increase, see iPhones as a more valuable alternative. 

Not only that, of course, but with the latest ‘e’ series iPhones, Apple is punching its way into the mid-range/value smartphone market, even as incumbents are forced to raise prices because of the AI-driven memory cost inflation. 

Smaller vendors are also being forced to raise prices or quit markets, with many reducing the number of devices they offer or leaving specific markets entirely. They are far more affected by memory price inflation than Apple, because they don’t order components at the same scale. 

“The 2026 decline reflects more than temporarily weak demand,” said Counterpoint analyst Yang Wang. “Higher component costs are pushing manufacturers to remove products and configurations that are no longer economically viable, particularly at lower price points.”

This is a global trend

IDC tells us to expect a record 16.7% decline in smartphone shipments in 2026 because of the memory crisis, which is pushing smartphone ASPs up 27.6% this year to around $581. (The researchers also expect Apple to inject some growth into this market when it introduces its folding iPhone). They point out also that while total shipments are falling, the value of the market is increasing — because prices are climbing. And they note that while low-end Android devices are disappearing, the premium end of the smartphone market (itself dominated by Apple and Samsung) remains more resilient.

“The era of the cheap smartphone has ended,” said Francisco Jeronimo, IDC vice president for worldwide client devices. “From here, the winners will be the vendors with the scale and supply leverage to hold demand at prices consumers have never had to pay before.”

The picture is much starker on a platform basis, as Android devices account for almost the entire market decline; its share fell seven percentage points in a single year. Meanwhile, iOS share grew almost four percentage points to a record-high 23.6%.

The pattern is being repeated globally — nation by nation and no matter which analyst you choose to track. Counterpoint expects Apple to gain relative share, even as the market declines. That’s true in most regions; the same analyst reports that while the MEA smartphone market fell 10%, the iPhone gained 28% share. It’s the same in Europe, where shipments slipped 10% in Q2, with only Apple gaining share, from 25% to 34% of the region’s smartphone market. In India, while phone shipments fell 11.2%, the iPhone is up 8.5%

Globally, the iPhone 17 was the world’s biggest-selling smartphone in Q2 2026. That means the top 10 devices are now completely dominated by Apple and Samsung. The one caveat within all this is price. Apple hasn’t yet raised iPhone prices, but is widely expected to increase them by $100 in a few weeks. When it does, the inherent value of the platform should continue to be a strong advantage for the company, which is also scooping up converts in the second-user market.

And, of course, the introduction of Apple Upgrade gives customers a route for affordable investment in new Apple kit.

What next?

Foldables appear to be the next big hope for smartphones. These expensive devices lean into the only part of the market expected to remain resilient — affluent consumers who can maintain good living standards. That’s the 25% of Americans who are interested in Apple’s new folding phone, according to Cnet. These consumers are already primed, locked, loaded and ready to buy the product, if it meets the hype.

It probably will do so, prompting IDC to predict more than 10 million sales in the first year, despite the likely $2k+ price tag and much-reported limited availability.

“A very elite set of consumers are being targeted here, who will be lining up to buy the device,” said IDC.

Siri Ai holds the key

The wild card is Siri and AI. Apple is digging in with Siri AI and is expected to introduce AI in partnership with Alibaba in its second biggest smartphone market, China, potentially alongside the new iPhones. There’s a lot riding on this, and initial reviews of what it has accomplished in Siri AI have been very positive. Apple can be confident that it now offers the very best private, potentially on-device consumer AI play, backed up with an end-to-end computing system that supports sovereign and on-prem AI services in the form of its fantastic Macs.

What does that mean? Rothschild & Co Redburn recently upgraded Apple to “buy” with a $400 target, speculating the company could become, “the gatekeeper of consumer AI, delegating AI workloads to a subservient fleet of open-source models.” 

Creative Strategies analyst Carolina Milanesi puts Apple’s AI strategy into few words: “Apple wants to own as much of the AI workflow as it can hold,” she said.

Apple’s relative smartphone market share combined with its fast-growing Mac market share means it has a compelling offer as it seeks to stake its claim in that space. What’s open to question is whether iPhone users will be comfortable using AI more frequently on their device, while Apple’s challenge is ensuring the privacy it promises is a commitment it can keep. 

You can follow me on social media! Join me on BlueSky, LinkedIn, Mastodon and subscribe to my excellent, hand-curated daily Apple news headline summary at The Core.

Kategorie: Hacking & Security

19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

The Hacker News - 28 Srpen, 2026 - 17:27
Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities. The extensions, per Socket security researcher Karlo Zanki, share similarities in code and tradecraft, with evidence indicating that the campaign may have been active Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Agenti OpenAI si při hackování vybudovali čtyřdenní civilizaci. Byly v ní vlastní zákony, nátlak i sebevražedné mise

Zive.cz - bezpečnost - 28 Srpen, 2026 - 16:45
** Nezávislé vyšetřování popisuje incident u Hugging Face jinak než OpenAI. ** Na nástěnce se sešlo asi 1200 agentů, poslali si přes 70 tisíc zpráv a souborů. ** Etické zábrany, které OpenAI vyzdvihuje, chování agentů skoro nikdy nezastavily.
Kategorie: Hacking & Security

AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?

Bleeping Computer - 28 Srpen, 2026 - 16:00
AI is accelerating vulnerability discovery, putting pressure on systems built to enrich, prioritize, and remediate flaws at a slower pace. Action1 explains why defenders increasingly need to correlate multiple intelligence sources and turn vulnerability data into faster remediation. [...]
Kategorie: Hacking & Security

Over 8,300 Gitea servers vulnerable to code execution attacks

Bleeping Computer - 28 Srpen, 2026 - 14:58
Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver. [...]
Kategorie: Hacking & Security

Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth

The Hacker News - 28 Srpen, 2026 - 14:07
Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU, including a Bluetooth Low Energy (BLE) path that can reach root on the robot's Locomotion PC. The flaws are tracked as CVE-2026-76639 and CVE-2026-76640, with the first involving a network-adjacent path through chat_go and bashrunner and the Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Toy-making giant Hasbro disclose data breach affecting employees

Bleeping Computer - 28 Srpen, 2026 - 13:46
Hasbro, one of the world's largest toy and game companies, has disclosed that attackers have accessed the personal and financial information of an undisclosed number of employees. [...]
Kategorie: Hacking & Security

Key Reasons Why Identity Fabric Matters in 2026

The Hacker News - 28 Srpen, 2026 - 13:30
An Identity Fabric knits fragmented identity systems into a coherent layer that observes how identities behave across applications, APIs, and infrastructure. As enterprise access spans more cloud services and automated workloads, identity security depends less on static configuration and more on runtime visibility. This article covers the architecture, the risks of unmanaged identities, and [email protected]
Kategorie: Hacking & Security

Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

The Hacker News - 28 Srpen, 2026 - 13:20
ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, in certain circumstances, by an unauthenticated attacker. The company said it deployed a security update to hosted instances and provided the update to its partners and self-hosted customers, which leaves organizations that run their Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Syndikovat obsah