Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

LACMA data breach last year exposed social security and medical data

Bleeping Computer - 25 Srpen, 2026 - 23:58
The Los Angeles County Museum of Art (LACMA) has announced that a breach last year exposed customer and employee information. [...]
Kategorie: Hacking & Security

Hackers abuse npm mirrors to host phishing redirect pages

Bleeping Computer - 25 Srpen, 2026 - 23:39
Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites. [...]
Kategorie: Hacking & Security

Perplexity’s on-device AI offering promises data control and lower token costs

Computerworld.com [Hacking News] - 25 Srpen, 2026 - 22:41

Perplexity on Tuesday rolled out an offering that runs the AI entirely on a local machine, and that, it said, will keep “private data local and escalating to the cloud only when a task needs it.”

The service, called simply Portable Computer, is a local version of Perplexity Computer that runs on the Nvidia DGX Spark with Qwen 3.8 27B or with PPLX 27B, a post-trained version of the Qwen model, Perplexity said, adding that a 30B open model is coming soon to the model picker. The orchestrator, planner, tool router, scheduler, durable task queue, and local search index all run on device.

Portable Computer requires Linux as its underlying OS, with Windows support “coming soon.”

The most critical benefits for enterprise IT are the Perplexity promise that data stays local, and that on-device work doesn’t consume token credits. Customers are only charged if the system is explicitly told to move compute to the cloud “for more advanced research and reasoning.”

Doing as much work as possible locally is becoming a trend, as users seek to lower token costs and minimize their need for increasingly expensive high-end AI systems.

“A user might want the confidential details of a term sheet to stay local, but escalate to the cloud to get current market comps or recent precedent deals,” the Perplexity announcement noted. “Portable Computer’s local orchestrator can escalate a task to the cloud for current information, browser use, connected apps, or one of 15+ frontier models for advanced reasoning. Through app connectors, Portable Computer works with Google Drive, Gmail, Slack, and GitHub.”

Aman Mahapatra, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, said that he liked the comprehensive capabilities included in the offering. 

“Running a model locally has been table stakes for two years,” Mahapatra said. “Running the entire agentic control plane locally means the decision about whether a task needs the cloud is itself made on device, by a model post-trained to keep work local and escalate when necessary.”

Hardware demands

However, some consultants and analysts questioned whether the economics, as well as the data and token control features, are truly ready for the enterprise at this point.

Nader Henein, a Gartner VP analyst, said that some of the announced Perplexity models can be run today on high-end laptops with off-the-shelf GPUs, “but until we see the price [of Portable Computer], it’s going to be hard to get excited about this.”

Flavio Villanustre, CISO for the LexisNexis Risk Solutions Group, also noted, “the hardware demands are quite steep, especially with the current hardware costs including RAM, GPU, and so forth. It needs at least a local GPU with 24GB of VRAM as a minimum.”

“Although it may help lower ongoing expenses, it does require an initial investment on this specialized hardware,” he said.

Concerns over control of cloud usage

But multiple consultants expressed concerns about the lack of details of how the local-versus-cloud decisions are enforced. For example, users might agree to a pop-up offering cloud compute reflexively, just as they simply agree to any software terms and conditions that pop up. Or an attacker could use prompt engineering or other tactics to place hidden commands that tell the system to move to the cloud without the user knowing. 

Justin Greis, CEO of consulting firm Acceligence, pointed out, “local-first should not be confused with local-only and that distinction is going to matter tremendously. Users routinely approve prompts they do not fully understand, and increasingly autonomous AI agents are operating across files, applications, connectors, and workflows that may be far more complicated than the user can see. The AI should be able to ask for permission, but the enterprise needs the ability to say, ‘You are not permitted to ask.’”

Mike Wilkes, enterprise CISO at Aikido Security, suggested that one way to prevent cloud usage would be for IT to lock down these systems so that they cannot have any external access, a technique that he doubted would be tolerated. 

“I would not expect either the agents or their users to be particularly happy if enterprises solve the security problem simply by denying network access. For many valuable use cases, connectivity is the point,” Wilkes said. “A proprietary trading firm, for example, may want confidential models and positions processed locally while still consuming current market data, SEC filings, news or research feeds.”

And, Mahapatra noted, although the built-in controls will not prevent unauthorized cloud escalation, “the reason is structural rather than a knock on Perplexity’s engineering. The gate is a permission prompt, which is consent, not control. It depends on a probabilistic model correctly classifying sensitive content and correctly scoping an escalation payload, and on a user judging a request they cannot fully inspect. Both fail adversarially.”

He pointed out that, with Gmail, Drive, Slack, and GitHub connectors on a device that also holds an authorized cloud path, “this is the same connector-plus-egress combination behind every Copilot exfiltration chain published this year. What would satisfy an enterprise security review is network-layer, not application-layer, and it does not exist in the product.”

It would need a mandatory egress proxy, DLP inspection on every escalation payload, deterministic classification rules that block defined data categories regardless of the model’s judgment, and immutable logging of what left the device, he said. “Sandboxed execution addresses code isolation and does nothing for data egress governance.”

His question to Perplexity is whether an enterprise administrator can define escalation policy centrally in a way the local model cannot override, and produce a full audit log of what crossed the boundary. “If escalation is governed by user consent and model judgment, this is a consumer product with a strong privacy story rather than an enterprise product with a compliance story,” he said, adding, “Whoever ships centrally managed escalation policy with enforceable egress inspection and tamper-evident audit will own the regulated-industry local AI market.”

Perplexity responds

In response to a request for an interview, Perplexity Communication Manager Beejoli Shah instead provided an emailed statement pushing back on the idea that data could travel to the cloud without deliberate permission. She wrote, “content in a local document can’t authorize an escalation by itself, nor can it override product controls. Escalation to the cloud requires explicit per-action approval in addition to toggling the app out of default local-only mode.”

Shah said such a data migration can only happen if the user has already toggled “allow advisor escalation” to “on” in app settings. “When that isn’t toggled on, no work can proceed to the cloud,” she said, pointing out that the product enforces restrictions on what local data and outbound actions are available to the agent.

She added that the user must also review a request in-app to send a piece of the task to the cloud, and that, she said, as illustrated in the introductory video, the request pop-up is the same size as prompt input. Furthermore, she said, “Escalation is only allowed once, not across the remainder of the task, or in future sessions.”

Kategorie: Hacking & Security

AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes

Bleeping Computer - 25 Srpen, 2026 - 22:25
A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature. [...]
Kategorie: Hacking & Security

AI hits entry-level jobs for younger workers the hardest — study

Computerworld.com [Hacking News] - 25 Srpen, 2026 - 21:25

AI has already begun to impact the job market and primarily affects young people early in their careers, according to a recent study by researchers at Stanford University. The researchers analyzed anonymized salary data from the HR platform ADP and compared occupations that are affected by AI to varying degrees to develop their findings, Ars Technica reported.

Among people aged 22 to 25, employment in the occupations most exposed to AI is now 19% lower than in positions less exposed to AI. Last year, the difference was 13%.

When looking at the labor market more broadly, the differences are significantly smaller. Older and more experienced workers have not been affected in the same way. According to the researchers, this is primarily because fewer young people are being hired in AI-exposed occupations, rather than existing employees being laid off.

The decline among young people is also most evident in occupations where AI can be used to replace specific tasks. In cases where AI is used instead to complement employees’ work, the picture is significantly more mixed.

Kategorie: Hacking & Security

U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

The Hacker News - 25 Srpen, 2026 - 20:17
The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an "unprecedented, whole-of-government, economic campaign" against the nation and its enablers. "We are launching an economic onslaught against Iran's financial connections around the globe. Our objective is to sever every economic lifeline that sustains this tyrannical regime Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

15 největších propadáků světa mobilů za posledních 15 let. Svůj moment si zažil kdekdo, i Apple

Zive.cz - bezpečnost - 25 Srpen, 2026 - 19:45
** Za posledních 14 let se ne vždy všechno vydařilo podle plánu ** Vzpomínáme na průšvihy značek i systémů ** A zmíníme i telefon, který se nechtěně stal velmi populárním
Kategorie: Hacking & Security

Massive DDoS attack disrupts Norway’s government digital services

Bleeping Computer - 25 Srpen, 2026 - 17:52
A large distributed denial-of-service (DDoS) attack has disrupted Norway's shared government digital infrastructure since Monday, affecting services used by the public sector. [...]
Kategorie: Hacking & Security

Mac production returns to America with the newest Mac mini

Computerworld.com [Hacking News] - 25 Srpen, 2026 - 17:39

Perhaps it is appropriate that the last few days of Tim Cook’s leadership at Apple is marked by the return of Mac manufacturing to America in the form of the new Mac mini, which the company has promised it will assemble in the US this year. The company on Tuesday also introduced new Mac Studio models.

It’s a perfect footnote to illustrate the tremendous work Cook has done to balance sometimes opposing forces both within and outside the company. In this instance, it mirrors his difficult diplomacy to try to get Apple one the right side of the Trump Administration. 

US officials have long wanted Apple to bring all of its product manufacturing back home. The company, in turn, has had to argue and cajole and show that this is simply not possible — because even if you built new factories today, you would not have sufficiently skilled employees to work in them tomorrow.

That reality has guided Apple in its approach to investing in US manufacturing. The company seeks to develop the most high-tech manufacturing in the US, while leaving more general product assembly elsewhere. This changes with the Mac mini, which is now the company’s flagship “Made in USA” product with final assembly in the US, replacing the now-discontinued Mac Pro. (Some components are made outside the US, but assembly has been promised at Houston.)

You should see this as a continuation of the company’s $600 billion investment in US manufacturing, which most recently saw Cook and US Commerce Secretary Howard Lutnick tour Apple/Foxconn’s Houston facility, where manufacturing will take place. It’s not the only hardware the company makes in the US; it also manufactures its Private Cloud Compute AI servers there. Both production lines are significant.

What to expect from the Mac mini

“Mac mini has always been our most versatile Mac. Whether it’s being used as a home computer, powering a professional studio, or as an always-on agentic device, it’s the little Mac that can do it all,” Johny Srouji, Apple’s chief hardware officer, said in a statement.

The all-new Mac mini features M6 and M5 Pro configurations that the company says provide a massive leap in AI performance (up to four times faster than before).  Storage and graphics are twice as fast, while the processor delivers 40% better performance than the one it replaces. Configurations ramp up to an 18-core CPU and 20-core GPU.

These things are fast. That’s significant given the growing number of people using one or more of these Macs to drive on-premises AI clusters. The new models are available now to order for delivery Sept. 22.

Both Mac mini models include Wi-Fi 7 and Bluetooth 6, as well as upgraded 2.5Gb Ethernet, with a 10Gb option available. With industry-leading performance per watt, these new Macs are fast, quiet, and cheaper to run, even at peak workloads.

They offer two USB-C port that support USB 3, a headphone jack, three Thunderbolt 4 ports on Mac mini with M6, and three Thunderbolt 5 ports on Mac mini with M5 Pro, along with HDMI and Ethernet. (You can cluster multiple Mac minis using Thunderbolt to create AI machines.)

It is also appropriate to point to the environmental credentials of these Macs, given Apple’s plan to be carbon neutral across its entire footprint by 2030. The Macs are made with 50% recycled material overall, including 100% recycled aluminum in the enclosure and 100% recycled rare earth elements in all magnets. All the energy used to make these Macs is sourced from renewable energy, Apple claims. 

Here are the mini details:

Mac mini M6, from $899
  • A 12-core CPU with the world’s fastest single-threaded performance, so everything feels extra snappy and responsive.
  • A 12-core GPU, includes Neural Accelerators in each core for the first time on a mini, resulting in up to 4x faster AI performance and 2x faster graphics than the mini with M4.
  • A new dual 16-core Neural Engine that delivers up to twice the performance of the previous generation.
  • 16GB of standard unified memory configurable up to 32GB, as well as higher memory bandwidth up to 170GB/s.
Mac mini with M5 Pro, from $1,699
  • Up to an 18-core CPU with remarkable multithreaded performance.
  • A 20-core GPU with enhanced shader core and third-generation ray tracing and Neural Accelerators in each GPU core.
  • Up to 64GB of unified memory with 307GB/s of memory bandwidth.
What about the Mac Studio?

Apple also introduced new Mac Studio configurations equipped with M5 Max and M5 Ultra chips, designed to handle the most demanding workflows. Available for pre-order now these, too, will ship Sept. 22.

The company promises up 4.3x faster AI performance, up to 2x faster storage, up to 1.8x faster graphics, and up to 1.3x faster CPU speed, along with higher memory bandwidth .“Mac Studio is the ultimate desktop for on-device AI and the world’s most demanding pro workflows, relied on by users for its tremendous performance and extensive pro connectivity, all in a quiet, compact design that sits right on your desk — and today, we’re pushing the boundaries even further,” said Srouji.

Mac Studio with M5 Max features an 18-core CPU, an up-to-40-core GPU with Neural Accelerators built into each core, and up to 128GB of unified memory. Prices start at $2,499.

The M5 Ultra variant scales up to a 36-core CPU, up to an 80-core GPU, and a possible 512GB of unified memory, enabling users to run enormous LLMs entirely on device. You also get Wi-Fi 7 and Bluetooth 6 and Thunderbolt 5, which enables multiple Mac Studio systems to be clustered for the most powerful possible on-prem AI deployments. Pricing starts at $5,499.

You can follow me on social media! Join me on BlueSky,  LinkedInMastodon and subscribe to The Core for the best daily Apple-related news summary in your in-box.

Kategorie: Hacking & Security

Hospital operator Nutex Health says data stolen in cyberattack

Bleeping Computer - 25 Srpen, 2026 - 16:44
Healthcare and services provider Nutex is investigating a data breach incident where an unauthorized third party exfiltrated information from company servers. [...]
Kategorie: Hacking & Security

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

The Hacker News - 25 Srpen, 2026 - 16:07
Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself. The findings were shared with The Hacker News ahead of publication, and the report says Oasis Security reported them to NVIDIA's Product Security Incident Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

From Fake Workers to Account Recovery: The Growing Identity Verification Risk

Bleeping Computer - 25 Srpen, 2026 - 16:01
Attackers are increasingly targeting the processes used to establish or recover identity rather than attacking the login itself. Specops explains how stronger identity verification can help organizations prevent fake workers and social engineering attacks from gaining legitimate access. [...]
Kategorie: Hacking & Security

Microsoft PowerToys adds Alt+Tab-style switching for an app's windows

Bleeping Computer - 25 Srpen, 2026 - 15:51
Microsoft updated its Windows PowerToys toolset with a new utility dubbed "Window Hopper" that lets users switch between an app's windows more quickly. [...]
Kategorie: Hacking & Security

Linux Hardening, Architecture & Isolation

LinuxSecurity.com - 25 Srpen, 2026 - 15:47
Linux hardening is not the act of enabling every restrictive setting a distribution provides. It is the work of reducing unnecessary exposure, limiting what users and processes can do, separating workloads, and confirming that those controls remain effective as the system changes.
Kategorie: Hacking & Security

WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android

The Hacker News - 25 Srpen, 2026 - 15:19
Meta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help users with both iOS and Android devices sign into their accounts using the phishing-resistant method. The tech giant said more than 1 billion people use a passkey to log into WhatsApp. Support for passkeys was first introduced in Android in October 2023, Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

WhatsApp adds stronger two-step verification, multiple passkeys

Bleeping Computer - 25 Srpen, 2026 - 15:00
WhatsApp has started rolling out several new account security features, including support for multiple passkeys and stronger two-step verification. [...]
Kategorie: Hacking & Security

Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode

The Hacker News - 25 Srpen, 2026 - 14:43
Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook, according to VulnCheck's CVE Numbering Authority (CNA) record. The CNA record says the command can run as a local subprocess when the notebook is opened in edit mode. The vulnerability, trackedSwati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Hackers breached over 270 Zimbra servers in ongoing attacks

Bleeping Computer - 25 Srpen, 2026 - 14:04
Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability. [...]
Kategorie: Hacking & Security

Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

The Hacker News - 25 Srpen, 2026 - 13:56
Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication. According to ANY.RUN research, 48% of targeted email addresses were potentially compromised. Most of the affected companies are US-based. Mirage2FA Campaign [email protected]
Kategorie: Hacking & Security

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

The Hacker News - 25 Srpen, 2026 - 13:52
Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. "While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn't do harm, the threat actor’s use of npm isn't to infect developers who install it, but to use the Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Syndikovat obsah