Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

Bleeping Computer - 24 Srpen, 2026 - 23:14
An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated attackers to create port-forwarding rules that can expose local network devices to the public internet. [...]
Kategorie: Hacking & Security

Hackers target WordPress sites in miniOrange auth bypass attacks

Bleeping Computer - 24 Srpen, 2026 - 21:26
Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. [...]
Kategorie: Hacking & Security

Inaudible sounds used to fingerprint browsers catch AliExpress red-handed

Ars Technica - 24 Srpen, 2026 - 21:19

Chinese retailer AliExpress has been caught fingerprinting visitors after one of the metrics—an outdated technique that measures inaudible sounds it sends to browsers—impeded a researcher's ability to use his bluetooth headphones.

Researcher Matthew Callaghan said he stumbled on the stealthy tracking by mistake. After loading the AliExpress homepage, audio from his phone stopped playing over his multipoint headphones, which accept connections from more than one device at a time. He set the headphones to play sounds from his phone except when his PC was producing audio. Each time he loaded AliExpress, the phone audio stopped. Each time he closed the tab the site was loaded into, the phone was once again audible.

Users can't hear it, but browsers can

While investigating the odd behavior, Callaghan said he found two highly obfuscated scripts. Together, they rendered a graph that analyzed the WebAudio readings of each visiting browser. This graph acted as an oscillator that measured Sawtooth waves, which are common in output from digital audio.

Read full article

Comments

Pro koho a kdy je papírový notes na hesla stejně bezpečný jako password manager

Zive.cz - bezpečnost - 24 Srpen, 2026 - 20:15
Notes s předtištěnými kolonkami na hesla vypadá jako vtip z doby modemů. Než ho ale úplně odsoudíte, zkuste si odpovědět: kdo se k heslům reálně může dostat a před kým je uživatel chrání.
Kategorie: Hacking & Security

TikTok reaches $400M settlement with US over COPPA violations

Bleeping Computer - 24 Srpen, 2026 - 19:56
The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children's Online Privacy Protection Act (COPPA). [...]
Kategorie: Hacking & Security

Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt

The Hacker News - 24 Srpen, 2026 - 19:41
If your developers are using AI coding tools, you are probably already seeing the upside: faster development, more code, and less time spent on routine work. The harder part is what comes after. AI can also introduce open-source packages at a pace your security team was never built to handle. More dependencies mean more vulnerabilities to review, more remediation work, and a backlog that can
Kategorie: Hacking & Security

Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt

The Hacker News - 24 Srpen, 2026 - 19:41
If your developers are using AI coding tools, you are probably already seeing the upside: faster development, more code, and less time spent on routine work. The harder part is what comes after. AI can also introduce open-source packages at a pace your security team was never built to handle. More dependencies mean more vulnerabilities to review, more remediation work, and a backlog that can [email protected]
Kategorie: Hacking & Security

Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning

The Hacker News - 24 Srpen, 2026 - 19:41
Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients. McAfee Labs said it detected and blocked more than 6,300 attempts to access malicious sites, adding that it found lookalike gaming websites designed to mimic legitimate projects, including branding, feature lists, FAQs,
Kategorie: Hacking & Security

Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning

The Hacker News - 24 Srpen, 2026 - 19:41
Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients. McAfee Labs said it detected and blocked more than 6,300 attempts to access malicious sites, adding that it found lookalike gaming websites designed to mimic legitimate projects, including branding, feature lists, FAQs, Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Apple’s folding iPhone has already launched – in your head

Computerworld.com [Hacking News] - 24 Srpen, 2026 - 17:51

You can’t have missed all the recent leaks. What used to be occasional glimpses into Apple’s future plans, followed by scripted public events, has now become a cadence of leaks followed by announcements.

Apple can’t seem to make a single move without it being telegraphed in advance to its users, usually from the same sources. We get treated to spookily accurate predictions about the big announcements, such as new iPhones. But now we also get a heads up for the smaller stuff, like the recently introduced Apple Upgrade scheme. It makes for interesting reading for the world’s most committed Apple watchers, that interest translates into waves of headlines, which is why Apple now effectively holds endless iPhone announcements each year.

Using the upcoming folding iPhone as an illustration, it works like this:

The seven waves of Apple product launches
  • First, we get an outsider rumor that Apple is about to introduce a new device, in this case a folding iPhone.
  • Later, we might get more speculation, usually along the lines that the still unannounced device has been “delayed” for some reason.
  • third series of rumors drip feed additional details about the upcoming new device. (There could be multiple waves of these.)
  • At some point, Apple will announce the event rumormongers has been predicting for months, spawning yet more reporting, speculation, and analysis.
  • Once the news is officially announced, it has already been reported, discussed, reported again, analysed, refuted, and even denied multiple times. 
  • Of course, the announcement also gets reported.
  • Then, the narrative turns to one of surprise/disappointment/analysis as the real-world product is compared to months of eerily accurate speculation and rumor.
  • Reality sets in as the early reviews arrive, typically first in the US. 
  • Millions rush to buy the new product, by which time many feel like they have nursed its birth for months.
  • Then the post-purchase help, advice, and follow-up reports begin.

But the magic is all in the stage setting during the earlier series of reports.

The arithmetic of anticipation

That means for every key Apple launch, we now experience at least seven waves of announcements for each product each year. Apple now holds two key calendar iPhone announcements annually, which makes for at least 14 waves of news — supplemented by additional speculation about individual models.

These multiple waves quickly add up, creating a tsunami of reporting that cannot help but establish Apple’s new product release in the public eye. How many people — and not just iPhone users — already know to expect a folding iPhone soon? How many also know demand for that device will exceed supply? Heck, we even know it will cost $2,000!

Manufactured consent 

This degree of public consciousness doesn’t happen by accident. It is created one wave at a time. It really doesn’t matter whether the speculation and rumors are generated by Apple itself or by merit of industrious digging on the part of well-connected reporters. It doesn’t matter because the results are the same. 

The rapid pace and multiple waves of leaks create a steady momentum to support any expected product release. This momentum works to Apple’s benefit, even when a leak is negative; the speculation allows for public debate before the bad news unfolds, giving Apple’s public time to digest the information. In this way, every news leak, every rumor, every bit of speculation does its part to support Apple’s incredible marketing machine. 

Momentum doesn’t care whether rumor makes the grade

Are we being cynical about this? Has the brazen nature of the approach turned people off from listening to news and speculation about the company? 

I don’t think so. Perhaps because, as the “father of public relations”, Edward Bernays said in his seminal book, “Propaganda”: “No matter how sophisticated, how cynical the public may become about publicity methods, it must respond to the basic appeals, because it will always need food, crave amusement, long for beauty, respond to leadership. If the public becomes more intelligent in its commercial demands, commercial firms will meet the new standards. If it becomes weary of the old methods used to persuade it to accept a given idea or commodity, its leaders will present their appeals more intelligently. Propaganda will never die out.”

Up next

We’re all expecting Apple to introduce new iPhones on Sept. 9. These will include the first ever folding iPhone, which will be available initially in the US only, and will deliver a high-end premium experience, though there may be some reservations around the camera. We’re also expecting a $100 price bump on other iPhones — but by the time the price increase is announced, we will already have come to terms with it. 

What’s coming next in the iPhone hype-cycle? Well, that will be news of the 20th anniversary glass iPhone, which is already up to wave three in the reporting cycle. Interested in following Apple’s news machinery? Sign up to my daily newsletter.

You can follow me on social media! Join me on BlueSky,  LinkedInMastodon and subscribe to The Core.

Kategorie: Hacking & Security

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

Bleeping Computer - 24 Srpen, 2026 - 17:17
Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team. [...]
Kategorie: Hacking & Security

⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

The Hacker News - 24 Srpen, 2026 - 16:32
A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet. That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks that sound harder than they actually are. Plenty to clean up. Here’s the short version. ⚡ Threat of the Week U.S.
Kategorie: Hacking & Security

⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

The Hacker News - 24 Srpen, 2026 - 16:32
A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet. That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks that sound harder than they actually are. Plenty to clean up. Here’s the short version. ⚡ Threat of the Week U.S. Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Microsoft Teams now lets admins block external bots from meetings

Bleeping Computer - 24 Srpen, 2026 - 16:00
Microsoft is rolling out a new Teams meeting protection policy that allows administrators to automatically block all identified external bots from joining Teams meetings. [...]
Kategorie: Hacking & Security

South Korean startup platform breach exposes key management failures

Bleeping Computer - 24 Srpen, 2026 - 16:00
A breach at South Korea's government-backed startup platform exposed encrypted personal data after an encryption key was included in an API. Penta Security explains why encryption keys must be securely managed and kept separate from the data they protect. [...]
Kategorie: Hacking & Security

Microsoft: August updates break printing, PDF export in WPF apps

Bleeping Computer - 24 Srpen, 2026 - 14:40
Microsoft has confirmed that .NET Framework updates released as part of the August 2026 Patch Tuesday are breaking printing and PDF export in WPF applications. [...]
Kategorie: Hacking & Security

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

The Hacker News - 24 Srpen, 2026 - 14:35
Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups. According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Stealer (aka ACR Stealer or AcridRain Stealer) via ClearFake campaigns, which employ the ClickFix (aka FakeCaptcha)
Kategorie: Hacking & Security

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

The Hacker News - 24 Srpen, 2026 - 14:35
Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups. According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Stealer (aka ACR Stealer or AcridRain Stealer) via ClearFake campaigns, which employ the ClickFix (aka FakeCaptcha) Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

BPF Congestion Control Exposed Two Linux TCP Use-After-Free Paths

LinuxSecurity.com - 24 Srpen, 2026 - 14:34
A Linux TCP query can touch congestion-control memory after a concurrent BPF update has freed it. Two new use-after-free reports show how an ordinary read path inherited a lifetime assumption that no longer holds when BPF makes congestion-control objects dynamically replaceable.
Kategorie: Hacking & Security
Syndikovat obsah