Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

Ještě ji držíme, ale jen tak tak. Před AI utrženou z vodítka nás chrání dvě pojistky (komentář)

Zive.cz - bezpečnost - 13 Září, 2026 - 18:45
Od doby, kdy se objevily podrobnosti o útocích AI agentů na Hugging Face, mi v hlavě leží myšlenka, které se stále vrací. Před tím, aby AI začala škodit, nás chrání jen dvě tenké pojistky. Někde seděl člověk, při tréninku zadal AI modelu úkol a agenti se ho vydali plnit. Po cestě si našli si ...
Kategorie: Hacking & Security

Hackers exploit Tencent app flaw to deploy GrayRabbit malware

Bleeping Computer - 13 Září, 2026 - 16:26
Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor. [...]
Kategorie: Hacking & Security

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

The Hacker News - 13 Září, 2026 - 12:11
Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. The first campaign, per the tech giant, involved sending over a million scam emails between August 3 and 5, 2026, by masquerading as chief executive officers Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Dario z Anthropiku: „Musíme zpomalit.“ Sam z OpenAI: „Souhlasíme, je potřeba postupovat opatrně.“

Zive.cz - bezpečnost - 12 Září, 2026 - 21:54
Dario Amodei, šéf společnosti Anthropic (to je ta s Claude) publikoval rozsáhlou esej, ve které se zamýšlí nad dalším rozvojem nejvýkonnějších AI modelů. Celý text najdete přeložený ve spodní části článku, zde je jeho shrnutí. Dario Amodei postupně mění názor: nestačí jen investovat do prevence ...
Kategorie: Hacking & Security

Nový rekord. Microsoft v září díky AI opravil 723 zranitelných míst ve Windows

Zive.cz - bezpečnost - 12 Září, 2026 - 18:45
**Microsoft opravil přes 970 zranitelných míst ve svých produktech. **Servisní aktualizace vyšly 8. září 2026 večer. **Windows 11 umožňují změnit polohu hlavního panelu.
Kategorie: Hacking & Security

CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

The Hacker News - 12 Září, 2026 - 17:54
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. Details of the vulnerabilities are as follows - CVE-2026-42016 (CVSS score: 8.1) - An incorrect authorization Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

Bleeping Computer - 12 Září, 2026 - 16:14
The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. [...]
Kategorie: Hacking & Security

When the Whole Company Adopts AI: What It Does to Your SOC

The Hacker News - 12 Září, 2026 - 12:24
Over the past year, we watched a new class of alert appear in enterprise security operations centers and grow faster than anything else in the stream: alerts that were triggered by AI tools and agents. Not attacks against AI, but the ordinary, everyday footprint of an organization using it, from developers running coding agents and non-technical staff signing consumer AI tools into corporate [email protected]
Kategorie: Hacking & Security

OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers

The Hacker News - 12 Září, 2026 - 11:07
The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated cyber attack that targeted the package manager for the Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Linux Virtualization Fix Limits a Host Memory Exhaustion Path

LinuxSecurity.com - 12 Září, 2026 - 01:10
Linux virtualization lets a physical host run guest virtual machines. A fix in vhost, the Linux component that helps those guests exchange data with virtual devices, limits memory consumed by repeated requests for a missing memory mapping.
Kategorie: Hacking & Security

Linux Can Hold TLS Traffic Until a Confidential VM Proves Its State

LinuxSecurity.com - 12 Září, 2026 - 00:15
Confidential computing can protect a virtual machine’s memory from the host that runs it. A remote client still needs to check that its connection reaches the protected machine. Transport Layer Security, or TLS, encrypts the connection and checks the service’s identity, but does not by itself verify the machine’s software environment.
Kategorie: Hacking & Security

Hackers abused Claude to extract secrets from 1.8M Android apps

Bleeping Computer - 11 Září, 2026 - 22:19
Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes. [...]
Kategorie: Hacking & Security

Florida confirms DMV database breached via stolen police account

Bleeping Computer - 11 Září, 2026 - 21:00
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. [...]
Kategorie: Hacking & Security

Phishing na zákazníky Trezoru nerozsvítil žádnou kontrolku. Přišel z jeho vlastní adresy

Zive.cz - bezpečnost - 11 Září, 2026 - 20:45
Česká firma Trezor, výrobce hardwarových peněženek pro kryptoměny, se stal terčem phishingové kampaně. Byla rozeslaná přímo z jeho vlastní e-mailové infrastruktury. Útočník se 9. září 2026 dostal do e-mailové platformy Brevo, kterou Trezor používá na rozesílání newsletterů. Jeho zákazníkům ...
Kategorie: Hacking & Security

Passkey-themed phishing attacks lead to Microsoft 365 data theft

Bleeping Computer - 11 Září, 2026 - 19:26
Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services. [...]
Kategorie: Hacking & Security

Teams and Copilot are changing addresses: update your firewalls

Computerworld.com [Hacking News] - 11 Září, 2026 - 18:56

Microsoft is changing the destination address of two of its most popular services: starting this month, it will redirect M365 and Teams web users to copilot.cloud.microsoft and teams.cloud.microsoft, respectively.

The Teams move is already under way, and Microsoft has now added M365 to the mix. The company announced the changes in two MessageCenter posts: MC1465764 (mirror) and MC1462915 (mirror).

Organizations using these products are advised to update their systems and documentation to ensure continued access. Microsoft has told customers to review configurations on client devices, proxies, firewalls, secure web gateways, or other enterprise network controls to confirm that users can connect to the new addresses. Companies having trouble connecting should ensure that their environment aligns with the recommended network requirements for Microsoft 365 Copilot

Enterprises that had been blocking the new Copilot address to prevent employees accessing their personal Microsoft accounts can use Microsoft’s TenantRestrictions control to achieve their goals instead, it said.

All redirects should be completed by early October, Microsoft said, advising companies that can’t meet the deadline to contact their account representative for help. Limited exceptions to the Teams redirect are possible until Dec. 31, 2026, but after that no further delays will be possible, it said.

Kategorie: Hacking & Security

GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

The Hacker News - 11 Září, 2026 - 18:30
GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Artifactory flaws chained in attacks deploying backdoor malware

Bleeping Computer - 11 Září, 2026 - 18:29
Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. [...]
Kategorie: Hacking & Security

Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks

The Hacker News - 11 Září, 2026 - 18:15
Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax. Knowledge distillation by itself is a legitimate training method. It refers to a machine learning technique where a large, powerful AI model assumes the role of a "teacher" to Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Syndikovat obsah