Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

Ryuk ransomware member pleads guilty in the US, faces 15 years in prison

Bleeping Computer - 2 hodiny 59 min zpět
A 34-year-old Armenian man has pleaded guilty to hacking U.S. companies and deploying the infamous Ryuk ransomware to encrypt their systems. [...]
Kategorie: Hacking & Security

Police suspects Dutch hackers were involved in Odido breach

Bleeping Computer - 4 hodiny 8 min zpět
The Dutch National Police (Politie) says it has found "strong indications" that Dutch hackers have been involved in a February breach at the telecommunications provider Odido. [...]
Kategorie: Hacking & Security

URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat

The Hacker News - 4 hodiny 15 min zpět
Progress Software has told ShareFile customers to shut down the Windows servers running their Storage Zone Controllers, confirming to The Hacker News that it is responding to a "credible external security threat." The company has temporarily disabled access to the affected accounts, a step it says it took "out of an abundance of caution" while it works with internal and external security Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages

The Hacker News - 4 hodiny 16 min zpět
Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases. The compromised version, @injectivelabs/[email protected], came embedded with fake telemetry functionality that exfiltrated data from cryptocurrency wallets. The version was Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Progress urges ShareFile admins to shut down servers over “credible” threat

Bleeping Computer - 4 hodiny 19 min zpět
Progress Software is emailing ShareFile customers who use Storage Zone Controllers to immediately shut down their servers after identifying what it describes as a "credible external security threat" targeting the on-premises secure file-sharing software. [...]
Kategorie: Hacking & Security

Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot

The Hacker News - 4 hodiny 47 min zpět
Researchers at firmware security firm Binarly have found six new flaws in U-Boot, the small program that starts up hardware as varied as home routers, smart cameras, and the management chips inside data-center servers. Four of the bugs can crash a device. The other two could let an attacker who slips a malicious image in front of the bootloader run their own code, before the device Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Hackers exploit critical auth bypass in Gitea Docker image

Bleeping Computer - 4 hodiny 56 min zpět
Hackers are actively exploiting a critical vulnerability in the official Docker image for the Gitea self-hosted Git service that allows attackers to impersonate any user, including administrators. [...]
Kategorie: Hacking & Security

Money launderer accused of stealing seized crypto while in prison

Bleeping Computer - 5 hodin 14 min zpět
A Bulgarian national has been charged with stealing $290,000 in government-seized cryptocurrency while serving 121 months in prison for helping launder millions stolen from American fraud victims. [...]
Kategorie: Hacking & Security

Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched

The Hacker News - 5 hodin 53 min zpět
Researchers at Ledger's Donjon security team have shown that a precisely timed laser pulse, aimed at the chip inside a Tangem crypto wallet card, can reset the card's password to anything the attacker picks. No old password. No backup card. Once it is reset, whoever did it controls the wallet and can move the coins out. This is not an emergency for most owners. The attack needs Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Microsoft Exchange Server on prem gets a little harder to use

Computerworld.com [Hacking News] - 6 hodin 4 min zpět

It’s the end of the road for yet another facet of Exchange Server, Microsoft’s on-premises email and calendar system. The stripped-down version of its web client, Outlook Web App (OWA) Light, is being retired, forcing those Exchange Server users still using it to adopt the standard Outlook Web App instead.

“OWA Light was created for a much earlier era of the web, when browser support, bandwidth, and accessibility technologies were very different from today. Going forward, we want to invest in a modern Outlook on the web experience that provides the cross-browser, accessible, and security-focused experience,” said Microsoft.

Those enterprises still operating in a resource-constrained environment are out of luck, then.

The change will be effected in an upcoming Exchange Server update expected in August. The move should come as no surprise: Microsoft had already deprecated the light version of Outlook in August 2024. Microsoft said that sysadmins should spend the next couple of months preparing for the change by identifying any staff still using OWA Light.

This is just the latest alteration that Microsoft has made to its Exchange ecosystem, which some holdouts still use instead of the SaaS-based Microsoft 365 service. However, even on-premises customers must now pay a subscription fee to use Exchange Server.

One of the advantages of SaaS offerings is that customers don’t have to deal with patching, an advantage brought home to on-premises customers in May when a zero-day exploit struck Exchange Server.

Kategorie: Hacking & Security

Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws

The Hacker News - 6 hodin 25 min zpět
Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully exploited, could enable credential theft, privilege escalation, and arbitrary code execution on the host. A brief description of the high-severity vulnerabilities is as follows - GHSA-hjr6-g723-hmfm (CVSS score: 8.8) - An operating system Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Mistral joins rush to build physical AI

Computerworld.com [Hacking News] - 6 hodin 30 min zpět

French AI company Mistral claims its latest AI model offers a more efficient way to train and operate robots.

The model, Robostral Navigate, can guide a robot through plain language instructions, using a single RGB camera to find its way. Mistral said that this was a radical departure from most other models, which rely on depth sensors, LiDAR or several cameras working together.

Robostral Navigate has achieved a score of 76.6% on the R2R-CE (Room-to-Room in Continuous Environments) benchmark for robots following instructions. This beats the best system using depth sensors or multiple cameras by 4.5 percentage-points, despite the Robostral Navigate using neither of these aids, and puts it 9.7 percentage-points ahead of the next-best single-camera robot.

Mistral said it had designed the model to autonomously navigate complex environments including offices, residential and commercial buildings, and outdoor settings. A key feature of the new model is that it is easier to train: Mistral said the number of training tokens is reduced significantly compared to other models, reducing training runs from months to days.

Robotics is an area ripe for AI research: The World Economic Forum at Davos in February heard how AI-driven robotics could drive advances in productivity.

Other AI model developers are ahead of the game: Nvidia announced robotic AI efforts in August 2025.

Kategorie: Hacking & Security

The Replicant in Your Directory: AI Agents and the Identity Security Gap

Bleeping Computer - 6 hodin 45 min zpět
AI agents are accelerating the growth of non-human identities, making it harder for organizations to understand what exists, who owns it, and what it can access. Netwrix explains why stronger visibility and identity governance are essential as AI expands the enterprise attack surface. [...]
Kategorie: Hacking & Security

Linux Log Analysis: How to Investigate Suspected Log Manipulation During Incident Response

LinuxSecurity.com - 6 hodin 49 min zpět
When an attacker breaks into a Linux system, their work is rarely done. Usually, the real work starts after the initial exploit: hiding their tracks. If you’re a Linux admin or security analyst, there is nothing worse than logging in, running a few commands, and realizing the logs aren't telling the whole story. When logs are missing or look "off," your primary source of truth is compromised. This guide covers how to handle that situation. We’ll walk through the workflow you need to determine...
Kategorie: Hacking & Security

Malicious Go Modules: Securing Your Linux Build Pipeline

LinuxSecurity.com - 7 hodin 57 sek zpět
Every Linux developer who works with Go has run the same workflow a thousand times. You find a library that solves your problem, you see a decent star count on GitHub, and you run go get. It is frictionless and efficient. Lately, however, it is becoming one of the most effective ways for an attacker to get code running on your build servers. The recent "Operation Muck and Load" campaign is a perfect example of why this workflow is risky. Researchers uncovered over 200 GitHub repositories dist...
Kategorie: Hacking & Security

New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic

The Hacker News - 7 hodin 29 min zpět
The China-linked cybercrime group known as Silver Fox has been attributed to a new Rust-based remote access trojan (RAR) called MODBEACON. Chinese cybersecurity company QiAnXin said that while the threat cluster may appear like a low-sophistication, high-activity operation that propagates malware via counterfeit installers using SEO poisoning techniques, it belies their true organizational Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Apple will buy more US-made components from Broadcom

Computerworld.com [Hacking News] - 7 hodin 1 min zpět

Apple has agreed to buy up to $30 billion-worth of additional chips and other wireless components from Broadcom over the next few years.

The new agreement could lead to Broadcom making up to 15 billion more chips in the US, and enable it to modernize its manufacturing facilities in Fort Collins, Colorado, where it will produce radio frequency components including thin-film bulk acoustic resonator (FBAR) filters and advanced wireless connectivity technologies, Apple said.

The deal is part of Apple’s effort to create an end-to-end supply chain in the US. It has already been exploring options that could wean it off Chinese-made chips. Last year it launched its American Manufacturing Program (AMP) to accelerate manufacturing in the US, committing to “invest $600 billion in the US economy over four years” in support of local manufacturing and jobs.

US companies have been keen to source chips manufactured in the US to eliminate supply-chain uncertainty in the face of President Trump’s ever-changing tariff policies.

“We’re grateful to the president and his administration for supporting important projects like this one,” Apple CEO Tim Cook said in a news release, without specifying the nature of the Trump administration’s support for such deals.

He said the components Broadcom makes in Fort Collins were essential to Apple’s products.

Kategorie: Hacking & Security

Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers

The Hacker News - 8 hodin 57 min zpět
A single wrong variable on one line in XQUIC, Alibaba's QUIC and HTTP/3 library, lets any remote client crash the server with a short burst of completely legal traffic. There is no patch. FoxIO researcher Sébastien Féry disclosed the flaw on July 8 and nicknamed it XRING. He says it needs no login and no malformed packets: about 260 bytes of ordinary QPACK traffic takes the server Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Zimbra urges customers to patch critical web client XSS flaw

Bleeping Computer - 8 hodin 57 min zpět
The Zimbra security team urged customers to patch a critical vulnerability affecting the Classic Web Client used to access the Zimbra Collaboration suite. [...]
Kategorie: Hacking & Security
Syndikovat obsah