Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

Coder's registry infrastructure compromised to push malicious modules

Bleeping Computer - 3 Září, 2026 - 22:04
Attackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code. [...]
Kategorie: Hacking & Security

Confused about which VPN is right, US senator asks the NSA for guidance

Ars Technica - 3 Září, 2026 - 21:52

A prominent US senator is asking the National Security Agency to provide guidance to the general public on best practices for using virtual private networks to secure their communications from spying by foreign adversaries.

VPNs funnel all of a user’s Internet traffic through an encrypted connection to a remote server. The design provides strong assurances that no one between the user and the server can read the encrypted contents. VPNs also allow users to hide their IP addresses from the destination servers they communicate with. While US agencies have previously recommended use of VPNs, none have given recommendations on which ones provide adequate protection.

It's all in the nuances

There are a host of limitations that can undo many of the protections users may think their VPN provides them. For instance, the encrypted tunnel often terminates once a single server decrypts the traffic and sends it on to its final destination. That means the decrypted traffic or the sending and destination IP addresses may be available for snooping by rogue employees or attackers who hack the server. VPNs also don’t encrypt certain types of metadata, such as time stamps, allowing nation-states to build profiles that can be useful in intelligence gathering.

Read full article

Comments

VMware migration reduces Tottenham Hotspur's licensing fees by 85 percent

Ars Technica - 3 Září, 2026 - 20:58

Tottenham Hotspur, a professional soccer team that’s part of the Premier League, has saved over 85 percent in licensing fees by replacing its stadium's VMware instance with Hewlett-Packard Enterprise’s (HPE’s) Morpheus VM Essentials (VME) virtualization software.

Tottenham hasn’t disclosed which VMware products it used or how much it previously paid the Broadcom firm.

The soccer organization confirmed this week to The Register that it has moved its stadium's server, storage, and networking infrastructure to HPE solutions delivered through HPE's hybrid cloud management platform, GreenLake. That is all “underpinned by" VME and HPE's OpsRamp software for hybrid and multi-cloud environments, Rob Pickering, Tottenham's CTO, told the publication, with HPE in charge of the hybrid cloud-managed service.

Read full article

Comments

HPE patches critical ArubaOS-CX remote code execution flaw

Bleeping Computer - 3 Září, 2026 - 20:28
Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution. [...]
Kategorie: Hacking & Security

ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories

The Hacker News - 3 Září, 2026 - 20:02
The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone might open the door? That idea runs through this edition. Attackers use real tools, fake login pages, old account links, and software guides that point to unsafe downloads. One wrong letter in a web address can be enough. There is also
Kategorie: Hacking & Security

ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories

The Hacker News - 3 Září, 2026 - 20:02
The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone might open the door? That idea runs through this edition. Attackers use real tools, fake login pages, old account links, and software guides that point to unsafe downloads. One wrong letter in a web address can be enough. There is also Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Word and Outlook will stop trying to guess what you’re going to type

Computerworld.com [Hacking News] - 3 Září, 2026 - 19:38

Microsoft’s text suggestion feature will now be turned off by default in both Word and Outlook, reports The Register. The text suggestions attempt to predict which words or phrases the user intends to type in advance.

According to Microsoft, some users appreciate the feature, while others find the suggestions distracting. With it disabled by default, interested users can now choose for themselves whether they want to turn it on manually.

It is unclear whether the change will disable text suggestions for existing users who already have the feature enabled, or if it applies only to new installations and profiles.

The change applies to Word for Windows, the web, iOS, and Android, and to classic Outlook for Windows and Outlook for Mac. Rollout timing will be communicated through the Microsoft 365 admin center and release notes, Microsoft said.

This article originally appeared on Computer Sweden.

Related:

Kategorie: Hacking & Security

Serious vulnerability threatens tens of thousands of Exchange servers

Computerworld.com [Hacking News] - 3 Září, 2026 - 19:20

A serious vulnerability was recently discovered in Exchange Server 2016, Exchange Server 2016, and Exchange Server Subscription Edition (SE). The vulnerability is designated CVE-2026-62911 and can be exploited by hackers to gain full access to affected systems, according to Bleeping Computer.

Microsoft has released security patches to address the vulnerability as part of its August 2026 Patch Tuesday release, but there are still 21,899 unpatched servers at risk, according to The Shadowserver Foundation. The highest concentrations of vulnerable servers are in the US and Germany, the security group said.

The Netherlands National Cyber Security Centre and other agencies have urged admins to install the latest patches as soon as possible.

This article originally appeared on Computer Sweden.

Related:

Kategorie: Hacking & Security

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

The Hacker News - 3 Září, 2026 - 17:52
Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version. The Nexus vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), is
Kategorie: Hacking & Security

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

The Hacker News - 3 Září, 2026 - 17:52
Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version. The Nexus vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), isSwati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

The Hacker News - 3 Září, 2026 - 17:26
Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts. "Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial
Kategorie: Hacking & Security

BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

The Hacker News - 3 Září, 2026 - 17:26
Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts. "Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercialSwati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Why is Apple so quiet about what it offers the enterprise?

Computerworld.com [Hacking News] - 3 Září, 2026 - 17:23

I’ve been writing about Apple and how it benefits the enterprise for so long it’s easy to forget that the company doesn’t make enough noise about its accomplishments

Sure, it has pursued and won the argument about Total Cost of Ownership, proving that while initial costs might be higher, dollar for dollar Macs are a far more cost-efficient platform, particularly when it comes to product reliability and tech support. 

Apple already offers so much

Apple has also introduced extensive tools and APIs to help manage enterprise Macs, spawning a wide ecosystem of providers — most visibly, Jamf. Certain Apple products are already becoming deeply ingrained in some key professions; just think about Vision Pro and what it offers in medical care or prototype design, or the tens of thousands of Macs being carried around by AI developers across all the big name firms.

Some of what Apple delivers is already of major benefit to enterprise users. MLX for example, is being actively used to support real-life AI implementations, including by active AI-based businesses such as Yembo. And simplicity and ease-of-use isn’t just an advantage to consumer users, it boosts productivity in enterprise, too.

Almost 10 years ago, the focus was all about mobile enterprise, something that hasn’t gone away. Indeed, it is arguable that with Siri AI and third-party AI partners, Apple’s mobile enterprise story has become even more compelling. All the same, even then it was crystal clear that Macs had a big part to play in the future of enterprise tech. The iPhone accounted for 72% of all enterprise smartphone activations back then, while Jamf data has consistently shown us the steady forward momentum Mac has in business. 

So why hide the light?

As former Apple Enterprise Marketing Manager Todd Dailey points out, Apple does have some people it trusts to tell its business and enterprise stories. But it isn’t investing very much in making sure they have stories to tell. For example, he notes just one enterprise-related story on the Apple website. Published in Chinese only, that story is about Haidilao, which is seeing serious TCO and energy consumption benefits by running its back-end operations on Mac minis.

He also points to a near-mythical Apple-in-business event the company ran in Cupertino last June. That event generated almost no coverage anywhere, because no one was there to report on it. And yet it gathered leaders from Disney, Ford, Anthropic, Perplexity, Christie’s and presumably elsewhere to talk about how they use Macs in business, many with a focus on enterprise AI. I’ve spent time trying to track down additional information from that event, but there is not much out there. And while I’m willing to accept that some of those who took part needed business confidentiality, it was a semi-public event, so it seems unlikely significant secrets would have slipped out. 

It feels like a lost opportunity. Imagine the follow-up if Apple had paid a media team to attend the event to churn out stories, develop case studies, shoot video, and make viral influencer tik-toks. Is it that Apple doesn’t believe in its own enterprise offer? I don’t think so. It has a small army of business experts available to customers in stores, and they wouldn’t be there if it didn’t see a need for them.

Overcome myopia

Dailey thinks it’s a disconnect generated by Apple’s traditional focus on consumer markets. He’s probably correct, but it is frustrating; the real value Apple offers enterprise IT has been crystal clear for years – certainly since before then-Apple CFO Luca Maestri declared that Apple had set a new enterprise revenue record back in 2017. “Corporate buyers reported a 96% satisfaction rate and a purchase intent of 68% for the June quarter,” said Maestri at that time.

With that kind of momentum across such an extensive length of time, the company has without doubt built strong foundations of enterprise success. But these emerge most frequently as short footnotes in CFO statements during fiscal calls, rather than being shouted from the rooftops.

Here are some details

Highlights announced during those calls since 2024 include:

  • Nvidia launched a Mac-as-choice program with more than 10,000 Macs deployed worldwide.
  • UC-San Diego Health became the first hospital in the world to test Vision Pro spatial-computing apps in clinical surgical trials.
  • BMW Group deployed tens of thousands of iPhones, including to factory employees.
  • Capital One expanded its “Mac Choice” program with thousands more MacBook Airs.
  • Crédit Agricole (France’s leading retail bank) turned to on-device AI on the MacBook Pro to cut regulatory-workflow processing time by more than 80%.
  • Perplexity selected the Mac as its preferred platform for building enterprise-grade AI agents.

Apple knows these wins exist, and recently launched Apple Business, the all-in-one platform that combines hardware, software, and enterprise services to manage large-scale deployments. This showed the company knows what’s going on.

Mac does AI

Follow the money and it feels as if the next stage of the Apple-in-the-enterprise journey will at least in part be built around AI; Apple has major advantages it should celebrate with the sector. It offers the best systems for on-device AI, use and development. MLX is unique, ahead of its time, and worth leaning into. Its commitment to privacy is becoming increasingly and recognizably important to enterprise professionals. Even its battles to protect encryption are fundamental to business success.

Lots of its customers, not just Perplexity or Crédit Agricole, already see the advantages.

The successes it already has should be celebrated on the company’s own enterprise websites, and the company should recognize and invest in those stories and share them. Dailey points out that developers at Nvidia, Anthropic, OpenAI, and most enterprise AI shops all already use MacBook Pros for portable AI, suggesting a campaign around “Mac Does AI” should be in place. I see his point. I hope Apple does.

Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, and follow me on BlueSky, LinkedIn, or Mastodon.

Kategorie: Hacking & Security

Microsoft: KB5120998 mouse reset bug affects only non-English PCs

Bleeping Computer - 3 Září, 2026 - 17:22
Microsoft says a known issue that reverts mouse settings after installing the KB5120998 August 2026 preview update affects only non-English Windows 11 systems. [...]
Kategorie: Hacking & Security

OpenAI confirms ChatGPT is down ahead of 'Astra' model launch

Bleeping Computer - 3 Září, 2026 - 17:13
ChatGPT and Codex are experiencing a major outage, with users reporting errors across nearly every major ChatGPT feature. [...]
Kategorie: Hacking & Security

Anthropic confirms Claude is down, multiple models affected

Bleeping Computer - 3 Září, 2026 - 17:02
Claude is experiencing an outage, with users encountering elevated errors when sending requests to multiple Anthropic AI models. [...]
Kategorie: Hacking & Security

Critical Elementor Pro flaw exploited to take over WordPress sites

Bleeping Computer - 3 Září, 2026 - 16:52
A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server. [...]
Kategorie: Hacking & Security

Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data

The Hacker News - 3 Září, 2026 - 16:39
Thomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. West Publishing said it discovered the activity on June 30, 2026. A subset of court records could contain individuals' names
Kategorie: Hacking & Security

Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data

The Hacker News - 3 Září, 2026 - 16:39
Thomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. West Publishing said it discovered the activity on June 30, 2026. A subset of court records could contain individuals' namesSwati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Your Employee’s Password Appeared in an Infostealer Log. Now What?

Bleeping Computer - 3 Září, 2026 - 15:50
Infostealers can expose far more than passwords, including authenticated sessions that may let attackers bypass MFA. Flare explains how defenders can prioritize compromised identities, determine whether stolen access is still usable, and respond before it leads to account takeover. [...]
Kategorie: Hacking & Security
Syndikovat obsah