Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

Year of free HPE software a “step in the correct direction” in VMware rivalry

Ars Technica - 17 Červen, 2026 - 00:11

Hewlett Packard Enterprise’s (HPE) new virtualization software promotion will likely pique the interest of end users and resellers who are unhappy with Broadcom's pricing of VMware.

During its HPE Discover event in Las Vegas this week, HPE announced that customers could use its “HPE Morpheus Software—VM Essentials” offering for free for “up to one year,” per a press release. HPE’s website describes its virtualization platform as a “VMware alternative.” It includes a hardware virtual machine (HVM) hypervisor and unified management and lets users "manage VMware ESXi and HVM clusters from one console and migrate when you’re ready,” HPE’s website says.

“New VM Essentials customers can receive up to one free year of licenses for VM Essentials, a year of HPE Zerto for $1 to support non-disruptive migration to HPE virtual machines, and 0 percent interest on software through HPE Financial Services,” HPE’s announcement reads, referring to HPE’s group for helping IT teams manage funding.

Read full article

Comments

Malicious JetBrains Marketplace plugins steal AI API keys from developers

Bleeping Computer - 16 Červen, 2026 - 23:54
At least 15 malicious plugins found on the JetBrains Marketplace were designed to steal AI API keys from developers. [...]
Kategorie: Hacking & Security

ChatGPT will soon be able to shop with your Visa card

Computerworld.com [Hacking News] - 16 Červen, 2026 - 22:24

OpenAI has signed a partnership agreement with Visa that allows the company’s AI agents to use the payment card for e-commerce transactions. The agreements lets users shop for everything from groceries and diapers to airline tickets without having to manually enter a lot of information.

“As AI agents become active participants in the economy, Visa’s focus is on ensuring that transactions are reliable, secure, and seamless,” Visa Chief Product and Strategy Officer Jack Forestell said in a statement, according to AP.

The pact means AI agents can complete purchases on a user’s behalf at virtually any merchant that accepts Visa. Details about the financial terms of the agreement, or whether specific transaction fees will apply, were not immediately detailed.

Kategorie: Hacking & Security

New Rokarolla Android malware targets 217 banking, crypto apps

Bleeping Computer - 16 Červen, 2026 - 22:04
A new Android banking trojan named Rokarolla is targeting 217 banking and cryptocurrency applications using an extensive set of 137 commands. [...]
Kategorie: Hacking & Security

Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting

The Hacker News - 16 Červen, 2026 - 21:05
A flaw in the Google Cloud Vertex AI SDK for Python let an attacker with no access to a victim's project hijack the victim's machine learning model upload and run code inside Google's serving infrastructure. Palo Alto Networks Unit 42, which found and reported the bug through Google's bug bounty program, calls the technique "Pickle in the Middle" and said it saw no exploitation in the wild. Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Steam Workshop abused to spread malware via Wallpaper Engine app

Bleeping Computer - 16 Červen, 2026 - 20:27
Threat actors are abusing Steam Workshop, Valve's community hub for downloading game-related content, to push various malware hidden in wallpaper packages. [...]
Kategorie: Hacking & Security

ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures

The Hacker News - 16 Červen, 2026 - 19:41
Cybersecurity researchers have flagged multiple ClickFix campaigns that deliver three malware loaders called BabaDeda Loader, Lorem Ipsum Loader, and Potemkin, per independent reports from Morphisec, BlueVoyant, and Huntress, respectively. Attacks involving BabaDeda Loader, observed in April 2026, have targeted education and financial organizations. "Earlier BabaDeda activity was known for Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

UK to require ID or face scan before you can make social media accounts

Bleeping Computer - 16 Červen, 2026 - 16:38
Opening a new social media account in the UK will soon mean proving you're over 16 with an ID upload or a facial age scan, under a government ban on under-16s taking effect in spring 2027. Security experts warn the age checks are easy to circumvent and create new data-breach risks. [...]
Kategorie: Hacking & Security

FreeRDP 3.27 Raises the Baseline for Secure Remote Access

LinuxSecurity.com - 16 Červen, 2026 - 16:32
Remote access tools do not need dramatic new features to improve security. Sometimes the more useful change is quieter, like stronger defaults that make weak encryption harder to use by accident.
Kategorie: Hacking & Security

SimpleHelp Authentication Bypass Exposes Remote Access Security Risk

LinuxSecurity.com - 16 Červen, 2026 - 16:22
Remote support platforms sit close to the systems attackers want most: administrator workflows, technician accounts, and managed endpoints. That is why the SimpleHelp OIDC flaw is more serious than a routine authentication bypass vulnerability. For organizations running these platforms on Linux-based infrastructure, the risk is compounded by the ease with which these services are deployed and integrated into larger management stacks.
Kategorie: Hacking & Security

GhostTree Attack Abused Recursive Windows Junctions to Hide Malware

Bleeping Computer - 16 Červen, 2026 - 16:17
GhostTree uses recursive NTFS junctions to generate vast numbers of valid Windows file paths. Varonis explains how the technique could cause Microsoft Defender folder scans to never complete, leaving malware undetected. [...]
Kategorie: Hacking & Security

Cisco SD-WAN Vulnerability: Why Security Starts With the Management Plane

LinuxSecurity.com - 16 Červen, 2026 - 16:04
For those of us who live and breathe Linux and open-source infrastructure, the "management plane" is usually just a collection of familiar tools—SSH, APIs, and centralized orchestration. But in the world of proprietary enterprise networking, the management plane is often a black box. Cisco’s latest SD-WAN issue serves as a stark reminder that even when these proprietary systems rely on Linux components under the hood, their centralized nature makes them the ultimate high-value target.
Kategorie: Hacking & Security

FTC warns of record $3.5 billion losses to imposter scams in 2025

Bleeping Computer - 16 Červen, 2026 - 15:42
The U.S. Federal Trade Commission (FTC) warned that Americans lost $3.5 billion to imposter scams in 2025, with reported losses nearly tripling since 2020. [...]
Kategorie: Hacking & Security

New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds

The Hacker News - 16 Červen, 2026 - 15:10
Security researchers at Zimperium's zLabs have documented a new Android banking trojan, Rokarolla, that targets 217 banking and cryptocurrency apps and packs 137 remote commands. Together, they give an operator near-total control of an infected phone: it lifts lock-screen PINs, reads and sends SMS, rewrites the clipboard to redirect crypto payments, and switches off Google Play Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Survey: 94% of Incidents Involve Anonymized Infrastructure. Teams Are Still Reactive

The Hacker News - 16 Červen, 2026 - 13:30
Security teams have never had more IP data at their disposal. Every day, analysts ingest enrichment feeds, geolocation data, reputation scores, telemetry, and threat intelligence from a growing ecosystem of vendors and platforms. Yet despite this abundance of information, many organizations continue to face a fundamental challenge: sifting through the noise to understand who is behind an IP [email protected]
Kategorie: Hacking & Security

Critical Copilot vulnerability allowed hackers to steal 2FA code from users

Ars Technica - 16 Červen, 2026 - 13:15

Last Tuesday, Microsoft patched a vulnerability it rated as max critical in its M365 Copilot AI platform. On Monday, the researchers who discovered the vulnerability and reported it to Microsoft revealed how their proof-of-concept exploit could retrieve 2FA codes and other sensitive data from emails accessible to Copilot.

Microsoft and other LLM providers have been unable to prevent their products from complying with malicious requests to reveal data. The root cause: AI bots are unable to distinguish between instructions provided by users and those snuck into third-party content the models are summarizing, drafting responses to, or using to perform other actions on behalf of the user. With no way to secure this crucial boundary, Microsoft and its peers are left to erect complicated and ad hoc guardrails designed to rein in the consequences of this incurable gullibility.

Jumping over guardrails

One guardrail built into Copilot and most other LLMs prevents them from submitting web forms, sending emails, and taking similar actions that can be used to exfiltrate data from the user. To work around this, LLM hackers turned to markup language, which, among other things, allows users to add formatting elements such as headings, lists, and links to text without the need for HTML tags. Another workaround is to wrap sensitive data inside HTML tags such as <img> and <form>. In either case, a web request showing the data hits the attacker’s web server, where the secret information is captured in logs.

Read full article

Comments

CISA warns of another cPanel plugin flaw exploited in attacks

Bleeping Computer - 16 Červen, 2026 - 12:47
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. government agencies three days to secure their servers against an actively exploited vulnerability (CVE-2026-54420) in the LiteSpeed cPanel user-end plugin. [...]
Kategorie: Hacking & Security

Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week

The Hacker News - 16 Červen, 2026 - 12:30
Bad actors are exploiting multiple security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber. In a post shared on X, the company said it has observed exploitation of CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089 over the past 24 hours. CVE-2026-39813 (CVSS score: 9.1) refers to a path traversal vulnerability in FortiSandbox JRPC API that could Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Ransomware gang abuses Microsoft Teams relays to hide malicious traffic

Bleeping Computer - 16 Červen, 2026 - 12:18
DragonForce ransomware used a custom malware named 'Backdoor.Turn' to hide command-and-control traffic inside Microsoft Teams relay infrastructure. [...]
Kategorie: Hacking & Security

China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth

The Hacker News - 16 Červen, 2026 - 11:44
Cybersecurity researchers have flagged two previously undocumented Windows variants of what was believed to be a Linux-only backdoor called SprySOCKS. "The Windows variants discovered are internally marked as WIN_DRV and WIN_PLUS," ESET said in a report shared with The Hacker News. "Both come with a hard-coded C&C [command-and-control] configuration and support communication over TCP, UDP, Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Syndikovat obsah