Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

Hacker claims 3.6 million Azure account records stolen from major companies

Bleeping Computer - 17 Srpen, 2026 - 21:35
A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials. [...]
Kategorie: Hacking & Security

Pokémon Center data breach exposes customer info, cancels some orders

Bleeping Computer - 17 Srpen, 2026 - 21:12
Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics. [...]
Kategorie: Hacking & Security

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

The Hacker News - 17 Srpen, 2026 - 20:44
Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to execute commands in a workflow containing internal Jira credentials. The issue was present in .github/workflows/jira_issue.yml, which ran when a Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

The Hacker News - 17 Srpen, 2026 - 20:22
A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites. The vulnerability, tracked as CVE-2026-15748, is rated 9.8 out of 10.0 on the CVSS scoring system. It was discovered and reported by a security researcher who goes by the online alias "Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic

The Hacker News - 17 Srpen, 2026 - 19:41
Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel. Russian cybersecurity company Kaspersky said its ongoing monitoring of the threat activity cluster since December 2025 has led to the discovery of previously unreported components that expand theRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Jak dobře vybrat Mac. Většině lidí bude stačit i ten nejlevnější počítač od Applu

Zive.cz - bezpečnost - 17 Srpen, 2026 - 18:45
**Všechny nové Macy vám budou dobře sloužit celé roky. **Výkonu mají dostatek, ani starší modely nejsou brzdou. **MacBook dává smysl, i když už máte iPad.
Kategorie: Hacking & Security

US confounds Apple’s memory supply challenge

Computerworld.com [Hacking News] - 17 Srpen, 2026 - 17:38

US Commerce Secretary Howard Lutnick is “not in favor” of Apple’s plan to alleviate the impact of rapid memory price inflation by purchasing RAM made in China for use in devices sold there.

Trade by US firms with the biggest Chinese memory manufacturers, CXMT and Yangtze Memory Technologies, is restricted. Apple must secure a license before it can share product information with either firm, though it can still purchase off-the-shelf components that do not require any product details to be shared.

That may be good for Apple, despite White House reticence. Apple has said there isn’t a lot of customization in how it uses memory on its systems, which means it might be able to purchase off-the-shelf RAM. Still, Lutnick seems ideologically against such a move, saying there must be “other solutions to the memory issue, but it’s not great American companies using Chinese memory.” 

No solution in sight

Apple isn’t alone. HP and Acer are both using memory from CXMT in devices sold outside the US, which suggests a US-native solution to the memory crisis doesn’t yet exist. Pending discovery of any magical fix to the real-world supply challenge, the big three US-approved memory vendors continue to raise DRAM prices as they focus manufacturing on data center clients. The vendors have promised to bring more capacity online, but this won’t get into production until 2029 at the earliest.

The US seems to be rushing to make this more difficult; there’s a bipartisan Senate push to force Apple to avoid doing business with the firms, alongside calls to place even heavier restrictions on trade with CXMT. That would prevent Apple from purchasing even commodity memory from the companies.

The lack of memory supply is raising prices across the consumer and enterprise electronics industries worldwide, putting smaller companies out of business and making tech far less affordable for US and international consumers. It is also affecting product inventories; Apple has had to delay delivery dates for newly purchased devices and was forced to temporarily stop sales of some high memory configurations.

Analyst Ming-Chi Kuo even warned Apple has scaled back its hardware shipment plans for 2026 in response to the crisis. (There are even reports that the supply of Apple silicon processors has been hit by the shortage of good memory.)

We pay the price

The only positive way to escape this inflationary loop is to source, manufacture, or otherwise secure more supply — as Apple is attempting to do with CXMT. Alternatively, the government might need to force existing vendors to divert additional capacity to DRAM, which the Trump Administration hasn’t done and has flagged no intention to do.

US consumers and US businesses continue to pay the price for that indifference. Apple has been forced to raise some product prices up to 25% and might yet have to implement another wave of price increases.

The rapid increase in prices is being reflected by consumer purchasing behavior. The biggest signal so far on how this will play out comes from Japan, where refurbished iPhone sales more than doubled after Appe’s July price hikes. That trend was confirmed by a second report in Japan Times, which reports a huge spike in iPhone sales via the Nicosuma online marketplace.

As that trend asserts itself globally, it will affect new device sales, hurting both down- and upstream manufacturers in the consumer electronic supply chain, creating another vortex of inflationary pressure. Consumers will also wind up using their devices longer and turn to lease and hire schemes in preference to cash or credit to settle high purchase costs. 

New consumer habits

This change in behaviour can only go on for so long while new device sales shrink. At some point, it will become apparent that not enough new devices are entering the second user value chain to satisfy demand in that side of the market. The result: an additional inflationary wave, prompting second-user devices to become even more costly as lowering sales of new devices put smaller manufacturers out of business entirely, further reducing competition, denting corporate profits and, conceivably, undercutting tax receipts.

You can follow me on social media! Join me on BlueSky,  LinkedInMastodon and subscribe to The Core.Apple’s Chinese memory puzzle

Kategorie: Hacking & Security

Fence2Pwn Technique Uses KFENCE to Bypass Linux Kernel Slab Hardening

LinuxSecurity.com - 17 Srpen, 2026 - 17:24
Security researchers have disclosed Fence2Pwn, a new Linux kernel exploitation technique that uses KFENCE’s alternate memory-allocation path to bypass protections enforced by the normal slab allocator.
Kategorie: Hacking & Security

OpenZFS Capability-Scoping Flaw Lets User Namespaces Reach Host Pool Operations

LinuxSecurity.com - 17 Srpen, 2026 - 17:15
A disclosure posted to the oss-security mailing list on August 16, 2026, reports that OpenZFS on Linux accepts namespace-local CAP_SYS_ADMIN for several host-level pool operations.
Kategorie: Hacking & Security

Microsoft confirms GitHub is down worldwide

Bleeping Computer - 17 Srpen, 2026 - 16:47
GitHub is down for some users as a widespread outage is causing errors across the website, API, Actions, Pull Requests, and several other services. [...]
Kategorie: Hacking & Security

Nvidia discloses $21B stake in SpaceX

Ars Technica - 17 Srpen, 2026 - 16:22

Nvidia has disclosed that it owns nearly 123 million shares in SpaceX, further highlighting the chipmaker’s entangled financial relationships with some of its biggest customers.

The $5.5 trillion company owned SpaceX stock worth nearly $21 billion at the end of June, according to an SEC filing on Friday. Elon Musk’s rocket conglomerate’s shares have fallen sharply since its June initial public offering, meaning Nvidia’s stake would now be worth $17 billion.

The disclosure marks a huge pay-off on Nvidia’s investment in xAI, completed in January, shortly before Musk combined the AI lab with SpaceX.

Read full article

Comments

LinuxSecurity HOWTO: The Modern Linux Security Operations Playbook

LinuxSecurity.com - 17 Srpen, 2026 - 16:03
Linux security problems rarely stay in one place. An authentication issue can lead to unexpected privilege. A container problem can reach the host. Missing logs can make it difficult to determine whether an incident is contained or still active.
Kategorie: Hacking & Security

Certighost and the Privilege Hiding in Your Certificate Authority

Bleeping Computer - 17 Srpen, 2026 - 16:00
CVE-2026-54121 lets a standard domain user turn your Enterprise CA into a Domain Controller. The patch is the easy part. The lesson is standing privilege, implicit trust, and treating PKI as the Tier 0 identity infrastructure it has always been. [...]
Kategorie: Hacking & Security

Why LinuxSecurity Is Rebuilding the Linux Security HOWTO

LinuxSecurity.com - 17 Srpen, 2026 - 15:58
Linux security no longer lives on one server.
Kategorie: Hacking & Security

⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More

The Hacker News - 17 Srpen, 2026 - 15:23
The expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and supply-chain problems kept spreading farther than the original compromise. A lot of it came down to access that was already there and defenses that assumed nobody would look too closely. So, nothing magical. Just a Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Moburst Launches Answerburst, a Purpose-Built AEO Practice for the AI Search Era

Computerworld.com [Hacking News] - 17 Srpen, 2026 - 15:00

Moburst has launched Answerburst, a dedicated practice within the agency focused specifically on Answer Engine Optimization, built out of what the team describes as an internal need that showed up before there was a market name for it.

The founding story

The practice did not start as a planned product launch. According to the team, it began with client questions that traditional App Store Optimization and SEO reporting could not fully answer, specifically, why install and traffic patterns were shifting in ways that did not map to any tracked channel. Investigating those anomalies led the team to AI-mediated referrals long before AEO had settled into an industry term.

“We were debugging a mystery, not building a product,” a member of the founding team said. “The naming and the packaging came after we had already been doing the work for a while.”

What changed in the process

Formalizing the practice required building measurement infrastructure that did not exist off the shelf: tracking citation frequency across multiple AI assistants, distinguishing that signal from ordinary seasonal noise, and connecting it back to the channel-specific discovery features that a purely web-focused approach would have missed.

The team also says internal expectations shifted over the course of building the practice. What started as a narrow reporting fix became a recognition that AEO measurement needed its own standing discipline, connected to the agency’s existing organic and paid acquisition work but scoped separately.

The early tooling problem

Part of what slowed the initial investigation, the team says, was that no existing tool answered the specific question they had. Not how a site ranks, but whether an AI system mentions the brand when asked, and why. Building that answer meant querying multiple assistants directly and manually, on a repeated schedule, before anything resembling automated tracking existed. Some of that manual process still underpins the methodology today, even as parts of it have been automated. The team says the manual groundwork, tedious as it was, gave them an unusually granular early view of how citation behavior varied across assistants, one that off-the-shelf tools built later did not initially replicate. 

Lessons learned

The clearest lesson the team points to is that consistency across independent sources matters more than any single piece of optimized content. An AI system deciding whether to cite a brand confidently seems to weigh agreement across many sources more heavily than the polish of any one source, which reframed a lot of the team’s early assumptions about where to focus effort.

The second lesson was measurement humility. Early internal reporting overstated AEO’s contribution before the team built a reliable way to separate it from seasonal and platform-driven noise. The current methodology takes a deliberately more conservative approach to attributing any outcome to AEO work.

A third, less expected lesson involved internal alignment. Getting the agency’s existing organic, app store, and paid acquisition teams to treat AEO as a connected discipline instead of a competing budget line took longer than building the measurement tooling, according to the team, since it meant changing how account teams were used to scoping and pricing engagements.

What comes next

Moburst says Answerburst will continue operating as a distinct practice inside the agency, serving both new AEO-specific engagements and existing clients looking to extend into AI search visibility. The team frames the launch as formalizing work it was already doing before the category had a name.

The near-term priority is publishing more of its internal measurement methodology externally, both to build credibility in a crowded field and to give the industry a clearer shared standard for what a defensible AEO results claim should include.

The team is also candid that the name itself is still being tested internally before any wider rollout. Whether Answerburst becomes a permanent externally facing sub-brand or an internal practice name attached to Moburst’s broader AEO work is, by the team’s own account, an open question, one they say they would rather answer correctly than quickly. For now, the name is a working label.

About Moburst

Moburst is a full-service, mobile-first digital marketing agency founded in 2013 by CEO Gilad Bechar and COO Lior Eldan. Headquartered in New York with global offices (including Israel), it helps startups and Fortune 500 brands scale using AI-powered marketing. Major clients include Google, Uber, Samsung, and Reddit.

Kategorie: Hacking & Security

Windows Server 2022 reaches end of mainstream support in 60 days

Bleeping Computer - 17 Srpen, 2026 - 14:33
Microsoft has reminded IT administrators that Windows Server 2022 is rapidly approaching its mainstream end date of October 2026, when it will switch to extended support. [...]
Kategorie: Hacking & Security

How MCP Servers Can Expose Enterprise Secrets

The Hacker News - 17 Srpen, 2026 - 13:58
MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams even know the server is running. As more organizations adopt AI agents into their systems, that exposure can silently become a major gap in MCP server security. The Model Context Protocol (MCP) allows AI agents to reach the tools and data, [email protected]
Kategorie: Hacking & Security

Exchange CU1 delayed further as Microsoft races to verify AI-found flaws

Computerworld.com [Hacking News] - 17 Srpen, 2026 - 13:25

AI-based assistants and agents are generally supposed to expedite software development lifecycles. For Microsoft’s Exchange team, it may be doing the opposite, in turn leaving enterprise IT teams waiting for an update that will require extensive compatibility testing before implementation.

In response to customer questions, Microsoft said in a blog post that it was again being forced to delay the first Cumulative Update (CU1) for its Exchange Server Subscription Edition because its engineers were racing against time to validate a growing volume of security findings surfaced through AI-assisted code scanning.

“Over the last few months, various Microsoft execs made statements explaining how Microsoft is leveraging a variety of AI tools to help find vulnerabilities in our products (examples of such announcements can be found herehere and here),” the company wrote.

“Many teams, Exchange Server included, are working through reported issues – which includes validation that they are real security issues, reproducing, fixing, testing for regressions / issues after fixes are deployed and releasing updates monthly,” it added.

The company had initially indicated that CU1 would arrive by the end of the first half of 2026, before revising its target to the second half of 2026. The latest delay, where Microsoft is yet to offer any timeline,  therefore marks the second time the hyperscaler has pushed back its expected release window.

A Cumulative Update (CU) is a periodically released package for Exchange Server that consolidates recent bug fixes and security updates, while also potentially introducing new features, architectural changes or removing deprecated components.

Unlike the monthly security updates that Microsoft has continued to issue for Exchange Server Subscription Edition (SE) consistently, CUs represent a more substantial update to the server software and are typically released once or twice a year.

This gives enterprise administrators the option of adopting a consolidated package of fixes and changes rather than managing individual updates separately, although the broader scope of a CU also means enterprises need to conduct more extensive testing before deployment.

Enterprises should stop waiting for a CU1 date

The second revision of the CU1 release timeline combined with the unavailability of a committed shipping date or month, according to Manoj Chandra Jha, principal analyst at Nord-IQ Research, should be reason enough for enterprises to course correct.

Enterprises should start tracking the monthly security update cadence as their operational patch baseline, and treat CU1 as a discrete, trigger-based project ,not a scheduled release until Microsoft provides a firmer signal,” Jha said.

For enterprises that are waiting for a commitment or CU1’s release to begin their preparation, however, the delay shouldn’t mean standing still, Jha pointed out.

“With no committed ship date, CIOs should separate CU1 readiness from Microsoft’s release calendar by maintaining a test environment, inventorying and pre-validating authentication, APIs and management tools, and establishing a fast-track change-approval process that can be activated once Microsoft announces the update,” Jha noted.

AI is moving the software bottleneck downstream

Microsoft’s Exchange isn’t the only company division confronting the unintended consequences of AI-driven increases in software output.

GitHub, which helped popularize AI-assisted coding through its vibe coding tool Copilot, has also been grappling with the volume and quality of code being generated by AI tools.

In February, GitHub considered allowing repository maintainers to restrict or even disable pull requests after maintainers warned that a surge of low-quality, often AI-generated submissions was overwhelming open-source projects. The problem was not simply that AI was generating more code, but that humans were struggling to review and manage the resulting flood of contributions.

GitHub subsequently introduced Stacked PRs in April, saying the feature was designed to help developers manage larger and more complex code changes as AI-assisted development increases the volume of code requiring review. Its rationale was to break larger changes into smaller units, in turn making them easier to review and merge.

AWS too identified a similar issue and in June added release management features to its DevOps Agent to help teams validate, test, and review AI-generated code before deployment.

More recently, AI-based Code Review platform CodeRabbit also added new features to help developers sort and prioritize pull requests in wake of the growing volume and complexity of code changes generated by vibe coding agents.

This mismatch between the volume of AI-generated output and the amount of human attention available to assess it extends beyond code review.

Earlier, in May, GitHub also said it had seen a sharp increase in low-quality security submissions to its bug bounty program, driven in part by newer generative AI tools.

The company responded by scaling back cash rewards for reports with low security impact and asking researchers to focus on vulnerabilities that represent meaningful security risks.

Kategorie: Hacking & Security

Philips and GE investigating Clop ransomware data theft claims

Bleeping Computer - 17 Srpen, 2026 - 13:25
Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]
Kategorie: Hacking & Security
Syndikovat obsah