Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

LinuxSecurity HOWTO: The Modern Linux Security Operations Playbook

LinuxSecurity.com - 17 Srpen, 2026 - 16:03
Linux security problems rarely stay in one place. An authentication issue can lead to unexpected privilege. A container problem can reach the host. Missing logs can make it difficult to determine whether an incident is contained or still active.
Kategorie: Hacking & Security

Certighost and the Privilege Hiding in Your Certificate Authority

Bleeping Computer - 17 Srpen, 2026 - 16:00
CVE-2026-54121 lets a standard domain user turn your Enterprise CA into a Domain Controller. The patch is the easy part. The lesson is standing privilege, implicit trust, and treating PKI as the Tier 0 identity infrastructure it has always been. [...]
Kategorie: Hacking & Security

Why LinuxSecurity Is Rebuilding the Linux Security HOWTO

LinuxSecurity.com - 17 Srpen, 2026 - 15:58
Linux security no longer lives on one server.
Kategorie: Hacking & Security

⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More

The Hacker News - 17 Srpen, 2026 - 15:23
The expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and supply-chain problems kept spreading farther than the original compromise. A lot of it came down to access that was already there and defenses that assumed nobody would look too closely. So, nothing magical. Just a Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Moburst Launches Answerburst, a Purpose-Built AEO Practice for the AI Search Era

Computerworld.com [Hacking News] - 17 Srpen, 2026 - 15:00

Moburst has launched Answerburst, a dedicated practice within the agency focused specifically on Answer Engine Optimization, built out of what the team describes as an internal need that showed up before there was a market name for it.

The founding story

The practice did not start as a planned product launch. According to the team, it began with client questions that traditional App Store Optimization and SEO reporting could not fully answer, specifically, why install and traffic patterns were shifting in ways that did not map to any tracked channel. Investigating those anomalies led the team to AI-mediated referrals long before AEO had settled into an industry term.

“We were debugging a mystery, not building a product,” a member of the founding team said. “The naming and the packaging came after we had already been doing the work for a while.”

What changed in the process

Formalizing the practice required building measurement infrastructure that did not exist off the shelf: tracking citation frequency across multiple AI assistants, distinguishing that signal from ordinary seasonal noise, and connecting it back to the channel-specific discovery features that a purely web-focused approach would have missed.

The team also says internal expectations shifted over the course of building the practice. What started as a narrow reporting fix became a recognition that AEO measurement needed its own standing discipline, connected to the agency’s existing organic and paid acquisition work but scoped separately.

The early tooling problem

Part of what slowed the initial investigation, the team says, was that no existing tool answered the specific question they had. Not how a site ranks, but whether an AI system mentions the brand when asked, and why. Building that answer meant querying multiple assistants directly and manually, on a repeated schedule, before anything resembling automated tracking existed. Some of that manual process still underpins the methodology today, even as parts of it have been automated. The team says the manual groundwork, tedious as it was, gave them an unusually granular early view of how citation behavior varied across assistants, one that off-the-shelf tools built later did not initially replicate. 

Lessons learned

The clearest lesson the team points to is that consistency across independent sources matters more than any single piece of optimized content. An AI system deciding whether to cite a brand confidently seems to weigh agreement across many sources more heavily than the polish of any one source, which reframed a lot of the team’s early assumptions about where to focus effort.

The second lesson was measurement humility. Early internal reporting overstated AEO’s contribution before the team built a reliable way to separate it from seasonal and platform-driven noise. The current methodology takes a deliberately more conservative approach to attributing any outcome to AEO work.

A third, less expected lesson involved internal alignment. Getting the agency’s existing organic, app store, and paid acquisition teams to treat AEO as a connected discipline instead of a competing budget line took longer than building the measurement tooling, according to the team, since it meant changing how account teams were used to scoping and pricing engagements.

What comes next

Moburst says Answerburst will continue operating as a distinct practice inside the agency, serving both new AEO-specific engagements and existing clients looking to extend into AI search visibility. The team frames the launch as formalizing work it was already doing before the category had a name.

The near-term priority is publishing more of its internal measurement methodology externally, both to build credibility in a crowded field and to give the industry a clearer shared standard for what a defensible AEO results claim should include.

The team is also candid that the name itself is still being tested internally before any wider rollout. Whether Answerburst becomes a permanent externally facing sub-brand or an internal practice name attached to Moburst’s broader AEO work is, by the team’s own account, an open question, one they say they would rather answer correctly than quickly. For now, the name is a working label.

About Moburst

Moburst is a full-service, mobile-first digital marketing agency founded in 2013 by CEO Gilad Bechar and COO Lior Eldan. Headquartered in New York with global offices (including Israel), it helps startups and Fortune 500 brands scale using AI-powered marketing. Major clients include Google, Uber, Samsung, and Reddit.

Kategorie: Hacking & Security

Windows Server 2022 reaches end of mainstream support in 60 days

Bleeping Computer - 17 Srpen, 2026 - 14:33
Microsoft has reminded IT administrators that Windows Server 2022 is rapidly approaching its mainstream end date of October 2026, when it will switch to extended support. [...]
Kategorie: Hacking & Security

How MCP Servers Can Expose Enterprise Secrets

The Hacker News - 17 Srpen, 2026 - 13:58
MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams even know the server is running. As more organizations adopt AI agents into their systems, that exposure can silently become a major gap in MCP server security. The Model Context Protocol (MCP) allows AI agents to reach the tools and data, [email protected]
Kategorie: Hacking & Security

Exchange CU1 delayed further as Microsoft races to verify AI-found flaws

Computerworld.com [Hacking News] - 17 Srpen, 2026 - 13:25

AI-based assistants and agents are generally supposed to expedite software development lifecycles. For Microsoft’s Exchange team, it may be doing the opposite, in turn leaving enterprise IT teams waiting for an update that will require extensive compatibility testing before implementation.

In response to customer questions, Microsoft said in a blog post that it was again being forced to delay the first Cumulative Update (CU1) for its Exchange Server Subscription Edition because its engineers were racing against time to validate a growing volume of security findings surfaced through AI-assisted code scanning.

“Over the last few months, various Microsoft execs made statements explaining how Microsoft is leveraging a variety of AI tools to help find vulnerabilities in our products (examples of such announcements can be found herehere and here),” the company wrote.

“Many teams, Exchange Server included, are working through reported issues – which includes validation that they are real security issues, reproducing, fixing, testing for regressions / issues after fixes are deployed and releasing updates monthly,” it added.

The company had initially indicated that CU1 would arrive by the end of the first half of 2026, before revising its target to the second half of 2026. The latest delay, where Microsoft is yet to offer any timeline,  therefore marks the second time the hyperscaler has pushed back its expected release window.

A Cumulative Update (CU) is a periodically released package for Exchange Server that consolidates recent bug fixes and security updates, while also potentially introducing new features, architectural changes or removing deprecated components.

Unlike the monthly security updates that Microsoft has continued to issue for Exchange Server Subscription Edition (SE) consistently, CUs represent a more substantial update to the server software and are typically released once or twice a year.

This gives enterprise administrators the option of adopting a consolidated package of fixes and changes rather than managing individual updates separately, although the broader scope of a CU also means enterprises need to conduct more extensive testing before deployment.

Enterprises should stop waiting for a CU1 date

The second revision of the CU1 release timeline combined with the unavailability of a committed shipping date or month, according to Manoj Chandra Jha, principal analyst at Nord-IQ Research, should be reason enough for enterprises to course correct.

Enterprises should start tracking the monthly security update cadence as their operational patch baseline, and treat CU1 as a discrete, trigger-based project ,not a scheduled release until Microsoft provides a firmer signal,” Jha said.

For enterprises that are waiting for a commitment or CU1’s release to begin their preparation, however, the delay shouldn’t mean standing still, Jha pointed out.

“With no committed ship date, CIOs should separate CU1 readiness from Microsoft’s release calendar by maintaining a test environment, inventorying and pre-validating authentication, APIs and management tools, and establishing a fast-track change-approval process that can be activated once Microsoft announces the update,” Jha noted.

AI is moving the software bottleneck downstream

Microsoft’s Exchange isn’t the only company division confronting the unintended consequences of AI-driven increases in software output.

GitHub, which helped popularize AI-assisted coding through its vibe coding tool Copilot, has also been grappling with the volume and quality of code being generated by AI tools.

In February, GitHub considered allowing repository maintainers to restrict or even disable pull requests after maintainers warned that a surge of low-quality, often AI-generated submissions was overwhelming open-source projects. The problem was not simply that AI was generating more code, but that humans were struggling to review and manage the resulting flood of contributions.

GitHub subsequently introduced Stacked PRs in April, saying the feature was designed to help developers manage larger and more complex code changes as AI-assisted development increases the volume of code requiring review. Its rationale was to break larger changes into smaller units, in turn making them easier to review and merge.

AWS too identified a similar issue and in June added release management features to its DevOps Agent to help teams validate, test, and review AI-generated code before deployment.

More recently, AI-based Code Review platform CodeRabbit also added new features to help developers sort and prioritize pull requests in wake of the growing volume and complexity of code changes generated by vibe coding agents.

This mismatch between the volume of AI-generated output and the amount of human attention available to assess it extends beyond code review.

Earlier, in May, GitHub also said it had seen a sharp increase in low-quality security submissions to its bug bounty program, driven in part by newer generative AI tools.

The company responded by scaling back cash rewards for reports with low security impact and asking researchers to focus on vulnerabilities that represent meaningful security risks.

Kategorie: Hacking & Security

Philips and GE investigating Clop ransomware data theft claims

Bleeping Computer - 17 Srpen, 2026 - 13:25
Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]
Kategorie: Hacking & Security

Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

The Hacker News - 17 Srpen, 2026 - 12:52
Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call, with no fix from the chipset maker. The advisory, published August 17, 2026, is the second stage of a chain that began in March 2026, when SSD disclosed remote code execution in the Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

French tax authority data breach affects 678,000 individuals

Bleeping Computer - 17 Srpen, 2026 - 12:09
The French Ministry of the Economy and Finance has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems and stole data belonging to 678,000 individuals. [...]
Kategorie: Hacking & Security

Zařízení velikosti mince dokáže hacknout letové systémy Boeingu 737. Instalace zabere minutu

Zive.cz - bezpečnost - 17 Srpen, 2026 - 11:50
** Odborníci připojili miniaturní čip přímo do údržbového konektoru Boeingu 737 ** Zneužitím zastaralé sběrnice dokázali přepsat nezabezpečenou komunikaci ** Útočník může snadno změnit naplánovanou trasu letu nebo hmotnost stroje
Kategorie: Hacking & Security

Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

The Hacker News - 17 Srpen, 2026 - 11:29
Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies. "While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, includingRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Microsoft working on Defender patch for ShieldBreak zero-day

Bleeping Computer - 17 Srpen, 2026 - 11:05
Microsoft is working on a security patch for the "ShieldBreak" zero-day vulnerability disclosed last week by security researcher "Nightmare Eclipse" and now tracked as CVE-2026-69414. [...]
Kategorie: Hacking & Security

Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

The Hacker News - 17 Srpen, 2026 - 09:36
Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT). The attacks involve the exploitation of CVE-2026-59310 (CVSS score: 9.8), a severe directory-traversal vulnerability in the VMware vCenter server that could be weaponized by a malicious actor to execute arbitrary codeRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

SafePal data breach impacts 39,798 customers, stolen info for sale

Bleeping Computer - 17 Srpen, 2026 - 01:47
Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data. [...]
Kategorie: Hacking & Security

Anthropic confirms Claude is down in major outage affecting multiple services

Bleeping Computer - 17 Srpen, 2026 - 00:28
Claude is experiencing a major outage, with users reporting login problems and degraded performance across several Anthropic services. [...]
Kategorie: Hacking & Security

Large-scale DDoS attacks disrupted Threema secure messaging service

Bleeping Computer - 16 Srpen, 2026 - 19:29
Multiple distributed denial-of-service (DDoS) attacks targeted the Threema secure messaging service earlier this week, causing severe disruptions to communications. [...]
Kategorie: Hacking & Security

New AmnesiaStealer macOS malware hijacks browser sessions via remote control

Bleeping Computer - 16 Srpen, 2026 - 17:07
A new information-stealing malware called AmnesiaStealer, which targets macOS users via ClickFix attacks, includes a streaming module that allows the attacker to interactively control the victim's web browser. [...]
Kategorie: Hacking & Security
Syndikovat obsah