Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

The Hacker News - 9 Září, 2026 - 11:11
Google on Tuesday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine. "Out-of-bounds write in V8 in Google Chrome prior to
Kategorie: Hacking & Security

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

The Hacker News - 9 Září, 2026 - 11:11
Google on Tuesday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine. "Out-of-bounds write in V8 in Google Chrome prior to Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Man gets 15 years for extorting women with AI-generated porn videos

Bleeping Computer - 9 Září, 2026 - 10:44
An Ohio man was sentenced to 15 years in prison for multiple cybercrimes, including sextortion and cyberstalking of numerous victims using AI-generated sexually explicit content. [...]
Kategorie: Hacking & Security

New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

The Hacker News - 9 Září, 2026 - 10:19
cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user. cPanel published the advisory on September 8 and says every supported version of cPanel and WHM is affected.
Kategorie: Hacking & Security

New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

The Hacker News - 9 Září, 2026 - 10:19
cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user. cPanel published the advisory on September 8 and says every supported version of cPanel and WHM is affected. Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

The Hacker News - 9 Září, 2026 - 09:36
Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances' own PHP scripts, the malware adds the web shell to the copy held in memory, so a check of the file on disk can come back clean. Those three scripts are
Kategorie: Hacking & Security

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

The Hacker News - 9 Září, 2026 - 09:36
Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances' own PHP scripts, the malware adds the web shell to the copy held in memory, so a check of the file on disk can come back clean. Those three scripts are Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

Bleeping Computer - 9 Září, 2026 - 09:30
An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. [...]
Kategorie: Hacking & Security

Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed

The Hacker News - 9 Září, 2026 - 08:47
The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher reported last month. "Microsoft has failed to properly patch ShieldBreak CVE-2026-69414," Chaotic
Kategorie: Hacking & Security

Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed

The Hacker News - 9 Září, 2026 - 08:47
The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher reported last month. "Microsoft has failed to properly patch ShieldBreak CVE-2026-69414," Chaotic Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Google warns of new Chrome zero-day bug exploited in attacks

Bleeping Computer - 9 Září, 2026 - 08:25
Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year. [...]
Kategorie: Hacking & Security

SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

The Hacker News - 9 Září, 2026 - 08:25
SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE-2026-44756 (CVSS score: 10.0), has been described as a case of memory corruption. Discovered and reported by SAP
Kategorie: Hacking & Security

SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

The Hacker News - 9 Září, 2026 - 08:25
SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE-2026-44756 (CVSS score: 10.0), has been described as a case of memory corruption. Discovered and reported by SAP Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Leap second proposal will keep software stacks in sync

Computerworld.com [Hacking News] - 9 Září, 2026 - 07:24

For decades, global time experts have mapped atomic clock time to the earth’s rotation, periodically adding a second (aka a leap second) as rotation slowed. But the planet’s rotation has now slightly sped up, which could mean that a negative adjustment will be required. 

The problem is that computer systems have not been programmed to do that.

To avoid this issue, the General Conference on Weights and Measures (GCWM) in October will vote on a proposal to maintain the Coordinated Universal Time (UTC) as a continuous time from May 20, 2027, without adjustment via leap seconds, allowing UT1, the measure of time based on the earth’s rotation, and UTC to drift apart by up to one hour.

It pointed out, “a negative leap second has not previously been applied, and it is considered to pose a high risk of causing anomalies and disruption to critical infrastructures that are largely unprepared, and the preparation would create, for the industries that rely on time synchronization, a need for financial investment, whose amount is estimated to be similar to their preparations for the millennium bug.”

The group said that a 2025 workshop which included experts on Earth rotation estimated that the probability of a negative leap second will increase rapidly in the near future, reaching 30% by 2035. Acceptance of the proposal, it said, will ensure the long-term continuity for UTC for several centuries.

Unexpected requirement

Jeremy Roberts, senior director at Info-Tech Research Group, said that authorities never expected the need to reverse time. 

“We have been adding leap seconds for decades, basically to keep atomic time in line with observed time, but this is the first time we’d have to take one away. The problem is that computer systems aren’t designed to work this way,” Roberts said. “Rather than introduce a negative leap second, the proposal here is to let the two clocks go out of sync rather than keep adjusting to keep synchronicity with UT1 time and atomic time, which is much more consistent and not impacted by changes in the Earth’s rotation. This would make it easier for those building and maintaining infrastructure, because the clock would behave in a predictable way.”

Still, Roberts stressed that the proposed approach might eventually cause problems. 

“As with all things, this will require work to implement, and because the proposal includes a provision that allows for the clocks to go up to an hour out of sync, that would presumably create a problem for our descendants when we eventually reach that point,” Roberts said. “[But] being indecisive could cause fragmentation in standard time as different entities move to different standards, which could come with its own set of problems.”

Frank Dickson, principal analyst at Dickson Research, added that this proposed move is revolutionary in time-keeping circles.

“This is the biggest change to civil timekeeping since the leap second itself was adopted in 1972,” Dickson said. “Earth’s rotation has historically been slowing down, so that’s the only direction the system has ever had to handle. What’s crazy is that the Earth’s rotation has been speeding up in recent years, requiring a negative leap second, subtracting a second instead of adding one. Nobody has ever run that in production, at global scale, on the systems the world actually depends on.”

Dickson said that it is critically important that the vote pass, because the IT community has seen what happens when clocks malfunction.

“In a world of interlocking software applications, you cannot always predict how a global change will impact digital systems. In 2012, one ordinary positive leap second took down Reddit, LinkedIn, and Qantas’s booking system,” Dickson said. “It also triggered a race condition in the Linux kernel that spiked CPU load across servers worldwide. Nobody had tested for it because it had never happened before.”

And another incident involving timekeeping took down the Telstra network in Australia just last month. 

A ‘more rational’ engineering decision

Mike Wilkes, enterprise CISO at Aikido Security, pointed out that the consequences of a negative leap second could be significant. “Skipping a second can expose assumptions buried in databases, distributed systems, authentication systems, schedulers, market infrastructure and logging platforms,” he said. “The CGPM proposal is effectively saying that, rather than forcing the entire digital economy to prepare for a novel failure mode, we should make UTC continuous. That seems like a far more rational engineering decision.”

Most consultants and analysts agreed that if the vote to adjust current time procedures fails, the resultant problems would likely happen gradually, and possibly dramatically.

“The most likely problem would not necessarily be one spectacular global outage. I would be more concerned about thousands of smaller inconsistencies occurring simultaneously,” said Boris Kolev, global head of technology at JA Worldwide. The problems he anticipated included timestamps appearing out of order, distributed transactions behaving unexpectedly, authentication tokens being interpreted incorrectly, monitoring and audit trails becoming inconsistent, or different systems disagreeing about the sequence of events.

Systemic technology risk

But Kolev warned of a potentially more severe problem, as different companies sharing varied technology dependencies with enterprises try tackling the time problem differently.

“That means an enterprise does not only have to worry about what its own servers do. It has to consider what happens when its cloud provider, operating system, identity provider, database, external APIs, and on premises systems interpret the same moment differently,” Kolev said. “This is precisely the type of systemic technology risk that concerns CIOs: individually, every dependency may look manageable, but globally there are millions of interconnected systems maintained by different organizations, written in different eras, and operating under different assumptions.”

Justin Greis, CEO of consulting firm Acceligence, also said that he hoped the proposal would pass. 

“I think this is one of those cases where delaying what appears to be the technically correct answer may actually be the more responsible engineering decision. At some point, you have to ask whether preserving the relationship between civil time and the Earth’s rotation to within a second is worth introducing operational risk across financial systems, telecommunications networks, cloud platforms, power infrastructure, transportation systems and countless other technologies that depend on precise synchronization,” Greis said. “For the overwhelming majority of enterprise technology, I don’t think it is.”

This article originally appeared on Network World.

Kategorie: Hacking & Security

Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

The Hacker News - 9 Září, 2026 - 06:41
Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Of these, over 110 shortcomings have been assigned a critical severity rating.
Kategorie: Hacking & Security

Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

The Hacker News - 9 Září, 2026 - 06:41
Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Of these, over 110 shortcomings have been assigned a critical severity rating. Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

The Hacker News - 9 Září, 2026 - 06:27
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in question is CVE-2026-86218 (CVSS score: 10.0), which has been described as a
Kategorie: Hacking & Security

N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

The Hacker News - 9 Září, 2026 - 06:27
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in question is CVE-2026-86218 (CVSS score: 10.0), which has been described as a Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Microsoft adds age-awareness APIs that can tell if users are children, teens, or adults

Bleeping Computer - 9 Září, 2026 - 03:16
Microsoft is adding new age-awareness APIs to Windows 11 that will allow apps to determine whether someone is a child, teenager, or adult without exposing their exact date of birth. [...]
Kategorie: Hacking & Security

Why this month's Microsoft patch release is a doozy

Ars Technica - 8 Září, 2026 - 23:11

Microsoft’s patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed and 112 of them meeting the high critical-severity threshold.

It was only two months ago that Microsoft patched a then-record 570 vulnerabilities. Then, last month, Microsoft patched some 620 of them. Google and other companies have also published record numbers of vulnerabilities in recent months. Two weeks ago, OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and 100 companies and organizations published an open letter warning of a narrowing window for patching vulnerabilities ahead of an expected tsunami of AI-enabled attacks that actively exploit them first. The industry is taking the threat seriously by pumping out unprecedented numbers of patches in their software.

Welcome to the new normal

Dustin Childs, a researcher at the Zero Day Initiative, calls the spikes the “new normal” and also cautions that despite them, the damage that’s likely to result from AI-assisted attacks could eventually be substantial.

Read full article

Comments

Syndikovat obsah