Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

GhostLock Exposes an Uncomfortable Truth About Open Source Security

LinuxSecurity.com - 14 Červenec, 2026 - 16:17
When researchers announced GhostLock, many people focused on the exploit. What stood out to me wasn't just what the vulnerability could do, but how long it had remained hidden. The flaw had lived in the Linux kernel for roughly 15 years before it was publicly identified by researchers. That means the flaw survived hundreds of kernel releases and years of upstream development before it was publicly documented. It raises an uncomfortable question about one of open source's oldest assumptions. O...
Kategorie: Hacking & Security

You Don't Have to Run an Exploit to Know If You're Vulnerable

Bleeping Computer - 14 Červenec, 2026 - 16:00
Many vulnerabilities cannot be safely validated with live exploits, either because no exploit exists or the affected systems are too critical to test. Picus explains how TTP chaining helps organizations determine exploitability by validating the attack techniques an exploit depends on, without launching the exploit itself. [...]
Kategorie: Hacking & Security

RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata

The Hacker News - 14 Červenec, 2026 - 15:48
Cybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow attackers to leak OAuth client secrets, expose enterprise messaging infrastructure to takeover risks, and bypass tenant boundaries. Miggo's security team, which discovered and reported the flaws, said one "leaks the broker's confidential OAuth
Kategorie: Hacking & Security

RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata

The Hacker News - 14 Červenec, 2026 - 15:48
Cybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow attackers to leak OAuth client secrets, expose enterprise messaging infrastructure to takeover risks, and bypass tenant boundaries. Miggo's security team, which discovered and reported the flaws, said one "leaks the broker's confidential OAuth Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

How Linux Security Teams Spot Vulnerabilities Before CVEs Are Published

LinuxSecurity.com - 14 Červenec, 2026 - 15:12
Most of us don't hear about a kernel vulnerability until a CVE lands in our inbox or the vulnerability scanner starts complaining. By then, the patch isn't new anymore. Kernel developers may have been passing it around for review, arguing over the implementation, or revising it for days before anyone outside that community noticed it. None of those discussions are secret. They're sitting in mailing list archives, Git commits, and patch reviews where they've been the whole time. The strange pa...
Kategorie: Hacking & Security

Microsoft Entra ID gets passkeys default authentication starting September

Bleeping Computer - 14 Červenec, 2026 - 14:49
Microsoft has announced that passkeys will become the default authentication method for the Entra ID enterprise identity service starting September 2026. [...]
Kategorie: Hacking & Security

New phishing kits target Microsoft 365 accounts, evade MFA

Bleeping Computer - 14 Červenec, 2026 - 14:49
Two new phishing kits, Jalisco and OmegaLord, have been discovered in attacks targeting Microsoft 365 accounts, using techniques that defeat multi-factor authentication (MFA). [...]
Kategorie: Hacking & Security

11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot

The Hacker News - 14 Červenec, 2026 - 14:46
Cybersecurity researchers have discovered 11 old, Microsoft-signed, Unified Extensible Firmware Interface (UEFI) applications that could be abused to bypass Secure Boot on most systems using the modern firmware standard. "An attacker exploiting one of these vulnerable applications can execute untrusted code during system boot, enabling deployment of malicious UEFI bootkits or other malware,"
Kategorie: Hacking & Security

11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot

The Hacker News - 14 Červenec, 2026 - 14:46
Cybersecurity researchers have discovered 11 old, Microsoft-signed, Unified Extensible Firmware Interface (UEFI) applications that could be abused to bypass Secure Boot on most systems using the modern firmware standard. "An attacker exploiting one of these vulnerable applications can execute untrusted code during system boot, enabling deployment of malicious UEFI bootkits or other malware," Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks

The Hacker News - 14 Červenec, 2026 - 13:55
Researchers at KU Leuven tested 85 of the most popular crypto wallets that run as browser extensions and found that the wallets themselves leak enough to link and track the people using them. The way these wallets talk to websites and blockchain servers can tie a person's separate addresses together and let outsiders follow them from site to site. And on a site that already holds a name or
Kategorie: Hacking & Security

Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks

The Hacker News - 14 Červenec, 2026 - 13:55
Researchers at KU Leuven tested 85 of the most popular crypto wallets that run as browser extensions and found that the wallets themselves leak enough to link and track the people using them. The way these wallets talk to websites and blockchain servers can tie a person's separate addresses together and let outsiders follow them from site to site. And on a site that already holds a name or Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

SAP warns of critical flaws in NetWeaver and Commerce Cloud

Bleeping Computer - 14 Červenec, 2026 - 13:42
SAP has addressed 16 vulnerabilities across multiple products as part of its July 2026 security updates, including three critical flaws in NetWeaver, Commerce Cloud, and AppRouter. [...]
Kategorie: Hacking & Security

How Pentera Turns AI Security Workflows into Validation Engines

The Hacker News - 14 Červenec, 2026 - 13:30
AI security agents are starting to influence real security decisions. They summarize findings, prioritize remediation, recommend next steps, and help teams move faster. But most still rely on fragmented risk signals: scanner output, severity scores, threat intelligence, configuration findings, and exposure data. That fragmentation matters because attackers do not move through environments one
Kategorie: Hacking & Security

How Pentera Turns AI Security Workflows into Validation Engines

The Hacker News - 14 Červenec, 2026 - 13:30
AI security agents are starting to influence real security decisions. They summarize findings, prioritize remediation, recommend next steps, and help teams move faster. But most still rely on fragmented risk signals: scanner output, severity scores, threat intelligence, configuration findings, and exposure data. That fragmentation matters because attackers do not move through environments one [email protected]
Kategorie: Hacking & Security

OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials

The Hacker News - 14 Červenec, 2026 - 13:21
At least two distinct threat actors are weaponizing a novel evasion technique called OAuth client ID spoofing in cloud campaigns, while slipping past telemetry. The activity allows users to enumerate user accounts and validate stolen credentials in Microsoft Entra ID environments, without ever generating a successful sign-in event that would otherwise alert defenders. And bad actors have begun
Kategorie: Hacking & Security

OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials

The Hacker News - 14 Červenec, 2026 - 13:21
At least two distinct threat actors are weaponizing a novel evasion technique called OAuth client ID spoofing in cloud campaigns, while slipping past telemetry. The activity allows users to enumerate user accounts and validate stolen credentials in Microsoft Entra ID environments, without ever generating a successful sign-in event that would otherwise alert defenders. And bad actors have begun Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

With its latest layoffs, Microsoft goes all in on AI

Computerworld.com [Hacking News] - 14 Červenec, 2026 - 13:00

Microsoft’s big lead over AI competitors like Google and others has vanished, and the company is now playing catch-up. As a result, Microsoft’s stock has tanked in the last year — down roughly 23% compared to a year ago, due mainly to its massive AI spending and an inability to monetize Copilot. 

The company clearly needs to do something. And last week it did, though not what you might expect. It laid off 4,800 people, a little more than 2% of its worldwide workforce, with its Xbox division hit hardest. And it’s not reducing its massive spending on AI data centers or other AI-related costs.

The New York Times explained the cuts this way: “It is Microsoft’s latest employee culling as it plows tens of billions of dollars into the infrastructure for building artificial intelligence.”

Was cutting back on gaming (while still going all-in on AI) the right move for Microsoft? To answer that, let’s take a look at the details of the company’s July layoffs.

A year of layoffs

The recent cuts come in the wake of larger Microsoft workforce reductions over the last year or so. In May 2025, the company laid off 6,000 employees, about 3% of its workforce. Then a few months later, it laid off 9,000 more, about 4% of its workers. In both rounds of cuts, the company’s gaming division was hit — though it wasn’t the primary target.

This year, in April and May, the company rolled out its first voluntary retirement program for US employees. Approximately 3,000 people took the money and ran.

Then came last week, when Microsoft primarily targeted gaming. When the cuts take full effect over the next year, 2,850 gaming employees will be let go. In addition, Microsoft is cutting loose several of its gaming studio brands, which will become independent companies or be sold to buyers.

The layoffs hit the two remaining gaming studios, Activision Blizzard, which makes the big-selling games Call of Duty and Candy Crush, and ZeniMax Media, which publishes series including Fallout and The Elder Scrolls. Three years ago, in 2023, Microsoft bought Activision Blizzard for $69 billion. That followed its purchase of ZeniMax Media in 2020 for $7.5 billion. Both seemed like sizable acquisitions at the time. 

Compared to Microsoft’s AI spending now, they’re chump change.

Follow the money

A memo sent to employees about the July layoffs by Amy Coleman, Microsoft executive vice president and chief people officer, made clear the layoffs were more about AI than they were about gaming

Of the cuts, she wrote: “The “why” is this: our business is changing because the world around it is changing. The way technology is built, deployed, and used is transforming faster than at any point in my time here. Our customers’ needs are shifting, the business models that serve them are shifting, and that means the work itself — what we do, where we focus, and how we’re organized — has to transform, too.

“Our customers are navigating this same shift, and they’re counting on us to help them through it.”

That last sentence is an oblique reference to the early July launch of the Microsoft Frontier Company, which will embed 6,000 engineers inside customers’ businesses to help them more effectively deploy AI. The cost: $2.5 billion.

That sounds like a substantial amount of money. But it’s only a drop in the bucket of how much money the company plans to spend on AI. In April, Microsoft told investors it would spend $190 billion on data centers and other AI infrastructure this year, a 60% increase over what it spent last year. At the same time, Microsoft said it would shrink its workforce.

Its latest layoffs are clear-cut evidence of that. It’s also evidence that the company recognizes how badly Xbox has performed, and that it needed to do something about it. 

In early June, Microsoft sent a memo to everyone in its Xbox division entitled “Next 100 Days: XBOX Reset.” The memo laid out the problems with its ailing game business and pulled no punches. It noted that beyond the $69 billion the company spent three years ago to buy Activision, “Over the past five years, we have spent over $20 billion on ongoing investments in our content, platform, and hardware subsidy, but our annual revenue has declined nearly half a billion during that time. Going forward, this cannot continue.” 

The layoffs and spinoffs were the first steps. They won’t be the last.

There’s no doubt this is just the beginning of Microsoft’s disinvestment in gaming. The issue isn’t just that the company’s investments haven’t paid off. It’s that Microsoft’s AI ambitions are so large and expensive that it can no longer afford to seriously fund gaming.

Ultimately, it was the right thing to do, at least from a business perspective. The future is AI. It’s not in gaming.

So, for the foreseeable future at Microsoft, when it comes to AI — the sky’s the limit. But when it comes to gaming, things look much less rosy.

Kategorie: Hacking & Security

Microsoft starts testing cleaner Windows Search without ads

Bleeping Computer - 14 Červenec, 2026 - 12:47
Microsoft is now testing a cleaner and faster version of Windows Search that should prioritize relevant results over ads and promotional content. [...]
Kategorie: Hacking & Security

Forg365 industrializes Microsoft 365 phishing with AI-generated lures

Computerworld.com [Hacking News] - 14 Červenec, 2026 - 11:51

A newly documented phishing-as-a-service platform distributed through Telegram is lowering the technical barrier to Microsoft 365 account takeovers by giving less-skilled attackers automated tools to evade some authentication controls and retain access after compromise.

The platform, called Forg365, uses AI-assisted lure creation alongside device-code abuse and adversary-in-the-middle techniques, according to research published by security company ZeroBEC.

Forg365 was offered with a five-day free trial, followed by subscriptions priced at $400 per month or $3,800 per year, the researchers said.

Customers can build phishing lures and control email delivery through a single operator panel. They can also manage captured account data and monitor compromised Microsoft 365 mailboxes. The service includes templates that impersonate widely used business platforms such as DocuSign, Adobe Acrobat Sign, SharePoint, and OneDrive.

“Phishing-as-a-service has been around for quite a few years,” said Jonathan Ong, senior analyst for managed security services at Omdia. “But the degree to which AI is integrated into Forg365 and enables users is what makes it concerning.”

Forg365’s significance lies in the industrialization and productization of the operator workflow, according to Devashri Datta, a cybersecurity researcher. “It integrates AI-assisted lure creation, evasion, and post-compromise mailbox operations into a subscription service distributed through Telegram,” Datta said.

How Forg365 works

ZeroBEC said the campaign it investigated began with an email built around a business-document and remittance-approval pretext. The message relied on legitimate cloud and email services before sending the recipient through several redirects.

Forg365 classified visitors before deciding whether to display a device-code phishing page, an adversary-in-the-middle flow, or a harmless decoy.

In the device-code attack, the victim is directed to a legitimate Microsoft authentication process and persuaded to enter a code that authorizes a session controlled by the attacker. The involvement of genuine Microsoft infrastructure can make the request appear credible.

The platform can also relay authentication through an adversary-in-the-middle attack and capture session information. ZeroBEC said suspicious visitors were diverted to a benign page, helping the operators conceal the phishing flow from researchers and automated security tools.

Complicating incident response

A browser extension called ForgCookie allows attackers to generate and refresh Microsoft single sign-on cookies from their own browsers, ZeroBEC said.

Forg365 also advertises tools for keeping sessions active and monitoring a compromised inbox. Read-only access to the mailbox can then be shared through a password-protected link.

As a result, resetting a password may not remove the attacker. Stolen refresh-token material or an attacker-controlled session could remain usable after the password is changed. Any devices registered during the compromise must also be investigated.

“CISOs should treat two controls as co-equal priorities rather than sequential ones,” Datta said, referring to tightly restricting device-code authentication and deploying phishing-resistant MFA such as FIDO2 or WebAuthn passkeys.

Organizations that do not require device-code authentication should consider blocking it in Microsoft Entra ID, said Keith Prabhu, founder and CEO of Confidis. This can disrupt the device-code component of a Forg365 campaign, although it would not stop attacks that rely on adversary-in-the-middle techniques or stolen session cookies.

Companies that still depend on device-code authentication should identify legitimate uses before imposing a broader restriction. Exceptions may be needed for some command-line tools, conference-room systems or other devices with limited input capabilities.

Deploying phishing-resistant authentication may also require hardware security keys or managed smartphones and could increase support requests during the transition, Datta said.

After detecting a compromise, response teams should revoke active refresh tokens and terminate existing sessions. Prabhu also recommended reviewing and revoking unauthorized OAuth permissions. Because ForgCookie runs in the attacker’s browser, defenders should look for repeated silent sign-ins and non-interactive Microsoft Graph activity from unfamiliar addresses, according to ZeroBEC.

Mailbox forwarding rules and delegated access should be reviewed for unauthorized changes, Prabhu said. Such changes could allow attackers to monitor communications or retain access after a password reset.

“IR teams should audit newly registered devices and remove any that cannot be attributed to the user,” Datta said. Teams should also check whether an attacker enrolled an unauthorized authenticator application or passkey during the compromise, she added.

ZeroBEC found that some devices registered during its investigation had names beginning with “Forg365,” giving defenders a possible indicator of compromise.

The article originally appeared on CSO.

Kategorie: Hacking & Security

US sanctions VPN, malware providers for enabling ransomware attacks

Bleeping Computer - 14 Červenec, 2026 - 11:40
The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) sanctioned two individuals and one entity for enabling ransomware attacks against U.S. organizations. [...]
Kategorie: Hacking & Security
Syndikovat obsah