Agregátor RSS

Kubernetes Storage Flaws Expose a Dangerous Security Blind Spot

LinuxSecurity.com - 24 Červenec, 2026 - 15:17
Two newly fixed storage bugs in Kubernetes showed more than just a problem with path traversal. They found a common security flaw in the cloud: powerful parts often think that requests accepted by a higher system are safe to run. This is a simple lesson for the platform and security teams: RBAC can accept a request without showing that its parameters will stay within a certain filesystem boundary. This is clear from a new study from SentinelLabs into flaws in the Kubernetes CSI drivers for NF...
Kategorie: Hacking & Security

Europol flags 4,340 URLs for removal in 'The Com' crackdown

Bleeping Computer - 24 Červenec, 2026 - 14:56
Europol has flagged 4,340 URLs for removal during a multi-week operation targeting online content linked to "The Com," a loosely organized network of nihilistic violent extremist groups. [...]
Kategorie: Hacking & Security

Místo deseti tisíc osmnáct stovek. Skvělý grafický balík CorelDRAW je ve slevě, kterou je těžké ignorovat

Živě.cz - 24 Červenec, 2026 - 14:45
CorelDRAW Graphics Suite 2025 je kompletní komplexní balík profesionálních aplikací pro grafický design – vektorovou ilustraci, úpravu fotografií, typografii a sazbu. Tato licence normálně stojí více než 10 tisíc, teď se objevila na populárním Humble Bundle a můžete za ni zaplatit, „kolik chcete“. ...
Kategorie: IT News

Komunikační platforma Buzz

AbcLinuxu [zprávičky] - 24 Červenec, 2026 - 14:25
Jack Dorsey představil (𝕏) open source týmovou komunikační platformu Buzz (GitHub) s cílem snížit závislost na Slacku a GitHubu.
Kategorie: GNU/Linux & BSD

Uncle Sam tells overseas cybercrooks their visas are canceled

The Register - Anti-Virus - 24 Červenec, 2026 - 14:15
Marco Rubio says the US will deny visas to foreign nationals involved in cybercrime and may extend the restrictions to their immediate families. The US secretary of state announced the restrictions on Thursday, citing a rise in overseas investment scams "often orchestrated by Chinese transnational criminal organizations." Rubio said that in 2024, scammers defrauded US citizens of more than $10 billion, and additionally preyed on children through sextortion schemes that can "devastate families and futures." "The Trump Administration is deploying every tool at our disposal – sanctions, prosecutions, asset seizures, extradition requests, and international law enforcement cooperation – to dismantle criminal scam networks and impose costs on those who enable them," he said. "By restricting visa issuance to those who are responsible for or complicit in these criminal enterprises, we are sending a clear message: The United States will go after those who prey on our citizens." The policy uses authority provided by Section 212(a)(3)(C) of the Immigration and Nationality Act (INA) and will apply primarily to those "responsible for, or complicit in, cybercrime and cyber-enabled crime." It may also extend to immediate family members, Rubio said. Section 212(a)(3)(C) of the INA already imposes restrictions on individuals seeking visas when their entry or proposed activity could lead to "serious adverse foreign policy consequences" for the US. Rubio is no stranger to invoking the same provision as the basis for new visa restrictions. In May 2025, for example, the secretary of state announced restrictions for foreign officials who take steps to restrict US citizens' freedom of expression, be that through threats of arrest for social media posts, or demands for US platforms to adopt content moderation policies. Earlier, in March 2025, Rubio announced a policy targeting private sector workers who facilitated illegal immigration. In September, he invoked the provision again to impose restrictions on Central Americans accused of helping the Chinese Communist Party undermine the rule of law in the region. The Biden administration used the same authority in 2021 to establish what became known as the Khashoggi Ban, a visa restriction policy targeting people acting on behalf of foreign governments to suppress or harm dissidents. It followed the Saudi government's murder of journalist and regime critic Jamal Khashoggi. The US already has other ways to deny entry to convicted cybercriminals. Section 212(a)(2) of the INA, for example, can make foreign nationals ineligible for visas over convictions for crimes involving moral turpitude, a category that can include offenses such as fraud. ®
Kategorie: Viry a Červi

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

The Hacker News - 24 Červenec, 2026 - 13:53
Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a victim's organization. The vulnerability has been codenamed AgentForger by Zenity Labs. The issue has since been addressed by OpenAI as of June 8,Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

The Hacker News - 24 Červenec, 2026 - 13:45
A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same fleet. XBOW's testing got the same result on workers across different hosts and network ranges, so the problem sat in Bing's image tier, not on one bad machine. Microsoft issued two critical CVEs, CVE-2026-32194 and Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do

The Hacker News - 24 Červenec, 2026 - 13:30
AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we've collectively discovered is that enforcing least privilege for AI agents is harder than we ever imagined. This is why there are so many approaches, from prompt filtering to identity-layer access controls. Where we've collectively landed is that understanding the intent [email protected]
Kategorie: Hacking & Security

Man gets six years for hacking 750 women's Snapchat accounts

Bleeping Computer - 24 Červenec, 2026 - 13:17
An Illinois man was sentenced on Tuesday to 76 months in prison and three years of supervised release for hacking the Snapchat accounts of over 750 women to steal nude photos. [...]
Kategorie: Hacking & Security

Google’s anti-search-scraping lawsuit dismissed

Computerworld.com [Hacking News] - 24 Červenec, 2026 - 12:59

A court has dismissed Google’s case against SerpApi over that company’s scraping of search results to train AI models.

The US District Court for the Northern District of California found that there was no indication that any copyright had been breached.

Google announced in December that it was suing SerpApI for its alleged web scraping, claiming that it was protecting copyright holders. In February, SerpApI fought back and asked the court to dismiss Google’s case. And this week, Judge Yvonne Gonzalez Rogers agreed with SerpApi that Google’s case has no merit.

Google’s argument was that SerpApi’s actions breached the US Digital Millennium Copyright Act (DCMA). It made two claims: first, that no person shall circumvent a technological measure that effectively controls access to a work protected under this title, and second that no person shall manufacture, import, offer to the public, provide, or otherwise traffic in any technology, product, service, device, or component protected by the Act.

SerpApi claimed that the URLs and other links that were being served by Google did not in themselves entail copyright and the judge agreed. In her judgment, she said that there was no indication that the copyright holders had authorized Google to take action against SerpApi.

The case is not completely over as the judge has given Google 21 days to amend its complaint to demonstrate that it was acting on behalf of the copyright owners. It remains to be seen whether its war against the web scrapers is finally over.

Kategorie: Hacking & Security

Microsoft explains why its West US Azure and cloud services failed

Computerworld.com [Hacking News] - 24 Červenec, 2026 - 12:55

Microsoft cloud and Azure services hosted on the West Coast of the US went down for hours on Thursday when network connectivity failed. Although services running entirely within Microsoft’s West US cloud region were unaffected, any traffic entering or leaving the facilities was affected.

Microsoft has now published a Preliminary Post Incident Review (PIR) of the incident, reporting that connectivity was lost for five hours between 14.44 UTC (7.44 a.m. Pacific Time) and 19.41 UTC on July 23. The problem was caused when a set of IP routes was removed in error while isolating a device for routine maintenance.

Before starting the maintenance work, Microsoft checked that at least one of the two redundant paths to the facility remained operational. When it came to starting the work, however, automated systems included some additional devices in the perimeter to be isolated, and removing some IP routes that had not been included in the initial assessment.

Customers discovered the problems very quickly, and engineers identified the issue within the first hour and started to reconnect services.  Microsoft said the disruption had been caused by some “recent fiber maintenance activity”.

To minimize the risk of disruption from such errors in the future, Microsoft advised organizations handling mission-critical data to consider a multi-region approach.

The Azure outage was the second significant one to hit Microsoft this year. In February, there was a 10-hour disruption to US West and US East regions.

This article first appeared on Network World.

Kategorie: Hacking & Security

Srovnávací test velkých bluetooth reproduktorů. Ten nejlepší vyhrál stylem, funkcemi i cenou

Živě.cz - 24 Červenec, 2026 - 12:45
Bezdrátové reproduktory ušly od svého uvedení dlouhou cestu vývoje a v posledních letech se tak setkáváme spíše s minimálními změnami, co se funkčnosti týká. Ve výdrži, výkonu a přenositelnosti je ale posun znatelný.
Kategorie: IT News

Email threats changed after the Tycoon2FA take-down

Computerworld.com [Hacking News] - 24 Červenec, 2026 - 12:29

Traditional phishing techniques are in decline as a result of the disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform, Microsoft said in a new report, “Email threat landscape: Q2 2026 trends and insights”.

“Phishing volume linked to the platform fell 92% from pre-disruption averages, including QR code phishing and CAPTCHA-gated phishing both declining from their March highs,” the company wrote in the report.

The takedown reduced activity across multiple phishing categories, forcing attackers to shift to newer delivery methods.

Riding this shift in were a few notable phishing campaigns, including an automated business email compromise (BEC) campaign that reached 42,000 organizations in under three hours, and a multi-stage phishing campaign that used nested email (EML) files, calendar invitations, and a Microsoft authentication redirect to deliver malware.

To counter phishing attacks, Microsoft recommends blocking emails containing known bad URLs/ subject fields, enabling password-less authentication methods, or moving to MFA for accounts that still require passwords.

Tycoon2FA disruption sent attackers exploring

The take-down of Tycoon2FA forced its operators to abandon portions of their infrastructure and rework hosting, domain registrations, and delivery mechanisms.

“After falling 15% in March and another 22% in April, Tycoon2FA-linked phishing volume dropped 74% in May to just 1.5 million messages, then fell another 20% in June to 1.2 million, by far the lowest monthly volumes observed in at least a year,” Microsoft said.

The decline extended to QR Code lures and fake CAPTCHA pages, two phishing techniques in which Tycoon2FA accounted for 12% and 14% of industry activity in June, respectively. This indicated that the platform’s customer base had not been able to migrate to a replacement infrastructure.

But cutting off one head of the hacker hydra only gave rise to new tactics elsewhere.

The adaptation came in the form of using Microsoft Teams as a social engineering channel. Attackers established conversations to build trust before attempting credential theft or delivering malicious payloads. “Teams-based phishing volume climbed steadily throughout Q2, with the average number of detected attacks rising 19% from March to April, holding roughly flat into May (+1%), then increasing another 10% into June,” Microsoft said.

Microsoft also observed a highly automated BEC campaign that reached over 67,000 users using scripted emails, Amazon Simple Email Service (SES), and engagement tracking, alongside a separate phishing campaign targeting 107,000 users that abused Microsoft’s authentication flow and trusted cloud services, including Teams archive recording and ICS calendar invite, to disguise malware delivery behind legitimate infrastructure.

Phishing changes but the defense doesn’t

While QR Code and Captcha-based phishing attacks dropped significantly in the second quarter, business email compromise (BEC) charted jumped 121% between March and April, before dropping down again in May.

QR Code phishing represented 8.3 million attacks in June 2026, down from a peak of 18.7 million in March. Similarly, Captcha-gated phishing fell from 12 million attacks in March to 2.2 million in June.

BEC attacks hit 9 million in March, falling to 3.9 million in June.

But even as these phishing classics lost momentum and newer techniques emerged, Microsoft’s defensive advice remained rooted in the basics. It noted organizations should complement email filtering with phishing-resistant authentication such as passkeys and phishing-resistant MFA to reduce the effectiveness of credential theft campaigns.

The company also recommended strengthening Exchange Online Protection and Microsoft Defender for Office 365 with capabilities such as Safe links and Zero-hour Auto Purge (ZAP), in which malicious emails already delivered to mailboxes are removed before they are read, alongside enforcing password-less authentication methods like Windows Hello, FIDO keys, and Microsoft Authenticator.

Microsoft concluded its report with a list of indicators of compromise (IoCs) from the threats observed in the quarter to support detection efforts.

This article first appeared on CSO.

Kategorie: Hacking & Security

Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry

The Hacker News - 24 Červenec, 2026 - 12:15
Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand's Ministry of Finance, which runs the country's treasury and tax collection. The agent then worked through the ministry's network on its own, checking hosts for ways to gain root access, hunting through file systems, and Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

The Hacker News - 24 Červenec, 2026 - 12:09
The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings. The malware families in question are: TinyEgg, ChonkyChicken, a modularized variant of ChonkyChicken, and a modified web browser credentialRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Windy nasadilo AI předpověď počasí. Láká na ni plešatý číšník a chová se jako další numerický model v nabídce

Živě.cz - 24 Červenec, 2026 - 11:50
Windy před dvěma lety koupilo švýcarský startup Meteoblue a záhy na to do své mapy promítlo jeden z jeho produktů – vlastní numerický model rozpálených center měst s vysokým rozlišením. Meteoblue toho ale umělo více a Windy jeho know-how později nasadilo i do předpovědi počasí a nyní se chlubí, že ...
Kategorie: IT News

Google fined $1 billion for anticompetitive search and mobile app practices in EU

Computerworld.com [Hacking News] - 24 Červenec, 2026 - 11:40

The European Commission has fined Google a total of €890 million ($1 billion) for its breaches of the Digital Market Act (DMA).

Just over half the fine — €460 million — was because Google illegally gave preference to its own services in Google Search results.

The remainder was because in the Google Play store for Android apps, the company prevented app developers from leading consumers to alternative, often cheaper, purchase channels. Under the DMA, app developers who distribute their apps via Google Play or Apple’s App Store should be able to inform customers of alternative offers.

Now Google must give third-party services featuring in its results the same treatment as its own services, and allow developers of apps in the Play Store to communicate about offers both in and outside the Play Store, or face further fines.

The Commission first raised these issues with Google in March 2025. In April of this year, the Commission laid out plans as to how Google should allow other third-parties to share its searches, suggestions that the tech firm firmly resisted. Earlier this month, the Commission also said  Android should be open to other AI agents and not limited to Google’s own Gemini.

Google is not the only US company to have fallen foul of the DMA. In April 2025, Apple was fined €500 million for breaching the Act and, last month, the Commission fired the first shots at cloud hyperscalers Microsoft and Amazon.

Kategorie: Hacking & Security

LG se rozhodlo, že bude majitele svých monitorů bombardovat reklamou na McAfee. Windows mu podržely dveře

Živě.cz - 24 Červenec, 2026 - 10:45
Na počítače s Windows a monitory od LG se začala instalovat obslužná aplikace. • Reálně sloužila hlavně k opakovanému zobrazování reklamy na McAfee. • Šéf vývoje Windows potvrdil, že LG od zobrazování reklamy po domluvě upustilo.
Kategorie: IT News

Finanční šéf TSMC: Továrna v USA nás stojí 4-5× víc než továrna na Tchaj-wanu

CD-R server - 24 Červenec, 2026 - 10:00
Wendell Huang z TSMC v rozhovoru CNBC potvrdil rostoucí poptávku ze strany amerických zákazníků. Na druhou stranu se netajil tím, že americké továrny stojí mnohonásobně víc než výstavba na Tchaj-wanu…
Kategorie: IT News
Syndikovat obsah