Agregátor RSS

Zranitelnost ve WordPress Core: CVE-2026-63030 s přezdívkou wp2shell

AbcLinuxu [zprávičky] - 20 Červenec, 2026 - 19:36
Vládní CERT upozorňuje (𝕏) na zranitelnost ve WordPress Core: CVE-2026-63030 s přezdívkou wp2shell. Zranitelnost typu vzdálené spuštění kódu (RCE) bez nutnosti autentizace umožňuje útočníkovi spouštět libovolný kód prostřednictvím endpointu WordPress REST API Batch. Ke zneužití není vyžadován platný uživatelský účet ani interakce uživatele. Úspěšné zneužití může vést ke kompletnímu kompromitování webové stránky a souvisejících dat. Zranitelnost postihuje verze WordPress 6.9.0 až 6.9.4 a 7.0.0 až 7.0.1.
Kategorie: GNU/Linux & BSD

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

The Hacker News - 20 Červenec, 2026 - 19:29
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer through a fake government ID-lookup site over WebDAV. What makes it more than a
Kategorie: Hacking & Security

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

The Hacker News - 20 Červenec, 2026 - 19:29
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer through a fake government ID-lookup site over WebDAV. What makes it more than a Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Jak dobře vybrat herní notebook. Grafická karta je důležitější než procesor

Živě.cz - 20 Červenec, 2026 - 18:45
Věčný souboj „herní notebook nebo stolní počítač“ měl v uplynulých letech jednoduchou odpověď. • Grafické karty pro počítače buď nebyly, nebo stály absurdní částky, takže ideální volbu představoval herní notebook. • Situace se vrací do normálu, ale herní notebooky nadále mají své místo.
Kategorie: IT News

Evropská komise vyměřila AliExpressu pokutu 550 milionů eur

AbcLinuxu [zprávičky] - 20 Červenec, 2026 - 18:17
Evropská komise (EK) vyměřila čínskému internetovému prodejci AliExpress pokutu 550 milionů eur (13,3 miliardy korun) za porušení povinností vyplývajících z nařízení o digitálních službách (DSA). Platforma podle EK řádně neposuzovala a neomezovala rizika související s prodejem nelegálních, nebezpečných nebo padělaných výrobků na svém internetovém tržišti. Komise zároveň firmě nařídila přijmout nápravná opatření. Podle AliExpressu je pokuta nepřiměřená.
Kategorie: GNU/Linux & BSD

Šílený i na Hitlerovy poměry. Gigantický tank Ratte byl tak těžký, že by drtil silnice a bořil mosty

Živě.cz - 20 Červenec, 2026 - 17:45
Hitler miloval velké a technologicky vyspělé zbraně • . • Mohutné bitevní lodě, nadzvukové rakety a proudová letadla Třetí říše skutečně nasadila. • S gigantickým tankem Landkreuzer P-1000 Ratte se však Adolfova fantazie vydala daleko za hranice možného.
Kategorie: IT News

Gitea 1.27 Delivers 45 Security Fixes for Self-Hosted Git Servers

LinuxSecurity.com - 20 Červenec, 2026 - 17:38
For organizations that run a self-hosted Git platform, it’s no longer just about hosting static code repositories. Today, Git servers are responsible for deployment pipelines, API tokens, SSH keys, package repositories, and the automation scripts that push code directly. Confirm that the upgrade addresses known vulnerabilities but also provides production environments. 
Kategorie: Hacking & Security

Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign

The Register - Anti-Virus - 20 Červenec, 2026 - 16:59
Microsoft 365 calendars have become the latest hiding place for espionage malware, with attackers stashing commands and stolen files inside appointments dated 24 years into the future. Researchers at Group-IB say they've uncovered a malware component they call HOLLOWGRAPH that swaps the usual command-and-control server for something rather less conspicuous – a compromised Microsoft 365 calendar. Instead of reaching out to attacker-controlled infrastructure for instructions, the implant rummages through calendar events, picks up encrypted tasking, and drops stolen files into new appointments for its operators to collect later. Every event created by HOLLOWGRAPH is dated May 13, 2050, an otherwise empty corner of the diary where encrypted attachments are less likely to attract attention. HOLLOWGRAPH isn't exploiting Microsoft Graph so much as blending into it, wrapping its command-and-control traffic inside legitimate Graph API requests that look just like any other Microsoft 365 application talking to the cloud. The malware itself is relatively lean. Group-IB says it does little more than fetch instructions from one calendar event, stash stolen files in another, and periodically retrieve fresh Entra ID credentials over a DNS tunneling channel so the Graph-based communications keep working. The security firm linked the malware to the Cavern framework with high confidence after finding matching command formats and other implementation details. It also spotted similarities with the Iranian-linked espionage group Lyceum, although it stopped well short of pinning the operation on that crew, saying the connection was supported with only low confidence. "HOLLOWGRAPH represents an advanced and highly targeted espionage threat," Group-IB wrote. "By abusing trusted Microsoft 365 calendars through the Microsoft Graph API and refreshing its cloud authentication credentials through DNS tunneling, the malware conceals its command-and-control within legitimate Microsoft 365 and network traffic, evading conventional perimeter defenses." The campaign itself appears to be narrowly targeted. Group-IB identified 12 infected systems, only three of which communicated with the compromised mailbox during the period it observed. The compromised mailbox used for command-and-control belonged to an Israeli organization, malware samples were uploaded from Israel, and the researchers said the evidence points to a focused espionage operation rather than a broad smash-and-grab. HOLLOWGRAPH doesn't exploit a flaw in Microsoft 365 or Microsoft Graph. Instead, it takes advantage of services that are already trusted inside most organizations, making the activity far less conspicuous than malware calling home to attacker-controlled infrastructure. ®
Kategorie: Viry a Červi

Diablo IV s novou sezónou opakuje staré chyby. Ani dobrý nápad hráče dlouhodobě neudrží

Živě.cz - 20 Červenec, 2026 - 16:45
Blizzard vypustil do světa čtrnáctou sezónu Diabla IV, tentokrát pod názvem Season of Death Awakening. Po velmi silné třinácté sezóně, která těžila z expanze Lord of Hatred, měla nová sezóna nelehký úkol - znovu přitáhnout hráče, kteří už začínají být unavení z recyklace mechanik a kosmetických ...
Kategorie: IT News

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

The Hacker News - 20 Červenec, 2026 - 16:33
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050. Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so the activity looks
Kategorie: Hacking & Security

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

The Hacker News - 20 Červenec, 2026 - 16:33
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050. Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so the activity looks Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

An AI SOC Evaluation Guide for Security Leaders

Bleeping Computer - 20 Červenec, 2026 - 16:01
Choosing an AI SOC platform requires understanding how it will perform in your own environment, not just during an evaluation. Prophet Security shares a practical framework for assessing AI SOC solutions, including how to validate accuracy, operating models, long-term reliability, and production readiness. [...]
Kategorie: Hacking & Security

Na Blízkém východě urychlují výstavbu nových ropovodů. Chtějí tak snížit závislost na Hormuzském průlivu

Živě.cz - 20 Červenec, 2026 - 15:45
Válečný konflikt mezi USA a Íránem donutil arabské státy stavět ropovody • Irák obnovuje staré potrubí do Sýrie a staví novou vnitrostátní magistrálu • Nové trasy však před íránskými útoky na pozemní terminály nikoho neochrání
Kategorie: IT News

⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More

The Hacker News - 20 Červenec, 2026 - 15:32
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had time to patch. Here is the full
Kategorie: Hacking & Security

⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More

The Hacker News - 20 Červenec, 2026 - 15:32
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had time to patch. Here is the full Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

How to Apply the Principle of Least Privilege in Modern Linux Environments

LinuxSecurity.com - 20 Červenec, 2026 - 15:24
We all spend a lot of time defending our systems from external threats, but the amount of damage an attacker can cause often depends on what happens after they get in. A single compromised account doesn't always lead to a major incident. The real danger begins when that account has far more access than it actually needs.
Kategorie: Hacking & Security

Apple could ‘run the table’ on AI if it does things right

Computerworld.com [Hacking News] - 20 Červenec, 2026 - 15:20

Looking ahead just a short time, Apple could hold a powerful position in AI where it most makes sense: deployment.

Not only will the company offer up its own AI models for the kind of tasks millions use ChatGPT to do today, but it will provide more sophisticated on-device agentic models to help users get things done through Siri AI.

Apple also offers limited capacity for more complex tasks through Private Cloud Compute, and, in partnership with the likes of Google in the US and Alibaba in China, the company is giving users a trusted conduit through which to access even more sophisticated AI services. 

Deeply deployable

Critics can say it took Apple a long time to get to this point, but they also seem to think the company has finally got the mix right with its series 27 operating systems. Arriving late to a party doesn’t mean you won’t shine once you get there.

Apple is also coming up the inside lane around frontier AI, with iterative OS and hardware enhancements that mean its devices become increasingly effective for Edge AI use cases, on device — no cloud service required.

The company appears to be digging down into those use cases. Mark Gurman at Bloomberg recently predicted that future M7 Ultra Macs will support as much as 1.5TB RAM, making these systems more than capable of running full weight frontier models in people’s offices, colleges, and homes. 

While that does assume the AI-flationary memory market can supply that much RAM at prices humans can afford, it is also true that people are already running AI clusters using off-the-shelf Mac minis networked over Thunderbolt cables. It’s no stretch to believe this will continue to be the case, and that it will even broaden as the power/performance offered at the high end grows.

What’s wrong with good enough?

When combined with open AI stacks, particularly newly emerging varieties, Apple’s platforms should become leading contenders for private AI services and edge AI. Many business users will leap at the chance to offer their workers powerful, self-hosted, private AI services using one or more daisy-chained Mac Studios or Mac minis. The recent craze in deployment of both Macs to support OpenClaw instances shows they already are.

Ultimately, these different slices of momentum mean I agree with investor Jason Calacanis that Apple is in position to apply a great deal of pressure on OpenAI and Claude just by putting models on their devices. 

It’s also worth thinking about how people use AI today. How many of the queries made in the world right now constitute relatively simple tasks that could be transacted by on-device AI, such as the emerging new version of Apple Intelligence or even smaller LLM models running on device? You can even run PrismML’s 1-bit, 27-billion parameter Bonsai on an iPad using the Locally app, and that’s in the here and now.

What happens? Pretty soon you’ll find people recognize that they can already run the vast majority of their AI-augmented workflows using services they have on their existing device or can access on their on-prem Mac set-ups. And, of course, as people get used to running small tasks locally and larger tasks on premises, the actual space in which they need to turn to cloud-based frontier models will erode. That’s even as companies like PrismML work towards slimming down full-weight models so they don’t need to run on a server at all.

“It’s going to be wild when people have unlimited tokens on their desks,” said Calacanis in a podcast round table discussion.

Who has the most to lose?

The current incarnations of AI felt like they came from nowhere. Most people weren’t aware of the technology until returning to work after the 2022 holiday season. Since then, the industry has proliferated with dozens of competing models, most recently including powerful but affordable frontier models such as Qwen and Kimi.ai.

These models aren’t necessarily all as good as one another, but in many cases for much of what we do, we’ll find them to be good enough. That’s an existential crisis for some, as industry observers now think the inevitable pricing pressure means some services might have over-invested in capacity before finding any way to turn a profit.

Those profit-seeking services are the ones with the most to lose as Apple extends its hardware advantage, democratizing AI access for all while providing platforms suitable for edge AI, on-premises AI, private AI, and even AI access using third-party services. (The need for the latter will shrink as the capabilities of the former get better.)

Cupertino rising

What does this all mean? While the industry remains young, it is already fragmenting. And striding through the dust of that process comes Apple, equipped with the hardware, software, and approach to build its business even as the enterprise of first mover AI services erodes.

You can follow me on social media! Join me on BlueSky,  LinkedInMastodon and subscribe to my daily Apple-related news summaries at The Core.

Kategorie: Hacking & Security

Úplná blbost, nebo zlepšení bezpečnosti? Laserový head-up displej pro cyklisty promítá data rovnou na silnici

Živě.cz - 20 Červenec, 2026 - 14:45
Podívat se při jízdě na kole na navigaci v mobilu nebo na cyklopočítači znamená, že přestanete sledovat situaci před sebou. I kdyby to byla jen sekunda, může být klíčová, může vás dostat do rizikové situace. Právě tenhle problém řeší Iris Green. Místo sklonění hlavy k displeji a přeostření očí vám ...
Kategorie: IT News

Ministerstvo couvá s další významnou změnou u důchodů, kterou slibovalo už od příštího roku

Lupa.cz - články - 20 Červenec, 2026 - 14:35
Ministerstvo práce předložilo vládě po připomínkování novelu, která má přinést změny v důchodech. Z původního balíku změn, které měly přijít v „první vlně“, je ale jen balíček.
Kategorie: IT News

Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine

The Hacker News - 20 Červenec, 2026 - 14:13
At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops. That is the finding of a cybersecurity advisory published July 10 by the AIVD and MIVD, the Netherlands' civilian and military intelligence
Kategorie: Hacking & Security
Syndikovat obsah