Agregátor RSS

N-able warns of N-central auth bypass flaw exploited in attacks

Bleeping Computer - 3 Srpen, 2026 - 19:00
N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers. [...]
Kategorie: Hacking & Security

12 bezplatných editorů videa. Stáhnout si můžete jednoduchou střižnu i software, který používá Hollywood

Živě.cz - 3 Srpen, 2026 - 18:45
Potřebujete sestříhat video z dovolené či vytvořit klip? • Vybrali jsme dvanáct nejlepších bezplatných editorů videa • Nabídka čítá jednoduché, ale i komplexní programy
Kategorie: IT News

12 bezplatných editorů videa. Stáhnout si můžete jednoduchou střižnu i software, který používá Hollywood

Živě.cz - 3 Srpen, 2026 - 18:45
Potřebujete sestříhat video z dovolené či vytvořit klip? • Vybrali jsme dvanáct nejlepších bezplatných editorů videa • Nabídka čítá jednoduché, ale i komplexní programy
Kategorie: IT News

Anthropic’s AI models accidentally hacked three companies

Computerworld.com [Hacking News] - 3 Srpen, 2026 - 18:38

Anthropic has launched an investigation into what went wrong during a recent test of three models that left a trio of companies accidentally hacked.

The company was testing how well Claude Opus 4.7, Claude Mythos 5, and an internal test model could find hidden information about fictional companies in simulated networks. But because of a misunderstanding by one of Anthropic’s partners, the AI models gained access to the internet — and managed to find real companies with the same or similar names as the fictional ones.

As a result, three companies were actually hacked. Anthropic said it halted the tests on July 23, and the affected companies were notified four days later. So far, the company has received responses from two of the three companies, according to Reuters.

Anthropic is not alone when it comes to renegade models. An OpenAI agent recently went rogue and breached AI platform Hugging Bear and a customer of the cloud platform Modal Labs.

Kategorie: Hacking & Security

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

The Hacker News - 3 Srpen, 2026 - 18:24
Malware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim's screen. Unit 42 detailed three attack paths against Chrome's Google Password Manager cloud authenticator, which it calls Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key; the strongest targets the master key
Kategorie: Hacking & Security

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

The Hacker News - 3 Srpen, 2026 - 18:24
Malware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim's screen. Unit 42 detailed three attack paths against Chrome's Google Password Manager cloud authenticator, which it calls Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key; the strongest targets the master keySwati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

The Hacker News - 3 Srpen, 2026 - 18:15
The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. In a report published over the weekend, Resecurity said it observed the INC Ransomware accelerating its activity since the beginning of August 2026, listing multiple victims on its data leak site. Per
Kategorie: Hacking & Security

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

The Hacker News - 3 Srpen, 2026 - 18:15
The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. In a report published over the weekend, Resecurity said it observed the INC Ransomware accelerating its activity since the beginning of August 2026, listing multiple victims on its data leak site. Per Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Russian spies turn public Wi-Fi into malware delivery systems

The Register - Anti-Virus - 3 Srpen, 2026 - 17:39
Conference-goers may want to think twice about connecting to public Wi-Fi after Microsoft disclosed that Russian foreign intelligence operatives (SVR) are compromising captive portal networks to deliver infostealers, keyloggers, and other malware. With the help of ReliaQuest's earlier work, Redmond fingered Storm-2945, a subdivision of the SVR's Midnight Blizzard (aka Nobellium), in an attack campaign targeting users of public Wi-Fi networks at places like hotels, conference centers, and other shared venues in the hospitality sector. Microsoft is still trying to determine how the hackers initially compromise captive-portal networks. The broader AI-assisted operation dates to February 2026, with traffic manipulation observed since early May. After gaining control of the network layer, Storm-2945 manipulates DNS and HTTP traffic to reroute users through attacker-controlled infrastructure, Microsoft said. The crew also abuses operating systems' connectivity checks to trigger malicious prompts and redirects. This gives the attackers an adversary-in-the-middle (AitM) position. Such prompts adopt ClickFix-style methods, which in some cases try to convince public Wi-Fi users to install malware under the guise of OS updates, driver repairs, and web verification failures. Users who follow through on the instructions provided in the prompts may then find their device infected with malware. Microsoft calls the campaign "CaptiveCrunch." One of the malware strains it delivers is CornFlake. Described as "a full-featured Windows RAT" written in Go, CornFlake is the SVR's go-to persistent implant in these hospitality network attacks. After presenting users with a "convincing" fake Windows update progress window, it provides attackers with a wealth of capabilities once installed. These include: Keylogging Clipboard monitoring Screenshot capture Audio surveillance Video surveillance Browser credential theft File exfiltration USB drive monitoring Security posture sweep Remote shell Microsoft also said that CornFlake exposes a localhost HTTP API server to transform the malware into a modular platform, delivering additional payloads such as ChocoShell, a PowerShell-based infostealer. ChocoShell is delivered and executed entirely in-memory, Microsoft said. SVR uses it primarily to suck up victims' browser session cookies, saved passwords, SSO tokens, and Wi-Fi credentials. Microsoft neatly summarized the two: "Where CornFlake provides the operator with a persistent, long-running foothold on the device, ChocoShell is designed to extract the most operationally valuable credentials, giving the operator access to victim cloud environments." The attacks primarily target Windows machines, but Microsoft has also seen indications of ClickFix prompts tailored to Android devices, encouraging users to download and install an APK file. In addition to the malware element, "a portion" of SVR's CaptiveCrunch activity is devoted to device code phishing. Users sent to attacker-controlled landing pages may be instructed to enter a device code on a legitimate Microsoft authentication page, unwittingly authorizing the attacker's session. Device code phishing exploits a legitimate OAuth flow, typically reserved for devices that struggle to open browsers, such as smart TVs. In such scenarios, attackers request an authentication code from Microsoft, which they then send to phishing targets. In the CaptiveCrunch campaign, this looks like a fake landing page, served to the user thanks to the AitM component of the attack. Targets are then asked to copy the code, which was originally given to the attacker, open a legitimate Microsoft authentication window, enter the code, and choose which account they wish to authenticate. Choosing the account completes the authentication flow, but in turn authenticates the attacker into the chosen account. This gives the attacker a valid OAuth token for the victim's Microsoft 365 account, potentially granting access to cloud data permitted by the token until it expires or is revoked. Device code phishing is not a new or unique attack, but can be an effective route to bypassing MFA, especially when an attacker already controls the flow of traffic after a captive portal compromise. "This activity is consistent with previously reported device code phishing operations conducted by Midnight Blizzard since August 2024," Microsoft said. "The observed technique does not appear fundamentally novel; however, integrating device code phishing into captive portal and traffic manipulation operations might increase the likelihood that users perceive the authentication request as legitimate." The main takeaway, in Microsoft's book, is to stop trusting public Wi-Fi so much. It did not discourage using hospitality networks' Wi-Fi services altogether, but said favoring personal hotspots and satellite internet connections over public networks is a safer bet. The majority of Redmond's advice could be brought under the user education umbrella: Don't trust public networks; teach users not to download updates over public networks or via prompts; educate users about what ClickFix attacks look like. That sort of stuff. But organizations have a role to play too. Among other technical implementations, passwordless authentication can thwart many phishing techniques, although device code phishing may bypass even passkeys. The best response would be for an employer to disable the device code authentication flow altogether, wherever possible, preventing staffers from surrendering their workplace cloud access to attackers. ®
Kategorie: Viry a Červi

T-Mobile nikdo k blokaci ‚dezinfowebu‘ AC24 nenutil, píše soud

AbcLinuxu [zprávičky] - 3 Srpen, 2026 - 17:26
Firma T-Mobile blokovala „dezinformační web“ AC24 bez toho, aniž by k tomu měla závazný pokyn orgánů veřejné moci. Píše to ve svém rozsudku Městský soud v Praze, který po čtyřech letech uzavřel kauzu blokace zmíněného webu. Operátor musí uhradit škodu ve výši 35 tisíc korun. Advokát společnosti T-Mobile se snažil i u odvolacího senátu argumentovat tím, že firma jednala v dobré víře, když na stránky omezila přístup poté, co ji k tomu vyzvalo Národní centrum kybernetických operací (NCKO), které spadá pod Vojenské zpravodajství. Stejně tak se odvolával na to, že blokaci schválili také představitelé vlády svým usnesením. Tento argument ale neuspěl. Podle soudu totiž muselo být operátorovi jasné, že ho ani usnesení, ani dopis zpravodajců – kterými byl k blokaci takzvaných dezinformačních webů na začátku ruského vpádu na Ukrajinu v roce 2022 vyzván – k podobnému kroku nezavazuje.
Kategorie: GNU/Linux & BSD

Rumunská armáda musela odstřelit kus Dunaje. Jejich jediná jaderná elektrárna je na suchu

Živě.cz - 3 Srpen, 2026 - 17:15
Extrémně nízká hladina Dunaje připomíná poněkud nedomyšlenou zranitelnost jaderných elektráren, které jinak řadíme mezi ty nejspolehlivější a nejstabilnější zdroje elektřiny. Nedostatek vody nyní vážně ohrozil jedinou rumunskou jadernou elektrárnu Cernavodă, jejíž dva reaktory pokrývají zhruba ...
Kategorie: IT News

ExfilSquad hackers leak info of over 100,000 UK police officers, staff

Bleeping Computer - 3 Srpen, 2026 - 17:04
A cyberattack on the U.K.'s Police National Legal Database (PNLD) has compromised contact data of more than 100,000 police officers and other criminal justice professionals. [...]
Kategorie: Hacking & Security

Inside the Underground Business of the Android BTMOB RAT malware

Bleeping Computer - 3 Srpen, 2026 - 16:45
Flare researchers analyzed thousands of underground posts to examine how the BTMOB Android malware operation evolved into a fragmented ecosystem of resellers, source-code vendors, custom versions, and competing sales channels. [...]
Kategorie: Hacking & Security

Windows 11 zaberou méně paměti. Na počítače se 4 GB ale Microsoft zapomněl

Živě.cz - 3 Srpen, 2026 - 16:45
Microsoft v hrubých obrysech nastínil další chystaná vylepšení Windows 11. • Ve druhém pololetí se zaměří i na optimalizaci, cílí ale na 8 GB operační paměti. • Jenže Windows 11 mohou oficiálně běžet i se na konfiguracích se 4 GB paměti.
Kategorie: IT News

Responding to a Web Server Compromise

LinuxSecurity.com - 3 Srpen, 2026 - 16:36
Your website isn’t acting normally. Users report errors. Monitoring detects unexpected outbound connections. You discover a recently modified PHP file in your web root. Nobody can explain why. What do you do first?
Kategorie: Hacking & Security

Padla obžaloba v bitcoinové kauze

AbcLinuxu [zprávičky] - 3 Srpen, 2026 - 16:35
Padla obžaloba v bitcoinové kauze. Státní zástupkyně chce pro Blažka 6,5 roku vězení, pro Titze 8 let.
Kategorie: GNU/Linux & BSD

What Is Fuzzing? Inside the Search for Hidden Linux Kernel Bugs

LinuxSecurity.com - 3 Srpen, 2026 - 16:06
If you spend time reading Linux kernel bug reports or security patches, that line is everywhere. It sits quietly at the bottom of code fixes across the entire operating system, from network drivers to file systems.
Kategorie: Hacking & Security

⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks

The Hacker News - 3 Srpen, 2026 - 16:03
This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended. Some of it was clever. Most of it was just access left lying around: old bugs, exposed gear, poisoned dependencies, weak defaults, and tooling that moved from
Kategorie: Hacking & Security

⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks

The Hacker News - 3 Srpen, 2026 - 16:03
This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended. Some of it was clever. Most of it was just access left lying around: old bugs, exposed gear, poisoned dependencies, weak defaults, and tooling that moved from Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Ohnivý mrak nad Francií přináší novou hrozbu. Může proměnit lesní požáry v ještě větší pohromu

Živě.cz - 3 Srpen, 2026 - 15:45
Extrémní lesní požáry v jihozápadní Francii vytvořily nebezpečný ohnivý mrak • Pyrokumulonimbus generuje vlastní blesky a silné nárazy větru daleko od ohniska • Mrak unáší saze do stratosféry a komplikuje veškeré záchranné práce
Kategorie: IT News
Syndikovat obsah