Agregátor RSS

Zaujal vás Rod draka nebo Hra o trůny? Potom se vám budou líbit i tyto seriály

Živě.cz - 13 Srpen, 2026 - 17:45
Hra o trůny (Game of Thrones) patří k nejslavnějším seriálům HBO. V osmi sezónách nabídla boj mocných rodů o vládu nad Západozemím, politické intriky, války, zrady i fantasy. V roce 2022 na ni navázal Rod draka a svět George R. R. Martina se od té doby dále rozrůstá. Pokud vás podobné výpravné ...
Kategorie: IT News

Trezor discloses data breach affecting nearly 14,000 customers

Bleeping Computer - 13 Srpen, 2026 - 17:13
Hardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping and logistics provider, was hacked [...]
Kategorie: Hacking & Security

Trump wants to grant private cyber firms a license to hack back

The Register - Anti-Virus - 13 Srpen, 2026 - 17:04
Donald Trump is allowing government agencies to contract private cybersecurity companies to carry out operations against cyber-enabled transnational criminal organizations (CE-TCOs). The US President signed a memo on Wednesday confirming a strategy hinted at earlier this year, saying participating companies can support national operations against criminals, including cyber surveillance and technical disruptions of their networks. The latter, described as "Cyber Effects Operations," covers activities that cause "the manipulation, disruption, denial, degradation, or destruction of information systems, networks, physical or virtual infrastructure controlled by information systems, or information resident thereon." Although the memo establishes a distinction between cyber effects operations and cyber surveillance missions, it acknowledged that the latter will also inevitably involve some disruption or manipulation of systems in order to carry out the surveillance. Surveillance operations are designed for intel gathering, either to support further snooping or for later use in cyber effects operations, with the intent of remaining undetected. Trump described CE-TCOs as "any foreign group that conducts cyber-enabled crime against the United States Government, a United States person, or United States interests." Crucially, the definition excludes entities directly associated with, or operating wholly on behalf of, foreign governments. No stepping on TAO's toes, of course. Participating companies will undergo "rigorous vetting" and will be subject to "strict operational procedures," the memo adds. The operational procedures are to be drawn up within 60 days and codified by program executive directors working with the Homeland Security Council. Companies wishing to be called up for service will have to demonstrate that they have the technical capabilities to carry out the required operations, and be willing to prove this each year via annual evaluations. Program managers must ensure that the operational procedures open opportunities for highly resourced, large organizations, as well as "smaller, more agile companies" that may prove useful for "specialized or discrete tasks." The Justice Department will also play a role in authorizing operations, particularly those targeting US residents or raising domestic legal issues. Participating companies will also be prohibited from executing operations that could lead to "critical outcomes," which is shorthand for attacks that result in the loss of life or serious injury, or those that could be seen as an armed attack under international law. These companies will also be required to maintain a bond or escrow of at least $1 million, which shall be forfeited if they violate the terms of their contracts. Unleashing Trump's cyber army The White House published "President Trump's Cyber Strategy for America" document in March, which promised to "unleash the private sector by creating incentives to identify and disrupt adversary networks and scale our national capabilities." The document [PDF] also stated: "We will leverage the immense talents and ingenuity of our private sector research base. "We will establish a new level of relationship between the public and private sectors to defend America in peace and war." The announcement prompted legal eagles and think tanks to ponder the implications of such a move. Many wondered how the promise to mobilize the private sector would be put into practice. They did not then have the details contained in this week's memo, and some assumed participating companies would support operations against nation-states. This particular program, however, excludes entities acting directly on behalf of foreign governments. Writing for the Royal United Services Institute (RUSI) and citing reporting available at the time, cyber and tech research fellow Gareth Mott said that the US Computer Fraud and Abuse Act (CFAA) might need to be amended before American companies could legally offer such services. Experts from law firm Skadden, Arps, Slate, Meagher & Flom agreed, despite the US Cyber Strategy not mentioning any plans for legislative changes. They wrote: "Any attempt to more directly involve the private sector in offensive cyber actions will likely require further legal and regulatory changes before it can be meaningfully implemented. "Even if the administration were to issue new enforcement guidance redirecting prosecutions away from hack-back cases, the availability of civil penalties under the CFAA and its five-year statute of limitations would likely render such executive actions significantly less impactful. "Technology companies should consider closely monitoring developments to track how the administration plans to enact such incentives." However, Jenner & Block lawyers noted in an analysis published by Lawfare that a provision of the CFAA could limit participating companies' exposure. Title 18 of the US Code, § 1030(f), says the CFAA does not prohibit lawfully authorized investigative, protective, or intelligence activity by a US government agency or intelligence agency. Participating companies might therefore be protected when acting under government contracts and direction. However, no court has determined whether that exemption covers private companies carrying out such work. "No court has addressed whether this exception provides any protection for private-sector entities engaged to perform these activities on behalf of the US government and, if so, under what circumstances," the lawyers wrote. "At the very least, it is unlikely that a court would interpret this provision to extend to private companies engaged in independent offensive operations, without government direction or involvement." The last part is key: because the US government will draw up procedures and direct the companies' involvement, the work may fall within the CFAA exemption. Whichever way the US constructs its private sector play, it represents a significant shift in the country's cybersecurity policy, and perhaps that of other nations further down the line. As Mott points out, US allies will certainly be keeping tabs on the private sector program's success, and its take-up from the companies it looks to attract. ®
Kategorie: Viry a Červi

New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure

The Hacker News - 13 Srpen, 2026 - 17:00
Afghan telecom providers and South Asian critical infrastructure organizations have emerged as the target of a new ongoing campaign that delivers a previously undocumented backdoor called PATCHCORD. According to Acronis Threat Research Unit (TRU), the backdoor is a compiled C/C++ implant delivered by means of sector-specific lures, including fake VPN installers impersonating Afghan Telecom (Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

The backup Microsoft never promised you

The Register - Anti-Virus - 13 Srpen, 2026 - 17:00
Confidence in an organization's cyber recovery capabilities deserves scrutiny. If a ransomware attack disables the SaaS data tenanted in the Microsoft cloud ecosystem, the data the business depends on as its lifeblood, the pace at which operations resume rests on assumptions that often prove wrong. Anyone whose answer is "It's all good. Microsoft has my back on this one with its comprehensive native retention and recovery capabilities" is due a reality check. With agile business tools like M365 and Entra ID and solid backend infrastructure in the form of Azure, Microsoft brings a lot to the SaaS party. Both IT departments and MSPs need to be aware, however, that Redmond operates on the same shared responsibility model as other major SaaS providers. In the event of a cyberattack, the recovery burden splits between what the cloud provider handles and what falls to the subscriber alone. MSPs face the additional pressure of meeting stringent SLAs, working with clients’ preferred providers or tooling, and managing their own staffing and profitability accordingly. Microsoft ensures that its services keep running in the aftermath of a strike but does not promise to restore data to a specific known good point before the disaster. That gap always sat with the customer, and planning for it before problems hit beats improvising while picking up the pieces. "There's a common misconception about what Microsoft is responsible for, as distinct from the service they're providing," explains Brent Torre, GM of cyber resilience . Microsoft's native tools, he points out, address problems like short-term accidental deletion and aspects of data governance. They are not a backup solution and will not protect against ransomware or recover data. "Microsoft is clear that whether it's a SaaS application like Microsoft 365, a platform application like SQL Server, or even VMs running in Azure, the customer is always responsible for the information that's in that service, as well as devices, accounts and identities," he adds. "If you get compromised and the attacker starts deleting data, Microsoft has no responsibility for that." A world of pain The gap between availability and true cyber recovery is misunderstood, and it has widened into something of a chasm in recent years. There are three contributing factors to this gap. The first is the evolution of cyberattacks. Typical cyberattacks have pivoted from muscling past a defensive barrier to targeting human weakness, because strolling in through the front entrance with a stolen pass is easier than shimmying through a forced window. Identity has become the primary attack surface. Credential compromise, or identity-based initial access, removes the need to find a vulnerability to exploit and requires only an unwary employee. AI is now a staple weapon in the criminal arsenal, augmenting exploitation techniques such as phishing, social engineering, deceptive emails and spoofed websites, all convincingly used to trick users into typing passwords into a portal controlled by the aggressor. The technique can get more scientific than that. Automated AI-powered bots test millions of leaked username and password pairs across hundreds of different websites, exploiting the common habit of password reuse. Microsoft Entra ID, the vendor's cloud-based identity and access management service and the very tool designed to keep criminals out, is now a prime vector for attack and no match for stolen identity. Once an attacker compromises Entra ID with pilfered credentials, without setting off alarms, they have a free run at gathering data from mailboxes, OneDrive, SharePoint, Teams and other soft targets. The ransomware attack itself can then be launched with ease and at leisure. Another contributory factor is that the vogue for moving workloads to infrastructure and platform as a service (IaaS and PaaS) models shows no sign of abating. Organizations tend to retain some functions on-premises, put some in SaaS applications, and others in cloud environments, but are often guilty of not protecting and managing everything to the same level of quality. Data gets backed up in a variety of locations, yet whether it is all equally recoverable in the event of a breach is another chink in the armor that nobody understands. The 'as a service' model is popular, but it is the weak link when ransomware strikes. The third part of the problem is the emergence of multiple compliance requirements mandating cyber resilience along with correct backup and recovery procedures, for which many organizations are ill-prepared. Together, these pressures give criminals room to do enormous harm to data, business operations and compliance posture in the gap between attack and restoration of SaaS availability. Given that Microsoft's native retention and recovery capabilities are not designed to deliver true cyber resilience, restoring the business to how it was before the attack is something to plan for in advance. Time for independent backup protection "At Kaseya we regularly recommend that you keep a copy of your data, independent of the primary environment it's operating in," advises Torre. "This needs to be something immutable that you can recover from even if the Microsoft or Google or Salesforce ecosystem goes down." This kind of protection is best delivered as a dedicated cloud-to-cloud backup solution stored outside the main SaaS tenant, he argues, an approach increasingly written into cyber insurance and compliance requirements. By pulling copies of regularly targeted data from the Microsoft tenant for storage offsite in a third-party datacenter, organizations can be sure that if SaaS credentials are compromised, critical assets remain safe from attack. Restoration can then push what is needed directly back into the SaaS environment, even where the original tenant has been destroyed. "In fact some people find it faster to stand up a new shell and rebuild it than try to gain access back into a compromised tenant," notes Torre. "Whether you're an internal IT technician, working the night shift, or an MSP needing to live up to your SLAs and maintain profitability, you require a solution that's super straightforward and you need to be able to trust that the recovery will work. Both IT departments and MSPs should be looking out for a solution that's incredibly easy to use. Disaster recovery isn't the only job that they have." A good platform, he says, focuses not just on guaranteeing recovery but on keeping the hygiene of the cyber resilience estate at a high standard without endless human intervention. It should also make certain that Microsoft 365 and Entra ID are restored together in a single workflow, so identity and the data it grants access to come back online in the right order rather than in separate stages. Choosing the right platform Datto is a cybersecurity and data protection business owned by Kaseya. Datto SaaS Protection for Microsoft 365, Datto Backup for Microsoft Azure, and Datto Backup for Microsoft Entra ID are designed between them to close the gap between availability and recovery by storing protected copies of tenant data in the Datto Cloud, outside the Microsoft environment. In this way a compromised production tenant does not take the recovery point down with it. "With our M365 backup, we're protecting one million users worldwide," claims Torre. "A lot of organizations have built trust around our ability to protect and recover their data. We offer a trusted platform for recovery that focuses on ease of recovery, ease of deployment, not just for M365 but for Azure and Entra ID too." Both IT bosses and MSP players need to recognize that a ransomware attack, or other cyber crisis, is a matter of when rather than if. Recovery matters more than protection, because protection is certain to fail at some point, and traditional approaches to backing up data are no longer sufficient on their own. Anticipating disaster is not enough; the organization also needs to be set up to withstand it. That means being as certain as possible that the Microsoft environment can be recovered rapidly, down to the last scrap of data. This capability underpins modern business workflows and operations. Microsoft tracks more than 4,000 identity attacks every second and analyzes 38 million identity risk detections daily — no organization is off the target list. When an attack lands, the restoration clock is already ticking, and any delay in fully restoring IT operations and key environments to their pre-attack state can mean the difference between survival and collapse, with profit, regulatory standing and reputation all riding on the outcome. Securing data with purpose-built cyber resilience platforms that enable rapid, clean recovery is how organizations meet that test. MSPs looking to close the gap can start with the Datto MSP Buyer's Guide to Microsoft Entra ID Backup Sponsored by Datto.
Kategorie: Viry a Červi

IBM Personal Computer uveden před 45 lety

AbcLinuxu [zprávičky] - 13 Srpen, 2026 - 16:46
Firma IBM uvedla svůj první mikropočítač Personal Computer před 45 lety, v srpnu 1981. Základní konfigurace modelu 5150 za 1 565 tehdejších dolarů obsahovala desktop s Intel 8088 a 16KB RAM, Color Graphics Adapter a klávesnici. Právě klávesnice Model F/XT vybavené kapacitními spínači, vlivné a s převodníkem dodnes použitelné, připomíná sběratelský web Admiral Shark's Keyboards.
Kategorie: GNU/Linux & BSD

Paměťová krize vyšvihla Čínu mezi špičku. O tamní čipy je extrémní zájem

Živě.cz - 13 Srpen, 2026 - 16:45
Podle analytiků z Counterpointu už čínští výrobci DRAM a NAND pamětí prohánějí své korejské a americké rivaly. Zpráva ze začátku srpna ukazuje, že ChangXin Memory Technologies (CXMT) již patří 7 % trhu s čipy pro operační paměti, když zaznamenala 719% meziroční růst. Konkurenti jsou v objemu ...
Kategorie: IT News

eBPF Security Logs May Show the Wrong File or Command, New Study Warns

LinuxSecurity.com - 13 Srpen, 2026 - 16:13
A Linux security tool can catch a system call and still record the wrong thing.
Kategorie: Hacking & Security

Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion

Bleeping Computer - 13 Srpen, 2026 - 16:00
AI coding tools can introduce unvetted or hallucinated open source dependencies faster than traditional security reviews can keep pace. ActiveState explains why organizations should govern packages at the point of selection, before they enter the development pipeline. [...]
Kategorie: Hacking & Security

Linux Audit Can Log a Syscall but Miss the Flag That Explains It

LinuxSecurity.com - 13 Srpen, 2026 - 15:45
Linux Audit can tell defenders that a system call ran while leaving out the setting that explains what the call did.
Kategorie: Hacking & Security

V Rumunsku kvůli nízké hladině Dunaje odstavili jadernou elektrárnu Cernavodă. Nepomohl ani odstřel břehu

Živě.cz - 13 Srpen, 2026 - 15:45
V Rumunsku kvůli rekordnímu suchu na Dunaji odstavili celou jadernou elektrárnu • . • Vojenské odstřely koryta nepomohly a stát na srpen vyhlásil energetickou nouzi. • Chybějící elektřinu nahradí obnovitelné zdroje, uhelná elektrárna i dovoz ze zahraničí.
Kategorie: IT News

AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS

The Hacker News - 13 Srpen, 2026 - 15:43
Cybersecurity researchers have disclosed details of a new macOS-oriented, Rust-based information stealer called AmnesiaStealer that's capable of hijacking Chromium web browsers to steal session data. The multi-stage stealer is spread via a counterfeit GitHub download page titled "Download for macOS" and claims to be from a verified publisher. The page employs a ClickFix-style lure that Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

White House taps security firms for offensive hack-back operations

Bleeping Computer - 13 Srpen, 2026 - 15:30
A new White House memo signed by U.S. President Donald Trump instructs the National Coordination Center (NCC) to establish a program that would allow private security companies to apply for approval to hack foreign cybercrime organizations. [...]
Kategorie: Hacking & Security

Slovensko označilo testované silniční kamery za bezpečnostní riziko

AbcLinuxu [zprávičky] - 13 Srpen, 2026 - 14:23
Slovensko odhalilo ruské součástky ve dvou testovaných zařízeních na zjišťování přestupků v silničním provozu a označilo je za bezpečnostní riziko. S odvoláním na vyjádření slovenského Národního bezpečnostního úřadu (NBÚ) to včera oznámil ministr vnitra Matúš Šutaj Eštok. Zároveň ohlásil ukončení spolupráce svého úřadu s dodavatelem části uvedeného systému, slovenskou společností Soitron. Opozice, která na problematické kamery upozornila už dříve, vyzvala k odvolání ministra vnitra.
Kategorie: GNU/Linux & BSD

It took $58 to break Microsoft’s SCCM, but a patch made it harder

Computerworld.com [Hacking News] - 13 Srpen, 2026 - 14:18

Researchers at XM Cyber found that a standard domain user with no Microsoft SCCM privileges can chain multiple flaws to reach remote code execution, although the attack does require network access to the SCCM environment.

Enterprises use Microsoft System Center Configuration Manager (SCCM) to deploy operating systems, manage patches, distribute software, and monitor compliance across large Windows fleets. XM Cyber’s attack can move from an ordinary domain account to code execution as “NT AUTHORITY\SYSTEM” on the primary site server.

“After the Site Server is compromised, all of its managed clients are compromised as well, which usually means taking over all the company assets,” XM Cyber’s Omri Baso told CSO.

The revealed attack chain combines four weaknesses, including a broken authorization in the AdminService upload functionality, a path-traversal flaw dubbed “CabSlip,” weak code-signing validation that could be tricked with a $58 commercial certificate, and an unsigned DLL-loading path in the SMS Executive service.

Microsoft fixed the initial authorization flaw, tracked as CVE-2026-47301, in July, but Baso said the remaining links in the chain are not expected to be fully addressed until ConfigMgr 2609, planned for October.

The patch did not patch

The initial foothold comes from SCCM’s AdminService API. Its normal extension-upload endpoint checks whether a user has the required permission, but its “chunked-upload” counterpart does not. That allows an authenticated Active Directory user to submit a malicious CAB archive without SCCM administrative privileges.

Microsoft’s July fix blocks that route for standard domain users. However, the downstream chain remains reachable through another path. Users assigned the built-in Operations Administrator role, or a custom role with Create permission on “SMS_ConsoleExtensionData,” can still trigger the same sequence.

But there is an important qualification here. XM Cyber said it believes organizations are unlikely to be exposed through the Operations Administrator route because it is already a highly privileged role.

Once the CAB reaches the server, CabSlip allows files to escape the intended temporary extraction directory and be written elsewhere on the filesystem. The attacker can use this arbitrary file-write capability to replace “adsource.dll,” a secondary library loaded by the SYSTEM-level SMS Executive service without its own signature check.

When the service subsequently loads the DLL, the attacker gets code execution as SYSTEM.

A $58 certificate can cross the trust boundary

The chain becomes particularly notable because SCCM’s signature validation does not establish that the signing certificate belongs to Microsoft or the target organization. It checks that the signature is structurally valid and non-expired, while revocation checks are disabled.

That means an attacker does not need an enterprise certificate. XM Cyber said the attack depends on a code-signing certificate and can also abuse certificates leaked online. For his own research, Baso used a Certum Open Source Developer Certificate that cost about $58.

For defenders, XM Cyber recommends restricting network access to the AdminService API and auditing SCCM RBAC assignments, particularly accounts with the Operations Administrator role or equivalent Create permissions.

Teams should also monitor the Site Server’s “AdminService.log” for a “System.IO.DirectoryNotFoundException” followed by an HTTP 500 response, a pattern that can indicate the path traversal was triggered, XM Cyber added.

Unexpected modifications to adsource.dll in the Configuration Manager installation directory can provide another detection signal.

Microsoft is reportedly working on patches for the remaining flaws. It did not immediately respond to CSO’s request for comment.

The article originally appeared on CSO.

Kategorie: Hacking & Security

Linux Security Roundup Privilege Escalation DoS Code Execution August 2026

LinuxSecurity.com - 13 Srpen, 2026 - 14:12
This week’s Linux security updates cover several areas administrators cannot afford to overlook. Debian, Ubuntu, Fedora, SUSE, openSUSE, and other distributions released fixes for privilege escalation, remote code execution, denial of service, and flaws affecting network-facing services.
Kategorie: Hacking & Security

WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud

The Hacker News - 13 Srpen, 2026 - 13:53
A previously unseen Android near field communication (NFC) relay malware family dubbed WindRelay is being deployed in conjunction with a known remote access trojan (RAT) called SpyNote as part of a contactless payment fraud scheme. The purpose-built malware, according to Group-IB, is designed to capture live card data via NFC and transmit it to fraudsters in real time. It was first detected in Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

WhatsApp rolls out new feature that flags potential scam messages

Bleeping Computer - 13 Srpen, 2026 - 13:50
WhatsApp has begun rolling out a new optional "Scam Alert" feature, which uses a local machine learning model to warn users when scammers are targeting them. [...]
Kategorie: Hacking & Security

North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring

The Hacker News - 13 Srpen, 2026 - 13:45
Companies are used to thinking about attackers as outsiders trying to break in. North Korean IT workers flip that model. They apply for jobs, pass interviews, receive legitimate credentials, and can end up inside the same systems companies spend millions trying to protect. That risk is no longer theoretical. The FBI is now investigating a North Korean remote IT worker who reportedly worked [email protected]
Kategorie: Hacking & Security
Syndikovat obsah