Agregátor RSS

Napsal původní Správce úloh pro Windows. Teď se legendární vývojář Microsoftu pustil do díla znovu

Živě.cz - 4 Srpen, 2026 - 16:45
Dave Plummer vytvořil původní Správce úloh ve Windows a další aplikace. • Teď na vlastní pěst vydal pokročilý Task Manager OG. • K dispozici je pro macOS, vyjde i na Windows a Linuxu.
Kategorie: IT News

AI helps Microsoft bug hunters chase a record $20M payday

The Register - Anti-Virus - 4 Srpen, 2026 - 16:40
Microsoft announced this week that between July 1, 2025, and June 30, 2026, the company had paid more than $20 million in bug bounties to 562 researchers. The total was a Redmond record, as was the number of those submitting bug reports – despite having to navigate a sometimes frustrating submissions process. For comparison, the previous year's program, which itself set a new company record, paid 344 researchers around $17 million. You could argue that the numbers do not represent a fair fight, however. Microsoft expanded its bug bounty program in December 2025, changing reports to what it calls "In Scope By Default." Under the policy, critical vulnerabilities became eligible for rewards if they had a direct and demonstrable impact on Microsoft's online services, even when the faulty code belonged to a third party or an open source project. In short, Microsoft had opened the door to paying out a shedload more each year. Microsoft introduced the policy roughly halfway through the bounty year and said it accounted for $800,000 in rewards that would not previously have been available. Another $2.3 million was awarded through Zero Day Quest, Microsoft's security research challenge and live hacking event. The increased number of reports this year can also be partially explained by the noticeable influx of submissions during the second half of the year, Microsoft said, which the company attributed in part to "the growing use of AI to support security research." Microsoft has also attributed its increasingly crowded Patch Tuesdays partly to its own use of advanced AI models for vulnerability discovery. July's 622 vulnerabilities pummeled the previous record of 206, set only a month earlier. June had itself surpassed April's 165, which at the time was Microsoft's second-biggest Patch Tuesday ever, and May's 137. Days before the record-breaking July Patch Tuesday, Microsoft's Windows + Devices veep warned customers to expect more of the same now that AI plays a big part in vulnerability discovery, both inside Microsoft and by external bounty hunters. However, Microsoft Executive VP of Windows + Devices Pavan Davuluri was quick to point out that the company offers customers a suite of automated patching tools to ease the burden, but didn't mention anything about tools to fix the machines its Windows updates so often borks, like Intel-based Dells. As well as navigating the rapid AI-ification of vulnerability research, and the onslaught of reports that came with it, Microsoft has arguably faced a bigger bug problem this year amid unverified speculation that one prolific researcher may be a former Microsoft staffer. Using the name NightmareEclipse, a researcher with deep knowledge of Microsoft's software and an equally apparent disdain for the company spent Q2 dropping sophisticated zero-days at will. NightmareEclipse claims that attempts to report vulnerabilities to Microsoft ended with them being insulted, humiliated, and left homeless. They subsequently began publishing zero-days outside coordinated disclosure, often shortly after Patch Tuesday, saying they wanted to cause Microsoft maximum pain. These ranged from serious privilege escalation flaws leading to SYSTEM access to BitLocker bypasses, and the approach seemed to have inspired at least two other aggrieved researchers to just drop the exploit code outside of responsible disclosure. Microsoft responded by threatening to involve its Digital Crimes Unit in the dispute with NightmareEclipse, suggesting it was willing to engage law enforcement, although this went down about as well as you would expect. ®
Kategorie: Viry a Červi

AI Is Already Performing Linux Security Work. What Happens When It Escapes Containment?

LinuxSecurity.com - 4 Srpen, 2026 - 16:05
Nearly everyone following technology has heard about the recent security incidents involving OpenAI and Anthropic. The headlines focused on the containment failures. For Linux administrators and security teams, however, the more important detail is what those systems were doing when it happened.
Kategorie: Hacking & Security

Varonis Agent IBAC keeps AI agents within their intended boundaries

Bleeping Computer - 4 Srpen, 2026 - 16:00
AI agents need broad access to be useful, but traditional access controls cannot determine whether an action aligns with a user's intent. Varonis explains how Agent IBAC detects intent drift and enforces real-time guardrails to keep agents within their intended boundaries. [...]
Kategorie: Hacking & Security

OpenStack IPA Flaws Highlight a Hidden Bare-Metal Security Risk

LinuxSecurity.com - 4 Srpen, 2026 - 15:58
OpenStack disclosed a flaw in its bare-metal management tool, the Ironic Python Agent (IPA), showing that it could accidentally fall back to local network discovery and connect to the wrong server entirely. 
Kategorie: Hacking & Security

Americký úřad FAA dal zelenou novému Boeingu 737 MAX-7. Nejmenší verze slavné řady vstupuje do služby

Živě.cz - 4 Srpen, 2026 - 15:45
Americký úřad pro letectví schválil nový model Boeing 737 MAX-7 • Letoun musel po nehodách získat bezpečnější systémy i software • První vyrobené stroje převezmou americké aerolinky Southwest Airlines
Kategorie: IT News

Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks

The Hacker News - 4 Srpen, 2026 - 15:30
A credential-stealing npm worm that first appeared in [email protected] spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026. SafeDep verified 353 poisoned versions across 79 package names in the npm registry. Its monitoring put the wider footprint at 442 versions across 353 names, while Aikido later reported at least 868 packages
Kategorie: Hacking & Security

Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks

The Hacker News - 4 Srpen, 2026 - 15:30
A credential-stealing npm worm that first appeared in [email protected] spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026. SafeDep verified 353 poisoned versions across 79 package names in the npm registry. Its monitoring put the wider footprint at 442 versions across 353 names, while Aikido later reported at least 868 packages Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Netflix a 30 nejoblíbenějších filmů a seriálů v srpnu 2026. Najdu si tě, akčňák My vás naučíme nebo krimi seriály Metanol a Rapl

Živě.cz - 4 Srpen, 2026 - 15:15
Tyto filmy a seriály jsou teď na českém Netflixu nejoblíbenější. Nerozlišujeme žánr, stáří ani hodnocení na filmových webech. Jde o souhrnnou oblíbenost za poslední týdny, kterou zjišťuje web FlixPatrol.
Kategorie: IT News

Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access

The Hacker News - 4 Srpen, 2026 - 15:11
Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Management (RMM) programs like ConnectWise ScreenConnect. The campaign has been codenamed SMOKE#SCREEN by Securonix Threat
Kategorie: Hacking & Security

Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access

The Hacker News - 4 Srpen, 2026 - 15:11
Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Management (RMM) programs like ConnectWise ScreenConnect. The campaign has been codenamed SMOKE#SCREEN by Securonix Threat Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Zásilkovna usnadní vrácení zboží e-shopům. Balíček zanesete do Z-Boxu, ani není nutné tisknout štítek

Živě.cz - 4 Srpen, 2026 - 14:45
Zásilkovna rozšiřuje možnosti vracení zboží. • Zákazníci nově mohou reklamace i vratky vyřídit přes Z-Boxy bez tištění štítků. • Služba je dostupná všem e-shopům napojeným na její systém.
Kategorie: IT News

Tennessee congressional hopeful accused of shooting license plate cameras

The Register - Anti-Virus - 4 Srpen, 2026 - 14:08
An independent congressional candidate in Tennessee faces four felony vandalism charges after allegedly shooting four automated license plate reader (ALPR) cameras between July 14 and 22. According to the Blount County Sheriff's Office (site geo-restricted), Adam Lee Heimerman, 37, is accused of targeting three cameras in Blount County and one in Maryville. Local news reports citing an affidavit say at least one was manufactured by Flock. Police said Heimerman allegedly reached one of the cameras through the grounds of a place of worship while a service was under way. Heimerman is running for election [PDF] to represent Tennessee's 2nd Congressional District. He is on the ballot in the general election on November 3, 2026. One of Heimerman's opponents in the 2nd Congressional District, Republican incumbent Tim Burchett, has also tried to tackle the Flock cameras across the state, albeit through less drastic means. Last week, Burchett introduced a bill that would prevent federal agencies from buying or accessing automated surveillance systems and bar state and local agencies from using federal funds to purchase them, citing Fourth Amendment abuses. The bill would allow individual counties to secure contracts with Flock and install its cameras, but if passed, the proposal would see that the county bears all the costs of doing so. Flock told local news that it welcomed legislation that both increased the guardrails around its tech and retained individual authorities' power to deploy cameras to support law enforcement. The case joins a series of attacks on ALPR cameras across the US amid growing opposition to the technology. From allegations of police officers using the cameras to stalk ex-partners, to controversial ties with ICE and CBP immigration investigations, Flock, the best-known brand of ALPRs in the US, has struggled with continued stories of its tech being abused. Georgia police arrested and fired five officers on suspicion of misusing ALPR cameras "for non-law enforcement purposes" just last month. One Milwaukee police officer was also allegedly caught searching the details of his ex-partner more than 100 times using Flock camera tech. Later, one of the detectives assigned to the investigation was also allegedly caught misusing ALPR data, and had allegedly unlawfully placed a GPS tracker on one of the victims' cars years earlier. The controversies coincide with a spate of physical attacks on ALPR hardware across the US, some carried out by people who regard the technology as unlawful or unconstitutional surveillance. An unidentified arsonist set two Flock cameras on fire in Georgia last month, weeks before a 40-year-old man was caught by regular CCTV cameras destroying ALPRs in California. Steve Eimers, a prominent campaigner for road infrastructure safety, was also recently forced to desist from his efforts to highlight potential legal issues with the poles Flock uses to erect its cameras after supporters started identifying the cameras used in his videos and destroying them. These vandalism cases have barely made a dent in the overall number of Flock cameras that operate across the US. The company does not specify the exact number that are up and running, but estimates range between 80,000 and 120,000 or more. Many police departments claim the technology makes policing crimes ranging from vehicle thefts to murders much easier, as it allows them to track the movements of vehicles with ease. Flock says its technology is used in roughly 5,000 communities across 49 states, although not all of them are sticking by the company amid the many controversies. Los Angeles Police Department, for example, said recently that it would let its Flock contract expire, while others such as Eugene and Springfield, Oregon, canceled their contracts in December. ®
Kategorie: Viry a Červi

How legitimate cloud platforms enable phishers to bypass MFA

Kaspersky Securelist - 4 Srpen, 2026 - 14:00

Threat actors are increasingly exploiting legitimate cloud services to evade detection and streamline the deployment of their scam infrastructure. Cloud hosting services and decentralized networks have become primary platforms for hosting phishing pages and sites. Throughout 2025 and 2026, we have observed phishing operators steadily migrate toward platforms like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS. This post analyzes the mechanics of a real-life adversary-in-the-middle (AitM) attack in a cloud environment and presents detailed statistics on the platforms and domains phishers abuse most frequently.

The cloud as a safe haven for phishers

Threat actors select platform-as-a-service (PaaS) offerings and distributed cloud environments to host phishing sites for much the same reasons legitimate software developers do:

  • Inherent trust and reputation. Phishing pages hosted on reputable platforms appear trustworthy, reducing suspicion among potential victims.
  • Most platforms offer generous free-tier developer plans. The onboarding process takes minutes and rarely requires Know Your Customer (KYC) identity verification. This enables a single operator to create hundreds of malicious accounts.
  • Evasion and anonymity. Attackers leverage native security features to obscure their true origin server IP address behind a CDN, which complicates detection for security vendors.

Additionally, these platforms allocate shared subdomains hosting millions of legitimate projects and websites. Security teams cannot simply block the parent domain or its subdomains without inflicting collateral damage on bona fide users – a limitation that malicious actors take advantage of. To counter this tactic, security vendors must advance content-based analysis methodologies.

Multi-stage AitM attack

Consider a modern AitM phishing campaign that leverages Cloudflare Workers, a widely adopted cloud platform. The attackers execute the operation through multiple HTML pages distributed across a compromised website and the cloud platform. Each page serves a specific function: harvesting target email addresses, initializing the reverse-proxy infrastructure, or spoofing the login form to capture multi-factor authentication (MFA) sessions.

Stage 1. Contact harvesting and network monitoring evasion

The attack typically begins with a phishing email that uses a plausible pretext – such as a request from a coworker to review documents – to entice the target into clicking a malicious link.

Upon clicking the link, the user is redirected to a fake CAPTCHA landing page hosted on a compromised legitimate website. This specific campaign used the https://t[REDACTED]e.com website, but any other variations are possible. In this scenario, the compromised page served as a disposable relay — vendor detection mechanisms typically block phishing links delivered directly via email much faster — to prevent the early discovery of the core phishing content hosted on Cloudflare.

If the user entered their email address and clicked Continue, the pseudo-CAPTCHA marked them as a human user and initiated a redirect. The primary objective of this stage is to harvest target email addresses, filter out bots, and route legitimate users to a subdomain of workers.dev. Such subdomains are generated automatically and free of charge by Cloudflare Workers. The victim’s email address was embedded in the URL hash (the part of the URL following the # character), allowing the page at [REDACTED].workers.dev to extract the email without issuing a request to the attacker’s server, thereby avoiding detection.

Stage 2. Initializing a transparent proxy

The user’s browser then loaded a [REDACTED].workers.dev page with #[email protected] at the end of the URL. At this point, the page presented the victim with a genuine CAPTCHA challenge. This step ensured that an actual user was interacting with the page rather than a security sandbox.

Another CAPTCHA, this time a legitimate one

Once the user successfully completed the challenge, a service worker was registered in their browser. This is a special JavaScript file capable of running in the background and intercepting all network requests generated by the current tab. As this type of script was designed as a core component of progressive web apps (PWAs) to optimize load times and support offline functionality, browsers treat service workers as standard site feature and execute them without prompting for user consent as long as the website uses an HTTPS connection.

The attackers leveraged the service worker to deploy Ultraviolet, a legitimate open-source web proxy library, to dynamically rewrite all links and forms on the page. This forced every outgoing request – including those for Microsoft login credentials – to route through the attackers’ server rather than directly to the legitimate services.

Immediately upon loading, the page extracted the victim’s email address from the URL hash and stored it in the browser’s sessionStorage property so it would not be overwritten when the CAPTCHA loaded. This step also allowed the script to pre-fill the username field in the form automatically. A pre-populated login field enhanced the page’s credibility and bolstered user trust. Once the CAPTCHA was passed, the malicious script constructed a redirect URL for the third stage, appending the email retrieved from sessionStorage back to the hash. By passing the email via the URL hash across three consecutive stages, the attackers successfully kept it hidden from network attack detection systems.

Registering a service worker to intercept traffic

Establishing a transparent proxy via an external library

Stage 3. Session hijacking and browser window spoofing

The final stage unfolded on a third page, combining adversary-in-the-middle (AitM) traffic interception with a browser-in-the-browser (BitB) UI spoofing technique. BitB attacks operate by rendering a block inside a legitimate webpage that visually mimics a native browser pop-up window.

In this case, the script hosted on the attacker’s page generated a pop-up visually identical to a native browser window, complete with window controls and a spoofed address bar showing a trusted Microsoft URL. Within this simulated window, an iframe loaded the authentic login interface, routed dynamically through the service worker reverse proxy created in Stage 2. When the victim entered their credentials and MFA code into the BitB window, the proxy script intercepted both the credentials and the session tokens. Combining BitB with AitM significantly increases the threat: BitB provides a convincing, trusted visual wrapper (displaying a legitimate URL and branding), while the hidden AitM proxy quietly handles traffic interception and session hijacking behind the scenes.

Upon successful login, the proxy instructs the interface to close the pop-up and redirect the victim to a generic system error page, such as SessionExpired. This minimizes suspicion: the victim assumes a technical glitch occurred and attempts to log in again, unaware that the attacker already has full access to the session.

Cloud platform phishing attack statistics

We analyzed phishing URLs hosted across popular cloud platforms – including Cloudflare, Netlify, and GitHub Pages – over a 12-month period spanning August 2025 to July 2026. The data below outlines trends in unique third-level domains exploited to deliver phishing content. In total, our security solutions blocked 224,984 unique third-level domains on cloud and decentralized services used in phishing attacks within that timeframe.

Number of unique third-level domains
(download)

Based on this telemetry, we compiled a list of the TOP 10 cloud domains most frequently abused in phishing campaigns over the specified period.

Number of phishing links

Unsurprisingly, Cloudflare and Vercel emerged as the undisputed leaders: both offer free tiers, automated SSL certificate issuance, and global CDNs. GitHub Pages ranked third. The widespread legitimate use of the github.io domain complicates bulk blocking efforts, as security teams risk limiting access to non-malicious projects.

Decentralized networks also warrant close attention – we posted on this subject in 2023. The ipfs.io and dweb.link domains function as IPFS gateways. The principal risk associated with these platforms is content persistence: even if a specific gateway gets blocked, the phishing page remains accessible via alternative nodes across the network.

The visual website builders Wix and Webflow also ranked among the TOP 10 (eighth and ninth, respectively). These platforms allow low-skilled individuals to build phishing pages rapidly without advanced coding expertise, which significantly lowers the barrier to entry for less capable malicious actors.

 

Domain Number of phishing links Platform 1 pages.dev 24.9% Cloudflare Pages 2 vercel.app 13.8% Vercel 3 github.io 13.7% GitHub Pages 4 netlify.app 10.0% Netlify 5 dweb.link 7.8% IPFS gateway 6 ipfs.io 5.3% IPFS (InterPlanetary File System) 7 workers.dev 2.5% Cloudflare Workers 8 wixstudio.com 1.9% Wix Studio 9 webflow.io 1.0% Webflow 10 azurewebsites.net 1.0% Microsoft Azure Other 17.9%

In total, we identified and neutralized over 390,000 phishing pages hosted across legitimate cloud platforms and decentralized networks (IPFS) over the past 12 months. This data confirms that threat actors actively exploit the implicit trust associated with legitimate PaaS providers (such as Cloudflare Workers, Vercel, Netlify, and GitHub Pages) and IPFS gateways. High domain reputation, generous free tiers, and built-in evasion capabilities enable phishers to deploy multi-stage AitM attacks designed to hijack MFA sessions.

Recommendations

Traditional security controls, such as relying on HTTPS lock icons or reputation-based domain denylists, are inadequate against these attacks. The cloud provider’s apex domain maintains a positive reputation score, while attackers generate malicious subdomains programmatically and at scale.

Effective defense against these threats calls for a layered security posture:

  • Exercise caution with unexpected requests, even if they are served from reputable domains or secured with valid SSL/TLS certificates.
  • Treat any CAPTCHA interface requiring personal data input as a possible scam. Legitimate CAPTCHA challenges rarely request personally identifiable information, such as email addresses.
  • Inspect the URL in the address bar at the very top of the browser window. In BitB attacks, threat actors can render a fake browser pop-up displaying any target URL, even a legitimate one. However, the true address bar – located at the top of the main browser window alongside native navigation controls (Back, Forward, Refresh) – will continue to display the actual attacker-controlled domain.
  • Avoid entering credentials in pop-ups you did not expect to see. If a login or MFA form appears without your explicit action, close the tab immediately. Navigate to the intended service manually by entering its address directly into the browser.
  • Additional protection can be provided by Kaspersky Secure Mail Gateway for enterprise environments and Kaspersky Premium for personal correspondence. These robust email security solutions neutralize phishing links at the delivery stage before they reach the inbox.

When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted

The Hacker News - 4 Srpen, 2026 - 13:30
The cybersecurity industry has spent decades assuming that offensive capability scales with technical expertise. That assumption is starting to break. Security teams have long estimated risk by ranking attacker sophistication. Nation-state actors sat at one end. Organized criminal groups followed. Inexperienced attackers, dismissed as "script kiddies," sat at the other end, running public
Kategorie: Hacking & Security

When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted

The Hacker News - 4 Srpen, 2026 - 13:30
The cybersecurity industry has spent decades assuming that offensive capability scales with technical expertise. That assumption is starting to break. Security teams have long estimated risk by ranking attacker sophistication. Nation-state actors sat at one end. Organized criminal groups followed. Inexperienced attackers, dismissed as "script kiddies," sat at the other end, running public [email protected]
Kategorie: Hacking & Security

CAF Bank reopens online service but warns of further outages

The Register - Anti-Virus - 4 Srpen, 2026 - 13:23
CAF Bank has told customers its online banking service is back after being shuttered for more than ten days following what it described as "attempted fraud." In an email update seen by The Reg, the bank warned that access could remain intermittent, and it might "need to limit the amount of traffic to the website" at certain times. It admitted: "There are likely to be periods where online banking is not available. We will try to keep this to outside business hours." The bank also gave customers a timeline of the incident, saying it first noticed "attempted fraudulent activity" on July 21 "on a small number of accounts." It then called in "external specialists" and temporarily withdrew access to the online service on Wednesday, July 22, and Friday, July 24, "while we investigated." Then, on Saturday, July 25, the bank detected "related malicious activity of a different kind," which the email to customers said was "aimed at removing a small number of individual online user logins, making those logins unavailable." It added: "Again, we caught this quickly and removed access to the online service. Our investigation identified a previously unknown vulnerability in how some third-party software connects to the online banking portal." The bank was at pains to reiterate that the "core bank" was not affected, "which means that money is safe and secure in accounts." The Charities Aid Foundation-owned bank came under fire last year after customers were unable to log in or make transactions following its long-running migration to a new platform based on Temenos Transact, formerly T24. In an open letter regarding the latest outage, charities described the new online banking platform as "significantly more time-consuming to use, placing an unnecessary administrative burden on already stretched small charities" and "often unreliable." They also expressed concern they would not be able to pay staff and suppliers, with Kevan Hodges, chief exec at Kent-based Down's syndrome charity 21 Together telling the BBC: "People are concerned that wages won't get paid because of this, and that's just stressful when they have bills to pay." The bank earlier said that “due to the disruption, as a small thank you for your patience, we will be waiving our monthly customer account charge for all customers for August and September 2026.” The Reg can confirm those charges are £5 a month. Alison Taylor, CAF Bank CEO said in a statement: “We have completed the essential work with our technology partners and our online banking service is now available." She added: "I very much appreciate that this has been a frustrating experience for our customers, and I am particularly sorry for the long delays to speak to us on the phone. Our thorough investigation into the incident will continue so that we, our partners and our industry can learn from it.” ®
Kategorie: Viry a Červi

Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent

The Hacker News - 4 Srpen, 2026 - 13:16
Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a privileged code-fixing agent. The researchers said the public agent could be prompt-injected into posting /adk-issue-fix as adk-bot. They identified the bot as a collaborator, so that comment satisfied
Kategorie: Hacking & Security
Syndikovat obsah