Agregátor RSS

Našli jsme nejlepší levné televizory se skvělým poměrem cena/výkon. Nejlepší TV do 20 tisíc

Živě.cz - 16 Červen, 2026 - 16:45
Vybrali jsme nejzajímavější televizory s výborným poměrem ceny a výkonu. Od těch menších a velmi levných po ty vybavenější a větší, které se však stále vyplatí.
Kategorie: IT News

Crooks found a new way to collaborate using Teams – by hiding command-and-control traffic

The Register - Anti-Virus - 16 Červen, 2026 - 16:41
Cybercrims deploying DragonForce ransomware appear to have gained access to a major US services company's network, then spent two months up to no good while disguising their command-and-control activities as legitimate Microsoft Teams traffic. Researchers at security firm Symantec said the intrusion began with attackers gaining access to the victim's environment before deploying a custom Go-based backdoor, tracked as "Backdoor.Turn," to maintain communication with the compromised systems. Rather than reaching out to attacker-controlled infrastructure that might raise alarms, the backdoor hid its activity inside traffic associated with Microsoft's widely used collaboration platform. To anyone monitoring network traffic, the compromised systems appeared to communicate only with legitimate Microsoft servers. "The attackers in this campaign use exceptionally sophisticated cyber tradecraft," Symantec said. "The configuration of Backdoor.Turn means that security products only see C&C traffic going to legitimate Teams servers, leaving defenders unaware that data is being siphoned away by malicious actors." Symantec said the attackers installed Backdoor.Turn on systems after deploying DragonForce ransomware, potentially giving them a way back into compromised networks or access they could later sell to other criminals. To connect to Microsoft's infrastructure, the backdoor first requested an anonymous visitor token from Microsoft Teams and Skype back-end services. It then used a Microsoft-operated TURN relay server – infrastructure typically used to help establish communication between users – before establishing a direct QUIC connection to a malicious command-and-control server. Symantec said this is the first known case of malware using this particular technique. The security firm did not identify the victim beyond describing it as a major US services company, nor did it say whether the Teams-based communications channel had been observed in other DragonForce incidents. The ransomware operation has become increasingly prominent over the past year, operating a ransomware-as-a-service model that allows affiliates to conduct attacks under the DragonForce banner. It has been linked to the prolific Scattered Spider group, which has conducted a string of high-profile attacks, including intrusions targeting major retailers in the UK. While attackers have long abused legitimate cloud services to conceal malicious traffic, Symantec's findings suggest that DragonForce operators continue to look for ways to blend into the software and infrastructure that organizations trust most. ®
Kategorie: Viry a Červi

UK to require ID or face scan before you can make social media accounts

Bleeping Computer - 16 Červen, 2026 - 16:38
Opening a new social media account in the UK will soon mean proving you're over 16 with an ID upload or a facial age scan, under a government ban on under-16s taking effect in spring 2027. Security experts warn the age checks are easy to circumvent and create new data-breach risks. [...]
Kategorie: Hacking & Security

FreeRDP 3.27 Raises the Baseline for Secure Remote Access

LinuxSecurity.com - 16 Červen, 2026 - 16:32
Remote access tools do not need dramatic new features to improve security. Sometimes the more useful change is quieter, like stronger defaults that make weak encryption harder to use by accident.
Kategorie: Hacking & Security

SimpleHelp Authentication Bypass Exposes Remote Access Security Risk

LinuxSecurity.com - 16 Červen, 2026 - 16:22
Remote support platforms sit close to the systems attackers want most: administrator workflows, technician accounts, and managed endpoints. That is why the SimpleHelp OIDC flaw is more serious than a routine authentication bypass vulnerability. For organizations running these platforms on Linux-based infrastructure, the risk is compounded by the ease with which these services are deployed and integrated into larger management stacks.
Kategorie: Hacking & Security

GhostTree Attack Abused Recursive Windows Junctions to Hide Malware

Bleeping Computer - 16 Červen, 2026 - 16:17
GhostTree uses recursive NTFS junctions to generate vast numbers of valid Windows file paths. Varonis explains how the technique could cause Microsoft Defender folder scans to never complete, leaving malware undetected. [...]
Kategorie: Hacking & Security

Firefox 152.0

AbcLinuxu [zprávičky] - 16 Červen, 2026 - 16:15
Byl vydán Mozilla Firefox 152.0. Přehled novinek v poznámkách k vydání a poznámkách k vydání pro vývojáře. Řešeny jsou rovněž bezpečnostní chyby. Nový Firefox 152 bude brzy k dispozici také na Flathubu a Snapcraftu.
Kategorie: GNU/Linux & BSD

Cisco SD-WAN Vulnerability: Why Security Starts With the Management Plane

LinuxSecurity.com - 16 Červen, 2026 - 16:04
For those of us who live and breathe Linux and open-source infrastructure, the "management plane" is usually just a collection of familiar tools—SSH, APIs, and centralized orchestration. But in the world of proprietary enterprise networking, the management plane is often a black box. Cisco’s latest SD-WAN issue serves as a stark reminder that even when these proprietary systems rely on Linux components under the hood, their centralized nature makes them the ultimate high-value target.
Kategorie: Hacking & Security

Prolétněte se zadarmo nad Českem v Google Earth Flight Simulator. Špičkovému GeoFS se ale nevyrovná

Živě.cz - 16 Červen, 2026 - 15:45
Nedílnou součástí starého desktopového glóbu Google Earth byl odjakživa skrytý jednoduchý letecký simulátor, který můžete dodnes spustit pomocí klávesové zkratky CTRL+ALT+A. Pilot dostane na výběr buď jednodušší pětimístný jednomotorový dolnoplošník Cirrus SR22, anebo rychlejší, ale na ovládání ...
Kategorie: IT News

FTC warns of record $3.5 billion losses to imposter scams in 2025

Bleeping Computer - 16 Červen, 2026 - 15:42
The U.S. Federal Trade Commission (FTC) warned that Americans lost $3.5 billion to imposter scams in 2025, with reported losses nearly tripling since 2020. [...]
Kategorie: Hacking & Security

New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds

The Hacker News - 16 Červen, 2026 - 15:10
Security researchers at Zimperium's zLabs have documented a new Android banking trojan, Rokarolla, that targets 217 banking and cryptocurrency apps and packs 137 remote commands. Together, they give an operator near-total control of an infected phone: it lifts lock-screen PINs, reads and sends SMS, rewrites the clipboard to redirect crypto payments, and switches off Google Play Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

AI exkluzivita počítačů Copilot+ skončí. Jazykové modely budou potřebovat aspoň GeForce RTX 30

Živě.cz - 16 Červen, 2026 - 14:45
AI funkce, které jsou poháněné NPU, nebudou všechny exkluzívní pro Copilot+. • Windows App SDK 2.2 Experimental 9 přidává podporu grafických karet. • Jako první jde o karty GeForce RTX 30 a novější s aspoň 6 GB videopaměti.
Kategorie: IT News

KDE Plasma 6.7

AbcLinuxu [zprávičky] - 16 Červen, 2026 - 14:13
Desktopové prostředí KDE Plasma bylo vydáno ve verzi 6.7 (Mastodon). Přehled novinek i s videi a se snímky obrazovek v oficiálním oznámení. Podrobný přehled v seznamu změn.
Kategorie: GNU/Linux & BSD

Hráli jsme Dreadline Express. Český horor o posledním lidském vlaku překvapí originální hratelností

Živě.cz - 16 Červen, 2026 - 13:45
Namixovat karetní hru s klasickou adventurou je poměrně zajímavý nápad, který ale může dopadnout všelijak. Povedlo se českým tvůrcům namíchat tu správnou směs zábavné hratelnosti a originálních prvků, aby to dalo dohromady zajímavou a unikátní hru? Nebo jde o přešlap vedle? Hratelná ukázka ...
Kategorie: IT News

Cardiac monitor maker's security skips a beat as data thieves go for the jugular

The Register - Anti-Virus - 16 Červen, 2026 - 13:45
Heart monitoring biz iRhythm says thieves made off with patient health information and tried to turn it into a payday. The California-based cardiac monitoring specialist offers customers a wearable device that collects data, then analyzes it to create reports about heart health. The company said it detected unauthorized activity on June 8 and launched an investigation with the help of third-party cybersecurity experts. A day later, the company received messages from a cybercriminal claiming to have obtained sensitive information, including proprietary company data, protected health information, and other personal information. According to iRhythm's filing with the US Securities and Exchange Commission, the attackers demanded payment in exchange for not publicly disclosing the stolen data. The company confirmed that data had been exfiltrated and, on June 10, determined that the incident was material due to the volume of information potentially affected. While the company disclosed the extortion demand and the existence of stolen data, it made no mention of negotiations. iRhythm spent a good chunk of the filing explaining what the attackers didn't get. According to the company, the intrusion was confined to business applications and never reached its clinical systems, medical devices, or customer connections. Patient care and day-to-day operations were unaffected. The company has not yet disclosed how many individuals may be affected, what data was accessed, or which third-party-hosted applications were involved in the breach. It has also not identified the threat actor behind the attack, and The Reg has found no evidence of major ransomware groups claiming responsibility. The company's filing states the attackers gained access through social engineering. Exactly how that happened remains unclear, although healthcare organizations have increasingly found themselves dealing with phishing campaigns, help desk impersonation scams, and other forms of human-targeted intrusion designed to bypass technical defenses. As of the filing date, iRhythm said it had not identified any ongoing unauthorized access to its systems and believed the incident was unlikely to have a material impact on its financial condition or operating results. The company added that it maintains cyber insurance that may cover some of the losses associated with the breach. iRhythm's disclosure comes less than a week after drug giant Novo Nordisk revealed that attackers had copied patient data from some clinical trials, adding another healthcare name to a growing list of organizations dealing with data theft and extortion attempts. ®
Kategorie: Viry a Červi

Survey: 94% of Incidents Involve Anonymized Infrastructure. Teams Are Still Reactive

The Hacker News - 16 Červen, 2026 - 13:30
Security teams have never had more IP data at their disposal. Every day, analysts ingest enrichment feeds, geolocation data, reputation scores, telemetry, and threat intelligence from a growing ecosystem of vendors and platforms. Yet despite this abundance of information, many organizations continue to face a fundamental challenge: sifting through the noise to understand who is behind an IP [email protected]
Kategorie: Hacking & Security

Critical Copilot vulnerability allowed hackers to steal 2FA code from users

Ars Technica - 16 Červen, 2026 - 13:15

Last Tuesday, Microsoft patched a vulnerability it rated as max critical in its M365 Copilot AI platform. On Monday, the researchers who discovered the vulnerability and reported it to Microsoft revealed how their proof-of-concept exploit could retrieve 2FA codes and other sensitive data from emails accessible to Copilot.

Microsoft and other LLM providers have been unable to prevent their products from complying with malicious requests to reveal data. The root cause: AI bots are unable to distinguish between instructions provided by users and those snuck into third-party content the models are summarizing, drafting responses to, or using to perform other actions on behalf of the user. With no way to secure this crucial boundary, Microsoft and its peers are left to erect complicated and ad hoc guardrails designed to rein in the consequences of this incurable gullibility.

Jumping over guardrails

One guardrail built into Copilot and most other LLMs prevents them from submitting web forms, sending emails, and taking similar actions that can be used to exfiltrate data from the user. To work around this, LLM hackers turned to markup language, which, among other things, allows users to add formatting elements such as headings, lists, and links to text without the need for HTML tags. Another workaround is to wrap sensitive data inside HTML tags such as <img> and <form>. In either case, a web request showing the data hits the attacker’s web server, where the secret information is captured in logs.

Read full article

Comments

CISA warns of another cPanel plugin flaw exploited in attacks

Bleeping Computer - 16 Červen, 2026 - 12:47
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. government agencies three days to secure their servers against an actively exploited vulnerability (CVE-2026-54420) in the LiteSpeed cPanel user-end plugin. [...]
Kategorie: Hacking & Security

Před lety revoluční, dnes skvěle vyladěný, ale bez zásuvky ztrácí dech. Test notebooku Asus ROG Zephyrus G16

Živě.cz - 16 Červen, 2026 - 12:45
Asus drží dva roky starý design bez velkých změn • Novinka hlavně upgraduje procesor a zjasňuje displej • Na hry je ho škoda, ale zábavě se nebrání
Kategorie: IT News

Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week

The Hacker News - 16 Červen, 2026 - 12:30
Bad actors are exploiting multiple security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber. In a post shared on X, the company said it has observed exploitation of CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089 over the past 24 hours. CVE-2026-39813 (CVSS score: 9.1) refers to a path traversal vulnerability in FortiSandbox JRPC API that could Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Syndikovat obsah