Agregátor RSS
PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser.
"Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium's own Secure Preferences
Kategorie: Hacking & Security
PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser.
"Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium's own Secure Preferences Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Předpověď od Googlu bude přesnější. Nový AI model WeatherNext 3 spolehlivěji odhadne srážky
Nový AI model od Googlu zpřesňuje předpověď deště i sněhu • Zpracovává čerstvá satelitní data a aktualizuje prognózu každou hodinu • Majitelé Pixelů uvidí detailní lokální údaje přímo v aplikaci
Kategorie: IT News
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
A zero-day vulnerability dubbed "StyleSmuggler" affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor. [...]
Kategorie: Hacking & Security
Jak dobře vybrat externí SSD. Jsou dvakrát dražší než HDD, ale ty rychlosti za to stojí
Poradíme, jak nejlépe vybrat externí disk SSD • Pro zálohování se má smysl dívat se i na mechanické disky • Externí SSD úložiště si můžete i sami poskládat
Kategorie: IT News
Google Patches Actively Exploited Chrome Vulnerability Affecting Linux
Chrome release notes can be a blur of version numbers. This one deserves a closer look. In the Linux build published on September 3, 2026, Google fixed CVE-2026-85046 and disclosed that an exploit was already in use. The build number to look for is 152.0.7977.82.
Kategorie: Hacking & Security
Linux Open vSwitch 2026-47916db6c7 RCU Race Condition Fix
A proposed patch fixes a bug in Open vSwitch, a virtual network switch with an in-kernel Linux packet-processing path. An ordering race can free a flow-table mask array while packet processing still reads it. The report includes a Kernel Address Sanitizer, or KASAN, trace, and the author says the crash reproduces in about one minute on a two-vCPU guest.
Kategorie: Hacking & Security
Linux OCFS2 Use After Free Risk Advisory 2026-47916db6c7
A reported race in OCFS2, a Linux clustered file system for shared storage, can trigger a use-after-free while administrators configure a heartbeat region. The failure occurs when concurrent writes reach the same configfs device attribute and both manipulate one region's slot-data allocation.
Kategorie: Hacking & Security
Linux Advisory Timer Vulnerabilities Leading to Use-After-Free Issues
A proposed Linux repair addresses two timer bugs that can trigger use-after-free conditions while one program replaces itself with another through exec(). Both failures begin with the same unusual transition: a thread that is not the process leader becomes the new leader, and Linux exchanges thread identifiers while timer and signal state still reflects the old ownership layout.
Kategorie: Hacking & Security
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins.
The activity, which mainly singles out directors, vice presidents, and other executive staff
Kategorie: Hacking & Security
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins.
The activity, which mainly singles out directors, vice presidents, and other executive staffRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Jak zjistit, co iPhonu nejvíc ždímá baterii a proč samotná procenta neříkají všechno
Nastavení iPhonu ukáže podrobnou spotřebu energie jednotlivých aplikací • Sledujte hlavně aktivitu na pozadí a slabý signál mobilní sítě • Stará baterie vyžaduje výměnu a ruční zavírání aplikací energii neušetří
Kategorie: IT News
BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. [...]
Kategorie: Hacking & Security
Ikea má nejlevnější chytrou termostatickou hlavici na trhu. Novinka Liljebagge bude stát pod 500 Kč
Už několik měsíců se na smart home fórech diskutovalo, že Ikea vstoupí i do chytrého vytápění. Později vyplynulo z databáze Distributed Compliance Ledger, že chystá termostatickou hlavici Liljebagge. No a ta se nově začala prodávat, zatím však jen v domovském Švédsku.
Ikea Liljebagge tam stojí 199 ...
Kategorie: IT News
Nightwing CEO has a Labor Day message for staff – and apparently The Register
Nightwing CEO Bob Coleman wanted to thank his employees for their hard work over the Labor Day weekend. Unfortunately, he also thanked The Register. The cybersecurity and intelligence contractor, which prides itself on “secure communications,” appears to have accidentally sent a for-employees'-eyes-only message from its chief executive to its media distribution list, giving journalists a brief and unsolicited glimpse into life at "Team Nightwing." The email, seen by The Register because, well, it was sent to us, is helpfully marked "For Internal Use Only." "Dear Colleagues," Coleman begins, addressing a group that apparently expanded rather dramatically when somebody selected the wrong mailing list. "As we head into this Labor Day weekend, I want to express my sincere appreciation for your commitment to Team Nightwing and the exceptional work you do every day," he adds. "Your efforts and unwavering dedication make all the difference in accomplishing our critical missions." Coleman went on to tell recipients that each of them plays "a vital role in our success," which came as welcome news to Vulture Central. "Please take this time to rest, recharge, and enjoy the well-deserved break with your loved ones," he states, before signing off simply: "Bob." Nightwing, which was spun out of defense giant Raytheon in 2024 and works across cybersecurity, intelligence, and national security, is perhaps not the sort of company you'd expect to struggle with the concept of an internal distribution list. We have asked Nightwing whether Bob's Labor Day message was intended to reach the press, although the words "For Internal Use Only" have given us a working theory. Either way, thanks, Bob. Hope you had a nice Labor Day too. ®
Kategorie: Viry a Červi
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on.
Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management
Kategorie: Hacking & Security
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on.
Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Nezkušení turisté si k plánování výstupu na horu vzali na pomoc Gemini. Akce skončila zásahem záchranářů
Nezkušení mladíci věřili umělé inteligenci a zabloudili v horách • Místo krátkého výletu musela muže zachraňovat horská služba • Umělá inteligence podcenila zásoby jídla a náročnost celé trasy
Kategorie: IT News
Hackers drain $320M in Bitcoin from Liquid Network, claim they're the good guys
Hackers have drained roughly $320 million in Bitcoin from the federation wallet backing the Liquid Network, while claiming to be the good guys. Liquid, a Bitcoin sidechain developed by Blockstream and used by exchanges and other financial institutions, said in a post on X on Sunday that around 4,000 BTC had been withdrawn from its federation wallet by what it cautiously described as "purported white-hat hackers." The wallet held about 4,200 BTC before the incident, meaning whoever was behind the exploit removed roughly 95 percent of its holdings. Liquid disabled its bridge nodes while federation members investigate and asked exchanges to suspend L-BTC deposits and withdrawals. The people behind the withdrawal, meanwhile, appear keen to establish that this isn't your standard crypto heist. In a message embedded in a Bitcoin transaction, they identified themselves as "whitehats" and asked Blockstream to get in touch. Blockstream responded on-chain with contact details for its security team, and Liquid said the parties subsequently moved their communications to encrypted channels. Those responsible said they would return "most" of the Bitcoin once the vulnerability was fixed and Liquid's nodes had been updated. "Please fix the bug first," the on-chain message said. "The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix." Exactly how they managed to move almost the entire federation wallet remains under investigation. Liquid said the BTC was withdrawn through SideSwap using its Peg-out Authorization Key, or PAK, but that neither SideSwap's key nor any other PAK appeared to have been compromised. PAKs allow federation functionaries to recognize destinations authorized to receive peg-outs; the functionaries collectively release the corresponding Bitcoin. That leaves the rather important question of how an apparently authorized SideSwap peg-out came to empty almost the entire federation wallet without the relevant PAK being compromised. Other assets issued on Liquid, including stablecoins, do not appear to have been directly affected, and the Bitcoin network itself was untouched. The incident is another reminder that adding Bitcoin to something does not give it Bitcoin's security model. Liquid is a federated sidechain whose members collectively manage the Bitcoin backing L-BTC, rather than relying on Bitcoin's miners to secure those funds. For now, those funds appear to be in the hands of people who insist they're conducting security research. Whether all 4,000 BTC eventually find their way home may determine how generous everyone feels about that description. ®
Kategorie: Viry a Červi
Mathspace discloses data breach affecting over 1 million people
Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after breaching its Metabase internal reporting system. [...]
Kategorie: Hacking & Security
- « první
- ‹ předchozí
- …
- 14
- 15
- 16
- 17
- 18
- 19
- 20
- 21
- 22
- …
- následující ›
- poslední »



