Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

Rejetto HFS servers now actively scanned for critical RCE flaw

Bleeping Computer - 1 hodina 16 min zpět
Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows session forgery, account takeover, and remote code execution (RCE). [...]
Kategorie: Hacking & Security

IQVIA fined $7.8 million for failing to properly anonymize health data

Bleeping Computer - 4 hodiny 16 min zpět
Italy's Data Protection Authority (GPDP) has fined IQVIA €7 million ($7.8M) over poor data-processing practices that the agency says could have put roughly one million patients at risk of data exposure and de-anonymization. [...]
Kategorie: Hacking & Security

Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes

The Hacker News - 5 hodin 14 min zpět
Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulnerability, tracked as CVE-2026-96940, is rated 8.8 on the CVSS scoring system. "Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Denmark population registry data breach affects 8.8 million people

Bleeping Computer - 6 hodin 15 min zpět
Denmark's Central Population Register (CPR) is warning of a data breach that exposed the personal information of approximately 8.8 million registered individuals. [...]
Kategorie: Hacking & Security

New Dell System Update flaw lets hackers gain root privileges

Bleeping Computer - 6 hodin 43 min zpět
Dell warned customers to patch a critical vulnerability in the System Update (DSU) command-line interface (CLI) deployment tool as soon as possible. [...]
Kategorie: Hacking & Security

South Korea probes bank breaches amid suspected AI-powered attacks

Bleeping Computer - 7 hodin 14 min zpět
South Korea's Financial Services Commission (FSC) held an emergency meeting following a series of cyberattacks targeting financial institutions in the country. [...]
Kategorie: Hacking & Security

⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests

The Hacker News - 7 hodin 16 min zpět
A blank field. A public repo. One reply to an email. A box left exposed. None of this sounds dramatic, which is partly the problem. This week’s threats keep finding leverage in small things that were easy to overlook. There are actively exploited bugs in the mix, cleaner intrusion paths, smarter automation, and a long patch list waiting behind them. Some attacks are getting more capable. OthersRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

tenfold CE: Our free Identity Governance tool just got 2 new features

Bleeping Computer - 8 hodin 3 min zpět
tenfold has added shared content governance and real-time event auditing to its free Community Edition for organizations with under 150 users. The new features help teams manage Microsoft 365 sharing and investigate suspicious identity activity. [...]
Kategorie: Hacking & Security

Alleged dev of Ploutus ATM malware appears in US court after arrest

Bleeping Computer - 8 hodin 35 min zpět
The U.S. Department of Justice has announced the arrest of the alleged developer of Ploutus malware, used to steal millions of dollars in ATM jackpotting attacks across the United States. [...]
Kategorie: Hacking & Security

The Credential Layer Is Expanding Faster Than Security Teams Can See It

The Hacker News - 9 hodin 1 min zpět
Every modern enterprise depends on credentials. This is how humans, systems, and now AI, all connect to data, services, and each other securely. GitGuardian helps secure that credential layer through three connected capabilities: Detect, Remediate, and Prevent. The journey starts with detection, because organizations first need to understand what credentials exist, where they live, and what [email protected]
Kategorie: Hacking & Security

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

The Hacker News - 9 hodin 50 min zpět
Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. "Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel," Nozomi Networks said in a report Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Tech execs are getting wise about ROI from AI

Computerworld.com [Hacking News] - 10 hodin 36 min zpět

Most organizations have been largely unable to measure financial returns from AI, but analysts say new ways to calculate return on investment are emerging.

“There’s a delay between the development of technology, even the investment in the technology, and the value that an organization can capture from it,” said Michael Chui, a senior fellow at McKinsey.

But more executives are asking questions. “The CFOs are asking CIOs, investors are asking CEOs: ‘Where’s the ROI from this stuff, already?’” he said.

In McKinsey’s “State of AI” survey released in August, about 80% of respondents said AI improved their productivity. But only 37% said AI’s impact showed up in profits, about the same as last year. An even smaller number — only 6% — said AI delivered significant value and accounted for at least 5% of their operating profit.

In other words, there’s a drop-off between the value that individual workers are getting from AI and the value that organizations are getting from AI, Chui said.

The biggest gains will come from redesigning workflows and processes in which humans and AI agents work together, according to McKinsey’s Technology Trends Outlook. Layering agents onto existing processes isn’t enough.

“Usually an end-to-end workflow involves multiple individuals, and completely redesigning that with the use of AI… is characteristic of high-performing companies,” Chui said.

Controlling costs

Managing token costs and applying the right model for a task is part of realizing better returns, Chui said. “In many cases, there just isn’t transparency… Which workloads are actually driving your costs?” he said.

Three out of five IT leaders are worried about AI agents running up unexpected costs, and this is already happening, said Gareth Herschel, a vice president analyst at Gartner, during a keynote at Gartner’s Data & Analytics Summit in Mumbai.

“Some organizations have already discovered that the cost of tokens for coding assistance is much higher than the cost of human software developers,” Herschel said.

As more agents work together, “your financial risk only grows. It’s like giving your teenager your credit card… I’m sure you will learn a lot, but mostly from the bill,” said Robert Thanaraj, a senior director analyst at Gartner and a co-speaker at the Mumbai keynote.

Companies should track costs in prototyping, such as finding the cost of an individual agent per completed task, Thanaraj said. “It’ll help you to evaluate different large language models or help you to go with a more affordable option, such as smaller language models or open weights model.”

A wider lens for ROI

Analysts highlight numerous challenges in calculating AI ROI, such as unexpected costs, poor data quality, failure to scale, and slow adoption among users.

But executives are skilling up in tracking what they spend on AI and the returns, said McKinsey’s Chui. “Between the CFO and the CIO, we’re starting to see these disciplines emerge.”

In 2025, the odds of an AI initiative achieving ROI were one in five, the Gartner analysts said in their keynote.

“ROI matters, but to achieve it, we must think of it not just as a financial metric, because value isn’t always just about money,” Thanaraj said.

Companies should tie AI projects to both financial and non-financial outcomes, part of what Gartner calls a “return on intelligence.”

“We need to shift the emphasis from cost to value,” Herschel said. “The outcomes can be financial, such as revenue, but they can also be non-financial, such as citizen experience.”

The right foundation: context, infrastructure, governance

The Gartner analysts said achieving ROI on AI requires a strong technical and contextual foundation.

“Governance adds trust. Context adds meaning. Without strong foundations, AI may well stand for amplified ignorance,” Thanaraj said.

For example, data quality can be a roadblock. “Without clear context, LLMs are just guessing,” Thanaraj said, and that amplifies misunderstanding. Poor data and poor AI design mean more hallucinations and bad output.

“You can’t buy this context layer off the shelf. It has to be built to fit your needs,” Herschel said.

A strong technical foundation, such as a robust networking backbone for data movement, is critical, said Jack Gold, principal analyst at J. Gold Associates.

“Agent-to-agent interactions will become commonplace and mission-critical, even as the number and distribution of agents expands dramatically to include interactions across remote agent locations and devices,” Gold wrote in a research note.

A majority of organizations are establishing harnesses — the software layer that controls and coordinates models, tools, and workflows — to govern AI use in business. According to a global KPMG survey released last month, 55% of organizations have a formal AI harness layer. That rises to 86% among organizations reporting established ROI.

Organizations that “combine clear accountability, coordinated governance, resilience, and reliable value measurement will likely be best placed to turn broad adoption into sustained performance,” KPMG said.

Kategorie: Hacking & Security

Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access

The Hacker News - 10 hodin 57 min zpět
Apple has announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents. "Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history – without users' full knowledge Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

OpenAI will show visual ads in ChatGPT while you generate images

Bleeping Computer - 11 hodin 8 min zpět
OpenAI is expanding ads in ChatGPT, and one of the first new formats will show visual ads while you're generating images. [...]
Kategorie: Hacking & Security

Apple locks down Full Disk Access, and AI agents are the reason

Computerworld.com [Hacking News] - 11 hodin 23 min zpět

Apple has been forced to make macOS even more locked down, to the dismay of some developers. It has announced plans to introduce more user-facing control over the process of giving apps Full Disk Access.

Some developers are upset, believing this will put more barriers in place to those creating apps outside the App Store. Endpoint security vendors voiced some concern but understand the cause: “poorly written/insecure/greedy AI agents/assistants insisting on Full Disk Access, and then once granted/obtained, abusing that, to access ,” as Objective-See co-founder Patrick Wardle wrote on X.

Explaining its plans, Apple says it will still make it possible for customers to choose to enable Full Disk Access; it’s just going to make the decision much more intentional, with additional steps to ensure that users know what they are signing up for.

Why is Apple doing this?

It may or may not be in reaction to Meta’s Muse AI agent, which was accused of reading a journalist’s private messages without permission — a claim Meta denies. 

But even if it is not a reaction to that, the move attempts to put additional obstacles in place to prevent users from casually giving AI agents the power to ransack their private data when they give them Full Disk Access without fully understanding the consequences of doing so.

What Apple said

Here’s what Apple said in a note on its developer website:

“We give developers powerful APIs to build incredible capabilities into their apps for Apple products, backed by a set of controls designed to protect users’ private data. Full Disk Access largely sidesteps these controls in order to allow backup apps to function properly on the Mac. Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.

“Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action. Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.”

The note makes it quite clear that Apple is doing this in reaction to the real and present danger that unconstrained AI places on security systems everywhere. 

Accident, or design?

After all, for every denied instance in which Meta’s Muse may, or may not, have surveyed private messages, there are now many incidents in which some “rogue” AI has “escaped” to do some kind of harm.

Except it’s quite easy to think these incidents are not really escapes, isn’t it? 

If you do, then this is AI doing precisely what it’s designed to do. 

Rather than railing at Apple, developers and critics should focus on why this change has been put in place. It should be recognized as another of the huge “benefits” most humans are already experiencing at this stage of AI disruption.

It’s a benefit to accompany hyper-inflated memory prices on consumer electronics costs. It’s a benefit that flows with the energy and water price increases we are seeing as AI data centers consume more of both, even as inventors of this tech warn that what they have invested hundreds of billions of dollars in poses an “existential threat” to humanity.

Sure, AI can and does release positive consequences, and I celebrate that, but that doesn’t give it a pass on its damage and risk, particularly existential risk.

Obsolete software

“Redefining” that risk is perhaps why Anthropic co-founder Christopher Olah visited Pope Leo XIV to convince people around the head of the Catholic church that AI can be considered conscious. 

One way to see that argument is that AI is not really an existential threat to humanity if you redefine it as some kind of evolution toward a new super race. It becomes a painful but necessary step toward the next phase of humanity, even if that does sound rather messianic (some say fascistic, as Gil Duran explains).

Thankfully, the Pope didn’t buy it. “Algorithms lack the spark of humanity. For this reason, the Church wishes to renew an alliance with artists and cultural institutions to safeguard our humanity,” he wrote in a recent declaration concerning the impact of AI on creative arts.

If I’m honest, and I do try to be, developers and critics attacking Apple for its decision to lock down this aspect of the Mac experience are focused on the wrong target. You need to reconsider who to blame.

For the many

It’s time, urgently time, for people in tech to get back on the road to what makes it great, which is now and always has been what results from the marriage of technology and liberal arts. AI is not conscious. AI has no moral soul. 

With that in mind, it’s appropriate to ensure that humans have informed agency before they provide AI with access to their data. Religions claim that divinity gave us free will. Do you think AI and the billionaires who own it want us to keep that gift? 

Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSky, LinkedIn, or Mastodon.

Kategorie: Hacking & Security

Microsoft: Windows KB5124010 update crashes some games and apps

Bleeping Computer - 11 hodin 58 min zpět
Microsoft confirmed over the weekend that some games and applications using AC-3 (Dolby Digital) audio decoding will crash after installing the September 2026 KB5124010 Windows 11 preview update. [...]
Kategorie: Hacking & Security

Google halts open-source bug bounty program amid AI spam surge

Bleeping Computer - 13 hodin 9 min zpět
Google has now suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded by AI-generated reports. [...]
Kategorie: Hacking & Security

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

The Hacker News - 13 hodin 27 min zpět
A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Ani třídenní pojistka neudělá z iPhonu nedobytný trezor. Vyšetřovatelé z něj dostanou i smazaná data

Zive.cz - bezpečnost - 13 hodin 1 min zpět
** Každý iPhone se po 72 hodinách bez použití tajně restartuje ** To proto, aby uložená data zůstala v bezpečí ** Ukázalo se však, že forenzní software může automatický restart zablokovat
Kategorie: Hacking & Security

New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

The Hacker News - 14 hodin 56 min zpět
Citrix has released security updates for a high-severity security flaw in NetScaler ADC and NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8.7 out of 10.0. "CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Syndikovat obsah