Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes

Bleeping Computer - 28 min 32 sek zpět
Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run. Multiple CVEs, patches, and Google downgrading two Antigravity findings. [...]
Kategorie: Hacking & Security

JadePuffer agentic attacks now target AI model data with ransomware

Bleeping Computer - 35 min 12 sek zpět
The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints. [...]
Kategorie: Hacking & Security

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

The Hacker News - 3 hodiny 20 min zpět
Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing campaign codenamed FakeGit. "FakeGit uses copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

New HollowGraph malware uses Microsoft Graph for stealthy C2 comms

Bleeping Computer - 4 hodiny 13 sek zpět
A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data. [...]
Kategorie: Hacking & Security

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

The Hacker News - 4 hodiny 13 min zpět
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer through a fake government ID-lookup site over WebDAV. What makes it more than a Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Gitea 1.27 Delivers 45 Security Fixes for Self-Hosted Git Servers

LinuxSecurity.com - 6 hodin 4 min zpět
For organizations that run a self-hosted Git platform, it’s no longer just about hosting static code repositories. Today, Git servers are responsible for deployment pipelines, API tokens, SSH keys, package repositories, and the automation scripts that push code directly. Confirm that the upgrade addresses known vulnerabilities but also provides production environments. 
Kategorie: Hacking & Security

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

The Hacker News - 7 hodin 9 min zpět
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050. Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so the activity looks Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

An AI SOC Evaluation Guide for Security Leaders

Bleeping Computer - 7 hodin 42 min zpět
Choosing an AI SOC platform requires understanding how it will perform in your own environment, not just during an evaluation. Prophet Security shares a practical framework for assessing AI SOC solutions, including how to validate accuracy, operating models, long-term reliability, and production readiness. [...]
Kategorie: Hacking & Security

⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More

The Hacker News - 8 hodin 10 min zpět
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had time to patch. Here is the full Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

How to Apply the Principle of Least Privilege in Modern Linux Environments

LinuxSecurity.com - 8 hodin 19 min zpět
We all spend a lot of time defending our systems from external threats, but the amount of damage an attacker can cause often depends on what happens after they get in. A single compromised account doesn't always lead to a major incident. The real danger begins when that account has far more access than it actually needs. That's exactly what the principle of least privilege is designed to prevent. By limiting users, services, and applications to only the permissions required for their jobs, yo...
Kategorie: Hacking & Security

Apple could ‘run the table’ on AI if it does things right

Computerworld.com [Hacking News] - 8 hodin 22 min zpět

Looking ahead just a short time, Apple could hold a powerful position in AI where it most makes sense: deployment.

Not only will the company offer up its own AI models for the kind of tasks millions use ChatGPT to do today, but it will provide more sophisticated on-device agentic models to help users get things done through Siri AI.

Apple also offers limited capacity for more complex tasks through Private Cloud Compute, and, in partnership with the likes of Google in the US and Alibaba in China, the company is giving users a trusted conduit through which to access even more sophisticated AI services. 

Deeply deployable

Critics can say it took Apple a long time to get to this point, but they also seem to think the company has finally got the mix right with its series 27 operating systems. Arriving late to a party doesn’t mean you won’t shine once you get there.

Apple is also coming up the inside lane around frontier AI, with iterative OS and hardware enhancements that mean its devices become increasingly effective for Edge AI use cases, on device — no cloud service required.

The company appears to be digging down into those use cases. Mark Gurman at Bloomberg recently predicted that future M7 Ultra Macs will support as much as 1.5TB RAM, making these systems more than capable of running full weight frontier models in people’s offices, colleges, and homes. 

While that does assume the AI-flationary memory market can supply that much RAM at prices humans can afford, it is also true that people are already running AI clusters using off-the-shelf Mac minis networked over Thunderbolt cables. It’s no stretch to believe this will continue to be the case, and that it will even broaden as the power/performance offered at the high end grows.

What’s wrong with good enough?

When combined with open AI stacks, particularly newly emerging varieties, Apple’s platforms should become leading contenders for private AI services and edge AI. Many business users will leap at the chance to offer their workers powerful, self-hosted, private AI services using one or more daisy-chained Mac Studios or Mac minis. The recent craze in deployment of both Macs to support OpenClaw instances shows they already are.

Ultimately, these different slices of momentum mean I agree with investor Jason Calacanis that Apple is in position to apply a great deal of pressure on OpenAI and Claude just by putting models on their devices. 

It’s also worth thinking about how people use AI today. How many of the queries made in the world right now constitute relatively simple tasks that could be transacted by on-device AI, such as the emerging new version of Apple Intelligence or even smaller LLM models running on device? You can even run PrismML’s 1-bit, 27-billion parameter Bonsai on an iPad using the Locally app, and that’s in the here and now.

What happens? Pretty soon you’ll find people recognize that they can already run the vast majority of their AI-augmented workflows using services they have on their existing device or can access on their on-prem Mac set-ups. And, of course, as people get used to running small tasks locally and larger tasks on premises, the actual space in which they need to turn to cloud-based frontier models will erode. That’s even as companies like PrismML work towards slimming down full-weight models so they don’t need to run on a server at all.

“It’s going to be wild when people have unlimited tokens on their desks,” said Calacanis in a podcast round table discussion.

Who has the most to lose?

The current incarnations of AI felt like they came from nowhere. Most people weren’t aware of the technology until returning to work after the 2022 holiday season. Since then, the industry has proliferated with dozens of competing models, most recently including powerful but affordable frontier models such as Qwen and Kimi.ai.

These models aren’t necessarily all as good as one another, but in many cases for much of what we do, we’ll find them to be good enough. That’s an existential crisis for some, as industry observers now think the inevitable pricing pressure means some services might have over-invested in capacity before finding any way to turn a profit.

Those profit-seeking services are the ones with the most to lose as Apple extends its hardware advantage, democratizing AI access for all while providing platforms suitable for edge AI, on-premises AI, private AI, and even AI access using third-party services. (The need for the latter will shrink as the capabilities of the former get better.)

Cupertino rising

What does this all mean? While the industry remains young, it is already fragmenting. And striding through the dust of that process comes Apple, equipped with the hardware, software, and approach to build its business even as the enterprise of first mover AI services erodes.

You can follow me on social media! Join me on BlueSky,  LinkedInMastodon and subscribe to my daily Apple-related news summaries at The Core.

Kategorie: Hacking & Security

Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine

The Hacker News - 9 hodin 29 min zpět
At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops. That is the finding of a cybersecurity advisory published July 10 by the AIVD and MIVD, the Netherlands' civilian and military intelligenceSwati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Hugging Face warns an autonomous AI agent hacked its network

Bleeping Computer - 9 hodin 46 min zpět
The Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production infrastructure using an autonomous AI agent system. [...]
Kategorie: Hacking & Security

Mythos Didn't Break Your Security Program. Your Exposure Window Could.

The Hacker News - 10 hodin 13 min zpět
The industry spent the initial months after Anthropic's April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AI-driven discovery overwhelm triage capabilities? How long would it take adversaries to weaponize Mythos findings at scale? Those questions were and remain valid. Yet they all stop short of [email protected]
Kategorie: Hacking & Security

Q&A: Why boutique consultancies might be better for AI rollouts than the bigwigs

Computerworld.com [Hacking News] - 10 hodin 43 min zpět

Major AI labs are unleashing forward-deployed engineers (FDEs) to try and grab enterprise customers. Large consultancies are dishing out tokens and assembling armies of consultants — both human and agent — to do the same.

But smaller firms are in the mix now, as well. AI is helping 28Stone Consulting, a New York-based, 230-person technology consultancy for capital markets, punch above its weight against larger rivals in the rush to deliver FDEs.

In this Q&A, Thomas Dolan and Frank Erickson, founders of 28Stone, argue that agentic AI isn’t a one-size-fits-all solution in vertical markets; success takes discipline, deep domain expertise, and human involvement to mitigate risk.

Many enterprises continue to struggle with the use of AI agents, which is consultancies are stepping in to get projects off the ground. 28Stone is among those that have published blueprints and methodologies on the development and delivery of agentic AI workflows with humans in the loop.

Computerworld spoke with both founding partners about why companies are still stumbling with agentic AI rollouts, and what a disciplined delivery process actually looks like.

After 15 years of delivering software for capital markets firms, is ‘AI-first’ a real distinction or just positioning?

Dolan: “We’re not shying away from being AI-forward. What needs to shine through is AI done intelligently — not stuff you get by buying some tokens for somebody on the trading desk. We’re an AI-first firm.”

Erickson: “And it’s temporary. At some point, AI is going to be synonymous with software development.

“The whole idea of an AI SDLC (software development lifecycle) versus an SDLC is going to be one and the same, a lot like cloud computing today. To not include AI in your strategy, you’d look like a COBOL vendor.”

What does agentic AI delivery look like?

Dolan: “We’ve got several AI initiatives delivering a pure agentic approach. We’ve doubled down on the human expertise wrapper in the SDLC. That doesn’t mean sacrificing any of the benefits of the AI models — quite the opposite.

“You don’t achieve anywhere near the same level of value from applying AI without keeping that expertise — industry, functional and technical — throughout the process.”

Where do humans stay in the loop once agents are doing the work?

Dolan: “We’re believers in starting with requirements discovery. Someone who knows the analytical nuances of a good business analyst is critically important; shaping a product owner’s business information through a markup file that can be fed into a BA agent, then treating the output as if it came from a very fast junior BA. Only then is the story complete.

“The developer takes that story, transforms it into the most efficient input, then owns the output, because they’re accountable for that code. A developer should own the code on both the input and output side.

“Your product owner, who knows the business, that’s great. But expecting them to interact with an agent and output enterprise code is ridiculous. It’s not a great plan.“

Why not just put one do-everything person in charge of AI and agents?

Erickson: “Every analyst, programmer or software engineer isn’t a great requirements analyst. And a great domain analyst with some technical background won’t know if the agent’s code is garbage, maintainable, performant.

“It’s unrealistic to expect one individual to have that breadth across domain, software engineering, testing, deployment. Clients ask all the time, and we push back: ‘Great, if you can find that guy, they’re few and far between.’ To deliver at the enterprise level, you need the human expertise, at depth.“

Dolan: “There’s system speed and latency, important in parts of finance. Then there’s speed of delivery, because other areas evolve quickly and time-to-market is critical.

“Our human wrapper may at first pass come across as a little slowed down. Maybe it is. But [Erickson] has a good analogy about one of the dangers of AI: you can end up going really fast in the wrong direction. By the time you look up, you’re way off base and have to backtrack.“

What about AI in your sector do you think is overhyped?

Dolan: “The hype around the ease of use of AI and the democratization of enterprise software delivery — that ‘anybody could do it now, it’s all being done by machines’ — is another idea that could prove costly in the long run.

“This do-it-yourself reaction is dangerous for clients, and for trust in the overall AI benefit, which is real. We compare it to the beginning of offshoring 20, 30 years ago: a golden idea that was going to cure everything. A lot of firms did it thoughtlessly, thinking it’s just labor arbitrage, and it almost inevitably failed. That all-or-nothing mentality missed that offshoring is an amazing way of getting better value for your dollar, but it has to be done thoughtfully, so the delivery process — the thing that ties it all together — stays unsevered.

“We’re seeing that now. I’ve heard, ‘We’ll just push a button, the machine’s building the system.’ The machine is not building the system. It might be writing the code, the story, running the tests.

The system is built by a team of engineers you bring in and trust. My fear is that people will say, ‘We don’t need this vendor or this technology team. I’ve got a product team. They might not be able to code at all, but they know the business,’ and it fails dramatically. 

“Then people say, ‘We played with AI, it’s not ready yet,’ and throw it all away. One of the best things we can do is ensure clients know the benefit is real.“

Erickson: “The hype can be summed up in a single phrase: vibe coding. That has done AI a massive disservice, because there’s a huge difference between vibe coding and enterprise software development, and some of the loudest proponents of AI are too latched on to it. In our industry, the only way to succeed would be a stable of unicorns. It just doesn’t scale. I get perturbed when our people internally refer to AI tooling as vibe coding; if they think that’s what they’re doing, they’re misunderstood.“

When you engage clients at different levels of AI maturity, how do you get them to a understand what works?

Dolan: “95% of our take on an agentic approach is in line with everyone else’s, but that 5% matters, especially in requirements discovery, in who’s giving the requirements and how they’re thought of. It can set you up for dramatic errors, given the speed at which you’re moving.

“There’s a dangerous human tendency we’re seeing among clients to try and cut corners at the start of a project and — in lieu of having deep, expert driven discovery sessions — just summarize what they may want using AI.

“We would hope our clients are collaborative, everyone understanding it’s early days. If a client insists on doing something we feel strongly against, like a product owner completely owning everything right up to code generation, that’s an issue we have to either push back strongly on or step out of the accountability for.“

AI body shops — LLM providers and giant consultancies — are emerging to help enterprises deploy AI. Does that model work?

Dolan: “Whether you’re partnering with an LLM or with an AI-first, generic software provider — ‘Hey, we’re not industry guys, but we know AI delivery’ — you end up, if you’re a bank or a broker-dealer, saying: ‘All right, we know our business, these guys know the AI side of it. What could go wrong? Put us together and we’ll have quality engineering.’

“The problem is what you miss: the know-how of putting industry and technical expertise together and actually delivering financial services systems. The people working at the generic delivery firms, whether an AI-only firm or a body shop somewhere, don’t have that capability.“

Does AI change the economics for smaller consultancies like yours competing against the big firms, and does it cut both ways?

Dolan: “Over our 15 years pre-AI, there were two recurring reasons we’d lose a project. One: ‘We’d love to work with you guys, given your subject matter expertise, but the costs just aren’t there compared to my budgets. I’m being forced to go to a body shop or an [offshore] delivery center.’ The other side of that coin: ‘We love your capabilities, but you’re a firm of 230 people and I need 300, 400 people.’

“AI changes the options for clients. You don’t have to sacrifice the niche vendor who knows your space just because you need a larger team or a cost target. AI levels the playing field and should allow smaller firms to compete with the larger, big-box generic firms, the Accentures of the world.“

Erickson: “It redefines what scale means. You can look at velocity as a measure of your cost to deliver, not a rate card. Scale can’t be defined in terms of headcount anymore. It’s got to be defined in terms of output.

“There’s a threat in it, too. If you’re an Accenture with hundreds of thousands of low-cost software engineers, how do you train all those people? I feel for them. But for us, a couple hundred people with a specific domain focus, it’s a huge opportunity.“

How has the profile of the people you and others hire changed with this agentic process?

Erickson: “You’re still looking for people with strong engineering and design backgrounds, and communication skills, because they interact across the software development lifecycle more than in the past.

“Many take too much joy in typing out perfect code. Sorry, I don’t need you writing for-loops and classes anymore. I need you reviewing them, understanding them, operating at a higher level. That’s a different kind of person: an engineer, not a programmer or a coder. On the [business analyst] side it’s similar: people took great pride in detailed user stories covering every path. Now it’s conversations, prompts, reviewing output — less doing, more interacting.

“More than ever, they have to be interested in the domain. They can’t just be, ‘I want to learn everything there is to know about Java.’ That’s too narrow. They don’t have to be an expert; they have to be interested. In our case, capital markets is a specific niche. The biggest challenge is getting familiar with the tools — finding time, while delivering for customers, to ramp up and make the mistakes you need to without jeopardizing projects.“

What about governance? Who’s keeping AI delivery and its costs under control?

Erickson: “This is evolving rapidly. People aren’t sure how to put governance around this. The most obvious is financial governance. People are starting to get hefty bills. One of our clients spent a million dollars on tokens over the last eight weeks alone. Sticker shock. The token-maxing policies are starting to show their flaws. It’s wild west still: learn on the fly, then figure out what needs to be governed.“

Are CIOs actually opening their wallets? And when they do, what’s the smarter way to invest?

Erickson: “There’s still a lot of caution. Forecasts keep going down on how long something should take. So: ‘I could wait three months and maybe still get it delivered by the same date someone’s promising me now, but for half the price. I’m going to wait and see when equilibrium is met.’ We haven’t seen the wallets open up like crazy — it’s slow adoption.“

Dolan: “One of our clients is looking at it from a productivity-boost perspective: instead of doing the same for less, I can do much more for the same. AI lets clients pull the trigger on things they wouldn’t have in the past — projects that might not have been approved pre-AI, where the costs have come down to a point that’s palatable with the business.“

Erickson: “And that’s the story we’re hoping to hear more of. There isn’t a huge cost anymore to exploring a business opportunity. The time and money that would have gone to a return-on-investment study could be spent on a proof-of-concept with AI, and the project done a few weeks later. Maybe [there’s] a hint of things to come, where decisions start being made quicker. 

“There’s a little fear on our side, though: a lot of tiny little projects is tough for a consulting business.“

Kategorie: Hacking & Security

Microsoft confirms Windows Server Update Services sync delays

Bleeping Computer - 10 hodin 55 min zpět
Microsoft is working to fix a known issue affecting Windows Server Update Services (WSUS) servers, which has caused synchronization problems for more than a week. [...]
Kategorie: Hacking & Security

Windows KB5121767 OOB update fixes shutdowns on some Dell PCs

Bleeping Computer - 11 hodin 36 min zpět
Microsoft has released emergency updates to fix a known issue causing some Dell PCs to shut down after installing the July 2026 Windows 11 security updates. [...]
Kategorie: Hacking & Security

Critical ServiceNow code execution flaw now exploited in attacks

Bleeping Computer - 12 hodin 13 min zpět
Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. [...]
Kategorie: Hacking & Security

New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

The Hacker News - 12 hodin 32 min zpět
Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro's Zero Day Initiative (ZDI) detailed it on July 15. A fix shipped on June 25 in 7-Zip 26.02. The overflow lets an attacker "execute code in the context of the current process," per the Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs

The Hacker News - 12 hodin 36 min zpět
A solo Russian-speaking threat actor known as "bandcampro" outsourced a chunk of their operations to Google's open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet. The findings come from an analysis of 200 Gemini CLI session logs between March 19 and April 21, 2026, which found the threat actor using AI, among other things, to crack passwords, set up a residential Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Syndikovat obsah