Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

Citrix patches NetScaler SAML zero-day exploited in attacks

Bleeping Computer - 4 Říjen, 2026 - 23:58
Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution. [...]
Kategorie: Hacking & Security

Anthropic asks Claude users to share voice data for AI model training

Bleeping Computer - 4 Říjen, 2026 - 12:53
Anthropic has started asking Claude users to voluntarily share their voice conversations to help train and improve its AI models. [...]
Kategorie: Hacking & Security

ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members

The Hacker News - 4 Říjen, 2026 - 09:22
A suspected member of the ShinyHunters digital extortion group, who goes by the online alias "Rey," has been allegedly detained by authorities in Jordan, Reuters reported, citing three people familiar with the matter. Rey, whose real name is Saif ‌al-Din Khader, is said to have been brought into custody on September 29, 2026, cooperating with the U.S. Federal Bureau of Investigation (FBI) andRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing

The Hacker News - 4 Říjen, 2026 - 09:20
A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations. The campaigns have impersonated prominent economists and AI policymakers, as well as a prominent Anthropic employee, to single out an AI policy expert at a Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Google Gemini could soon get full access to your Mac’s files, apps and the web

Bleeping Computer - 4 Říjen, 2026 - 01:12
Google's Gemini could soon access any file on your macOS device, open apps, browse the web, and perform actions without asking for permission every time. [...]
Kategorie: Hacking & Security

ShinyHunters hacker reportedly detained in Jordan, aiding FBI

Bleeping Computer - 3 Říjen, 2026 - 21:09
A suspected ShinyHunters hacking group member known online as "Rey" has reportedly been detained in Jordan and is cooperating with the FBI to help locate other members of the extortion group. [...]
Kategorie: Hacking & Security

MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics

The Hacker News - 3 Říjen, 2026 - 16:38
The U.K.'s domestic intelligence and security agency has warned that more than 100 academics have helped China boost its intelligence gathering efforts on behalf of Beijing's state security service. In a "Security Service Espionage Alert" issued on September 30, 2026, MI5 said the "primary purpose of the China General Technology Research Institute (CGTRI) 中国通用技术研究院 is to fund research that Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

The Hacker News - 3 Říjen, 2026 - 16:36
The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations. "In the Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Danish university DTU breach exposes data of up to 200,000 people

Bleeping Computer - 3 Říjen, 2026 - 16:35
The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data. [...]
Kategorie: Hacking & Security

The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations

The Hacker News - 3 Říjen, 2026 - 13:00
Featuring: Cybersecurity is being reshaped by the expansion of cloud infrastructure, AI, distributed systems, and increasingly complex digital environments. As organizations manage more identities, devices, data, and internet-facing infrastructure, security is shifting toward continuous visibility, control, and the ability to respond to risk at scale. This report examines how core areas of [email protected]
Kategorie: Hacking & Security

LiteLLM Key Reuse Lets Internal Users Forge Admin Tokens

LinuxSecurity.com - 3 Říjen, 2026 - 01:45
LiteLLM has patched a privilege-escalation flaw that can let an authenticated internal user forge an administrative session and reach command-execution features in some AI gateway deployments.
Kategorie: Hacking & Security

Apache HTTP Server Vulnerability Update Fixes Code Execution and Memory Flaws

LinuxSecurity.com - 3 Říjen, 2026 - 01:30
Apache released HTTP Server 2.4.69 on October 1, 2026, to fix security faults ranging from unwanted code execution to mishandled web responses.
Kategorie: Hacking & Security

Apache APISIX Vulnerabilities Let Attackers Impersonate Users and Bypass Protected Routes

LinuxSecurity.com - 3 Říjen, 2026 - 01:15
Apache detailed two Apache APISIX vulnerabilities in notices issued on October 1, 2026.
Kategorie: Hacking & Security

Apple changes full-disk access permissions to curb abuse from AI agents

Ars Technica - 3 Říjen, 2026 - 01:03

Apple says it is changing its macOS privacy settings to stop third-party app developers from misusing them to access message histories.

Friday's announcement comes two weeks after tech columnist Jason Aten said that Meta’s new general-purpose AI agent Muse sent him an unsolicited notification referencing a thread between him and a co-worker over Apple Messages. Aten said he never granted Muse permissions to read his messages and had assumed they were off-limits. Social media last week blew up with masses of people who agreed and said the incident showed that AI assistants given access to calendars, emails, messages, shopping accounts, and other resources are akin to a skill saw or other power tool. While potentially useful, they can do real damage if not used carefully.

He said/she said

Meta CTO David Singleton joined the fray with a rebuttal that appeared solid. For Muse to access Apple Messages, a user must manually give it two privileges. One is full-disk access, a macOS system-level permission. The other is to enable a Messages connector setting in Muse.

Read full article

Comments

Apache APISIX Denial of Service Flaw Can Disrupt Web Traffic

LinuxSecurity.com - 3 Říjen, 2026 - 01:00
Apache disclosed CVE-2026-94250 on October 1, 2026, warning that public access to a batch-request endpoint can let an attacker exhaust a gateway worker's memory.
Kategorie: Hacking & Security

Apache Camel Vulnerability Can Expose Files and Internal Services

LinuxSecurity.com - 3 Říjen, 2026 - 00:45
Apache's September 30, 2026 advisory, CVE-2026-88789, warns that an XML document can make an affected Camel Quarkus application read files or contact internal services.
Kategorie: Hacking & Security

Frontline Education breach exposes school district employee data

Bleeping Computer - 2 Říjen, 2026 - 21:01
Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee information, including Social Security numbers. [...]
Kategorie: Hacking & Security

Warlock ransomware breach SharePoint in water, telecom operator attacks

Bleeping Computer - 2 Říjen, 2026 - 20:33
The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access. [...]
Kategorie: Hacking & Security

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

The Hacker News - 2 Říjen, 2026 - 19:33
A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory. The gateway is the service that connects a GitLab instance to AI models, and only organizations that host their own gateway need to act. The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1. The flaw Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

The Hacker News - 2 Říjen, 2026 - 19:33
Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Syndikovat obsah