Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

Microsoft fixes broken copy and paste for Excel 2016 users

Bleeping Computer - 46 min 59 sek zpět
Microsoft has fixed a known issue that causes copy-and-paste failures for some Excel users after installing the September 2026 KB5002914 security update. [...]
Kategorie: Hacking & Security

RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall

The Hacker News - 2 hodiny 5 min zpět
Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices. "Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to deceptive third-party download portals, RatHat uses Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

USA mají zbraně na oběžné dráze. Poprvé to někdo řekl nahlas, a tím to skončilo

Zive.cz - bezpečnost - 2 hodiny 37 min zpět
** Spojené státy poprvé potvrdily zbraně pro ovládnutí vesmírného prostoru. ** Experti čekají rušičku nebo laserový oslňovač s vratným účinkem. ** Kinetické zásahy tvoří trosky, Pentagon proto sází na nezničující prostředky.
Kategorie: Hacking & Security

An undisclosed Microsoft presentation is now central to a multi-million dollar antitrust fight

Computerworld.com [Hacking News] - 8 hodin 9 min zpět

There’s a new development in a Microsoft antitrust case, originally filed in England’s High Court in April 2021, and it doesn’t look good for the tech giant.

A consent order from the UK Competition Appeal Tribunal is demanding documents from past and present Microsoft executives that may have a bearing on a £270 million (about $361 million) lawsuit filed by secondhand software reseller ValueLicensing. The company alleges that Microsoft offered incentives to customers to shift to subscription services without selling their pre-owned licenses.

Central to this development is a historic, potentially damning internal “Second-Hand Software” (SHS) presentation, referred to in the consent order as a “known adverse document.” The specific content of the presentation has not yet been made public, but Microsoft has until October 31 to explain why it did not disclose the presentation earlier.

Further, a confidentiality designation that previously applied to 11 documents relevant to the case has been lifted.

These developments represent “an inflection point in European tech litigation,” said Forrester senior analyst Dario Maisto.

“For Amazon (AWS), Google, and Microsoft, the signal is clear: Antitrust tribunals are fully comfortable examining software licensing mechanics as tools of anticompetitive lock-in.”

The allegations against Microsoft

Under EU law, it is fully legal to resell perpetual pre-owned (“second hand”) software licenses; software makers cannot use their Terms of Service (ToS) to override this right. ValueLicensing specializes in this secondary market, re-selling licenses for products including Microsoft Windows and Microsoft Office.

But the company alleges that Microsoft has stifled the supply of these pre-owned licenses in the UK and the European Economic Area (EEA) comprising 27 European Union member and non-member countries. It says Microsoft abused its market dominance and entered into agreements that “prevented, restrained or distorted competition” via clauses restricting customers from reselling their Microsoft perpetual licenses in return for subscription service discounts.

“The net result has been higher prices and less choice for customers, who have been steered into cloud-based Office365 and Azure subscriptions,” ValueLicensing claimed, pointing out that many enterprises, as well as publicly-funded organizations, rely on pre-owned Microsoft licenses to keep operating costs low.

The consent order is asking Microsoft to provide its “view” of whether those allegations are true, and to make “reasonable endeavors” to contact former COO Kevin Turner, former president and EVP Jean-Philippe Courtois, and former corporate VP of worldwide licensing and pricing Joe Matz. The company must document that it has done so by November 30.

The company must also file a witness statement from a former consultant addressing who within the company was aware of the SHS presentation and when they became aware of it; why the presentation was not disclosed as a “known adverse document”; when in-house legal counsel became aware of the presentation; what steps were taken to check for these types of “known adverse documents”; and the decision making process within the company when the presentation was located.

Microsoft is also being asked to search for specific terms in the emails and document repositories of Matz, Courtois, Turner, and several other named current and past research managers, former VPs and presidents, between July 2012 and June 2020.

The more than 40 search terms include “SHS,” “antitrust,” “competition,” “ValueLicensing,” “used licenses,” “do nothing,”  “competition,” “revenue,” and “discount licensing.” These documents cannot be designated “restricted” or “confidential,” according to the consent order. They must also be disclosed by November 30.

A witness statement from deputy general counsel Cynthia Randall has been paused.

Microsoft has said that any abuse of dominance was “objectively justified” and that the contractual terms at issue were “necessary and reasonable.” It also argued that anti-competitive effects were “outweighed by and proportionate to” certain benefits and efficiencies.

The company did not reply to a request for comment.

Microsoft is facing similar antitrust allegations from UK barrister Alexander Wolfson, who issued an opt-out class action claim in May 2025 alleging that public and private UK organizations that purchased software licenses, including those for Microsoft Office and Windows, were overcharged over a 10 year period due to Microsoft’s market practices.

Wolfson said in a release at the time that Microsoft’s actions had a significant and far-reaching impact on UK consumers, businesses, and public bodies. “With billions of pounds potentially at stake, this case is about ensuring fairness in the digital marketplace and ensuring even the largest tech companies play by the rules,” he wrote.

Implications for enterprise leaders

For enterprise CIOs, procurement leads, and IT financial managers, the current development holds “practical implications,” said Forrester’s Maisto: Organizations that surrendered perpetual licenses or agreed to contractual restrictions against reselling software as part of an enterprise agreement (EA) renewal or cloud commitment may have given up quantifiable asset value.

“The secondary market for perpetual licenses remains legally valid,” he pointed out.

CIOs should pay close attention to licensing “penalties” or inflated costs for running legacy software on third-party clouds, like AWS or GCP, versus Azure, he said. They should also evaluate the benefits of hybrid licensing strategies. Combining pre-owned perpetual licenses for static workloads with cloud subscriptions for dynamic workloads can yield significant cost savings compared to all-subscription models, Maisto pointed out.

Finally, he urged, “use these rulings as leverage during Microsoft agreement renewals.”

Kategorie: Hacking & Security

New RatHat Android malware uses AI to automate device control

Bleeping Computer - 17 Září, 2026 - 23:50
A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices. [...]
Kategorie: Hacking & Security

Linux Security Researcher Uses AI to Find Four Python Code-Execution Flaws

LinuxSecurity.com - 17 Září, 2026 - 23:15
Security researcher Sai Teja Erukude disclosed four alarming Python security flaws between June and August 2026 after combining specialized AI models with automated scanning and manual code review.
Kategorie: Hacking & Security

CISA Warns of Active Attacks on a Critical Cisco ISE Flaw

LinuxSecurity.com - 17 Září, 2026 - 23:00
Attackers are exploiting a critical Cisco ISE flaw that can open the product’s web management interface without a valid login. Cisco disclosed CVE-2026-76460 on September 16 and traced the problem to the way an ISE API handles authentication. A remote attacker does not need credentials or help from a user. A crafted request is enough to reach the vulnerable interface.
Kategorie: Hacking & Security

How a PowerPC Guest Could Trigger a KVM Use-After-Free

LinuxSecurity.com - 17 Září, 2026 - 22:45
A PowerPC KVM use-after-free could leave the Linux host kernel accessing a nested-guest object after another virtual CPU caused that object to be removed and freed. The upstream Linux correction adds a missing reference that keeps the object alive while KVM invalidates cached address translations.
Kategorie: Hacking & Security

Red Hat Quay Build Workflow Could Expose Registry Credentials

LinuxSecurity.com - 17 Září, 2026 - 22:00
As of September 17, Red Hat had documented a flaw in a Red Hat Quay build workflow that could expose container registry credentials to code retrieved from a mutable GitHub Action branch. Tracked as CVE-2026-85469, the issue created a software supply chain risk in the workflow used to publish Quay builder images.
Kategorie: Hacking & Security

OpenAI details more cases of AI agents taking unauthorized actions

Bleeping Computer - 17 Září, 2026 - 20:55
OpenAI has presented new examples of what they call "AI model misalignment" from the past six months, including unauthorized file uploads, following self-generated instructions, hiding mistakes, and leveraging exposed API keys. [...]
Kategorie: Hacking & Security

LLMs respond differently to harmful prompts when AI watermarking is used

Ars Technica - 17 Září, 2026 - 20:33

In response to a new European Union law, AI platforms are implementing new schemes for watermarking the content they generate. Anthropic recently disclosed its future Claude models will use SynthID-Text, an approach Google created and released as open source. It uses a secret key that subtly changes the process a model uses for choosing the next word in a sentence. Whereas a top next word choice might be “cloudy,” the key might change it to “overcast.” Anyone who knows the key can determine if it was generated by the platform using it.

New research shows that SynthID-Text can change not just word selection but also the tools a model invokes and the chances it will adhere to or disregard safety guardrails it has been trained to follow. The threat can become greater in the face of an adversarial prompt, in which an attacker attempts to cause a model to carry out a harmful action, such as revealing a password or other sensitive information. Instructions that normally wouldn’t be followed will, in some cases, be performed once the watermarking is deployed. The finding underscores the need for developers to thoroughly test how their LLMs and agents behave when watermarking is in place.

Changing safety behavior

“As compared to the same models without watermarking, it is definitely going to change their behavior, especially when we place it under adversarial conditions, or we make these models call tools when they’re powering an agent,” Andrea Siposova, an AI security researcher at Lasso Security, told Ars. “Watermarking is made to not be perceptible to a reader, but we know that when we are changing anything about what the model is generating, it is going to cause some tradeoffs, it’s going to show up somewhere.”

Read full article

Comments

Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

The Hacker News - 17 Září, 2026 - 20:08
A critical vulnerability in Check Point's Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network. The Security Management Server is the system that controls firewall policy and administrator access. Check Point has released a fix through its LivePatch update channel and says it has no indication that the flaw Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories

The Hacker News - 17 Září, 2026 - 19:32
Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them. This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold like a monthly subscription. Some attacks use new tricks. Others just reuse what was already lying around. Both work often enough. So the threat landscape is not getting cleaner. It is just Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Brevo supply-chain attack injected ClickFix scripts on customer sites

Bleeping Computer - 17 Září, 2026 - 19:11
Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware. [...]
Kategorie: Hacking & Security

Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

The Hacker News - 17 Září, 2026 - 17:37
Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a security announcement on September 15. The escape runs with the rights of the host account that runs the virtual machine. The flaw, CVE-2026-77179, is rated Critical, affects versions Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Anthropic tries to make Claude stickier with launch of Docs and Slides

Computerworld.com [Hacking News] - 17 Září, 2026 - 16:28

Anthropic is equipping its Claude AI assistant for more productivity work with the launch of Claude Docs and Slides.

While it’s already possible to create documents such as Microsoft Word and Google Docs files from Claude chats, the latest update, announced Wednesday, brings a rich-text editor directly into Claude.

Users ask the AI assistant to draft a document or slides via the chat interface, and Claude will ask clarifying questions before starting work. It will also leave comments to explain its choices.

Claude Docs files are then stored in the Artifacts tab and can be exported as Word, PDF, Google Docs, or markdown files. Documents can be shared with colleagues for real-time collaboration.

Anthropic

“Strategically, this signals Claude moving from an AI assistant into an agentic platform meant for full lifecycle of knowledge work,” said Arun Chandrasekaran, Distinguished VP analyst at Gartner.

He anticipates early user demand around “recurring, template-driven work,” such as status reports, board decks, and data-to-story reports.

“The likely near-term outcome isn’t wholesale replacement of alternative digital workplace tools, but it positions Anthropic as an entry point for workflows historically created in third-party tools,” said Chandrasekaran.

Claude Docs usage counts towards a customer’s Claude usage limits, and larger requests such as drafting a document with several sources takes up more of the limit. There are currently feature limitations, with no version history, access levels, or external sharing on Team and Enterprise pans. It’s also unavailable for customers that use “customer-managed encryption keys (CMEK), zero data retention (ZDR), or a HIPAA-ready configuration,” according to Claude’s support site.

Claude Docs and Slides are available in beta now on paid plans, rolling out to Pro and Max plans first. The feature is turned off by default for enterprise plans.

Anthropic

All of the major AI model providers are seeking ways to make their products stickier within customer organizations, said Jack Gold, principal analyst at J. Gold Associates. Some have targeted coding agents, while others, particularly Microsoft and Google, have AI assistants and agents that are connected into existing office productivity tools.

Microsoft’s Copilot is embedded across its Office suite, for instance, although users can also create documents directly from the Microsoft 365 Copilot chat interface.


“Microsoft and Google are bringing AI deeper into established productivity environments, while Anthropic is bringing more of the productivity environment into AI,” said Maria Bell, senior research analyst at FDM CCS Insight. “Over time, the competition may increasingly be over which becomes the primary interface through which knowledge workers get work done.”

Early findings of FDM CCS Insight’s ‘2026 Employee Workplace Technology Survey’ show that show that around half of employees that use generative AI at work do so to create or edit reports and documents.

It’s unlikely that native document editing features in Claude will result in a large-scale move from Microsoft or Google’s productivity suites, analysts say.

The updates to Claude this week have the potential to help users get more done, said Gold, “but it’s unclear how many users that already have productivity suites in place will choose to move to other tools,” even if they prefer Claude for its AI capabilities.

“The fundamental question is, if I am used to certain tools and they work for me, am I willing to change for the promise of working better? Not sure that will be a winning strategy,” he said.

“Microsoft and Google are deeply embedded in how people already work, and users have spent years becoming comfortable with their products and workflows,” said Bell.

“They are also increasingly bringing access to powerful AI models directly into those familiar environments. Anthropic therefore must do more than match document-creation features; it has to offer an experience compelling enough for users to build new habits around Claude,” she said.

As well as Anthropic’s Claude, it has long been rumored that OpenAI plans to build its own native productivity tools in ChatGPT that would bring it into more direct competition with Microsoft and other incumbent office software vendors.

Anthropic also announced that users can now invoke Claude Design in an ordinary chat. Claude Design, which generates visual outputs such as slides and prototypes, was previously available as a separate tool within the Claude app.  

In addition, Claude Cowork — which can perform multiple-stage tasks — and the regular Claude chat interface have now been combined, with Claude determining how to handle a request. This removes the need for users to decide which tool to use for a particular task, according to Anthropic. It’s not clear exactly how Anthropic decides where to route a request, however. Cowork queries are generally more token-intensive than the core chat interface.

“Claude can now figure out what a task needs, so what Cowork and Design can do is available from any conversation, with the context, skills, and connectors you already have,” the company said in a blog post.

The new Claude experience will roll out gradually, starting with Pro and Max customers. Anthropic said it will alert Claude Enterprise customers before any changes are made to their account.

Claude Enterprise costs $20 per user each month alongside consumption-based pricing.

Kategorie: Hacking & Security

Will Apple enter the server business?

Computerworld.com [Hacking News] - 17 Září, 2026 - 16:09

In a world of speculation, this week’s most interesting rumor says Apple may plan to enter the server business once again, with powerful systems running its own Apple Silicon chips.

It’s hard to dismiss the claims, particularly as Apple is already in the server business, with its Texas factory manufacturing servers for its Private Cloud Compute (PCC) cloud intelligence system. While those servers are only used internally —or externally if installed at third-party data centers for use with Apple’s ecosystem of products — they are still servers.

Apple is already in the server business

It’s also a business Apple has been in before. Many years ago, around 2002, I visited Apple in Paris, where the company demonstrated its Xserve and Xserve RAID systems. These were particularly aimed at the video and music industries and became quite widely used in those sectors. Apple discontinued Xserve in 2011, because the product sat outside its broad consumer-focused strategy.

Things were different then. You see, today’s Apple has billions of users. It has a fast-growing reach into enterprise tech — SAP recently updated its fleet of 60,000 Macs to macOS 27 on the very day the OS shipped, and there are hundreds of thousands of Macs in use at businesses worldwide. Apple has hundreds of millions of iPhones in active use across business. Apple even has the silicon to power these things.

The Apple Silicon advantage

You can’t ignore the computational advantage of Apple Silicon. The first leaked benchmarks for the M5 Ultra chip used in the new Mac Studio are incredibly impressive, with multi-core performance at an astonishing 52,516. That’s amazing performance from a Mac that costs an estimated 8 cents an hour to run at full capacity. 

Now imagine that price/performance ratio stashed in a server.

You don’t even need to imagine it, because MacStadium, AWS, and others already use Macs in server farms, with great success. MacStadium CTO Chris Chapman once told me that Apple Silicon is so power efficient his data centers would tell him the Macs he had racked with them were not using enough power for the space. (Data centers sell space by the square foot and calculate energy costs within that calculation.)

Making cloud cheaper and more secure

The computational performance per watt is an advantage to any user, but the cost benefits rack up pretty fast when you have a thousand machines racked up on the data farm. Apple even has a server operating system waiting in the wings — or did until it stopped offering macOS Server four years ago. 

Apple’s existing server production is focused on Private Cloud Compute. That system is impressive, (a) because Apple has opened it up to security experts to confirm it is secure, and (b) because it delivers data and privacy security equal to what its end-user platforms provide. 

But, as data centers blossom across Terra Firma, there’s a growing recognition of the need for sovereign AI, on-premises AI, and private AI. Think of it this way: We already know Macs can run some of the world’s most powerful LLMs very, very well. What’s wrong with introducing Apple Silicon-based servers to do the same thing? These things could even offer companies access to their own white-label private builds of Apple Intelligence, though I consider that unlikely. 

Why the speculation makes sense, and why it doesn’t

So, I see lots of reasons why speculation that Apple may re-enter the server market makes sense — though it may not be in a huge hurry, as the original claim is that these servers will run M8 Ultra chips. (Mark Gurman thinks it may be an M7 Ultra). 

Of course, speculation and conversation don’t always become fact. Merely because Apple is talking about servers again doesn’t mean it will advance those plans. 

Former Apple business-focused product marketing executive Todd Dailey doubts these plans. He says Apple is far more focused on consumer markets than enterprise. 

He also points out that if it were to offer servers, the company would need to consider providing same-day tech support and more flexibility around OS upgrades, adding that the business may not be big enough to justify the cost of implementing the plan. 

That doesn’t mean Apple isn’t considering it, just that once you bounce the idea through a few real-world weeds there may be obstacles to making it happen.

Is it time for iCloud Ultra?

I do think there are signs Apple is taking enterprise markets more seriously. I also think that as PCC deployment expands, it makes sense for Apple’s server teams to build a product road map for the future of PCC servers like any other Apple product, even if they are only used to support its own server-side AI.  

But I also think that if the company were to go ahead to make this happen, the solution would be aimed at developers and businesses seeking a uniquely private way to deploy sophisticated AI outside of the thrall of the frontier models, chipping a little more business away from those over-leveraged entities as it does. 

The thing is, if that’s the case, then is it servers Apple is thinking of building, or server farms offering hosted services for a price? An iCloud Ultra service for developers and enterprise users may perhaps make more sense. I guess we’ll have to wait and see.

Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSkyLinkedIn, or Mastodon.

Kategorie: Hacking & Security

Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords

The Hacker News - 17 Září, 2026 - 16:03
The Iran-linked "hacktivist" persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE. "HEAVYGRAM offers builtin commands supporting remote command execution, system, network and process information discovery, data and Telegram session files exfiltration, screenshot capture, DLL sideloading, Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

What Recent AI-Powered Attacks Mean for Your Identity Security

Bleeping Computer - 17 Září, 2026 - 16:01
AI is making credential theft faster and easier to scale, giving attackers more opportunities to abuse valid identities. Specops explains why identity security must go beyond successful authentication by verifying that both the user and the device requesting access can be trusted. [...]
Kategorie: Hacking & Security

Windows 11 24H2 Home and Pro reach end of support in October

Bleeping Computer - 17 Září, 2026 - 15:09
Microsoft reminded customers this week that devices running Windows 11 24H2 Home and Pro editions will stop receiving updates next month. [...]
Kategorie: Hacking & Security
Syndikovat obsah