Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

Canadian pleads guilty to Snowflake cloud data-theft attacks

Bleeping Computer - 5 Srpen, 2026 - 23:53
A Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims. [...]
Kategorie: Hacking & Security

Hackers run khunt post-exploitation toolkit from Oracle database

Bleeping Computer - 5 Srpen, 2026 - 21:55
Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate network. [...]
Kategorie: Hacking & Security

Microsoft moves to limit AI use by its employees

Computerworld.com [Hacking News] - 5 Srpen, 2026 - 20:46

Until recently, it was common for companies and organizations to engage in “tokenmaxxing” — that is, maximizing their use of AI. But with AI costs going up, companies are now looking to save money, a trend underscored by a recent Microsoft decision to limit AI use by its employees.

“As we ramp up our use of GitHub Copilot to achieve our goals, we all need to be mindful of how we consume tokens,” Microsoft Executive Vice President Jay Parikh wrote in an email to the company’s employees.

Starting now, each department at Microsoft will be allocated a certain pool of tokens, with usage then adjusted up or down as needed.

The change prompted concern among some employees. “It’s very telling that a company that has invested so much in AI and subsidized so much AI inference is now advising its own employees to cut back on spending,” an anonymous Microsoft employee said in a comment to 404 Media.

Kategorie: Hacking & Security

Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

The Hacker News - 5 Srpen, 2026 - 20:44
A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks. The server-side gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake software download. Microsoft Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes

The Hacker News - 5 Srpen, 2026 - 20:33
OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes. To that end, it banned a coordinated network of ChatGPT accounts likely originating from Southeast Asia and operating from the city of Poipet, a region with extensiveRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

COLDCARD security audit phishing attack installs remote access tool

Bleeping Computer - 5 Srpen, 2026 - 19:49
A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software. [...]
Kategorie: Hacking & Security

Apple’s memory crisis is a big red flag for tech

Computerworld.com [Hacking News] - 5 Srpen, 2026 - 18:54

The memory crisis is getting worse for Apple, which is struggling to get enough memory chips together for its upcoming iPhone 18 Pro series smartphones. That’s according to tech journalist Tim Culpan.

As he details it, Apple and its assembly partners are still attempting to secure sufficient quantities of memory, and though they’re confident they can meet initial demand once the devices are introduced, they apparently remain concerned that wait times could rapidly extend as retail inventory evaporates.

Apple’s manufacturing process compounds the problem. The A20 processor is packaged with memory using a new TSMC process, meaning processors are reportedly piling up while manufacturers wait for memory chips. You should read Culpan’s report to get the full picture.

What’s the frequency?

You don’t need to read between the lines to see the challenge. Despite demand for TSMC’s new processors, Apple seems to have been able to secure the supply it needs. But when it comes to churning out the final packaged chips memory, supply constraints have created significant obstacles to producing in quantity.

This is bad for Apple, particularly as the challenge doesn’t appear to be confined to iPhones; customers are experiencing delays getting new Macs. “Many new orders are now not arriving until September,” Bloomberg’s Mark Gurman wrote earlier this week

It isn’t just Apple that will be impacted by the AI-driven memory drought. The scale of Apple’s orders is among the greatest in the industry, and if its product plans are feeling the pain, every other manufacturer will be feeling it as well.

Conscious uncoupling

This is certainly in tune with expectations voiced at the beginning of the year when Ranjit Atwal, senior director analyst at Gartner, warned: “This is the steepest contraction in device shipments witnessed in over a decade. Higher prices will narrow the range of devices available, prompting buyers to hold on to devices for longer, fundamentally altering upgrade cycles.”

Gartner in February predicted a 10.4% decline in global PC shipments and an 8.4% drop in smartphone shipments as a result. The analyst also predicted a 130% surge in combined memory and SSD storage prices by the end of this year, with steep product price increases to follow. Recent data from IDC, Gartner, Counterpoint, and Omdia confirm PC market declines, but only at around 4% (the estimates vary).

Today’s report from Culpan suggests we’ve not yet experienced the full extent of this decline — hinting that while the initial fall reflected price, the next impact will be defined by lack of supply. While this hurts big brands like Apple, smaller entities could be left high and dry. 

When the chips are down

It is interesting to reprise Atwal’s warning in February that, “the sub-$500 entry-level PC segment will disappear by 2028,” as this seems to be what’s happening. That’s something long-time Mac users like me find particularly ironic, given it was only this year Apple briefly offered up its superbly priced $499 MacBook Neo. The industry direction we’re seeing now suggests we’ll never see that again, though the success of that device gave Apple a phenomenal 28.7% increase in sales in its just-revealed June quarter.

Despite memory supply challenges, Apple seems to be faring fairly well, with market share increasing across its business. Counterpoint data reveals that Apple has achieved an astonishing 65% share of the premium smartphone market. In part, that’s because as an existing premium brand, Apple was able to better absorb rising memory costs through higher margins and reduced promotions. Realistically, this means we can expect an overall increase in iPhone prices when the new range is announced up to $300 more, Jeff Pu, of GF Securities, recently claimed

Building the moat

Once again, what’s sustainable but difficult for larger brands such as Apple is existential disaster for smaller players — and it’s only now a matter of time before we see some real blood. That’s particularly true in smart home and device markets, where manufacturers lack the margins to sustain higher memory prices while delivering products customers can afford. A recent Global Electronics Association report tells us 62% of electronics manufacturers are already experiencing constrained availability or extended lead times. It also tells us 82% expect rising prices, including 33% who cite a “significant increase.”

This is already being felt by consumer and business users, as networking equipment is experiencing significant shipping delays. So, while we may find ourselves waiting a month or more for an iPhone, the wait for new routers, external storage devices, and home automation systems could be even longer once available inventories disappear. 

This doesn’t appear to be a short-term challenge; a recent Digitimes report warns that vendors have already sold their entire allocation of memory capacity for 2027.

Don’t even get me started on the likely impact on the military and defense markets as high-performance memory, storage, and processor supplies become constrained. Just like declining river levels in Europe, lack of memory threatens severe disruption. With so much turbulence impacting the tech economy, all we need now is for one or more of theinvestor-supported AI companies that have helped create the memory shortages to default on loan payments.

Got to keep the customer satisfied

Eager to protect sales, Apple recently introduced the Apple Upgrade leasing service in the US. This should enable consumers to purchase new devices at prices more sustainable to them over time. Apple isn’t alone in taking such action, which will inevitably extend beyond America.

“OEMs are expanding financing, trade-in and buyback programs to improve affordability,” said Counterpoint’s Harshit Rastogi. “Samsung has also expanded its Galaxy Forever program to several markets to make flagship devices more accessible.” 

Such schemes are all well and good, of course. Consumers will embrace them in hopes of a better tomorrow. But the tech industry is not immune to the wider constellation of existential challenges impacting economic environments.

In the end, if Apple, the industry’s biggest buyer of advanced components, is struggling to secure memory, the rest of the electronics sector is likely to face even greater challenges. For consumers, the initial impacts will be longer waits and higher prices. But the longer term consequences could be slower innovation and increased consolidation across the industry.

You can follow me on social media! Join me on BlueSky,  LinkedInMastodon and subscribe to The Core.

Kategorie: Hacking & Security

CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws

Bleeping Computer - 5 Srpen, 2026 - 17:51
The U.S. Cybersecurity and Infrastructure Security Agency is giving federal agencies three days to mitigate vulnerabilities in IBM Langflow, N-central, and Apache Tomcat, all actively exploited. [...]
Kategorie: Hacking & Security

Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt

The Hacker News - 5 Srpen, 2026 - 17:36
Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on underground cybercrime forums and messaging platforms. One such service, Poison Claude, claims to offer access to Anthropic's large language models (LLMs), including Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6. "Advertisements for Poison Claude Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports

The Hacker News - 5 Srpen, 2026 - 17:14
Two security flaws in Paperclip could let attackers execute commands on a network server or a developer's computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on importing a malicious agent and starting it. A third flaw could expose sensitive data and control-plane details through application programming interface (API) routesSwati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Google Blogger locks hundreds of blogs in malware false positive

Bleeping Computer - 5 Srpen, 2026 - 16:59
Google has locked hundreds of Blogger websites after a false positive claimed they violated its "Malware and Similar Malicious Content" policy, with some sites deleted from the platform. [...]
Kategorie: Hacking & Security

Reducing Attack Surface Without Breaking Production

LinuxSecurity.com - 5 Srpen, 2026 - 16:40
When people talk about Linux hardening, the conversation often quickly turns to enterprise security platforms, EDR agents, and complex monitoring stacks.
Kategorie: Hacking & Security

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

The Hacker News - 5 Srpen, 2026 - 16:27
HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django. The three most serious: An unauthenticated flaw in Veeam's console that hands over a managed agent's credentials, rated 9.5 A cross-tenant flaw in HashiCorp's MCP server that lets one user's Terraform token be reused for later users'Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

How AI-powered phishing killed blocklists for good

Bleeping Computer - 5 Srpen, 2026 - 16:01
AI is helping attackers create disposable phishing infrastructure and rapidly evolving toolkits that blocklists cannot track fast enough. Push Security explains why browser-level, technique-based detection offers a more durable defense than relying on domains, signatures, and other known-bad indicators. [...]
Kategorie: Hacking & Security

Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain

The Hacker News - 5 Srpen, 2026 - 15:41
Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer. The new dead drop resolver approach, observed in two trojanized npm packages "bianira-ui" and "fluid-type-ui," has been codenamed NullReceiver by Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch

The Hacker News - 5 Srpen, 2026 - 13:43
A memory corruption flaw in the Linux kernel's Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distributions, and a public exploit ships with pre-built records for roughly 800 kernel builds. The vulnerability, tracked as CVE-2026-64531 (CVSS score: 7.8) and codenamed OVSwrap by its discoverer, was disclosed by security researcher Asim Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk

The Hacker News - 5 Srpen, 2026 - 13:43
Kali365 is turning a legitimate Microsoft login into a gateway to corporate data. The phishing kit targets US organizations with attacker-controlled device codes that victims approve on Microsoft's real authentication page. Once access and refresh tokens are issued, attackers may retain access to email, documents, and cloud resources, creating a direct path to data exposure, financial fraud, [email protected]
Kategorie: Hacking & Security

Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup

The Hacker News - 5 Srpen, 2026 - 13:04
An unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in versions 1.22.1 through 1.27.0. No login, no repository write access. A public repository and crafted Org-mode markup are enough. The flaw is fixed in Gitea 1.27.1. The file-read flaw is tracked as CVE-2026-59774, rated Critical with a CVSS score of 9.8, and received its Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Leaked n8n API Tokens Exposed Live Instances to Credential Theft

The Hacker News - 5 Srpen, 2026 - 12:35
GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without exploiting a software vulnerability. We scanned public GitHub commits for exposed n8n API tokens and identified 4,576 unique credentials associated with 1,255 hostnames. Of the 896 [email protected]
Kategorie: Hacking & Security

6 things you should know about Google’s new selfie sign-in system

Computerworld.com [Hacking News] - 5 Srpen, 2026 - 11:45

Losing access to your Google account might just be the epitome of a modern-day nightmare.

Especially if you’re using Android and even more so if you’re invested in lots of different Google services on top of that, the amount of access and info connected to that one single sign-in is just staggering. Think about it: You’ve got everything from your Android apps and settings to potentially your email, your documents and spreadsheets, and all of your assorted files in Google Drive. And that’s to say nothing of all the images you might be backing up to Google Photos, the notes you might be storing in Google Keep, and even random things you might not think about like your browsing activity in Chrome or your location-related data in Maps.

It’s a lot, to say the least. And that’s precisely why it’s so important to think about your Google account security proactively and do everything you can to (a) make sure no one else ever gains access and, equally important, (b) make sure you never lose access to that all-encompassing sign-in.

At this point, you’re hopefully already doing smart stuff like using a unique and secure password and relying on two-factor authentication to add an extra layer of security beyond that — or maybe using a passkey for an alternate form of two-factor protection.

But even with all of those layers, the issue still remains of what happens if for any reason you aren’t able to get into your own Google account one day. And now, Google’s got a new option to help you make sure that nightmare never actually comes to pass.

Suffice it to say, it’s well worth your while to consider. But there are some important things you should know about it first.

[Get fresh Googley insight in your inbox with my free Android Intelligence newsletter. One new and useful tip every Friday!]

The ins and outs of Google selfie sign-in

The system of which we speak is an option to use a sophisticated selfie of yourself to sign into your Google account in an emergency — if all of your usual methods are for whatever reason not getting you through the gate. It happens more often than you’d think. And having multiple secure workarounds in such a scenario could be a massive lifesaver if it ever happens to you.

Depending on where you look, the option is called “selfie for sign-in,” “video verification,” or sometimes just “selfie video.” (Hey, this is Google we’re talking about here. Branding has never been a strength.) The system was announced in a random blog post a couple weeks back and has been slowly but surely showing up under the hood for accounts around the world ever since — but you’d never know it unless you happened to poke around in the exact area of your Google account settings where the option appears.

In my experience so far, it seems most average Android-owning animals are woefully unaware of its existence — and those who are aware of it are mostly perplexed by how exactly it works and if or when it’s advisable to use.

I’ve set it up on my own personal Google account, and I’ve explored every last nook and cranny. Here’s everything there is to know:

1. Selfie sign-in is super simple to set up

Seriously — it couldn’t be much easier. Just go to this page within the Google account settings site on a device with a camera (like, y’know, your phone or maybe an Android tablet).

Provided the feature is available on your account now, you’ll just click a couple o’ quick buttons to get the process started, then you’ll follow some simple prompts to stare into your camera longingly for a few moments.

Setting up a Google selfie sign-in is surprisingly swift ‘n’ simple.

JR Raphael, Foundry

The system will ask you to turn your head in specific directions. Then, it’ll take a handful of seconds to process and save your stunning turn on the virtual runway.

The process takes less than a minute to verify and save your selfie video.

JR Raphael, Foundry

And — well, that’s pretty much it.

2. Your selfie video is only for access to your Google account — not your phone or tablet

This is slightly confusing, since most modern Android devices offer the ability to use biometrics on the lock screen and show your face to unlock the phone itself — but the selfie sign-in system we’re speaking of here has nothing to do with any of that. It won’t unlock your device in any scenario or have any connection to any specific phone or tablet.

It’s connected purely to your Google account, and its sole purpose is acting as a mechanism to let you sign into that account — not to unlock or access any specific piece of hardware.

Speaking of which…

3. It’s only there as a last resort

Once you set up your selfie sign-in, odds are, you’ll never actually think about it again or have a reason to use it. Anytime you sign into your Google account, you’ll still use your standard password, passkey, and any two-factor authentication you’ve placed on the account.

The selfie path is there only in the event that all those regular methods are for some reason failing you. It’s unlikely, but it’s not impossible. And with your selfie video saved, if that situation ever arises, you’ll have an easy alternate way to prove your identity — by submitting a live on-the-fly selfie video and allowing Google to match it with your original saved one — so you can avoid getting locked out.

4. The selfie sign-in is designed to be both private and secure

When it comes to matching a saved selfie video and a new live one, Google requires different movements to verify validity and avoid any impersonation attempts.

Google says the data from your saved selfie video is always encrypted, too — not just in transport but also at rest, when it isn’t actively being used — which means no one else should ever be able to access it or do anything with it. You can always opt to delete a saved selfie video entirely, if you want, via that same Google account settings page.

And on that note…

5. You can prevent your selfie video from being used for any form of training

Lots of folks are understandably uneasy about the idea of their personal data — including their personal faces! — being used for any manner of machine learning these days. Google does ask for permission to do that and anonymously lean on your submission to help improve its facial recognition systems when you sign up for the selfie sign-in option, but critically, you can easily say no thanks.

When you’re in the midst of the selfie sign-in setup, look for the option to “Improve Google services.” It’ll appear at the bottom of the initial service agreement.

Keep that box unchecked, and your selfie video will never be used for any form of training or other purposes.

JR Raphael, Foundry

As long as you don’t check the box in that area, your selfie sign-in data will never be used for anything other than its primary intended purpose. And if you ever change your mind or are unsure of how you initially answered, you can also always revisit and revise that decision on that same Google account settings page.

The option to opt out of model training is always available on the selfie video settings screen.

JR Raphael, Foundry

6. Selfie sign-ins are (so far) only for individual Google accounts

With this initial rollout, Google’s selfie sign-in option is not available for accounts that are part of a Google Workspace team or organization. That kind of makes sense, since in any such situation, you could always turn to an admin for help if you were ever to lose account access, anyway.

This is something more intended for individual Google accounts, where you’re on your own and largely out of luck if you ever lose access. So whether you’re conducting business from an individual account or using an individual account alongside a Workspace-connected company sign-in, it’s something to consider for that part of your online identity.

The only other noteworthy asterisk is that selfie sign-ins won’t work with accounts where Advanced Protection is enabled. Advanced Protection is an extra-heightened form of Google account security created for people in the public eye or otherwise at an elevated risk of a targeted attack, and so it deliberately makes it much more difficult to get into an account in ways that go above and beyond what’s necessary for most ordinary organisms. If you have Advanced Protection on for your Google account, selfie sign-in won’t be available for you.

But for the rest of us, it’s a powerful new path that could prevent an unthinkable nightmare — and all you’ve gotta do is take two minutes to set it up now and then hopefully forget all about it.

Got Android? Check out my free Android Intelligence newsletter to get an exceptional new tip in your inbox every Friday.

Kategorie: Hacking & Security
Syndikovat obsah