Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

Cyber exec arrested in case allegedly tied to ShinyHunters hackers

Bleeping Computer - 10 Říjen, 2026 - 17:07
Canadian cybersecurity executive Edward Dubrovsky has been arrested in Pennsylvania in connection with alleged extortion activity that multiple reports have linked to the FBI's ongoing crackdown on the ShinyHunters hacking group. [...]
Kategorie: Hacking & Security

ARTEX AI, Claude agents used in cyberattacks on South Korean banks

Bleeping Computer - 10 Říjen, 2026 - 16:16
The cyberattacks that shook the South Korean financial sector earlier this month were launched by a Chinese hacker using the ARTEX AI penetration testing suite and Claude agents. [...]
Kategorie: Hacking & Security

Zítra se mění kořenové klíče internetu. A teprve podruhé v historii. Co to vlastně je a jak to funguje

Zive.cz - bezpečnost - 10 Říjen, 2026 - 15:56
Internet v neděli dostane nové kořenové klíče. Zkontrolujte své DNS resolvery, píše na blogu CZ.NIC jeho výkonný ředitel Ondřej Filip. A i když ve své prosbě míří především na správce sítí a běžní smrtelníci si vůbec ničeho nevšimnou (pokud tedy oni správci neudělají nějakou tu kulišárnu), pojďme ...
Kategorie: Hacking & Security

Criminal IP Introduces AITEM as the Next Evolution of Attack Surface Management

Bleeping Computer - 10 Říjen, 2026 - 14:30
Traditional attack surface management helps organizations discover exposed assets, but visibility alone is not enough to address threats. Criminal IP introduces AITEM, an AI-powered approach that connects exposure discovery with investigation, risk prioritization, and response. [...]
Kategorie: Hacking & Security

The Third-Party Agent Problem: Why Security Built for AI You Chose Misses the Agents You Didn't

The Hacker News - 10 Říjen, 2026 - 13:00
In environments studied for the 2026 State of Agent Security Report, roughly 1,280 third-party products now embed AI. About 282 of them sit behind single sign-on. The other thousand are invisible to identity infrastructure by default, not because anyone hid them, but because an identity stack can only govern what authenticates through it, and most agents never do. That gap is the clearest [email protected]
Kategorie: Hacking & Security

Anthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection Flaws

The Hacker News - 10 Říjen, 2026 - 11:18
Anthropic on Friday said it's cutting off live internet access for all its internal evaluations following the discovery of new incidents in which its artificial intelligence (AI) models exhibited misaligned behavior and targeted real websites. The AI company said it identified four broad categories of unintended model actions during evaluations and internal use of Claude - Claude Mythos Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Anthropic Launches AI Vulnerability Scanner for Open-Source Projects

LinuxSecurity.com - 9 Říjen, 2026 - 23:05
Open-source maintainers can now apply for free security scans from Anthropic.
Kategorie: Hacking & Security

Go Security Update Fixes 15 Flaws in Servers and Toolchains

LinuxSecurity.com - 9 Říjen, 2026 - 23:00
Go 1.27.2 and 1.26.9 arrived on Oct 8, 2026 with corrections for 15 security flaws.
Kategorie: Hacking & Security

CI/CD Security Flaw in AWS CDK Could Pull Host Files Into Builds

LinuxSecurity.com - 9 Říjen, 2026 - 22:45
A file on a build machine could end up in a cloud deployment bundle because of a flaw disclosed by Amazon Web Services (AWS) on Oct 8, 2026.
Kategorie: Hacking & Security

Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks

Bleeping Computer - 9 Říjen, 2026 - 22:31
Hackers are abusing legitimate Bing search-result redirects as click URLs in Google search ads to direct users to fake Claude installers that deliver ClickFix attacks. [...]
Kategorie: Hacking & Security

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

The Hacker News - 9 Říjen, 2026 - 21:14
Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories. "Using the account of Takashi Kitao, author of the 18,400-star game engine pyxel, the attacker pushed a malicious workflow to 27 repositories starting at 13:20 UTC," StepSecurity Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

PC shipments fall 20.1 percent in “sharpest decline” since Q1 2023

Ars Technica - 9 Říjen, 2026 - 20:54

PC shipments saw a steep drop of about 20 percent in Q3 2026, analysts reported this week.

The industry saw its “sharpest decline since “Q1 2023," Omdia said in an announcement toady. Global shipments of laptops, desktops, and workstations fell 21.2 percent year over year (YoY) to 58.1 million devices, the analyst said.

Desktop PC shipments (including desktop workstations) decreased 23.5 percent to 11.7 million units, and laptop shipments (including laptop workstations) declined 20.6 percent to 46.4 million, per Omdia.

Read full article

Comments

FBI Arrests Another ShinyHunters Suspect Reportedly Involved in Its Jobs Portal Hack

The Hacker News - 9 Říjen, 2026 - 19:45
The FBI has arrested another suspected co-conspirator of ShinyHunters, FBI Director Kash Patel said on October 9 in a post on X. ShinyHunters is the extortion group that said in September it had breached the FBI's jobs portal and stolen sensitive data on almost all FBI agents and job applicants. The FBI has not named the suspect, and no charges have been made public. The Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto

Bleeping Computer - 9 Říjen, 2026 - 19:17
Threat actors are exploiting one critical and one medium-severity vulnerability still unpatched in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners. [...]
Kategorie: Hacking & Security

FBI arrests another suspected ShinyHunters hacker after agency breach

Bleeping Computer - 9 Říjen, 2026 - 19:02
The FBI has arrested another suspected member of the ShinyHunters extortion group believed to be involved in the recent breach of FBI systems, Director Kash Patel announced Friday. [...]
Kategorie: Hacking & Security

P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands

The Hacker News - 9 Říjen, 2026 - 18:29
Cybersecurity researchers have disclosed details of a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword. "Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker's infrastructure," iVerify said in a new report published Thursday. The name Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Bidding war over key component could eliminate third hard disk maker

Computerworld.com [Hacking News] - 9 Říjen, 2026 - 17:59

What if the three remaining hard disk manufacturers became two? Seagate Technology and Western Digital control 90% of the market, according to market researcher TrendForce, with Toshiba picking up the crumbs.

Seagate and WD both make their own magnetic drive heads, but Toshiba relies on a third party, TDK, which also sells to Seagate and WD when they need extra capacity.

Seeking to guarantee supplies of this critical component, Toshiba made a bid for TDK’s drive head business earlier this year, according to Bloomberg. Concerned that this could affect its ability to meet the growing demand for hard disks from AI data centers, Seagate made a counteroffer, Bloomberg reported. TDK is staying mum.

If Seagate were to capture the TDK unit it could knock Toshiba out of the hard disk market altogether, according to Bloomberg.  

While Toshiba is reliant on its suppliers for technological advances, WD and Seagate continue to innovate. In February, Western Digital announced two technologies aimed at speeding up drive throughput: high bandwidth drive technology (HBDT) and dual pivot technology (DPT).

Western Digital said HBDT will enable simultaneous reading and writing from multiple heads on multiple tracks, delivering up twice the bandwidth of conventional HDDs.

In July, Seagate launched a hard disk packing 30TB into a 3.5-inch enclosure using its Heat-Assisted Magnetic Recording (HAMR) technology, and announced plans to release 32TB and 36TB models.

This article first appeared on Network World.

Kategorie: Hacking & Security

Ransomware consultant said he would decrypt data, is accused of paying ransoms instead

Computerworld.com [Hacking News] - 9 Říjen, 2026 - 17:48

The owner of a ransomware remediation company is facing trial for defrauding customers.

Zohar Pinhasi, also known as “Zack Silver” and “Zack Green,” has been arraigned in New York on wire fraud charges for allegedly defrauding clients of his ransomware remediation company, MonsterCloud.

Pinhasi falsely claimed he could recover documents encrypted by ransomware without paying a ransom, according to district attorney Joseph Nocella. “The defendant re-victimized his clients while extracting a hefty profit for himself,” Nocella said.

MonsterCloud claimed to offer an alternative to paying the ransom. Its website said that, thanks to its decryption techniques, “our team specializes in helping businesses recover their data without succumbing to ransom demands.” 

However, the indictment alleges that rather than using any technology, Pinhasi simply paid the cybercriminals in exchange for a decryption key with which MonsterCloud employees would then an attempt to unlock their clients’ files. It is alleged that Pinhasi typically charged clients a fee that was substantially higher than the ransom payment. For example, in 2023, he made a payment of $8,200 to a cybercriminal while charging a client $150,000.

There may be several reasons why clients chose to use MonsterCloud. US government advice (echoed by other governments) is not to pay ransoms as it may encourage more attacks, and victims may not get their data back. In addition, in some cases, if the attackers are from a country or group subject to trade sanctions, making a payment may actually be illegal, leaving the victim facing criminal charges.

There may be other factors at play. “Cases vary; sometimes negotiators simply overcharge for their services. In other cases, they may inflate the final amount, saying, for instance, that 50 percent extra is to ensure a third-party validation of secure data erasure or something similar that the client would buy,” said Ilia Kolochenko of cybersecurity company ImmuniWeb.

He warned that there were several techniques being used to extract additional money from ransomware victims.

“Some will be contacted by fake law enforcement agencies, which typically promise to find and arrest the hackers, but also mention the victim’s civil liability for the data breach and ask to prepay a bond for an eventual regulatory fine. Other victims may be contacted by fake cybersecurity companies, which claim that they have already found their stolen data on the Dark Web and ask for money to ‘securely erase’ the data from the dark web to avoid bad publicity and regulatory sanctions,” he said.

Similar cases have come to court recently, said Kolochenko, one in July involving a Florida business and another targeting a Latvian national in May.

This article first appeared on CSO.

Kategorie: Hacking & Security

Germany arrests alleged core Qilin ransomware member after extradition

Bleeping Computer - 9 Říjen, 2026 - 17:38
Germany has arrested a Russian national suspected of being a leading member of the Qilin ransomware group following extradition from Japan earlier this month. [...]
Kategorie: Hacking & Security

How to keep AI agents within their permissions

Bleeping Computer - 9 Říjen, 2026 - 16:01
AI agents can use valid credentials to perform actions beyond their assigned permissions, creating risks that traditional access controls may not prevent. Token Security explains how organizations can enforce agent-specific policies without sacrificing autonomy. [...]
Kategorie: Hacking & Security
Syndikovat obsah