Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

Autonomous AI agents tried to hack US, Canadian government websites

Bleeping Computer - 46 min 55 sek zpět
Autonomous AI agents using aggressive strategies attempted to hack U.S. and Canadian government websites to find school and divorce statistics. [...]
Kategorie: Hacking & Security

Microsoft says threat actors are ahead in the early AI race

Bleeping Computer - 2 hodiny 6 min zpět
Microsoft says cyberattackers are currently benefiting from artificial intelligence faster than defenders, allowing threat actors to speed up vulnerability discovery, malware development, and post-compromise activity while security teams struggle to keep pace. [...]
Kategorie: Hacking & Security

Memory executives expect RAM shortage to continue through 2028

Ars Technica - 3 hodiny 49 min zpět

Micron and Samsung executives this week said the memory shortage will continue for at least the next couple of years.

Micron CEO Sanjay Mehrotra expects demand for the firm’s memory to exceed its available supply over that period, he told investors last night.

Micron no longer sells consumer RAM, and Mehrotra’s statements refer to Micron’s business-to-business sales of high-bandwidth memory (HBM) for AI and DRAM for servers. However, his comments also have implications for consumer devices. Manufacturing capacity is prioritizing memory for AI and servers, limiting the supply of memory manufactured for consumer devices.

Read full article

Comments

Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers

The Hacker News - 4 hodiny 43 min zpět
Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organizations and threatening to publish it on its leak site unless they paid. The 16-year-old was one of 3 people arrested on September 30, when police also took control of that site. Investigators identified him as KillSec's suspected Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories

The Hacker News - 4 hodiny 54 min zpět
This week, the useful words are boring ones: inspect, cache, compile, store, trust. Each sounds harmless. Each can become an attack path when a system does a little more than people expect. A model check can run code. A cache can mix up requests. A public secret can stay useful for years. That is the lesson running through the list. Attackers do not always need a brilliant new trick. They can Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

The Hacker News - 7 hodin 2 min zpět
Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. The backdoor has been codenamed SC after the "SC_" markers present in the injected content. Sucuri has described the malware as a "self-healing mesh" that's Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Police dismantle KillSec ransomware gang allegedly led by 16-year-old

Bleeping Computer - 7 hodin 14 min zpět
An international law enforcement operation dubbed "Operation KillSwitch" seized the KillSec ransomware gang's data leak site and servers, led to three arrests, and identified a 16-year-old as the group's alleged administrator. [...]
Kategorie: Hacking & Security

Memory squeeze set to tighten through 2028, Micron says

Computerworld.com [Hacking News] - 7 hodin 32 min zpět

The global memory shortage that has driven up the cost of servers, storage and PCs through 2026 will get worse in 2027 and 2028, according to memory maker Micron Technology.

“We expect memory and storage supply-demand conditions to be much tighter in calendar 2027 and 2028 than they were in 2026,” CEO Sanjay Mehrotra said in prepared remarks for the company’s fiscal fourth-quarter earnings call.

Even with new cleanroom space planned across the industry, “We do not have line of sight to when supply and demand will return to balance,” he said. Earlier industry forecasts had expected the two to return to balance in 2028.

Mehrotra added that new plants would not bring quick relief. “Production from new DRAM and NAND fabrication facilities takes time to ramp and gradually becomes more meaningful starting a few quarters after initial output,” he said.

Neil Shah, vice president of research at Counterpoint Research, said the outlook means CIOs “will have to be prudent about which equipment to upgrade and which to stretch to maintain cost efficiencies.”

Higher prices, less memory

On the same call, CFO Mark Murphy said Micron’s “inventory levels and supply remain extremely tight.” Its DRAM prices rose by a percentage in the high teens in the fiscal fourth quarter, while NAND prices climbed about 30%, he said.

Taiwan-based market research firm TrendForce expects prices across the industry to keep rising. In a Sept. 30 report, it forecast that conventional DRAM contract prices will increase another 10% to 15% in the fourth quarter from the third. It expects NAND flash prices to climb 15% to 20%. The firm said increases are slowing but the market remains undersupplied.

IDC expects PC buyers to pay more as well. The research firm forecast in June that average PC selling prices will rise 17% in 2026.

TrendForce has also tracked a shift toward less memory per server. Cloud providers and OEMs have moved some servers from 96GB and 128GB memory modules to 32GB and 64GB modules since the first half of 2026, the firm said in a July report. Analysts had warned in January of higher prices and lower memory specifications for enterprise PCs.

Supply committed years ahead

Micron has already committed more than 75% of its 2027 output, and most of its customer discussions now concern 2028, Mehrotra told analysts on the call.

Much of that supply is locked into multiyear, take-or-pay contracts that Micron calls strategic customer agreements (SCAs). “Any new discussions on SCAs where pricing is involved are negotiated with higher pricing based on prevailing market conditions and outlook,” Mehrotra said.

Some cloud providers have signed similar long-term agreements with memory makers, TrendForce said in its July report. That has left buyers without such deals as the main source of server DRAM price increases, it said.

Shah said enterprises should lock in pricing too. “Companies should secure multiyear pricing for the computing capacity they know they will need,” he said. Moving workloads to the cloud will not avoid rising hardware and energy costs “because providers will pass them on,” he added.

Which refreshes to delay

When it comes to replacing existing equipment, Shah said, the right call depends on the workload. “For general back-office PCs and routine file servers, stretching lifecycles from three years to five is harmless,” he said. “But for core infrastructure and engineering seats, delaying refreshes can backfire.” Aging equipment can drag on productivity, lose software support and fail more often, he added.

Shah also cautioned against turning to older memory to save money. Memory makers have been converting production lines to high-bandwidth memory and DDR5, so DDR4 is no longer cheap or plentiful, he said. “If you buy legacy platforms today to shave 10% off upfront server costs, you’re buying into systems which won’t have serviceable parts two years from now.”

He recommended starting with the hardware already in place. “Enterprises often waste 30% to 50% of memory by provisioning for peaks that rarely occur,” he said. Right-sizing virtual machines, quantizing AI models and batching workloads more efficiently can cut memory use significantly, according to Shah.

Before buying more hardware, he said, “CIOs should think about optimizing on the silicon already in place.”

What hardware vendors say

Hardware vendors had no helpful advice to offer budget-constrained buyers.

Lenovo did not answer questions directly but pointed to remarks executives made on its Aug. 13 earnings call.

Chairman and CEO Yuanqing Yang said then that he expects memory demand to keep rising and supply to remain constrained at least through the end of 2027. He said Lenovo can respond quickly to rising component costs: “When the material costs rise, we can adjust the pricing at the front end in a timely manner.”

Luca Rossi, president of Lenovo’s Intelligent Devices Group, said he expects the PC market to shrink about 15% in units in the six months to March, with business demand holding up better than consumer demand.

On the server side, Ashley Gorakhpurwalla, president of Lenovo’s Infrastructure Solutions Group, said a “strong server refresh cycle is underway.”

Dell, HPE, HP, Cisco and Supermicro did not respond to requests for comment by publication time.

This article first appeared on CIO.

Kategorie: Hacking & Security

The Day-One Hole in Zero Trust Architecture

Bleeping Computer - 7 hodin 38 min zpět
Zero Trust can verify users once they are established, but onboarding creates a gap where organizations must decide who to trust before strong authentication exists. Specops explains why identity verification should begin before credentials, MFA methods, and access are issued. [...]
Kategorie: Hacking & Security

Kiteworks patches max severity code injection vulnerability

Bleeping Computer - 7 hodin 48 min zpět
Secure file-sharing software company Kiteworks has released security updates to address 126 vulnerabilities, including a max-severity flaw affecting its Email Protection Gateway (EPG) security solution. [...]
Kategorie: Hacking & Security

ServiceNow launches standalone AI service desk to provide support in Teams, Slack, and email

Computerworld.com [Hacking News] - 8 hodin 20 min zpět

ServiceNow has a new take on the service desk: Flow by ServiceNow, a standalone AI product that allows users to get help via chats in Microsoft Teams, Slack, or a Flow web app, or by email, rather than having to leave what they’re doing to open a helpdesk ticket.

Flow can be up and running within a day, no implementation project or infrastructure required, the company said. The product can stand alone or plug into the ServiceNow platform for customers who need enterprise scale, governance, and cross-functional workflows, it said.

It’s a smart move, said Frank Dickson, principal analyst at Dickson Research. “The pitch is what Flow does not require. ServiceNow claims Flow can be running in a day with no implementation project, no CMDB migration, and no infrastructure. Every item on that list is something its flagship ITSM platform does require. ServiceNow is selling the absence of its own complexity,” he said.

Flow will connect to more than 100 systems through pre-built connectors. If the AI can’t surface the information it needs to fulfill a request from available data sources, Flow will escalate the issue to a human. Frequent requests, such as those for password resets, can easily be automated by IT, ServiceNow said.

Cost of consumption

Customers don’t need an existing ServiceNow implementation to use Flow; as soon as it goes live, it can handle user requests. Pricing will be consumption-based.

ServiceNow customers who subscribe to its AI services will also be able to deploy Flow with no additional licensing costs; they will just pay for consumption via assists from their existing pool.

The product is currently available at no charge during what ServiceNow refers to as Controlled Availability. Organizations seeking early access can sign up on the Flow website.

Flow is now available to current ServiceNow customers in North America, and the company plans to make it generally available in North America and EMEA by year-end. Wider availability will follow in the first quarter of 2027, a company representative said.

Melody Brue, principal analyst at Moor Insights & Strategy, said that Flow is a logical next step for ServiceNow. “The company built its business around digitizing work that historically moved through tickets, forms, portals, and manual handoffs,” she noted. “The AI opportunity is to make that same operational depth easier to access through conversation and, increasingly, voice.”

Headless trade-off

Dickson said Flow rides a larger trend toward headless software, in which the engine runs in the background and uses someone else’s user interface, in this case Slack or Teams. But it’s a trade-off: “ServiceNow describes its platform as a single pane of glass. With Flow, it hands the glass to someone else. Whoever owns the interface owns the daily habit, and in headless software, the habit may become the relationship.”

That said, Brue saw Flow as a good fit for today’s market. “Customers want AI with a clear use case, quick time to value, and proof that it can do more than generate answers,” she said. “They want it to resolve real work. A standalone product also gives ServiceNow a lower-friction place to land (with the goal of expanding), reaching customers that may not be ready or have time for a full platform rollout.”

But, she said, while many vendors offer AI assistants, “the real test is whether this can reliably complete work across systems, with the right permissions, approvals, and human handoffs. ServiceNow has a credible foundation in workflow and service operations. The question is whether it can make that enterprise depth simple and fast enough to deploy for the product-led AI market it is targeting.”

With the current fierce competition to capture “the front door of work,” she said, “ServiceNow’s opportunity is to differentiate not just on the conversational experience, but on its ability to carry a request through governed workflow, approval, and fulfillment across systems.”

This article first appeared on CIO.

Kategorie: Hacking & Security

How Financial Services Companies Can Modernize Their Software Supply Chain

The Hacker News - 9 hodin 54 min zpět
Every security leader at a bank, insurer, or asset manager has had a version of this conversation: Security wants to eliminate a class of vulnerabilities. Engineering explains what it would take to upgrade the platform where they live. Somebody prices out the regression testing. Somebody else raises the change-freeze calendar. The finding gets an exception, a compensating control, and a date [email protected]
Kategorie: Hacking & Security

Microsoft enables Windows settings backup by default for orgs

Bleeping Computer - 10 hodin 25 min zpět
Microsoft announced that Windows settings backup and restore is now enabled by default on all Microsoft Entra-joined or Microsoft Entra hybrid-joined enterprise systems upgraded to Windows 11 26H2. [...]
Kategorie: Hacking & Security

Will ‘move fast, ship quicker’ kill the Apple brand?

Computerworld.com [Hacking News] - 10 hodin 1 min zpět

Tech writers seem hugely excited at news that new Apple CEO John Ternus intends to launch a wave of new products, presumably because we’ll get to fill our feeds waxing lyrical about all the new things. But what does it mean when a company known for a few great products begins to introduce lots of potentially lesser gadgets?

Will this dilute the Apple brand? Extend it? Or will an even greater sense of product ubiquity amplify the core products it creates? Will Apple’s new hardware drive huge revenue, or are these plans just a sign the company now intends to capitalize on its brand equity with a wave of new devices, some of which may fail?

More things, more money?

That’s not to say that the new products will fail, of course. I’m sure there are plenty of households that want an iPad on a base to use as a home security monitor, recipe-finder and call center to stay in touch with friends. I’m pretty certain touchscreen Macs and new all-glass-seeming iPhones will strike a chord. 

All of these products will no doubt enable Apple to identify and offer new services to boost that side of its income. Services have become the second-largest revenue stream for 21st-century Apple, after the iPhone. Online commentators claim Ternus wants to generate more revenue from that part of the Apple family.

Breaking the pattern

This shift in strategy suggests that a new internal culture may be coming into play at Apple, one that mirrors the ‘move fast and break things’ ethos that has become so popular in Silicon Valley while becoming vastly less popular outside it as we look at what the tech giants break. 

But at Apple’s scale, the main risk it faces is breaking too much. Can it really afford to introduce products that don’t capture the zeitgeist, and to what extent do the company’s product designers see the zeitgeist of today? That seems to be a completely appropriate question when the company’s former lead designer now makes a living crafting expensive watches and cars for Ferrari. 

A world in perma-crisis is less about aspiration and more about survival. Is distraction what we crave or a solution to what plagues us? Will Apple get it right with a tease of toys to delight us or bring in solutions that seem somehow less relevant to the masses? Can the company that gave us the iPod, the iMac, and the iPhone do something similar for the smart home? Distill the need, capture the zeitgeist, and design something possibly made in Vietnam we’ll buy for $$$…?

Or is it going to come up with the hardware equivalent of Ping?

We don’t have too long until we find out. 

Solving the smart home crisis

At time of writing, reports claim Apple will begin its new assault with a product reveal on October 13, where it’s expected to introduce that combined iPad/HomePod I referred to above, along with a bunch of upgrades for its existing smart home products: Apple TV, HomePod, and a new homeOS to glue it all together. 

If Apple gets this right, I do think it has a huge opportunity to open up the domestic intelligence market, given that so many of the products that have been thrown at that segment have proved pretty poor in the long run. How many times each decade are you supposed to replace a piece of smart kit, and is it really positive progress if its life span is a fraction of that of the utensil it’s meant to replace? 

A company that can deliver robust, resilient, easy to set up smart devices that last at least as long as their mechanical alternatives could do pretty well, although Apple isn’t expected yet to offer up an AI-savvy garlic press or coffee percolator, and I’m still waiting on the Apple iBike I asked for more than a decade ago.

Finding the sweet spot

In the end, the clamor for product is all very well, but we have to ask ourselves what resonates best, what matters most, and what direction we’re going in culturally, as the sweet spot in product design is — as the iPod showed us long ago — almost certainly about summarizing all those needs inside one beautiful package that does one thing well that you didn’t know how much you needed. 

Will Apple deliver? Will AI be its superpower to enable new product opportunity?

We’ll find out in a week or two.

Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSky, LinkedIn, or Mastodon.

Kategorie: Hacking & Security

OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates

The Hacker News - 10 hodin 57 min zpět
OpenAI on Wednesday said it identified and disrupted a coordinated distillation campaign that was designed to illicitly extract protected reasoning from its artificial intelligence (AI) models. A "core cluster of the activity," going back to the first week of July, has been attributed to individuals associated with Moonshot AI, a Chinese AI company based in Beijing. It did not cite any Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV

The Hacker News - 11 hodin 6 min zpět
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV), following reports of active exploitation. The vulnerability, tracked as CVE-2026-76504 (CVSS score: 9.8), could allow an unauthenticated, remote attacker to access an affected system with Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Hackers stole Pentagon personnel records of over 3 million people

Bleeping Computer - 11 hodin 55 min zpět
The Pentagon's Defense Manpower Data Center (DMDC) is notifying millions of military service members that hackers stole their data after breaching the Pentagon's human resources management system in October 2025. [...]
Kategorie: Hacking & Security

Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version

The Hacker News - 13 hodin 50 min zpět
Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cyber defenders through its Fairwind Program. "It delivers frontier performance in complex workflows across real-world software engineering, enterprise knowledge work like legal and finance, and cybersecurity defense," Koray Kavukcuoglu, Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Metamask discloses security incident affecting its infrastructure

Bleeping Computer - 14 hodin 5 min zpět
On Thursday, cryptocurrency wallet provider MetaMask has disclosed an ongoing infrastructure security incident affecting some of its infrastructure. [...]
Kategorie: Hacking & Security

Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path

The Hacker News - 15 hodin 45 min zpět
Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals. The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs. The code causes a crash, not an execution error. Turning the memory corruption into a working Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Syndikovat obsah