Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

CubePilot drone software dev hit by DNS hijacking to intercept traffic

Bleeping Computer - 28 Červenec, 2026 - 23:17
CubePilot, an Australian firm that designs flight controllers for drones (UAVs), announced a severe operational disruption caused by a DNS hijacking attack. [...]
Kategorie: Hacking & Security

OpenAI models used Artifactory zero-days to escape to the internet

Bleeping Computer - 28 Červenec, 2026 - 22:37
JFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated testing environment and gain access to the internet before attacking Hugging Face. [...]
Kategorie: Hacking & Security

Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack

The Hacker News - 28 Červenec, 2026 - 20:59
Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128. The HAWK attack exploits a previously unused symmetry in the lattice behind the signature scheme. Anthropic's released implementation gives an expected end-to-end runtime of about three hours and 42 minutes on a 96-core serverSwati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

CISA shares advice on isolating vital systems during cyberattacks

Bleeping Computer - 28 Červenec, 2026 - 20:41
The U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems in the event of a cyberattack or other major disruptions. [...]
Kategorie: Hacking & Security

vBulletin fixes critical pre-auth RCE flaw with public exploit

Bleeping Computer - 28 Červenec, 2026 - 20:08
A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering. [...]
Kategorie: Hacking & Security

AI has become Apple’s latest bug detective

Computerworld.com [Hacking News] - 28 Červenec, 2026 - 18:17

Artificial intelligence is becoming a force multiplier for Apple security research. Apple’s latest 26.5.2 software update includes patches for a record number of bugs — many of them identified by security researchers using AI-assisted tools.

A record haul of fixes

The numbers tell the story. Apple fixed 87 security vulnerabilities in iOS and iPadOS 26.6, along with an additional 155 patches for Macs. Roughly 100 flaws have been patched in each of Apple’s other operating systems: watchOS, tvOS, and visionOS. Taken together, these represent record numbers for an Apple security update. 

This is only the beginning. The scale of the release echoes the impact AI coding agents are already having on security research and may well reflect Apple’s Project Glasswing research with Anthropic and others to use AI to identify software vulnerabilities. 

Apple’s use of AI for security research is visible in the official release note. Read through it and you’ll see multiple credits to Claude, Codex, and AI adjacent tools, labs, and researchers. These tools identified flaws across Apple’s systems, including in WebKit, WebDAV, and WebKit Storage.

For good and ill

It’s a neat illustration of the sea change under way as AI adoption accelerates. This release highlights how security researchers are leaning into AI tools to check platform security just as heavily as attackers are. One fix in today’s release is credited to researchers from Calif.io, who some may recall used Anthropic’s Mythos Preview model to create a working macOS kernel memory corruption exploit in just a few days.

The release is proof positive that while AI can be used to identify vulnerabilities to undermine protection, it can also be used to identify opportunities to further secure the platforms. It is also true that as AI use across the security industry grows, the number of flaws identified will also accelerate; it’s doubtful we’ll ever reach a point at which there are no flaws at all. Apple is likely to beef up its own internal observability tools following the acquisition of SigLens, which might help it identify even more bugs using AI.

Don’t delay, install today

None of these matters much, though, if the security patches never get installed — and the delay between security patch release and installation represents a huge opportunity for attackers. Recent analysis from Fleet Device Management found that 79% of organizations take more than a day to deploy critical security patches, even as attackers increasingly exploit vulnerabilities within hours of disclosure. The same report also showed something else to worry about: AI tools are spreading fast across the enterprise, often without the version control or auditability that would let anyone track how they’re actually being used.

Despite their number, the tally of fixes Apple has published isn’t the end of the story. In this case, while Apple has published its latest fixes, how many of those vulnerabilities have already been abused in the weeks between discovery and security patch release? More to the point, how swiftly will Apple’s installed base update devices now, and how many attackers will use that delay to dive in and do the damage?

It’s a security arms race

Adam Boynton, senior security strategy manager at Jamf noted that one vulnerability, CVE-2026-43810, can be exploited by a remote user to corrupt kernel memory. “The WebKit fixes are easy to read as a phishing story, when they are actually something slightly different,” he said.

“The raw material for targeted spyware is browser engine memory corruption, and those chains are expensive enough that they get pointed at specific people like senior executives, journalists, anyone whose access justifies the cost. That’s the honest reason to update promptly rather than eventually. 

“In other words, this update matters less for its raw numbers than for what those numbers represent: an arms race between defenders and attackers who are both, increasingly, running the same kind of tools,” Boynton said.

You can follow me on social media! Join me on BlueSky,  LinkedInMastodon and subscribe to The Core.

Kategorie: Hacking & Security

Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

The Hacker News - 28 Červenec, 2026 - 17:01
A new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its main process. If that happens, Tengu's other persistence mechanisms get another chance to relaunch it. Nozomi Networks Labs observed the dropper reaching its honeypots through Telnet credential brute force. Tengu supports 25 distributed denial-of-service (Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Linux Kernel Updates Privilege Escalation Provisioning July 28 2026

LinuxSecurity.com - 28 Červenec, 2026 - 16:50
The volume of Linux security advisories remains high across enterprise distributions, but the more difficult task is determining which updates carry the broadest operational risk. Looking across this week's advisory set, one pattern stood out more than any other.
Kategorie: Hacking & Security

24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

The Hacker News - 28 Červenec, 2026 - 16:41
Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management Interface (IPMI) protocol to the public internet. Of the 36,872 internet-exposed server-management interfaces running IPMI, 24,650 have been found to disclose password-derived authentication hashes before login due toRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Is Your SSO Protected Against Modern Credential Attacks?

Bleeping Computer - 28 Červenec, 2026 - 16:00
A compromised SSO login can provide attackers with access to multiple enterprise applications and services. Specops Software explains how stronger passwords, phishing-resistant MFA, and identity hardening help secure modern SSO environments and the applications they protect. [...]
Kategorie: Hacking & Security

Synsira Launches Kind Local Pro with 100% On-Device AI

Computerworld.com [Hacking News] - 28 Červenec, 2026 - 15:57

Operating entirely offline, Kind Local Pro gives individuals local data sovereignty without sacrificing AI performance

Synsira Software is addressing the biggest concern with AI: privacy. Today, the company introduced Kind Local Pro, an AI platform that operates independently of corporate cloud-based LLM models and is available to download onto desktops and laptops. Designed for people and organizations wanting the benefits of AI without sending their data, analysis and queries to external sources, the platform allows users to take control of their information.

Kind Local Pro builds on Synsira’s flagship Kind platform, giving professionals, researchers, communicators, legal teams, educators and organizations a more private way to search and understand their own files using AI. Built to operate locally on a user’s desktop or laptop, Kind Local Pro lets users create collections and ask questions across their materials, with answers generated only from their data and not the open web.

“People want AI to be useful, but they also want to know where their data is going,” said Dr. Jonathan Schaeffer, founder of Synsira Software and creator of Kind. “That is not a small concern. For many people and businesses, it is the whole issue. Kind Local Pro was built for users who want AI on their own terms: private, local and grounded in their own information.”

With Kind Local Pro, users add documents, presentations, research papers, notes, videos, images, email inboxes, audio and other supported files into collections. Once the content is indexed, summarized, tagged and analyzed by Kind AI, they can ask natural-language questions or do fuzzy searching and receive answers with precise citations into the information in those files. If the user’s data does not contain enough information to answer a question, Kind Local Pro is designed to say so rather than invent a response.

The platform is purpose-built for data-sensitive environments:

  • Legal and Compliance: Lawyers can analyze internal memoranda and client files with all analysis private and staying local to their machine
  • Intellectual Property: Agency professionals, influencers, creators and executives can organize proprietary brand assets, manuscripts and corporate strategies with zero risk of their data being used to train public models.
  • Academic Research: Scientists and researchers can search years of papers, drafts and video lecture materials while keeping unpublished work on their own machine.

The product reflects Synsira’s broader view that AI adoption depends on trust, transparency and practical value. Many people remain cautious about AI because of concerns about errors or bias in internet answers, privacy, data training, security and the environmental demands of large-scale cloud computing. Kind Local Pro addresses those concerns by moving the AI experience closer to the user and keeping private data under local control.

“Not every AI task needs to be sent to a massive data center,” said Schaeffer. “Sometimes the smartest place for AI to work is right where the information already lives: on your own computer. Bigger is not always better. Private, practical and accurate is better.”

Kind Local Pro allows for 10,000 files to be uploaded, up to 500 at a time. It is now available for an initial subscription cost of $79 at Kind.Synsira.com. Local Kind Free allows up to 50 files to be uploaded. Both versions are 1.9GB installed plus 6GBs of AI models installed.

A media kit with logos, headshots and screenshots of Kind Local Pro is available here.

About Kind by Synsira

Synsira builds ethical, user-friendly Al products from rigorously evaluated and curated Al models for folks who demand privacy and environmental responsibility in Al. Synsira’s flagship product, Kind, available now at synsira.com, is a desktop Al application that securely and privately helps users unlock the knowledge contained in their own curated data. By putting guardrails on the Al commercial and open-source models and implementing strict data controls, Kind Al delivers accurate, reliable results with surgical precision across all personal files, photos, video and audio.

Contact

Bethany Rhodes

[email protected]

Kategorie: Hacking & Security

Linux Logs Have Become a Prompt Injection Target

LinuxSecurity.com - 28 Červenec, 2026 - 15:45
An attacker may no longer need to erase Linux logs to hide an intrusion. They may only need the AI reading them to believe a different story.
Kategorie: Hacking & Security

JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

The Hacker News - 28 Červenec, 2026 - 15:33
JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment. Artifactory is JFrog's software repository manager. OpenAI says the models then escalated privileges and moved laterally until they reached an internet-connected node. JFrog says it has since developed and released fixes for cloud Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

The Hacker News - 28 Červenec, 2026 - 14:56
OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default. The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1 in OpenWrt's GitHub advisory, lets an unauthenticated attacker able to reach the DHCPv6 server overwrite a stack buffer in odhcpd through a crafted DHCPv6 Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Over 24,000 exposed server BMCs leak password hash via decades-old flaw

Bleeping Computer - 28 Červenec, 2026 - 14:10
More than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface. [...]
Kategorie: Hacking & Security

Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

The Hacker News - 28 Červenec, 2026 - 13:55
The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia. The intrusions involve the use of a previously undocumented Windows backdoor called NightLedger and two custom WebSocket tunnelers, Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Anthropic rejects open-weight AI bans, calls for China chip controls and safety tests

Computerworld.com [Hacking News] - 28 Červenec, 2026 - 13:13

Anthropic CEO Dario Amodei has argued that policymakers should keep lower-risk open-weight AI accessible while placing stricter safeguards around frontier systems, including mandatory testing and limits on China’s access to advanced computing and model capabilities.

In a post outlining Anthropic’s position, Amodei said broad restrictions, including bans on Chinese open-weight models used by US businesses, would not address his main national security concerns. Instead, he pointed to the possibility of authoritarian governments surpassing the US in advanced AI, as well as cyber, biological, and alignment risks posed by increasingly capable systems.

Amodei also called for action against industrial-scale model distillation, which he said allows Chinese developers to improve their models with less computing power than would be needed to train comparable systems from scratch.

The statement followed criticism of Anthropic for not signing an industry letter backed by Nvidia, Microsoft, Meta, IBM, Mistral, Hugging Face and other technology companies urging policymakers to avoid premature restrictions on open-weight models.

The letter said that open weights could broaden access to AI, intensify competition, and enable organizations to adapt and deploy models without relying on a single provider. Amodei agreed with parts of that case but disputed claims that openness inherently improves safety research or gives defenders an advantage over attackers.

He said regulation should be based on a model’s capabilities and risks rather than whether its weights are openly available. Under that approach, sufficiently capable open and closed models would undergo testing before release.

Conditional support

Analysts said Anthropic had moved closer to industry consensus by rejecting blanket bans, but its support remained more limited than the approach backed by many major technology companies.

Deepika Giri, head of research for AI, analytics, and data at IDC, said the Nvidia-backed letter presented open weights as strategic infrastructure that should remain broadly accessible, in contrast with Anthropic’s more restrictive position.

Amodei’s statement clarified that Anthropic supports open-weight models only under certain conditions, a stance that could also help the company preserve its competitive advantages as a proprietary model provider focused on compliance and tighter controls, according to Lian Jye Su, chief analyst at Omdia.

The statement was “a real olive branch” to supporters of open-weight models, according to Pareekh Jain, CEO of Pareekh Consulting. But he said the disagreement had shifted from whether such models should be released to where policymakers should draw the line.

“Anthropic still thinks that once a model gets powerful enough, releasing its weights publicly is riskier than keeping it locked behind an app, because you can never take it back or add safety fixes later,” Jain said.

Will the controls work?

Analysts differed over whether Anthropic’s proposed controls would achieve their aims without creating new barriers for smaller AI developers.

Jain said chip restrictions and measures against illicit model distillation would mainly affect model developers and infrastructure providers, rather than enterprises using models already on the market. Mandatory safety testing, however, could raise development costs and reduce the number of advanced open-weight models available.

“Testing is expensive and time-consuming, and so, giant, well-funded companies like Anthropic, Google and OpenAI can afford it,” Jain said. Smaller developers seeking to release cutting-edge open-weight models could struggle to meet the same requirements, he added.

The additional testing and screening could also restrict the number of open-weight models available to enterprises, according to Su. He said the requirements could weaken some of their principal benefits, including lower costs, reduced vendor dependence and community-led development.

Anand Joshi, managing director of market research firm JP Data, questioned whether limiting China’s access to advanced chips would materially slow its AI development, arguing that Chinese companies had shown they could build highly capable models with less computing power. He supported action against illicit distillation, however, saying safeguards were needed to prevent developers from reproducing the capabilities of other models without authorization.

The impact on most enterprise users could remain limited if less capable models were exempted, Jain said. Businesses deploying models that fall below the proposed testing threshold would probably face little additional cost.

How CIOs should choose

Giri said CIOs should assess models according to their capabilities rather than whether they are open, and should demand independent testing, clear licensing, model documentation and accountability for monitoring and incident response.

“Mandatory safety testing should be triggered by a model’s demonstrated capabilities, not its size or training cost,” Jain said, particularly when a system could significantly assist cyberattacks, biological misuse, or autonomous harmful actions.

Before deployment, CIOs should seek independent evaluations, detailed model documentation, security test results and information about the model’s software supply chain, he added. Charlie Dai, principal analyst at Forrester, said that assessment should include documented red-team results, model provenance, disclosures about training and fine-tuning, and evidence of independent testing against recognized safety benchmarks.

Kategorie: Hacking & Security

Microsoft’s Nadella calls out Big AI for hypocrisy — but what about his own company?

Computerworld.com [Hacking News] - 28 Červenec, 2026 - 13:00

The 19th-century French novelist Honore de Balzac is believed to have said that behind every great fortune lies a great crime.

That’s even more true today than it was 200 years ago — just look at how Big AI, including Anthropic, OpenAI, Google, and others have built their trillion-dollar fortunes. 

They all use vast amounts of copyrighted material to train their large language models (LLMs) without paying the copyright holders. In other words, they steal it. They don’t call it stealing, though. They call it “fair use,” which in this case amounts to the same thing.

Generative AI (genAI) training requires massive amounts of text. The better-written and more information-dense that text is, the more it helps. AI gets a lot smarter a lot faster when it’s trained on well-written books and magazine and newspaper articles than when it’s trained on social media banter (or most everything else you find on the internet).

Since the dawn of AI, companies have been hoovering up copyrighted material wherever they find it — on the open web, behind paywalls, even in manually scanned books — and then used the scanned text. And they do it all without asking authors’ or publishers’ permissions, and without paying them.

It’s the greatest intellectual property theft in history by a long shot — billions and billions of dollars worth. Books, articles, music, photographs, artwork, you name it. If a human being has created it, Big AI has likely grabbed it and ingested it without asking, then made big profits off it.

I know this from personal experience; I’ve got skin in the game. Big AI companies have used at least 30 of my books to train their models without asking.  And that’s only what I’ve confirmed. Big AI might well have stolen even more. And it also might have stolen many of the thousands of articles I’ve written through the years.

For the AI bigwigs, it’s standard operating procedure. So it was surprising to see Microsoft CEO Satya Nadella calling out Big AI for its hypocrisy in using other people’s intellectual property without paying, then crying foul when small AI companies use Big AI’s work to train their own models using a technique called distillation.

He wrote on X: “While the great innovation that comes from model providers having fair use rights to train models on public data is needed, I find it ironic that the status quo is to then turn around and impose restrictive terms on distillation, and to reserve the right to learn from customer usage and interaction data.” 

One important note here: Nadella believes Big AI should be allowed to steal copyrighted material for training purposes. He makes that clear by his mention of “fair use.” His issue is that he believes smaller AI companies should be able to use Big AI’s work to train their models — and Big AI doesn’t want to let them do it.

Alistar Barr, in Business Insider, makes a related point: “Anthropic, OpenAI, and Google are discovering what the rest of the internet has already learned through painful experience: once you put something online, people will find ways to use it in ways you don’t like and can’t stop.” 

Before we look at whether Nadella is right in calling Big AI’s actions hypocritical, let’s examine the technique at the heart of the issue: distillation.

The lowdown on distillation

Distillation refers to an AI training technique in which you take outputs from one AI model, such as the answer to a prompt, and use that output to train your own model. AI companies do that quite frequently and have been doing so for a long time.

Barr explains distillation this way: “Distillation looks an awful lot like what AI companies have been doing to the rest of the internet. Scrape web content for free and without permission. Turn it into a product you sell. Argue it’s fair use. Hope the lawyers sort out the details later.”

Elon Musk has admitted his company xAI used distillation techniques to take output from competitor OpenAI to train xAI’s Grok chatbot. He explained, “Generally AI companies distill other AI companies.”

Analysts point out the AI industry is built on distillation. Neil Shah, vice president of research at Counterpoint Research says, “The reality is none of the models is an island and the entire industry has mostly evolved based on recursive learning. The newer entrants are in many instances going through the same routes of ‘distillation’ and ‘optimization.’”

It’s only become an issue now because Chinese AI companies have been using distillation techniques to catch up to American AI companies.

OpenAI CEO Sam Altman has been pressuring the US to take legal action against the Chinese companies.  Anthropic has piled on as well, saying the fight against distillation requires a coordinated response across the AI industry, cloud providers, and policymakers.

Hypocrisy or fair use?

So are OpenAI, Anthropic and other big US AI firms hypocritical, as Nadella claims? Absolutely. They’ve built their businesses on the theft of billions of dollars of stolen intellectual property and call it fair use. Now, they’re playing the victims when competitors do the same to them. (They’re also in some cases paying up; Anthropic just last week settled a copyright suit, paying out $1.5 billion.)

It’s good to see Nadella call out their hypocrisy. But Microsoft is as guilty of intellectual theft as the others — its AI Copilot is powered by OpenAI’s and Anthropic’s chatbots. The company faces major lawsuits for intellectual property theft. Among them is one by the New York Times, New York Daily News, and Center for Investigating Reporting, another by 400 local and regional newspapers, and another by 11 authors, including Pulitzer Prize winners Kai Bird, Jia Tolentino, and Daniel Okrent.

So, don’t praise Nadella for speaking out. Criticize him (and other AI tech leaders) for stealing billions of dollars in intellectual property from countless writers and publishers and calling it fair use.

Kategorie: Hacking & Security

Data breach at medical billing firm MCBS affects 1.26 million people

Bleeping Computer - 28 Červenec, 2026 - 11:10
Healthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people. [...]
Kategorie: Hacking & Security

Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

The Hacker News - 28 Červenec, 2026 - 10:11
JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution. The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions. It has been addressed in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have alreadyRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Syndikovat obsah