Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

OpenAI’s runaway AI agent also compromised a cloud platform customer

Computerworld.com [Hacking News] - 20 min 13 sek zpět

OpenAI’s renegade AI agent, which carried out a high-profile breach of the AI platform Hugging Face, also reportedly compromised a customer of the cloud platform Modal Labs, according to Reuters.

The agent is said to have exploited a vulnerability in the customer’s own code, where an unprotected endpoint allowed anyone to run code in an isolated test environment.

Modal Labs emphasized that its own infrastructure was not compromised and that the security isolation worked as intended.

OpenAI declined to comment on the Modal case, but referred to a recent update in which the company confirmed that the tested AI agent managed to gain access to four accounts across four separate services. The company has not named the services.

Kategorie: Hacking & Security

Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads

The Hacker News - 1 hodina 55 min zpět
Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials,Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare

Bleeping Computer - 2 hodiny 11 min zpět
Health-ISAC, a cybersecurity information-sharing organization for the health sector, is warning healthcare and medical technology organizations of an observed increase in successful attacks by ShinyHunters. [...]
Kategorie: Hacking & Security

Apple preps for a wearable AI revolution

Computerworld.com [Hacking News] - 2 hodiny 36 min zpět

This fall, with watchOS 27, Apple Watch will finally get access to Siri AI with a software update that turns your wrist into the most widely-used wearable AI platform on Earth.

That’s not hyperbole. Siri AI on Apple Watch is arguably the most important feature to this year’s watchOS update. Though it didn’t get much attention at WWDC, the update also offers a preview into how Apple will wrap AI into its future smart glasses.

What to expect

One important caveat is to observe that Siri AI on Apple Watch still requires your Apple Intelligence-enabled iPhone to do the heavy lifting. The interaction is easy: tap the Digital Crown and Apple’s new glowing icon appears on screen (you’ll also find this in the App viewer). The experience looks identical across every Apple device — iPhone, iPad, Mac, Apple Watch, and Vision Pro — making the assistant feel like one consistent product rather than a different experience per device.

The Siri app lets you access all your past Siri conversations (unless you turn that feature off) and pick up an old conversation right where you left off. Conversation history syncs privately through iCloud, so you can start an exchange on your iPhone and continue it later from your wrist. You can also pin a conversation you expect to revisit.

You can also use Siri on the Apple Watch to ask questions, launch apps, or even get more complex responses, such as step counts on a specific day. It can also answer difficult and specific queries with detailed answers and can summon real-time information from the web.

Personal context is the real story

That’s key, of course, as it means the smartwatch on your wrist can help you access specific details from all your contextual information; it can get details from messages, emails, and notes, for instance. Or you might use it to find a number and call it, access your door code, or look up customer information for business — all without touching your phone.

One of Apple’s own examples demonstrates this well: Saying, “Show me photos from when I went to Spain,” results in precisely that. You can also ask follow-up questions and keep the conversational going naturally, rather than being confined to single, isolated commands.

Beyond personal data, the watch can also act in apps — get directions home, send an email, play a playlist, or even more specifically, “Play the song that Brandon sent me.”

Context runs deep. A new Call Context tool can proactively surface relevant information from across your apps when phoning a business or help locate a confirmation code from Mail while calling an airline. This arguably challenges a real pain point when speaking with providers and is a good illustration of Apple’s broader AI strategy: to use on-device intelligence to remove everyday friction without asking you to track down the information yourself.

Where we are, where it’s going

It’s frustrating that you still can’t use the Watch to remotely run applications on your Mac, iPhone, or iPad. What you can do is trigger Shortcuts that run on your iPhone: enable this first on your phone by selecting the Shortcut you want and switching on “Show on Apple Watch.” Once that’s done, you can run the Shortcut from your wrist, even by voice.

That’s useful now, but as more complex apps add Shortcuts support and App Intents become more widely adopted by developers, it should be easy to trigger genuinely complex, multi-stage tasks on your iPhone from your wrist.

It’s worth noting: early hands-on testing of the watchOS 27 beta has found Siri AI genuinely impressive on personal-context queries, but still buggy in places. This is very much a first-generation feature — promising, but not yet fully reliable.

Watch the developers

Developers are already beginning to experiment with the potential for wearable AI. One of the best current examples is Granola, which just launched a Watch app built specifically to take notes during in-person meetings away from a laptop. The idea is that you tap your wrist, the screen turns green and makes a sound to alert your companion(s) that it is recording and then you carry on as normal. Once the meeting stops, switch the app off and you’ll get polished notes with meeting summaries and action items provided to you.

The only reservation I have with Granola is the lack of documentation on privacy and data retention on the developer site. Tools like these will almost certainly become more private, more secure, and more prevalent once Apple’s on-device dictation APIs extend fully to watchOS.

That last thing is perhaps the most important as wearable AI emerges: the decisions Apple makes around watchOS and SiriAI will be foundational to its future wearable AI glasses products.

You can follow me on social media! Join me on BlueSky,  LinkedInMastodon and subscribe to The Core.

Kategorie: Hacking & Security

OpenAI agent used exposed credentials at 4 services in Hugging Face breach

Bleeping Computer - 4 hodiny 28 sek zpět
In a new update, OpenAI says its AI models also used publicly exposed credentials to compromise accounts on four third-party services during the recent attack on Hugging Face, expanding the scope of the four-day security incident to other organizations. [...]
Kategorie: Hacking & Security

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

The Hacker News - 4 hodiny 25 min zpět
Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3. It has been codenamed RufRoot by Noma Security's Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

The Hacker News - 4 hodiny 34 min zpět
Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity. The first of the three critical-rated flaws is CVE-2026-59309 (CVSS score: 9.8), which has been described as an authentication bypass in VMware vCenter. "A malicious actor with network access to vCenter Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack

Bleeping Computer - 5 hodin 9 min zpět
The Minnesota IT Services (MNIT) agency activated its cybersecurity incident response capabilities across the entire state after hackers targeted more than 30 community water systems in "a coordinated cyberattack." [...]
Kategorie: Hacking & Security

Detecting Web Shell Activity on Linux Using Behavioral Clues

LinuxSecurity.com - 5 hodin 12 min zpět
Although its main website is loading, a production Linux server can host an active command-and-control gateway without any errors that can be seen. If you wait for the site to break or for users to report broken functionality, you are already months behind an attacker.
Kategorie: Hacking & Security

Opera konečně podporuje vertikální listy a zabrání zkopírování škodlivého kódu

Zive.cz - bezpečnost - 5 hodin 20 min zpět
**Opera 133.0.5932.85 přidává vertikální navigaci. **Zlepšuje také integraci Google Lens. **Od začátku července chrání schránku před škodlivými kódy.
Kategorie: Hacking & Security

Why Automation Breaks When Visual Data Is Treated as an Afterthought

LinuxSecurity.com - 5 hodin 59 min zpět
Most automation projects don’t fail with dramatic outages; they fail through a slow erosion of trust.
Kategorie: Hacking & Security

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

Bleeping Computer - 6 hodin 3 min zpět
AI agents are designed to improvise as they complete tasks, making broad permissions a growing security risk. Token Security explains why identity, intent-based access controls, and least privilege are becoming the foundation for securing agentic AI. [...]
Kategorie: Hacking & Security

Windows 11 KB5101684 update released with 42 changes and fixes

Bleeping Computer - 6 hodin 9 min zpět
​​Microsoft has released the KB5101684 preview cumulative update for Windows 11 24H2 and 25H2, which 42 bug fixes and additional feature improvements for the operating system. [...]
Kategorie: Hacking & Security

Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline

The Hacker News - 6 hodin 16 min zpět
A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response. Braham, Plymouth, South St. Paul and Maple Plain have publicly described a plant outage, communications failures or affected automated controls. Braham's water plant went offline, and the city asked residents to minimize Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments

The Hacker News - 6 hodin 22 min zpět
Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more than nine years. According to Russian cybersecurity vendor F6, the threat actors have set up clone websites of Russian companies across fertilizer manufacturers, petrochemical companiesRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Mythos Asks the Right Question. It Doesn't Answer It.

The Hacker News - 7 hodin 50 min zpět
AI is compressing exploit timelines. The real question isn't whether your vulnerability management playbook needs to change, it's which part of it you've been getting wrong all along. The conversation happening in security circles right now goes something like this: Mythos is here. Exploit timelines are collapsing. Does the vulnerability management playbook need to change? The honest answer [email protected]
Kategorie: Hacking & Security

Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser

The Hacker News - 8 hodin 8 min zpět
Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process. Mozilla rated it High and fixed it in the Firefox 151.0.3 update. "No settings or additional user interaction are required," Eten Zou, Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Co nového v aplikaci WhatsApp. Volejte přímo z prohlížeče a přepínejte hovory mezi zařízeními

Zive.cz - bezpečnost - 8 hodin 20 min zpět
** V tomto článku mapujeme novinky v aplikaci WhatsApp ** Většina funkcí se nejprve testuje ve vybraných zemích ** Poté přichází k dalším uživatelům a je nasazována plošně
Kategorie: Hacking & Security

73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack

The Hacker News - 8 hodin 52 min zpět
Most organizations have incident response plans, security tools, and technical teams in place. Yet new research suggests that many still lack the coordination, visibility, and executive alignment needed to withstand a serious cyberattack. According to The State of Incident Response Readiness 2026, based on a survey of 600 senior IT security decision makers conducted by Vanson Bourne in January [email protected]
Kategorie: Hacking & Security

These near-mint ASUS Chromebook refurbs are only $145

Bleeping Computer - 8 hodin 53 min zpět
Buying a new computer in 2026 is a unique experience. Rather than deal with incredibly high tech prices, more shoppers are opting for high-quality refurbished tech. This ASUS Chromebook CM30 refurb is in near-mint condition with a grade "A" rating, but it still only costs $144.97 (reg. $369.99) on sale. [...]
Kategorie: Hacking & Security
Syndikovat obsah