Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

Hackers abused Claude to extract secrets from 1.8M Android apps

Bleeping Computer - 11 Září, 2026 - 22:19
Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes. [...]
Kategorie: Hacking & Security

Florida confirms DMV database breached via stolen police account

Bleeping Computer - 11 Září, 2026 - 21:00
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. [...]
Kategorie: Hacking & Security

Phishing na zákazníky Trezoru nerozsvítil žádnou kontrolku. Přišel z jeho vlastní adresy

Zive.cz - bezpečnost - 11 Září, 2026 - 20:45
Česká firma Trezor, výrobce hardwarových peněženek pro kryptoměny, se stal terčem phishingové kampaně. Byla rozeslaná přímo z jeho vlastní e-mailové infrastruktury. Útočník se 9. září 2026 dostal do e-mailové platformy Brevo, kterou Trezor používá na rozesílání newsletterů. Jeho zákazníkům ...
Kategorie: Hacking & Security

Passkey-themed phishing attacks lead to Microsoft 365 data theft

Bleeping Computer - 11 Září, 2026 - 19:26
Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services. [...]
Kategorie: Hacking & Security

Teams and Copilot are changing addresses: update your firewalls

Computerworld.com [Hacking News] - 11 Září, 2026 - 18:56

Microsoft is changing the destination address of two of its most popular services: starting this month, it will redirect M365 and Teams web users to copilot.cloud.microsoft and teams.cloud.microsoft, respectively.

The Teams move is already under way, and Microsoft has now added M365 to the mix. The company announced the changes in two MessageCenter posts: MC1465764 (mirror) and MC1462915 (mirror).

Organizations using these products are advised to update their systems and documentation to ensure continued access. Microsoft has told customers to review configurations on client devices, proxies, firewalls, secure web gateways, or other enterprise network controls to confirm that users can connect to the new addresses. Companies having trouble connecting should ensure that their environment aligns with the recommended network requirements for Microsoft 365 Copilot

Enterprises that had been blocking the new Copilot address to prevent employees accessing their personal Microsoft accounts can use Microsoft’s TenantRestrictions control to achieve their goals instead, it said.

All redirects should be completed by early October, Microsoft said, advising companies that can’t meet the deadline to contact their account representative for help. Limited exceptions to the Teams redirect are possible until Dec. 31, 2026, but after that no further delays will be possible, it said.

Kategorie: Hacking & Security

GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

The Hacker News - 11 Září, 2026 - 18:30
GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Artifactory flaws chained in attacks deploying backdoor malware

Bleeping Computer - 11 Září, 2026 - 18:29
Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. [...]
Kategorie: Hacking & Security

Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks

The Hacker News - 11 Září, 2026 - 18:15
Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax. Knowledge distillation by itself is a legitimate training method. It refers to a machine learning technique where a large, powerful AI model assumes the role of a "teacher" to Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

ConnectWise patches critical ScreenConnect authentication failure after five days

Computerworld.com [Hacking News] - 11 Září, 2026 - 18:13

ConnectWise has issued a security update for ScreenConnect, five days after warning customers the product could allow files to be transferred and executed through active remote sessions without authorization or confirmation.

The company warned customers on Sept. 3 of the problem with support and access sessions in ConnectWise Remote Access, advising admins to log in and remove the “TransferFiles” permission from any users with an open session.

The vulnerability, tracked as CVE-2026-84869, has been patched in the ScreenConnect client version 26.6.5 onwards.

Last month ConnectWise took the opportunity to reassure customers at its IT Nation Connect Asia Pacific conference that it was getting back on track after a “nation-state attack” in May 2025 that had affected several customers. The company quickly released a patch for that attack and said no customers had suffered loss.

This was not the first time that the company had suffered from a cyberattack. In 2024, ConnectWise had to issue a patch after reports that ScreenConnect had been exploited.

Kategorie: Hacking & Security

Apple’s A20 Pro rewrites the rules for chip design — again

Computerworld.com [Hacking News] - 11 Září, 2026 - 17:36

IDC analyst Francisco Jeronimo said something interesting following the iPhone Duo introduction on Wednesday: “Apple showed up years after everyone else, yet it walks in and sets the rules.”

He’s right. From the IP resistance to the little touches that set the new foldable apart from most of the competition, Apple has set expectations for the entire market, and while competitor Samsung is trash talking the foldable, even it stands to benefit from the millions Apple is about to sell. Apple is, after all, allegedly paying Samsung $250 for each iPhone Duo display.

But it is not just the rules concerning foldables the company has now defined; it has also set the standard competitors must follow in chip design with its A20 Pro, a super-powered processor that delivers noticeable performance improvements even compared to last year’s iPhone 17. 

What’s new in the chip?

With six CPU cores, seven GPU cores and a new Dual 16-core Neural Engine, the new chip boasts numerous improvements compared to the A19 Pro, not the least of which is that it’s the first 2nm chip Apple has put inside a smartphone. These enhancements bestow it with a series of superlatives:

  • Memory bandwidth is 50% higher than last year’s chip.
  • GPU graphics performance increases up to 40% over the A19 Pro.
  • AI performance is expected to double.

These are all significant improvements that make for noticeable experience boosts for anyone using one of these phones. Prosaically, I anticipate first reviews will celebrate how fast and responsive these devices are, and this will be most evidenced in tasks such as video capture and photography. Pictures will capture more swiftly, open faster, and edit features will become (and already are) more advanced and sophisticated than before. Apple spent ample time celebrating the iPhone 18 Pro series for the new frontiers in digital photography they open up, and not just because of the new reflexive lens.

The point is that the devices have the horsepower to get through computationally intensive tasks, including AI, thanks to the Neural Engines and GPU.

Thermal management is the icing on the quake

What those tasks have in common is heat, which Apple’s product designers have addressed in two critical ways: liquid cooling and processor design.

The processor design is the important thing, because in this case Apple has moved away from the InFO POP packaging of the A19 Pro in which the DRAM is stacked above the chip. It’s now embraced a side-by-side design it described as “inspired by” M-series Apple Silicon.

That works because placing both components alongside each other, rather than in a perpetual embrace, reduces the overall temperature of both by putting a little space between them. As Apple explained it, this Wafer-level Multi-Chip Module (WMCM) approach means the memory gets out of the way of the processor, allowing the latter to make direct contact with the vapor chamber cooling system.

In layman’s terms, it means both memory and chip can perform more intensively while being more efficiently cooled, a move that helps Apple’s iPhone meet those astonishing performance achievements. The vapor chamber is also bigger, made of new material with three times the surface area of before, making it even better at cooling the device.

It also means Apple has achieved a lot of things competitors have not, most particularly in packaging, the use of 2nm chips in a mass market product, and overall design.

That’s where it gets interesting. Both Qualcomm and MediaTek now plan to follow in Apple’s footsteps with the adoption of 2nm chips and side-by-side packaging.

Digitimes suggests it is a move others will follow, as vendors work furiously to ensure their hardware can run AI effectively on device, which iPhones already do. Apple, of course, already knows its Macs, iPhones, and iPads have been designed from the ground-up to support on-device AI as it works to provide the world’s best mass market platforms for secure and private use of the tech.

Friends don’t let friends bet against Apple

All the same, even at the microprocessor level, it’s hard to ignore that where Apple goes, others follow — even while where others go, Apple frequently follows later, but seems to do it better. It has never been a company to bet against, after all. People really should stop doing that.

Please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSkyLinkedIn, or Mastodon.

Kategorie: Hacking & Security

Anthropic finds evidence of a fourth AI escaping from containment

Computerworld.com [Hacking News] - 11 Září, 2026 - 17:18

Anthropic has owned up to a fourth security incident involving its AI model, Claude, escaping onto the open internet and attacking other organizations during a test of cybersecurity abilities on what was believed to be a closed system.

The company revealed three such incidents in July after a preliminary investigation.

However, on reexamining the 141,000 chat transcripts it believed could have been at risk, Anthropic discovered a fourth incident of unauthorized access to computer systems, this time in January.

After this discovery, the company instigated a wider search of 481 million transcripts, covering all those from its Frontier Red Team, some non-cyber evaluations, reinforcement learning environments, and more, to see if any other incidents had occurred. So far, this search has only identified the four already-known incidents, it said.

It has also reported details of all the previous incidents to the non-profit lab Model Evaluation and Threat Research (METR), which has agreed to conduct an independent investigation.

Anthropic is not revealing too many details of its latest discovery. It has contented itself with saying that it was due to a misconfiguration which mistakenly connected to the open internet, when the simulation was meant to be without such access. It also said that it all four faults were with the same evaluation partner. It has asked METR to investigate all the incidents. The company said that this latest revelation was not connected to the Mythos incident reported by the UK’s AI Security Institute last month.

News of the latest discovery broke at the same time as a young researcher, Jacob Coxon, dramatically quit Anthropic accusing it and his previous employer, OpenAI, of “acting irresponsibly” and “gambling with our lives” — a warning that has excited many sections of the press.

This article first appeared on CSO.

Kategorie: Hacking & Security

Claude Used to Automate Exploitation and Data Theft Across Multiple Victims

The Hacker News - 11 Září, 2026 - 16:29
Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026. The threat actors, which the artificial intelligence (AI) company has branded Generative Threat Groups (GTGs), span state-sponsored groups, financially motivated criminals, commercial Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection

The Hacker News - 11 Září, 2026 - 16:10
Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve. The operation has been attributed to a cyber espionage group it calls GTG-20006 (where "GTG" stands for Generative Threat Group), which aligns with broader reporting linking the cluster to MidnightRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface

Bleeping Computer - 11 Září, 2026 - 16:01
Threat actors are abusing trusted AI platforms to host malicious content, poison search results, and trick users into installing malware. Huntress examines campaigns targeting AI users through weaponized Claude Artifacts, shared AI conversations, sponsored search results, and ClickFix-style lures. [...]
Kategorie: Hacking & Security

AI máma? Když doma chybí rozhovor, děti se svěřují AI. Nadace O2 nabízí konkrétní pomoc a spouští Bezpečně v síti

Zive.cz - bezpečnost - 11 Září, 2026 - 15:32
Nadace O2 představuje novou podobu svého vzdělávacího programu Bezpečně v síti. Ten pomáhá rodičům, dětem i učitelům s online bezpečností a komunikací o digitálním světě. Zdarma nabízí třeba praktické návody, edukační hry, odborné materiály nebo další obsah. Nový výzkum Nadace O2 a agentury NMS ...
Kategorie: Hacking & Security

ClickFix attacks infecting PCs and Macs are going viral

Ars Technica - 11 Září, 2026 - 13:30

It wasn’t that long ago that ClickFix attacks were exotic. Now the technique has become mainstream as attackers reap its simplicity and effectiveness in infecting users of PCs and Macs alike. All that’s required is a compromised website—a painless enough task—a fake CAPTCHA overlay, and the inclusion of a single terminal command. So many visitors get suckered into pasting and running the command that just about every malware pusher has adopted the technique. Even Kremlin-backed hacking groups are joining in.

“Reddit is becoming post after post after post of people getting their computer infected via ClickFix,” independent researcher Kevin Beaumont observed Thursday. “Legit websites everywhere [are] getting hacked to serve the fake captcha prompts.”

How many of us make things worse

More seasoned Internet users—a fair number who read this site—are quick to dismiss the attack. They typically blame the people who fall for the scams and marvel at their gullibility and lack of attention. The reality is that for more casual users, using computers and the Internet has become so difficult—think impossible-to-close interstitials, CAPTCHAs with an endless series of pictures to analyze, and constantly changing interfaces that bury the features they’re looking for—that they have grown desensitized to instructions that seem ridiculous and burdensome.

Read full article

Comments

Your Critical Vulnerabilities Might Not Be Your Biggest Risk

The Hacker News - 11 Září, 2026 - 13:30
Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually create a path to compromise. A critical vulnerability may look alarming on a scanner report, but if it sits behind strong segmentation, identity controls, and other defenses that prevent an attacker [email protected]
Kategorie: Hacking & Security

GitLab urges users to patch max severity path traversal flaw

Bleeping Computer - 11 Září, 2026 - 13:15
GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. [...]
Kategorie: Hacking & Security

Microsoft fixes Teams, Outlook launch failures on ARM Windows PCs

Bleeping Computer - 11 Září, 2026 - 11:39
Microsoft has fixed a bug that prevented Teams and Outlook from launching on ARM-based Windows devices after installing updates released since the August 2026 Patch Tuesday. [...]
Kategorie: Hacking & Security
Syndikovat obsah