Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

Police dismantle Kratos phishing platform, arrest developer

Bleeping Computer - 1 hodina 27 min zpět
Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia. [...]
Kategorie: Hacking & Security

FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware

Bleeping Computer - 2 hodiny 1 min zpět
A large-scale operation dubbed 'FakeGit' is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads. [...]
Kategorie: Hacking & Security

Critical SharePoint RCE flaw exploited to steal machine keys

Bleeping Computer - 21 Červenec, 2026 - 22:06
Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched. [...]
Kategorie: Hacking & Security

Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak

Bleeping Computer - 21 Červenec, 2026 - 20:50
The Anubis ransomware gang has claimed responsibility for the cyberattack on Coca-Cola's Fairlife dairy subsidiary, threatening to publish allegedly stolen corporate data unless the company pays a ransom. [...]
Kategorie: Hacking & Security

Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs

The Hacker News - 21 Červenec, 2026 - 20:46
Apple has moved to address a security flaw in its Hide My Email service that enabled users' real email addresses to be unmasked, effectively undermining the feature's privacy guarantees. 404 Media reported Tuesday that a fix for the issue was deployed by Apple on July 3, 2026, after more than a year, when it was disclosed to the company by Tyler Murphy, co-founder of EasyOptOuts. Hide My EmailRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Anthropic pays $1.5B to settle contentious copyright case

Computerworld.com [Hacking News] - 21 Červenec, 2026 - 20:12

A US federal court has approved Anthropic’s $1.5 billion settlement in a class-action lawsuit in which authors accused the AI company of using their books without permission to train the AI model Claude. This is the largest such settlement to date in a US copyright case, according to Reuters.

The dispute is one of several legal cases in which copyright holders sued AI companies over how large language models (LLMs) were trained, and it is the first major AI-related copyright dispute in the US to be resolved through a settlement.

A judge had previously ruled that the actual training of AI models using books falls under the “fair use” doctrine in US copyright law. But Anthropic was found to have violated the law by storing more than 7 million pirated books in a central library, regardless of whether they were later used for AI training or not.

Kategorie: Hacking & Security

Critical wp2shell WordPress flaws exploited to install webshells

Bleeping Computer - 21 Červenec, 2026 - 18:41
Hackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent webshells and install malicious plugins on affected servers. [...]
Kategorie: Hacking & Security

Apple and the changing of the guard

Computerworld.com [Hacking News] - 21 Červenec, 2026 - 18:25

As Apple gears up to anoint John Ternus the new company CEO in September (while current leader Tim Cook takes a seat on the board) the company appears to be firing on all cylinders ahead of the leadership transition. 

What’s going well

Just look at the evidence: 

  • Apple is building market share across its entire product range; even memory-driven price inflation doesn’t seem to have dampened demand for its hardware yet.
  • While Apple had to raise prices, the company’s MacBook Neo remains seriously popular. It’s sitting atop Amazon’s US best-selling chart, which currently includes six Macs in the top 10. The Neo has topped this chart since its introduction.
  • Apple’s iPhone 17 series continues to sell well, with recent market data showing sustained growth. Both Counterpoint and IDC tell us that iPhone shipments continue to increase, even as other vendor shipments slide.
  • IDC analyst Francisco Jeronimo recently estimated that Apple’s upcoming foldable iPhone Ultra could grab 29.4% of global folding smartphone sales this year, rising to 34.9% in 2027.
  • The company’s new 27 series of operating systems is attracting a great response as beta testers report that it is already solid, stable, and performing well.
  • The AI narrative has really changed, with analysts no longer quite so starry-eyed at the prospects for the big frontier AI firms. Apple’s edge-AI-enabling approach is winning converts.
What’s coming up

The company’s newly-filed lawsuit against OpenAI may or may not succeed, but it will certainly help consolidate recognition of the importance of Apple’s designs and intellectual property in whatever hardware emerges from the AI firm. It also means both Apple and OpenAI are already competing in hardware, even though neither company yet offers anything that directly challenges the other. 

Apple has just set out its stall to brand-loyal fans in a big way and did so before OpenAI gets to woo the same set of customers with a wriggle of its Jony Ive-tinged talisman.

The stage is set for intense competition between the two. Though some say Apple’s needs to improve employee retention, if it does find proof of efforts to use recruitment to engage in industrial espionage, it’ll be easier to represent its own products as being the OG for new hardware. 

If nothing else, it means consumers will forever be asking, “If OpenAI’s designers are so good, why did it need to poach them from Apple?” Doubt is a weapon.

Managing perception

It doesn’t matter how the case goes, because there fight is already affecting consumer psychology. It also means that as Ternus prepares to take his seat atop the rainbow-colored Apple throne, we can already size him up. “A man is measured by his enemies,” Joe Abercrombie wrote in “The Trouble With Peace.”

Given the proximity of the leadership transition, it’s highly probable that Ternus signed-off on the litigation; in doing so he — and Apple — tell us to expect more of the same. 

Apple has, rightly or wrongly, decided that OpenAI will become its new existential bugbear, following in the footsteps of Microsoft Windows, Real Networks, Adobe Flash, Android, and Samsung, all of whom have been useful foils against which Apple has been able to build and maintain its identity.

Looking at that list, you’d be tempted to believe that nothing much is new. Apple has often defined itself by the enemies it sometimes keeps. What has been will be again, which in this case means even as OpenAI attempts to carve out an identity as a hardware manufacturer delivering solutions to compete with Apple and Google, Ternus’ team’s looks to drive a consensus-shaped wedge into the pro-LLM propaganda. 

That blow comes as Apple finally gets its act together around AI, and as the company prepares for a future in which the world’s most-used wearable device also becomes the wearable way to woo Siri AI.

My kingdom come

Rising market share, powerful solutions, an increasingly recognized and respected approach to AI, and an ideological crusade — these details constitute Apple’s place today and are Tim Cook’s coronation gift to Ternus. He’s passing along a strong and hyper-profitable baton that screams of timeliness and relevance even as the company gets set, ready, to go with a year or two of new product designs, new product families, and a 20thanniversary iPhone.

This is Apple’s party. OpenAI’s name didn’t make the list. 

You can follow me on social media! Join me on BlueSky,  LinkedInMastodon and subscribe to The Core.

Kategorie: Hacking & Security

AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code

The Hacker News - 21 Červenec, 2026 - 18:06
Hidden text on a web page was enough to make Kiro, AWS's agentic coding IDE, rewrite its own configuration file and run an attacker's code on a developer's machine, with no approval step able to stop it. Intezer, in research with Kodem Security, found that a request as ordinary as asking Kiro to summarize a page could end in remote code execution. AWS has patched the issue, and no CVE has been Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

TreeSize won't renew perpetual-license support unless users subscribe

Ars Technica - 21 Červenec, 2026 - 17:18

The company behind the disk space analyzer TreeSize has irked some users by no longer offering support or updates for perpetual licenses beyond their maintenance period unless customers subscribe. Further frustration has come from JAM Software's long-standing policy of not providing license keys or installers to TreeSize perpetual license holders after that support period ends.

Since 2025, JAM Software has been transitioning most TreeSize editions to subscription models. Today, it sells perpetual licenses only for personal use, which include 12 months of updates, support, and “downloads of older versions, and your license,” plus the option to extend the support period. TreeSize currently has "no plans to discontinue the sale of perpetual licenses for TreeSize Personal," product manager Hendrik Christ told Ars Technica.

As perpetual-license maintenance periods expire, customers are discovering that extending support now generally requires subscribing to software they already own the right to use.

Read full article

Comments

Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities

The Hacker News - 21 Červenec, 2026 - 17:09
Google's DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.5 Flash that's designed to discover, validate, and patch vulnerabilities quickly and efficiently. According to the tech giant, the model will be exclusively available to governments and trusted partners via CodeMender as part of a limited-access pilot Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

The Hacker News - 21 Červenec, 2026 - 16:57
A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Office SharePoint that could allow an unauthorized attacker to execute code over a network. Microsoft credited DEVCORE Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

The Hacker News - 21 Červenec, 2026 - 16:04
Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments. Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Closing the Identity Gaps in Critical Infrastructure Security

Bleeping Computer - 21 Červenec, 2026 - 16:00
Critical infrastructure attacks often begin with stolen credentials, compromised devices, or trusted accounts. Specops Software explains why Zero Trust should verify both user identities and device trust before granting access to critical systems. [...]
Kategorie: Hacking & Security

Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities

The Hacker News - 21 Červenec, 2026 - 15:18
Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component. As many as nine security vulnerabilities have been patched in Zimbra 10.1.20. Topping the list is a command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled. Also patched Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

A new extortion cocktail: office printers, small ransoms, and BitLocker

Kaspersky Securelist - 21 Červenec, 2026 - 15:00

Recently, our teams in Latin America investigated a series of incidents involving misconfiguration, the deployment of BitLocker, and the exploitation of corporate printers. Attackers used the devices to notify organizations that their infrastructure had been compromised and they had to pay a ransom to recover their data.

This article analyzes two incidents that occurred in June in Colombia and in May in Mexico. We highlight the similarities in the attackers’ communications and outline emerging trends in ransom amounts.

Initial sign of an attack

In both cases, the affected users initially noticed a padlock icon next to their drives in Windows Explorer. This indicated that the drive was encrypted with BitLocker, blocking access to its contents.

Drive icon indicating that the drive is locked

A recovery key was required to unlock the drive.

Attempt to access the disk’s contents and the prompt for the BitLocker recovery key

This is not the first time we have seen such threats; a few years ago, our team discovered a threat known as ShrinkLocker, which utilized BitLocker to achieve its goals.

First case: abusing RDP to encrypt data

One of the incidents occurred in Colombia in June. The attackers exploited an internet-exposed RDP service on a machine connected to an 8 TB storage device containing mission-critical data. After taking control of the system and manipulating user credentials, the attackers enabled BitLocker exclusively on the drive that primarily stored financial data. Once the encryption was complete, they locked the drive and used the company’s printers to produce ransom notes.

Ransomware note

Unfortunately, it was not possible to obtain evidence in the case due to the company’s rush to restore the encrypted disk. The communication with the attackers revealed a demand for just $3,000, and the company considered paying the ransom. After that, the system was restored before the forensic team could take any action, eliminating the evidence needed to assess the incident.

Attacker’s reply to the victim’s email sent to the address in the printed ransom note

This attack was made possible by an internet-facing remote desktop service (RDP) with additional open ports, which employees used to access corporate information. By exploiting this network exposure and misconfiguration, attackers breached the system, identified an additional drive, and leveraged BitLocker to encrypt the data and demand a ransom payment. Leaving RDP ports open without proper security controls jeopardizes the security of systems and information, as highlighted in the our “Global Report: Anatomy of a Cyber World“.

Exposed ports identified in the system in recent months

The company confirmed that, due to compatibility issues with applications required for operation, EPP (Endpoint Protection Platform) protection was disabled on the system, making it easier for attackers to validate, enumerate, and execute applications without revealing malicious activity to central monitoring systems.

Second case: meet the XEntry Team

In another incident, which occurred in Mexico in May, our team identified how the threat actor gained initial access to the infrastructure. They exploited a misconfigured MSSQL service. This allowed them to execute commands on the system after obtaining the database login credentials from code insecurely published on GitHub.

XEntry team attack

In this incident, the attack began three months prior to detection, with the intruder discovering and verifying their access to the environment. After confirming their access and privilege level within the MSSQL server settings, which extended beyond the DBMS to the underlying operating system, the attackers initially focused on manipulating certain aspects of the web server configuration on the same system. They lowered the server’s security settings and created web shell files in the publicly accessible folders. Many of these attempts to manipulate the service or create malicious files were contained by existing EPP security controls, but despite the alerts, the necessary investigation to address the activity was not conducted.

Commands executed when attempting to manipulate the web server

The attackers subsequently confirmed their ability to execute commands locally and set up their attack infrastructure to transmit data via a communications bridge. By exploiting the MSSQL service, they gained access to each of the organization’s internal systems.

The database engine used by the company was Microsoft SQL Server 2019.0150.2160.04, misconfigured to allow operating system сommand execution via the xp_cmdshell extended stored procedure.

Due to this misconfiguration of an internet-exposed service, the attackers established a channel capable of executing any type of command directed at the server and the local infrastructure within its scope.

Attack path

One of the main objectives was to identify shared systems and resources that provided access to critical information. Our analysis confirmed the attackers’ access to systems storing configuration parameters for networking, enterprise management, and cloud services, among others.

A subset of the critical information identified and collected by the attackers

In early May, the attackers focused on running additional scans and deploying ManageEngine’s Endpoint Central RMM (Remote Monitoring and Management) to establish persistence and begin the final stages of their intrusion.

Scanning and RMM deployment

Further RMM-type applications, such as Mesh Agent and Tactical RMM, were installed in the days that followed. These were used to deploy scheduled tasks responsible for enabling the BitLocker service and individually encrypting the infrastructure’s disks, generating a key for each encrypted system.

Commands executed through RMM tools to collect Bitlocker keys

Finally, in mid-May, the attackers managed to execute a Group Policy Object (GPO) used to deploy activation and encryption tasks, as well as other policies responsible for continued deployment of RMM applications via scheduled tasks. The activity initially targeted critical systems but later spread to every system synchronized with the domain controller. Users became aware of the attack when their machines displayed a blue screen with the message “Hacked by XEntry Team”, and their credentials stopped working to access their systems.

A few hours later, ransom notes began emerging from office printers.

Ransom note printed by the XEntry team

These cases confirm that adversary’s objective is to gain access to infrastructure while avoiding investment in or partnership with ransomware groups. Instead, they leverage built-in Microsoft tools to facilitate data encryption and ransom payments. Monitoring and centralizing logs on protected resources, as well as promptly managing alerts, are critical to countering this type of intrusion.

Conclusions
  • Although the systems under review had security measures in place, there was a lack of proper alert management or inadequate decisions regarding application incompatibilities.
  • We strongly recommend configuring the Remote Desktop Protocol (RDP) in strict accordance with cybersecurity best practices to prevent unauthorized access. This is especially critical: according to our Global Report: Anatomy of a Cyber World, more than 13% of incidents are related to policy violations and configuration errors, confirming that misconfigurations continue to pose a significant risk.
  • Organizations should prioritize strict application control policies and active monitoring of network traffic for command-and-control (C2) communications. This is especially critical: according to the same report, more than 20% of incidents involved the abuse of RMM (Remote Monitoring and Management) tools for execution and C2 strategies. The fact that attackers used more than three distinct tools to gain control during a single incident further underscores the urgent need for these measures.
  • Some questions remain unanswered due to a lack of evidence and a hasty system restoration effort that bypassed critical stages of the incident response process. It is important to ensure an adequate incident response procedure, preserving evidence to confirm all related activities, and adjusting or proposing controls to prevent future incidents involving similar TTPs.
  • Although the ransom notes do not reveal a clear connection between the actors, certain words used in the messages, as well as the method of delivery and communication, may confirm a link:

“As a guarantee, we have no negative online reviews about non-fulfillment of our obligations…” (Ransom note from the first case)

“Our reputation is the guarantee that all content will be fulfilled…” (Ransom note from the second case)

Our teams continue to monitor these threats.

Detection signatures
  • Trojan.Multi.Agent.gen
  • Trojan.Win32.GenAutorunMsSqlServerCommandRun.a
  • Trojan.Win32.Generic
  • Exploit.Win32.SCShell.a

US AI testing institute chief steps down within three months

Computerworld.com [Hacking News] - 21 Červenec, 2026 - 14:26

The head of the US government’s AI testing institute, Chris Fall, has resigned about three months after taking charge of the Center for AI Standards and Innovation (CAISI), the federal organization responsible for evaluating advanced artificial intelligence models for safety and security.

Current National Institute of Standards and Technology NIST Director Arvind Raman will serve as acting CAISI Director following Fall’s departure while continuing to oversee the Commerce Department office responsible for the institute, the Daily Signal reported, citing two people familiar with the matter.

A Commerce Department spokesperson who spoke to the publication did not disclose a reason for the resignation.

Fall assumed leadership of CAISI in April after the Trump administration reorganized the former US AI Safety Institute under NIST. The institute develops methodologies for evaluating frontier AI models and works with AI developers on voluntary technical assessments covering areas such as cybersecurity, model misuse, reliability and other risks associated with increasingly capable AI systems.

The leadership change comes as governments and AI companies continue developing technical approaches for evaluating frontier AI models while enterprises expand deployments of generative AI and agentic AI across business operations.

In recent months, the Commerce Department has taken a more active role in AI policy involving advanced models, placing greater attention on how the federal government evaluates technologies with potential national security implications.

Continuity matters more than personalities

CAISI works with AI developers such as Anthropic, Google’s DeepMind and OpenAI on voluntary evaluations of frontier AI models and develops methodologies for testing model capabilities and risks. The institute does not regulate AI developers or certify commercial AI systems.

For enterprises, those evaluations are one source of technical information alongside vendors’ own testing, third-party security assessments and internal AI governance programs.

Sanchit Vir Gogia, chief analyst at Greyhound Research, said enterprises should focus less on the individual leading the institute and more on whether its technical work continues with the same level of consistency and transparency.

“Leadership churn at CAISI weakens the signal long before it weakens the science,” Gogia said. “The testing has not stopped. Its authority simply does not travel as cleanly once the leadership does not.”

According to Gogia, the more important question for enterprises is not whether the institute’s evaluation work will continue but whether the processes supporting those evaluations remain stable.

“The instinct is to ask whether the pipeline is breaking,” he said. “The more useful question is where the pipeline now sits.”

Enterprises still carry the burden of AI governance

Gogia said organizations should continue treating government-led AI evaluations as one input into their governance processes rather than as evidence that a model is inherently safe for enterprise deployment.

“A government evaluation was always a signal, never a certificate,” he said. “A signal loses value the moment its issuer becomes unpredictable.”

He said enterprises should instead monitor whether CAISI maintains consistent evaluation methodologies, continues publishing technical findings and preserves continuity within its research teams under interim leadership.

“The name on the door is not the signal. The behaviour underneath it is,” Gogia said.

Gogia also cautioned against linking Fall’s resignation to recent Commerce Department actions involving AI policy or export controls, noting that there is no public evidence connecting the two.

“CAISI evaluates; it does not enforce export controls, because it holds no such power,” he said. “This is not a testing body reaching for enforcement. It is enforcement reaching past the testing body.”

With Raman assuming the role on an interim basis, the next significant milestone for enterprises will be the appointment of a permanent director, and whether the institute’s evaluation programs continue without disruption, the analyst said.

Gogia said the successor’s mandate may prove more important than the individual selected.

“A CAISI result is not a safe harbour,” he said. “It informs an obligation; it does not discharge one.” NIST did not immediately respond to a request for comment.

Kategorie: Hacking & Security

Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs

The Hacker News - 21 Červenec, 2026 - 13:58
An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the same app is running commands on the PC driving the agent. Researchers demonstrated that chain, plus six other attacks, against five open-source mobile agent frameworks: AppAgent, AppAgentX, Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

N-day is Becoming N-Hour. Patching Faster Won't Save You.

The Hacker News - 21 Červenec, 2026 - 13:42
Every patch is a confession. The moment a vendor ships a security fix, the diff between the old code and the new code tells anyone watching exactly what was broken and where. Turn that diff back into a working exploit, and you can hit every system that hasn't updated yet. This is N-day exploitation, and it's always been a race: the vendor patches, the clock starts, and defenders try to deploy [email protected]
Kategorie: Hacking & Security

New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit

The Hacker News - 21 Červenec, 2026 - 13:24
A cloud tenant using nothing but ordinary GPU access can push a data center's power draw up and down fast enough to threaten the grid it runs on, with no exploit and no break-in. That is the claim behind Bit2Watt, described by three Zhejiang University researchers in a paper accepted to CHES 2026, the IACR's hardware-security conference, and the evidence splits in two: they measured the power Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security
Syndikovat obsah