Security-Portal.cz je internetový portál zaměřený na počítačovou bezpečnost, hacking, anonymitu, počítačové sítě, programování, šifrování, exploity, Linux a BSD systémy. Provozuje spoustu zajímavých služeb a podporuje příznivce v zajímavých projektech.

Kategorie

SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs

The Hacker News - 19 Srpen, 2026 - 15:12
A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia. The intrusion set makes use of seven remote access tool (RAT) families, five of which have never been previously documented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. SilkParasite, first discovered in late 2025, is assessed to be a
Kategorie: Hacking & Security

SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs

The Hacker News - 19 Srpen, 2026 - 15:12
A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia. The intrusion set makes use of seven remote access tool (RAT) families, five of which have never been previously documented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. SilkParasite, first discovered in late 2025, is assessed to be a Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P

The Hacker News - 19 Srpen, 2026 - 13:34
Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay technique. The activity, codenamed Operation CameraSwarm, was reconstructed from a 407 MB exposed working directory containing 2,616 files
Kategorie: Hacking & Security

Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P

The Hacker News - 19 Srpen, 2026 - 13:34
Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay technique. The activity, codenamed Operation CameraSwarm, was reconstructed from a 407 MB exposed working directory containing 2,616 files Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Phishing 3.0: The Fight Moves to Agent Versus Agent

The Hacker News - 19 Srpen, 2026 - 13:30
Most email defenses still do the job they did a decade ago. Scan the message, look for something malicious, block it. That worked when the danger sat in the payload, a bad link or an attachment. It stopped working when the danger moved into the message's intent, and it is failing now that the sender is no longer a person. From Bad Content to Bad Intent to AI on Both Sides Phishing 1.0 was bad
Kategorie: Hacking & Security

Phishing 3.0: The Fight Moves to Agent Versus Agent

The Hacker News - 19 Srpen, 2026 - 13:30
Most email defenses still do the job they did a decade ago. Scan the message, look for something malicious, block it. That worked when the danger sat in the payload, a bad link or an attachment. It stopped working when the danger moved into the message's intent, and it is failing now that the sender is no longer a person. From Bad Content to Bad Intent to AI on Both Sides Phishing 1.0 was bad [email protected]
Kategorie: Hacking & Security

StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

The Hacker News - 19 Srpen, 2026 - 13:25
Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the activity. "The operation doesn't rely on a single piece of malware, but on a whole toolkit of criminal software
Kategorie: Hacking & Security

StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

The Hacker News - 19 Srpen, 2026 - 13:25
Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the activity. "The operation doesn't rely on a single piece of malware, but on a whole toolkit of criminal software Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Microsoft fixes known issue causing Windows Defender crashes

Bleeping Computer - 19 Srpen, 2026 - 13:14
Microsoft has resolved a bug that caused Windows Defender to crash after a recent security update, resulting in 0xc0000005 access violation errors on some affected systems. [...]
Kategorie: Hacking & Security

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

The Hacker News - 19 Srpen, 2026 - 13:01
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. The shortcomings added to the KEV catalog are listed below - CVE-2026-65400 (CVSS score: 9.8) - An improper authentication vulnerability impacting Apple macOS that could allow an
Kategorie: Hacking & Security

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

The Hacker News - 19 Srpen, 2026 - 13:01
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. The shortcomings added to the KEV catalog are listed below - CVE-2026-65400 (CVSS score: 9.8) - An improper authentication vulnerability impacting Apple macOS that could allow an Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Critical RCE flaw in Windows IKE Extension now actively exploited

Bleeping Computer - 19 Srpen, 2026 - 12:12
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity remote code execution (RCE) flaw in the Windows Internet Key Exchange (IKE) Service Extensions component. [...]
Kategorie: Hacking & Security

Windows 11 24H2 Home and Pro reach end of support in 2 months

Bleeping Computer - 19 Srpen, 2026 - 11:10
Microsoft has reminded customers that systems running Home and Pro editions of Windows 11 24H2 will stop receiving updates in two months. [...]
Kategorie: Hacking & Security

CISA: Medusa ransomware hit over 500 critical infrastructure orgs

Bleeping Computer - 19 Srpen, 2026 - 10:00
The FBI said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021. [...]
Kategorie: Hacking & Security

Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure

The Hacker News - 19 Srpen, 2026 - 08:01
Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, after correlating recurring endpoint and network behaviors across changing infrastructure, tracing the malware from payload retrieval through data collection, staging, and exfiltration. The tech giant said it required multiple endpoint and network behaviors to align before
Kategorie: Hacking & Security

Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure

The Hacker News - 19 Srpen, 2026 - 08:01
Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, after correlating recurring endpoint and network behaviors across changing infrastructure, tracing the malware from payload retrieval through data collection, staging, and exfiltration. The tech giant said it required multiple endpoint and network behaviors to align before Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

The Hacker News - 19 Srpen, 2026 - 07:39
A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Management (PLM) software, according to new findings from ReliaQuest. The cybersecurity company characterized the web shell as a fully equipped extortion platform capable of mapping sensitive vault
Kategorie: Hacking & Security

Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

The Hacker News - 19 Srpen, 2026 - 07:39
A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Management (PLM) software, according to new findings from ReliaQuest. The cybersecurity company characterized the web shell as a fully equipped extortion platform capable of mapping sensitive vault Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Microsoft finally patches critical one-click Copilot vulnerability, almost eight months after learning of it

Computerworld.com [Hacking News] - 19 Srpen, 2026 - 04:23

Almost eight months after confirming a critical security vulnerability within the personal version of its AI assistant, Copilot, Microsoft on Tuesday issued a patch to close the hole, which relies on an LLM’s inability to distinguish the data in a query from an instruction.

The CoSnitch hole was discovered by Varonis, and marked the third Copilot bug that Varonis has reported to Microsoft this year, following Reprompt, which bypassed Copilot guardrails by repeating queries, and SearchLeak, which Varonis said turned Microsoft 365 Copilot Enterprise into “a silent exfiltration tool. All three share the same exploit pattern: one click on a legitimate-looking link is enough.”

A detailed blog, posted by Varonis on Tuesday, said the hole’s capabilities were significant. 

CoSnitch relied on an attacker leveraging three different Copilot flaws, Varonis wrote: 

  • Automatic prompt execution. “The ?q= URL parameter, combined with an undocumented parameter, causes any attacker-supplied prompt to execute instantly on page load: no click, no confirmation, no user action. One link is all it takes.”
  • Data exfiltration to external servers. “An injected prompt can query the victim’s connected apps, such as Gmail, Drive, Calendar or OneDrive, encode the results into a URL and exfiltrate them via Copilot’s built-in URL-fetch capability to an attacker-controlled webhook.”
  • Persistent memory poisoning via web summarization. “A crafted webpage, when summarized by Copilot, injects attacker instructions into the victim’s permanent memory store. The injection survives password changes, session revocation, and device re-enrollment, persisting forever.”

But the potentially most intriguing element of the CoSnitch bug was how it was discovered: Copilot essentially revealed the hole itself. 

Copilot revealed its own flaw

“We prompted Copilot to explain why auto-execution was impossible, and each refusal came with a technical justification, which mapped the architecture,” the Varonis post said. Varonis then “reframed every refusal as a follow-up question, and each answer narrowed the attack surface further. Copilot then disclosed an undocumented URL parameter, unprompted, mid-refusal, including its historical behavior and every protection put in place to disable it. We built the URL exactly as described. With no click or confirmation from the user, the prompt was successfully executed automatically. Copilot wasn’t breached; it was played.”

Microsoft confirmed both the flaw and the fix, emailing a statement that said, “our customers are already protected and do not need to take any action. We continuously update our guardrails to strengthen our protections against similar techniques.” It also issued an MSRC disclosure labeling the hole “critical.” 

But Microsoft’s emailed comments also included a statement that is not strictly accurate: It said, “enterprise customers using Microsoft 365 Copilot are not affected.”

But analysts and others stressed that the complex nature of enterprise environments would often also house some consumer-grade Copilots from the personal accounts of workforce members, meaning that the flaw in the personal version could have absolutely impacted the enterprise version.

This is further complicated by the fact that Microsoft also said that it “is in the process of moving toward a more unified Copilot experience,” referred to as Copilot Fusion; details of the planned product merger began to leak last month. That means that enterprise CISOs need to be concerned about flaws in the personal version of Copilot that may be carried over into the merged offering.

The timing of Microsoft’s fix was also fragmented. Varonis reported the CoSnitch hole on December 31, and the company patched one element of the hole, its auto-execution capability, on February 1, noted Lior Adar, a Varonis senior security researcher, in an interview, but it didn’t complete the fix until Tuesday.

That February patch “lowered the other vulnerabilities significantly,” Adar said. And, added his colleague, Chen Levy Ben Aroy, the Varonis Cloud Security Research Team leader, “LLMs are a whole new world of vulnerabilities.”

Mark Tauschek, VP and distinguished analyst at Info-Tech Research Group, said that he found the Varonis methodology of tricking Copilot into revealing its own flaws powerful.

Varonis used “a very sophisticated combination of social engineering on an LLM, a variety of jailbreaks, and a prompt injection attack that is very concerning in its capability,” he said. “The combination of hack vectors is what makes it more startling, as we’ve seen all of those methods alone before, but I think all three working for one exploit is new, at least from a disclosure perspective.”

For CISOs, Tauschek said urgent action might be required. 

“Much like in the old macro virus days in the late 90s and early 2000s, the only way to definitively stop it is to turn it off. Disable macros back then. Disable Copilot now,” Tauschek said. “There are many mitigation steps that can reduce risk to negligible, but that’s not zero. The point is, it’s just the beginning.”

The money trail will make this fix difficult

Aman Mahapatra, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, said there is a much more difficult issue involved in this case. He argued that the financial incentives for the major AI companies will make meaningfully fixing these kinds of holes almost impossible.  

He pointed out that every guardrail that would fully close this class of attack degrades the product, because the same capabilities being exploited are the features that Microsoft is marketing as Copilot’s value. “The fix and the feature are in direct tension, which means these will not be cleanly patched so much as perpetually mitigated, and the eight-month window is what it looks like when a vendor is negotiating between its security obligation and its product roadmap on every single fix,” Mahapatra said.

“This is the pattern CISOs must internalize: in agentic systems, the malicious action and the legitimate action are the same action with different intent, which collapses the entire signature-and-anomaly detection model that enterprise security has been built on for twenty years,” Mahapatra said. “CoSnitch is serious, but its defining property is that nothing was broken. Three chained flaws: an autorun URL parameter firing a prompt with no click, OAuth connector abuse reading full Gmail bodies rather than metadata, and persistent memory poisoning through web summarization, and every one is Copilot doing exactly what it was designed to do.”

Mahapatra added that the third element of the CoSnitch flaw is the most troubling.

“The memory-poisoning component is the one being undersold, and it is the most dangerous. A single summarized webpage writes attacker instructions into Copilot’s persistent memory, and that memory survives password changes, session revocation, and device re-enrollment,” he said. “Every standard incident response step leaves the injection intact. The attacker needs no persistent infrastructure after the initial write, because every future session runs under attacker-controlled context, recorded only in a memory settings UI almost no user has opened.”

Flavio Villanustre, CISO for the LexisNexis Risk Solutions Group, also pointed to a bigger-picture issue that impacts all agentic and genAI deployments. 

“The mechanisms behind the prompt injection part of the attack are based on the inability of the LLM to differentiate between data, the unsafe data stream coming from an external web page, and instructions which happen to be embedded in that data stream by the attacker controlling that external web page,” Villanustre said. “This is another example of why a different architectural approach to LLMs that separates data and instructions is needed to better guarantee the safety of their operation. This is not something that Microsoft or any other AI vendor has addressed to date.”

Kategorie: Hacking & Security
Syndikovat obsah