Agregátor RSS

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

The Hacker News - 9 Září, 2026 - 09:36
Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances' own PHP scripts, the malware adds the web shell to the copy held in memory, so a check of the file on disk can come back clean. Those three scripts are
Kategorie: Hacking & Security

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

The Hacker News - 9 Září, 2026 - 09:36
Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances' own PHP scripts, the malware adds the web shell to the copy held in memory, so a check of the file on disk can come back clean. Those three scripts are Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

Bleeping Computer - 9 Září, 2026 - 09:30
An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. [...]
Kategorie: Hacking & Security

Sluchátka se mění v hlídače našeho zdraví. Měří tep, sledují spánek a pomáhají se špatným sluchem

Živě.cz - 9 Září, 2026 - 09:15
Anker během jediného týdne představil naslouchadla, sluchátka sledující spánek a přístroj, který měří dech i tep z nočního stolku. Spotřební audio objevilo zdraví. Vedle skutečného užitku se ale prodává také pocit, že kdo své tělo nepřetržitě neměří, nedělá pro sebe dost.
Kategorie: IT News

Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed

The Hacker News - 9 Září, 2026 - 08:47
The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher reported last month. "Microsoft has failed to properly patch ShieldBreak CVE-2026-69414," Chaotic
Kategorie: Hacking & Security

Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed

The Hacker News - 9 Září, 2026 - 08:47
The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher reported last month. "Microsoft has failed to properly patch ShieldBreak CVE-2026-69414," Chaotic Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Největší investice v historii Česka se komplikuje. Onsemi stěhuje stroje do Asie a Babišova vláda váhá s pobídkou

Živě.cz - 9 Září, 2026 - 08:45
Největší zahraniční investice v historii Česka, rozšíření továrny Onsemi, se zdá být stále nejistější. • Onsemi v Rožnově propustila stovky lidí a stroje na výrobu čipů raději přesunula do Asie. • Projekt by mohl pomoct i dalším automobilkám v Česku, věří exministr Lukáš Vlček.
Kategorie: IT News

Google warns of new Chrome zero-day bug exploited in attacks

Bleeping Computer - 9 Září, 2026 - 08:25
Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year. [...]
Kategorie: Hacking & Security

SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

The Hacker News - 9 Září, 2026 - 08:25
SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE-2026-44756 (CVSS score: 10.0), has been described as a case of memory corruption. Discovered and reported by SAP
Kategorie: Hacking & Security

SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

The Hacker News - 9 Září, 2026 - 08:25
SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE-2026-44756 (CVSS score: 10.0), has been described as a case of memory corruption. Discovered and reported by SAP Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Volkswagen už ví, co bude vyrábět, až evropské automobilky rozdrtí Čína. Legendární izraelský Iron Dome

Živě.cz - 9 Září, 2026 - 07:45
Šéfové Volkswagenu se v posledních letech už několikrát nechali slyšet, že je doba zlá a německá průmyslová legenda se neobejde bez hlubší restrukturalizace. Jednou z cest je zbrojní a obecně obranný průmysl, kterému dal zelenou i Berlín a hodlá do něj nalévat miliardy eur. Z ikonických fabrik tak ...
Kategorie: IT News

Intel na podzim zdraží procesory o ~10 %, uvažuje i o zrušení levných Atomů

CD-R server - 9 Září, 2026 - 07:40
Intel připravuje dodavatelský řetězec na podzimní zdražování procesorů. Jde patrně o součást transformace Intelu pod taktovkou Lip-Bu Tana. Pokračuje také propouštění, společnost opustí další tisíce…
Kategorie: IT News

Leap second proposal will keep software stacks in sync

Computerworld.com [Hacking News] - 9 Září, 2026 - 07:24

For decades, global time experts have mapped atomic clock time to the earth’s rotation, periodically adding a second (aka a leap second) as rotation slowed. But the planet’s rotation has now slightly sped up, which could mean that a negative adjustment will be required. 

The problem is that computer systems have not been programmed to do that.

To avoid this issue, the General Conference on Weights and Measures (GCWM) in October will vote on a proposal to maintain the Coordinated Universal Time (UTC) as a continuous time from May 20, 2027, without adjustment via leap seconds, allowing UT1, the measure of time based on the earth’s rotation, and UTC to drift apart by up to one hour.

It pointed out, “a negative leap second has not previously been applied, and it is considered to pose a high risk of causing anomalies and disruption to critical infrastructures that are largely unprepared, and the preparation would create, for the industries that rely on time synchronization, a need for financial investment, whose amount is estimated to be similar to their preparations for the millennium bug.”

The group said that a 2025 workshop which included experts on Earth rotation estimated that the probability of a negative leap second will increase rapidly in the near future, reaching 30% by 2035. Acceptance of the proposal, it said, will ensure the long-term continuity for UTC for several centuries.

Unexpected requirement

Jeremy Roberts, senior director at Info-Tech Research Group, said that authorities never expected the need to reverse time. 

“We have been adding leap seconds for decades, basically to keep atomic time in line with observed time, but this is the first time we’d have to take one away. The problem is that computer systems aren’t designed to work this way,” Roberts said. “Rather than introduce a negative leap second, the proposal here is to let the two clocks go out of sync rather than keep adjusting to keep synchronicity with UT1 time and atomic time, which is much more consistent and not impacted by changes in the Earth’s rotation. This would make it easier for those building and maintaining infrastructure, because the clock would behave in a predictable way.”

Still, Roberts stressed that the proposed approach might eventually cause problems. 

“As with all things, this will require work to implement, and because the proposal includes a provision that allows for the clocks to go up to an hour out of sync, that would presumably create a problem for our descendants when we eventually reach that point,” Roberts said. “[But] being indecisive could cause fragmentation in standard time as different entities move to different standards, which could come with its own set of problems.”

Frank Dickson, principal analyst at Dickson Research, added that this proposed move is revolutionary in time-keeping circles.

“This is the biggest change to civil timekeeping since the leap second itself was adopted in 1972,” Dickson said. “Earth’s rotation has historically been slowing down, so that’s the only direction the system has ever had to handle. What’s crazy is that the Earth’s rotation has been speeding up in recent years, requiring a negative leap second, subtracting a second instead of adding one. Nobody has ever run that in production, at global scale, on the systems the world actually depends on.”

Dickson said that it is critically important that the vote pass, because the IT community has seen what happens when clocks malfunction.

“In a world of interlocking software applications, you cannot always predict how a global change will impact digital systems. In 2012, one ordinary positive leap second took down Reddit, LinkedIn, and Qantas’s booking system,” Dickson said. “It also triggered a race condition in the Linux kernel that spiked CPU load across servers worldwide. Nobody had tested for it because it had never happened before.”

And another incident involving timekeeping took down the Telstra network in Australia just last month. 

A ‘more rational’ engineering decision

Mike Wilkes, enterprise CISO at Aikido Security, pointed out that the consequences of a negative leap second could be significant. “Skipping a second can expose assumptions buried in databases, distributed systems, authentication systems, schedulers, market infrastructure and logging platforms,” he said. “The CGPM proposal is effectively saying that, rather than forcing the entire digital economy to prepare for a novel failure mode, we should make UTC continuous. That seems like a far more rational engineering decision.”

Most consultants and analysts agreed that if the vote to adjust current time procedures fails, the resultant problems would likely happen gradually, and possibly dramatically.

“The most likely problem would not necessarily be one spectacular global outage. I would be more concerned about thousands of smaller inconsistencies occurring simultaneously,” said Boris Kolev, global head of technology at JA Worldwide. The problems he anticipated included timestamps appearing out of order, distributed transactions behaving unexpectedly, authentication tokens being interpreted incorrectly, monitoring and audit trails becoming inconsistent, or different systems disagreeing about the sequence of events.

Systemic technology risk

But Kolev warned of a potentially more severe problem, as different companies sharing varied technology dependencies with enterprises try tackling the time problem differently.

“That means an enterprise does not only have to worry about what its own servers do. It has to consider what happens when its cloud provider, operating system, identity provider, database, external APIs, and on premises systems interpret the same moment differently,” Kolev said. “This is precisely the type of systemic technology risk that concerns CIOs: individually, every dependency may look manageable, but globally there are millions of interconnected systems maintained by different organizations, written in different eras, and operating under different assumptions.”

Justin Greis, CEO of consulting firm Acceligence, also said that he hoped the proposal would pass. 

“I think this is one of those cases where delaying what appears to be the technically correct answer may actually be the more responsible engineering decision. At some point, you have to ask whether preserving the relationship between civil time and the Earth’s rotation to within a second is worth introducing operational risk across financial systems, telecommunications networks, cloud platforms, power infrastructure, transportation systems and countless other technologies that depend on precise synchronization,” Greis said. “For the overwhelming majority of enterprise technology, I don’t think it is.”

This article originally appeared on Network World.

Kategorie: Hacking & Security

Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

The Hacker News - 9 Září, 2026 - 06:41
Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Of these, over 110 shortcomings have been assigned a critical severity rating.
Kategorie: Hacking & Security

Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

The Hacker News - 9 Září, 2026 - 06:41
Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Of these, over 110 shortcomings have been assigned a critical severity rating. Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

The Hacker News - 9 Září, 2026 - 06:27
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in question is CVE-2026-86218 (CVSS score: 10.0), which has been described as a
Kategorie: Hacking & Security

N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

The Hacker News - 9 Září, 2026 - 06:27
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in question is CVE-2026-86218 (CVSS score: 10.0), which has been described as a Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Microsoft adds age-awareness APIs that can tell if users are children, teens, or adults

Bleeping Computer - 9 Září, 2026 - 03:16
Microsoft is adding new age-awareness APIs to Windows 11 that will allow apps to determine whether someone is a child, teenager, or adult without exposing their exact date of birth. [...]
Kategorie: Hacking & Security

Microsoft breaks Patch Tuesday record with 974-CVE deluge

The Register - Anti-Virus - 9 Září, 2026 - 02:25
The vulnpocalypse is upon us, dear reader. Microsoft delivered a record number of patches to address 974 CVEs in its own products this month, including two bugs that Redmond says are already under exploitation. September's record-breaking collection of security updates comes after Microsoft served up 421 fixes in August, and 622 in July. We've seen the new normal and we are not impressed. Thanks, but no thanks, AI. In addition to Microsoft’s massive patch drop, Adobe on Tuesday issued 10 bulletins addressing 172 CVEs, including a max-severity vulnerability exploited as a zero day in Magento and its successor product Adobe Commerce. Adobe on Monday shipped a hotfix for this one, tracked as CVE-2026-75650 and named StyleSmuggler, that gives unauthenticated attackers remote code execution. StyleSmuggler If your organization has any type of online shop, prioritize this one first as it’s already being abused to compromise stores, according to e-commerce security shop Sansec. Sansec discovered StyleSmuggler, and reports that attacks started on September 4. Every version of Magento and Adobe Commerce, from 2.4.4 up to and including 2.4.9, has the flaw. The bug allows attackers to inject malicious PHP code inside Magento templates using the “styles” properties to evade safety detections. In confirmed attacks, the payload then installs a backdoor that connects to a command-and-control server and waits for instructions. “So far, we have no indication that the backdoor has been weaponized,” the Sansec Forensics Team wrote. Don’t wait to find out on this one. Put it at the top of your mitigation list. Microsoft's 974 CVEs On to Microsoft’s record-breaking 974 CVEs, which according to Tenable is not many fewer than the 1,130 CVEs Redmond issued in 2025. Two are already being exploited as zero-days. First up: CVE-2026-85880, a privilege escalation bug in Windows Advanced Local Procedure Call (ALPC). Successful exploitation can result in the attacker gaining SYSTEM privileges. “An attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system,” Redmond warned. “No additional user interaction is required.” No word yet on who is exploiting this bug, and to what end. The US Cybersecurity and Infrastructure Security Agency on Tuesday added CVE-2026-85880 plus a second Microsoft security hole (and the Adobe Commerce and Magento zero-day) to its Known Exploited Vulnerabilities Catalog, and set a September 22 deadline for federal agencies to fix both new Microsoft bugs and a September 11 deadline to patch the Adobe flaw. The second Microsoft bug found and exploited as a zero-day is CVE-2026-81963, another privilege escalation vulnerability. This one affects the Windows Update Stack. We also have very little detail about this flaw, other than it also allows attackers to gain SYSTEM-level access. “More likely is that this bug is being combined with a code execution bug to spread malware or ransomware,” opined Zero Day Initiative’s Dustin Childs, who advised users to “Patch this one quickly.” While those are the only two (so far) under active exploitation, Childs rated CVE-2026-55007, one of nine Exchange Server flaws disclosed this month, as “the most important” patch for the messaging server. It allows a remote, unauthenticated attacker to execute code on a vulnerable Exchange server by sending an email with a malicious Visio attachment. No user interaction is required, and the code executes when the server processes the attachment during content indexing. Redmond says it’s “difficult to reliably trigger,” but as Childs points out: “The attacker only needs to get it right once. Schedule your downtime and update your Exchange servers with haste.” Childs also said he counts 20 patches for wormable bugs, so be sure to read his full Patch Tuesday review for those. “While some might be more exploitable than others, having 20 of them in a single release is something else.” The missing CVE While Redmond addressed nearly 1,000 security holes this month alone, it’s also worth pointing out one that isn’t this month’s Patch Tuesday roundup: CVE-2026-85046. Google patched this bug in Chrome on September 3, and at the time warned that it “is aware that an exploit for CVE-2026-85046 exists in the wild.” The high-severity, type confusion flaw exists in the V8 JavaScript engine used in both Google’s Chrome and Microsoft’s Edge browsers. And yet Microsoft still hasn’t published a security advisory for CVE-2026-85046. “If you’re patched, you are protected, but if you rely on advisories to know which vulns exist, you could miss this zero-day vulnerability altogether,” Adam Barnett, lead software engineer at Rapid7, told The Register. “A patch without an advisory is perhaps marginally better than an advisory without a patch, but keeping track of exposures without reliable advisory materials is not straightforward,” Barnett said. “Chrome patched 11 other vulnerabilities at the same time as CVE-2026-85046, but it’s not yet clear if those are patched in Edge. Until Microsoft sets the record straight, the only safe assumption is that these vulnerabilities (e.g. CVE-2026-85045) remain unpatched in Edge.” ® Updated at 2145 GMT on September 10, 2026 After this story was published, Microsoft confirmed that the Chromium security updates have been incorporated in Microsoft Edge (Version 152.0.4191.62).
Kategorie: Viry a Červi
Syndikovat obsah