Agregátor RSS

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

The Hacker News - 25 Srpen, 2026 - 13:52
Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. "While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn't do harm, the threat actor’s use of npm isn't to infect developers who install it, but to use the Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

The Hacker News - 25 Srpen, 2026 - 13:33
Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE. While threat actors are known to abuse legitimate services to point to additional command-and-control (C2) infrastructure and blend in with regular network traffic, the development
Kategorie: Hacking & Security

E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

The Hacker News - 25 Srpen, 2026 - 13:33
Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE. While threat actors are known to abuse legitimate services to point to additional command-and-control (C2) infrastructure and blend in with regular network traffic, the developmentRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Frontier AI: Vulnerability Management's Systemic Revolution

The Hacker News - 25 Srpen, 2026 - 13:14
Vulnerability management has been a staple of security programs since the dawn of the cybersecurity discipline. The symbiotic relationship between vulnerability and patch management teams has also existed for that time and has gone through waves of contention and thankfulness. While this relationship required thoughtful care and feeding from both sides, both sides were aiming to work toward a
Kategorie: Hacking & Security

Frontier AI: Vulnerability Management's Systemic Revolution

The Hacker News - 25 Srpen, 2026 - 13:14
Vulnerability management has been a staple of security programs since the dawn of the cybersecurity discipline. The symbiotic relationship between vulnerability and patch management teams has also existed for that time and has gone through waves of contention and thankfulness. While this relationship required thoughtful care and feeding from both sides, both sides were aiming to work toward a [email protected]
Kategorie: Hacking & Security

Microsoft to China: So long, it’s been good to know ya….

Computerworld.com [Hacking News] - 25 Srpen, 2026 - 13:00

Once upon a time Microsoft was bullish on China. 

Back in early 2010, when Steve Ballmer was CEO and Bill Gates was Chairman, Google was threatening to pull out of China because of Chinese censorship and because of what the company called Chinese government-sponsored cyberattacks. Google wasn’t alone. Other tech companies — as well as politicians like then-House Speaker Nancy Pelosi — were saying the same things.

Microsoft, though, was having none of it. 

Ballmer told Reuters back then, “We’re attacked every day from all parts of the world and I think everybody else is, too. We didn’t see anything out of the ordinary.”

Reuters asked Ballmer whether the company would pull out of China, and Ballmer bluntly said, “No,” adding, “I don’t understand how that helps anything. I don’t understand how that helps us and I don’t understand how that helps China.”

There was, of course, an ulterior motive to Ballmer’s defense of its China relationship. Google’s search engine was dominant across the world, and Microsoft’s Bing couldn’t catch up. Ballmer hoped Bing would make inroads into the Chinese market and eventually overtake Google worldwide.

That didn’t happen, of course. It likely never will. 

Today, though, Microsoft has all but abandoned China. And that doesn’t look like it will change. Here’s why.

Microsoft hangs up the ‘Closing’ sign

First, let’s look at the ways Microsoft’s relationship with China has withered.

In the past five years, Microsoft has closed at least 15 offices and joint ventures with China, Reuters reports. The story claims the actions are part of a careful plan, adding, “Microsoft is pursuing what five company sources described as a strategy of retreat” from China.

24/7 Wall St. reports that among those now-closed joint ventures is Wicresoft, Microsoft’s first such venture in China. An estimated 2,000 jobs were lost in China as a result of the closing.

Microsoft is also moving much of its manufacturing out of the country. Most of its Surface, Xbox and hardware production will leave China, as will server-related manufacturing for data centers.

There are other signs of a retreat. In 2024, Microsoft closed all of its authorized Chinese retail stores and began selling its products via third-party and online partners. It’s also been reducing its Chinese headcount. According to 24/7 Wall St., “Around June 2026, Microsoft cut an estimated 200 to 400 Azure cloud jobs in China, its third downsizing round in two years.”

How did Microsoft get here?

This didn’t happen all at once. It’s been a long, gradual process, the result of geopolitical tensions between the US and China and the worsening business climate between the two countries.

Microsoft began engaging with China more than 30 years ago, in 1994 when Gates first visited the country. After that the company “made various efforts to build a relationship with the ruling Communist Party,” Reuters reported, including co-investments in startup incubators. 

Over time, Microsoft moved some manufacturing to China, opened Microsoft stores there, and pushed the Chinese government to buy Windows and other software. In 2014, Microsoft launched LinkedIn in China, agreeing to comply with the government’s censorship demands even as other companies like Google refused. 

But the relationship deteriorated in the mid-2010s as China soured on its relationships with US and western tech firms, believing they were spying on the Chinese government. To assuage Chinese fears, Microsoft built a version of Windows specifically for the Chinese government, called Windows 10 China ​Government Edition. (According to Reuters, current Microsoft CEO Satya Nadella personally handled the negotiations with the Chinese government for the OS.)

It flopped. Only a handful of Chinese government agencies purchased it, and in 2017 China established government procurement guidelines that largely froze it out.

Things went downhill from there. In 2021, Microsoft shuttered LinkedIn in China when China increased its censorship demands.

The current and future state of the relationship

So where are we now? Despite that “strategy of retreat” described by Reuters, Microsoft officially denies it’s backing away. But the company also said that as of 2024, only 1.5% of its revenue comes from China. That figure is probably even lower now. 

There’s one current bright spot in Microsoft’s Chinese relationship — the use of Azure to provide Chinese companies with AI services and infrastructure, notably TikTok owner ByteDance and fashion retailer Shein. 

But even that is at risk, because of increasingly powerful AI models in China like Kimi, which are less expensive than Microsoft’s and other US technologies.

What does this mean for the future? Expect Microsoft to gradually close more of its Chinese operations. Azure will likely be replaced by Chinese home-grown tech. Microsoft’s already shrunken income from China will shrink even more.

And that’s a good thing. Having a big presence in China — or even a small one — means making a deal with the devil by kowtowing to Chinese censors. It’s time Microsoft made the break-up complete.

Kategorie: Hacking & Security

Police arrests dozens of suspects in global cybercrime crackdown

Bleeping Computer - 25 Srpen, 2026 - 12:53
Law enforcement agencies from 22 countries helped identify 263 suspects and arrested 58 individuals linked to cybercrime networks coordinated by African crime groups. [...]
Kategorie: Hacking & Security

Tesla ruší solární tašky. Konec krásného snu, odteď už jen ošklivé černé panely

Živě.cz - 25 Srpen, 2026 - 12:45
Ta myšlenka je geniálně jednoduchá. Proč pokrývat střechu a pak na ni instalovat solární panely, když lze integrovat fotovoltaiku přímo do střešní krytiny? „Je to hezčí, lehčí a levnější řešení než kombinace obyčejné tašky a solárního panelu,“ sliboval Elon Musk v říjnu 2016, když představoval ...
Kategorie: IT News

CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw

The Register - Anti-Virus - 25 Srpen, 2026 - 12:43
The US Cybersecurity and Infrastructure Security Agency (CISA) just dished out another three-day deadline for patching an actively exploited vulnerability, the most urgent in its wheelhouse. The culprit: a max-severity Oracle bug affecting Windows VMs. Tracked as CVE-2026-21962 (10.0), the improper access control (CWE-284) flaw affects Oracle’s HTTP Server and WebLogic Server Proxy Plug-in. Successful attacks targeting CVE-2026-21962 can allow miscreants to create, delete, or modify access to critical data, and even gain “complete access” to all data stored on the affected systems. Oracle disclosed and provided patches for CVE-2026-21962 as part of its January 20, 2026, updates. At the time, it said versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0 were affected, and that the vulnerability could be exploited in low-complexity attacks. CISA added CVE-2026-21962 to its Known Exploited Vulnerability (KEV) catalog on August 24, giving federal civilian executive branch (FCEB) agencies three days to protect themselves against attacks – the tightest deadline it is authorized to set. Other bugs to have recently been given the three-day treatment include the critical remote code execution (RCE) flaw affecting Python scaling framework Ray. Despite being disclosed in 2025, CISA added it to the KEV catalog last week. N-able’s “god mode” vulnerability, the one that offered attackers "full administrative access to an N-central console" and was exploited as of July 31, according to the vendor, was also lumped with a three-day deadline when CISA added it to the KEV catalog on August 3. Although CISA only added Oracle’s CVE-2026-21962 to the KEV Catalog on Monday, seven months after it was first disclosed, reports from the private sector suggest attackers had the bug in their sights much earlier in the year. Vikas Kundu, cyber intelligence analyst at CloudSEK, operated a honeypot for 12 days between January 22 and February 3, shortly after CVE-2026-21962 was first disclosed and public exploit code was released. The honeypot captured attacks attempting to exploit the vulnerability, as well as other WebLogic RCE bugs dating back to 2020 and 2017. “The overall activity was characterized by high-volume, automated scanning, with tools like libredtail-http and the Nmap Scripting Engine dominating the malicious traffic,” he said. “Furthermore, the logs revealed significant background noise, including attempts to exploit non-WebLogic-specific vulnerabilities (e.g., Hikvision CVE, PHPUnit RCE, and generic command injections), indicating a broad ‘spray and pray’ approach by threat actors.” Kundu said the findings demonstrated “the critical and immediate need for organizations to prioritize patching” the vulnerability at the time. ®
Kategorie: Viry a Červi

Perovskitová fotovoltaika snad konečně zamíří na naše střechy. V testu překonala křemík a láme rekordy ve výrobě elektřiny

Živě.cz - 25 Srpen, 2026 - 11:45
Čínský perovskitový modul porazil v testu tradiční křemíkovou technologii TOPCon • Pasivace karboxyláty olova výrazně zvyšuje odolnost panelu vůči extrémní vlhkosti • Testované panely úspěšně splnily mezinárodní normy pro komerční nasazení
Kategorie: IT News

Crooks push Mac malware through fake OpenAI Codex ads

The Register - Anti-Virus - 25 Srpen, 2026 - 11:15
Cybercrims are using fake OpenAI Codex download pages to trick Mac developers into running malware disguised as installation commands. Researchers at Cato Networks uncovered the campaign after spotting sponsored Google search results targeting people looking to download Codex for macOS. The ads direct would-be users to a convincing-looking download page hosted on Google Sites, complete with the familiar OpenAI branding. There is, however, no Codex waiting at the other end. Instead of serving up an installer, the fake site tells Mac users to open Terminal, paste in a supplied command, and run it. The instructions are dressed up as part of the installation process, but the command quietly kicks off a multi-stage malware infection. It's a variation of the increasingly popular "ClickFix" technique, in which attackers convince victims to execute malicious commands themselves rather than relying on a dodgy attachment or executable to do the dirty work. In this case, the command begins with what appears to be a legitimate npm instruction for installing Codex. Tacked onto it, however, is code that decodes a Base64-encoded URL, fetches an attacker-controlled shell script and pipes it into zsh. That script pulls down another stage, which contacts the attacker's server to report that someone has taken the bait before downloading a Mach-O executable to “/tmp/helper.” It then removes security information macOS uses to flag suspicious downloads, helping the malware dodge the usual warnings before it launches. Cato said the final binaries are universal Mach-O files, meaning they can run natively on both Intel-powered Macs and newer Apple Silicon machines. The researchers found substantial similarities between the campaign and Atomic macOS Stealer, better known as AMOS, an infostealer previously spread through fake software downloads and malicious advertising campaigns. Cato isn't quite ready to slap an AMOS label on the malware, but says plenty of fingerprints point in that direction, from how the attack is staged to how the final payload is built. The crooks have also taken steps to keep researchers from getting a good look at their handiwork. Although victims initially land on Google Sites, the malicious content itself is pulled into the page from attacker-controlled infrastructure using an iframe. That infrastructure checks details including the visitor's operating system and the path used to reach it, allowing it to show harmless-looking content when a visitor doesn't fit the profile the attackers are after. Cato said the decoy site offered both macOS and Linux download buttons, although it only observed the malware chain being delivered to Mac users. Codex isn't the only AI coding assistant getting this treatment. During its investigation, Cato found a similar ClickFix page masquerading as Anthropic's Claude Code and sharing infrastructure with the Codex campaign. The attackers don't have to work particularly hard to find their victims, either. Developers searching Google for Codex do that work for them, with sponsored ads pushing the fake download page above the legitimate results. ®
Kategorie: Viry a Červi

Videím na YouTube budou rychleji přibývat zhlédnutí. Google je započítá hned po stisku Play

Živě.cz - 25 Srpen, 2026 - 10:45
YouTube od včerejška změnil způsob, jakým pracuje veřejné počítadlo zhlédnutých videí. Nově se za zhlédnutí považuje samotné spuštění, stačí tedy zobrazit jeden snímek videa. V minulosti se video započítalo jako zhlédnuté až po určité době sledování. Google to nikdy neupřesnil, ale spekuluje se o ...
Kategorie: IT News

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

The Hacker News - 25 Srpen, 2026 - 10:34
Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators. The vulnerabilities, as disclosed by Patchstack, are listed below - CVE-2026-61979 (CVSS score: 8.1) - An unauthenticated privilege escalation
Kategorie: Hacking & Security

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

The Hacker News - 25 Srpen, 2026 - 10:34
Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators. The vulnerabilities, as disclosed by Patchstack, are listed below - CVE-2026-61979 (CVSS score: 8.1) - An unauthenticated privilege escalation Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Windows 11 po aktualizaci na RGB sestavách padají, zejména ve hrách

CD-R server - 25 Srpen, 2026 - 10:00
Asi málokdo by čekal, že když mu z ničeho nic začnou na PC padat hry, může být na vině bezpečnostní záplata na Windows 11 v kombinaci s ovladačem RGB podsvícení. Ale stalo se…
Kategorie: IT News

O sedm tisíc levněji než u Applu. Jestli chcete MacBook Air M5 za 27 990 Kč, spěchejte

Živě.cz - 25 Srpen, 2026 - 08:45
Mall nabízí MacBook Air M5 za 27 990 Kč, Apple si účtuje 34 990 Kč. • Jde o základní verzi s 16GB RAM, 512GB SSD a v hvězdně bílé barvě. • Nabízí skvělý výkon, celodenní výdrž a rychlejší síťový modul.
Kategorie: IT News

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

The Hacker News - 25 Srpen, 2026 - 08:12
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-21962 (CVSS score: 10.0), allows an unauthenticated attacker with network access via HTTP to
Kategorie: Hacking & Security
Syndikovat obsah