Agregátor RSS

From Fake Workers to Account Recovery: The Growing Identity Verification Risk

Bleeping Computer - 25 Srpen, 2026 - 16:01
Attackers are increasingly targeting the processes used to establish or recover identity rather than attacking the login itself. Specops explains how stronger identity verification can help organizations prevent fake workers and social engineering attacks from gaining legitimate access. [...]
Kategorie: Hacking & Security

Microsoft PowerToys adds Alt+Tab-style switching for an app's windows

Bleeping Computer - 25 Srpen, 2026 - 15:51
Microsoft updated its Windows PowerToys toolset with a new utility dubbed "Window Hopper" that lets users switch between an app's windows more quickly. [...]
Kategorie: Hacking & Security

Linux Hardening, Architecture & Isolation

LinuxSecurity.com - 25 Srpen, 2026 - 15:47
Linux hardening is not the act of enabling every restrictive setting a distribution provides. It is the work of reducing unnecessary exposure, limiting what users and processes can do, separating workloads, and confirming that those controls remain effective as the system changes.
Kategorie: Hacking & Security

WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android

The Hacker News - 25 Srpen, 2026 - 15:19
Meta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help users with both iOS and Android devices sign into their accounts using the phishing-resistant method. The tech giant said more than 1 billion people use a passkey to log into WhatsApp. Support for passkeys was first introduced in Android in October 2023,
Kategorie: Hacking & Security

WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android

The Hacker News - 25 Srpen, 2026 - 15:19
Meta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help users with both iOS and Android devices sign into their accounts using the phishing-resistant method. The tech giant said more than 1 billion people use a passkey to log into WhatsApp. Support for passkeys was first introduced in Android in October 2023, Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

WhatsApp adds stronger two-step verification, multiple passkeys

Bleeping Computer - 25 Srpen, 2026 - 15:00
WhatsApp has started rolling out several new account security features, including support for multiple passkeys and stronger two-step verification. [...]
Kategorie: Hacking & Security

Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode

The Hacker News - 25 Srpen, 2026 - 14:43
Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook, according to VulnCheck's CVE Numbering Authority (CNA) record. The CNA record says the command can run as a local subprocess when the notebook is opened in edit mode. The vulnerability, tracked
Kategorie: Hacking & Security

Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode

The Hacker News - 25 Srpen, 2026 - 14:43
Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook, according to VulnCheck's CVE Numbering Authority (CNA) record. The CNA record says the command can run as a local subprocess when the notebook is opened in edit mode. The vulnerability, trackedSwati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Firefox 157 přinese zapnutou podporu JPEG XL

AbcLinuxu [zprávičky] - 25 Srpen, 2026 - 14:16
Firefox 157 přinese zapnutou podporu rastrového grafického formátu JPEG XL. Založena je na v Rustu napsané implementaci jxl-rs používané i v Chrome a Chromiu.
Kategorie: GNU/Linux & BSD

Hackers breached over 270 Zimbra servers in ongoing attacks

Bleeping Computer - 25 Srpen, 2026 - 14:04
Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability. [...]
Kategorie: Hacking & Security

Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

The Hacker News - 25 Srpen, 2026 - 13:56
Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication. According to ANY.RUN research, 48% of targeted email addresses were potentially compromised. Most of the affected companies are US-based. Mirage2FA Campaign
Kategorie: Hacking & Security

Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

The Hacker News - 25 Srpen, 2026 - 13:56
Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication. According to ANY.RUN research, 48% of targeted email addresses were potentially compromised. Most of the affected companies are US-based. Mirage2FA Campaign [email protected]
Kategorie: Hacking & Security

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

The Hacker News - 25 Srpen, 2026 - 13:52
Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. "While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn't do harm, the threat actor’s use of npm isn't to infect developers who install it, but to use the
Kategorie: Hacking & Security

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

The Hacker News - 25 Srpen, 2026 - 13:52
Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. "While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn't do harm, the threat actor’s use of npm isn't to infect developers who install it, but to use the Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

The Hacker News - 25 Srpen, 2026 - 13:33
Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE. While threat actors are known to abuse legitimate services to point to additional command-and-control (C2) infrastructure and blend in with regular network traffic, the development
Kategorie: Hacking & Security

E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

The Hacker News - 25 Srpen, 2026 - 13:33
Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE. While threat actors are known to abuse legitimate services to point to additional command-and-control (C2) infrastructure and blend in with regular network traffic, the developmentRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Frontier AI: Vulnerability Management's Systemic Revolution

The Hacker News - 25 Srpen, 2026 - 13:14
Vulnerability management has been a staple of security programs since the dawn of the cybersecurity discipline. The symbiotic relationship between vulnerability and patch management teams has also existed for that time and has gone through waves of contention and thankfulness. While this relationship required thoughtful care and feeding from both sides, both sides were aiming to work toward a
Kategorie: Hacking & Security

Frontier AI: Vulnerability Management's Systemic Revolution

The Hacker News - 25 Srpen, 2026 - 13:14
Vulnerability management has been a staple of security programs since the dawn of the cybersecurity discipline. The symbiotic relationship between vulnerability and patch management teams has also existed for that time and has gone through waves of contention and thankfulness. While this relationship required thoughtful care and feeding from both sides, both sides were aiming to work toward a [email protected]
Kategorie: Hacking & Security
Syndikovat obsah