Výsledky hledání

sektor: školství× v celém archivu zrušit filtry

34 karet z 34 položek CZ · EN/orig

3

Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon

Research by: Amit Yardeni Key Points A Chinese-speaking actor is now targeting Brazil. Check Point Research has uncovered a sustained campaign against Brazilian organizations, primarily government and educational institutions since mid-2025. We dubbed this group Gambling Goblin: a Chinese-speaking cybercrime cluster connected to a previously documented group, Earth Berberoka, that targeted gambling sites across Asia. It marks a shift from Brazil’s usual home-grown banking-trojan threats to a…

Check Point veřejná správa školství IL

tg: varování tg: rozbor tp: phishing tp: špionáž

Check Point Research ·

Savjeti Nacionalnog CERT-a za siguran početak školske godine – što učiniti ako nešto pođe po krivu?

Koliko god se pridržavali svih sigurnosnih preporuka, ponekad se dogodi da nešto ipak pođe po krivu, bilo da je riječ o sumnjivoj poruci na koju smo kliknuli, kompromitiranom računu ili neugodnom iskustvu s nekim na internetu. Uz sve savjete o prevenciji, jednako je važno znati i kako reagirati ako se dogodi problem. U nastavku donosimo pregled nekoliko čestih situacija i osnovne korake koje možete poduzeti sami, bez obzira radi li se o vašem uređaju, računu ili neugodnom iskustvu na mreži. Ako…

školství HR

tg: návod tp: phishing tp: identita tp: soukromí

CERT.hr ·

Counterfeit installers to system compromise: Tracking a deceptive software download campaign

In this article Attack chain overviewCampaign scope and targetingMitigation and protection guidanceReferencesLearn more Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software-download websites to impersonate trusted vendors and distribute malicious installers. The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of…

Microsoft Razer Kaspersky zdravotnictví výroba a průmysl veřejná správa školství US

tg: varování tg: rozbor tp: malware

Microsoft Security Blog ·

1

Otvorene su prijave za Hacknite 2026

Otvorene su prijave na 7. izdanje Hacknite – CTF natjecanja za srednje škole! Ovogodišnje natjecanje donosi nova pravila vezana uz prijavu i korištenje tehnologija umjetne inteligencije. Prilikom prijave timova u obrazac je potrebno upisati @skole.hr adrese prijavitelja i natjecatelja! Tijekom natjecanja je ograničeno korištenje AI alata, a detaljnu uputu što se smije, a što ne pronaći ćete u Pravilima na dnu stranice. Natjecanje u obliku CTF-a (Capture the Flag) namijenjeno je srednjoškolskim…

školství HR

tg: propagace tp: AI

CERT.hr ·

1

Savjeti Nacionalnog CERT-a za siguran početak školske godine – pazi na svoj digitalni trag

Svaki put kada pristupimo internetu (pretražujemo, komuniciramo, plaćamo online, objavljujemo fotografije ili se prijavljujemo u neku aplikaciju) ostavljamo za sobom trag podataka. Taj trag naziva se digitalni trag i on nas prati mnogo dulje nego što bismo možda željeli. Povratak u školske klupe dobar je trenutak da se podsjetimo kako svjesno upravljati onim što o nama govori internet. Što je digitalni trag i zašto je važan Digitalni trag čini skup svih podataka koje ostavljamo svojim…

školství HR

tg: návod tp: soukromí

CERT.hr ·

1

PaperCut NG/MF Critical Zero-Day Exploited in the Wild

Overview On August 27, 2026, PaperCut Software published an urgent security advisory stating that it is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. PaperCut has confirmed customer incidents and is treating the issue as a security emergency. At the time of writing, the vulnerability has not been assigned a CVE identifier, and PaperCut has not publicly disclosed a CVSS score, vulnerability class, authentication requirements, or the technical details…

KEV ✓ EPSS 1.00 CVE-2023-27350 PaperCut Software PaperCut školství výroba a průmysl US 2 zdrojů

tg: zneužíváno tg: zranitelnost tp: malware

Rapid7 · BleepingComputer

1

Savjeti Nacionalnog CERT-a za siguran početak školske godine – zaštita uređaja i podataka

Početak školske godine znači povratak svakodnevnom korištenju laptopa, tableta i mobitela za učenje, komunikaciju i zabavu. Povećano korištenje digitalnih uređaja i online usluga sa sobom donosi i veći broj prilika za kibernetičke prijetnje, zbog čega je važno obratiti pozornost na osnovne sigurnosne navike. U nastavku donosimo nekoliko jednostavnih koraka za zaštitu koji mogu značajno smanjiti rizik od kibernetičkog napada. Redovito ažurirajte svoje uređaje i aplikacije. Omogućite automatsko…

školství HR

CERT.hr ·

2

Popular school apps may be sharing student data with advertisers

A two-year investigation into educational technology (EdTech) apps used by Utah schools found that many were collecting and sharing student data in ways that appeared inconsistent with their privacy commitments. EdTech is a massive commercial industry and some argue that it functions much like traditional big tech by prioritizing profits, scalable software, and user data collection over proven learning outcomes. The project, published by the Utah State Board of Education in partnership with…

školství US

Malwarebytes Labs ·

1

Savjeti Nacionalnog CERT-a za siguran početak školske godine – razmisli prije nego klikneš

Internet je veliko mjesto gdje gotovo svatko može stvarati i dijeliti sadržaj. Zato je važno obratiti pozornost i razmisliti o sadržaju s kojim se susrećete. Prije nego što nešto kliknete, podijelite ili povjerujete, zastanite i razmislite tko je objavio sadržaj i zašto te je li istinit ili je osmišljen da vas navede na krivi trag. Najčešći oblici prijevara na internetu s kojima se možete susresti S početkom školske godine mogu se očekivati prijevare kao što su phishing poruke s navodnim važnim…

Microsoft Google školství HR

CERT.hr ·

1

Savjeti Nacionalnog CERT-a za siguran početak školske godine – kibernetička higijena

S početkom školske godine dolaze nova prijateljstva, novi predmeti, ali i novi korisnički računi i uređaji. Prije nego što vam školske obveze preuzmu svu pažnju, sada je prilika da se pobrinete za sigurnost svojih računa, uređaja i podataka. Za početak je potrebno usvojiti osnovna pravila kibernetičke higijene pomoću kojih možete spriječiti situacije kao što su neovlašteni pristup vašim računima i uređajima, gubitak podataka, razne ucjene te krađa novca. 1/ Koristite snažne i jedinstvene…

školství HR

CERT.hr ·

1

Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia

Written by: Gabby Roncone, Wesley Shields Overview Google Threat Intelligence Group (GTIG) is tracking three distinct suspected Russian cyber espionage threat clusters abusing legitimate authentication flows to target individuals working in academia, aerospace and defense, governments and think tanks across Europe, as well as academia and think tanks within the United States. Examples of these techniques can be found in our previous blog on UNC6293’s phishing operations. We now track an…

Microsoft Google veřejná správa obrana školství US

Mandiant / Google TI ·

1

1

2

Armored Likho expands its cyber-espionage toolkit

In May 2026, we discovered a new cyber-espionage campaign by the Armored Likho group, also known as Eagle Werewolf, that targets private individuals and organizations across various industries in Russia, including major corporations, the public sector, IT, and education. The attackers used a fake app as bait that mimics a service for donations. However, the most interesting part of this campaign isn’t the initial infection method – it’s the malicious implants the attackers use for cyber…

Kaspersky veřejná správa školství RU

Securelist (Kaspersky) ·

1

Patch Tuesday: Update now to fix 421 flaws, including three zero-days

Microsoft’s August 2026 Patch Tuesday addresses 421 Microsoft vulnerabilities, including 62 rated Critical. One Windows vulnerability has been exploited in the wild by the Lazarus group to gain SYSTEM privileges. The August update is smaller than July’s record-breaking release, but it’s still among Microsoft’s largest Patch Tuesday batches. More importantly, it includes several flaws likely to attract attacker interest: a publicly disclosed Windows privilege escalation flaw with a proof-of…

EPSS 0.03 CVSS 9.8 CVE-2026-62832 CVE-2026-62893 Microsoft školství veřejná správa US

Malwarebytes Labs ·

1

2

An analysis of incidents at Brazilian educational institutions

Introduction Because of the amount of data that can be obtained and the high impact that successful attacks may have, educational institutions are frequent targets of cybercriminals. Both public and private schools and universities rely on software for managing personally identifiable information (PII) that is often insecure or insufficiently tested against known vulnerabilities. In addition, machines used by multiple people without accountability can be vulnerable to insider threats. The…

školství RU

Securelist (Kaspersky) ·

Riasztás Semmelweis Egyetem nevében küldött, káros csatolmányt tartalmazó levelekkel kapcsolatban

A Nemzetbiztonsági Szakszolgálat Nemzeti Kiberbiztonsági Intézet (NBSZ NKI) riasztást ad ki a Semmelweis Egyetem nevében küldött, káros csatolmányt tartalmazó e-mail üzenetekkel kapcsolatban. Intézetünkhöz több bejelentés érkezett arról, hogy ismeretlen elkövetők a Semmelweis Egyetem nevével és arculati elemeivel visszaélő e-maileket küldenek, amelyek célja a címzettek munkaállomásainak kompromittálása és hitelesítési adatok megszerzése. A levelek közös jellemzője, hogy […]

Semmelweis University školství HU

NKI Maďarsko ·

1

OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia

Introduction We have been tracking two new backdoors, OctLurk and SilkLurk, observed in attacks against government organizations primarily in Central Asia since January 2025. Identified victims are located in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic. These organizations operate across several sectors, including healthcare, research, government offices, ministries of foreign affairs, logistics, law‑enforcement agencies, urban planning and…

veřejná správa zdravotnictví školství RU

Securelist (Kaspersky) ·

1

13th July – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 13th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES U.S. auto insurer AssuranceAmerica has disclosed a data breach affecting approximately 7 million people. Attackers targeted an employee and used compromised credentials to access company systems, stealing names, contact information, driver’s license numbers, insurance policy and account data, vehicle information, and claims details. Latvia’s state…

KEV ✓ EPSS 1.00 CVE-2025-3248 CVE-2026-11405 CVE-2026-53359 Tenda Google Opera U-Boot školství finance IL

Check Point Research ·

1

Trenažni kamp etičkog hakiranja u Beču

Hrvatski predstavnici sudjelovali su na četvrtom izdanju International Ethical Hacking Bootcampa, koji je održan od 2. do 5. srpnja 2026. godine u Beču, u organizaciji TU Wien Cybersecurity Centra i Cybersecurity Austria. Na kampu je sudjelovalo oko 150 sudionika iz 12 europskih zemalja. Sudjelovanje na kampu jedinstvena je prilika za učenje i razmjenu ideja među mladima zainteresiranima za kibernetičku sigurnost. Deset sudionika iz Hrvatske, koji su svoje znanje pokazali na domaćim CTF…

školství HR

CERT.hr ·

1

ZDI-26-387: Oracle PeopleSoft HttpListeningConnector Server-Side Request Forgery Vulnerability

This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Oracle PeopleSoft. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.3. The following CVEs are assigned: CVE-2026-35273.

KEV ✓ EPSS 0.95 CVSS 9.8 CVE-2026-35273 Oracle Google Microsoft školství US 2 zdrojů

Zero Day Initiative · Mandiant / Google TI

1

Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research

Written by: Patrick Whitsell, John McGuiness, Muhammad Umair Google Threat Intelligence Group (GTIG) has identified a sophisticated campaign attributed to UNC6508, a People's Republic of China (PRC)-nexus threat actor, targeting institutions in the North American academic, medical, and military research community. While remaining undetected for over a year, the threat actor compromised externally facing web applications, deployed bespoke malware, pivoted to sensitive internal systems, and…

Google zdravotnictví obrana školství US

Mandiant / Google TI ·

1

1

1

1

Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability

Written by: Takahiro Sugiyama, Peter Revelant, Mathew Potaczek Introduction In late 2025, Mandiant responded to a security incident involving a compromised web server running KnowledgeDeliver. KnowledgeDeliver is a Learning Management System (LMS) developed by Digital Knowledge commonly used in Japan. Mandiant identified a critical vulnerability that allowed unauthenticated Remote Code Execution (RCE). An unknown threat actor leveraged this access to inject malicious code into the LMS platform,…

EPSS 0.01 CVE-2026-5426 Digital Knowledge školství US

Mandiant / Google TI ·

1

1

1

Кібератака UAC-0255 під виглядом сповіщення від CERT-UA із застосуванням програмного засобу AGEWHEEZE (CERT-UA#21075)

Національною командою реагування на кіберінциденти, кібератаки, кіберзагрози CERT-UA 26-27 березня 2026 року зафіксовано випадки розповсюдження електронних листів нібито від імені CERT-UA із закликом завантажити з сервісу Files.fm захищений паролем архів ("CERT_UA_protection_tool.zip", "protection_tool.zip") та встановити "спеціалізоване програмне забезпечення". Серед отримувачів листів: державні організації, медичні центри, охоронні фірми, навчальні заклади, фінансові установи, компанії…

veřejná správa zdravotnictví finance školství UA

CERT-UA ·

1

CSIRTs Around the World – Azerbaijan

Hello, this is Shihono from the Global Coordination Division. In early March, we traveled to Baku, the capital of Azerbaijan, and had the opportunity to visit five organizations, including CSIRTs and facilities involved in cyber security workforce development. In this article, I would like to introduce an overview of these visits. Azerbaijan, the “Land of Fire,” and Its Capital Baku, the “City of Winds” Baku cityscape and the Caspian Sea Azerbaijan is located in the Caucasus region, which…

Technion – Israel Institute of Technology veřejná správa školství JP

JPCERT/CC – blog ·

1