> TODAY'S SUMMARY (105 articles)
Today's cybersecurity landscape highlights several significant threats and trends:
1. A critical vulnerability (CVE-2026-21589) in multiple Atlassian products is being actively exploited, prompting urgent patching efforts from the company. This flaw allows unauthenticated access to sensitive files.
2. The FBI and Secret Service issued warnings regarding the FortiBleed campaign, which has compromised over 86,000 Fortinet devices, locking out administrators and stealing credentials.
3. A new malware strain, PoeLLM, has created a botnet by infiltrating over 3,400 servers, cleverly disguising its infrastructure within a poem.
4. Data breaches continue to escalate, with Georgia Power and Alabama Power confirming unauthorized access to 400,000 customer accounts, and a separate breach affecting over 1 million individuals in Arizona's court system.
5. Ransomware attacks are increasingly targeting backup infrastructures, complicating recovery for victims and heightening the pressure to pay ransoms.
These developments underscore the critical need for robust security measures and prompt updates to protect against emerging threats.
|
// AI-powered summary generated at 16:00
New haveged packages are available for Slackware 15.0 and -current to fix a security issue.
New mozilla-firefox packages are available for Slackware 15.0 and -current to fix security issues.
Learn what an account takeover is, how it can happen, and how businesses can detect and prevent attacks.
Cybersecurity researchers have disclosed details of a new ad fraud and malvertising operation dubbed Trapdoor targeting Android device users.
The activity, per HUMAN's Satori Threat Intelligence and Research Team, encompassed 455 malicious Android apps and 183 threat actor-owned command-and-control...
The company unsealed a legal case in U.S. District Court on Tuesday detailing the disruption of Fox Tempest — a popular service that has operated since May 2025 and provides cybercriminals with code signing tools.
La Commission Nationale de l'Informatique et des Libertés (CNIL) a publié son rapport d'activité pour l'année 2025, mettant en lumière une augmentation significative des plaintes, un montant total de sanctions inédit et un nombre record de notifications de violations de données.L'année 2025 a été ma...
L'autorité espagnole de protection des données (AEPD) a publié une décision de sanction à l'encontre d'un syndicat de copropriétaires, comprenant le prononcé d'une amende de 1 000 €, pour des manquements liés au principe de confidentialité. Cette affaire débute par une plainte signalant la publicati...
Drupal says attackers may develop an exploit for the vulnerability within hours or days.
The post Drupal to Patch Highly Critical Vulnerability at Risk of Quick Exploitation appeared first on SecurityWeek.
L'Agence Espagnole de Protection des Données (AEPD) a publié une décision de sanction à l'encontre d'une personne physique mineure, comprenant le prononcé d'une amende de 1 200 €, pour des manquements liés à la publication sur un réseau social d'une vidéo montrant l'agression d'un autre mineur. Cett...
Microsoft plans to raise the quality bar of Windows 11 drivers, as drivers "sit at the heart of every Windows experience" and connect the OS to the "silicon, components, and peripherals." [...]
Organizations often struggle to enforce security and compliance requirements consistently across their cloud infrastructure. In one environment, a workload might be deployed in an AWS Region that was never approved for that class of data. In another, a security group might allow broader access than...
Microsoft has confirmed user reports that the Teams team collaboration app is displaying non-dismissible location prompts on some macOS systems. [...]
 Fox Tempest provides a service that cybercriminals use to distribute ransomware and other malware disguised as legitimate software.
The post Microsoft Disrupts Malware-Signing Service Run by ‘Fox Tempest’ appeared first on SecurityWeek.
The org’s staying mum on the details, but Wednesday’s fixes reach back to unsupported 8.9 branches
NYC Health + Hospitals says attackers accessed its systems for months through a third-party vendor compromise, affecting at least 1.8 million people.
Key methods for cutting off AI access to an organization’s core IT assets.
Cisco Talos’ Vulnerability Discovery & Research team recently disclosed eight vulnerabilities in TP-Link, and one each in Adobe Photoshop, OpenVPN, and Gen Digital's Norton VPN.The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s...
The attacks are part of a wider campaign known as Mini Shai-Hulud, which has already compromised several open source projects and, in turn, developers and companies that use them.
Another malware wave is washing through open-source software repos, stealing publishing tokens, installing OS‑level backdoors and persisting in developer tools and CI pipelines.
The post Mini Shai-Hulud returns, compromising hundreds of npm packages appeared first on CyberScoop.
Faced with the growing volume of submission to its bug bounty program, GitHub is replacing cash bounties with swag rewards for reports with low security impact — and asking researchers to stop submitting reports that are low quality or about things that aren’t its fault.
Th...