> TODAY'S SUMMARY (151 articles)
Today's cybersecurity news highlights several significant threats and trends. The U.S. is offering a $10 million reward for Zhang Yu, a key figure in the Hafnium hacking campaign, which compromised thousands of systems. In a concerning incident, attackers hijacked top-level domains to issue fake security certificates for major organizations, including Google, posing a severe risk of trusted brand impersonation. Additionally, vulnerabilities in Microsoft, Adobe, and Atlassian products have been disclosed, prompting urgent updates as exploitation attempts have already begun. The FBI and Secret Service are warning about the ongoing FortiBleed credential-stealing campaign, which has impacted over 86,000 devices. Finally, a data breach in Arizona's court system exposed information on over 1.3 million individuals, underscoring the persistent threat of cyberattacks on sensitive data.
|
// AI-powered summary generated at 20:00
Grafana Labs disclosed that hackers have downloaded its source code after breaching its GitHub environment using a stolen access token. [...]
The open source project said hackers stole its codebase and threatened to publish its source code if the company did not pay.
New for 2026, the Infosecurity Europe Startup competition will see five finalists pitch their ideas in front of a live audience, including senior industry leaders, investors and buyers
A critical NGINX vulnerability (CVE-2026-42945) disclosed last week is being exploited by attackers, VulnCheck security researcher Patrick Garrity revealed on Saturday. The vulnerability, dubbed NGINX Rift, can be reliably exploited to trigger a denial-of-service condition and can potentially allow...
ChimeraZ revendique des fuites visant le tourisme français et décrit la vente de bases sensibles. Il annonce aussi de nouvelles fuites !
Researchers say 18-year-old flaw already being probed and exploited just days after disclosure
A hotel check-in system exposed over 1 million passports, IDs, and selfies online due to a misconfigured cloud storage bucket. A security lapse in the Reqrea’s Tabiq hotel check-in system exposed over 1 million passports, driver’s licenses, and selfie verification photos online. The issue came from...
SHub Reaper bypasses Apple's Terminal mitigation, steals credentials and documents, and plants a persistent backdoor for continued access after infection.
What happens when a phishing email looks clean enough to pass through security, but dangerous enough to expose the business after one click? That is the gap many SOCs still struggle with: the attacks that leave teams unsure what was exposed, who else was targeted, and how far the risk has spread.
Ea...
Several healthcare data breaches impacting hundreds of thousands and even millions were added to the HHS tracker.
The post Millions Impacted Across Several US Healthcare Data Breaches appeared first on SecurityWeek.
Security researchers have developed a new image-based prompt injection attack that can manipulate how multimodal AI systems interpret user instructions without modifying the original text prompt, potentially expanding security risks for AI agents and vision-language systems....
SmartBear has announced ReadyAPI’s new AI test generation capability that accelerates API testing by up to 80% while giving teams control to enable or disable AI. While competitors focus on speed alone, ReadyAPI’s AI test generation capability is architected for quality at scale and addresses the te...
Shift comes amid mounting reports of successful social engineering attacks targeting higher-ups in government
Four vulnerabilities in OpenClaw can be chained together to steal credentials, escape the sandbox, and plant persistent backdoors.
The post ‘Claw Chain’ OpenClaw Flaws Allow Sandbox Escape, Backdoor Delivery appeared first on SecurityWeek.
An old elevation-of-privilege (EoV) vulnerability affecting the Cloud Filter driver “cldflt.sys” in Windows has come back to haunt Microsoft, as researchers claim it is still exploitable six years after it was supposedly patched.
The flaw, originally reported to Microsoft b...
In a new red-teaming exercise, social engineering moved to advanced tunneling attacks, revealing a critical lesson in today's AI security.
Exploitation of Critical NGINX Vulnerability Begins Threat actors have started exploiting CVE-2026-42945, the critical NGINX rewrite module flaw disclosed and patched last week. The vulnerability is an 18-year-old heap buffer overflow in ngx_http_rewrite_module that can be triggered by a single unau...
The hackers claimed to have stolen more than 600,000 Salesforce records, including personal information and corporate data.
The post 7-Eleven Data Breach Confirmed After ShinyHunters Ransom Demand appeared first on SecurityWeek.
Supply chain attackers are not only trying to slip malicious code into trusted software. They are trying to steal the access that makes trusted software possible. Recently, three separate campaigns hit npm, PyPI, and Docker Hub in a 48-hour window, and all three targeted secrets from developer envir...
Microsoft has finally brought back the resizable taskbar and Start menu to Windows 11 in the latest preview version rolling out to Insiders in the Experimental channel. [...]