> TODAY'S SUMMARY (151 articles)
Today's cybersecurity news highlights several significant threats and trends. The U.S. is offering a $10 million reward for Zhang Yu, a key figure in the Hafnium hacking campaign, which compromised thousands of systems. In a concerning incident, attackers hijacked top-level domains to issue fake security certificates for major organizations, including Google, posing a severe risk of trusted brand impersonation. Additionally, vulnerabilities in Microsoft, Adobe, and Atlassian products have been disclosed, prompting urgent updates as exploitation attempts have already begun. The FBI and Secret Service are warning about the ongoing FortiBleed credential-stealing campaign, which has impacted over 86,000 devices. Finally, a data breach in Arizona's court system exposed information on over 1.3 million individuals, underscoring the persistent threat of cyberattacks on sensitive data.
|
// AI-powered summary generated at 20:00
It’s nasty, but it requires physical access to the computer:
The exploit, named YellowKey, was published earlier this week by a researcher who goes by the alias Nightmare-Eclipse. It reliably bypasses default Windows 11 deployments of BitLocker, the full-volume encryption protection Microsoft provid...
Ivanti, Fortinet, n8n, SAP, and VMware have released security fixes for various vulnerabilities that could be exploited by bad actors to bypass authentication and execute arbitrary code.
Topping the list is a critical flaw impacting Ivanti Xtraction (CVE-2026-8043, CVSS score: 9.6) that could be exp...
MoD says StormBreaker will plug gap until homegrown SPEAR 3 integration lands
Saved passwords in Microsoft Edge will no longer sit in plaintext memory for the entire browser session after a researcher raised concerns.
The researcher dropped the MiniPlasma exploit that uses the original proof-of-concept (PoC) code targeting the bug.
The post Researcher Drops MiniPlasma Windows Exploit for Unpatched 2020 CVE appeared first on SecurityWeek.
The UK’s National Cyber Security Centre is helping organizations to understand agentic AI security risks
No GPS? No problem! Berla shows how investigators can turn odometer events and open-source reachability tools into location-based leads when vehicle geolocation data is missing.
Geekom propose une réduction énorme de 200 euros sur le Geekom A6, un mini PC équipé d'un AMD Ryzen 7, de 16 Go de RAM et d'un disque SSD NVMe de 1 To.
Le post Bon plan : le mini PC Geekom A6 a le droit à 200 euros de réduction immédiate avec ce code a été publié sur IT-Connect.
Cybercriminals brought down the most widely used learning platform in North America. The Canvas breach is a blueprint for how SaaS attacks now work — and a warning about how unprepared most organizations still are.
The post The Canvas breach proved that prevention is no longer enough appeared first...
Firefox maker says the tools are basic security infrastructure, not teenage contraband
The research community was awarded $1.3m as it found dozens of novel vulnerabilities at Pwn2Own Berlin
At least one threat actor has adopted the recently released malware source code in attacks against NPM developers.
The post First Shai-Hulud Worm Clones Emerge appeared first on SecurityWeek.
David Norman, a former Phoenix police officer who’s described himself as “a fucking savage,” now runs a company that provided training to Homeland Security’s Special Response Teams.
MiniPlasma, c'est le nom d'une faille zero-day Windows dévoilée par Chaotic Eclipse. Elle permet d'obtenir les privilèges SYSTEM sur une machine à jour.
Le post Windows 11 : la faille zero-day MiniPlasma donne les privilèges SYSTEM a été publié sur IT-Connect.
Passwords have been the weak point in online authentication for decades. They can be reused, guessed, stolen, phished, leaked, sprayed, stuffed, and captured by malware. Passkeys are one of the first mainstream authentication technologies that remove many of those problems entirely, and any website...
A threat actor has managed to access Grafana Labs’ GitHub environment and download the company’s codebase, the open-source observability and data visualization firm announced on Sunday. The breach is significant given Grafana Labs’ widespread use across enterprise engineering and DevOps teams worldw...
When Matt Schlicht built Moltbook, the social network where AI agents talk to one another, he didn’t write the code himself. He “just had a vision,” and vibe-coded it. The social network launched on Jan. 28, 2026, and within days, security researchers started to see serious se...
There is a conversation that happens in boardrooms every quarter that security leaders will recognize. The CISO presents the threat landscape. The board asks what the company needs. The answer, almost always, is another tool. Another platform, another module, another vendor to...
The UK’s financial authorities have set expectations for the sector on cybersecurity and operational resilience
Cybersecurity researchers have discovered four new npm packages containing information-stealing malware, one of which is a clone of the Shai-Hulud worm open-sourced by TeamPCP.
The list of identified packages is below -
chalk-tempalte (825 Downloads)
@deadcode09284814/axios-util (284 Downloads)
axo...