> TODAY'S SUMMARY (3 articles)
Today's cybersecurity news highlights a critical vulnerability in SonicWall's core product, identified as CVE-2026-102255, which has been rated a 10 in severity, indicating an urgent need for patching. Additionally, a ransomware fixer has been accused of defrauding clients by charging them more than the ransom amounts, pocketing the difference instead of providing legitimate decryption services. This underscores ongoing issues with trust and reliability in the cybersecurity space. As these incidents unfold, organizations must remain vigilant and prioritize updates and threat mitigation strategies.
|
// AI-powered summary generated at 04:00
Linux admins reeling from handling last month’s CopyFail and last week’s Dirty Frag kernel vulnerabilities have a new headache to deal with: Fragnesia.
“This is a significant vulnerability,” Robert Beggs, head of incident response firm DigitalDefence, told CSO. “It is bypas...
The actions are being taken in light of an expanding supply chain campaign impacting the popular open-source library TanStack and additional npm and PyPI packages tied to several AI companies.
While AI tools present unique cybersecurity threats, they still rely on poor identity security by organizations to do the most damage, a White House official said Thursday.Â
The post White House cyber official: identity security matters more than ever in the age of AI appeared first on CyberScoop.
Cisco is warning that a critical Catalyst SD-WAN Controller authentication bypass flaw, tracked as CVE-2026-20182, was actively exploited in zero-day attacks that allowed attackers to gain administrative privileges on compromised devices. [...]
Lesson one for aspiring dark web kingpins: don't have your laundered gold bars shipped to your home address.
Read more in my article on the Hot for Security blog.
OpenAI says two employees' devices were breached in the recent TanStack supply chain attack that impacted hundreds of npm and PyPI packages, causing the company to rotate code-signing certificates for its applications as a precaution. [...]
On the first day of Pwn2Own Berlin 2026, security researchers collected $523,000 in cash awards after exploiting 24 unique zero-days. [...]
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Cisco Catalyst SD-WAN to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a flaw in Cisco Catalyst SD-WAN, tracked as CVE-2026-20182 (CVSS score of 10.0)...
Director of National Intelligence Tulsi Gabbard has tapped two individuals to coordinate work across U.S. spy agencies to monitor threats to the 2026 elections, according to multiple sources familiar with the matter.
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected. Our mission with Wordfence Intellige...
In this week’s newsletter, Martin reflects on what the next iteration of AI tools means for vulnerability discovery and our ability to manage large-scale patch releases.
Fragnesia, a new Linux kernel flaw tracked as CVE-2026-46300, could let local attackers gain root access through page cache corruption. Researchers disclosed a new Linux kernel privilege escalation vulnerability named Fragnesia, tracked as CVE-2026-46300 (CVSS score of 7.8). The flaw affects the XFR...
Cisco has released updates to address a maximum-severity authentication bypass flaw in Catalyst SD-WAN Controller that it said has been exploited in limited attacks.
The vulnerability, tracked as CVE-2026-20182, carries a CVSS score of 10.0.
"A vulnerability in the peering authentication in Cisco Ca...
Cybersecurity researchers are sounding the alarm about what has been described as "malicious activity" in newly published versions of node-ipc.
According to Socket and StepSecurity, three different versions of the npm package have been confirmed as malicious -
[email protected]
[email protected]
node-ipc...
L'autorité de protection des données grecque a analysé un projet de décision du ministère de l'Intérieur établissant la procédure d'inscription sur les listes électorales spéciales pour les citoyens résidant à l'étranger et le vote par correspondance.Le projet de décision définit les modalités de so...
L'autorité britannique de protection des données (ICO) a publié des recommandations pour aider les organisations à se prémunir contre les cybermenaces basées sur l'intelligence artificielle (IA).Face à l'évolution rapide des menaces, telles que l'hameçonnage amélioré par l'IA, l'ingénierie sociale p...
How and why Kaspersky’s Product Security Team utilizes Kaspersky Container Security.
OpenAI said the damage was limited to the employees’ devices, and did not affect user data nor its production systems, and none of its intellectual property was stolen.
Migrating your TLS endpoints to Post-quantum cryptography (PQC) starts with understanding your current TLS endpoint inventory and posture. This post introduces the PQC Readiness Scanner — an automated tool that inventories your Application Load Balancer (ALB), Network Load Balancer (NLB), and Amazon...
Everything is still on fire.
This week feels dumb in the worst way — bad links, weak checks, fake help desks, shady forum posts, and people turning supply chain attacks into some cursed little game for clout and cash. Half of it feels new. Half of it feels like crap we should have fixed years ago.
T...