> TODAY'S SUMMARY (16 articles)
Today's cybersecurity landscape highlights several key threats and trends. Attackers exploiting the FortiBleed vulnerability are locking victims out of Fortinet devices by creating new accounts and deleting existing credentials. A critical flaw in Atlassian products allows unauthorized file access, urging immediate patching. The npm package "tensorlake" has been compromised to deliver a credential-stealing worm, raising concerns about supply chain security. Meanwhile, a significant number of vulnerabilities have been discovered and patched in Java libraries by IBM and Red Hat. Additionally, SonicWall has disclosed a severe flaw with a CVSS score of 10, indicating a serious security pattern. Overall, the ongoing risks emphasize the importance of proactive security measures and timely updates in the face of evolving threats.
|
// AI-powered summary generated at 08:00
Un pirate informatique, membre des groupes Akira et Conti, condamné à 8 ans prison. sa mission, analyser les données volées.
ClickFix, a one-shot social engineering technique that tricks victims into executing malicious workflows disguised as fixes to technical issues in their systems, has got a persistence upgrade.
In a one-off instance, ReliaQuest researchers have spotted an intrusion chain usi...
Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files Foxconn confirmed a cyberattack affecting some North American factories after the Nitrogen ransomware group claimed it stole 8 TB of data, including more than 11 million files tied to internal project...
Security teams have never had better visibility into their environments and never been worse at confirming what they fix stays fixed.
Mandiant's M-Trends 2026 report puts the mean time to exploit at an estimated negative seven days. The Verizon 2025 DBIR puts median time to remediate edge device vul...
The telehealth platform was hacked in January, and users’ personal information was exfiltrated from its systems.
The post 716,000 Impacted by OpenLoop Health Data Breach appeared first on SecurityWeek.
Il voulait se venger après son licenciement : 96 bases gouvernementales supprimées.
The UK’s AI Security Institute evaluated GPT-5.5’s ability to find security vulnerabilities, and found that it is comparable to Claude Mythos. Note that the OpenAI model is generally available.
Here is the Institute’s evaluation of Mythos.
And here is an analysis of a smaller, cheaper model. It requ...
The G7 Cybersecurity Working Group releases new SBOM for AI guidance, outlining seven key data clusters to boost transparency and security across AI supply chains
May’s Patch Tuesday may not be the giant release many expected, but there are still plenty of important fixes that shouldn’t be ignored.
European governments and public institutions have been shifting away from proprietary software for years, and the financial infrastructure supporting open-source alternatives is growing to match. Germany’s Sovereign Tech Fund announced today that it is investing more than €1 million in KDE, the open...
Un professionnel de l'eau sanctionné après deux ans d’intrusion Cl0p et 633 887 données exposées.
The US Cybersecurity and Infrastructure Security Agency (CISA) and its G7 cyber agency partners have released a list of minimum elements for an AI software bill of materials, a move that could help CISOs assess the security and provenance of AI systems entering enterprise envi...
Microsoft responded to growing competition in AI security by announcing that its new agentic security system helped researchers discover 16 new vulnerabilities in the Windows networking and authentication stack, including four critical remote code execution (RCE) flaws. MDASH architecture diagram (S...
Microsoft on Tuesday released patches for 138 security vulnerabilities spanning its product portfolio, although none of them have been listed as publicly known or under active attack.
Of the 138 flaws, 30 are rated Critical, 104 are rated Important, three are rated Moderate, and one is rated Low in...
Instructure paie ShinyHunters après l’attaque de Canvas, tandis que le Congrès enquête sur la réponse cyber.
CVE-2026-40361 is similar to a vulnerability found a decade ago, BadWinmail, which at the time was dubbed an “enterprise killer”.
The post Microsoft Patches Critical Zero-Click Outlook Vulnerability Threatening Enterprises appeared first on SecurityWeek.
Fuite revendiquée contre la PACI au Koweït : données civiles, cartes sensibles et enjeu de renseignement.
Educational tech firm Instructure reached a deal with hackers after a major Canvas breach exposed data stolen from schools and universities. Educational tech firm Instructure says it reached an agreement with the cybercrime group behind a major Canvas data theft, after attackers broke into its syste...
Philippe shares his unique journey from French engineering school to the front lines of cybersecurity, explaining how his lifelong love for solving puzzles helps him uncover critical security flaws before they can be exploited.
West Pharmaceutical touché par un rançongiciel : données volées, production perturbée et enquête cyber en cours.