> TODAY'S SUMMARY (51 articles)
Today's cybersecurity news highlights several significant threats and trends. The FBI has issued warnings about ongoing FortiBleed attacks, where attackers can lock organizations out of their own Fortinet firewalls, indicating a serious vulnerability for admins. In AI developments, Anthropic's new model is reportedly better at identifying vulnerabilities, while a Chinese hacker successfully utilized AI tools to breach South Korean banks. Additionally, there has been a rise in sophisticated phishing kits that include advanced session management features, targeting banking and government sectors across multiple regions. A critical vulnerability in Atlassian products is currently being exploited, and a recent ransomware recovery scheme has revealed fraudulent practices, underscoring the ongoing challenges in cybersecurity integrity.
|
// AI-powered summary generated at 12:00
May’s Patch Tuesday may not be the giant release many expected, but there are still plenty of important fixes that shouldn’t be ignored.
The G7 Cybersecurity Working Group releases new SBOM for AI guidance, outlining seven key data clusters to boost transparency and security across AI supply chains
Un professionnel de l'eau sanctionné après deux ans d’intrusion Cl0p et 633 887 données exposées.
The US Cybersecurity and Infrastructure Security Agency (CISA) and its G7 cyber agency partners have released a list of minimum elements for an AI software bill of materials, a move that could help CISOs assess the security and provenance of AI systems entering enterprise envi...
Microsoft responded to growing competition in AI security by announcing that its new agentic security system helped researchers discover 16 new vulnerabilities in the Windows networking and authentication stack, including four critical remote code execution (RCE) flaws. MDASH architecture diagram (S...
Microsoft on Tuesday released patches for 138 security vulnerabilities spanning its product portfolio, although none of them have been listed as publicly known or under active attack.
Of the 138 flaws, 30 are rated Critical, 104 are rated Important, three are rated Moderate, and one is rated Low in...
Instructure paie ShinyHunters après l’attaque de Canvas, tandis que le Congrès enquête sur la réponse cyber.
CVE-2026-40361 is similar to a vulnerability found a decade ago, BadWinmail, which at the time was dubbed an “enterprise killer”.
The post Microsoft Patches Critical Zero-Click Outlook Vulnerability Threatening Enterprises appeared first on SecurityWeek.
Educational tech firm Instructure reached a deal with hackers after a major Canvas breach exposed data stolen from schools and universities. Educational tech firm Instructure says it reached an agreement with the cybercrime group behind a major Canvas data theft, after attackers broke into its syste...
Fuite revendiquée contre la PACI au Koweït : données civiles, cartes sensibles et enjeu de renseignement.
Philippe shares his unique journey from French engineering school to the front lines of cybersecurity, explaining how his lifelong love for solving puzzles helps him uncover critical security flaws before they can be exploited.
West Pharmaceutical touché par un rançongiciel : données volées, production perturbée et enquête cyber en cours.
Foxconn confirme une cyberattaque en Amérique du Nord, revendiquée par Nitrogen, avec 8 To de données volées
Successful exploitation of these flaws could lead to arbitrary code execution and information disclosure.
The post Fortinet, Ivanti Patch Critical Vulnerabilities appeared first on SecurityWeek.
UK cybersecurity sector reaches ÂŁ14.7bn in revenue, driven by rapid growth in AI security firms, increased investment and rising employment across the industry
The annual CSO Awards annually recognize security projects that demonstrate outstanding security leadership and business value.
For this year’s program, CSO honors 64 security organizations whose hard work and innovative approaches have had a significant impact on how their...
The two chip giants have published over two dozen advisories describing recently identified security defects.
The post Chipmaker Patch Tuesday: Intel and AMD Patch 70 Vulnerabilities appeared first on SecurityWeek.
Découvrez Retyc, une alternative européenne de transfert sécurisé, offrant chiffrement post-quantique, zero-knowledge, et hébergement européen souverain.
Le post Retyc : une alternative française à WeTransfer, chiffrée et sans IA a été publié sur IT-Connect.
Microsoft has patched 120 vulnerabilities in this month’s security update round
Cybersecurity researchers are calling attention to a new campaign dubbed GemStuffer that has targeted the RubyGems repository with more than 150 gems that use the registry as a data exfiltration channel rather than for malware distribution.
"The packages do not appear designed for mass developer com...