> TODAY'S SUMMARY (126 articles)
Today's cyber news highlights several significant threats and trends in the cybersecurity landscape:
1. Zohar Pinhasi, CEO of MonsterCloud, has been indicted for allegedly defrauding ransomware victims by secretly paying attackers while significantly overcharging clients for recovery services.
2. A malware campaign named 'Midnight Mimosa' has been uncovered, involving low-cost Android phones pre-installed with residential proxy malware, enabling covert installations of malicious apps.
3. The FBI reported that China-linked hackers compromised email systems of various Southeast Asian government and healthcare organizations, creating a portal for third-party access to stolen data.
4. A critical vulnerability in multiple Atlassian products is currently being exploited, allowing unauthorized access to sensitive files.
5. Cybercriminals have hijacked country-code domains to obtain certificates for impersonating trusted services, while a new phishing campaign targets YouTube creators through fake sponsorship offers.
These incidents reflect ongoing challenges in ransomware, malware distribution, and sophisticated phishing tactics, underscoring the need for heightened cybersecurity measures.
|
// AI-powered summary generated at 20:01
Un kill switch dans le noyau Linux pourrait désactiver des fonctions vulnérables, renforçant la sécurité en attendant un correctif pour une faille de sécurité.
Le post CopyFail, Dirty Frag : un mainteneur propose d’ajouter un kill switch à Linux a été publié sur IT-Connect.
CVSSv3 Score:
5.1
An improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability [CWE-89] in FortiNDR may allow an authenticated attacker to execute arbitrary SQL commands on selected databases and tables via specifically crafted HTTP requests....
CVSSv3 Score:
6.3
An improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiMail may allow an authenticated privileged attacker to execute unauthorized code or commands via specifically crafted HTTP or HTTPS requests.
Revi...
In May 2026, the real estate services firm Cushman & Wakefield was the target of a "pay or leak" extortion campaign by the ShinyHunters group. Following the threat, the group publicly published data they alleged had been obtained from the firm, consisting mostly of C&W email addresses along...
CVSSv3 Score:
8.3
An Out-Of-Bounds Write vulnerability [CWE-787] in FortiOS capwap daemon may allow an attacker controlling an authenticated FortiAP FortiExtender or FortiSwitch to gain execution privileges on the FortiGate device
Revised on 2026-05-12 00:00:00
CVSSv3 Score:
5.0
An improper export of Android application components [CWE-926] in FortiTokenAndroid may allow other applications on the device to read the OTP code via an exported Content Provider URI.
Revised on 2026-05-12 00:00:00
OpenAI has launched Daybreak, a new cybersecurity initiative that brings together frontier artificial intelligence (AI) model capabilities and Codex Security to help organizations identify and patch vulnerabilities before attackers find a way in using the same issues.
"Daybreak combines the intellig...
CVSSv3 Score:
6.5
An OS command injection vulnerabtility [CWE-78] in FortiAP and FortiAP-W2 cli may allow an authenticated attacker to execute unauthorized code or commands via a specifically crafted cli command.
Revised on 2026-05-12 00:00:00
CVSSv3 Score:
9.1
A missing authorization vulnerability [CWE-862] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to execute unauthorized code or commands via HTTP requests.
Revised on 2026-05-12 00:00:00
ThreatFabric found a new TrickMo Android trojan focused on stealth and persistence, moving its command-and-control traffic to the TON network. Security researchers at ThreatFabric have recently identified a new version of TrickMo, a dangerous Android banking trojan that shows how malware operators a...
CVSSv3 Score:
9.1
An Improper Access Control vulnerability [CWE-284] in FortiAuthenticator may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
Revised on 2026-05-12 00:00:00
CVSSv3 Score:
2.1
A Missing Authorization [CWE-862] in FortiClient Windows may allow an authenticated local attacker to decrypt a currently logged in users VPN password via use of an unprotected DLL function.
Revised on 2026-05-12 00:00:00
423 failles de sécurité ont été corrigées dans le navigateur web Mozilla Firefox en avril 2026, grâce à l'utilisation de l'IA, notamment Claude Mythos.
Le post Mozilla Firefox : 423 failles de sécurité corrigées en avril 2026, merci l’IA ! a été publié sur IT-Connect.
CVSSv3 Score:
5.2
A use of potentially Dangerous Function vulnerability [CWE-676] in FortiAnalyzer and FortiManager API may allow an authenticated attacker to cause a system hang via multiple specially crafted HTTP requests causing crashes. This happens if internal locks are aligned, whi...
CVSSv3 Score:
6.1
An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] in FortiAP, FortiAP-U & FortiAP-W2 CLI may allow an authenticated privileged attacker to execute unauthorized code or commands via crafted CLI request...
Fears exponential increase in attack scale and speed
CVSSv3 Score:
4.0
An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability [CWE-88] in FortiDeceptor WEB UI may allow an authenticated attacker with at least read-only admin permission to read log files via HTTP crafted requests.
Revised on...
Apple on Monday officially released iOS 26.5 with support for end-to-end encryption (E2EE) to Rich Communication Services (RCS) in beta as part of a "cross-industry effort" to replace traditional SMS with a more secure alternative.
To that end, E2EE RCS messaging is rolling out to iPhone users runni...
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.4. The follow...
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows that run Message Queueing. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS...