> TODAY'S SUMMARY (15 articles)
Today's cybersecurity landscape highlights several significant threats and trends. Ten leading AI firms have pledged to enhance data protection in response to UK regulatory pressures. Meanwhile, Mozilla removed 16 malicious Firefox extensions designed to steal cryptocurrency recovery phrases and private keys. Citrix has issued an urgent patch for a critical NetScaler vulnerability that could allow remote code execution. The FBI successfully disrupted tools used by the China-linked Flax Typhoon group targeting critical infrastructure. Additionally, the Pwn2Own Ireland hacking contest awarded over $1.2 million for exploits, underscoring the ongoing prevalence of zero-day vulnerabilities. Lastly, a report revealed thousands of unprotected wind and solar park systems across Europe, raising concerns about their cybersecurity posture.
|
// AI-powered summary generated at 08:00
Hackers who gained access to the databases of Spanish fast-fashion retailer Zara stole data belonging to more than 197,000 customers, according to data breach notification service Have I Been Pwned. [...]
Lua could be made to crash or run programs as your login if it opened a specially crafted file.
Social media biz says watchdog's fine formula is 'disproportionate' and should stop counting global revenue
Discover what’s new on Forensic Focus – explore the emerging threat of AI-generated CSAM, preview what’s to come at Techno East 2026, register free for Forensics Europe Expo 2026, and more.
The dark secret of enterprise security operations is that defenders have quietly institutionalized the practice of not looking. This is not just anecdotal, but rather backed by a recent report investigating more than 25 million security alerts, including informational and low-severity, across live e...
Ivanti has released fixes for 5 high-severity vulnerabilities in its Endpoint Manager Mobile (EPMM) solution, one of which (CVE-2026-6973) has being exploited as a zero-day by attackers. “We are aware of a very limited number of customers exploited with CVE-2026-6973,” the company said in a security...
Retour sur les actualités cyber de la quinzaine du 8 mai 2026 : hacking, piratage, arrestations et IA.
Google has expanded Play Policy Insights in Android Studio to help developers catch policy issues while coding, including warnings for common problems such as missing login credentials. Later this year, developers who connect their Play developer account directly to Android Studio will receive tailo...
Model Context Protocol (MCP) is the connective tissue of modern AI tooling and has quietly become one of the most significant blind spots in modern security programs. Like shadow IT before it, shadow AI — especially as it relates to MCP risk — introduces a new class of exposur...
Two U.S. nationals were sentenced to 18 months in prison for operating “laptop farms” that helped North Korean IT workers gain employment at nearly 70 American companies, generating more than $1.2 million for Pyongyang’s government. Although Matthew Issac Knoot of Nashville, Tennessee, and Erick Nte...
You don't need to live near a scam compound for it to wreck your life. Americans lost $5.8 billion to crypto investment scams last year alone - and a raid in Sri Lanka this month shows exactly how the operations behind them keep finding new places to hide.
Read more in my article on the Hot for S...
It was discovered that the Lua parser incorrectly handled garbage collection
when processing specially crafted Lua scripts. A remote attacker could possibly
use this issue to cause a denial of service or execute arbitrary code.
Penetration tests of AI-based systems are revealing a greater percentage of high-risk flaws than those discovered in legacy systems.
Security consultancy Cobalt’s annual State of Pentesting Report reveals that 32% of all AI and large language model (LLM) findings are rated...
The conversation is straightforward, but the problem behind it is not. The customer bought servers in 2017 and typically refresh every five to six years. Generally, around the 2022 to 2023 timeframe, they would have looked to buy new.
Historically, that is what would have h...
SentinelOne believes the PCPJack campaign may be the brainchild of a former TeamPCP member
A 34-year-old Virginia man was found guilty of conspiring to destroy dozens of government databases after getting fired from his job as a federal contractor. [...]
Cybersecurity researchers have disclosed details of a new Linux backdoor named PamDOORa that's being advertised on the Rehub Russian cybercrime forum for $1,600 by a threat actor called "darkworm."
The backdoor is designed as a Pluggable Authentication Module (PAM)-based post-exploitation toolkit th...
The malware framework targets web applications and cloud environments, including AWS, Docker, Kubernetes, and more.
The post ‘PCPJack’ Worm Removes TeamPCP Infections, Steals Credentials appeared first on SecurityWeek.
With the launch of the first 16 satellites, Russia begins construction of a network for satellite internet that aims to cover the entire country by 2030. But getting there won’t be easy.
Snyk has announced it is leveraging Anthropic’s Claude models to advance software security. Snyk has integrated Claude into the Snyk AI Security Platform, enabling automated vulnerability discovery, prioritization, and developer-ready fixes across code, dependencies, containers, and AI-generated art...