> TODAY'S SUMMARY (44 articles)
In Q3 2026, ransomware attacks reached a record high of 2,627, particularly impacting critical sectors like finance and healthcare. Citrix has issued urgent patches for a critical NetScaler vulnerability (CVE-2026-107406) that could allow remote code execution. Meanwhile, hackers hijacked multiple country code top-level domains (ccTLDs) linked to Google, raising concerns over domain security. An update on the ASOS breach reveals that customer data, including shopping habits, has been compromised, increasing phishing risks. The FBI has disrupted operations of Chinese state-sponsored hacking tools, while new vulnerabilities in AhsayCBS are being actively exploited. Additionally, the rise of pre-installed malware on low-cost Android devices highlights ongoing threats in mobile security.
|
// AI-powered summary generated at 12:00
La Commission Nationale de l'Informatique et des Libertés (CNIL) a publié une recommandation sur l'utilisation des données personnelles pour l'évaluation de la solvabilité dans le cadre de l'octroi de crédit.Cette recommandation, qui remplace l'autorisation unique AU-005, s'adresse aux organismes de...
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 148.0.7778.96-1~deb12u1.
opam could be made to install files in unintended locations if it installed a specially crafted package.
Several security issues were fixed in OpenEXR.
Happy World Password Day! Maybe it's finally time to kill this holiday in favor of World No-More-Passwords Day?
Several security issues were fixed in the Linux kernel.
La cybersécurité ne se limite plus à installer un pare-feu, déployer un antivirus et espérer que tout se passe bien. Elle devient un exercice permanent de conformité, de contrôle, de preuve et de mesure.
TL;DR Crypto prediction markets use blockchain technology to create liquid platforms for forecasting and hedging real-world events, driving massive growth…
The post Crypto Prediction Markets Explained: How the Blockchain Is Reshaping Forecasting appeared first on Chainalysis.
Security researchers at Mozilla say Anthropic's Mythos has unearthed a wealth of high-severity bugs in Firefox.
Amazon Web Services (AWS) achieved three Standar Nasional Indonesia (SNI) certifications for the AWS Asia Pacific (Jakarta) Region: SNI ISO/IEC 27017:2015, SNI ISO/IEC 27018:2019, and SNI ISO 9001:2015. SNI represents Indonesia’s national standards framework, comprising standards that are broadly ap...
This World Passkey Day, read how Microsoft is advancing passkey adoption to replace passwords, cut phishing risk, and deliver simpler, more secure sign-ins.
The post World Passkey Day: Advancing passwordless authentication appeared first on Microsoft Security Blog.
Over the past several months, Mozilla ran an agentic harness powered by Claude Mythos Preview across Firefox’s source code, identifying 271 security bugs that were fixed in Firefox 150, with additional fixes shipped in versions 149.0.2 and 150.0.1. Over 100 people contributed code to get those patch...
Josh Eads, Kristoffer Janke, Eduardo Vela Nava, Tavis Ormandy, and Matteo
Rizzo discovered that some AMD Zen processors did not properly verify the
signature of CPU microcode. This flaw is known as EntrySign. A privileged
attacker could possibly use this issue to cause load malicious CPU
microcode c...
Josh Eads, Kristoffer Janke, Eduardo Vela Nava, Tavis Ormandy, and Matteo
Rizzo discovered that some AMD Zen processors did not properly verify the
signature of CPU microcode. This flaw is known as EntrySign. A privileged
attacker could possibly use this issue to cause load malicious CPU
microcode c...
The cybersecurity firm has not explicitly accused China of being behind the attack, but the evidence suggests it was.Â
The post Palo Alto Zero-Day Exploited in Campaign Bearing Hallmarks of Chinese State Hacking appeared first on SecurityWeek.
Quang Luong discovered that OpenEXR incorrectly handled sample count
accumulation when processing deep scan line image files. An attacker could
possibly use this issue to cause OpenEXR to crash, resulting in a denial of
service, or execute arbitrary code. (CVE-2026-27622)
It was discovered that Ope...
Josh Eads, Kristoffer Janke, Eduardo Vela Nava, Tavis Ormandy, and Matteo
Rizzo discovered that some AMD Zen processors did not properly verify the
signature of CPU microcode. This flaw is known as EntrySign. A privileged
attacker could possibly use this issue to cause load malicious CPU
microcode c...
Ivanti warned customers today to patch a high-severity remote code execution vulnerability in Endpoint Manager Mobile (EPMM) exploited in zero-day attacks. [...]
Andrew Nesbitt discovered that opam did not properly validate file
destination paths in package install files. An attacker could use this
issue to bypass sandbox protections and write files to arbitrary locations,
possibly leading to arbitrary code execution.
Josh Eads, Kristoffer Janke, Eduardo Vela Nava, Tavis Ormandy, and Matteo
Rizzo discovered that some AMD Zen processors did not properly verify the
signature of CPU microcode. This flaw is known as EntrySign. A privileged
attacker could possibly use this issue to cause load malicious CPU
microcode c...