> TODAY'S SUMMARY (44 articles)
In Q3 2026, ransomware attacks reached a record high of 2,627, particularly impacting critical sectors like finance and healthcare. Citrix has issued urgent patches for a critical NetScaler vulnerability (CVE-2026-107406) that could allow remote code execution. Meanwhile, hackers hijacked multiple country code top-level domains (ccTLDs) linked to Google, raising concerns over domain security. An update on the ASOS breach reveals that customer data, including shopping habits, has been compromised, increasing phishing risks. The FBI has disrupted operations of Chinese state-sponsored hacking tools, while new vulnerabilities in AhsayCBS are being actively exploited. Additionally, the rise of pre-installed malware on low-cost Android devices highlights ongoing threats in mobile security.
|
// AI-powered summary generated at 12:00
Postfix could be made to crash if it received specially crafted network traffic.
OpenJPEG could be made to crash or run programs when encoding image files.
Stonejiajia, Shir Tamari and Sagi Tzadik discovered that the OverlayFS
implementation in the Ubuntu Linux kernel did not properly perform
permission checks in certain situations. A local attacker could possibly
use this to gain elevated privileges. (CVE-2023-2640)
Shir Tamari and Sagi Tzadik discov...
Nouvelle alerte du côté de Node.js : une faille de sécurité critique a été découverte dans la bibliothèque vm2 : protégez vos applications de la CVE-2026-26956.
Le post vm2 : la célèbre sandbox Node.js affectée par une faille critique (CVE-2026-26956) a été publié sur IT-Connect.
The incident underscores the dangers public officials face from doxxing, as well as how easy it has become to find sensitive information online.
Michał Majchrowicz discovered that Vim’s zip plugin could overwrite
arbitrary files. An attacker could possibly use this issue to delete
sensitive data or execute arbitrary code. This issue only affected
Ubuntu 26.04 LTS. (CVE-2026-35177)
It was discovered that Vim’s netbeans interface did not prop...
The company is expanding its platform’s capabilities with the acquisition of SecureIQx and Korbit.ai.
The post Boost Security Raises $4 Million for SDLC Defense Platform appeared first on SecurityWeek.
Traditional network security tools are undermining data protection, with Forrester and Capital One Software research warning AI adoption is impossible without rethinking data security
Toronto police said this is the "first known instance" of an SMS blaster being used in Canada.
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Network drivers;
- NVME drivers;
- Netfilter;
(CVE-2026-23112, CVE-2026-23231, CVE-2026-23273)
AI investment scammers abused the Keitaro ad-tracking platform to cloak their campaign, exposing it only to likely targets.
Mitiga researchers say attackers can silently redirect Claude Code MCP traffic, intercept OAuth tokens, and maintain persistent access to connected SaaS platforms.
The post Claude Code OAuth Tokens Can Be Stolen Through Stealthy MCP Hijacking appeared first on SecurityWeek.
Kamil Frankowicz discovered that Postfix incorrectly handled certain
enhanced status codes. A remote attacker could possibly use this issue to
cause Postfix to crash, resulting in a denial of service.
Articles
Are Dimension and WebBlocker Server affected by the Linux kernel vulnerabilities (CVE-2026-23268 and CVE-2026-23269)?
ThreatSync remediation response actions do not block wireless client connections to some types of malicious access points
Block or disable weak CBC ciphers for Firebox web...
Oasis Security finds critical Cline kanban WebSocket flaw exposing AI coding agents to hijack
Cisco fixed several high‑severity flaws in its enterprise products, including SSRF bugs in Unity Connection that could enable code execution or service disruption. Cisco released patches for multiple high‑severity vulnerabilities affecting its enterprise products. Successful exploitation could allow...
The fresh browser update resolves critical-severity integer overflow and use-after-free vulnerabilities.
The post Chrome 148 Rolls Out With 127 Security Fixes appeared first on SecurityWeek.
Several security issues were fixed in libpng.
Little CMS could be made to crash if it opened a specially crafted ICC profile.
Your security controls aren't failing, they're missing where most of today's work actually happens. Keep Aware shows how browser activity like copy/paste and AI prompts bypass traditional protections. [...]