[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (4 articles)

|

// AI-powered summary generated at 12:01

> Ubuntu 25.10 Linux Kernel Critical Threat Malicious Microcode USN-8183-2
Several security issues were fixed in the Linux kernel.
> Managing AI Agents: Balancing Security and Productivity
Why AI Agent Governance Is Now a Board-Level Priority AI agents are no longer experimental tools. They are embedded into workflows across engineering, marketing, operations,...Read More The post Managing AI Agents: Balancing Security and Productivity appeared first on ISHIR | Custom AI Software Deve...
> Ubuntu 20.04 LTS Linux-Raspi Security Update USN-8098-10 Critical
Several security issues were fixed in the Linux kernel.
> USN-8205-1: GStreamer Bad Plugins vulnerabilities
It was discovered that multiple plugins in GStreamer contained arithmetic overflows. An attacker could possibly use this issue to cause applications using the plugins to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2023-37329, CVE-2023-40474, CVE-2023-40475, CVE-...
> Hybrid clouds have two attack surfaces and you’re not paying enough attention to either
Windows Admin Center flaws mean on-prem can attack cloud, and vice-versa Black Hat Asia  Israeli researchers found a series of flaws in Microsoft's Windows Admin Center (WAC) and suggest this shows hybrid cloud management tools are a two-way attack surface that users don't spend enough time worrying...
> Google drafts AI agents secure systems against AI hackers
In response to Anthropic Mythos, instead of launching another LLM, Google unveiled a broad push toward agentic, AI-driven defense at Google Cloud Next ‘26 to help SOC analysts as they scramble to keep up with the influx of CVEs Mythos threatens. As Mythos promises more vuln...
> Google gets agent-ready for the Mythos age
In response to Anthropic Mythos, instead of launching another LLM, Google unveiled a broad push toward agentic, AI-driven defense at Google Cloud Next ‘26 to help SOC analysts as they scramble to keep up with the influx of CVEs Mythos threatens. As Mythos promises more vuln...
> New GopherWhisper APT group abuses Outlook, Slack, Discord for comms
A previously undocumented state-backed threat actor named GopherWhisper is using a Go-based custom toolkit and legitimate services like Microsoft 365 Outlook, Slack, and Discord in attacks against government entities. [...]
> [Webinar] Mythos Reality Check: Beating Automated Exploitation at AI Speed
Imagine a world where hackers don't sleep, don't take breaks, and find weak spots in your systems instantly. Well, that world is already here. Thanks to AI, attackers are now launching automated, large-scale exploits faster than ever before. The time you have to fix a vulnerability before it gets at...
> How Branded SSO Interfaces Improve User Trust And Experience
Learn how branded SSO interfaces improve user trust and experience by creating seamless, secure, and consistent authentication flows. The post How Branded SSO Interfaces Improve User Trust And Experience appeared first on Security Boulevard.
> Google brings instant email verification to Android, no OTP needed
Google has introduced cryptographically verified email credentials for Android through the Credential Manager API. This API aligns with the W3C Digital Credential API standard. It provides a unified way for apps to request and retrieve user credentials for authentication and authorization. “By integ...
> Surveillance vendors caught abusing access to telcos to track people’s phone locations, researchers say
The Citizen Lab found two separate surveillance vendors abusing the backbone of cellular networks to spy on several victims across the world.
> Ubuntu 25.10 python-tornado Moderate Denial of Service USN-8198-1
Several security issues were fixed in Tornado.
> Ubuntu 25.10 Rack Session Important Cookie Access Flaw CVE-2026-39324
Rack::Session could allow unintended access to network services.
> Supporting AI adoption for UK cyber defence
Adopting AI will require time, the development of new capabilities and careful oversight. 
> NCSC: Leave passwords in the past - passkeys are the future
Passkeys are the more secure and user-friendly login method and should be the default authentication option for consumers.
> Google Introduces Unique AI Agent Identities in New Gemini Enterprise Platform
Google Cloud will attribute a unique cryptographic ID every AI agent that will be tied to “traceable and auditable” authorization policies
> Passkeys are more secure than traditional ways to log in
Passkeys and other FIDO2 credentials offer a more usable, secure replacement for passwords and are already supported by most modern devices.
> Executive Summary: Defending against China-nexus covert networks of compromised devices
Organisations should map and baseline their edge device traffic, especially VPN and remote access connections, and adopt dynamic threat feed filtering that includes known covert network indicators.
> Trailmark turns code into graphs
We’re open-sourcing Trailmark, a library that parses source code into a queryable call graph of functions, classes, call relationships, and semantic metadata, then exposes that graph through a Python API that Claude skills can call directly. Install it now: uv pip install trailmark “Defenders think...