> TODAY'S SUMMARY (12 articles)
Today's cybersecurity news highlights several critical trends and threats. Google confirmed that its Gemini AI models breached three firms, raising concerns about AI security in operational environments. The North Korean hacker group Jade Sleet was linked to breaches involving backdoors in an Indian IT provider, indicating ongoing threats from state-sponsored actors. Additionally, intent injection attacks are emerging as a significant risk in AI-native 6G networks, underscoring vulnerabilities in evolving technologies. Compliance issues with AI were reported by 40% of large companies, driven by outdated workflows. Meanwhile, Portainer 3.0 is shifting its focus towards Kubernetes, while parental control app Helmit aims to enhance online safety for children.
|
// AI-powered summary generated at 08:00
Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters.
"Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'fundi...
The U.S. Department of Justice and the U.K.'s National Crime Agency and Crown Prosecutor signed a memorandum to cooperate on cases involving Southeast Asian scam operations.
Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian. [...]
PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server.
The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logical decoding was introduc...
Deux suspects arrêtés après les attaques de ZeroBytes contre le fisc, tandis que l’enquête cyber se poursuit.
A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors.
The attackers named the implant ted in debug strings left in the bin...
In its first annual assessment, published Friday, the City of London Police said victims reported losing ÂŁ6.3 million ($8.5 million) to account hacks in the year ending March 31, up from ÂŁ1.2 million ($1.6 million) a year earlier.
Microsoft is working to resolve a known issue that causes delays or blocks some users from opening the Microsoft Teams desktop client on Windows systems. [...]
Researchers have found a way to hack Boeing 737 systems with a device that costs less than US$100. Here’s how the Bus Driver attack works, and how realistic a threat it actually is.
Passkeys eliminate many password-based attacks, but researchers have documented 39 methods for compromising authentication built around them. Token explains how attackers can abuse authentication prompts, synced credentials, enrollment, recovery, and other trust boundaries without breaking FIDO2 cry...
Drivers in North America received a nasty shock this week when it was revealed that digital scans of 153 million drivers’ licenses were for sale on the dark web. Among the victims were US Defense Secretary Pete Hegseth – and investigative reporter Brian Krebs, who has dug deep...
PostGREShell (CVE-2026-6471) is a 12-year-old PostgreSQL flaw that lets low-privileged attackers execute code and take over servers. Cyera researchers found a severe PostgreSQL vulnerability, dubbed PostGREShell and tracked as CVE-2026-6471 (CVSS score of 7.2). Present in releases dating back to 201...
Russia's data centers are concentrated in areas increasingly exposed to Ukrainian drone attacks. The Kremlin wants them to stiffen their physical defenses.
The destiny of Spirit Airline’s data is still undecided, months after the company sought bankruptcy protection.
AI data company Micro1 has now offered $12.5 million to acquire a trove of the company’s emails, Teams chats, operations and employee productivity data, according...
Tracked as CVE-2026-9586, the unauthenticated SQL injection flaw can be exploited remotely for arbitrary code execution.
The post Sangoma Switchvox Vulnerabilities Exploited in the Wild appeared first on SecurityWeek.
Synology dévoile ActiveProtect Manager 2.0 : sauvegarde d'Amazon EC2, Azure VM, Proxmox VE, Nutanix AHV et Google Workspace, et restauration cloud à cloud.
Le post Synology : APM 2.0 s’ouvre à de nouvelles plateformes dont Proxmox et Nutanix a été publié sur IT-Connect.
An anonymous security researcher who uses the "Nightmare Eclipse" handle released a CrowdStrike Falcon zero-day exploit named "FalconFlank" that lets attackers escalate privileges on up-to-date Windows systems. [...]
A senator's letter confirms the U.S. military moved to prevent the tracking after foreign adversaries used location data to target troops.
OpenAI dévoile GPT-6 Astra : 100 % sur ExploitBench, deux zero-day découvertes en test, mais la version publique est volontairement bridée et c'est tant mieux.
Le post OpenAI a publié une version bridée de GPT-6 Astra, ce modèle redoutable en cyber a été publié sur IT-Connect.
In a joint advisory released Thursday, the G7 Cyber Security Working Group and the U.S. Cybersecurity and Infrastructure Security Agency, CISA, said organizations should begin moving to post-quantum cryptography now.