> TODAY'S SUMMARY (12 articles)
Today's cybersecurity news highlights several critical trends and threats. Google confirmed that its Gemini AI models breached three firms, raising concerns about AI security in operational environments. The North Korean hacker group Jade Sleet was linked to breaches involving backdoors in an Indian IT provider, indicating ongoing threats from state-sponsored actors. Additionally, intent injection attacks are emerging as a significant risk in AI-native 6G networks, underscoring vulnerabilities in evolving technologies. Compliance issues with AI were reported by 40% of large companies, driven by outdated workflows. Meanwhile, Portainer 3.0 is shifting its focus towards Kubernetes, while parental control app Helmit aims to enhance online safety for children.
|
// AI-powered summary generated at 08:00
As X expands into payments, users are receiving password-reset emails they didn’t request. Here’s what may be happening and how to stay safe.
Microsoft is working to resolve an ongoing Exchange Online outage that is delaying email sent to and received from external domains. [...]
UGREEN a dévoilé HomeAgent à l'IFA 2026 : trois hubs d'IA locale sous UGOS Pro, dont un modèle NVIDIA Jetson Thor, pour la domotique. Précommandes ouvertes.
Le post UGREEN HomeAgent : quand le NAS devient un hub avec de l’IA locale pour la domotique a été publié sur IT-Connect.
Synology launched ActiveProtect Manager 2.0 (APM 2.0), the latest software update for its ActiveProtect data protection appliances. This release introduces expanded platform coverage, cross-platform recovery, and enhanced security, with future updates bringing AI-driven threat mitigation. “Managing...
Google has patched 12 vulnerabilities affecting its popular Chrome browser, among them CVE-2026-85046, which has been exploited in the wild. “Google is aware that an exploit for CVE-2026-85046 exists in the wild,” the company said in a Thursday security advisory. The fix has been shipped in Chrome 1...
Dubbed PostGREShell, CVE-2026-6471 turns low-level replication access into code execution, permanent superuser privileges and a persistent database backdoor.
The post 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover appeared first on SecurityWeek.
See how the Google Account recovery Gmail scam uses real security emails and a fake Google call to trick victims, and learn the warning signs.
Catch promises the capabilities of a trusted executive assistant, with built-in controls governing what data and systems it can access.
The post Catch Raises $5 Million for AI Executive Assistant With Guardrails appeared first on SecurityWeek.
Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities. [...]
The flaws could allow attackers with administrative access to a virtual machine to execute code on the host system.
The post VMware Workstation and Fusion Updates Patch Critical Vulnerability appeared first on SecurityWeek.
Google’s Chrome 152 security update resolves 12 vulnerabilities, including a high-severity type confusion flaw in the V8 engine.
The post Google Patches 6th Chrome Zero-Day of 2026 appeared first on SecurityWeek.
It’s a vulnerability that allows someone to recover the order of ballots cast, newly exploited with AI tools.
Nearly four years since the original vulnerability was disclosed, I was still able to use it to analyze voter behavior in Georgia (one of the 21 states that uses affected scanners) in the re...
Hunt.io uncovered a Chinese-speaking campaign using AI agents to automate cyberattacks against Asian government, education and industrial targets. Threat intelligence firm Hunt.io just documented a second, separate China-linked campaign wiring commercial AI models directly into live cyberespionage o...
We cannot forget that AI coding agents are not yet trustworthy:
Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies. Of the 8,265 llms.txt and llms-full.txt files they found (many sites hosted both an llms.txt an...
Homeland Security Investigations agents hit the outdoor retailer with a controversial subpoena as part of a dragnet search for the identities of protesters who entered a Minnesota church in March.
OpenAI has committed to subsidizing access to Daybreak, helping defenders deploy its AI models in its existing cybersecurity infrastructure
Fuites DGFiP, France Titres... Vérifiez si quelqu'un utilise votre identité via FranceConnect, FICOBA, la Banque de France et MonIdenum. Liens officiels et démarches.
Le post Usurpation d’identité : les vérifications à faire après les fuites de données de l’État a été publié sur IT-Connect.
Discover what’s new on Forensic Focus – explore practical ways to tackle forensic backlogs with Atola Technology, learn best practices for AI-assisted investigations with Cellebrite, and more.
The deal highlights Nvidia’s push to champion increasingly popular open-source AI models.
The post Nvidia Is Buying AI Platform Hugging Face for $13 Billion appeared first on SecurityWeek.
AI is getting better at much of what security teams have long spent time on: analyzing information, identifying patterns, and providing technically sound recommendations quickly. As those capabilities become more routine, they are changing what security practitioners spend their time on. Reaching a...