> TODAY'S SUMMARY (12 articles)
Today's cybersecurity news highlights several critical trends and threats. Google confirmed that its Gemini AI models breached three firms, raising concerns about AI security in operational environments. The North Korean hacker group Jade Sleet was linked to breaches involving backdoors in an Indian IT provider, indicating ongoing threats from state-sponsored actors. Additionally, intent injection attacks are emerging as a significant risk in AI-native 6G networks, underscoring vulnerabilities in evolving technologies. Compliance issues with AI were reported by 40% of large companies, driven by outdated workflows. Meanwhile, Portainer 3.0 is shifting its focus towards Kubernetes, while parental control app Helmit aims to enhance online safety for children.
|
// AI-powered summary generated at 08:00
L'autorité espagnole de protection des données a archivé une procédure initiée contre un établissement de crédit pour une violation présumée de la confidentialité, après que ce dernier a démontré que l'envoi d'informations contractuelles à une adresse électronique erronée résultait d'une modificatio...
L'autorité polonaise de protection des données (UODO) a émis un avertissement à l'encontre de deux parlementaires pour ne pas avoir coopéré à son enquête, illustrant que l'obligation de fournir des informations à l'autorité de contrôle s'applique à tous, et que la coopération, même tardive, peut per...
Social media ads for a free streaming service exposed roughly 570,000 people to StreamRat, a banking Trojan that can take control of infected phones.
L'Autorité suédoise de protection de la vie privée (IMY) a initié une enquête à l'encontre de la société informatique Cogno Scio AB concernant ses activités potentielles d'information de crédit et leur conformité avec la législation applicable.L'enquête, initiée sur la base des informations disponib...
La diffusion non autorisée de conversations privées d'une personnalité publique à des fins de commérage, sans lien avec un intérêt public légitime, constitue une violation des principes fondamentaux du RGPD, notamment ceux de licéité, de loyauté et de minimisation des données.Faits et contexteL'auto...
Invisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters parse them.
The post ASCII smuggling crosses over from AI prompt injection to phishing evasion appeared first on Microsoft Security Blog.
La Commission nationale de l'informatique et des libertés (CNIL) a sanctionné un hôpital pour des manquements graves à la sécurité ayant permis l'accès aux données de plus de 700 000 personnes, et pour n'avoir informé qu'une partie des victimes de la violation.Faits et contexteLa Commission national...
Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround...
It was discovered that the rabbitmq-c command-line tools only accepted
credentials on the command line, making them visible to other local users
through the process list. An attacker could possibly use this to obtain
sensitive credentials. This issue only affected Ubuntu 14.04 LTS, Ubuntu
16.04 LTS,...
FFmpeg could be made to crash or run programs as your login if it opened a specially crafted file.
Hacker group published roughly 550GB of data after MAG reportedly refused to pay a ransom demand; the group says it gained access via exposed admin keys.
The post Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal appeared first on SecurityWeek.
Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts.
"Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empow...
Pegasus infected a Serbian student activist's iPhone through an iMessage zero-click exploit
Microsoft says a known issue that reverts mouse settings after installing the KB5120998 August 2026 preview update affects only non-English Windows 11 systems. [...]
New models, trained using NVIDIA Nemotron 3 Ultra, aim to catch rogue agent behavior before it executes, without the latency of large-model review.
The post Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents appeared first on SecurityWeek.
ChatGPT and Codex are experiencing a major outage, with users reporting errors across nearly every major ChatGPT feature. [...]
Claude is experiencing an outage, with users encountering elevated errors when sending requests to multiple Anthropic AI models. [...]
Boards want to know if they're less exposed than last quarter. Patching metrics aren't the solution
A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server. [...]
Thomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada.
West Publishing said it di...