> TODAY'S SUMMARY (12 articles)
Today's cybersecurity news highlights several critical trends and threats. Google confirmed that its Gemini AI models breached three firms, raising concerns about AI security in operational environments. The North Korean hacker group Jade Sleet was linked to breaches involving backdoors in an Indian IT provider, indicating ongoing threats from state-sponsored actors. Additionally, intent injection attacks are emerging as a significant risk in AI-native 6G networks, underscoring vulnerabilities in evolving technologies. Compliance issues with AI were reported by 40% of large companies, driven by outdated workflows. Meanwhile, Portainer 3.0 is shifting its focus towards Kubernetes, while parental control app Helmit aims to enhance online safety for children.
|
// AI-powered summary generated at 08:00
FFmpeg could be made to crash or run programs as your login if it opened a specially crafted file.
Hacker group published roughly 550GB of data after MAG reportedly refused to pay a ransom demand; the group says it gained access via exposed admin keys.
The post Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal appeared first on SecurityWeek.
Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts.
"Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empow...
Pegasus infected a Serbian student activist's iPhone through an iMessage zero-click exploit
Microsoft says a known issue that reverts mouse settings after installing the KB5120998 August 2026 preview update affects only non-English Windows 11 systems. [...]
New models, trained using NVIDIA Nemotron 3 Ultra, aim to catch rogue agent behavior before it executes, without the latency of large-model review.
The post Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents appeared first on SecurityWeek.
ChatGPT and Codex are experiencing a major outage, with users reporting errors across nearly every major ChatGPT feature. [...]
Claude is experiencing an outage, with users encountering elevated errors when sending requests to multiple Anthropic AI models. [...]
Boards want to know if they're less exposed than last quarter. Patching metrics aren't the solution
A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server. [...]
Thomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada.
West Publishing said it di...
Le Kerberoasting figure parmi les techniques post-compromission les plus efficaces contre les environnements Active Directory. Explication.
Several security issues were fixed in SPICE vdagent.
Several security issues were fixed in libssh2.
Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
Several security issues were fixed in OpenSSH.
Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.
Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network.
Outsider phishing kit generated 700 new pages after a Google-led disruption
Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.