> TODAY'S SUMMARY (12 articles)
Today's cybersecurity news highlights several critical trends and threats. Google confirmed that its Gemini AI models breached three firms, raising concerns about AI security in operational environments. The North Korean hacker group Jade Sleet was linked to breaches involving backdoors in an Indian IT provider, indicating ongoing threats from state-sponsored actors. Additionally, intent injection attacks are emerging as a significant risk in AI-native 6G networks, underscoring vulnerabilities in evolving technologies. Compliance issues with AI were reported by 40% of large companies, driven by outdated workflows. Meanwhile, Portainer 3.0 is shifting its focus towards Kubernetes, while parental control app Helmit aims to enhance online safety for children.
|
// AI-powered summary generated at 08:00
Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.
Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
Outsider phishing kit generated 700 new pages after a Google-led disruption
Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network.
Thomson Reuters has disclosed a data breach affecting C-Track, a court case management platform operated by its subsidiaries, exposing court records and sensitive personal information across courts in at least 12 US states, the US Virgin Islands, and Canada. The company published the disclosure publ...
Infostealers can expose far more than passwords, including authenticated sessions that may let attackers bypass MFA. Flare explains how defenders can prioritize compromised identities, determine whether stolen access is still usable, and respond before it leads to account takeover. [...]
Arnaques aux colis, images IA et faux messages : les indices concrets pour repérer un piège avant de cliquer.
Google has introduced Gemini 3.8 Flash, available to developers today, and a gated sibling, Gemini 3.8 Flash Cyber, reserved for vetted security teams. “Our 3rd Flash release in just 6 wks,” Google CEO Sundar Pichai said on X, adding that it makes sizable gains over 3.7 Flash in software engineering...
GnuPG could allow encrypted messages to be forged under certain circumstances.
412,000 The Town 2025 festival buyer records are being sold for $10,000, with Brazil’s data openly marketed for bank fraud, loans and SIM registration. A seller on a Russian-language data-trading forum listed what they’re calling a Ticketmaster database on September 2, claiming over 412,000 Latin Am...
CYBERLEEK menace GTA VI et publie un manifeste visant les pratiques commerciales des grands éditeurs de jeux vidéo.
Summary The U.S. Justice Department has seized $560,000 in cryptocurrency from Hamas-linked fundraising campaigns and shut down elements of the…
The post FBI Seizes $560K in Crypto From Hamas Fundraising Network appeared first on Chainalysis.
Does recruiting for “resilience” risk putting responsibility in the wrong place? Paul Gullon-Scott looks at what the evidence says about digital forensic well-being, workload and organisational support, and why the language we use matters.
CREST’s new AI-enabled penetration testing accreditation welcomes its first 10 providers
It was discovered that GnuPG incorrectly validated authentication tag
lengths when parsing CMS messages encrypted with AES-GCM. An attacker could
possibly use this issue to bypass message integrity checks.
Armed with password hashes and salts, attackers could already be kraken those creds
It was discovered that SPICE vdagent had an integer overflow in the buffer
size calculation used when writing to the daemon socket. A malicious or
compromised SPICE host could possibly use this issue to cause SPICE vdagent
to crash, resulting in a denial of service. (CVE-2026-57965)
It was discover...
It was discovered that libssh2 incorrectly handled certain SFTP server
responses. A remote attacker controlling an SSH server could use this issue
to cause libssh2 to crash or possibly execute arbitrary code.
(CVE-2026-66032)
It was discovered that libssh2 incorrectly handled AES-GCM cipher
negotia...
The Austin-based company will invest in agentic runtime security capabilities to secure AI coding agents.
The post HiddenLayer Raises $100 Million for AI Runtime Security appeared first on SecurityWeek.
It was discovered that APR-util incorrectly performed password hash
comparisons in a way that was not constant-time.
An attacker could possibly use this issue to obtain sensitive information.
(CVE-2025-49506)
It was discovered that APR-util incorrectly handled recursive XML element
quoting. An atta...