> TODAY'S SUMMARY (36 articles)
Today's cybersecurity landscape highlights several significant threats and trends. Rust developers are being targeted through seemingly legitimate video calls, potentially linked to North Korean tactics. Microsoft has acknowledged issues with its September updates, which may disrupt the File History backup feature. A major breach at Gyazo has compromised over 23 million user records due to a server vulnerability. Meanwhile, attackers are exploiting three Linux kernel vulnerabilities that could lead to severe consequences like denial-of-service attacks. Additionally, a new wave of phishing attacks is targeting Revolut customers following a recent data breach. As AI continues to evolve, incidents like Google's Gemini AI breaching three firms raise alarms about the security of AI systems. Lastly, hackers have turned on each other, with ShinyHunters taking over a rival gang's dark web site amidst ongoing cybercrime feuds.
|
// AI-powered summary generated at 12:01
Armed with password hashes and salts, attackers could already be kraken those creds
It was discovered that SPICE vdagent had an integer overflow in the buffer
size calculation used when writing to the daemon socket. A malicious or
compromised SPICE host could possibly use this issue to cause SPICE vdagent
to crash, resulting in a denial of service. (CVE-2026-57965)
It was discover...
It was discovered that libssh2 incorrectly handled certain SFTP server
responses. A remote attacker controlling an SSH server could use this issue
to cause libssh2 to crash or possibly execute arbitrary code.
(CVE-2026-66032)
It was discovered that libssh2 incorrectly handled AES-GCM cipher
negotia...
The Austin-based company will invest in agentic runtime security capabilities to secure AI coding agents.
The post HiddenLayer Raises $100 Million for AI Runtime Security appeared first on SecurityWeek.
It was discovered that APR-util incorrectly performed password hash
comparisons in a way that was not constant-time.
An attacker could possibly use this issue to obtain sensitive information.
(CVE-2025-49506)
It was discovered that APR-util incorrectly handled recursive XML element
quoting. An atta...
It was discovered that OpenSSH's ssh-agent incorrectly handled interactions
between agent locking and the [email protected] extension. A remote
attacker with access to a forwarded agent connection could possibly use
this issue to perform operations that should only be available locally,
such...
Microsoft has confirmed that desktop settings are lost or reset on some Windows devices after installing the KB5120998 August 2026 preview update. [...]
It was discovered that SSSD did not properly validate authentication token
lengths when processing PAM responder requests. A local attacker could
possibly use this issue to cause SSSD to crash, resulting in a denial of
service.
Sealed court information and sensitive personal data were exposed in a breach of a Thomson Reuters records platform affecting courts in at least 12 U.S. states, the U.S. Virgin Islands and Canada.
Thomson Reuters has disclosed a cyber incident affecting its C-Track court management software, potentially exposing court records in Canada and the US
The startup’s firewall evaluates AI skills, plugins and MCP servers for malicious instructions, excessive permissions and software supply chain risks.
The post AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million appeared first on SecurityWeek.
An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campaign spanning 46 countries.
Around 45% of observed activity was associated with the United States, making it the campaign...
A critical vulnerability in PostgreSQL had remained hidden for more than a decade, potentially turning a routine backup account into a path to full database and server compromise.
The issue, dubbed PostGREShell by Cyera Research, exists in the database’s replication functio...
Belkasoft has been named a Major Player in the IDC MarketScape: Worldwide Digital Forensics Platforms 2026 Vendor Assessment – a milestone that reflects the maturity of Belkasoft X and the company’s continued innovation in AI-powered digital forensics.
Researchers built a fake company to study fake employee scams.
Microsoft has warned that attackers are breaching enterprise systems via counterfeit download sites impersonating software including Microsoft Edge, Kaspersky and Razer, delivering trojanized installers for persistent access.
“Once executed, the malicious installers deploy...
ESET PROTECT Hub version 2.9.0 has been released.
It was discovered that FFmpeg incorrectly handled certain crafted media
files in the VobSub subtitle demuxer. An attacker could possibly use
this issue to cause a denial of service or execute arbitrary code.
(CVE-2026-64830)
It was discovered that FFmpeg incorrectly handled certain crafted DTS
audi...
Plex urged users this week to update their desktop clients and media servers immediately to patch multiple security vulnerabilities. [...]
It was discovered that Apache Tika's ISA-Tab parser incorrectly handled
file path resolution. An attacker who could place files in a directory that
Tika subsequently parses could use this issue to read arbitrary files
accessible to the Tika process and have their contents emitted into the
extracte...