> TODAY'S SUMMARY (36 articles)
Today's cybersecurity landscape highlights several significant threats and trends. Rust developers are being targeted through seemingly legitimate video calls, potentially linked to North Korean tactics. Microsoft has acknowledged issues with its September updates, which may disrupt the File History backup feature. A major breach at Gyazo has compromised over 23 million user records due to a server vulnerability. Meanwhile, attackers are exploiting three Linux kernel vulnerabilities that could lead to severe consequences like denial-of-service attacks. Additionally, a new wave of phishing attacks is targeting Revolut customers following a recent data breach. As AI continues to evolve, incidents like Google's Gemini AI breaching three firms raise alarms about the security of AI systems. Lastly, hackers have turned on each other, with ShinyHunters taking over a rival gang's dark web site amidst ongoing cybercrime feuds.
|
// AI-powered summary generated at 12:01
Cybercriminals are offering digital scans of US and Canadian driver’s licenses, likely stolen from IDScan.net.
The post 153 Million Driver License Images Offered on Dark Web appeared first on SecurityWeek.
Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads.
According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, techn...
A Russian national accused of using fake accounts on a freelance employment platform to spread malware to approximately 80,000 users has been indicted by a federal grand jury in California. Searzhudin Tamirlanovich Aktulaev, 40, faces charges of conspiracy, transmission of malicious code, and aggrav...
The high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution.
The post Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability appeared first on SecurityWeek.
In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations across developer environments, Continuous Integration/Continuous Deployment (CI/CD) tooling, cloud configurations, and even AI tool configs.
Earl...
Publicly disclosed S/MIME flaws could expose encrypted email content, while critical IOS XR and Nexus bugs could enable remote code execution and authentication bypass.
The post Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities appeared first on SecurityWeek.
Hackers exploit critical JFrog Artifactory flaw to forge admin tokens A critical authentication bypass flaw in JFrog Artifactory, tracked as CVE-2026-82329 and carrying a CVSS score of 9.8, is being actively exploited to mint fraudulent admin tokens on self-managed instances running in their default...
WIRED rebuilt Flock’s latest search tool from code the company sends to a police officer’s browser. Its AI can keep watch across multiple cameras for anyone fitting a written description.
Explore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt operations.
The post Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America appeared first on Unit 42.
See how Cellebrite Genesis uses agentic AI to help enterprise investigative teams cut through complex digital evidence, uncover connections, and move from data to actionable leads in minutes.
Chaotic Eclipse released FalconFlank, a PoC exploit for a Crowdstrike Falcon ZeroDay Elevation of Privileges Vulnerability Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Crowdstrike Falcon cybersecur...
A ransomware attacker used AI agents to move through an enterprise network in less than 10 hours, according to Palo Alto Networks researchers, who estimated that similar work could have taken human operators about two weeks.
The incident involved more than 50 techniques map...
The FBI is investigating how scans of over 153 million driver’s licenses are being sold on the dark web
Most of us, staying in a hotel room or a vacation rental, have wondered at least once whether we’re safe there, whether someone might be watching or recording us without our knowledge. The thought alone leaves a bitter taste in the mouth. A team from the Korea Advanced Institute of Science and Techn...
Children's Commissioner also furious with Ofcom over a string of failures
We have spent years telling chief information security officers (CISOs) that they need to become better aligned with the business. They need to understand strategy. They need to speak the language of the board. They need to build relationships with business leaders. They need...
Microsoft is working to fix a known issue that causes crashes and launch failures for Microsoft Teams and New Outlook users after installing updates released since the August 2026 Patch Tuesday. [...]
California and Colorado will require operating systems to collect users’ ages, but open-source software like Linux may be exempt.
The iPhone belonging to a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware, according to new findings from the Citizen Lab in collaboration with the SHARE Foundation.
"Our analysis confirmed that an iMessage zero-click exploit was used to infect the device w...
US-led action sinkholes machines caught up in Sality botnet