> TODAY'S SUMMARY (36 articles)
Today's cybersecurity landscape highlights several significant threats and trends. Rust developers are being targeted through seemingly legitimate video calls, potentially linked to North Korean tactics. Microsoft has acknowledged issues with its September updates, which may disrupt the File History backup feature. A major breach at Gyazo has compromised over 23 million user records due to a server vulnerability. Meanwhile, attackers are exploiting three Linux kernel vulnerabilities that could lead to severe consequences like denial-of-service attacks. Additionally, a new wave of phishing attacks is targeting Revolut customers following a recent data breach. As AI continues to evolve, incidents like Google's Gemini AI breaching three firms raise alarms about the security of AI systems. Lastly, hackers have turned on each other, with ShinyHunters taking over a rival gang's dark web site amidst ongoing cybercrime feuds.
|
// AI-powered summary generated at 12:01
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- OCFS2 file system;
- SCTP protocol;
(CVE-2026-53043, CVE-2026-53224, CVE-2026-53225, CVE-2026-53246,
CVE-2026-5330...
Researcher tracking 764 said the first-of-its-kind case has a wider impact that will cause ripples across the landscape of violent extremist crime.
The post Jail time for Maine child in 764 marks turning point in federal law enforcement appeared first on CyberScoop.
Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. [...]
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, sandbox escape or privilege escalation. For the stable distribution (trixie), these problems have been fixed in version 140.15.0esr-1~deb13u1.
September 2, 2026: This post was republished to include Active Directory migration strategies and automation for permission sets. AWS IAM Identity Center manages user access to Amazon Web Services (AWS) resources, including both AWS accounts and applications. You can use IAM Identity Center to creat...
An identity theft search site claimed to have more than 150 million driver's license photos stolen from an ID verification service. The crime site has now shut down.
The security tool intercepts potentially dangerous agent actions, blocking clear threats and requesting human approval when intent is uncertain.
The post OpenLeash Adds a Human Check to Risky AI Agent Actions appeared first on SecurityWeek.
An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites. [...]
Searzhudin Tamirlanovich Aktulaev appeared in a San Francisco federal court on Monday after being arrested in Cyprus in May 2025 and extradited to the U.S. last week.
After talking with enterprise security leaders over the past year, one thing has become clear: the rise of autonomous AI agents is the most significant shift in security posture since the move to cloud. Organizations across every industry are adopting AI agents that authenticate on behalf of users,...
Adding insult to injury
I received the two emails below earlier in the month. They’re vaguely coherent. I suppose I shouldn’t be surprised that the corpus that AIs are training on contain data suggesting that I am someone to write to with random computer and network security problems. After all, I observe that behavior in...
Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program.
"The Fairwind Program gives high-priority defenders (like governments, healthca...
The FCC wants consumers to rate their telecom’s anti-robocall protections.
The post The FCC wants consumers to rate their telecom’s anti-robocall protections appeared first on CyberScoop.
La communication de données d'affiliation syndicale dans le cadre d'une procédure judiciaire, alors qu'elles avaient été collectées initialement pour la seule gestion de la paie, constitue une violation du principe de limitation des finalités, même si le responsable invoque la nécessité de se défend...
Le groupe de travail interministériel sud-coréen a présenté les résultats de son plan global d'éradication de l'hameçonnage vocal, qui a permis une réduction significative des incidents et des préjudices financiers grâce à une nouvelle approche préventive.Un an après son lancement, le plan a entraîn...
Within the last few days, two important state actions have dealt a big blow to automated license plate reader (ALPR) networks. This is just the latest proof of the growing tide of public opposition to mass surveillance. After years of successful grassroots battles to pull these cameras from local st...
L'autorité estonienne de protection des données (AKI), en collaboration avec l'Inspection du travail, a clarifié plusieurs aspects de la gestion des données personnelles en milieu professionnel, notamment dans des contextes de conflit ou de fin de contrat.Face à l'augmentation des demandes d'accès d...
L'Agence espagnole de protection des données (AEPD) a annoncé sa participation aux vingtièmes Journées STIC avec un programme dédié à la protection des données.L'AEPD disposera d'un espace dédié à la protection des données le 24 novembre 2026, lors de cet événement qui se tiendra à Madrid du 24 au 2...
The healthcare data company Aesto informed federal regulators this week that more than 9.5 million people had sensitive information leaked during a cyberattack last December.