> TODAY'S SUMMARY (36 articles)
Today's cybersecurity landscape highlights several significant threats and trends. Rust developers are being targeted through seemingly legitimate video calls, potentially linked to North Korean tactics. Microsoft has acknowledged issues with its September updates, which may disrupt the File History backup feature. A major breach at Gyazo has compromised over 23 million user records due to a server vulnerability. Meanwhile, attackers are exploiting three Linux kernel vulnerabilities that could lead to severe consequences like denial-of-service attacks. Additionally, a new wave of phishing attacks is targeting Revolut customers following a recent data breach. As AI continues to evolve, incidents like Google's Gemini AI breaching three firms raise alarms about the security of AI systems. Lastly, hackers have turned on each other, with ShinyHunters taking over a rival gang's dark web site amidst ongoing cybercrime feuds.
|
// AI-powered summary generated at 12:01
Sality’s peer-to-peer infrastructure allowed it to evade system-wide disruption efforts for an exceptionally long period. Authorities and cybersecurity experts finally brought it down.
The post Dogged Russia-based botnet dismantled after 23-year run appeared first on CyberScoop.
An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers.
"The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affe...
Miscreants use chained zero days to pwn boxen as third-party SOCs say further attacks 'almost certain'
Read the latest DFIR news – SANS AI frameworks for DFIR, AI hackathon tools, investigator well-being, macOS unlock artifacts, cross-platform log analysis, Apple Health forensics, and more.
Tech support scams have evolved beyond fake virus warnings. Here’s how scammers reach their targets now, and how to stay safe.
A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide administrative access. [...]
Late amendments to the Cyber Security and Resilience Bill would give ministers new powers to restrict risky technology providers as supply chain attacks intensify.
The post UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure appeared first on SecurityWeek.
On August 19th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Elementor Pro, a WordPress plugin with more than 6,000,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including executa...
The group, which calls itself VantaCore, has targeted at least seven known victims, Russian cybersecurity firm F6 said in a report published this week.
It’s the first Pegasus infection of 2026 that Citizen Lab is forensically confirming, and the SHARE Foundation said it’s the biggest wave of spyware surveillance in Serbia yet.
The post Pegasus, NoviSpy variant spyware found on devices of Serbian activists appeared first on CyberScoop.
HiddenLayer has raised a $100M Series B from Delta-v Capital, Ten Eleven Ventures, Morgan Stanley, Microsoft's M12, Booz Allen Hamilton, and others.
it’s the latest in a sequence of letters to feds from Sen. Ron Wyden, D-Ore., on commercial VPNs.
The post Wyden seeks upgraded NSA security guidance on commercial VPN use appeared first on CyberScoop.
If your forensic tool isn’t showing you every file in a case, how can you be sure you’re investigating the full picture? See how S21 VisionX keeps difficult, damaged and excluded material visible to investigators.
Russian man extradited to US over malware campaign that targeted 80,000 freelance users
If you live in Jersey and bank with Revolut, you should be on your guard against scam phone calls.
Because local police on the largest of the Channel Islands have warned that over a single four-week period, an astonishing 75% of all scam crime reports they have received have involved Revolut acco...
BioSig could be made to crash or run programs as your login if it opened a specially crafted file.
Cloud storage biz severs old integration and urges victims to reset credentials
SonicWall patched two zero-days in SMA 1000 VPNs, including a CVSS 10 pre-auth SSRF flaw, after confirming active exploitation. SonicWall has released security updates for two vulnerabilities in its SMA 1000 VPN appliances that are actively exploited in attacks in the wild. SonicWall’s researchers W...
Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication.
The command executes as the user, outside the ag...
Mark Bereza and Lilith Wyatt discovered that BioSig incorrectly handled certain crafted input
files. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. (CVE-2026-22891, CVE-2026-20777)