> TODAY'S SUMMARY (85 articles)
Today's cybersecurity news highlights several emerging threats and trends. Attackers are impersonating established companies to distribute fake LastPass installers that deploy the 'Rapuncel' stealer, which can disable multiple security products. A significant cyberattack on Belgium’s national table tennis federation compromised data for tens of thousands of members. Additionally, Google faced a €403 million fine for mishandling user location data, indicating ongoing scrutiny over data privacy practices. The TASK#STOMP campaign has surfaced, utilizing a PowerShell backdoor to steal sensitive information. Furthermore, North Korean attackers are targeting developers in the Rust community with job scams designed to compromise their devices. This week also saw a takeover of the Clop ransomware site by rival group ShinyHunters, showcasing the ongoing power struggles within cybercrime syndicates.
|
// AI-powered summary generated at 16:01
The FBI is investigating a possible breach of idscan.net linked to 153 million driver’s license scans for sale online.
Using autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks.
The post An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation appeared first on Unit 42.
Ministers reject proposed red lines and emergency shutdown powers, pointing instead to voluntary safeguards
Environ 5 000 comptes Dropbox ont été piratés sans mot de passe entre le 4 et le 21 août 2026 via une faille dans la connexion SSO Lenovo ID.
Le post Dropbox : 5 000 comptes piratés sans mot de passe à cause d’une faille dans la connexion via Lenovo ID a été publié sur IT-Connect.
What you tell an AI chatbot could come back to haunt you in court. The Washington Post found chat histories already used in 12 legal cases.
Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals.
The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, and published the...
The browser refreshes fix multiple use-after-free, sandbox escape, and privilege escalation bugs.
The post Chrome and Firefox Updates Patch Dozens of Vulnerabilities appeared first on SecurityWeek.
The U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malware-laced Excel attachments to about 80,000 of its users in 2016 and 2017.
Searzhudin Tamirlanovich Aktulaev, 40, was ar...
A California federal grand jury has indicted a Russian national for his role in a phishing campaign that infected thousands of freelancers with TVRAT and DarkVNC malware. [...]
In April 2026, the balance between finding software flaws and fixing them broke. Frontier AI models released by Anthropic and OpenAI can now autonomously identify exploitable vulnerabilities in production software — work that used to take experienced human researchers roughly...
Batteries connected to the grid make money by reacting to frequency, pushing power out when it sags and soaking it up when it rises. A few hundred of them moving together, on command from someone who should not have the command, would look the same on a control room screen right up to the moment the...
SonicWall has urged customers to patch two new zero-day vulnerabilities being exploited in the wild
Sality, a peer-to-peer (P2P) botnet that had been running for 23 years and infecting more than 15,000 machines worldwide, has been taken down in a joint operation by international law enforcement agencies, working with CrowdStrike and the Shadowserver Foundation. The operation cut Sality’s operator...
Déployez Windows Hello for Business avec Intune : prérequis, profil de configuration, réinitialisation du PIN et pièges à éviter. Guide pas à pas.
Le post Déployer Windows Hello for Business avec Intune : le guide complet a été publié sur IT-Connect.
The shutdown operation involved peer list manipulation and Sality payload URL takedown.
The post 23-Year-Old Sality P2P Botnet Disrupted appeared first on SecurityWeek.
Last week, the US Justice Department and FBI announced court-authorized seizures of domains hard-coded into two complementary hacking platforms known as “QScan” and “QTRouter,” used by Chinese state-sponsored hackers to target US critical infrastructure and other sensitive net...
Threat group FulcrumSec claims MAG breach and leaks 550GB of data online
Keepnet, an Extended Human Risk Management (xHRM) and Secure Behavior Management platform, today launched the Keepnet SMS/Call Reporter. It is a free app that turns a suspicious SMS or phone call into a one-tap report. Anyone can download it for personal protection. Organizations can roll it out acr...
International law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botnet. [...]
Hackers are exploiting a critical Langflow flaw that lets unauthenticated attackers remotely execute Python code on vulnerable systems. Hackers have started exploiting a critical vulnerability, tracked as CVE-2026-0768 (CVSS score of 9.8), in the AI-focused low-code platform Langflow. The flaw affec...