> TODAY'S SUMMARY (85 articles)
Today's cybersecurity news highlights several emerging threats and trends. Attackers are impersonating established companies to distribute fake LastPass installers that deploy the 'Rapuncel' stealer, which can disable multiple security products. A significant cyberattack on Belgium’s national table tennis federation compromised data for tens of thousands of members. Additionally, Google faced a €403 million fine for mishandling user location data, indicating ongoing scrutiny over data privacy practices. The TASK#STOMP campaign has surfaced, utilizing a PowerShell backdoor to steal sensitive information. Furthermore, North Korean attackers are targeting developers in the Rust community with job scams designed to compromise their devices. This week also saw a takeover of the Clop ransomware site by rival group ShinyHunters, showcasing the ongoing power struggles within cybercrime syndicates.
|
// AI-powered summary generated at 16:01
Forescout Research - Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware.
The exploit targets CVE-2021-31886, a s...
In August 2026, Manchester Airports Group (MAG) disclosed a data breach impacting their services. The incident was later claimed by the FulcrumSec hacking group, who subsequently published email addresses and phone numbers relating to 8.7M customers of Manchester, Stansted and East Midlands airports...
Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution.
The vulnerability in question is CVE-2026-9586 (CVSS score: 9.3), a critical unauthenticated SQL injection vulnerability in Sangoma...
The U.S. Department of Justice (DoJ) on Tuesday announced the takedown of a long-standing peer-to-peer (P2P) botnet known as Sality as part of a coordinated law enforcement operation.
The effort was undertaken on August 31, 2026, by authorities from the U.S., Bulgaria, Hungary, and Romania, in coll...
SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. [...]
Visa announced an enhanced version of A2A Protect, delivering real-time risk insights that help banks stop account-to-account fraud before money leaves customer accounts. The expanded solution introduces a new unified fraud score—Visa’s integration of Featurespace technology—giving financial institu...
Edge Case launched Guardian, an AI-driven platform that connects safety analysis, engineering data, and operational signals to give teams a continuous understanding of how system risk evolves. At launch, Guardian will support some of the world’s most advanced autonomous platforms, with six customer...
La Commission européenne désigne ChatGPT comme grand moteur de recherche, Reddit et Roblox comme grandes plateformes. Quatre mois pour être conforme au DSA.
Le post DSA : l’Europe place ChatGPT, Reddit et Roblox sous surveillance renforcée a été publié sur IT-Connect.
Hannes MĂĽhleisen and Mark Raasveldt started as AWS employees. The two built DuckDB, an analytical database that runs inside your process instead of on a server somebody has to administer. If you ship anything on top of DuckDB, your license does not change. Amazon did not buy the project. DuckDB, Duc...
F5 announced innovations to block frontier AI-driven threats in the data path and enable faster virtual patching, giving security leaders time to make intelligent risk-based decisions rather than reactive operational compromises. With new features such as anomaly detection and agentic threat intelli...
Welcome to this new release. Get it as always from https://curl.se. If you rather want a security-patched older release branch, stay tuned for the follow-up Rock-solid curl announcement within a few days. Release presentation At 10:00 CEST (08:00 UTC) Daniel makes a live-streamed release presentatio...
Vali Cyber released ZeroLock 5, a major release focused on closing the two most dangerous gaps in hypervisor security: insider threats and stolen credentials on ESX and Linux hosts. The hypervisor is now the target Over the past two years, ransomware operators and nation-state actors alike have shif...
In this Help Net Security interview, Becky Palmer is VP and CISO at National Life Group, answers five questions about defending against AI-driven attacks. The discussion covers why patch cycles built for human speed cannot keep up, and which compensating controls buy time when an immediate fix is no...
Exchange exposé sur Internet: tout savoir sur la CVE-2026-62911, les risques, les chiffres Shadowserver et les correctifs à appliquer rapidement.
Le post Exchange Server : près de 22 000 serveurs exposés sont vulnérables à la CVE-2026-62911 a été publié sur IT-Connect.
A team of NYU and Radboud University researchers spent a year building a tool to find deceptive software ads inside Google’s public ad archive. It works. It also exposed something more uncomfortable: reporting a bad ad to Google doesn’t mean the ad, or the domain behind it, stops running. The tool i...
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The vulnerabilities CVE-2026-83549 and CVE-2026-83548 can be chained for unauthenticated remote code execution.
The post SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks appeared first on SecurityWeek.
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: