> TODAY'S SUMMARY (85 articles)
Today's cybersecurity news highlights several emerging threats and trends. Attackers are impersonating established companies to distribute fake LastPass installers that deploy the 'Rapuncel' stealer, which can disable multiple security products. A significant cyberattack on Belgium’s national table tennis federation compromised data for tens of thousands of members. Additionally, Google faced a €403 million fine for mishandling user location data, indicating ongoing scrutiny over data privacy practices. The TASK#STOMP campaign has surfaced, utilizing a PowerShell backdoor to steal sensitive information. Furthermore, North Korean attackers are targeting developers in the Rust community with job scams designed to compromise their devices. This week also saw a takeover of the Clop ransomware site by rival group ShinyHunters, showcasing the ongoing power struggles within cybercrime syndicates.
|
// AI-powered summary generated at 16:01
Learn how to organize shared password vaults by department, enforce least privilege, and keep credential management secure.
This is interesting:
The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, which is associated with protected communications, cryptography, and information security.
[…]
The reporting also linked...
It was discovered that pyasn1 did not properly bound the size of long-form
tag identifiers when parsing BER, CER, or DER encoded data. An attacker
could possibly use this issue to cause applications decoding untrusted
ASN.1 data to consume excessive CPU resources, resulting in a denial of
service. (...
It was discovered that Libgcrypt had a timing-based side-channel flaw in
its RSA implementation. A remote attacker could possibly use this issue to
obtain sensitive information.
A fake GTA 6 leak is using wallet-draining code to steal cryptocurrency, tokens, and NFTs from eager fans.
AIR's platform can discover agents running at a company, continuously vets any skills and add-ons they use, and blocks any unwanted behaviour.
USN-8688-1 fixed a vulnerability in PAM. This update provides the
corresponding fix for PAM on Ubuntu 26.04 LTS.
Original advisory details:
Juthawong Naisanguansee discovered that PAM incorrectly cleared failed
login attempt records when certain services invoked the account phase
without first...
USN-8555-1 fixed vulnerabilities in Ubuntu Advantage Tools. On Ubuntu
14.04 LTS only, it was discovered that some machines were unable to
enable esm-infra-legacy due to a preemptive apt-helper check. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Bi...
Cybercriminals breached company data and made an extortion attempt with it, Houston-based Nutex Health said in a filing with federal regulators.
Alexis Challande discovered that libevent incorrectly handled certain
empty output buffers. An attacker could possibly use this issue to
trigger a use-after-free, resulting in a denial of service or arbitrary
code execution. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04
LTS, Ubuntu 22.04 L...
On August 14th, 2026, we received a submission for an Unauthenticated Second-Order SQL Injection vulnerability in All-in-One WP Migration and Backup, a WordPress plugin with more than 5 million active installations.
The post 5 Million WordPress Sites Affected by SQL Injection Vulnerability in All-i...
It was discovered that ncurses incorrectly handled specially crafted
terminfo database entries. A local attacker could possibly use this issue
to cause applications using ncurses to crash, resulting in a denial of
service.
For years, the security industry has treated vulnerabilities as an endless queue of individual fixes. A recent CISA review argues that this is precisely why attackers keep winning. The solution to this problem, they believe, is eliminating entire categories of weaknesses at the source. “By reducing...
Aesto Health suffered a breach exposing personal and health data of more than 9.5 million people after attackers accessed its AWS infrastructure. Aesto Health, a U.S. healthcare technology company, disclosed a data breach that exposed personal and health information belonging to more than 9.5 millio...
Flock's searchable network of 130,000 license plate cameras around the U.S. have sparked bipartisan privacy and civil liberties concerns.
Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers. [...]
Chaotic Eclipse released PrettyPrague, a PoC exploit for a GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting GenDigital Avast Ant...
Attackers used a stolen METR API key for three weeks, consuming model credits worth $600,000
Healthtech company Novocure says the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients has been exposed in a mid-August cyberattack. [...]
Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices.
"The inject...