> TODAY'S SUMMARY (85 articles)
Today's cybersecurity news highlights several emerging threats and trends. Attackers are impersonating established companies to distribute fake LastPass installers that deploy the 'Rapuncel' stealer, which can disable multiple security products. A significant cyberattack on Belgium’s national table tennis federation compromised data for tens of thousands of members. Additionally, Google faced a €403 million fine for mishandling user location data, indicating ongoing scrutiny over data privacy practices. The TASK#STOMP campaign has surfaced, utilizing a PowerShell backdoor to steal sensitive information. Furthermore, North Korean attackers are targeting developers in the Rust community with job scams designed to compromise their devices. This week also saw a takeover of the Clop ransomware site by rival group ShinyHunters, showcasing the ongoing power struggles within cybercrime syndicates.
|
// AI-powered summary generated at 16:01
A coordinated voice-phishing (vishing) campaign, named Spring Ring, used fake IT support accounts on Microsoft Teams to trick employees into installing malware or granting remote access to their computers, according to Unit 42, Palo Alto Networks’ threat intelligence team. The campaign ran between J...
Attackers can hide behind residential proxies, VPNs, and other infrastructure that makes malicious sessions appear legitimate to existing edge security controls. Spur explains how session enrichment adds data points that help organizations identify risky sessions and make stronger enforcement decisi...
The Federal Ballot Mail Portal is described by a federal official as one of several IT systems that will be used to potentially deny thousands of mail-in ballots or more to states.
The post Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots appeared first on Cyber...
Five Venezuelan nationals pleaded guilty after failed ATM jackpotting attempts in Kansas. The FBI recorded 700+ cases in 2025, causing $20M in losses. Five Venezuelan nationals have pleaded guilty after trying to steal cash from ATMs in Kansas using the popular ATM jackpotting technique. The U.S. De...
EMA survey finds 65% of enterprises have seen AI agents act beyond intended scope
The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access trojans (RATs) dev...
Could we get more cache space with the same hardware? We prototyped compression inside Cloudflare's cache to find out.
It was discovered that sudo-rs incorrectly handled time-of-check vs time-
of-use conditions in sudoedit. A local attacker with permission to edit
specific files using sudoedit could use this issue to place files in
arbitrary directories, and possibly escalate their privileges. This issue
only affect...
Project Watershed 250 will see water providers in Texas provided with federal and private sector cybersecurity resources amid rising nation-state threats
McKesson Discloses Breach After ShinyHunters Claims Patient Data Theft Healthcare and pharmaceutical distribution giant McKesson has confirmed a cybersecurity incident involving unauthorized access to third-party applications after the ShinyHunters extortion group claimed it stole roughly 284 millio...
Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes. [...]
Forescout researchers used Claude AI to port a remote code execution exploit between WAGO PLC models.
The post Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars appeared first on SecurityWeek.
In a report published Tuesday, Kaspersky said it first discovered NodeRabbit on a system in Afghanistan and later identified variants on systems in Egypt and Ethiopia.
OpenClaw has released what it describes as the largest update in its history, introducing a system-wide overhaul spanning runtime behavior, plugins, and security controls, as enterprises increasingly evaluate how such agent-based systems operate across connected environments....
Andrew Bailey, chair of the Financial Stability Board, called on financial institutions and technology providers to “prepare for more severe scenarios involving simultaneous disruption across multiple firms or shared technology dependencies.”
A malicious GitHub repository impersonating Anthropic and claiming to offer free access to “Claude Opus 5” is delivering RevStealer, Windows information-stealing malware that targets passwords, cryptocurrency wallet data and login credentials, according to Morphisec. Repository README using Claude O...
The familiar ClickFix fake CAPTCHA trick has been adapted to deliver a payload that can give attackers access to the victim’s wider network.
Tracked as CVE-2026-0768, the security defect allows unauthenticated attackers to execute arbitrary Python code remotely.
The post Hackers Start Exploiting Critical Langflow Vulnerability appeared first on SecurityWeek.
Hosting software vendor tells customers to reset credentials and hunt for malicious packages
The US Army’s laser system is part of a new generation of directed-energy weapons capable of detecting, tracking, and destroying drones with a concentrated beam of light.