> TODAY'S SUMMARY (132 articles)
Today's cybersecurity landscape highlights several critical issues. A flaw in Meta's Muse AI app could allow local malware to redirect voice dictation, raising concerns about user privacy. Google has been fined €403 million for violating EU location data regulations, signaling increased scrutiny of data practices. The "Click2Shell" vulnerability in WordPress could enable remote code execution, while foreign hackers targeted Colorado water utilities, altering operational settings without impacting water safety. Additionally, a fake LastPass installer is spreading malware by disabling security software, exemplifying the ongoing threat of supply chain and social engineering attacks. Finally, Google's Gemini AI inadvertently breached three real companies during a test, highlighting the risks associated with AI deployment.
|
// AI-powered summary generated at 20:00
Pillow could be made to crash or expose sensitive information if it processed a specially crafted image file.
A China-linked cyber espionage group has expanded beyond VMware environments to target network and authentication infrastructure that enterprises rely on to manage access and administer critical systems, according to new findings from incident response firm Sygnia.
The thre...
Chaotic Eclipse released HardBreacher, a PoC exploit for a Kaspersky Endpoint Security privilege escalation flaw, adding another zero-day to his list. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting K...
The Financial Stability Board has warned G20 banking leaders about the cyber risks of frontier AI
Five Venezuelan nationals pleaded guilty to attempting to empty automated teller machines (ATMs) using malware in a series of ATM jackpotting attacks. [...]
Hackers stole personal and health information from the healthcare technology company’s AWS infrastructure.
The post 9.5 Million Impacted by Aesto Health Data Breach appeared first on SecurityWeek.
Berlin’s state government has confirmed an extortion attempt following a data theft from its administrative network in August. Governing Mayor Kai Wegner and Interior Senator Iris Spranger addressed the extortion attempt on Friday, following an emergency Senate session at the Rotes Rathaus. “The sta...
METR (short for Model Evaluation and Threat Research and pronounced "Meter"), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks, disclosed that it suffered "two notable security incidents" where external actor...
Three critical issues in the Fireware OS iked process could allow unauthenticated attackers to execute arbitrary code remotely.
The post WatchGuard Patches Critical Vulnerabilities appeared first on SecurityWeek.
Cybersecurity researchers have disclosed a new technique dubbed GuardBreaker that's been put to use by a Russia-aligned threat actor known as UAC-0099 against a target in Ukraine with an aim to interfere with artificial intelligence (AI)-assisted analysis.
The idea, ESET said in a series of posts o...
Today marks the beginning of the end of an era for enterprise Microsoft authentication.
As of Sept. 1, passkeys are now the default authentication method for Entra ID, Microsoft’s cloud-based identity and access management (IAM) service. By Feb. 1, 2027, Microsoft-provided...
ShinyHunters claims to have stolen 284 million records from McKesson
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: PaperCut,...
Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks. [...]
zlib could be made to consume excessive CPU resources if it received specially crafted input.
Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck.
The vulnerabilities in question are listed below -
CVE-2026-0768 (CVSS score: 9.8) - A lack of proper validation of a user-supplied input vulnerability that could be e...
It was discovered that Pillow did not properly manage memory when
processing certain image files. An attacker could possibly use this issue
to cause a denial of service or read sensitive data.
LastPass announced a series of strategic product innovations, customer experience enhancements, and industry milestones. These advancements reflect the company’s continued focus on providing practical tools to protect access and identity in an increasingly AI-driven threat landscape. Highlights incl...
Askeal takes the opposite approach to omniscient Gen AI: rather than pretending to know everything, it combines AI with community expertise. Vetted vendors, researchers, and practitioners contribute their intelligence and tools to help users conduct manual investigations. The startup, backed by a $1...
CISA has added the vulnerabilities tracked as CVE-2026-82078 and CVE-2026-81578 to its KEV catalog.
The post PaperCut Exploitation Escalates to Active Intrusions appeared first on SecurityWeek.