> TODAY'S SUMMARY (132 articles)
Today's cybersecurity landscape highlights several critical issues. A flaw in Meta's Muse AI app could allow local malware to redirect voice dictation, raising concerns about user privacy. Google has been fined €403 million for violating EU location data regulations, signaling increased scrutiny of data practices. The "Click2Shell" vulnerability in WordPress could enable remote code execution, while foreign hackers targeted Colorado water utilities, altering operational settings without impacting water safety. Additionally, a fake LastPass installer is spreading malware by disabling security software, exemplifying the ongoing threat of supply chain and social engineering attacks. Finally, Google's Gemini AI inadvertently breached three real companies during a test, highlighting the risks associated with AI deployment.
|
// AI-powered summary generated at 20:00
AWS IAM Identity Center integrates with external identity provider (IdP) to provide customers with a centralized authentication and authorization solution for AWS resources across AWS Organizations. AWS continues to invest into IAM Identity Center with a growing number of AWS services that natively...
Microsoft is investigating a widespread service issue causing authentication issues and email delays and failures for Exchange Online customers. [...]
ChatGPT Work is experiencing a partial outage, and users across multiple subscription plans may be unable to start or continue tasks. [...]
Regulating commercial location tracking has reached a turning point. Last year, we published our rubric for what comprehensive and protective location privacy laws should look like, outlining the baseline standards states should meet to shield individuals from pervasive location surveillance. Since...
Commodity malware steals authenticated sessions, letting thieves freeload on victims' paid usage
This post is adapted from a video recorded by EFF and the Trevor Project. Head over to our TikTok or Instagram to watch!Â
EFF answers all the queer digital rights questions you submit to us through our LGBT Q&A. You asked us: What’s one thing I can do today to improve my safety and security onli...
It was discovered that primitive decoders in openCryptoki produced integer
underflows when the encoded length was zero. An attacker could possibly use
this issue to trigger out-of-bounds reads. (CVE-2026-40253)
It was discovered that openCryptoki incorrectly handled symlinks. An
attacker in the tok...
Several security issues were fixed in GNU cpio.
GNU diffutils could be made to crash if it received specially crafted input.
AI is proving effective at finding and exploiting vulnerabilities. Some say this will make it harder for governments to use hacking tools and spyware and could reignite calls to backdoor devices.
Several security issues were fixed in CRaC JDK 21.
Several security issues were fixed in CRaC JDK 25.
The researchers discovered Fire Ant's new tactic after finding an active GRE (Generic Routing Encapsulation) tunnel interface on a Cisco IOS XR router that could not be explained by a running configuration or commit history. [...]
p11-kit could be made to crash if it received specially crafted input.
Healthcare company McKesson acknowledged a data breach. ShinyHunters claims to have stolen hundred of millions of records
Governing Mayor Kai Wegner said on Friday that Berlin had received an extortion demand following the cyberattack, which was discovered in mid-August.
Attackers are disguising automated scanning as traffic from AI crawlers operated by OpenAI, Anthropic, Google, Perplexity and other companies while searching websites for exposed credentials and configuration files, according to GreyNoise. (Source: GreyNoise) “Every program that visits a website ann...
The threat actor targeting internet-facing PaperCut Application Servers is covertly installing legitimate remote access software on them, PaperCut Software shared in the most recent update on the ongoing attack campaign. PaperCut zero-days exploited to deploy remote access tools The vendor first war...
Kaspersky told SecurityWeek that it patched the vulnerability affecting its Endpoint Security product.
The post Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit appeared first on SecurityWeek.
File servers remain a critical part of many IT environments, but managing access securely can become complex as permissions accumulate. tenfold Software outlines five best practices for simplifying file server administration and maintaining least-privilege access. [...]