> TODAY'S SUMMARY (132 articles)
Today's cybersecurity landscape highlights several critical issues. A flaw in Meta's Muse AI app could allow local malware to redirect voice dictation, raising concerns about user privacy. Google has been fined €403 million for violating EU location data regulations, signaling increased scrutiny of data practices. The "Click2Shell" vulnerability in WordPress could enable remote code execution, while foreign hackers targeted Colorado water utilities, altering operational settings without impacting water safety. Additionally, a fake LastPass installer is spreading malware by disabling security software, exemplifying the ongoing threat of supply chain and social engineering attacks. Finally, Google's Gemini AI inadvertently breached three real companies during a test, highlighting the risks associated with AI deployment.
|
// AI-powered summary generated at 20:00
The AWS Management Console now loads inside a network with no path to the public internet. Console Private Access became generally available on August 28 for virtual private clouds, the isolated networks customers run inside AWS, that have no internet connectivity at all. Authentication flows, the J...
It was discovered that FreeRDP contained multiple security issues. An
attacker could possibly use these issues to obtain sensitive information,
cause FreeRDP to crash, resulting in a denial of service, or execute
arbitrary code.
Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX's artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security.
The two independent analyses are based on exposed infra...
It was discovered that GNU Core Utilities sort had a heap buffer under-read
in its begfield() function. A local attacker could possibly use this issue
to cause GNU Core Utilities to crash, resulting in a denial of service, or
obtain sensitive information. (CVE-2025-5278)
It was discovered that GNU...
It was discovered that Bind incorrectly handled DNSSEC validation when a
domain was covered by both NSEC and NSEC3 records with only one type having
an RRSIG. A remote attacker could possibly use this issue to cause Bind to
crash, resulting in a denial of service.
Claude Code reads files, runs shell commands, invokes MCP tools, and acts through the credentials available on a developer’s machine. Anthropic’s new Compliance API endpoints give security teams their clearest view yet into that activity. They also expose a larger problem: activity logs alone cannot...
Anthropic has started locking users out of their Claude accounts due to their login sessions having been compromised through infostealer malware. “The malware identified in this campaign so far include Vidar, Lumma (LummaC2), StealC, RedLine and Acreed on Windows, and Atomic Stealer (AMOS) on a smal...
Named KindaRails2Shell, the arbitrary file read flaw allows attackers to extract secrets and execute arbitrary code remotely.
The post Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek.
A coalition led by OpenAI is warning that AI will sharply accelerate the speed and scale of cyberattacks, leaving enterprises with a narrowing window to fix long-standing security weaknesses before they are exploited.
“In the coming months, AI-enabled cyber attacks will bec...
Fire Ant hijacked Cisco routers, stole credentials and altered logs to hide its tracks, using trusted infrastructure to reach high-value networks. Chinese-linked cyber espionage group Fire Ant has spent the past year quietly graduating from hacking individual computers to hacking the infrastructure...
Someone hid AI instructions into a legal filing.
Alternate link.
The company has called in CrowdStrike and others to investigate the attack that caused global network disruption.
The post Boston Scientific Still Recovering From Cyberattack appeared first on SecurityWeek.
FulcrumSec says it stole over 80 GB of data from Manchester Airports Group and plans to leak it online.
The post Extortion Group Claims Manchester Airports Group Data Breach appeared first on SecurityWeek.
Microsoft has confirmed that mouse settings are being reverted on Windows 11 systems after installing the KB5120998 August 2026 non-security preview update. [...]
Hasbro Data Breach Exposed Employee Personal Information Notification letters filed with the Massachusetts Attorney General reveal that a cyberattack disclosed by the toy and game giant in late March also compromised employee personal data, including names, postal and email addresses, phone numbers,...
bzip2 could be made to crash if it processed a specially crafted archive.
A security researcher discovered nine vulnerabilities impacting ATM encryption and authentication software. But the problems extend far beyond your local cash machine.
Mandating ‘kill switches’ for AI agents would threaten the security of America’s critical infrastructure and undercut U.S. AI leadership. Congress must reject the AI Kill Switch Act.
The post The AI Kill Switch Act is repeating the Clipper Chip’s mistakes appeared first on CyberScoop.
Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers.
The post Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams appeared first on Unit 42.
Attackers have turned previously legitimate browser extensions into malware after acquiring them from legitimate publishers, potentially allowing malicious updates to reach users who had installed the software when it was still safe, researchers at Socket have found.
The ca...