> TODAY'S SUMMARY (132 articles)
Today's cybersecurity landscape highlights several critical issues. A flaw in Meta's Muse AI app could allow local malware to redirect voice dictation, raising concerns about user privacy. Google has been fined €403 million for violating EU location data regulations, signaling increased scrutiny of data practices. The "Click2Shell" vulnerability in WordPress could enable remote code execution, while foreign hackers targeted Colorado water utilities, altering operational settings without impacting water safety. Additionally, a fake LastPass installer is spreading malware by disabling security software, exemplifying the ongoing threat of supply chain and social engineering attacks. Finally, Google's Gemini AI inadvertently breached three real companies during a test, highlighting the risks associated with AI deployment.
|
// AI-powered summary generated at 20:00
Hasbro Data Breach Exposed Employee Personal Information Notification letters filed with the Massachusetts Attorney General reveal that a cyberattack disclosed by the toy and game giant in late March also compromised employee personal data, including names, postal and email addresses, phone numbers,...
bzip2 could be made to crash if it processed a specially crafted archive.
A security researcher discovered nine vulnerabilities impacting ATM encryption and authentication software. But the problems extend far beyond your local cash machine.
Mandating ‘kill switches’ for AI agents would threaten the security of America’s critical infrastructure and undercut U.S. AI leadership. Congress must reject the AI Kill Switch Act.
The post The AI Kill Switch Act is repeating the Clipper Chip’s mistakes appeared first on CyberScoop.
Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers.
The post Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams appeared first on Unit 42.
Attackers have turned previously legitimate browser extensions into malware after acquiring them from legitimate publishers, potentially allowing malicious updates to reach users who had installed the software when it was still safe, researchers at Socket have found.
The ca...
Russian state hackers are trying to interfere with AI-assisted malware analysis in Ukraine by deliberately setting off AI safety mechanisms, ESET has found. The technique, named GuardBreaker by ESET, appeared in a malicious VBS script tied to UAC-0099, a Russia-aligned group previously observed cond...
Two Nigerian men extradited to the U.S. on Thursday have been charged with involvement in sextortion schemes that resulted in the deaths of two minor victims in Mississippi and North Carolina. [...]
Infostealers can steal active Claude sessions, bypass 2FA and drain paid usage. Anthropic is revoking access and refunding unauthorized charges. Anthropic confirmed that several infostealer malware can hijack an active Claude login session and let attackers burn through your usage without ever touch...
The ruling is part of Anthropic's legal battle against the Pentagon after the government labeled the company as a supply chain risk earlier this year.
The post Judge Says Pentagon’s Measures Against Anthropic Were ‘Illegal and Baseless’ appeared first on SecurityWeek.
A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, and manage high-value...
Details about the Hugging Face hack, critical infrastructure under attack, a spoofed in-flight Wi-Fi network, and more of this month's cybersecurity news
The Rhysida ransomware group has claimed the exfiltration of over 5TB of data, including personal information and credentials.
The post Berlin Won’t Pay Extortion Group Claiming Data Theft appeared first on SecurityWeek.
Proton a analysé plus de 7 000 applications VPN mobiles : 85 % de celles téléchargées aux États-Unis contiennent des traqueurs et 64 accèdent à votre position.
Le post Applications VPN : 85 % de celles téléchargées aux États-Unis embarquent des traqueurs a été publié sur IT-Connect.
Microsoft asked customers this week to ignore incorrect alerts that Defender Antivirus has been turned off after installing the latest Defender updates. [...]
Cloud architectures designed to withstand human attackers are facing a new threat: AI agents that rewrite the rules on the pace and scope of attacks.
The recent OpenAI incident involving Hugging Face offers an early example of what an autonomous AI attack can look like, wit...
Gitea a publié la première version stable de son extension pour VS Code : suivi des Actions et revue des pull requests sans quitter l'éditeur de code.
Le post Gitea sort enfin son extension officielle pour VS Code a été publié sur IT-Connect.
Les développeurs Debian ont voté : l'IA générative n'est ni interdite ni recommandée, mais celui qui soumet une contribution en assume toute la responsabilité.
Le post Debian autorise officiellement l’IA générative, mais le contributeur reste responsable a été publié sur IT-Connect.
A maintainer reading a merge request can’t tell whether a person or a model wrote the diff, and nobody has to say. Debian developers voted on that through August 28, and Kurt Roeckx, the project secretary, announced the result: the winning option encourages contributors to disclose AI assistance and...
PaperCut NG et MF sont visés par 2 failles déjà exploitées : CVE-2026-81578 et CVE-2026-82078. Le premier correctif a été contourné, un second est disponible.
Le post PaperCut NG/MF : deux failles exploitées et un premier correctif contourné a été publié sur IT-Connect.