> TODAY'S SUMMARY (115 articles)
Today's cybersecurity landscape reveals several significant threats and trends. A critical CVSS 9.8 vulnerability in libheif, used by many servers for processing HEIC images, could lead to file disclosure and code execution risks. The Gyazo data breach has compromised 23 million user records due to a server vulnerability, while North Korean hackers have exploited fake job interviews to infect over 30,000 devices. Notably, AI-generated exploits are emerging, with researchers successfully using AI to hack into OpenAI employee accounts. Additionally, multiple vulnerabilities were disclosed across platforms like WordPress, Linux, and Check Point, highlighting ongoing risks in widely used software. Lastly, the FBI reported that impersonation scams have cost victims $1.6 billion, underscoring the financial impact of social engineering attacks.
|
// AI-powered summary generated at 20:00
Agentic exploits for the win (again)
A Gyazo breach exposed 23 million user records after attackers exploited a vulnerability in Helpfeel’s image upload server. Japanese software company Helpfeel is notifying Gyazo users about a data breach that compromised 23 million user records. Attackers gained unauthorized access by exploiting a v...
WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without anyone clicking Install.
The security firm pwn.ai, whose...
WaterPlum recruiters used bogus coding tests to backdoor jobseekers and raid more than 7,000 crypto wallets
The rise in AI-generated security threats may just have generated one casualty: the death of the weekly bulletin of security threats from the US Cybersecurity Infrastructure and Security Agency (CISA).
The agency will discontinue its weekly bulletin of known vulnerabilities...
AI, fake uniforms, and mock offices help crooks sell the con
TeamPCP pulled off the worst-ever software supply-chain hacking spree and breached thousands of companies. Now Google’s threat intelligence group says it had a mole inside the hackers’ inner circle.
The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6Â million user records. [...]
The U.S., Japan, Germany and Australia said WaterPlum operators pose as prospective employers and have infected more than 30,000 devices worldwide.
The post International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data appeared first on CyberScoop.
The feds are said to be investigating the compromise of the tankers' networks, which in one case interfered with one of the tanker's navigation and propulsion systems.
Popular AI coding agents such as OpenAI’s Codex, Anthropic’s Claude Code, Google’s Gemini CLI, and Microsoft-owned GitHub Copilot were vulnerable to a zero-click attack that enabled attackers to execute malicious code, even without developer interaction, by swapping a trusted...
RatHat can navigate infected phones while stealing bank logins, authentication codes, and screen-lock PINs.
The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan.
The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tool...
 An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel. [...]
Microsoft 365 users are being tricked into handing over access to their accounts by a new phishing kit, GhostCode, that exploits a weakness in a legitimate device authorization flow. Researchers in eSentire’s threat response unit identified the campaign in late August 2026....
A report published Wednesday said that as of July, Vietnam, Laos, Pakistan and Argentina took meaningful steps to respond to allegations involving North Korea listed in an October study.
Noteworthy stories that might have slipped under the radar: Mandiant's 2026 AI risk report, PhantomRaven malware used by bug bounty hunter, WordPress plugin bug exploited.
The post In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw appeared first on SecurityWeek...
rclone could be made to run programs if it received specially crafted network traffic.
An unreleased OpenAI model wrote instructions telling itself to ignore developer controls. Here’s what actually happened.
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.