> TODAY'S SUMMARY (18 articles)
Today's cybersecurity landscape highlights several critical threats and vulnerabilities. A new WordPress vulnerability, Click2Shell, allows remote code execution via a single click, emphasizing the need for immediate updates to version 7.1.1. Additionally, a fake job interview campaign linked to North Korea has infected over 30,000 devices, showcasing the ongoing risks of social engineering attacks. The TryCloudflare service misconfiguration has led to unintended Google indexing, exposing sensitive user services. On the infrastructure side, flaws in Zyxel switches and Veeam software are actively exploited, prompting CISA to add them to its Known Exploited Vulnerabilities catalog. Lastly, security researchers have identified potential backdoor access through Meta's AI assistant, underlining the importance of scrutinizing AI integrations for security flaws.
|
// AI-powered summary generated at 08:01
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- File systems infrastructure;
- OCFS2 file system;
- B.A.T.M.A.N. meshing protocol;
- SCTP protocol;
- TIPC p...
New details about the July attack on Hugging Face reveal that hundreds of AI agents driven by OpenAI's internal IM1 model coordinated the compromise through an unauthorized message board. [...]
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi
implementation in the Linux kernel did not properly handle aggregated
frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A
physically proximate attacker could use this issue to inject packets.
(CVE-2025-27558...
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Open vSwitch;
- SCTP protocol;
(CVE-2026-53224, CVE-2026-53246, CVE-2026-64531)
It's 'built to be operated by a human with no technical background'
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Network drivers;
- Open vSwitch;
- SCTP protocol;
(CVE-2026-53224, CVE-2026-53246, CVE-2026-53247, CVE-2026-6453...
Dark Caracal targets Venezuela with GoCaracal, an upgraded Bandook toolkit and an Ethereum fallback for resilient C2 communications. Dark Caracal is back with new malware and the same hunting grounds. Arctic Wolf Labs researchers link a June 2026 intrusion against a communications organisation in Ve...
The Trump administration is banning the acquisition of foreign-made components used to manage electricity and power, alleging that “certain foreign actors are increasingly creating and exploiting vulnerabilities” in the technology.
When you create an AI agent that makes a breakthrough that is so difficult to understand that you need to ask it to write a blog post to explain it to you, you know you’re on to something.
The post Wordfence Argus: Moving Beyond Human Research Capability appeared first on Wordfence.
Juthawong Naisanguansee discovered that PAM incorrectly cleared failed
login attempt records when certain services invoked the account phase
without first performing authentication. An attacker could possibly use
this issue to reset failed login counters, resulting in authentication
lockout restrict...
L'autorité sud-coréenne de protection des données, la Commission de protection des informations personnelles (PIPC), a mené une inspection préventive dans le secteur financier pour mettre fin au traitement des numéros d'enregistrement de résident sans base légale.Cette démarche fait suite à une sanc...
L'autorité britannique de protection des données (ICO) a publié une déclaration concernant l'issue d'un procès impliquant Meta aux États-Unis et les engagements pris par l'entreprise.L'ICO a pris note de la décision et des mesures que Meta s'est engagée à mettre en œuvre, et a indiqué qu'elle contac...
Even testing and staging sites need protection from prying eyes
La Commission Nationale de l'Informatique et des Libertés (CNIL) a mené une action de sensibilisation en 2026 auprès de 2 500 élèves de CM2 du département de l’Oise sur les enjeux du numérique et la protection des données personnelles.Ce projet, mené en collaboration avec l’Adico, le Syndicat Mixte...
L'autorité polonaise de protection des données (UODO) a publié des recommandations pour les personnes concernées et les responsables du traitement à la suite d'un incident de sécurité impliquant la société MyDr.L'UODO a annoncé qu'elle mènerait une inspection des mesures techniques et organisationne...
OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior as early as late May.
The incident, the company said, took place during cybersecurity evaluations o...
L'autorité norvégienne de protection des données (Datatilsynet) s'est associée à plusieurs autres entités publiques pour fournir des recommandations sur la prévention et la gestion des violations de données.En collaboration avec l'Autorité nationale de sécurité (NSM), la Police et la Direction de la...
Une violation de données résultant d'une vulnérabilité non corrigée sur un serveur et d'une absence de cloisonnement réseau entre deux sociétés d'un même groupe a conduit l'autorité sud-coréenne à sanctionner les deux entités, en distinguant la responsabilité de celle dont le système a servi de poin...
Your team collaboration software stack isn't free — it's just expensive in ways you haven't counted yet. Here's how to fix that.
Une société commercialisant des dispositifs de blocage d'appels a été sanctionnée pour avoir elle-même réalisé des campagnes massives de démarchage téléphonique illicite, en ciblant spécifiquement des personnes âgées et vulnérables inscrites sur une liste d'opposition.Faits et contexteL'autorité de...