> TODAY'S SUMMARY (18 articles)
Today's cybersecurity landscape highlights several critical threats and vulnerabilities. A new WordPress vulnerability, Click2Shell, allows remote code execution via a single click, emphasizing the need for immediate updates to version 7.1.1. Additionally, a fake job interview campaign linked to North Korea has infected over 30,000 devices, showcasing the ongoing risks of social engineering attacks. The TryCloudflare service misconfiguration has led to unintended Google indexing, exposing sensitive user services. On the infrastructure side, flaws in Zyxel switches and Veeam software are actively exploited, prompting CISA to add them to its Known Exploited Vulnerabilities catalog. Lastly, security researchers have identified potential backdoor access through Meta's AI assistant, underlining the importance of scrutinizing AI integrations for security flaws.
|
// AI-powered summary generated at 08:01
PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. [...]
If you’re running AI agents in production, Amazon Bedrock Guardrails protects the model boundary. But your agents also invoke tools, fetch external data, and communicate with other systems. That data flows outside the model boundary, where model-level guardrails can’t reach. You can extend guardrail...
Found a bank card that isn’t yours? Here’s who to reach out to, why you shouldn’t try to track down the owner yourself, and the right way to handle a found card.
Vols de cartes Pokémon : collectionneurs et boutiques deviennent des cibles pour des criminels parfois très informés via les fuites de données et les réseaux sociaux.
The Manchester Airports Group (MAG) disclosed that hackers breached its systems and stole customer data, including Wi-Fi sign-ups from Manchester, Stansted, and East Midlands airports. [...]
This month’s updates provide new capabilities to help organizations gain insights into agent activity, expand security coverage across supported environments, and enhance security management across their environments.
The post ​​​​​​What’s new in Microsoft Security: August 2026 appeared first on Mic...
Several security issues were fixed in openCryptoki.
TeamPCP : deux suspects arrêtés après une enquête sur des attaques de supply chain ayant touché plus de 1 000 organisations.
Guillem Lefait discovered a path traversal attack in suricata-update, a tool for updating Suricata rules, which allowed malformed rules to overwrite files on the system. For the stable distribution (trixie), this problem has been fixed in version 1.3.4-1+deb13u1.
The appeals court sent the case back to the Helsinki District Court to be heard on its merits, although the three men, who had previously been detained in Finland, have since left the country.
US Justice Department investigating the breach
22 failles corrigées dans l’écosystème UniFi (Protect, Network, OS, Talk) avec 3 failles critiques associées à un score CVSS de 10 sur 10.
Le post 22 failles corrigées dans l’écosystème UniFi, dont 3 avec un score CVSS de 10 sur 10 a été publié sur IT-Connect.
It was discovered that p11-kit incorrectly handled certain RPC messages. A
local attacker could use this issue to cause p11-kit to crash, resulting in
a denial of service. (CVE-2026-13757)
It was discovered that p11-kit incorrectly handled nested attribute
decoding on 32-bit systems. A local attack...
Flock’s CEO wants a compromise between privacy and public safety, but the public has already compromised enough.
Credit:Â Hacktron
Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting server...
A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine.
The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing the...
SPONSORED FEATURE: Verify and survive: your backup isn't real 'til you test it
What happens when disturbing material in a CSAM investigation has to be read, not viewed? Paul Gullon-Scott examines the psychological impact of messages, descriptions and AI prompts on digital forensic investigators.
Foreign intelligence services, particularly those from China and Russia, are increasingly behind cyberattacks on German companies, according to a new survey of the country’s private sector.
It was discovered that primitive decoders in openCryptoki produced integer
underflows when the encoded length was zero. An attacker could possibly use
this issue to trigger out-of-bounds reads. (CVE-2026-40253)
It was discovered that openCryptoki incorrectly handled symlinks. An
attacker in the tok...