> TODAY'S SUMMARY (18 articles)
Today's cybersecurity landscape highlights several critical threats and vulnerabilities. A new WordPress vulnerability, Click2Shell, allows remote code execution via a single click, emphasizing the need for immediate updates to version 7.1.1. Additionally, a fake job interview campaign linked to North Korea has infected over 30,000 devices, showcasing the ongoing risks of social engineering attacks. The TryCloudflare service misconfiguration has led to unintended Google indexing, exposing sensitive user services. On the infrastructure side, flaws in Zyxel switches and Veeam software are actively exploited, prompting CISA to add them to its Known Exploited Vulnerabilities catalog. Lastly, security researchers have identified potential backdoor access through Meta's AI assistant, underlining the importance of scrutinizing AI integrations for security flaws.
|
// AI-powered summary generated at 08:01
A trusted name on a trusted platform does not guarantee a trustworthy listing. It could still lead to a tech support scammer.
The two men face 14 charges combined. Private researchers traced one suspect through leaked passwords and a decade-old gaming profile.
The post Two alleged TeamPCP members arrested and charged after months of software supply-chain chaos appeared first on CyberScoop.
The arrests come after a wave of cyberattacks earlier this year targeting tech companies that rely on high-profile and widely used open source software.
The White House’s new executive order 14420 widens scrutiny of industrial control systems over cyber sabotage concerns.
The post Trump Order Aims to Block Foreign Backdoors in US Power Grid Gear appeared first on SecurityWeek.
Australian police charged two men linked to TeamPCP over malware hidden in open-source code that stole 500,000+ credentials from 1,000+ organizations. Australian police have charged two men from Western Australia over a global cybercrime operation that allegedly hid malicious code in open-source sof...
A recap of all the incidents involving LLMs made by Anthropic, Meta, and OpenAI, which went rogue and attacked real companies and individuals on the internet.
Tous les services Proton sont tombés dans la nuit du 27 août 2026 après une panne totale du système de refroidissement à Francfort. Voici ce que l'on sait.
Le post Panne mondiale chez Proton : le datacenter de Francfort a eu un coup de chaud a été publié sur IT-Connect.
Updated CWE value. This is an informational change only.
Google is introducing new network security protections in Android 17 to strengthen connection privacy, address cellular vulnerabilities, and protect the privacy of users' home networks. [...]
Threat research gives security teams insight into how attackers operate, while MDR turns that intelligence into faster detection and response. ESET explains how combining threat intelligence, continuous monitoring, and human expertise can help SMBs strengthen their defenses. [...]
Two men from Western Australia have been charged after police allege they were part of TeamPCP, a cybercrime group that planted malicious code in open-source software, then used it to break into organizations around the world. The Australian Federal Police (AFP), working with the FBI and Western Aus...
Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers.
The security flaw, which does not have a CVE i...
Australian authorities have arrested and charged two young men accused of belonging to TeamPCP, a hacking group linked to a string of far-reaching developer supply chain attacks. [...]
A spokesperson told The Yorkshire Post that roughly 8.7 million people were impacted, although they did not provide a date range. They added that in the “vast majority” of cases, the only information accessed was an email address.
AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes A phishing-as-a-service platform called AnonyMousKIT automates the theft of unlock codes for stolen iPhones by impersonating Apple support through email, SMS, WhatsApp, and AI-powered voice calls; researchers tracked the operation to...
Two men in Australia were charged Wednesday over their alleged membership in TeamPCP, the cybercrime group blamed for one of the most damaging hacking campaigns of the past year.
Customer data linked to bookings and airport Wi-Fi registrations at Manchester, Stansted and East Midlands airports has been accessed by an unauthorized third party
UK’s largest airport operator reportedly believes 8.7 million customers affected
Australian and US authorities collaborated to identify and charge the alleged cybercriminals, who face many years in prison.
The post Australia Arrests 2 Alleged TeamPCP Hackers appeared first on SecurityWeek.
Built for mobile users, this tech support scam uses a fake Apple Pay alert and browser tricks to pressure victims into calling a scam number.