> TODAY'S SUMMARY (55 articles)
Today's cybersecurity landscape highlights significant threats and vulnerabilities that organizations must address. Forescout warns that inadequate network segmentation is enlarging attack surfaces, making businesses more vulnerable. A critical vulnerability in ZyXEL switches has been exploited by Chinese hackers, leading to the exfiltration of sensitive data from nearly 1,000 devices globally. Additionally, a newly discovered flaw in the Linux kernel allows unauthorized access to host memory from guest virtual machines, raising concerns for cloud environments. Meanwhile, a malicious NPM package, disguised as a legitimate software, has garnered millions of downloads, highlighting the persistent threat of supply chain attacks. Lastly, CISOs are urged to update incident response playbooks in light of emerging AI-driven threats, including sophisticated deepfakes and autonomous malware.
|
// AI-powered summary generated at 12:01
CISA has ordered U.S. government agencies to patch their Citrix NetScaler appliances against an actively exploited remote code execution vulnerability by Saturday. [...]
OpenAI reveals that unauthorized message boards were at the heart of the recent Hugging Face breach
The operation focused on a group named QTFY, which offers hacking services to the Chinese government and others.
The post US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks appeared first on SecurityWeek.
It’s getting cheaper and easier for cybercriminals to research potential victims. Here’s what’s still in your control.
Multiple vulnerabilities have been discocvered in Wireshark, a network protocol analyzer which could result in denial of service or the execution of arbitrary code. For the stable distribution (trixie), these problems have been fixed in version 4.4.18-0+deb13u1.
A cyberattack that forced a small British electricity generator offline for four days caused no power outage, threatened no part of the national grid, and may not even have been carried out by the Iran-linked hackers initially blamed.
But the incident illustrates a conseque...
Meta will pay up to $18B and cap teen Facebook and Instagram use at two hours daily after nearly all US states sued over child safety. Meta will pay up to $18 billion over the next decade and impose real usage limits on teenagers using Facebook and Instagram, settling claims that the company deliber...
ATF, the regulatory agency that enforces federal laws governing firearms and explosives in the United States, has confirmed that one of its systems was compromised after breach claims made by the Qilin ransomware gang. [...]
Academic researchers have disclosed a Rowhammer attack impacting NVIDIA workstation GPUs with GDDR6 memory that defeats error correction codes (ECC), the mitigation NVIDIA recommends against GPU Rowhammer, and enables denial-of-service (DoS) and privilege escalation to a root shell.
Dubbed GPUThor,...
The pro-Russian hacker group Server Killers claimed responsibility for the attack.
The post Pro-Russian Hackers Claim Responsibility for Major Cyberattack on Norway’s Public Digital Services appeared first on SecurityWeek.
CISA urges water utilities to find and secure internet-exposed PLCs after July attacks showed how easily exposed industrial systems can be compromised. Over 100 internet-exposed systems in the US water and wastewater sector got hit by cyberattacks in July 2026, and CISA’s response wasn’t just an inc...
Several vulnerabilities were discovered in GIMP, the GNU Image Manipulation Program, which could result in denial of service or potentially the execution of arbitrary code if malformed PSP, TIFF, DDS, PSD, SGI, FLI, FITS or ICNS files are opened. For the stable distribution (trixie), these problems...
The Justice Department and FBI have seized domains tied to two hacking tools built and run by a Chinese state-sponsored group, cutting off access to malware that had been used against U.S. government agencies for years. The tools, known as QScan and QTRouter, were developed by a group called QTFY, w...
Microsoft teste dans Windows 11 une gestion des autorisations caméra, microphone et localisation application par application y compris pour les logiciels Win32.
Le post Windows 11 : Microsoft teste des permissions caméra, micro et localisation par application a été publié sur IT-Connect.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation.
The vuln...
Microsoft va retirer 28 propriétés CSS supplémentaires de la personnalisation des pages de connexion Entra ID le 26 octobre 2026, soit 49 au total.
Le post Votre page de connexion Microsoft 365 pourrait changer d’allure le 26 octobre 2026 a été publié sur IT-Connect.
Multiple vulnerabilities were discovered in xrdp, a Remote Desktop Protocol (RDP) server, which may result in denial of service, information disclosure, privilege escalation or the execution of arbitrary code. Several of these issues are exploitable by an unauthenticated remote attacker.
Plus de 270 serveurs de messagerie Zimbra ont été compromis via la faille de sécurité CVE-2026-73570. Voici comment se protéger de cette menace.
Le post Zimbra : plus de 270 serveurs de messagerie compromis grâce à la faille CVE-2026-73570 a été publié sur IT-Connect.
Abnormal AI announced an expansion of its email security platform with three new capabilities: Control Center, Email DLP Rules, and AI Phishing Coach upgrades. Together, the launch extends Abnormal’s behavioral AI across all three surfaces of email risk: what comes into the inbox, what leaves the or...
Camera systems often outlive the companies that install them. In this Help Net Security interview, Rob Janssens, EMEA Cyber Security Director at Hikvision Europe, discusses what happens when the integrator is gone, the documentation is lost, and nobody holds the admin credentials. He explains why pr...