> TODAY'S SUMMARY (55 articles)
Today's cybersecurity landscape highlights significant threats and vulnerabilities that organizations must address. Forescout warns that inadequate network segmentation is enlarging attack surfaces, making businesses more vulnerable. A critical vulnerability in ZyXEL switches has been exploited by Chinese hackers, leading to the exfiltration of sensitive data from nearly 1,000 devices globally. Additionally, a newly discovered flaw in the Linux kernel allows unauthorized access to host memory from guest virtual machines, raising concerns for cloud environments. Meanwhile, a malicious NPM package, disguised as a legitimate software, has garnered millions of downloads, highlighting the persistent threat of supply chain attacks. Lastly, CISOs are urged to update incident response playbooks in light of emerging AI-driven threats, including sophisticated deepfakes and autonomous malware.
|
// AI-powered summary generated at 12:01
The order says any foreign-produced equipment deemed to pose national security risks canât be purchased or installed.
The post Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure appeared first on CyberScoop.
A critical vulnerability chain in the popular Avada theme for WordPress can be exploited by an unauthenticated attacker to execute arbitrary PHP code on the server. [...]
Immigration and Customs Enforcement (ICE) has conducted unlawful investigations into dozens of individuals who have documented ICE activities in their communities, social media users who criticized the government, and international students who attended a protest.
A favored tool in these speech chil...
The National Security Agency will welcome back to campus potentially hundreds of former members of the elite group known as Tailored Access Operations (TAO) to celebrate the divisionâs recent rebranding.
Learn how Chrome tracks your activity, what information it sends to Google, and which privacy settings can reduce tracking while you browse.
The full hacking suite, seized by authorities, allowed Chinese government funded attackers to intrude highly sensitive networks undetected for more than eight years.
The post Officials disrupt Chinese espionage operation that hit multiple federal agencies appeared first on CyberScoop.
If you found time for a bit of vacation this summer, you might be in catch-up mode. Hereâs a list to help: all the expert blog posts, new service capabilities, code samples, and workshops, in case you missed it, from July 2026. AWS Security Blog post This monthâs AWS Security Blog posts covered AI a...
The AI giant acknowledges that it could have done far more to prevent its AI agents from going rogue. But it still fails to explain why it didn't see this fiasco coming.
The company released a statement and filed documents with the Securities and Exchange Commission (SEC) saying a cybersecurity incident was discovered on Tuesday.
'These are test runs for a larger-scale attack'
The company says the breach stemmed from a systemic failure of alignment and security, and has taken measures to prevent agents from independently orchestrating complex cyberattacks.
The post OpenAI: Agent behavior that led to Hugging Face intrusion formed in May appeared first on CyberScoop.
A newly disclosed Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service (DoS) and root-level privilege escalation. [...]
The communications product company disclosed 22 total Wednesday, all but one of which was rated âcriticalâ at 9.0 or higher.
The post Three 10.0 security flaws fixed across Ubiquitiâs UniFi line appeared first on CyberScoop.
A multibillion-dollar settlement with attorneys general from nearly every U.S. state and territory will mean new privacy and safety protections in Meta products.
The company won't say if medical devices are affected or if any customer data was exfiltrated.
Two security issues were discovered in GNU Emacs, which could result in the execution of arbitrary code when opening a malformed file and denial of service when processing malformed PBM/PPM/PGM images. For the stable distribution (trixie), this problem has been fixed in version 1:30.1+1-6+deb13u1.
Chinaâs hacking campaign targeted NASA, the Federal Reserve, the US Senate, the Justice Department, and more, according to the DOJ.
Le Commissaire fédéral à la protection des données et à la liberté d'information (BfDI) a vu ses supports pédagogiques sur la protection des données recevoir un label de qualité de la part de la Fédération des organisations allemandes de consommateurs (vzbv).La série de leçons intitulée "Qu'est-ce q...
L'association None of Your Business (noyb) a adressĂ© une mise en demeure Ă l'agence d'Ă©valuation de crĂ©dit SCHUFA concernant la conservation et l'utilisation de donnĂ©es personnelles dans une "base de donnĂ©es fantĂŽme".Des enquĂȘtes mĂ©diatiques ont rĂ©vĂ©lĂ© que la SCHUFA conserve des donnĂ©es qui auraient...
Automated license plate readers (ALPRs) build a searchable map of everywhere a driver goes, fed into databases that police, ICE, and private vendors can query after the fact. Networked across a city, ALPRs are purpose-built to track everyone regardless of suspicion. ALPRs are not a surveillance tool...