[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (98 articles)

|

// AI-powered summary generated at 16:01

> CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published the results of two red team assessments it conducted simultaneously against two critical infrastructure organizations, using what it described as similar tradecraft while recording sharply different defensive outcomes. B...
> Four in Five AI Tools Run with No IT Oversight, New Research Finds
Reco report reveals growing shadow AI problem and surge in vulnerability disclosures
> Edge Infrastructure Under Siege: What Two Independent Datasets Reveal About Who’s Exploiting Your Perimeter
A new joint study by Tenable and SentinelOne reveals how state and criminal groups converge on the same vulnerable edge infrastructure.
> AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes
A phishing-as-a-service (PhaaS) platform called AnonyMousKIT is automating the theft of Apple ID credentials needed to remove Activation Lock from stolen iPhones, SOCRadar found. “By leveraging a critical flaw – the use of bare relative paths – the investigation unraveled a reseller supply chain of...
> Adobe and Nvidia Patch Dozens of Vulnerabilities
Adobe and Nvidia each published several advisories, including ones that address critical vulnerabilities in their products. The post Adobe and Nvidia Patch Dozens of Vulnerabilities appeared first on SecurityWeek.
> How to scan a document on iPhone
Learn how to scan a document on iPhone using Notes, Files, Preview, and Proton Drive. Only one of these protects your privacy by default.
> Popular school apps may be sharing student data with advertisers
A Utah investigation found educational apps collecting unauthorized student data and sharing information with third parties and advertisers.
> Microsoft tests new privacy controls for Windows 11 desktop apps
Microsoft has begun testing new privacy controls that will let Windows 11 users choose which desktop applications can access their camera, microphone, and precise location. [...]
> Spyware for Babies
The New York Times has a long article (alt link) on surveillance systems aimed at babies. They are increasingly using AI. Nanit and its rivals want to own 24/7 health tracking for the sub-four-foot set. And their already astonishing levels of baby data collection are just the beginning. Nanit recent...
> Average Cyber Insurance Losses Increase Despite Fewer Claims
Chubb reported that growing privacy litigation has contributed to surging cyber claim costs in the US
> Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code
The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it. The flaws, tracked as CVE-2026-19913 and CVE-2026-19912, both stem f...
> Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine
The SOC we've always known was built around a model that guarantees most of the alert queue will never receive analyst review. There's never time. In a traditional SOC, the typical progression follows a well-known pattern: an alert arrives; a detection engine assigns a severity score. The issue then...
> NemoClaw’s AI can be poisoned through a browser tab
A vulnerability affecting Nvidia’s NemoClaw could let an attacker gain control of the local Ollama model server through a single malicious website visit on the victim’s machine. According to a Cyera research, the flaw could give attackers unauthenticated access to the serve...
> CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks
The agency has released guidance on reducing internet exposure in the wake of the recent Iran-linked hacker attacks. The post CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks appeared first on SecurityWeek.
> Microsoft warns patch window is collapsing, urges shift to network-level containment
Microsoft is warning that the window for patching vulnerabilities is rapidly shrinking, as attackers move from disclosure to exploitation faster than enterprises can safely deploy fixes, and is urging organizations to adopt network-level controls to limit exposure during that...
> Hackers now exploit critical Gitea flaw in code injection attacks
Attackers are now exploiting a critical-severity vulnerability in the Gitea self-hosted Git service, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). [...]
> Critical Denial of Service Vulnerabilities in Ubuntu OpenJDK 8 USN-8673-1
Ubuntu has issued a security notice for OpenJDK 8 vulnerabilities affecting multiple LTS versions, urging users to update due to risks of unauthorized data access and denial of service.
> Ubuntu OpenJDK 25 Important User Authorization Issues USN-8681-1
Ubuntu announced security updates for OpenJDK 25, addressing multiple vulnerabilities that allow potential data manipulation and denial of service. Users should update their systems accordingly.
> VMs won't contain cyber-capable agents
As part of Patch the Planet, we received preview access to GPT 5.6-Cyber with a simple task: evaluate its cyber capabilities. Recent events inspired me to give it a challenge to work through: escape the VM I’d normally use for sandboxing. The target was a QEMU/KVM VM on my Linux dev machine (Debian...
> Ubuntu OpenJDK 11 Important Denial of Service Vulnerabilities USN-8674-1
Ubuntu has released security updates for OpenJDK 11 addressing multiple vulnerabilities that allow potential remote attacks, requiring users to update their systems to ensure safety.