> TODAY'S SUMMARY (98 articles)
Today's cybersecurity news highlights several critical threats and trends. Z.ai faced backlash for security flaws in its ZCode coding assistant, prompting the temporary disabling of certain features. In the UK, two individuals were arrested following the disruption of the "EvilTokens" AI chatbot, which facilitated cybercriminals in account compromise for a subscription fee. Researchers revealed that stolen passwords pose significant risks to U.S. water providers, exposing critical infrastructure to potential cyberattacks. Additionally, a wave of AI-driven threats is emerging, with reports indicating that AI is increasingly aiding cybercriminals while defenders struggle to keep pace. Lastly, vulnerabilities in Zyxel switches and recent attacks exploiting deepfake technology underscore the evolving landscape of cybersecurity risks.
|
// AI-powered summary generated at 16:01
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published the results of two red team assessments it conducted simultaneously against two critical infrastructure organizations, using what it described as similar tradecraft while recording sharply different defensive outcomes.
B...
Reco report reveals growing shadow AI problem and surge in vulnerability disclosures
A new joint study by Tenable and SentinelOne reveals how state and criminal groups converge on the same vulnerable edge infrastructure.
A phishing-as-a-service (PhaaS) platform called AnonyMousKIT is automating the theft of Apple ID credentials needed to remove Activation Lock from stolen iPhones, SOCRadar found. “By leveraging a critical flaw – the use of bare relative paths – the investigation unraveled a reseller supply chain of...
Adobe and Nvidia each published several advisories, including ones that address critical vulnerabilities in their products.
The post Adobe and Nvidia Patch Dozens of Vulnerabilities appeared first on SecurityWeek.
Learn how to scan a document on iPhone using Notes, Files, Preview, and Proton Drive. Only one of these protects your privacy by default.
A Utah investigation found educational apps collecting unauthorized student data and sharing information with third parties and advertisers.
Microsoft has begun testing new privacy controls that will let Windows 11 users choose which desktop applications can access their camera, microphone, and precise location. [...]
The New York Times has a long article (alt link) on surveillance systems aimed at babies. They are increasingly using AI.
Nanit and its rivals want to own 24/7 health tracking for the sub-four-foot set. And their already astonishing levels of baby data collection are just the beginning. Nanit recent...
Chubb reported that growing privacy litigation has contributed to surging cyber claim costs in the US
The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it.
The flaws, tracked as CVE-2026-19913 and CVE-2026-19912, both stem f...
The SOC we've always known was built around a model that guarantees most of the alert queue will never receive analyst review. There's never time. In a traditional SOC, the typical progression follows a well-known pattern: an alert arrives; a detection engine assigns a severity score. The issue then...
A vulnerability affecting Nvidia’s NemoClaw could let an attacker gain control of the local Ollama model server through a single malicious website visit on the victim’s machine.
According to a Cyera research, the flaw could give attackers unauthenticated access to the serve...
The agency has released guidance on reducing internet exposure in the wake of the recent Iran-linked hacker attacks.
The post CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks appeared first on SecurityWeek.
Microsoft is warning that the window for patching vulnerabilities is rapidly shrinking, as attackers move from disclosure to exploitation faster than enterprises can safely deploy fixes, and is urging organizations to adopt network-level controls to limit exposure during that...
Attackers are now exploiting a critical-severity vulnerability in the Gitea self-hosted Git service, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). [...]
Ubuntu has issued a security notice for OpenJDK 8 vulnerabilities affecting multiple LTS versions, urging users to update due to risks of unauthorized data access and denial of service.
Ubuntu announced security updates for OpenJDK 25, addressing multiple vulnerabilities that allow potential data manipulation and denial of service. Users should update their systems accordingly.
As part of Patch the Planet, we received preview access to GPT 5.6-Cyber with a simple task: evaluate its cyber capabilities. Recent events inspired me to give it a challenge to work through: escape the VM I’d normally use for sandboxing. The target was a QEMU/KVM VM on my Linux dev machine (Debian...
Ubuntu has released security updates for OpenJDK 11 addressing multiple vulnerabilities that allow potential remote attacks, requiring users to update their systems to ensure safety.