> TODAY'S SUMMARY (98 articles)
Today's cybersecurity news highlights several critical threats and trends. Z.ai faced backlash for security flaws in its ZCode coding assistant, prompting the temporary disabling of certain features. In the UK, two individuals were arrested following the disruption of the "EvilTokens" AI chatbot, which facilitated cybercriminals in account compromise for a subscription fee. Researchers revealed that stolen passwords pose significant risks to U.S. water providers, exposing critical infrastructure to potential cyberattacks. Additionally, a wave of AI-driven threats is emerging, with reports indicating that AI is increasingly aiding cybercriminals while defenders struggle to keep pace. Lastly, vulnerabilities in Zyxel switches and recent attacks exploiting deepfake technology underscore the evolving landscape of cybersecurity risks.
|
// AI-powered summary generated at 16:01
Ubuntu addressed multiple vulnerabilities in OpenJDK 17 across various LTS versions, enabling potential denial of service and data security risks, necessitating package updates for user protection.
As part of Patch the Planet, we received preview access to GPT 5.6-Cyber with a simple task: evaluate its cyber capabilities. Recent events inspired me to give it a challenge to work through: escape the VM I’d normally use for sandboxing. The target was a QEMU/KVM VM on my Linux dev machine (Debian...
Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop.
The post The MFA Identity Trap: When Authentication Creates a False Sense of Security appeared first on SecurityWeek.
Attackers have begun exploiting CVE-2026-60004, a critical code injection vulnerability in the Gitea Git platform, CISA confirmed on Tuesday by adding the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. The KEV entry does not contain or point to details about the attacks, but acc...
Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution Microsoft disclosed a maximum-severity flaw in its Entra ID identity service, tracked as CVE-2026-69836 with a CVSS score of 10.0, tracing back to unsafe deserialization of untrusted data that could let an attacker exe...
RightCrowd announced RightCrowd Pass, a credentialing solution that issues and manages mobile, physical and biometric access credentials from a single platform. Many large enterprises and universities rely on badge programs-built years ago. As organizations add mobile and biometric credentials, what...
Aikido Security has published research that recreates the Australian gym-booking incident in a synthetic environment, finding that Claude Opus 4.6, running on the OpenClaw agent harness, exploited a client-side-only booking restriction in 9 of 10 runs.
The original incident was first reported by AB...
Scammers posing as HR staff at well-known companies are running interview scheduling scams that end with a stolen corporate password, according to Zimperium. Attackers are using a technique called browser-in-the-browser, or BitB, which CTM360 documented in earlier research on recruitment phishing. T...
Selecting a model for your security operations center (SOC) and digital forensics and incident response (DFIR) tasks is important, but selecting the best one is more involved than you might think. Here's how to choose.
Most of the flaws were discovered by Google using AI, but researchers are still discovering high-value Chrome vulnerabilities.
The post Chrome 152 Patches Over 300 Vulnerabilities appeared first on SecurityWeek.
OpenAI on Tuesday said it banned a cluster of Russian ChatGPT accounts that used VPNs to bypass access restrictions and run an influence operation, which relied on its artificial intelligence (AI) tool to generate social media posts and comments that were shared on Substack, Telegram, X, Facebook an...
Oracle Linux 8 updates include Python 3.12.14 packages to address CVE-2026-11940, with various RPMs uploaded for x86_64 and aarch64 architectures.
Oracle Linux 8 has released updates for gstreamer1-plugins-good addressing multiple CVEs, including heap buffer overflows and use-after-free vulnerabilities, enhancing system security.
This new open standard offers hardware-attested runtime and compliance evidence for AI agents
Oracle released updated RPMs for Oracle Linux 8 addressing a denial of service vulnerability in the python3-pyasn1 package with CVE-2026-59886. Updates are available for x86_64 and aarch64.
Oracle Linux 7 has received security updates for 389-ds-base packages addressing CVE-2026-11610 and CVE-2026-11774, improving system security and functionality.
A coordinated DDoS campaign has caused disruption among Norwegian government services
Oracle Linux 7 has received security updates for multiple X11 server components, addressing several CVEs, including CVE-2026-55999, with respective RPMS and source packages now available.
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Gitea flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA)Â added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE-2026-60004 (CVSS sco...
88 ID-verification breaches exposed billions of records, highlighting the growing risks of collecting sensitive identity and biometric data. A new report from Mysterium VPN compiles 88 documented incidents since 2011 where data collected specifically to verify someone’s identity or age got breached,...