> TODAY'S SUMMARY (98 articles)
Today's cybersecurity news highlights several critical threats and trends. Z.ai faced backlash for security flaws in its ZCode coding assistant, prompting the temporary disabling of certain features. In the UK, two individuals were arrested following the disruption of the "EvilTokens" AI chatbot, which facilitated cybercriminals in account compromise for a subscription fee. Researchers revealed that stolen passwords pose significant risks to U.S. water providers, exposing critical infrastructure to potential cyberattacks. Additionally, a wave of AI-driven threats is emerging, with reports indicating that AI is increasingly aiding cybercriminals while defenders struggle to keep pace. Lastly, vulnerabilities in Zyxel switches and recent attacks exploiting deepfake technology underscore the evolving landscape of cybersecurity risks.
|
// AI-powered summary generated at 16:01
AI agents can go to great lengths to complete the tasks their operators assign, and as a series of recent incidents showed, this can include exploiting third-party systems, manipulating people, and distributing malicious code. But AI agents are not people who can be fired, sue...
WhatsApp says 1 billion users now use passkeys, while stronger two-step verification and caller context add new layers of account protection. WhatsApp has reached a significant security milestone: more than one billion people now use passkeys to protect access to their accounts. At the same time, Me...
Scammers are posing as employers on Indeed to trick job seekers into installing fake Android interview apps that deliver malware.
La nouvelle version PowerToys 0.101 intègre l'outil Window Hopper : il permet de basculer facilement entre les fenêtres d'une même appli avec un raccourci.
Le post PowerToys 0.101 : un nouvel outil pour basculer facilement entre vos applications a été publié sur IT-Connect.
Un chercheur a analysé Paint et Photos : un GUID fourni par les serveurs de Microsoft est encodé dans les pixels des images IA générées en local.
Le post Paint et Photos inscrivent un identifiant unique de Microsoft dans vos images générées par IA a été publié sur IT-Connect.
An eight-month INTERPOL operation targeting West African organized crime groups has led to arrests of 58 people and the identification of 263 suspects.
"The operation, which brought together 22 countries from six continents, is a response to the escalating global threat posed by West African crimin...
Meta has added new security enhancements to WhatsApp, this time in the form of stronger two-step verification, additional information about calls from unknown numbers, and the ability to add multiple passkeys to the same account. New account security features (Source: Meta) “On WhatsApp, your conver...
Nutex Health has informed the SEC that it recently detected unauthorized access and data exfiltration.
The post Sensitive Information Exposed in Nutex Health Data Breach appeared first on SecurityWeek.
INTERPOL’s Operation Jackal IV made 58 arrests and exposed global networks laundering money from scams, fraud and sextortion. INTERPOL announced that Operation Jackal IV, running from November 2025 to June 2026, led to 58 arrests and identified 263 suspects tied to West African organized crime netwo...
An independent malware researcher has documented a previously unreported Windows backdoor, dubbed SLEEPWALKER, that stays inert in memory until a specifically crafted network packet reaches the machine and then runs commands written in a 23-instruction language of its own design.
The sample is an u...
Unraid 8 va abandonner Slackware pour une base Fedora signée Universal Blue, avec Docker Compose natif et un outil de sauvegarde intégré.
Le post Unraid 8 : l’OS pour NAS quitte Slackware pour une base Fedora, avec Docker Compose natif a été publié sur IT-Connect.
Microsoft déploie une nouveauté pour Remote Help : le helpdesk peut se connecter à un PC Windows sans utilisateur présent. Voici les prérequis et limites.
Le post Intune : Remote Help permet enfin la prise en main à distance de Windows sans surveillance a été publié sur IT-Connect.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea.
The vulnerability in question is CVE-2026-60004 (CVSS score: 9.8), a case of remote code execution that allows an at...
Plus de data n'est pas toujours synonyme de meilleure affaire : il est essentiel de comparer le réseau, les frais et les services pour faire le bon choix.
Le post Forfait mobile : pourquoi l’offre d’entrée de gamme est rarement la plus intéressante a été publié sur IT-Connect.
The Linux Foundation announced the contribution of TRACE (Trust, Runtime Attestation and Compliance Evidence), from OPAQUE. Collaboratively developed by AMD, Intel, Microsoft, OPAQUE and the Technology Innovation Institute (TII), TRACE creates a standard, open evidence layer that enables reliable go...
Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple's Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode.
SOCRadar Threat Research Unit (STR...
In this Help Net Security interview, Erika Dean, CISO at Tricentis, talks about keeping production data out of test environments and why she thinks the alternatives are good enough now. She explains how her team caught a prompt injection gap in red-teaming and held a release for a week until it was...
CVE-2026-60004 is a remote code execution vulnerability patched by Gitea developers in late July with the release of version 1.27.1.
The post CISA Warns of Exploited Gitea Vulnerability appeared first on SecurityWeek.
Risk managers, auditors and senior executives at 316 companies spent April and May ranking 20 threats they have not yet felt. AI discovery of cyber vulnerabilities came back first, according to Gartner. Three months earlier the same quarterly survey put information integrity risk at the top and left...
Presented here is a curated selection of noteworthy open-source cybersecurity solutions that have drawn recognition for their ability to enhance security postures across diverse settings. SkillSpector: NVIDIA’s open-source security scanner for AI agent skills SkillSpector is an open-source scanner f...