> TODAY'S SUMMARY (98 articles)
Today's cybersecurity news highlights several critical threats and trends. Z.ai faced backlash for security flaws in its ZCode coding assistant, prompting the temporary disabling of certain features. In the UK, two individuals were arrested following the disruption of the "EvilTokens" AI chatbot, which facilitated cybercriminals in account compromise for a subscription fee. Researchers revealed that stolen passwords pose significant risks to U.S. water providers, exposing critical infrastructure to potential cyberattacks. Additionally, a wave of AI-driven threats is emerging, with reports indicating that AI is increasingly aiding cybercriminals while defenders struggle to keep pace. Lastly, vulnerabilities in Zyxel switches and recent attacks exploiting deepfake technology underscore the evolving landscape of cybersecurity risks.
|
// AI-powered summary generated at 16:01
Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSiteYou're not going to believe this, but turns out you can't always take criminals at their word. Actually, I'll walk that back a bit as it may not even be...
Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites. [...]
In August 2026, clothing retailer Carhartt was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data allegedly obtained from the company including 12.9M unique email addresses, names, phone numbers and physical addresses. The published corpus also conta...
Le gouvernement norvégien a annoncé la création d'un groupe d'experts chargé de proposer une réglementation plus stricte pour les technologies émergentes telles que les lunettes intelligentes.Cette décision, annoncée par la ministre de la numérisation, fait suite aux recommandations de l'Autorité no...
L'Agence pour la protection des données personnelles (AZOP), l'autorité de contrôle croate, a publié des orientations sur les mécanismes de certification prévus par le RGPD, clarifiant leur portée, leurs bénéfices et les procédures associées.La certification est une démarche volontaire permettant au...
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi
implementation in the Linux kernel did not properly handle aggregated
frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A
physically proximate attacker could use this issue to inject packets.
(CVE-2025-27558...
L'autorité espagnole de protection des données (AEPD) a déclaré une violation du RGPD par une municipalité sans prononcer d'amende, appliquant le régime spécifique prévu par le droit national pour les entités publiques.Faits et contexteL'autorité espagnole de protection des données (AEPD) a aujourd'...
La décision analyse la délicate conciliation entre la liberté d'expression à des fins journalistiques et le droit à la protection des données, en précisant que la publication d'un document nominatif n'est licite que si elle est strictement nécessaire à l'information du public, ce qui n'est pas le ca...
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- x86 architecture;
- InfiniBand drivers;
- Network drivers;
- Mellanox network drivers;
- File systems infras...
La diffusion non autorisée de données de santé d'une résidente dans un groupe de messagerie instantanée d'une copropriété a conduit l'autorité espagnole à sanctionner le syndicat, malgré la faible gravité perçue de l'incident et les mesures correctrices prises.Faits et contexteL'Agence Espagnole de...
L'Autorité suédoise de protection de la vie privée (IMY) a publié des orientations sur la diffusion en continu d'événements sportifs impliquant des enfants et des jeunes, afin de clarifier les règles applicables au regard du RGPD.Ces orientations rappellent que si la diffusion peut générer des reven...
A memecoin, a manifesto, and a week of daily leaks — but to researchers, it's a familiar extortion playbook with an unusually large audience.
The post The GTA VI leaks are breaking the internet. Security researchers have seen this before. appeared first on CyberScoop.
La Commission de protection des informations personnelles de Corée du Sud (PIPC) et le Ministère de l'Intérieur et de la Sécurité ont annoncé une augmentation du personnel dédié à la protection des données au sein du secteur public, suite à une décision du Conseil des ministres du 25 août 2026.Cette...
Interpol officials said it uncovered a crime-as-a-service network in Argentina run by 196 people that provided website domains and money laundering support to West African organized crime groups like Black Axe.
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Open vSwitch;
- SCTP protocol;
(CVE-2026-53224, CVE-2026-53246, CVE-2026-64531)
A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature. [...]
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Network drivers;
- Open vSwitch;
- SCTP protocol;
(CVE-2026-53224, CVE-2026-53246, CVE-2026-53247, CVE-2026-6453...
A security issue was discovered in the Linux kernel.
An attacker could possibly use this to compromise the system.
This update corrects flaws in the following subsystems:
- Open vSwitch;
Debian issued a security advisory for the Linux kernel addressing multiple vulnerabilities that can cause privilege escalation, denial of service, or information leaks, advising users to upgrade.
Adrian Junge discovered that FFmpeg incorrectly handled certain subtitle
data. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. (CVE-2026-70628)
Adrian Junge discovered that FFmpeg incorrectly handled certain video
files. An attacker could possibly u...