> TODAY'S SUMMARY (98 articles)
Today's cybersecurity news highlights several critical threats and trends. Z.ai faced backlash for security flaws in its ZCode coding assistant, prompting the temporary disabling of certain features. In the UK, two individuals were arrested following the disruption of the "EvilTokens" AI chatbot, which facilitated cybercriminals in account compromise for a subscription fee. Researchers revealed that stolen passwords pose significant risks to U.S. water providers, exposing critical infrastructure to potential cyberattacks. Additionally, a wave of AI-driven threats is emerging, with reports indicating that AI is increasingly aiding cybercriminals while defenders struggle to keep pace. Lastly, vulnerabilities in Zyxel switches and recent attacks exploiting deepfake technology underscore the evolving landscape of cybersecurity risks.
|
// AI-powered summary generated at 16:01
Joshua Culver, aka “Maverick Young,” is accused of imitating the head of the NSA’s Tailored Access Operations unit during a time it wasn’t called that.
The post Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice appeared first on CyberScoop.
Proton released a new video featuring CEO Andy Yen and the team explaining why the company exists, and why privacy has to be the default.
The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an "unprecedented, whole-of-government, economic campaign" against the nation and its enablers.
"We are launching an economic onslaught against Iran's financial connections around the...
USN-8678-1 fixed vulnerabilities in OpenSSL. This update provides the
corresponding fix for OpenSSL and OpenSSL 1.0 on Ubuntu 14.04 LTS,
Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS.
In addition, this update also fixes the following issues that were
not previously addressed in those releases:
It was dis...
A year ago we wrote that we'd put AI to work across the whole company, turning everyone on the team into a capable AI operator so our defenders could stay ahead of the threat actors attacking the sites we protect. In April we showed where it was heading: in the space of a few months, AI-assisted rep...
Norway ’s shared government infrastructure suffered a third DDoS attack, disrupting digital services but showing no signs of data compromise. Norway ‘s shared digital government infrastructure has been hit by another distributed denial-of-service (DDoS) attack that disrupted services used by citizen...
It was discovered that OpenSSL incorrectly handled the QUIC server incoming
channel queue. A remote attacker could possibly use this issue to cause
OpenSSL to use excessive resources, leading to a denial of service. This
issue only affected Ubuntu 26.04 LTS. (CVE-2026-14456)
It was discovered that...
Agency red-teamers got initial access to both organizations they tested, but one quickly isolated and shut down the attempts from going further.
The post Water sector passes, government sector fails attempts to spot and halt simulated CISA attack appeared first on CyberScoop.
Uber faces an €825M GDPR fine for automatically suspending drivers without human review, highlighting the risks of AI decisions affecting workers. The Dutch Data Protection Authority handed Uber its largest privacy fine yet, and this one isn’t about data transfers or cookie consent. The regulator im...
Two CVSS 9.8 miniOrange SAML WordPress plugin auth bypasses were exploited while paid editions never appeared in any vulnerability database. Manual patch required. Two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On WordPress plugin, both rated CVSS 9.8, are...
USN-8670-1 fixed a vulnerability in curl. This update provides the
corresponding update for Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu
22.04 LTS.
Original advisory details:
Joshua Rogers discovered that curl incorrectly handled reusing
connections when client certificate settings changed. Th...
TRACE was developed by AMD, Intel, Microsoft, OPAQUE, and TII and contributed to the Linux Foundation.
The post Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation appeared first on SecurityWeek.
Attackers now ready to exploit how things work, rather than just break them, says Oracle support expert
Organizations need protection that operates in the gap between discovery and remediation.
The post The patch window is collapsing: Why security needs a new control plane appeared first on Microsoft Security Blog.
A large distributed denial-of-service (DDoS) attack has disrupted Norway's shared government digital infrastructure since Monday, affecting services used by the public sector. [...]
Grand Theft Auto fans, eager for news about one of the most anticipated video games of all time, appear especially vulnerable to this new cyberattack.
Discover how early-stage AI yields rapid SOC returns, driving platform consolidation and reducing analyst burnout in this blog post.
On August 11th, 2026, we received a submission for an Unauthenticated Account Takeover vulnerability in TranslatePress, a WordPress plugin with more than 400,000 active installations. This vulnerability makes it possible for unauthenticated attackers to obtain an administrator's password reset link,...
It is pretty obvious that hostnames can replace IP addresses. Pretty much any software accepting an IP address will also accept a hostname as an argument. Last week, I wrote about scans for the cloud metadata service listening at 169.254.169.254. These scans attempted to exploit Server Side Request...
Installez GoAccess pour analyser les logs de vos serveurs web Nginx, Apache ou Traefik : tableau de bord terminal, rapport HTML temps réel et compatible Docker.
Le post GoAccess : analyser les logs de votre serveur web en temps réel a été publié sur IT-Connect.