> TODAY'S SUMMARY (98 articles)
Today's cybersecurity news highlights several critical threats and trends. Z.ai faced backlash for security flaws in its ZCode coding assistant, prompting the temporary disabling of certain features. In the UK, two individuals were arrested following the disruption of the "EvilTokens" AI chatbot, which facilitated cybercriminals in account compromise for a subscription fee. Researchers revealed that stolen passwords pose significant risks to U.S. water providers, exposing critical infrastructure to potential cyberattacks. Additionally, a wave of AI-driven threats is emerging, with reports indicating that AI is increasingly aiding cybercriminals while defenders struggle to keep pace. Lastly, vulnerabilities in Zyxel switches and recent attacks exploiting deepfake technology underscore the evolving landscape of cybersecurity risks.
|
// AI-powered summary generated at 16:01
It was discovered that Perl incorrectly handled short source addresses
in the Socket module. An attacker could possibly use this issue to
trigger an out-of-bounds heap read, resulting in information disclosure.
(CVE-2026-12087)
It was discovered that Perl incorrectly handled regular expressions
con...
Apple says it will no longer ditch using its icloud.com domain for hiding people's email addresses.
Healthcare and services provider Nutex is investigating a data breach incident where an unauthorized third party exfiltrated information from company servers. [...]
Can you trust a website just because your browser isn’t showing any warnings? Here’s how to recognize gray-area websites, check whether a page is safe, and protect your data and devices.
ZeroTokens gives phishing operators live control of victim sessions targeting 53 financial brands
The multi-country sting targeted Black Axe financial networks, seizing millions in assets and uncovering Crime-as-a-Service infrastructure across four continents.
The post Interpol targets Black Axe’s illicit financial web in latest international sting appeared first on CyberScoop.
The company, previously known as ActiveFence, has raised a total of $280 million from investors.
The post Alice Raises $140M to Expand AI Model Defenses and Enterprise Guardrails appeared first on SecurityWeek.
Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself.
The findings were shared with The Hacker News ahead of public...
Attackers are increasingly targeting the processes used to establish or recover identity rather than attacking the login itself. Specops explains how stronger identity verification can help organizations prevent fake workers and social engineering attacks from gaining legitimate access. [...]
Police across 22 countries arrested 58 people and identified 263 suspects during an eight-month INTERPOL operation targeting West African organized crime groups. Suspects detained in an operation targeting West African crime groups (Source: INTERPOL) Operation Jackal IV ran from November 2025 to Jun...
Ukraine will give Britain access to a vast trove of battlefield data collected during the war with Russia, allowing U.K. companies and researchers to use it to train and test artificial intelligence systems.
Microsoft updated its Windows PowerToys toolset with a new utility dubbed "Window Hopper" that lets users switch between an app's windows more quickly. [...]
CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin.
The post WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities appeared first on SecurityWeek.
Citrix announced Citrix UniconOS dual boot, a new endpoint resiliency capability designed to help organizations recover access to work in minutes — without spare hardware, central reimaging or prolonged business downtime. Available now as part of Citrix UniconOS Release 7 2607, dual boot turns every...
Meta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help users with both iOS and Android devices sign into their accounts using the phishing-resistant method.
The tech giant said more than 1 billion people use a passk...
Fideo Intelligence introduced Fideo Lens, an investigative intelligence platform that helps fraud and financial crime teams discover hidden relationships among identities, accounts, devices and behaviors. Starting with a single identity signal, investigators can use Fideo Lens to visualize and conne...
Summary Chainalysis recently convened Operation Lighthouse: a multi-day sprint by law enforcement and the private sector to disrupt crypto-enabled CSAM…
The post Operation Lighthouse: Chainalysis’s CSAM-Disruption Sprint IDs Suspects in 125 Countries appeared first on Chainalysis.
There usually is a crucial time lapse from when a vulnerability is newly disclosed to when security scanners are finally updated to scan for it. Nucleus Security says it wants to close that gap.
The cybersecurity outfit focused on unified exposure management is expanding it...
WhatsApp’s two-step verification previously relied on a six-digit PIN, but now users can choose a longer, alphanumeric password with special characters.
WhatsApp has started rolling out several new account security features, including support for multiple passkeys and stronger two-step verification. [...]