> TODAY'S SUMMARY (122 articles)
Today's cybersecurity landscape highlights several critical threats and trends. The Canadian regulator is investigating IDScan for potential data privacy violations, while the ransomware PAYLOAD has demonstrated a new tactic, paralyzing an organization without file encryption. Volexity reported a China-aligned threat group exploiting vulnerabilities in Chrome and Microsoft software. The hacking group ShinyHunters claims to have breached the FBI, raising significant counterintelligence concerns. Additionally, ClosedQuorum malware is leveraging AI for attack decisions, indicating a trend towards more sophisticated, autonomous threats. CISA has urged federal agencies to patch a critical Zyxel flaw actively exploited by attackers. Meanwhile, the rise of AI in cybercrime continues, with deepfakes and AI-driven bots posing increasing risks to organizations.
|
// AI-powered summary generated at 20:01
Checker max analyse Solana par lots de 1 000 adresses, une capacité sensible pour le triage de portefeuilles proposé sur un forum de pirates.
Other noteworthy stories that might have slipped under the radar: Threema DDoS attack, Evooo1Bot Linux botnet, Crypto4A secures top-tier NIST certification.
The post In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug appeared first on SecurityWeek.
La faille CVE-2026-18963 permet de réinitialiser le mot de passe de n'importe quel compte Keycloak sans authentification. Un patch est disponible.
Le post Keycloak : cette faille critique permet de pirater un compte via la fonction de mot de passe oublié a été publié sur IT-Connect.
Sen. Ron Wyden and Rep. Greg Casar want a GAO probe on the government’s use of spyware and other sophisticated hacking tools and authorities.
The post Lawmakers seek watchdog review of federal hacking of Americans appeared first on CyberScoop.
Oracle has released multiple updated RPM packages for Oracle Linux 10, addressing several CVEs and including various versions of Java 21 OpenJDK with enhancements and fixes.
Oracle Linux has released updated Java packages for version 10 to address several CVEs, including CVE-2026-60589 and others, with a detailed list of RPMs provided.
The Hospital for Sick Children — which was hit in a ransomware incident in 2022 that disabled some of its systems — released a statement on Thursday warning of a data theft incident they believe is tied to a third-party software application.
Oracle Linux 10 updates include versions of ansible-core and ansible-test that address CVE-2026-11332, which involved potential arbitrary git configuration injection during role installation.
Oracle Linux has released several kernel updates addressing multiple CVEs, including security enhancements and fixes for various stability and performance issues in its 10th version.
Malicious updates turned routine builds into a delivery system for infostealer malware
Oracle Linux released updates for version 10, addressing CVE-2026-72693 with enhancements to the openvt process matching. New RPMs are available for x86_64 and aarch64 architectures.
Microsoft says ongoing issues causing games to crash or fail to launch after installing the August 2026 Windows updates may be caused by peripherals with RGB lighting. [...]
DYSPHOR1A émerge comme un nouveau groupe ransomware maître chanteur, avec ventes, fuites et retraits payants de données.
Researchers say the new ‘Cryptographic Context Injection’ technique conceals malicious instructions until they are decrypted inside a trusted execution environment.
The post Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini appeared first on SecurityWeek.
Kaspersky experts have discovered a trojan that infects car head units and makes them part of a botnet. Here’s how the infection works.
Researchers say iAuthFlow V2 can register an attacker-controlled passkey, enabling persistent access even after passwords are changed and active sessions revoked.
The post New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets appeared first on SecurityWeek.
Découvrez Endstate, un outil open source qui sauvegarde les applications et les réglages d'un PC Windows dans un fichier, puis les restaure sur un nouveau PC.
Le post Endstate : sauvegarder et restaurer ses applications Windows (et leurs configs) sur un nouveau PC a été publié sur IT-Connect.
Business email compromise attacks don't rely on links or malware. Learn how they work and the controls that stop them.
Scientific research showed that the expiration date on some Visa credit cards can be manipulated in so-called Zombie Card attacks.
Using the same email, phone number, payment method, and other identifiers makes it easier for data brokers and attackers to profile your activity. Anonyome Labs explains how separate digital personas can reduce correlation and limit the impact of breaches, spam, and identity theft. [...]