[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (14 articles)

|

// AI-powered summary generated at 16:00

> Cline: Vulnerable To Data Exfiltration And How To Protect Your Data
Cline is quite a popular AI coding agent, according to the product website it has 2+ million downloads and over 47k stars on GitHub. Unfortunately, Cline is vulnerable to data exfiltration through the rendering of markdown images from untrusted domains in the chat box. This allows an adversary to ex...
> ShadowSilk Campaign Targets Central Asian Governments
A series of cyber-attacks against government organizations in Central Asia and Asia- Pacific has been linked to the ShadowSilk threat cluster
> Implement EIP-7730 today
EIP-7730 enables hardware wallets to decode transactions into human-readable formats, eliminating blind signing vulnerabilities with minimal implementation effort for dApp developers.
> Citrix Patches Three NetScaler Zero Days as One Sees Active Exploitation
Citrix customers are urged to patch their vulnerable NetScaler appliances, but “patching alone won’t cut it,” experts said
> ENISA to Coordinate €36m EU-Wide Incident Response Scheme
EU security agency ENISA is being handed €36m to operate the EU Cybersecurity Reserve
> "The entire internet is broken": ethical hacking expert John Hammond meets James Kettle
In a brand-new collaboration between ethical hacking and AppSec expert John Hammond and world-renowned security researcher James Kettle, the pair explore how tens of millions of websites are compromis
> Don’t let “back to school” become “back to (cyber)bullying”
Cyberbullying is a fact of life in our digital-centric society, but there are ways to push back
> New Data Theft Campaign Targets Salesforce via Salesloft App
Google is warning of a new credential theft campaign targeting Salesforce customers via Salesloft Drift
> New Phishing Campaign Abuses ConnectWise ScreenConnect to Take Over Devices
Abnormal AI said the campaign, which lures victims into downloading legitimate RMM software, marks a major evolution in phishing tactics
> Home Assistant + Ubiquiti + AI = Home Automation Magic
Presently sponsored by: 1Password Extended Access Management: Secure every sign-in for every app on every device.It seems like every manufacturer of anything electrical that goes in the house wants to be part of the IoT story these days. Further, they all want their own app, which means you have to...
> ZDI-25-855: Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability
This vulnerability could allow remote attackers to bypass authentication on systems that use the affected version of the Cockroach Labs cockroach-k8s-request-cert container image. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2025-9276.
> TheSqua.re - 107,041 breached accounts
In June 2025, 107k unique customer email addresses were allegedly obtained from TheSqua.re, the "easiest way to find your next serviced apartment". The data also included names, phone numbers and cities which were subsequently posted to a popular hacking forum. TheSqua.re did not respond to repeated...
> Centre de services scolaire des Appalaches
Le Centre de services scolaire des Appalaches a été victime d'une attaque par rançongiciel, les pirates revendiquant avoir obtenu 180 Go de données de l'organisation, dont des informations personnelles sur les élèves et les employés. L'organisation a repris le contrôle de ses serveurs et travaille a...
> Saint Mary’s Home of Erie
Saint Mary’s Home of Erie experienced a data breach where files and folders stored on certain databases may have been accessible to others outside of their organization between August 26, 2025, and August 28, 2025. A cyberattack was claimed by Worldleaks on October 3.
> First known AI-powered ransomware uncovered by ESET Research
The discovery of PromptLock shows how malicious use of AI models could supercharge ransomware and other threats
> Kovack Financial, LLC
Kovack Financial, LLC experienced a data breach between August 8, 2025, and August 27, 2025, where an unknown actor gained access to files within their network. The breach was discovered on July 16, 2026. The incident may have impacted some of the company's information.
> ESET Endpoint Antivirus and ESET Endpoint Security for Windows version 12.0.2062.0 have been released
ESET Endpoint Antivirus and ESET Endpoint Security for Windows version 12.0.2062.0 have been released and are available for download.
> New Android Trojan Variant Expands with Ransomware Tactics
A new version of the Hook Android banking Trojan features 107 remote commands, including ransomware overlays
> Phishing Campaign Uses UpCrypter to Deploy Remote Access Tools
A global phishing campaign has been identified using personalized emails and fake websites to deliver malware via UpCrypter
> Widespread Data Theft Targets Salesforce Instances via Salesloft Drift
Written by: Austin Larsen, Matt Lin, Tyler McLellan, Omar ElAhdan Update (August 28) Based on new information identified by GTIG, the scope of this compromise is not exclusive to the Salesforce integration with Salesloft Drift and impacts other integrations. We now advise all Salesloft Drift custom...