> TODAY'S SUMMARY (44 articles)
In Q3 2026, ransomware attacks reached a record high of 2,627, particularly impacting critical sectors like finance and healthcare. Citrix has issued urgent patches for a critical NetScaler vulnerability (CVE-2026-107406) that could allow remote code execution. Meanwhile, hackers hijacked multiple country code top-level domains (ccTLDs) linked to Google, raising concerns over domain security. An update on the ASOS breach reveals that customer data, including shopping habits, has been compromised, increasing phishing risks. The FBI has disrupted operations of Chinese state-sponsored hacking tools, while new vulnerabilities in AhsayCBS are being actively exploited. Additionally, the rise of pre-installed malware on low-cost Android devices highlights ongoing threats in mobile security.
|
// AI-powered summary generated at 12:00
Five major banking associations in the US claim the new SEC cyber incident disclosure rule puts a strain on their resources
Over two audits in 2023, we reviewed a blockchain system developed by Axiom that allows computing over the entire history of Ethereum, all verified by zero-knowledge proofs (ZKPs) on-chain using ZK-verified elliptic curve and SNARK recursion operations. This system is built using the Halo2 framework...
The FBI provided details of Funnull’s malicious activities, selling infrastructure to criminal groups to facilitate cryptocurrency fraud in the US
We’re proud to announce that PortSwigger has been awarded the prestigious King’s Award for Enterprise in the category of International Trade - a recognition that reflects our sustained international s
From a flurry of attacks targeting UK retailers to campaigns corralling end-of-life routers into botnets, it's a wrap on another month filled with impactful cybersecurity news
The UK MoD has unveiled a new Cyber and Electromagnetic Command, which will focus on offensive cyber operations and “electromagnetic warfare” capabilities
Security teams should use vulnerability context alongside KEV lists to prioritize patching, OX argued
Le ministère de la Justice a subi un ataque cibernétique, ce qui a obligé à suspendre temporairement certains services, notamment la délivrance du certificat de casier judiciaire. Les autorités travaillent à résoudre l'incident et à protéger les données personnelles des citoyens. La sécurité de l'in...
Christian Brothers Academy suffered a cyberattack that may have exposed personal information, including names, addresses, financial information, and identification numbers. The breach occurred through a potential phishing attack, and the attackers may have accessed certain files containing personal...
Service releases for ESET Mail Security for Microsoft Exchange Server version 11.1.10013.0, ESET Security for Microsoft SharePoint Server version 11.1.15005.0 and ESET Server Security for Microsoft Windows Server version 11.1.12013.0 are available for download.
Civil Service Employees Association Inc. experienced a cybersecurity incident involving unauthorized access to their systems between May 3, 2025, and May 31, 2025, resulting in the theft of files containing personal information, including names and Social Security numbers.
The firm’s remote monitoring management tool, ScreenConnect, has reportedly been patched
Fullscreen Browser-in-the-Middle attacks are making it harder for users to detect malicious websites
We recently hosted a webinar to introduce Burp Suite DAST, the new name for Burp Suite Enterprise Edition, the best-in-class, automated web application and API security scanning solution for modern Ap
Fortinet has identified a new Windows RAT operating stealthily on compromised systems with advanced evasion techniques
A threat actor has used ASUS routers’ legitimate features to create persistent backdoors that survive firmware updates and reboots
Introducing the Custodial Stablecoin Rekt Test; a new spin on the classic Rekt Test for evaluating the security maturity of stablecoin issuers.
A new EY report found that cybersecurity teams are a major vehicle for business growth, and CISOs should push for a seat at the top table
EasyDMARC found that just 7.7% of the world’s top 1.8 million email domains have implemented the most stringent DMARC policy
Le comté de Lorain a subi une faille de sécurité réseau, ce qui a perturbé ses systèmes et a entraîné la fermeture de plusieurs départements jusqu'à ce que les systèmes soient rétablis. Les services critiques et les départements essentiels restent en ligne pour les citoyens. L'organisation travaille...