> TODAY'S SUMMARY (5 articles)
Today's cyber news highlights several critical developments and threats. Rabbit has launched OS3, a cloud-based operating system that utilizes local agents on users' devices, raising concerns about potential security vulnerabilities. Meanwhile, NetBSD has released version 10.2 to address a severe kernel flaw in ipfilter that could be exploited remotely. Additionally, the rise of AI-driven malware is transforming the threat landscape, as attackers can now automate significant parts of the attack process, increasing both speed and scale. These trends underscore the need for heightened vigilance and robust security measures across all platforms.
|
// AI-powered summary generated at 04:00
CodeSecCon is the premier virtual event bringing together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained.
The post Virtual Event Today: CodeSecCon – Secure Your Code and Applications appeared first on SecurityWeek.
Ubuntu Security Notice USN-8649-1 addresses several vulnerabilities in libheif affecting Ubuntu 26.04 LTS and 24.04 LTS, urging users to update their systems to fix these issues.
Ubuntu Security Notice USN-8563-3 addresses nginx vulnerabilities affecting multiple versions, providing a better fix for CVE-2026-42533 and correcting issues that could lead to denial of service.
Rebranded feature promises household alerts without video, but mind the small print
Multiple vulnerabilities in Bind9 affecting various Ubuntu LTS versions have been addressed, potentially allowing remote attacks leading to impersonation, denial of service, and cache poisoning.
A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia.
The intrusion set makes use of seven remote access tool (RAT) families, five of which have never been previously documented: DriveSilkRAT, CookiETagRAT, NomadRAT, Gog...
A vulnerability in libssh affecting Ubuntu 26.04 LTS could lead to crashes or unexpected behavior due to improper bounds checking, fixed in the latest update.
Ubuntu Security Notice USN-8113-2 addresses vulnerabilities in LibTIFF for Ubuntu 26.04 LTS, allowing potential denial of service from improper memory handling in certain image processing.
The cyberattack at CareCloud resulted in one of the largest reported data breaches in the U.S. healthcare industry this year.
It was discovered that libheif had an integer underflow in the Fraction
constructor when a clap transform was applied twice. An attacker could
possibly use this issue to cause libheif to crash, resulting in a denial of
service. (CVE-2026-62289)
It was discovered that libheif had an out-of-bounds re...
The Justice Department accused 17 alleged hackers with ties to the Iranian government of breaching email accounts at U.S. government agencies and stealing intellectual property from dozens of universities.
USN-8563-1 fixed vulnerabilities in nginx. The fix for CVE-2026-42533 was
backed out in USN-8563-2 because it could cause a regression. This update
includes a better fix for CVE-2026-42533.
We apologize for the inconvenience.
Original advisory details:
It was discovered that nginx incorrectly ha...
OpenAI is strengthening safeguards for its most advanced AI models, citing growing risks as frontier systems gain more powerful cyber capabilities
AI-powered data fabric company Prevalent AI today announced raising $22 million in growth funding from Integrity Growth Partners (IGP). Founded in 2017 by former GCHQ and Darktrace leaders and headquartered in London, Prevalent AI has operated on a bootstrapped basis until now. The UK-based company...
It was discovered that Bind incorrectly accepted NSEC3 records whose signer
name did not match the owning zone. A remote attacker could possibly use
this issue to perform NSEC3 impersonation attacks, bypassing DNSSEC
validation. (CVE-2026-10723)
It was discovered that Bind incorrectly handled Key R...
Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay technique.
The activity, codenamed Operatio...
Most email defenses still do the job they did a decade ago. Scan the message, look for something malicious, block it. That worked when the danger sat in the payload, a bad link or an attachment. It stopped working when the danger moved into the message's intent, and it is failing now that the sender...
The 17 members of the Mabna Institute targeted hundreds of universities and organizations in the US and abroad.
The post US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them appeared first on SecurityWeek.
Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the activity.
"The opera...
Microsoft has resolved a bug that caused Windows Defender to crash after a recent security update, resulting in 0xc0000005 access violation errors on some affected systems. [...]