> TODAY'S SUMMARY (5 articles)
Today's cyber news highlights several critical developments and threats. Rabbit has launched OS3, a cloud-based operating system that utilizes local agents on users' devices, raising concerns about potential security vulnerabilities. Meanwhile, NetBSD has released version 10.2 to address a severe kernel flaw in ipfilter that could be exploited remotely. Additionally, the rise of AI-driven malware is transforming the threat landscape, as attackers can now automate significant parts of the attack process, increasing both speed and scale. These trends underscore the need for heightened vigilance and robust security measures across all platforms.
|
// AI-powered summary generated at 04:00
Flock’s surveillance cameras have already sparked outrage. WIRED reconstructed its next-generation AI system, already in use by some police, to confirm it goes much further than tracking license plates.
Microsoft tracked over 30 MacSync Stealer domains by focusing on behavioral patterns, revealing a campaign targeting passwords, keys, wallets and other data. Domain blocking is a losing game when the thing you’re blocking can register a new domain faster than you can add it to a list. That’s the exa...
Trois incidents à la DGFiP, 678 000 usagers touchés, 1,8 million de comptes cadastraux et une revendication géante à l'Éducation nationale. Le point complet.
Le post DGFiP, cadastre, Éducation nationale : l’État français enchaîne les fuites de données a été publié sur IT-Connect.
OpenAI temporarily paused reinforcement learning (RL) training on its latest models intended for deployment for two weeks while it hardened and red-teamed research environments and expanded monitoring. “Our largest planned frontier RL run remains on hold while we conduct smaller-scale training and e...
Cifas data finds account takeover and identity fraud are driving a surge in fraud cases
Over 50,000 exposed Stripe API keys show how leaked secrets can enable fraud, data access and account abuse within hours. Ransomnews researchers have documented a large-scale leak of Stripe merchant API keys found exposed in public code repositories, GitHub Actions logs, and misconfigured web server...
A few weeks ago, on a busy day, threat-modeling expert Adam Shostack opened an email from a client. Someone at that organization had vibe-coded an app and put it to work with customer data. Now, the client wanted to know what risks the tool posed. And what it should do about t...
The bugs could lead to code execution, privilege escalation, sandbox escape, and information disclosure.
The post Chrome, Firefox Updates Patch Dozens of Vulnerabilities appeared first on SecurityWeek.
USN-8093-1 fixed a vulnerability in libssh. This update provides
the corresponsing fix for Ubuntu 26.04 LTS.
Original advisory details:
It was discovered that libssh incorrectly performed bounds checking when
processing SFTP extensions. If a client application queried extension data out
of boun...
The FBI said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021. [...]
USN 8113-1 fixed vulnerabilities in tiff. This update
provides the corresponding fixes for Ubuntu 26.04 LTS.
Original advisory details:
It was discovered that LibTIFF did not properly handle memory when
processing certain images. An attacker could possibly use this issue to
cause LibTIFF to cra...
The University of Texas at San Antonio pushed back the start of its fall semester by three days after a cyberattack targeted its academic network over the weekend. Classes that were due to begin on Wednesday, August 19 will now start on Monday, August 24. UT San Antonio is one of the largest univers...
When Cameron Curry discovered that his contract as a data analyst wasn't going to be renewed, he could have updated his LinkedIn profile. He could have started sending out his resume.
But what the 27-year-old from Charlotte, North Carolina, did instead was turn to extortion.
Read more in my ar...
Stripe est visé par une fuite revendiquée avec, selon le pirate, clés API et des données clients sensibles.
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities t...
F5 has introduced enhancements to the F5 AI Gateway and integrated the solution into the F5 AI Security Platform. The enhanced F5 AI Gateway seamlessly enforces policies on every AI request, giving enterprises a unified control plane to govern how AI models, agents, and tools are accessed and used,...
The data breach was initially believed to affect roughly 350,000 people, but the HHS breach tracker shows a far bigger impact.
The post CareCloud Data Breach Impact Grows to 3.7 Million Individuals appeared first on SecurityWeek.
Multiple security vulnerabilities in .NET affecting Ubuntu 26.04, 24.04, and 22.04 LTS were addressed, enabling potential request smuggling, information disclosure, denial of service, and privilege escalation.
Microsoft a retiré WMIC de Windows 11 24H2, 25H2 et des builds Insider. L'outil n'est plus réinstallable en tant que fonctionnalité facultative.
Le post Windows 11 : WMIC a bel et bien totalement disparu des versions 24H2 et 25H2 a été publié sur IT-Connect.
Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, after correlating recurring endpoint and network behaviors across changing infrastructure, tracing the malware from payload retrieval through data collection, staging, and exfiltr...