> TODAY'S SUMMARY (21 articles)
Today's cybersecurity landscape highlights several critical threats and vulnerabilities. A zero-day vulnerability in F5 BIG-IP is being actively exploited, allowing unauthenticated attackers to achieve remote code execution; F5 has released patches to address this issue. Similarly, a new flaw in Next.js could enable server code execution through crafted SVG input. In a concerning development, the ShinyHunters group claims to have breached the FBI, threatening to leak sensitive data unless a report is retracted. Additionally, vulnerabilities in Chromium and Check Point's management server are also drawing attention, underscoring the ongoing risks associated with software security. As malicious bot activity continues to surge, nearly two-thirds of websites tested are failing bot defenses, signaling a growing cyber threat landscape.
|
// AI-powered summary generated at 08:01
Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT.
"TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Microsoft services," Ontinue said in a tec...
Security researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence (AI) agent to the next through the editable system prompt files that autonomous agent harnesses use to carry state between sessions.
The work, releas...
Une base belge piratée de 148 251 profils, avec IBAN et données personnelles, aurait été exposée selon un pirate sans authentification.
Xpander’s platform uses a universal agent harness that executes AI agents as portable workloads and securely renders interfaces on demand.
The post Xpander Raises $7.5 Million for AI Management and Governance appeared first on SecurityWeek.
SpyGuard et MVT aident à rechercher des traces de spyware sur smartphones grâce au réseau et à l’analyse forensique.
Find out how to write a letter of resignation email, plus simple resignation email templates designed to simplify your offboarding process.
Fortinet will use Virtue AI technology to enhance its AI security portfolio, including for AI models, applications, and agentic systems.
The post Fortinet Acquires AI Security Company Virtue AI appeared first on SecurityWeek.
85% of cybersecurity professionals consider compromised credentials a primary attack path, yet only 19% continuously monitor active credentials and automatically remediate exposure. The 2026 Credential Risk Report examines where credential security programs fall short and what it takes to move towar...
From mobile extractions and emails to cloud data and video, see how Cellebrite Genesis brings diverse evidence sources together to help enterprise investigators reach faster, source-traceable and defensible findings.
Google’s open-source autonomous Customer Support & Returns Agent, built using the Agent Development Kit (ADK) and Gemini, demonstrates how developers can apply zero-trust security principles to AI agents that interact with sensitive systems and take real-world actions. The project tests an appro...
Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer.
OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of packages published as...
GitLab has released patches for two vulnerabilities, including a critical-severity code injection flaw that can be exploited without authentication. The vulnerabilities affect GitLab Community Edition (CE) and Enterprise Edition (EE) versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 befor...
Un plaignant a caché du texte blanc dans ses écritures pour manipuler toute IA lisant le document. Le juge lui a retiré l'accès au dépôt en ligne.
Le post IA : il cache une injection de prompt dans un document judiciaire, le juge le sanctionne a été publié sur IT-Connect.
A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this week by agent security platform Reco.
The activity, which Reco has named the City Forum campaign after a...
UT San Antonio has taken IT systems offline following a cyber incident, disrupting student registration and tuition payments days before term is due to resume
As one developer found out when his Google Doc containing company passwords showed up in Google search results.
Microsoft has started testing a faster File Explorer and a less cluttered and more customizable context menu in Windows 11 preview builds rolling out to Insiders this week. [...]
Security researchers are warning of a newly uncovered Python malware framework that routes much of its command-and-control (C2) activity through Microsoft services that defenders already expect to see.
The Ontinue Cyber Defense Center discovered the implant while investigat...
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects GitLab shipped an out-of-cycle patch for a critical flaw, tracked as CVE-2026-19478 with a CVSS score of 9.4, that could have let an unauthenticated attacker remotely modify or delete public projects and user dat...
Tracked as CVE-2026-15748, the arbitrary file upload bug allows unauthenticated attackers to upload executable files.
The post 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw appeared first on SecurityWeek.