> TODAY'S SUMMARY (21 articles)
Today's cybersecurity landscape highlights several critical threats and vulnerabilities. A zero-day vulnerability in F5 BIG-IP is being actively exploited, allowing unauthenticated attackers to achieve remote code execution; F5 has released patches to address this issue. Similarly, a new flaw in Next.js could enable server code execution through crafted SVG input. In a concerning development, the ShinyHunters group claims to have breached the FBI, threatening to leak sensitive data unless a report is retracted. Additionally, vulnerabilities in Chromium and Check Point's management server are also drawing attention, underscoring the ongoing risks associated with software security. As malicious bot activity continues to surge, nearly two-thirds of websites tested are failing bot defenses, signaling a growing cyber threat landscape.
|
// AI-powered summary generated at 08:01
I have been thinking a lot about AI and integrity. Part of that is contextual integrity. I recently found two papers on the topic.
“CIMemories: A Compositional Benchmark for Contextual Integrity of Persistent Memory in LLMs“:
Abstract: Large Language Models (LLMs) increasingly use persistent memory...
Leaked personal and financial data of around 750,000 US citizens, including SSNs and bank details, could put victims at risk of identity theft and phishing.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April. [...]
Proton’s CEO is a champion of encryption for everyone. So why is he going all in on un-encryptable AI?
Fuite DGFiP : pas de panique. Pourquoi vos réactions publiques peuvent aider les pirates à cibler leurs futures campagnes de phishing.
Black Kite finds mid-market is the sweet spot for ransomware as manufacturers are most likely to be hit
After Noel Pichardo called out his city's embrace of Flock surveillance cameras, he was subjected to five internal affairs investigations in less than two years.
Following the OpenAI-Hugging Face incident, in which an agentic collective autonomously penetrated OpenAI’s research infrastructure and another company’s production infrastructure by chaining together multiple weaknesses, OpenAI began strengthening its safety requirements. The weaknesses included pr...
Microsoft says some users are experiencing issues searching in Microsoft 365 apps, including Outlook on the web, Outlook desktop, SharePoint Online, and OneDrive. [...]
Hackers stole names, addresses, phone numbers, Social Security numbers, and financial information from a third-party platform.
The post Heights Finance Data Breach Impacts at Least 1.2 Million Individuals appeared first on SecurityWeek.
SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers.
The hardware wallet maker said all affected customers were notified individually by email on A...
A threat actor known as “TheHatman” claims to have obtained millions of employee records from the Azure environments of several Fortune 500 companies, including McDonald’s, Vodafone, Kyndryl, and Tata Consultancy Services (TCS), according to Hudson Rock. Over the past week, the threat actor has post...
The first 24 hours after a cyber incident are messy. Teams are moving fast, and a lot gets said on Slack or email that can come back later. People are scrambling to contain the issue, figure out what happened and keep things moving. In the process, they create a record that do...
New CPD-accredited training from our Well-Being Lead, Paul Gullon-Scott, is now available to help digital forensic investigators and their organisations better understand and manage the psychological demands of the role — book your place today.
The security defect allows unauthenticated attackers to modify or delete user data and public projects.
The post GitLab Patches Critical Code Injection Vulnerability appeared first on SecurityWeek.
GitLab patched a critical GraphQL flaw that let unauthenticated attackers remotely modify or delete public projects on self-managed servers. GitLab pushed out an emergency patch this week to address a critical flaw, tracked as CVE-2026-19478 (CVSS score of 9.4), that could let an attacker with zero...
In recent months, LLMs have gone from flooding open-source projects and bug bounty programs with questionable security reports that wasted developers’ time, to routinely finding zero-day flaws that humans and traditional security audit tools had missed for years — a rapid evol...
Solicitors Regulation Authority sounds the alarm over AI hallucinations and data leaks
Nightmare Eclipse a publié ShieldBreak, une faille zero-day qui contourne le patch RoguePlanet de Microsoft Defender. Microsoft dit travailler sur un correctif.
Le post ShieldBreak : cette faille zero-day menace Windows, Microsoft prépare un patch a été publié sur IT-Connect.
Microsoft announced that it removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week. [...]