[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (21 articles)

|

// AI-powered summary generated at 08:01

> LLMs and Contextual Integrity
I have been thinking a lot about AI and integrity. Part of that is contextual integrity. I recently found two papers on the topic. “CIMemories: A Compositional Benchmark for Contextual Integrity of Persistent Memory in LLMs“: Abstract: Large Language Models (LLMs) increasingly use persistent memory...
> Heights Finance data breach: What customers need to know
Leaked personal and financial data of around 750,000 US citizens, including SSNs and bank details, could put victims at risk of identity theft and phishing.
> CISA: Windows Task Host flaw now exploited by ransomware gangs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April. [...]
> Can AI Coexist With Privacy? Proton’s Andy Yen Says It Will Have To
Proton’s CEO is a champion of encryption for everyone. So why is he going all in on un-encryptable AI?
> Fuite fiscale, pas de panique !
Fuite DGFiP : pas de panique. Pourquoi vos réactions publiques peuvent aider les pirates à cibler leurs futures campagnes de phishing.
> Three-quarters of Ransomware Attacks Target Mid-Market Firms
Black Kite finds mid-market is the sweet spot for ransomware as manufacturers are most likely to be hit
> The Cop Who Took On Flock
After Noel Pichardo called out his city's embrace of Flock surveillance cameras, he was subjected to five internal affairs investigations in less than two years.
> OpenAI tightens defenses after AI agents breach research environment
Following the OpenAI-Hugging Face incident, in which an agentic collective autonomously penetrated OpenAI’s research infrastructure and another company’s production infrastructure by chaining together multiple weaknesses, OpenAI began strengthening its safety requirements. The weaknesses included pr...
> Microsoft confirms outage affecting search in Microsoft 365 apps
Microsoft says some users are experiencing issues searching in Microsoft 365 apps, including Outlook on the web, Outlook desktop, SharePoint Online, and OneDrive. [...]
> Heights Finance Data Breach Impacts at Least 1.2 Million Individuals
Hackers stole names, addresses, phone numbers, Social Security numbers, and financial information from a third-party platform. The post Heights Finance Data Breach Impacts at Least 1.2 Million Individuals appeared first on SecurityWeek.
> SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers
SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers. The hardware wallet maker said all affected customers were notified individually by email on A...
> Hacker claims millions of records stolen from corporate Azure tenants
A threat actor known as “TheHatman” claims to have obtained millions of employee records from the Azure environments of several Fortune 500 companies, including McDonald’s, Vodafone, Kyndryl, and Tata Consultancy Services (TCS), according to Hudson Rock. Over the past week, the threat actor has post...
> What you say during a cyber breach can — and will — be used against you
The first 24 hours after a cyber incident are messy. Teams are moving fast, and a lot gets said on Slack or email that can come back later. People are scrambling to contain the issue, figure out what happened and keep things moving. In the process, they create a record that do...
> New DFIR Mental Health Training Webinar (CPD-Accredited)
New CPD-accredited training from our Well-Being Lead, Paul Gullon-Scott, is now available to help digital forensic investigators and their organisations better understand and manage the psychological demands of the role — book your place today.
> GitLab Patches Critical Code Injection Vulnerability
The security defect allows unauthenticated attackers to modify or delete user data and public projects. The post GitLab Patches Critical Code Injection Vulnerability appeared first on SecurityWeek.
> GitLab Patches Critical Unauthenticated GraphQL Vulnerability
GitLab patched a critical GraphQL flaw that let unauthenticated attackers remotely modify or delete public projects on self-managed servers. GitLab pushed out an emergency patch this week to address a critical flaw, tracked as CVE-2026-19478 (CVSS score of 9.4), that could let an attacker with zero...
> AI can find zero-days but still can’t reliably write secure code
In recent months, LLMs have gone from flooding open-source projects and bug bounty programs with questionable security reports that wasted developers’ time, to routinely finding zero-day flaws that humans and traditional security audit tools had missed for years — a rapid evol...
> UK Legal Regulator Raises AI Misuse Concerns
Solicitors Regulation Authority sounds the alarm over AI hallucinations and data leaks
> ShieldBreak : cette faille zero-day menace Windows, Microsoft prépare un patch
Nightmare Eclipse a publié ShieldBreak, une faille zero-day qui contourne le patch RoguePlanet de Microsoft Defender. Microsoft dit travailler sur un correctif. Le post ShieldBreak : cette faille zero-day menace Windows, Microsoft prépare un patch a été publié sur IT-Connect.
> Microsoft starts removing WMIC tool used by cybercriminals
Microsoft announced that it removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week. [...]