> TODAY'S SUMMARY (21 articles)
Today's cybersecurity landscape highlights several critical threats and vulnerabilities. A zero-day vulnerability in F5 BIG-IP is being actively exploited, allowing unauthenticated attackers to achieve remote code execution; F5 has released patches to address this issue. Similarly, a new flaw in Next.js could enable server code execution through crafted SVG input. In a concerning development, the ShinyHunters group claims to have breached the FBI, threatening to leak sensitive data unless a report is retracted. Additionally, vulnerabilities in Chromium and Check Point's management server are also drawing attention, underscoring the ongoing risks associated with software security. As malicious bot activity continues to surge, nearly two-thirds of websites tested are failing bot defenses, signaling a growing cyber threat landscape.
|
// AI-powered summary generated at 08:01
BlackFileâs four affiliate groups are still targeting victims, including medical technology organizations. Several potential victims received new extortion demands last week, according to Google.
The post Details emerge on BlackFileâs recent attacks on financial companies appeared first on CyberScoo...
In a post-mortem, the frontier AI testing company said internet access for models is necessary to fully test out their cybersecurity capabilities.
The post Irregular says âhuman oversightâ responsible for AI sandbox escape incidents appeared first on CyberScoop.
Apple today released updates for iOS/iPadOS (26 and 18) and macOS 26. This update fixes 108 vulnerabilities and comes about two weeks after the much smaller macOS update that addressed the single screen-sharing vulnerability. This vulnerability did not affect iOS/iPadOS.
Cybersecurity experts who investigate spyware attacks say the number of people who received a recent threat notification from Apple is unusually high.
The breach affected anyone who received a loan through the company or inquired about a loan product through a third party.
A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials. [...]
Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics. [...]
Debian released Advisory DSA-6445-1 highlighting multiple vulnerabilities in Ironic that could lead to bypassing access restrictions, information leaks, or arbitrary code execution, advising users to upgrade.
Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to execute commands in a workflow containing internal Jira credent...
A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites.
The vulnerability, tracked as CVE-2026-15748, is rated 9.8 out of 10.0 on the CVSS scori...
A vulnerability in Engrampa could allow attackers to execute arbitrary code via malicious files. Users on affected Ubuntu versions should update to the latest package versions for security.
SafePal says a breach exposed personal data of 39,798 customers, but not wallet credentials, private keys, seed phrases, or payment information. SafePal disclosed a data breach affecting about 39,798 customers after hackers exploited a vulnerability in its order-tracking plugin. The flaw exposed inf...
Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel.
Russian cybersecurity company Kaspersky said its ongoing monitoring of the threat activity cluste...
It was discovered that Engrampa incorrectly handled symbolic links when
extracting certain archives. An attacker could possibly use this issue to
write arbitrary files and execute arbitrary code.
Amazon Web Services (AWS) is gradually introducing updates to the AWS Sign-In and sign-up experience to a limited number of customers. Weâre sharing these changes so you will know what to expect as we gradually make the updated experience available to more customers. These updates include new option...
The SANDCLOCK LiteLLM supply-chain attack exposed credentials across 2,038 repositories, affecting technology, finance, healthcare, retail and more. Resecurity (USA) estimated the most affected sectors by the âSANDCLOCKâ backdoor, which was planted as a result of the code repository compromise. Acco...
On July 14th, 2026, we received a submission for an Unauthenticated Arbitrary File Upload vulnerability in Forminator Forms, a WordPress plugin with more than 600,000 active installations.
The post 600,000 WordPress Sites Affected by Arbitrary File Upload Vulnerability in Forminator Forms WordPress...
Le ContrÎleur européen de la protection des données (CEPD) a communiqué sur ses récentes activités concernant la surveillance des décisions automatisées, l'identité numérique et la coopération internationale en matiÚre de protection des données.Le CEPD a mis à disposition une nouvelle liste de contr...
La Déléguée à la protection des données et à la transparence de Saxe a signalé une augmentation des notifications de violations de données en juillet et août, due à l'exploitation de failles de sécurité dans des systÚmes de gestion de contenu.Cette hausse concerne des instances d'hébergement web pir...
The crypto hardware wallet company SafePal confirmed a data breach on Sunday, telling users that nearly 40,000 customers had information stolen during a recent security incident.