> TODAY'S SUMMARY (51 articles)
Today's cybersecurity landscape reveals a record surge in ransomware attacks, with 1,073 firms targeted globally in August, primarily in the industrial sector. Microsoft has disrupted the AI-powered phishing service, EvilTokens, which compromised over 12,000 inboxes across various organizations. Meanwhile, critical vulnerabilities have been reported in several platforms, including Adobe, WordPress, and F5's BIG-IP, necessitating immediate patches to prevent potential exploitation. Additionally, the ShinyHunters group claims to have breached FBI systems via a zero-day vulnerability in Oracle PeopleSoft, threatening to leak sensitive data. In malware developments, Chinese hackers are leveraging a Chrome-Windows zero-day to deploy CLEANGULP malware, highlighting the ongoing threat posed by exploit chains.
|
// AI-powered summary generated at 12:01
Multiple distributed denial-of-service (DDoS) attacks targeted the Threema secure messaging service earlier this week, causing severe disruptions to communications. [...]
Mustang Panda upgraded CoolClient with a signed kernel driver that hides processes, files and network activity, making the backdoor harder to detect. HoneyMyte, also known as Mustang Panda, has pushed its CoolClient backdoor another step deeper into Windows. Kaspersky’s latest analysis shows a new v...
A new information-stealing malware called AmnesiaStealer, which targets macOS users via ClickFix attacks, includes a streaming module that allows the attacker to interactively control the victim's web browser. [...]
Corma CEO tells The Reg it's building 'One ring to rule them all, for the defenders to have this power'
Debian issued a security advisory for docker.io addressing multiple vulnerabilities that could lead to privilege escalation and unauthorized file access, urging users to upgrade to the latest version.
France’s tax agency says hackers stole data on 678,000 taxpayers, including income and tax details, in a sophisticated cyberattack. A threat actor claimed to have breached France’s tax agency in late June. France’s tax administration confirmed that a cyberattack exposed personal data of 678,000 indi...
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Crooks Are Buying Your Expired Domains and Using Them...
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: GitHub Dependabot malware alerts now cover eight ecosystems GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.io, or PHP Composer package...
Acronis uncovered PATCHCORD, a stealthy backdoor targeting Afghan telecom and South Asian infrastructure via fake VPN tools and Google Sheets C2. Researchers at Acronis just documented an espionage operation that reads like it was built by someone with genuinely good taste in disguises. Their Threat...
Le service numérique de la mairie de Tangerhütte est inaccessible depuis plus de deux semaines en raison d'une attaque externe. Bien qu'un incident similaire à Berlin ait récemment conduit à la vente de données sur le Darknet, il n'est pas confirmé que cela soit arrivé à Tangerhütte.
La présence d'une activité non autorisée sur les systèmes technologiques de l'Université du Texas à San Antonio (UT San Antonio) a nécessité la suspension de certains services en ligne et téléphoniques. L'incident a été détecté le week-end, avant qu'il n'atteigne les systèmes centraux. Les autorités...
New proftpd packages for Slackware 15.0 and -current address security issues, including a critical use-after-free bug and passive transfer settings. Updated packages are available online.
Attackers are buying expired domains to exploit their reputation, traffic and DNS history, using them for malware delivery, scams and C2 infrastructure. Every day, roughly 65,000 domain names that once belonged to someone else get re-registered by a new owner. Infoblox Threat Intel calls these dropc...
Attackers are actively exploiting a maximum severity SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231, just days after SAP released a patch. A critical SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231 (CVSS score of 10.0), is under active exploitation just days after SAP releas...
A guide on how to check if hackers have broken into your accounts on the most popular AI platforms.
Oracle Linux 8 has released updated Node.js packages addressing multiple CVEs, including security fixes and dependency updates for improved stability and functionality across both x86_64 and aarch64 architectures.
Oracle Linux 8 has received updated RPMs for various .NET components, including SDK and runtime packages, addressing multiple CVEs and adding support for Oracle Linux.
A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes. [...]
Oracle Linux 8 has released updates for dracut packages addressing various bugs and performance improvements, including DHCP enhancements and boot time optimizations, linked to CVE-2026-15816.
Oracle Linux 8 has released updates for various .NET packages including SDK and runtime, addressing vulnerabilities associated with specific CVEs and enhancing support for Oracle Linux.