> TODAY'S SUMMARY (51 articles)
Today's cybersecurity landscape reveals a record surge in ransomware attacks, with 1,073 firms targeted globally in August, primarily in the industrial sector. Microsoft has disrupted the AI-powered phishing service, EvilTokens, which compromised over 12,000 inboxes across various organizations. Meanwhile, critical vulnerabilities have been reported in several platforms, including Adobe, WordPress, and F5's BIG-IP, necessitating immediate patches to prevent potential exploitation. Additionally, the ShinyHunters group claims to have breached FBI systems via a zero-day vulnerability in Oracle PeopleSoft, threatening to leak sensitive data. In malware developments, Chinese hackers are leveraging a Chrome-Windows zero-day to deploy CLEANGULP malware, highlighting the ongoing threat posed by exploit chains.
|
// AI-powered summary generated at 12:01
Oracle Linux has released updated bind packages for version 8 addressing multiple CVEs, enhancing DNS security through various validation and rejection improvements in DNS records.
Shai-Hulud variant poisons 444 packages, spreads via tarballs and dev-tool hooks
A maximum-severity security vulnerability impacting SAP Commerce Cloud is witnessing active exploitation efforts.
The vulnerability, tracked as CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It relates to an instance of insufficient authorization checks and input validation.
"SAP Commer...
Hackers are exploiting a macOS Screen Sharing flaw to gain root access and install Monero miners on Macs with port 5900 exposed online. The Dutch National Cyber Security Centre confirmed active exploitation of a critical macOS authentication flaw, tracked as CVE-2026-65400 (CVSS score of 9.8), less...
A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency miner, the Netherlands National Cyber Security Centre (NCSC) has warned.
The vulnerability in question is CVE-2026-65400 (CVSS score: 9.8), a critical authentication issue impac...
GeoServer faces an unpatched zero-day enabling SQL injection and potentially RCE, with attackers already probing exposed systems. A newly disclosed GeoServer zero-day is already attracting active exploitation attempts, and there is no patch available yet. Organisations running the open-source geospa...
2026: the year the tools learned to hack
In May 2026, OpenAI began testing an internal research model against a cybersecurity benchmark called ExploitGym. While the test environment was not supposed to have access to the open internet, there was, however, one narrow path out because the agents still...
OSINT Tools Update
New Firewall Guide
Une entreprise prestataire de la ConsejerĂa de Agricultura, nommĂ©e Tecnoabi, a Ă©tĂ© victime d'une cyberattaque qui a exposĂ© les donnĂ©es personnelles (identifiants, contacts et bancaires) de milliers d'agriculteurs et de propriĂ©taires de terres bĂ©nĂ©ficiaires des aides de la Politique Agricole Commune...
The New Blog
L'Information Regulator enquête sur une violation de données chez Cartrack, une société de suivi de véhicules. L'incident, qui est survenu en août, a été un incident de ransomware. Cartrack a confirmé que sa base de données client a été accédée, contenant des informations personnelles telles que les...
L'entreprise d'oncologie Novocure a signalé un incident de sécurité cibernétique qui a exposé les dossiers internes de plus de 1 400 patients américains. L'accès non autorisé aux systèmes d'information a eu lieu à la mi-août.
The New Blog
Le réseau de l'État de Berlin a été victime d'une cyberattaque. Deux administrations sénatoriales, celles de l'Aménagement du territoire et de la Mobilité, ont été isolées du réseau après la découverte d'une intrusion. L'attaque, attribuée à une vulnérabilité dans le système de l'administration de l...
Le bureau de la ville de Lincoln a été contraint de fermer suite à une cyberattaque qui a chiffré une partie de son réseau. Les autorités locales travaillent à la restauration des systèmes pour éviter toute réinfection et minimiser les perturbations des services.
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
It could soon become easier to identify AI-generated content, even if it's not the usual "It's Not X, it's Y" type of post you'd come across on LinkedIn and other socials. [...]
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.