> TODAY'S SUMMARY (101 articles)
Today's cybersecurity news highlights several significant threats and trends. OpenAI has partnered with Ukraine to enhance the cybersecurity of critical infrastructure amid ongoing conflict with Russia. A member of the Ryuk ransomware gang received a two-year prison sentence for extorting over $1.2 million. The ShinyHunters group claims to have breached the FBI, demanding the retraction of a report criticizing their methods. Vulnerabilities in multiple platforms, including GitHub and WordPress, continue to pose risks, with leaked GitHub App keys still being exploited. Additionally, a new Windows malware, CLOSEDQUORUM, utilizes AI models to determine its actions, showcasing the evolving landscape of AI in cyberattacks.
|
// AI-powered summary generated at 16:00
Cl0p revendique près de 50 entreprises après l’exploitation présumée d’une faille critique dans PTC Windchill et FlexPLM.
Slackware has released updated rsync packages for version 15.0 and -current to address security issues and bugs, with various download links and MD5 signatures provided.
The “philosophical shift” that the memo authorizes raises legal, practical and moral questions, experts say.
The post A bold new strategy or a dangerous precedent? Experts are divided on Trump’s memo. appeared first on CyberScoop.
The surveillance company announced it's making a tool called "Audit Assistance" mandatory for all customers, claiming it's already helped catch abuse. But the company has yet to explain how the tool works in detail, raising questions about its effectiveness.
Cameron Curry stole corporate data and employee information, which he used to threaten the company as his six-month contract gig came to a close. He ultimately extorted the company for $7,540.92.
The post Tech contractor for Brightly Software sentenced to 2 years in prison for insider attack appeare...
Ubuntu 22.04 LTS has resolved multiple vulnerabilities in the Linux kernel affecting NVIDIA Tegra IGX systems, including issues with WiFi and various subsystems requiring kernel updates.
Ubuntu released a security notice for version 16.04 LTS addressing multiple Linux kernel vulnerabilities that could allow attackers to compromise systems, with necessary updates detailed.
Apple now sends out push notifications to iPhone lock screens when the company identifies government spyware targeting someone's devices.
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi
implementation in the Linux kernel did not properly handle aggregated
frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A
physically proximate attacker could use this issue to inject packets.
(CVE-2025-27558...
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi
implementation in the Linux kernel did not properly handle aggregated
frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A
physically proximate attacker could use this issue to inject packets.
(CVE-2025-27558...
Ubuntu 16.04 LTS received an update addressing multiple Linux kernel vulnerabilities, including a logic flaw allowing privilege escalation, along with several other critical subsystem fixes.
Today, we’re announcing that AWS Certificate Manager (ACM) will discontinue support for email-validated public certificates by September 30, 2027. If you use email validation for your ACM public certificates, you need to migrate to DNS validation before that date. This change aligns with the Certifi...
Ubuntu Security Notice USN-8529-2 reveals multiple vulnerability fixes in the Linux kernel affecting Ubuntu 16.04 LTS, with local attackers potentially escalating privileges or escaping containers.
Ubuntu 16.04 LTS received security updates for the linux-aws-hwe kernel to correct several vulnerabilities that could allow local attackers to escalate privileges or escape containers.
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP
subsystem in the Linux kernel when handling socket buffer fragments. This
flaw is known as Fragnesia. A local attacker could use this to escalate
privileges, or possibly escape a container. (CVE-2026-43503)
Several security issues w...
Debian's security advisory DSA-6438-1 warns of multiple vulnerabilities in PostgreSQL 17, possibly allowing arbitrary code execution and privilege escalation, urging users to upgrade their packages.
Authorities in Ukraine shut down 94 fraudulent call centers across the country that lured people into investment scams or tried to obtain access to bank accounts. [...]
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP
subsystem in the Linux kernel when handling socket buffer fragments. This
flaw is known as Fragnesia. A local attacker could use this to escalate
privileges, or possibly escape a container. (CVE-2026-43503)
Several security issues w...
It was discovered that the Linux kernel did not properly handle shared page
fragments during socket buffer operations, collectively known as Dirty
Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the
RxRPC networking subsystem when processing paged fragments. A local
attacker could...
Flock Safety, the embattled vendor of mass surveillance technology, has rolled out a handful of new reforms intended to appease the justified nationwide anger that has seen scores of towns cancel or suspend their contracts with the company for automated license plate readers (ALPRs). The reforms are...