> TODAY'S SUMMARY (101 articles)
Today's cybersecurity news highlights several significant threats and trends. OpenAI has partnered with Ukraine to enhance the cybersecurity of critical infrastructure amid ongoing conflict with Russia. A member of the Ryuk ransomware gang received a two-year prison sentence for extorting over $1.2 million. The ShinyHunters group claims to have breached the FBI, demanding the retraction of a report criticizing their methods. Vulnerabilities in multiple platforms, including GitHub and WordPress, continue to pose risks, with leaked GitHub App keys still being exploited. Additionally, a new Windows malware, CLOSEDQUORUM, utilizes AI models to determine its actions, showcasing the evolving landscape of AI in cyberattacks.
|
// AI-powered summary generated at 16:00
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP
subsystem in the Linux kernel when handling socket buffer fragments. This
flaw is known as Fragnesia. A local attacker could use this to escalate
privileges, or possibly escape a container. (CVE-2026-43503)
Several security issues w...
It was discovered that the Linux kernel did not properly handle shared page
fragments during socket buffer operations, collectively known as Dirty
Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the
RxRPC networking subsystem when processing paged fragments. A local
attacker could...
Flock Safety, the embattled vendor of mass surveillance technology, has rolled out a handful of new reforms intended to appease the justified nationwide anger that has seen scores of towns cancel or suspend their contracts with the company for automated license plate readers (ALPRs). The reforms are...
An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking. [...]
Security researchers have seen evidence that attackers are attempting to exploit a currently unpatched SQL injection vulnerability in GeoServer, an open-source web server for managing and publishing geospatial data.
The software is widely used by organizations in many indus...
Cloudflare's data shows a clear impact on Internet traffic from Iceland to Spain and Portugal, following the path of totality of the total solar eclipse that occurred on August 12, 2026.
Ameer Assadi discovered that Axios did not properly handle certain
hostnames when applying NO_PROXY rules. An attacker could possibly use
this issue to bypass proxy restrictions and access internal services,
resulting in server-side request forgery. (CVE-2025-62718)
It was discovered that Axios did...
A newly disclosed zero-day flaw in GeoServer is seeing active exploitation efforts, per watchTowr.
The vulnerability, which has yet to be assigned a CVE identifier, is an SQL injection vulnerability in the open-source platform that can lead to remote code execution (RCE). The security defect remain...
Cyberattaque contre la DGFiP : données extraites, des milliers de victimes évoquées et une seconde fuite revendiquée.
Anthropic researchers found AI agents can clash, collude and coordinate in unexpected ways, raising new questions about whether today’s safety tests capture the risks of multi-agent systems.
Some weeks have one big security story. Others bring many smaller updates that are easy to miss but still matter. This week has plenty of them, covering cloud services, AI tools, malware, data breaches, scams, and new attack methods.
The latest ThreatsDay Bulletin puts all of these short updates in...
Cl0p revendique Philips et Shell : compromission reconnue chez Philips, enquête chez Shell, données volées non confirmées.
The Jewelbug hacker group has been carrying out espionage operations targeting governments and militaries while also engaging in cryptocurrency fraud. [...]
In this edition of the Threat Source newsletter, William reflects on the “Make Hazel a Hacker” segment in Beers with Talos, and how cybersecurity is a field where questions can lead to multiple correct answers.
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- x86 architecture;
- InfiniBand drivers;
- Network drivers;
- Thunderbolt and USB4 drivers;
- Network traffic...
L’été, c’est souvent le moment où l’on ouvre les placards, où l’on retrouve quelques vieilles boîtes oubliées et où l’on se demande pourquoi on les avait rangées là . Chez ZATAZ, le ménage est aussi numérique. Ces dernières semaines, plusieurs anciens outils maison ont été ressortis, dépoussiérés, co...
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi
implementation in the Linux kernel did not properly handle aggregated
frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A
physically proximate attacker could use this issue to inject packets.
(CVE-2025-27558...
Hackers began targeting a critical Adobe Commerce flaw that could let unauthenticated attackers hijack customer accounts and access private data. Hackers began targeting CVE-2026-71362 (CVSS score of 9.1), a critical Adobe Commerce flaw, shortly after its public disclosure. The vulnerability allows...
Microsoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch Tuesday. [...]
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- x86 architecture;
- InfiniBand drivers;
- Network drivers;
- Mellanox network drivers;
- File systems infras...