> TODAY'S SUMMARY (101 articles)
Today's cybersecurity news highlights several significant threats and trends. OpenAI has partnered with Ukraine to enhance the cybersecurity of critical infrastructure amid ongoing conflict with Russia. A member of the Ryuk ransomware gang received a two-year prison sentence for extorting over $1.2 million. The ShinyHunters group claims to have breached the FBI, demanding the retraction of a report criticizing their methods. Vulnerabilities in multiple platforms, including GitHub and WordPress, continue to pose risks, with leaked GitHub App keys still being exploited. Additionally, a new Windows malware, CLOSEDQUORUM, utilizes AI models to determine its actions, showcasing the evolving landscape of AI in cyberattacks.
|
// AI-powered summary generated at 16:00
VMware vCenter : CVE-2026-59310 est exploitée activement, avec plus de 360 IP victimes, dont en France.
À Pattaya, un lecteur de ZATAZ signale une fraude NFC. Son histoire éclaire la menace Ghost Tap suivie par l’EPC.
Debian released DSA-6436-1, addressing critical security vulnerabilities in Chromium that could allow arbitrary code execution, denial of service, or information disclosure; users are advised to upgrade.
Beyond Mirai’s usual functions, the new code features include encrypted communications with command-and-control servers and a “sniffer” that looks for default access credentials.
CRM provider Beacon has revealed that a compromised AWS access key was the likely root cause of the breach of 1500 UK charities’ data
Une fuite attribuée à Maisons du Monde apparaît avant une période financière critique. Le timing du pirate interroge.
Hardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping and logistics provider, was hacked [...]
Contractors could surveil and disrupt foreign criminal networks, provided they follow strict rules and put up $1M
Afghan telecom providers and South Asian critical infrastructure organizations have emerged as the target of a new ongoing campaign that delivers a previously undocumented backdoor called PATCHCORD.
According to Acronis Threat Research Unit (TRU), the backdoor is a compiled C/C++ implant delivered...
Google Cloud has set a 2027 deadline to mitigate store-now-decrypt-later risks as part of its post-quantum cryptography roadmap, with wider migration goals extending through 2028
A major new HMICFRS report exposes the urgent need for proactive, mandatory mental health support for digital forensic investigators and others working daily with online child sexual abuse material.
SPONSORED FEATURE: Your M365 and Azure data might not be as safe as you think from ransomware; time for a reality check
Why — and for whom — artificial intelligence is now churning out books, how they end up on Amazon, and what risks this poses for readers.
Significant cybersecurity M&A deals announced by Barracuda, CrowdStrike, Cyera, Okta, Palo Alto Networks, and Qualcomm.
The post Cybersecurity M&A Roundup: 21 Deals Announced in July 2026 appeared first on SecurityWeek.
President Trump signed a National Security Presidential Memorandum on August 12 allowing vetted private companies to run offensive cyber operations against foreign threat actors, under the control and oversight of the US government.
The post White House authorizes private US companies to hack foreig...
And will today’s surge in AI-driven vulnerability discovery eventually make tomorrow’s software safer?
The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches.
The post Adobe Commerce Bug Targeted Immediately After Disclosure appeared first on SecurityWeek.
The new order sweeps away decades of existing U.S. cybersecurity policy prohibiting private companies from conducting 'hack back' attacks or offensive cyber operations.
AI coding tools can introduce unvetted or hallucinated open source dependencies faster than traditional security reviews can keep pace. ActiveState explains why organizations should govern packages at the point of selection, before they enter the development pipeline. [...]
Attackers exploited a critical-severity vCenter flaw five days after Broadcom disclosed it