> TODAY'S SUMMARY (122 articles)
Today's cybersecurity landscape highlights several significant threats and vulnerabilities. Active exploitation of the critical F5 BIG-IP APM zero-day (CVE-2026-94127) allows unauthenticated remote code execution, prompting urgent updates from the vendor. Similarly, a newly identified WordPress vulnerability (CVE-2026-87902) has transitioned from probing to exploitation, enabling file writing and command execution. On another front, malicious AI agents have been implicated in large-scale phishing campaigns, compromising over 600,000 credit cards. Additionally, Check Point warns of active exploitation of a remote code execution flaw in its Security Gateway VPN. In the U.S., many federal agencies are falling short in complying with CISA's cloud security directives, increasing their risk of attack. Lastly, the cybercrime group ShinyHunters claims to have breached the FBI, demanding a retraction of a report detailing their activities.
|
// AI-powered summary generated at 20:00
Oracle Linux 10 has received updates for udisks2 packages, enhancing btrfs support and addressing CVE-2026-7867 related to fstab mount authorization.
Oracle Linux has released an update for gstreamer1-plugins-good packages to address CVE-2026-18649, fixing an issue related to excessive memory allocation from malicious RTP packets.
It was discovered that libgit2 incorrectly handled the Git Smart Protocol.
A remote attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. This issue only affected Ubuntu 14.04
LTS and Ubuntu 16.04 LTS. (CVE-2016-10128)
It was discovered that libgit2 incorrec...
Oracle Linux has released updated rpms for version 10 to address a double-free vulnerability (CVE-2026-55995) in isns-utils and its libraries for both x86_64 and aarch64 architectures.
More than 737 browser extensions published on the Chrome Web Store impersonated well-known VPN and proxy services while routing users' traffic through SOCKS5 proxies operated by a single provider. [...]
Drones IA : collecte, conservation et floutage soulèvent des enjeux majeurs de vie privée.
Debian fixed security vulnerabilities in the Lemonldap::NG web SSO system, specifically related to insufficient access enforcement with GitHub and LinkedIn authentication backends in version 2.21.2+ds-1+deb13u3.
Debian has addressed multiple vulnerabilities in Flatpak that could lead to privilege escalation, sandbox escape, or information disclosure, urging users to upgrade to version 1.16.6-1~deb13u2.
China-linked hackers reportedly used eight AI agents to breach a government network, steal data and compromise accounts with minimal human oversight. Israeli cybersecurity firm Dream documented what looks like the first fully autonomous, end-to-end AI hacking operation against a government target. O...
The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India.
The activit...
Leaked passwords, social engineering and spoofed social media sites are among the tools hackers are using to gather individuals' private content and sell it online, the FBI said.
An extortion gang known for targeting transportation companies and private equity firms has taken credit for a breach at Uber Freight.
Israeli cyber firm Dream said the framework adapted mid-operation, corrected its mistakes and expanded as it went along.
The post Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan appeared first on CyberScoop.
Dans un avis, l'autorité danoise de protection des données a estimé qu'un responsable du traitement, ayant manqué à son obligation de suppression de données, pouvait néanmoins les conserver et les communiquer à un tiers, dès lors qu'une nouvelle finalité légitime, en l'occurrence la recherche scient...
L'autorité britannique de protection des données a prononcé une réprimande à l'encontre du Bureau des casiers judiciaires (ACRO) en raison de défaillances fondamentales en matière de cybersécurité, notamment une gestion des correctifs et une surveillance des alertes inadéquates, qui ont permis un ac...
Security researchers have disclosed new "Plug and Pwn" attacks that abuse the Windows Plug and Play feature to trigger Windows into installing vulnerable or insecure vendor software and gain SYSTEM privileges. [...]
Le Contrôleur européen de la protection des données (CEPD) a émis son avis 17/2026 concernant la proposition de la Commission européenne visant à modifier le Règlement (UE) 2018/1725, qui régit le traitement des données personnelles par les institutions et organes de l'Union.La proposition vise à ha...
Le ministère de l'Intérieur et de l'Administration polonais a répondu aux objections de l'autorité de protection des données (UODO) concernant la légalité de la collecte et de la conservation des données biométriques et génétiques des agents de police.En juillet 2026, le président de l'Autorité de p...
North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. [...]
L'Autorité polonaise de protection des données (UODO) a communiqué sur un incident de cybersécurité impliquant la société MyDr et a rappelé les démarches à suivre pour les personnes concernées par une violation de données.Suite à des rapports médiatiques sur un possible incident de cybersécurité et...