> TODAY'S SUMMARY (122 articles)
Today's cybersecurity landscape highlights several significant threats and vulnerabilities. Active exploitation of the critical F5 BIG-IP APM zero-day (CVE-2026-94127) allows unauthenticated remote code execution, prompting urgent updates from the vendor. Similarly, a newly identified WordPress vulnerability (CVE-2026-87902) has transitioned from probing to exploitation, enabling file writing and command execution. On another front, malicious AI agents have been implicated in large-scale phishing campaigns, compromising over 600,000 credit cards. Additionally, Check Point warns of active exploitation of a remote code execution flaw in its Security Gateway VPN. In the U.S., many federal agencies are falling short in complying with CISA's cloud security directives, increasing their risk of attack. Lastly, the cybercrime group ShinyHunters claims to have breached the FBI, demanding a retraction of a report detailing their activities.
|
// AI-powered summary generated at 20:00
This is the latest zero-day released by security researcher Nightmare Eclipse, despite Microsoft publicly threatening to take legal action against them.
Turn partial school badges into actionable leads with S21 School Badge Lookup v2.0, fast offline image intelligence built for CSAM and ICAC investigations worldwide.
The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild.
The post SharePoint Vulnerability Exploited Shortly After PoC Release appeared first on SecurityWeek.
Update Zoom now to protect against critical vulnerabilities that could allow an attacker in the same meeting to run malicious code on your device.
Helix claims nearly a million files, while the logistics biz says operations never hit the brakes
New WindRelay NFC malware paired with SpyNote RAT let a fraudster clone a card mid-call
Read the latest DFIR news – NIST’s new ArtCat digital forensics catalog, Kohberger case methodology, Android intrusion log analysis, offline AI with BelkaGPT, and more.
An AI agent bypassed a gym's booking rules on its own. Here's how autonomous agents find security weaknesses and how to protect your business.
A couple of days ago, Xavier posted about Atuin to gain more insight into the command history. Atuin does a great job of better organizing what is usually handled by "bash&#;x26;#;x5f;history"&#;x26;#;xc2;&#;x26;#;xa0;and collecting meaningful additional data. Our reader David commented...
The FBI warns that cybercriminals are targeting adults' and children's social media and other online accounts to steal sexually explicit images or videos. [...]
A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept browser traffic and route them through a proxy infrastructure.
The extensions, published across at least 40 Chrome Web Store develop...
Fake remote workers can exploit gaps between hiring checks, device delivery, and account access to enter organizations under false identities. Specops Software explains how document verification and biometric liveness checks can help organizations confirm that the person receiving access is the legi...
Updated the build numbers. This is an informational update only.
Most security stories start with something broken. This one starts with everything working as designed. Researchers at Reco have been tracking a campaign they call City-Forum, named after a domain registered in 2002, abandoned, and now resolving to a generic rented server from a German hosting provi...
Microsoft's August Patch Tuesday fixes 421 vulnerabilities, including three zero-days, 62 critical flaws, and dozens of Office remote code execution bugs.
Signal has introduced a feature called automatic key verification, giving users a new way to confirm that nobody has secretly interfered with their encrypted chats. “Signal is always end-to-end encrypted, and automatic key verification provides an additional, streamlined way to confirm that there’s...
ScienceLogic has announced Skylar AI 2.5, expanding secure deployment options for organizations with stringent security, sovereignty, and compliance requirements, while introducing enhancements that strengthen AI performance, operational intelligence, and enterprise integrations. The release further...
Nobody patched the CMS or read the alerts, and ACRO still cannot tell whether info was exfiltrated
Lazarus malware used post-quantum key exchange to protect delivery of a Windows zero-day exploit
AI took center stage, but the clearest lesson was less about what AI can do than about who is accountable when something goes wrong