> TODAY'S SUMMARY (122 articles)
Today's cybersecurity landscape highlights several significant threats and vulnerabilities. Active exploitation of the critical F5 BIG-IP APM zero-day (CVE-2026-94127) allows unauthenticated remote code execution, prompting urgent updates from the vendor. Similarly, a newly identified WordPress vulnerability (CVE-2026-87902) has transitioned from probing to exploitation, enabling file writing and command execution. On another front, malicious AI agents have been implicated in large-scale phishing campaigns, compromising over 600,000 credit cards. Additionally, Check Point warns of active exploitation of a remote code execution flaw in its Security Gateway VPN. In the U.S., many federal agencies are falling short in complying with CISA's cloud security directives, increasing their risk of attack. Lastly, the cybercrime group ShinyHunters claims to have breached the FBI, demanding a retraction of a report detailing their activities.
|
// AI-powered summary generated at 20:00
Deloitte has expanded AI Controls and Assurance services and solutions designed to help organizations confidently adopt, scale and govern AI across the enterprise. From early exploration to enterprise deployment, Deloitte’s enhanced services provide end-to-end support across the AI lifecycle, combin...
The cybersecurity startup will use the fresh investment to scale its product, engineering, sales, and marketing teams.
The post Mindgard Raises $30 Million to Protect AI Systems appeared first on SecurityWeek.
Gunra actors are using stealth to exfiltrate vast volumes of data from Microsoft services, US and Korean agencies have warned
Unread antivirus alerts and an unpatched content management system exposed Britain's ACRO to three separate data breaches, according to a reprimand notice.
Researchers observed the novel campaign exploiting unauthenticated guest access to quietly enumerate and exfiltrate exposed data from both platforms.
The post Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset appeared first on SecurityWeek.
Gives a whole new meaning to Safe Mode
Signal has also made a security announcement: an automatic key verification feature to complement its safety number system.
The post WhatsApp Unveils New Scam Alert Feature appeared first on SecurityWeek.
This month’s update features about five times the volume of patches Microsoft was shipping in a typical month before AI-assisted vulnerability discovery took hold.
The US National Institute for Standards and Technology wants to modernize its National Vulnerability Database to embrace AI-powered vulnerability research
Hackers have already begun using a proof-of-concept (PoC) exploit for a critical Microsoft SharePoint vulnerability, published by cybersecurity company Rapid7 on Tuesday. [...]
Researchers disclosed the bug to Microsoft after examining a long-running campaign by North Korean hackers to exploit the job application process.
Security researchers found that in less than 60 seconds, they could open a hatch on a plane’s exterior, plug in a tiny device, and redirect the aircraft’s autopilot or sabotage its flight plan.
The NCSC wants to collaborate with organisations developing technologies and approaches for secure, resilient and deployable private 5G
The North Korea-linked Lazarus group is using fake job offers, trojanized PDF software and a Windows zero-day in attacks aimed primarily at the defense sector, Check Point researchers have found. The activity is part of Operation Dream Job, a long-running campaign in which attackers pose as recruite...
A newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API calls let researchers recover internal reasoning and secrets from session logs, including API keys and passwords.
The weakness affected encrypted reasoning objects used by the providers' reasonin...
Enterprise defenses are tuned to catch the attacks that make noise. This year's data shows attackers winning by making none.
According to Picus Labs' new Blue Report 2026, which measured more than 338 million real attack simulations across actual client production environments in the first half of...
Affecting European contract logistics operations at eight Ceva warehouses, the incident caused shipment delays for multiple customers.
The post Ceva Logistics Operations Disrupted by Cyberattack appeared first on SecurityWeek.
A convincing fake version of the widely used CCleaner utility is being used to deliver a multi-stage Windows malware that ultimately abuses Google Chrome for credential theft and surveillance.
Researchers from Malwarebytes found the campaign distributing a malicious Chrome...
​Signal has introduced Automatic Key Verification, a new security feature that gives users a new way to ensure their encrypted chats haven't been intercepted. [...]
Victoria is the first stop as privacy campaigners warn the technology is becoming routine