> TODAY'S SUMMARY (108 articles)
Today's cybersecurity landscape highlights several significant threats and trends. AI models continue to leak sensitive corporate data, with over 13,000 exposed images identified by Glow Security. A major breakthrough in law enforcement occurred with the arrest of a ShinyHunters leader in the Netherlands, coinciding with recent high-profile hacks, including an attack on the FBI. Russian threat actor Star Blizzard has refined phishing techniques, while Citrix NetScaler is facing mass exploitation of a zero-day vulnerability (CVE-2026-88771). Apple has patched a critical zero-day flaw (CVE-2026-86950) linked to sophisticated attacks, underscoring ongoing vulnerabilities in popular software. Additionally, the Pentagon personnel agency breach affecting 3 million individuals emphasizes the persistent risk to sensitive government data.
|
// AI-powered summary generated at 16:00
Use of stalkerware in the UK correlates with a worrying increase in domestic abuse queries
Phishing messages used COVID-19 as a lure to access Office 365 accounts
Amazon Bug Bounty! Great news: Amazon is now offering bounties via a security vulnerabiltiy research program
Bad news: AWS is out of scope!
When I read this I remembered that a few years ago I found persistent Cross-Site-Scripting on the AWS Console.
This post is a write up on how I found the XSS ba...
69% say BYOD is embraced by their organization
Around 15 billion credentials are in circulation in cyber-criminal marketplaces
I’m excited that Feedspot ranked this blog (Embrace the Red) the number #10 pentest blog out there.
Subscribe and check-in regularly for new content related to offensive security engineering, penetration testing and red teaming.
You can also follow me on Twitter @wunderwuzzi23.
Cheers.
Peter Christou joins bot mitigation and detection firm BotRx as EVP of global sales
Researchers at vpnMentor find another misconfigured database
Gemini Advisory warns Keeper group is still at large
Portuguese energy giant was hit with Ragnar Locker in April
UK startups have nearly eclipsed the total raised last year already despite COVID-19
Russian BEC group Cosmic Lynx has been operating on the quiet for at least a year, says Agari
With Project Freta, Microsoft claims to have made it easy to scan thousands of virtual machines invisibly
A good drone pilot is hard to find, unless you happen to be a researcher from Ben-Gurion University of the Negev
The manufacturing sector made 62% of ransomware payments last year
Platforms will not work with police on data access until international consensus
Angry investors still trying to get their money back from VaultAge Solutions
Hundreds of millions laundered from cybercrimes
17 companies to benefit from year-long innovation scheme
Registration is now open for Infosecurity’s two-day virtual event