> TODAY'S SUMMARY (108 articles)
Today's cybersecurity landscape highlights several significant threats and trends. AI models continue to leak sensitive corporate data, with over 13,000 exposed images identified by Glow Security. A major breakthrough in law enforcement occurred with the arrest of a ShinyHunters leader in the Netherlands, coinciding with recent high-profile hacks, including an attack on the FBI. Russian threat actor Star Blizzard has refined phishing techniques, while Citrix NetScaler is facing mass exploitation of a zero-day vulnerability (CVE-2026-88771). Apple has patched a critical zero-day flaw (CVE-2026-86950) linked to sophisticated attacks, underscoring ongoing vulnerabilities in popular software. Additionally, the Pentagon personnel agency breach affecting 3 million individuals emphasizes the persistent risk to sensitive government data.
|
// AI-powered summary generated at 16:00
Patient data impacted by long-running breach at Florida senior care provider
EEMA is leading independent European think tank focused on identity, privacy and trust
A few months ago we discussed the importance of performing active credential hunting for your organization.
This is to ensure clear text credentials in widely accessible locations and source code are identified before an adversary gets a hold of them.
In this post we will explore using built-in oper...
Vardy sues Rooney for publicly accusing her of leaking stories to the British press
Group-IB report details deceptively simple tactics of âFxmspâ
Les marqueurs techniques suivants sont associĂ©s au groupe cybercriminel TA505 (voir la publication CERTFR-2020-CTI-006). Ils peuvent ĂȘtre utilisĂ©s Ă des fins de recherche de compromission dans des journaux historiques ou de dĂ©tection. Mise Ă jour du 10 fĂ©vrier 2021 : un nouveau rapport dĂ©taillant...
Watchguard warns of persistently evasive attackers
Shared browser risk for personal information
The Shadowbunny TTP in the PenTest Magazine The latest edition of the PenTest Magazine features an article of mine about using virtual machines (VMs) during lateral movement to establish persistence and evade detections.
A few years back when I came up with the idea of using VMs for lateral movement...
Cyber-criminal tries to blackmail Commonwealth Games gold medalist swimmer via Facebook
US police sitcom named show most targeted by malicious threat actors
As a company, we believe Black lives matter. In the face of continued police brutality, racial disparities in law enforcement, and limited accountability, we demand an end to systemic racism, endorse restrictions on police use of force, and seek greater accountability for police actions. We believe...
Digital transformation in cybersecurity an increasing priority
Keizer coughs up the cash to retrieve files encrypted by cyber-criminals
Some organization have this interesting concept of a bug jail to prevent new feature development when there are too many existing flaws in the system.
For instance, if an engineer has 5 or more bugs assigned they arenât allowed to work on anything else but fixing their bugs.
What is the Security Bug...
More action needed to enable regulator, praise proactivity and enable automated moderation in Online Harms plan
DCMS details online harms plans
Upgradeable contracts are not as safe as you think. Architectures for upgradeability can be flawed, locking contracts, losing data, or sabotaging your ability to recover from an incident. Every contract upgrade must be carefully reviewed to avoid catastrophic mistakes. The most common delegatecall p...
All new domains will automatically preload from September
Long-term flexible working plans require digital changes