> TODAY'S SUMMARY (108 articles)
Today's cybersecurity landscape highlights several significant threats and trends. AI models continue to leak sensitive corporate data, with over 13,000 exposed images identified by Glow Security. A major breakthrough in law enforcement occurred with the arrest of a ShinyHunters leader in the Netherlands, coinciding with recent high-profile hacks, including an attack on the FBI. Russian threat actor Star Blizzard has refined phishing techniques, while Citrix NetScaler is facing mass exploitation of a zero-day vulnerability (CVE-2026-88771). Apple has patched a critical zero-day flaw (CVE-2026-86950) linked to sophisticated attacks, underscoring ongoing vulnerabilities in popular software. Additionally, the Pentagon personnel agency breach affecting 3 million individuals emphasizes the persistent risk to sensitive government data.
|
// AI-powered summary generated at 16:00
Zero-day vulnerabilities found in Treck software library pose threat for millions of IoT devices
Customer complaints trigger investigation into alleged cyber-attack at Wiggle
Some organization have this interesting concept of a bug jail to prevent new feature development when there are too many existing flaws in the system.
For instance, if an engineer has 5 or more bugs assigned they aren’t allowed to work on anything else but fixing their bugs.
What is the Security Bug...
eBay executives accused of cyber-stalking staff at an online newsletter and mailing them live cockroaches
With correct human intervention and data validation, automation can work for businesses
Upgradeable contracts are not as safe as you think. Architectures for upgradeability can be flawed, locking contracts, losing data, or sabotaging your ability to recover from an incident. Every contract upgrade must be carefully reviewed to avoid catastrophic mistakes. The most common delegatecall p...
Financial and employee data regularly being shared between colleagues via email
ASA and IAB set up new UK Scam Ad Alert tool
The elliptic curve digital signature algorithm (ECDSA) is a common digital signature scheme that we see in many of our code reviews. It has some desirable properties, but can also be very fragile. For example, LadderLeak was published just a couple of weeks ago, which demonstrated the feasibility of...
An apparent major DDoS attack was caused by a T-Mobile widespread routing issue
Ivanti study reveals major spike in workload for tech teams
Monte Carlo simulations can be a useful tool to uplevel your red teaming skills and provide a different and fresh perspective for highlighting, discussing and presenting findings.
Red teaming is about challenging an organization. This includes analyzing business processes and methodologies, includin...
As stores go online only, data thieves line up
NCSC says credential harvesting operation has been ongoing since 2018
TL;DR: Can we check if a mutex is locked in Go? Yes, but not with a mutex API. Here’s a solution for use in debug builds. Although you can Lock() or Unlock() a mutex, you can’t check whether it’s locked. While it is a reasonable omission (e.g., due to possible race conditions; see also Why […]
Rappler founder and executive director to appeal conviction for cyber-libel in a Philippines court
Mobile threats distributed via adult content doubled in 2019
Over the last few months, we’ve been fuzzing solc, the standard Solidity smart contract compiler, and we’ve racked up almost 20 (now mostly fixed) new bugs. A few of these are duplicates of existing bugs with slightly different symptoms or triggers, but the vast majority are previously unreported bu...
Delivery Hero confirms Foodora data breach affecting three quarters of a million customers
People regularly use the same passwords across online financial accounts