> TODAY'S SUMMARY (19 articles)
Today's cybersecurity landscape highlights several critical threats and vulnerabilities. Citrix confirmed two severe zero-day vulnerabilities in its NetScaler product, prompting CISA to mandate federal agencies patch their systems immediately. Additionally, a SQL injection vulnerability in Roundcube (CVE-2026-48842) is now actively exploited, endangering unpatched webmail servers. Microsoft has suspended a problematic update (KB5002907) that inadvertently disabled Office licenses for some users. Security experts continue to emphasize the importance of monitoring AI agent memory due to potential risks like API key exposure. Lastly, a recent Ubuntu vulnerability could allow attackers to execute arbitrary code through improperly handled file requests.
|
// AI-powered summary generated at 08:00
A new quiz tests user ability to detect fake social accounts.
Researchers say at least six other organizations were also infiltrated in supply chain attacks.
For months, Facebook has been heavily refactoring the entire osquery codebase, migrating osquery away from standard development tools like CMake and integrating it with Facebook’s internal tooling. Their intention was to improve code quality, implement additional tests, and move the project to a mor...
Demand soars for industry roles
Admins look like they’re taking the money and running
Exciting news: We’re hosting the second annual QueryCon on June 20th-21st in New York City, co-sponsored by Kolide and Carbon Black! Register here QueryCon has become the foremost event for the osquery and osql open-source community. QueryCon brings together core maintainers, developers, and end-use...
For every 20 used drives analyzed, at least three contained PII
UK spy agency able to share threat intel in seconds, says boss
Fuzzing is a great way to find bugs in software, but many developers don’t use it. We hope to change that today with the release of Sienna Locomotive, a new open-source fuzzer for Windows that emphasizes usability. Sienna Locomotive aims to make fuzzing accessible to developers with limited security...
Legacy systems and unmanaged devices widen the attack surface in healthcare, says report.
Card-skimming malware targets NBA team's online store.
Bodybuilding.com suffered a security breach.
Tech support, ransomware and extortion losses also climbed
“Blockchainbandit” took advantage of improperly generated keys
Theresa May over-rules ministerial concerns over Chinese spying
Privacy fears of Big Brother state swirl around Brussels
Another unsecured Elasticsearch database spills PII
Hiscox report finds 61% of firms have been hit
Singapore comes back strong after recent data breaches.
The man who reverse-engineered WannaCry has pleaded guilty in a US court to two counts of creating and spreading malware