> TODAY'S SUMMARY (19 articles)
Today's cybersecurity landscape highlights several critical threats and vulnerabilities. Citrix confirmed two severe zero-day vulnerabilities in its NetScaler product, prompting CISA to mandate federal agencies patch their systems immediately. Additionally, a SQL injection vulnerability in Roundcube (CVE-2026-48842) is now actively exploited, endangering unpatched webmail servers. Microsoft has suspended a problematic update (KB5002907) that inadvertently disabled Office licenses for some users. Security experts continue to emphasize the importance of monitoring AI agent memory due to potential risks like API key exposure. Lastly, a recent Ubuntu vulnerability could allow attackers to execute arbitrary code through improperly handled file requests.
|
// AI-powered summary generated at 08:00
Facebook tells all to Business Insider, confirming that the upload was unintentional.
A privacy foundation found unsecured databases that held LinkedIn data, including email addresses.
For months, Facebook has been heavily refactoring the entire osquery codebase, migrating osquery away from standard development tools like CMake and integrating it with Facebook’s internal tooling. Their intention was to improve code quality, implement additional tests, and move the project to a mor...
CyberInt found TA505 is using tactics and a remote administration tool, developed by TektonIT.
Following the tragic events in Paris, cyber-criminals have taken advantage of people's goodwill.
Exciting news: We’re hosting the second annual QueryCon on June 20th-21st in New York City, co-sponsored by Kolide and Carbon Black! Register here QueryCon has become the foremost event for the osquery and osql open-source community. QueryCon brings together core maintainers, developers, and end-use...
Forrester claims public cloud native security spend will grow fastest
Terbium Labs reveals old, incomplete and repackaged how-to guides flooding the dark web
Fuzzing is a great way to find bugs in software, but many developers don’t use it. We hope to change that today with the release of Sienna Locomotive, a new open-source fuzzer for Windows that emphasizes usability. Sienna Locomotive aims to make fuzzing accessible to developers with limited security...
New state-sponsored groups goes after registrars
The government department responsible for implementing the GDPR has committed a faux pas with UK journalists which could mean it has broken its own rules
For my winternship and springternship at Trail of Bits, I researched novel techniques for symbolic execution on cryptographic protocols. I analyzed various implementation-level bugs in cryptographic libraries, and built a prototype Manticore-based concolic unit testing tool, Sandshrew, that analyzed...
The UK will become "the first country in the world" to bring in age-verification for online pornography, according to the Department for Digital, Culture, Media and Sport (DCMS).
A new password and data stealing operation that has been targeting China has started to infect users worldwide using a rootkit driver
Distil Networks reveals financial services is most affected sector
European Commission effectively confirms that Parliament vote was ill-informed
A dozen customers suspected of being compromised
New survey finds concerning approach to security testing before productS are launched into the market
A spear-phishing email campaign targeting Ukraine could have been active as early as 2014.
Charity, school and social support websites are being blocked by "overzealous" web filters designed to protect children from harmful online content.