> TODAY'S SUMMARY (19 articles)
Today's cybersecurity landscape highlights several critical threats and vulnerabilities. Citrix confirmed two severe zero-day vulnerabilities in its NetScaler product, prompting CISA to mandate federal agencies patch their systems immediately. Additionally, a SQL injection vulnerability in Roundcube (CVE-2026-48842) is now actively exploited, endangering unpatched webmail servers. Microsoft has suspended a problematic update (KB5002907) that inadvertently disabled Office licenses for some users. Security experts continue to emphasize the importance of monitoring AI agent memory due to potential risks like API key exposure. Lastly, a recent Ubuntu vulnerability could allow attackers to execute arbitrary code through improperly handled file requests.
|
// AI-powered summary generated at 08:00
Essex cyber-criminal was part of Russian Angler EK gang
The Baldr stealer malware incorporates three threat actors, says researchers.
Exciting news: We’re hosting the second annual QueryCon on June 20th-21st in New York City, co-sponsored by Kolide and Carbon Black! Register here QueryCon has become the foremost event for the osquery and osql open-source community. QueryCon brings together core maintainers, developers, and end-use...
Cyber-criminals are using digital doppelgangers traded in dark web marketplaces to avoid detection.
A researcher discovers three vulnerabilities in Verizon's home router.
Fuzzing is a great way to find bugs in software, but many developers don’t use it. We hope to change that today with the release of Sienna Locomotive, a new open-source fuzzer for Windows that emphasizes usability. Sienna Locomotive aims to make fuzzing accessible to developers with limited security...
European Data Protection Supervisor follows up on Dutch investigation
Hoya saw output drop 40% after malware hit factories
For my winternship and springternship at Trail of Bits, I researched novel techniques for symbolic execution on cryptographic protocols. I analyzed various implementation-level bugs in cryptographic libraries, and built a prototype Manticore-based concolic unit testing tool, Sandshrew, that analyzed...
Compensation claimants have personal details exposed
Penetration testers intercept CT scans, and inject or remove cancerous nodes on scans.
It is time for the second installment of our efforts to reproduce original fuzzing research on modern systems. If you haven’t yet, please read the first part. This time we tackle fuzzing on Windows by reproducing the results of “An Empirical Study of the Robustness of Windows NT Applications Using R...
Attackers impersonate tax services and payroll companies ahead of US tax filing deadline.
After only 16 months on the job, Secretary of DHS submits letter of resignation.
TLS 1.3 represents the culmination of over two decades of experience in deploying large-scale transport security. For the most part it simplifies and improves the security of TLS and can act as a drop-in replacement for TLS 1.2. However, one new feature in the protocol represents a significant secur...
Tenable finds skills shortages and visibility key barriers to effective security
DETER Act looks to punish Russia and other rogue nations
Local authority in the dock over 2017 incident
Exploit attempts in a DNS hijacking campaign originated from hosts on Google Cloud Platform.
Researchers discover dozens of cyber-fraud services on Facebook.