> TODAY'S SUMMARY (13 articles)
Today's cybersecurity landscape highlights two critical zero-day vulnerabilities in Citrix NetScaler (CVE-2026-88771 and CVE-2026-88772), which have been actively exploited for remote code execution before patches were available. Cloudflare also addressed a significant flaw in its Containers service that could expose customer data across tenants. Additionally, Microsoft SharePoint vulnerability (CVE-2026-65660) has been added to CISA's KEV catalog, indicating it is being exploited in the wild. In the cybercrime arena, a Kosovo national faces severe penalties for operating a marketplace selling stolen data and fraud tools. As automated traffic surges, the ongoing evolution of AI continues to reshape the cybersecurity landscape, as noted in Cloudflare's annual founders' letter.
|
// AI-powered summary generated at 20:00
US court says products will remain off-limits to federal government
US site formerly known as Viyet was affected
Earlier this year, the Web3 Foundation (W3F) commissioned Trail of Bits for a security review and assessment of the risks in storing cryptocurrency. Everyone who owns cryptocurrency — from large institutions to individual enthusiasts — shares the W3F’s concerns. In service to the broader community,...
Hotel chain Marriott suffers data breach with the sensitive details of 500 million customers possibly at risk
A study finds IT security teams underestimating value of critical assets.
Remember last December’s Empire Hacking? The one where we dedicated the event to sharing the best information about blockchain and smart contract security? Let’s do that again, and let’s make it a tradition; a half-day mini conference focused exclusively on a single topic every December. On December...
Holiday gift card spear phishing attack targets office managers.
Over 100,000 officers will gain access to Cisco Network Academy
We wanted to make up for missing the first three Devcons, so we participated in this year’s event through a number of talks, a panel, and two trainings. For those of you who couldn’t join us, we’ve summarized our contributions below. We hope to see you there next year. Using Manticore and Symbolic E...
Vulnerabilities enable hacking camera feeds and other restricted functions.
UK intelligence service stresses default position is to disclose
S’il est nécessaire d’avoir recours aux patchs de sécurité pour protéger vos composants industriels, ils peuvent s’avérer contre productif en amenant à se focaliser sur les vulnérabilités d’un système plutôt que sur des solutions de protection globale. Alors, patch ou [...] Lire la suite
Employee risk and third-party visibility continues to be a challenge
Credential-stuffing attack targets rewards points from DD Perks account holders.
Researchers discover a new family of injections dubbed EternalSilence.
Since its release in 2017, Headless Chrome has grown popular among DevOps and attackers.
Three years of attacks caused $30m in losses for hospitals, cities and others
Personal info was left publicly accessible for at least two weeks
Attackers may have obtained names, emails and hashed passwords
Attacker uses malicious code to gain legitimate access to JavaScript library EventStream.