> TODAY'S SUMMARY (13 articles)
Today's cybersecurity landscape highlights two critical zero-day vulnerabilities in Citrix NetScaler (CVE-2026-88771 and CVE-2026-88772), which have been actively exploited for remote code execution before patches were available. Cloudflare also addressed a significant flaw in its Containers service that could expose customer data across tenants. Additionally, Microsoft SharePoint vulnerability (CVE-2026-65660) has been added to CISA's KEV catalog, indicating it is being exploited in the wild. In the cybercrime arena, a Kosovo national faces severe penalties for operating a marketplace selling stolen data and fraud tools. As automated traffic surges, the ongoing evolution of AI continues to reshape the cybersecurity landscape, as noted in Cloudflare's annual founders' letter.
|
// AI-powered summary generated at 20:00
LastPass claims only Amazon offers customers more secure log-ins
Remember last December’s Empire Hacking? The one where we dedicated the event to sharing the best information about blockchain and smart contract security? Let’s do that again, and let’s make it a tradition; a half-day mini conference focused exclusively on a single topic every December. On December...
Has spam email been defeated, or should we admit we cannot beat it?
Old vulnerabilities persist, because of how vulnerability management and full stack visibility is done
We wanted to make up for missing the first three Devcons, so we participated in this year’s event through a number of talks, a panel, and two trainings. For those of you who couldn’t join us, we’ve summarized our contributions below. We hope to see you there next year. Using Manticore and Symbolic E...
Irisscon opens with a look back at the last 10 years of the Irish CERT, and a call for better government involvement
Sectigo research finds just a third have chosen most secure certs
S’il est nécessaire d’avoir recours aux patchs de sécurité pour protéger vos composants industriels, ils peuvent s’avérer contre productif en amenant à se focaliser sur les vulnérabilités d’un système plutôt que sur des solutions de protection globale. Alors, patch ou [...] Lire la suite
Error meant anyone with an account could view others’ details
Firm under fire for phishy looking email
Guidance for risk assessors, and developers of applications which will be run on devices handling OFFICIAL data.
Mirai was detected attacking non-IoT, targeting unpatched Linux servers.
As users become more aware of threats, phishing campaigns are growing more sophisticated, says Zscaler.
Building and using cryptographic libraries is notoriously difficult. Even when each component of the system has been implemented correctly (quite difficult to do), improperly combining these pieces can lead to disastrous results. Cryptography, when rolled right, forms the bedrock of any secure appli...
A security researcher uses Twitter to warn users about 13 malicious Android apps.
One group attempts to sabotage skimming operation of the other
Juniper Research warns of rising synthetic ID fraud
Nominet stats reveal another sharp increase in phishing and IP abuse
Security is still an Achilles heel in IoT.