> TODAY'S SUMMARY (13 articles)
Today's cybersecurity landscape highlights two critical zero-day vulnerabilities in Citrix NetScaler (CVE-2026-88771 and CVE-2026-88772), which have been actively exploited for remote code execution before patches were available. Cloudflare also addressed a significant flaw in its Containers service that could expose customer data across tenants. Additionally, Microsoft SharePoint vulnerability (CVE-2026-65660) has been added to CISA's KEV catalog, indicating it is being exploited in the wild. In the cybercrime arena, a Kosovo national faces severe penalties for operating a marketplace selling stolen data and fraud tools. As automated traffic surges, the ongoing evolution of AI continues to reshape the cybersecurity landscape, as noted in Cloudflare's annual founders' letter.
|
// AI-powered summary generated at 20:00
Remember last December’s Empire Hacking? The one where we dedicated the event to sharing the best information about blockchain and smart contract security? Let’s do that again, and let’s make it a tradition; a half-day mini conference focused exclusively on a single topic every December. On December...
Instagram's Download Your Data tool potentially exposed passwords of Instagram users.
A Voxox database was left without password protection, exposing 2FA codes in real time.
We wanted to make up for missing the first three Devcons, so we participated in this year’s event through a number of talks, a panel, and two trainings. For those of you who couldn’t join us, we’ve summarized our contributions below. We hope to see you there next year. Using Manticore and Symbolic E...
Users worldwide have been impacted by issues with Microsoft 2FA in Office 365 and Azure
Vision Direct notifies customers of November data compromise
S’il est nécessaire d’avoir recours aux patchs de sécurité pour protéger vos composants industriels, ils peuvent s’avérer contre productif en amenant à se focaliser sur les vulnérabilités d’un système plutôt que sur des solutions de protection globale. Alors, patch ou [...] Lire la suite
Survey finds 63% of respondents are now more likely to cross reference email domains with legitimate retailers’ URLs
The renamed agency will oversee cybersecurity under a reorganization bill that went to the White House for the president's signature.
Guidance for risk assessors, and developers of applications which will be run on devices handling OFFICIAL data.
BlackBerry will include Cylance's AI offerings to enable the enterprise of things.
Employee mobility and satisfaction are the main drivers for enabling BYOD.
Building and using cryptographic libraries is notoriously difficult. Even when each component of the system has been implemented correctly (quite difficult to do), improperly combining these pieces can lead to disastrous results. Cryptography, when rolled right, forms the bedrock of any secure appli...
Senior politician appeared confused over basic questions
Response to committee report lacked urgency, says chair
Smart contracts can be compromised: they can have bugs, the owner’s wallet can be stolen, or they can be trapped due to an incorrect setting. If you develop a smart contract for your business, you must be prepared to react to events such as these. In many cases, the only available solution is to dep...
Researchers find major flaws which could put children in danger
Is collaborating and sharing threat intelligence an option or a responsibility?
Keeping up with compliance in a post-GDPR world.
What are the common strategies that will harden defenses in the NSA’s cybersecurity threat operations center and industries' security operations centers?