> TODAY'S SUMMARY (10 articles)
Today's cyber news highlights a range of emerging threats and vulnerabilities. Notably, two unpatched zero-day vulnerabilities in Citrix NetScaler appliances are actively exploited, posing significant risks. Additionally, Microsoft SharePoint's CVE-2026-65660 has been flagged by CISA, indicating ongoing exploitation, with a patching deadline recently issued. The recent Gyazo breach has compromised 23.6 million user records, further emphasizing the growing risk of data exposure. In malware news, a notable report discusses the proliferation of cybercrime marketplaces, exemplified by Ardit Kutleshi's guilty plea for selling stolen data. On the positive side, Cloudflare has addressed a serious cross-tenant flaw that exposed customer data. Overall, the landscape remains dynamic, with AI integration in cybersecurity and malware research continuing to evolve.
|
// AI-powered summary generated at 16:00
Cyber-criminals breathe new life into old tactics and techniques, says Malwarebytes.
New employees discuss how to get ahead in getting a first job in cyber
Finding randomness on the blockchain is hard. A classic mistake developers make when trying to acquire a random value on-chain is to use quantities like future block hashes, block difficulty, or timestamps. The problem with these schemes is that they are vulnerable to manipulation by miners. For exa...
Financial and personal information may have been exposed by contractor
Ransomware costs hit home for under-funded health service
Certaines solutions de sécurité développées pour l’IT peuvent être utilisées pour l’OT (Operational Technology), mais à condition d’être adaptées. Au vu des derniers événements, en particulier le hack hardware « Supermicro », on peut se demander si l’inverse ne serait pas une [...] Lire la suite
Some 14m had virtually all their profile info scraped
One Amazon data center revealed by WikiLeaks runs under the name Vandalay Industries
Of the nearly 200 papers on software fuzzing that have been published in the last three years, most of them—even some from high-impact conferences—are academic clamor. Fuzzing research suffers from inconsistent and subjective benchmarks, which keeps this potent field in a state of arrested developme...
New iteration of Magecart malware obfuscates data collection, says The Media Trust.
Q2 2018 saw 1.6m attacks on gaming and gambling sector, according to the ThreatMetrix cybercrime report.
We came away from ETH Berlin with two overarching impressions: first, many developers were hungry for any guidance on security, and second; too few security firms were accessible. When we began taking on blockchain security engagements in 2016, there were no tools engineered for the work. Useful doc...
Banking association suggests levy to help compensate victims
Unprotected cloud database again to blame
We’re proud to announce the release of Winchecksec, a new open-source tool that detects security features in Windows binaries. Developed to satisfy our analysis and research needs, Winchecksec aims to surpass current open-source security feature detection tools in depth, accuracy, and performance wi...
Bloomberg doubles down with latest Supermicro allegations
Continued widespread use of Symantec certificates has led to Mozilla to delay Firefox updates
Phishing resiliency on the rise as reporting rates increase
Cifas stats also reveal more under-21s are victims of fraud
Blueliv stats reveal declines in other regions this year