> TODAY'S SUMMARY (4 articles)
Today's cyber news highlights significant threats and trends in the cybersecurity landscape. Ardit Kutleshi, a Kosovo national, faces 20 years in prison for operating the Rydox cybercrime marketplace, which sold stolen identities and fraud tools. Meanwhile, a critical vulnerability in Microsoft SharePoint (CVE-2026-65660) has been actively exploited, prompting the CISA to issue a patching deadline for federal agencies. Additionally, the recent breach of Gyazo has exposed 23.6 million user records, raising concerns about data security. In another alarming development, two unpatched zero-day vulnerabilities in Citrix NetScaler are being actively exploited, emphasizing the urgent need for organizations to bolster their security measures.
|
// AI-powered summary generated at 12:00
Plaintiffs lose the battle due to time constraints and shift focus to winning the war.
A cybersecurity startup founded by a convicted Anonymous hacker sees its first major capital raise.
Today, we’re going to talk about a hard problem that we are working on as part of DARPA’s Cyber Fault-Tolerant Attack Recovery (CFAR) program: automatically protecting software from 0-day exploits, memory corruption, and many currently undiscovered bugs. You might be thinking: “Why bother? Can’t I j...
A Black Hat survey finds 50% of hackers enter IT systems via Windows 8 and 10.
Names, addresses, phone numbers and card digits could be accessed
Most smart contracts have no verified source code, but people still trust them to protect their cryptocurrency. What’s more, several large custodial smart contracts have had security incidents. The security of contracts that exist on the blockchain should be independently ascertainable. Ethereum VM...
Data-collection tools could be a target for hackers
Plaintiffs and defendants in the Yahoo suit reach a settlement agreement.
A popular trend in smart contract design is to promote the development of upgradable contracts. At Trail of Bits, we have reviewed many upgradable contracts and believe that this trend is going in the wrong direction. Existing techniques to upgrade contracts have flaws, increase the complexity of th...
The US Congress approved a national standard on data breach notifications in financial sector, and states are not happy.
A new phishing campaign uses the subject line “2018 UPDATE: NON RESIDENT ALIEN TAX WITHHOLDING,” says Fortinet.
Alleged hacker is “non-entity,” says Pyongyang
Staff forced to hand-write flight information on white boards
Students blamed for many attacks
Phishing attacks remain successful by leveraging macros.
Lawmakers are critical of the State Department for failure to meet basic cybersecurity standards.
A new survey finds nearly all attacks automatically executed are against outdated code.
Let’s change the way we talk about security, as global news and incidents are creating new threats
Malicious script injected into supplier’s JavaScript library
UK regulator receives 500 calls a week as firms play it safe