> TODAY'S SUMMARY (4 articles)
Today's cyber news highlights significant threats and trends in the cybersecurity landscape. Ardit Kutleshi, a Kosovo national, faces 20 years in prison for operating the Rydox cybercrime marketplace, which sold stolen identities and fraud tools. Meanwhile, a critical vulnerability in Microsoft SharePoint (CVE-2026-65660) has been actively exploited, prompting the CISA to issue a patching deadline for federal agencies. Additionally, the recent breach of Gyazo has exposed 23.6 million user records, raising concerns about data security. In another alarming development, two unpatched zero-day vulnerabilities in Citrix NetScaler are being actively exploited, emphasizing the urgent need for organizations to bolster their security measures.
|
// AI-powered summary generated at 12:00
Mac App Store app was exfiltrating data to China
Major two-year study claims e-systems are too vulnerable
Most smart contracts have no verified source code, but people still trust them to protect their cryptocurrency. What’s more, several large custodial smart contracts have had security incidents. The security of contracts that exist on the blockchain should be independently ascertainable. Ethereum VM...
Bouxtie founder faces jail
Africa, Asia and Latin America most targeted for ICS computer attacks, finds Kaspersky Lab
A popular trend in smart contract design is to promote the development of upgradable contracts. At Trail of Bits, we have reviewed many upgradable contracts and believe that this trend is going in the wrong direction. Existing techniques to upgrade contracts have flaws, increase the complexity of th...
Researchers break certificate authorities' domain validation
Targeted mobile-based attack against Iranian citizens discovered by Check Point
Access Control Lists (ACLs) are an integral part of the Microsoft Windows security model. In addition to controlling access to secured resources, they are also used in sandboxing, event auditing, and specifying mandatory integrity levels. They are also exceedingly painful to programmatically manipul...
ProtonMail investigated Apophis Squad to find poor opsec
Lazarus Group member Park allegedly worked for government front company
An increasing number of organizations and companies (including the federal government) rely on open-source projects in their security operations architecture, secure development tools, and beyond. Open-source solutions offer numerous advantages to development-savvy teams ready to take ownership of t...
Hackers compromised website and mobile ap
Ad blockers don't go far enough to protect against malvertising, finds The Media Trust
State of the SOAR Report finds SOCs only respond to 12,000 alerts per week
The company will offer rewards of up to $10,000
Marketing company did not seek recipient consent
One member suspected of being current or former security bod
Alleges that company misled over its preparedness
Hackers received a historically high payout at H1-702 2018.