> TODAY'S SUMMARY (4 articles)
Today's cyber news highlights significant threats and trends in the cybersecurity landscape. Ardit Kutleshi, a Kosovo national, faces 20 years in prison for operating the Rydox cybercrime marketplace, which sold stolen identities and fraud tools. Meanwhile, a critical vulnerability in Microsoft SharePoint (CVE-2026-65660) has been actively exploited, prompting the CISA to issue a patching deadline for federal agencies. Additionally, the recent breach of Gyazo has exposed 23.6 million user records, raising concerns about data security. In another alarming development, two unpatched zero-day vulnerabilities in Citrix NetScaler are being actively exploited, emphasizing the urgent need for organizations to bolster their security measures.
|
// AI-powered summary generated at 12:00
COBALT DICKENS is likely responsible for large campaign targeting university credentials.
The T-Mobile security team discovered and stopped unauthorized access of customer data.
Access Control Lists (ACLs) are an integral part of the Microsoft Windows security model. In addition to controlling access to secured resources, they are also used in sandboxing, event auditing, and specifying mandatory integrity levels. They are also exceedingly painful to programmatically manipul...
A single file containing nearly all Texas voter records was left on unsecured server.
NSA leaker Winner revealed true extent of Russian election hacking
An increasing number of organizations and companies (including the federal government) rely on open-source projects in their security operations architecture, secure development tools, and beyond. Open-source solutions offer numerous advantages to development-savvy teams ready to take ownership of t...
US chain caught out via POS compromise
Public exploit available for CVSS 10.0 vulnerability
This spring and summer, as an intern at Trail of Bits, I researched modeling fault attacks on RSA signatures. I looked at an optimization of RSA signing that uses the Chinese Remainder Theorem (CRT) and induced calculation faults that reveal private keys. I analyzed fault attacks at a low level rath...
Two recent ransomware campaigns have earned attackers over $1 million.
New malicious operation by the Lazarus group penetrates Asian cyryptocurrency exchange network
Attackers exploiting high-wattage IoT devices could cause large-scale blackouts.
To fill the jobs gap, cybersecurity educators and investors need to focus on diversity. And a new scholarship helps them do it.
More than $1m is lost every minute to cybercrime, while 1861 people fall victim to scams
Local authorities woefully exposed to threats, FOI study reveals
Ombudsman says lenders can’t simply blame customers for falling victim
Attack appears to have been foiled early on by Democrats
Completing its acquisition of AlienVault, AT&T will turn the threat intelligence vendor into its standalone Cybersecurity Solutions Division.
A new exploit lets an attacker take over applications and servers via Ghostscript
A new survey shows that companies still have work to do to get GDPR compliant