> TODAY'S SUMMARY (17 articles)
Today's cybersecurity landscape highlights several critical threats and trends. A newly disclosed vulnerability in WordPress (CVE-2026-87902) is being exploited by attackers, allowing remote code execution without authentication. Additionally, a concerning statistic reveals that 97% of ransomware victims had multi-factor authentication (MFA) enabled, suggesting the need to identify and address other security gaps. Meanwhile, the emergence of CLOSEDQUORUM malware, which utilizes AI models for decision-making, raises alarms about the sophistication of cyber threats. Europe is witnessing a rise in cybercrime targeting public services and technology providers, emphasizing the need for enhanced security measures. Finally, vulnerabilities in urllib3 and ImageMagick have been reported, indicating ongoing risks in commonly used software.
|
// AI-powered summary generated at 08:01
Overall, respondents said that 70% of the responsibility for protecting and securing customer data lies with companies.
Outdated AV software significant problem when it comes to protecting patient records from malware
John Oliver may have written off 2016, but we’re darn proud of all that we accomplished and contributed this year. We released a slew of the security tools that help us -and you- work smarter, and promoted a few more that deserved recognition. We helped the New York City InfoSec community build a fo...
Webmaster allegedly hoovered up log-ins from sites he designed
Police bosses warn businesses of shifting trend
We’re back with our promised second installment discussing control flow integrity. This time, we will talk about Microsoft’s implementation of control flow integrity. As a reminder, control flow integrity, or CFI, is an exploit mitigation technique that prevents bugs from turning into exploits. For...
A cross-site scripting flaw in McDonald’s website could allow an attacker to steal and decrypt a password from a registered user.
Launches open source, generic and interoperable directory of public keys
I think you’ll agree when I say: there’s no VPN option on the market designed with equal emphasis on security and ease of use. That changes now. Today we’re introducing Algo, a self-hosted personal VPN server designed for ease of deployment and security. Algo automatically deploys an on-demand VPN s...
Ransomware ruled out by UK’s largest NHS Trust
EU agency looks to support manufacturers and other stakeholders
Poorly trained cops leave data downloads unencrypted and with no audit trail
CA discovers five-month-old domain validation bug
Those who use two-factor authentication (2FA) admit that they receive complaints about it from their users.
Japanese researchers raise biometric security fears
Experts finger same culprit as December 2015 attack
The audit program, based on the NIST Cybersecurity Framework, provides direction on cyber-governance.
Royal and Sun Alliance (RSA) has been fined £150,000 by the Information Commissioner’s Office following the loss of personal information relating to 59,592 customers
Move seems to validate last year’s report on widespread bugs but doesn’t fix larger problems
The ransom note features Robot Santa Claus from the TV show Futurama.