> TODAY'S SUMMARY (122 articles)
Today's cybersecurity landscape highlights several significant threats and vulnerabilities. Active exploitation of the critical F5 BIG-IP APM zero-day (CVE-2026-94127) allows unauthenticated remote code execution, prompting urgent updates from the vendor. Similarly, a newly identified WordPress vulnerability (CVE-2026-87902) has transitioned from probing to exploitation, enabling file writing and command execution. On another front, malicious AI agents have been implicated in large-scale phishing campaigns, compromising over 600,000 credit cards. Additionally, Check Point warns of active exploitation of a remote code execution flaw in its Security Gateway VPN. In the U.S., many federal agencies are falling short in complying with CISA's cloud security directives, increasing their risk of attack. Lastly, the cybercrime group ShinyHunters claims to have breached the FBI, demanding a retraction of a report detailing their activities.
|
// AI-powered summary generated at 20:00
Micro-virtualization vendor Bromium has offered a “Bring-Your-Own-Malware challenge” to delegates at Infosecurity Europe.
The epidemic shows no signs of abating.
Using Vector35’s Binary Ninja, a promising new interactive static analysis and reverse engineering platform, I wrote a script that generated “exploits” for 2,000 unique binaries in this year’s DEFCON CTF qualifying round. If you’re wondering how to remain competitive in a post-DARPA DEFCON CTF, I hi...
The insecure Wi-Fi mechanism allows hackers to disable the anti-theft alarm, flash the lights, tweak charging settings and drain the battery.
Russian Facebook denies breach
In the year since we started this bi-monthly meetup, we’ve been thrilled by the community that it has attracted. We’ve had some excellent presentations on pragmatic security research, shared our aspirations and annoyances with our work, and made some new friends. It’s a wonderful foundation for an e...
Nine in ten Brits are against the mass surveillance powers contained in the Investigatory Powers Bill.
The malware targets specific processes within simulated Siemens control system environments.
Google’s Protocol Buffers (protobuf) is a common method of serializing data, typically found in distributed applications. Protobufs simplify the generally error-prone task of parsing binary data by letting a developer define the type of data, and letting a protobuf compiler (protoc) generate all the...
Ransomware family continues to evolve with version 3.1
Cybercriminals recognize that holding the data hostage is more lucrative than simply stealing the data and selling it on the black market.
If you follow the recommendations in the 2016 Verizon Data Breach Investigations Report (DBIR), you will expose your organization to more risk, not less. The report’s most glaring flaw is the assertion that the TLS FREAK vulnerability is among the ‘Top 10’ most exploited on the Internet. No experien...
The US central bank is a high-value target that should be well-guarded; but an internal audit showed critical vulnerabilities in its systems.
The connected nature of these products creates unintentional ports to other sensitive and critical systems, data and devices.
Apple has yet to release a patch
Egress FoI request shows healthcare is once again the worst offender
Bad guys use operational security to avoid detection and retain attack infrastructure; good guys use it to deny adversaries critical information.
Deal should not be ratified in current form, says Buttarelli
Anomali research finds widespread reuse of corporate credentials
First major casualty of new breed of email scam