> TODAY'S SUMMARY (122 articles)
Today's cybersecurity landscape highlights several significant threats and vulnerabilities. Active exploitation of the critical F5 BIG-IP APM zero-day (CVE-2026-94127) allows unauthenticated remote code execution, prompting urgent updates from the vendor. Similarly, a newly identified WordPress vulnerability (CVE-2026-87902) has transitioned from probing to exploitation, enabling file writing and command execution. On another front, malicious AI agents have been implicated in large-scale phishing campaigns, compromising over 600,000 credit cards. Additionally, Check Point warns of active exploitation of a remote code execution flaw in its Security Gateway VPN. In the U.S., many federal agencies are falling short in complying with CISA's cloud security directives, increasing their risk of attack. Lastly, the cybercrime group ShinyHunters claims to have breached the FBI, demanding a retraction of a report detailing their activities.
|
// AI-powered summary generated at 20:00
A South African government website is being hacked to host the malicious phishing URL.
More than 75% of the US IT budget goes to maintaining legacy IT systems that are up to 50 years old.
In the year since we started this bi-monthly meetup, we’ve been thrilled by the community that it has attracted. We’ve had some excellent presentations on pragmatic security research, shared our aspirations and annoyances with our work, and made some new friends. It’s a wonderful foundation for an e...
Symantec claims a Philippine bank may be group’s fourth known victim
Liability shift mooted for those with poor online security
Google’s Protocol Buffers (protobuf) is a common method of serializing data, typically found in distributed applications. Protobufs simplify the generally error-prone task of parsing binary data by letting a developer define the type of data, and letting a protobuf compiler (protoc) generate all the...
Email containing personal details sent to wrong person
The primary target for the attack is Sweden, but additional campaigns may follow, replicating the same model.
If you follow the recommendations in the 2016 Verizon Data Breach Investigations Report (DBIR), you will expose your organization to more risk, not less. The report’s most glaring flaw is the assertion that the TLS FREAK vulnerability is among the ‘Top 10’ most exploited on the Internet. No experien...
As cyber-attacks targeting SAP continue to grow, organizations need to secure their SAP landscape as part of an overall security posture.
Firm hopes to make it easier to seek out secure products
Dynamic list is continually updated
Macedonian accused of operating Codeshop.su now in US custody
David Anderson will look into proposed bulk data collection powers
The $5 DDoS-for-hire services bill themselves as “stressor” services to “help test the resilience of your own server.”
Good news for Google's Project Abacus, 80% of consumers believe biometric authentication is more secure than traditional passwords.
A widespread Locky campaign emerges just as survey numbers show that most consumers have no idea about ransomware or what to do.
The idea is to financially quantify cyber-risk in terms of dollars and cents using value-at-risk modeling.
Hackers changed users’ profile pictures, biography and full name to further promote the sites, with recent tweets containing suggestive images and language discussing adult webcam sessions and sexual encounters.
A flaw in the service’s password reset processes meant that 4% of Instagram accounts could be rather easily compromised.