> TODAY'S SUMMARY (122 articles)
Today's cybersecurity landscape highlights several significant threats and vulnerabilities. Active exploitation of the critical F5 BIG-IP APM zero-day (CVE-2026-94127) allows unauthenticated remote code execution, prompting urgent updates from the vendor. Similarly, a newly identified WordPress vulnerability (CVE-2026-87902) has transitioned from probing to exploitation, enabling file writing and command execution. On another front, malicious AI agents have been implicated in large-scale phishing campaigns, compromising over 600,000 credit cards. Additionally, Check Point warns of active exploitation of a remote code execution flaw in its Security Gateway VPN. In the U.S., many federal agencies are falling short in complying with CISA's cloud security directives, increasing their risk of attack. Lastly, the cybercrime group ShinyHunters claims to have breached the FBI, demanding a retraction of a report detailing their activities.
|
// AI-powered summary generated at 20:00
Report by Intel Security finds large proportion of cybersecurity professionals think CTI sharing helps build stronger security, but just 42% of companies currently do it
Fall-out from Bangladesh Bank hack continues
Developers have access to tools like AddressSanitizer and Valgrind that will tell them when the code that they’re running accesses uninitialized memory, leaks memory, or uses memory after it’s been freed. Despite the availability of these excellent tools, memory bugs still persist, still get shipped...
A healthy portion of IT staff say they're dissatisfied with their security approach because it slows down their system.
Malware with a never-ending propagation loop uses thirst for porn to spread SMS stealers and fake installers.
The ransomware has a nifty new feature: RSA 4096 for encrypting data, so it's impossible to recover.
Following the FBI’s warning of cyber hacks on connected and driverless cars, Raj Samani of Intel Security has urged UK government and defense to address the problem
The US Department of Defence and Israeli Ministry of Defence have entered an agreement to increase cyber-defence cooperation between the nations.
E-commerce fraud also spikes over the period as criminals target CNP transactions
Law enforcers should be forced to request warrant to use phone surveillance tech
Lieberman Software poll says IT pros have had enough of static credentials
It exploits Apple’s DRM, tricking iOS devices into believing that a malicious app was purchased by victim, allowing its installation.
US law still seen as inadequate to protect EU citizens’ liberties
Pennsylvania man phished iCloud and Gmail log-ins
Information Security Forum maintains government intervention one of three trends to affect quality of information over next two years.
A March 3 phishing attack targeted 2015 payroll data, containing names, addresses, social security numbers, and salary info.
A new rash of malicious ads on top publishing and media sites surreptitiously inflict ransomware on unsuspecting site visitors.
Huge uptick in Angler activity linked to malicious ads
Proofpoint spots new campaigns aimed at US, Middle East and Europe
Only 35% of boardroom executives believe their board has a high level of personal expertise in cybersecurity.