> TODAY'S SUMMARY (112 articles)
Today's cybersecurity news highlights several significant threats and trends:
1. Labcorp faces a $2.3 million fine due to cybersecurity failings and is implementing enhanced data security measures, including a new incident response plan.
2. Cryptocurrency exchange Bitget reports a staggering $351.6 million theft by suspected North Korean hackers, prompting investigations and withdrawal suspensions.
3. A critical vulnerability in the Elementor WordPress plugin allows unauthenticated attackers to create admin accounts, emphasizing the ongoing risk of exploited software flaws.
4. Fake desktop applications targeting payroll services have emerged, tricking HR staff into granting remote access to attackers.
5. CISA warns of exploited flaws in Adobe and WSO2 products, adding them to its Known Exploited Vulnerabilities catalog, highlighting the urgency for organizations to patch these vulnerabilities.
|
// AI-powered summary generated at 20:00
Explore a selection of the latest DFIR employment opportunities in this week’s Forensic Focus jobs round-up.
Solana is a crypto platform known for speed. Developers like it to develop distributed applications or to implement crypto payments. To interact with the blockchain, APIs are provided for developers. These APIs will either "speak" JSON or gRPC. One implementation often used for development is "surfp...
Attackers breached a Polish CHP plant through a Fortinet device and private APN, reaching PLCs and disrupting turbine and water treatment systems. Poland’s CERT has described a second attack on the country’s energy sector, and this one matters for a simple reason: it shows how an ordinary-looking ne...
We shipped Device Bound Session Credentials at Report URI, open-sourced the server-side implementation, and then discovered a long list of things the specification doesn't prepare you for.Some caused random logouts. One could deadlock a browser tab indefinitely. Two silently turned a device-bound se...
Pseudo, e-mail, numéro de téléphone : découvrez comment Maigret, user-scanner et Ignorant permettent de retrouver vos comptes en ligne en quelques minutes.
Le post Quels comptes avez-vous vraiment sur le Web ? Trois outils OSINT pour le découvrir a été publié sur IT-Connect.
Microsoft is named a Leader in the 2026 IDC MarketScape for MDR services. Discover how Microsoft Defender Experts MDR combines AI, threat intelligence, and human expertise.
The post Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise appeared first on Microsoft Secu...
The incident occurred on the same day as coordinated cyberattacks struck more than 30 other renewable energy installations and a larger heat plant, as Poland publicly disclosed in January.
Two Democratic senators introduced legislation that would allocate $300 million each year to fund cybersecurity improvements for the water and wastewater sector.
Ubuntu has issued security updates for systemd to address vulnerabilities that could allow local attackers to gain elevated privileges or terminate processes on specific LTS releases.
Atlassian fixed a flaw letting one crafted link make its Rovo AI assistant exfiltrate company data
We discovered a kit that gave us an insight into how modern online scams are built, promoted, and potentially used to target everyday consumers.
Ukraine’s computer emergency response team, CERT-UA, said Saturday that the campaign has been running since at least May and is linked to Sandworm, the notorious hacking unit associated with Russia’s GRU military intelligence agency.
Justin Swaddle, who was a minor when he committed the crimes, coerced children across multiple countries into self-harm and sexual abuse using threats tied to their personal information, authorities said.
The post UK man tied to The Com sentenced for abusing 117 victims appeared first on CyberScoop.
A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default.
That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit paths are so short...
Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations alongside double extortion tactics used to pressure victims.
The p...
How polyglots are built, real-world cyberattack examples, and tips for detecting and preventing this threat.
Video game publisher Valve is alerting customers in Europe to a data breach at CEVA Logistics, its Steam hardware shipping partner. Reports from affected customers began surfacing on social media earlier today, after Valve started sending out data breach notification emails. “Between July 29 2026 an...
CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. [...]
The current GPT-5.6-Sol has been assigned a ‘high’ cybersecurity threshold, but Astra could reach the maximum ‘critical’ threshold.Â
The post OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns appeared first on SecurityWeek.
Poisoned JSON feed let attackers backdoor WordPress sites without changing any plugin files