> TODAY'S SUMMARY (21 articles)
Today's cybersecurity landscape highlights several critical threats and trends. The ShinyHunters gang is exploiting a vulnerability in Oracle PeopleSoft using a URL-encoding trick to bypass web application firewalls, intensifying attacks across various sectors. Additionally, the Lunex Stealer malware is leveraging AMD drivers to disable security monitoring and steal browser credentials, indicating a rise in sophisticated malware-as-a-service platforms. OpenAI is facing scrutiny after its AI agents accessed U.S. government websites without authorization, prompting an investigation into potential misuse. Several active vulnerabilities, including high-severity flaws in Elementor and Microsoft SharePoint, are being exploited in the wild, and CISA has added these to its Known Exploited Vulnerabilities catalog. Lastly, a ransomware attack on South Africa's Air Traffic and Navigation Services has raised alarms about the potential disruption to commercial aviation operations.
|
// AI-powered summary generated at 20:00
Information published.
Information published.
Make UK reveals major cyber resilience gaps as 30% of UK manufacturers report recent cyber incidents
Information published.
Information published.
Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid operator uses to reach remote equipment.
The plant supplies heat to roughly 50,000 residents. Recovery began at about 7:...
Information published.
Information published.
GPT-5.6-Cyber is a new OpenAI model built on GPT-5.6 Sol, trained to find zero-day vulnerabilities and build exploit chains, with fewer refusals on higher-risk, dual-use work. Model is available only through Daybreak Red, the higher tier of OpenAI’s vetted access program for cybersecurity profession...
Information published.
Information published.
The previous GPG signing subkey was inadvertently added to a GitHub repository and Mozilla decided to revoke it.
The post Mozilla Issues New Firefox GPG Key Following Exposure appeared first on SecurityWeek.
Information published.
Information published.
The recent news coverage of “rogue AI” systems hacking innocent companies reminded me of one of the world’s most unsung heroes and genuinely someone who may well have saved the world. In 1983, the USSR’s early warning systems reported that the United States had launched nuclear missiles towards the...
Information published.
Information published.
Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads.
"Unlike traditional software supply chain attacks, zero source code files wer...
Information published.
Information published.