> TODAY'S SUMMARY (4 articles)
Today's cyber news highlights significant threats and trends in the cybersecurity landscape. Ardit Kutleshi, a Kosovo national, faces 20 years in prison for operating the Rydox cybercrime marketplace, which sold stolen identities and fraud tools. Meanwhile, a critical vulnerability in Microsoft SharePoint (CVE-2026-65660) has been actively exploited, prompting the CISA to issue a patching deadline for federal agencies. Additionally, the recent breach of Gyazo has exposed 23.6 million user records, raising concerns about data security. In another alarming development, two unpatched zero-day vulnerabilities in Citrix NetScaler are being actively exploited, emphasizing the urgent need for organizations to bolster their security measures.
|
// AI-powered summary generated at 12:00
Hackers stole personal information, medical records, and financial information from the organization’s server.
The post 311,000 Impacted by Brown Health Medical Group-MA Data Breach appeared first on SecurityWeek.
An automated system called NOVA read the source code of 3,915 open-source projects over two months and came back with 14,090 vulnerabilities, each one confirmed through the system’s validation pipeline. Vulnerability researchers at Palo Alto Networks’ Unit 42 built the system and checked its output...
Over time, passkeys are supposed to replace passwords. But what happens when malware steals the master key?
The guidelines are the work of the recently launched Open Secure AI Alliance, which now includes 120 organizations.
The post Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data appeared first on SecurityWeek.
Database backups likely stolen, potentially exposing donor, supporter, and service user details
An unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in versions 1.22.1 through 1.27.0. No login, no repository write access. A public repository and crafted Org-mode markup are enough. The flaw is fixed in Gitea 1.27.1.
The file-read...
Nitro Enclaves and Key Management
Service (KMS) feel like a
natural fit: since the KMS can verify attestation documents generated by the enclaves, developers
can offload key management tasks from their applications to the AWS-managed service. But integrating
an external service with your trusted enc...
Prompt injection remains the most dangerous security threat to LLMs, according to OWASP’s latest Top 10 LLM Applications list
GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without exploiting a software vulnerability.
We scanned public GitHub commits for exposed n8n...
In one instance, an unsanctioned model attempted to inject malicious code into an open source repository.
The post AI Security Institute Reports Anthropic and OpenAI Models Going Rogue Against Organizations appeared first on SecurityWeek.
I was mapping the command-and-control infrastructure behind a state-linked intrusion set when the query came back and effectively ended the exercise I thought I was running.
The malware resolved its C2 address by reading a smart contract on a public blockchain. Public repor...
A new npm worm has compromised packages with over two billion monthly installs
The flaws can be exploited for remote code execution, authentication bypass, and EncryptInterceptor bypass.
The post CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities appeared first on SecurityWeek.
This is disturbing:
…a team of security researchers at UC San Diego, who found that a model of aftermarket car alarm known as the KARR Security System, installed in more than 2 million vehicles across the US by their estimate, can let any hacker within Bluetooth range send radio commands to silently...
TP-Link prints the serial number of an Omada router on its packaging and on a label attached to the device. Those numbers run in sequence, and feeding a guessed one to the Omada cloud service returns the matching device’s MAC address and model. Serials beginning 22460J500 appear to be ER605 routers,...
A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed.
The "evil twin" extensions were uploaded to the repository between July 26 and...
The easiest way to reclaim storage on your phone. Free up space without hunting through folders or risking your important files.
Comparisons of LangChain, CrewAI and AutoGen are easy to find — dozens of guides this year cover the same ground: developer experience, ecosystem maturity, how easy it is to wire up multi-agent workflows. None of them ask the question I actually care about: does the framework...
AI chatbots are avoiding some of the obvious errors that plagued earlier models, but they still fall short giving voters the full picture compared to state and local sources.
The post AI is getting better at election facts, but voters shouldn’t rely on it appeared first on CyberScoop.
The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials.
The post Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack appeared first on SecurityWeek.