> TODAY'S SUMMARY (4 articles)
Today's cyber news highlights significant threats and trends in the cybersecurity landscape. Ardit Kutleshi, a Kosovo national, faces 20 years in prison for operating the Rydox cybercrime marketplace, which sold stolen identities and fraud tools. Meanwhile, a critical vulnerability in Microsoft SharePoint (CVE-2026-65660) has been actively exploited, prompting the CISA to issue a patching deadline for federal agencies. Additionally, the recent breach of Gyazo has exposed 23.6 million user records, raising concerns about data security. In another alarming development, two unpatched zero-day vulnerabilities in Citrix NetScaler are being actively exploited, emphasizing the urgent need for organizations to bolster their security measures.
|
// AI-powered summary generated at 12:00
The week-old Open Secure AI Alliance, spearheaded by Nvidia and grown to over 120 companies, already has proposals out for defending against AI agents.
A new version of the XCSSET malware is targeting thousands of macOS users through compromised Xcode projects and GitHub repositories. [...]
Attribution is preliminary, and so far it seems no real damage.
And it seems like this is a campaign that has targeted at least seven states. And, because this is where the US is right now, Trump doesn’t believe it’s Iran and that Minnesota…I guess…hacked itself.
“I think I blame it on Minnesota bec...
77 extensions on the Open VSX marketplace impersonated legitimate developer tools while transmitting information about the systems and development environments where they were installed. [...]
Microsoft expands its Zero Trust for AI strategy to enhance security for AI and DevSecOps environments with new tools and guidance.
The post Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps appeared first on Microsoft Security Blog.
Microsoft Defender automatically isolated a compromised QNET endpoint in 128 seconds, stopping a multi-stage attack before the payload could persist or spread.
The post 128 Seconds to disruption: Microsoft Defender stops ransomware at QNETÂ appeared first on Microsoft Security Blog.
The five senators said the administration has alternated between being too passive and overstepping, and China stands to benefit as a result.
The post Dem senators criticize Trump administration decisionmaking on AI security risks appeared first on CyberScoop.
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and sei...
Amazon Web Services (AWS) is pleased to announce the successful completion of our Payment Card Industry (PCI) Data Security Standard (DSS) and Three Domain Secure (3DS) certifications. As part of this renewal, we have expanded the scope to include three additional AWS services and one additional AWS...
Claiming 'it's my server' was often enough to persuade models to help
Oracle Linux 10 has received updates for Node.js packages addressing multiple CVEs, including enhancements and security fixes, ensuring improved software performance and resilience against vulnerabilities.
Oracle Linux 10 received an updated Firefox package addressing multiple CVEs, introducing changes including fixes to default preferences and an update to ESR version 140.13.0.
Airlock Digital, a leader in preventative endpoint security, today announced Agentic AI Control & Governance at Black Hat USA 2026. The new capabilities build on application control by providing command- and session-level visibility into trusted AI agent behavior, centrali...
Oracle Linux released an update for nodejs-nodemon version 3.1.14 addressing CVE-2026-13149, available for x86_64 and aarch64 architectures via the Unbreakable Linux Network.
Oracle Linux 10 has updated RPM packages for Node.js, addressing multiple CVEs including CVE-2026-13149. Versions released include related devel packages and documentation for x86_64 and aarch64 architectures.
Many companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas.
The post Black Hat USA 2026 – Summary of Vendor Announcements (Part 2) appeared first on SecurityWeek.
Oracle Linux released updated Thunderbird RPMs for version 10, addressing multiple CVEs; the packages are available for x86_64 and aarch64 architectures.
What to expect as BSides, Black Hat, and DEF CON descend on Las Vegas
A security vulnerability in the cryptocurrency hardware wallet Coldcard is allowing hackers to drain the crypto from victims’ wallets. The total losses amount to more than $130 million, according to blockchain-monitoring firms.
L'autorité espagnole de protection des données a sanctionné un important sous-traitant des secteurs bancaire et immobilier pour des mesures de sécurité insuffisantes ayant conduit à une cyberattaque de grande ampleur, ainsi que pour avoir notifié cette violation avec un retard significatif.Faits et...