> TODAY'S SUMMARY (4 articles)
Today's cyber news highlights significant threats and trends in the cybersecurity landscape. Ardit Kutleshi, a Kosovo national, faces 20 years in prison for operating the Rydox cybercrime marketplace, which sold stolen identities and fraud tools. Meanwhile, a critical vulnerability in Microsoft SharePoint (CVE-2026-65660) has been actively exploited, prompting the CISA to issue a patching deadline for federal agencies. Additionally, the recent breach of Gyazo has exposed 23.6 million user records, raising concerns about data security. In another alarming development, two unpatched zero-day vulnerabilities in Citrix NetScaler are being actively exploited, emphasizing the urgent need for organizations to bolster their security measures.
|
// AI-powered summary generated at 12:00
Cloudflare Wallets will provide AI agents with native payments and verifiable identity on the web. Using the x402 protocol, agents can autonomously purchase APIs and content within clear safety guardrails.
Agents can write code faster than teams can review, deploy, and maintain it. Today we’re introducing the Agent Development Lifecycle and the Cloudflare primitives that underpin it
Frontier AI is reshaping vulnerability discovery. Learn how our NOVA system found 14,000+ unknown vulnerabilities across the open-source software supply chain.
The post The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software appeared first on Unit 4...
RapidFort has launched RapidFort Runtime, a real-time security solution that extends RapidFort’s SSCS capabilities into live production environments. The offerings provide end-to-end continuous threat elimination, from curated, independently malware-scanned open-source software before deployment to...
Nearly half of C2 malware bypasses DNS by connecting directly to IP addresses. Zero trust IP enforcement secures networks against these threats.
The post Almost Half of Malware Samples Communicate Direct to IP appeared first on Unit 42.
See how the Metropolitan Police Service used ADF Pro to triage thousands of devices, accelerate investigations, reduce forensic backlogs, and deliver actionable intelligence on the same day as a search warrant.
This morning, I noticed specific sources "hunting" for vulnerabilities in URLs that I haven&#;x26;#;39;t noticed before. All of these URLs appear to be associated with diagnostic tools:
The Federal Office for Information Technology and Communications (BIT) said specialists detected anomalies in on-premises Microsoft servers. The Swiss agency could not confirm exactly how the hackers got in.
A critical cPanel flaw (CVE-2026-58048) lets authenticated users execute SQL as root. Users should update to fixed versions immediately. If you run a shared hosting box, this one’s worth reading before your morning coffee gets cold. cPanel just patched a flaw, tracked as CVE-2026-58048 (CVSS score o...
A critical vulnerability in Microsoft Azure’s Cosmos DB database service could have enabled attackers to escape the platform’s Gremlin query sandbox, execute code on shared infrastructure, and ultimately gain access to any customer’s database, including data stores used by Mic...
Cops arrest budding politician for allegedly dealing with Flock's expansion the American way
Russian cybercrime groups are running a campaign that abuses hospitality Wi-Fi to steal information from travelers worldwide.
Black Hat 2026 is shaping up to be another AI-heavy conference, but this year’s announcements suggest the industry is moving beyond simply adding copilots to existing products.
Vendors are increasingly packaging AI into operational workflows, while pairing automation with g...
A statement from Ollie Whitehouse, Chief Technology Officer at the NCSC, on AI security following recent incidents.
Obsidian Security has developed a platform for governing AI agents across third-party applications.
The post Obsidian Security Raises $85 Million at $1.1 Billion Valuation appeared first on SecurityWeek.
Black Hat 2026 is shaping up to be another AI-heavy conference, but this year’s announcements suggest the industry is moving beyond simply adding copilots to existing products.
Vendors are increasingly packaging AI into operational workflows, while pairing automation with g...
Forescout researchers have found 15 new vulnerabilities in the TP-Link Omada networking ecosystem.
The post TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover appeared first on SecurityWeek.
Security flaws in automated workflows in the GitHub repository for Google’s Agent Development Kit for Python could allow public-facing AI agents to trigger more privileged automation, opening one path to manipulate pull-request reviews and another to expose credentials, accord...
Google has walked back an AI feature that allowed users to generate artificial images inside Google Earth, after a predictable flurry of deepfakes.
The cybersecurity industry has spent decades assuming that offensive capability scales with technical expertise.
That assumption is starting to break.
Security teams have long estimated risk by ranking attacker sophistication. Nation-state actors sat at one end. Organized criminal groups followed....