> TODAY'S SUMMARY (10 articles)
Today's cyber news highlights a range of emerging threats and vulnerabilities. Notably, two unpatched zero-day vulnerabilities in Citrix NetScaler appliances are actively exploited, posing significant risks. Additionally, Microsoft SharePoint's CVE-2026-65660 has been flagged by CISA, indicating ongoing exploitation, with a patching deadline recently issued. The recent Gyazo breach has compromised 23.6 million user records, further emphasizing the growing risk of data exposure. In malware news, a notable report discusses the proliferation of cybercrime marketplaces, exemplified by Ardit Kutleshi's guilty plea for selling stolen data. On the positive side, Cloudflare has addressed a serious cross-tenant flaw that exposed customer data. Overall, the landscape remains dynamic, with AI integration in cybersecurity and malware research continuing to evolve.
|
// AI-powered summary generated at 16:00
Une vulnérabilité a été découverte dans les produits Check Point. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance et un contournement de la politique de sécurité.
De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager's synced passkeys to take over accounts, bypass user verification, and extract passkey private keys. [...]
The Senate Commerce Committee is once again considering legislation that would dramatically expand age verification, and undermine privacy for everyone. Alongside the SCREEN Act, the CHATBOT Act, and the Youth AI Privacy Act, the Kids Online Safety Act (KOSA) would push companies to collect more inf...
EFF joined a group of 18 civil society organizations to send a letter encouraging New York Governor Kathy Hochul to Senate Bill 9934A, the New York Stealth Crawler Prohibition Act. The letter states:
While framed as a measure to protect local journalism, this legislation harms free expression and es...
The post Public interest coalition urges Congress to investigate OpenAI, Hugging Face hack appeared first on CyberScoop.
The Federal Trade Commission (FTC) in July issued a proposed policy statement “concerning the suppression of accuracy in artificial intelligence systems.” We urge the FTC to withdraw this misguided proposal and instead focus on its core strengths and mission to protect consumers.Â
The new proposed p...
Oracle Linux Security Advisory ELSA-2026-48170 announces updated RPM packages for PHP version 8.3.32 for x86_64 and aarch64 architectures, addressing vulnerabilities including CVE-2026-14355.
Oracle Linux has released security updates for version 10, addressing CVE-2026-5056 related to integer overflow and bounds check vulnerabilities in uncompressed video handling.
That "free" adult TikTok site could leave you with spam, unwanted apps, or fake verification fees.
Oracle Linux has released updated Perl DBI packages to fix vulnerabilities CVE-2026-14380 and CVE-2026-14739, affecting Oracle Linux 10 for x86_64 and aarch64 architectures.
Oracle released updates for Oracle Linux 10 to address CVE-2026-9538, enhancing security by fixing a vulnerability in the Archive-Tar package that could lead to memory denial-of-service.
The Senate Commerce Committee is poised to consider the Youth AI Privacy Act, a bill that would require AI companies to create kids-only privacy rules and implement so-called “safe design features,” which would—like three other bills under consideration this week—require more data collection and mak...
Oracle Linux has released updated RPMs for version 10 addressing CVE-2026-13757, specifically re-basing to version 0.26.4 across various package subsets for x86_64 and aarch64 architectures.
The European Union (EU) has started enforcing key parts of the AI Act, with immediate, visible consequences for chatbots, deepfakes and other consumer‑facing AI.
California has launched the Delete Request and Opt‑out Platform (DROP), a state‑run portal that lets residents send deletion and opt‑out requests to all registered data brokers.
Poisoned pull requests contain prompt injection that allows one to control another
The company behind a popular hardware wallet for bitcoin owners was forced to destroy part of its inventory after thieves siphoned more than $88 million from customers through a firmware vulnerability.
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems. [...]
OpenAI and Anthropic admitted that their unreleased AI models escaped their sandboxes and hacked several companies in unprecedented cyberattacks. Who is legally to blame? Should prosecutors charge the two AI frontier labs? Can victims sue them? We spoke to lawyers who specialize in computer hacking...