> TODAY'S SUMMARY (10 articles)
Today's cyber news highlights a range of emerging threats and vulnerabilities. Notably, two unpatched zero-day vulnerabilities in Citrix NetScaler appliances are actively exploited, posing significant risks. Additionally, Microsoft SharePoint's CVE-2026-65660 has been flagged by CISA, indicating ongoing exploitation, with a patching deadline recently issued. The recent Gyazo breach has compromised 23.6 million user records, further emphasizing the growing risk of data exposure. In malware news, a notable report discusses the proliferation of cybercrime marketplaces, exemplified by Ardit Kutleshi's guilty plea for selling stolen data. On the positive side, Cloudflare has addressed a serious cross-tenant flaw that exposed customer data. Overall, the landscape remains dynamic, with AI integration in cybersecurity and malware research continuing to evolve.
|
// AI-powered summary generated at 16:00
The physical security firm says its alarm monitoring and system functionality have not been affected.
The post Brinks Home Discloses Data Breach as Hackers Leak Files appeared first on SecurityWeek.
A critical security vulnerability (CVE-2026-66066) in Ruby on Rails (aka Rails), one of the most widely used frameworks for building websites and web apps, may allow attackers to read sensitive files off a server and, in some cases, take full control of it. Nicknamed “KindaRails2Shell” by the resear...
AI is moving incredibly fast, and every security leader is feeling the pressure to keep up.
AI platforms like Claude, Codex and Cursor are already helping security teams write detections, investigate alerts, summarize incidents, and automate repetitive work. The conversation has evolved from whethe...
New HollowFrame loader hid Go code in a fake Python DLL after pre-staging Defender exclusions
Qodana 2026.2 shipped with new security inspections, published benchmark results, post-quantum cryptography checks, and coverage reporting that no longer has to be pointed at the reports. The security work sits in the .NET linter and runs by default. Qodana tracks untrusted data across files in C#,...
ESET PROTECT Hub version 2.8.0 has been released.
L’UE valide une initiative contre l’identité numérique et la vérification d’âge obligatoires pour les services en ligne.
Simbian has released its autonomous AI Threat Hunt Agent, that investigates potential threats and identifies malicious activity across enterprise environments. The Threat Hunt Agent represents the third pillar of Simbian’s AI-driven security suite. These three Agents eliminate blind spots across the...
Employee failed to follow security policy, leaving internal management file open to the public
An unknown Chinese-threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit.
Attack surface management platform Censys said it identified the threat actor running more than 100 web properties, most of which ar...
This essay originally appeared in Foreign Policy.
Earlier this month, two of OpenAI’s models broke out of their containment sandbox and attacked another AI company. The story is kind of wild. OpenAI was running security tests on two of its models: GPT-5.6 Sol and an unreleased model that is almost c...
The INC Ransomware gang has been targeting vulnerable SMA1000 appliances for root access and lateral movement.
The post Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks appeared first on SecurityWeek.
23andMe, géant de l'analyse ADN, condamné pour des failles cyber ayant facilité la fuite massive de données génétiques.
Internal documents show ICE's DNA collection has skyrocketed in the second Trump administration. Now hundreds of thousands of people never convicted of a crime are in an FBI criminal database forever.
Explore how passkey implementation gaps undermine security when relying parties fail to validate the User Verified flag, reducing MFA to a single factor.
The post Pass the Passkey: A Novel Attack Surface in Passwordless Authentication appeared first on Unit 42.
Korean telco KT has been fined $39m for a year-long breach linked to femtocell compromise
ZATAZ relaie une cagnotte pour aider une céramiste du Porge à reconstruire son atelier détruit par les incendies.
Midnight Blizzard has been stealing Microsoft account credentials via compromised Wi-Fi networks at hospitality organizations.
The post Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking appeared first on SecurityWeek.
The Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the dark web.
The data included names, organisations and work email addresses belonging to police officers, police staff, criminal justice professionals,...
Alleged Żabka data leak offered for €5,000 includes Jira data, GitLab repos, and secrets; researchers verified much of the sample. A brand-new forum account showed up on August 2, posted once, and asked five grand for what it claims is a full data dump from Żabka Polska. Żabka Polska is Poland’s lar...