> TODAY'S SUMMARY (10 articles)
Today's cyber news highlights a range of emerging threats and vulnerabilities. Notably, two unpatched zero-day vulnerabilities in Citrix NetScaler appliances are actively exploited, posing significant risks. Additionally, Microsoft SharePoint's CVE-2026-65660 has been flagged by CISA, indicating ongoing exploitation, with a patching deadline recently issued. The recent Gyazo breach has compromised 23.6 million user records, further emphasizing the growing risk of data exposure. In malware news, a notable report discusses the proliferation of cybercrime marketplaces, exemplified by Ardit Kutleshi's guilty plea for selling stolen data. On the positive side, Cloudflare has addressed a serious cross-tenant flaw that exposed customer data. Overall, the landscape remains dynamic, with AI integration in cybersecurity and malware research continuing to evolve.
|
// AI-powered summary generated at 16:00
In cybersecurity, third-party risk management normally looks simple on paper: evaluate your vendor, learn the risk, report out on the gaps and weaknesses, transfer to the contract, and continue. Unfortunately, it seldom works that way in practice.
In my roles as a CISO, I f...
Michigan, South Dakota, and Georgia are reportedly on the list of states whose water systems have been targeted by Iran-linked hackers.
The post US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States appeared first on SecurityWeek.
A hacker has drained nearly $89m from Coldcard Bitcoin wallets after exploiting a legacy bug
OpenAI banned a coordinated network of ChatGPT accounts that likely originated in Cambodia’s Preah Sihanouk province, a region reports have linked to online scam compounds and human trafficking operations. The network used the company’s models to create and manage fake online personas, generate and...
Attackers reaching for kernel access on a Windows machine bring a driver Microsoft already trusts. It is signed, it loads, and it carries a known flaw. That flaw gives them enough room to tamper with memory or disable the security software watching the host. Once an attacker holds that level of acce...
When OpenAI disclosed that one of its models escaped a test environment and broke into Hugging Face’s systems on its own, headlines cast the incident as the start of a new era of AI-driven attacks. But the underlying cause of the incident was a familiar one: a misconfigured sa...
Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analysis software loads them.
The vendor's July 31 security bulletin says nearly undetectable changes to .fsa and .hid outputs could occur if labor...
AI generates 2.5 signals for every human-triggered signal CrowdStrike has to assess. Meanwhile, attackers are using AI to weaponize vulnerabilities faster than companies can patch them.
The post CrowdStrike: AI is now both the weapon and the target in cyberattacks appeared first on CyberScoop.
CrowdStrike tracks 89% surge in machine-assisted activity as patch windows shrink to 48 hours
A list of topics we covered in the week of July 27 to August 2 of 2026
At this exact moment curl’s summer of bliss 2026 ends. We (the maintainers of curl) took the entire month of July off from vulnerability reporting and in this post I will try to explain how this went. (If you feel like skipping the wordy blab below, the single word answer is: fine) This was possibly...
N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers.
Its first fix was incomplete. CVE-2026-18577 affects N-central builds prior to 2026.3.1.7. N-able shipped build 2026.3.1.7 on Augu...
Three high-severity security flaws have been disclosed in Hugging Face's Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code on machines that load it, opening the artificial intelligence (AI) supply chain to security risk.
"These vulnerabilities are by...
Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSiteToday, we welcome the 47th government onboarded to Have I Been Pwned’s free gov service: Nepal. Their National Cyber Security Centre now has access to m...
Ruby on Rails fixed a critical vulnerability that could let unauthenticated attackers read files and achieve remote code execution. Ruby on Rails has patched CVE-2026-66066, a critical vulnerability (CVSS score of 9.5) that could allow unauthenticated attackers to read arbitrary files from vulnerabl...
In this interview with Help Net Security, Mike Wiacek, founder and CTO of Stairwell, explains Backstory, an AI agent that takes a single alert and works outward to map how far a malware campaign spread. He walks through the research behind the claim that each published sample hides an average of 2.4...
SkillSpector is an open-source scanner from NVIDIA that reads an agent skill and tells you whether to install it. Point it at a directory, a zip file, a single SKILL.md, or a Git URL, and it returns a list of findings, a risk score, and recommendations. The folder it reads runs with everything you h...
In this Help Net Security video, Mike Boyle, VP of Business Units at GMO GlobalSign, and Rahul Powar, CEO and founder of Red Sift, unpack the evolution of email security and why it matters for business trust. With a combined 45+ years worth of experience in tech, they dissect email from the very beg...
Guardio Mobile Security brings several protection features to iPhone and Android, allowing users to monitor exposed personal information, identify phishing attempts, and receive alerts about emerging threats from a single application. It is available on smartphones and tablets, while browser extensi...