> TODAY'S SUMMARY (13 articles)
Today's cybersecurity landscape highlights two critical zero-day vulnerabilities in Citrix NetScaler (CVE-2026-88771 and CVE-2026-88772), which have been actively exploited for remote code execution before patches were available. Cloudflare also addressed a significant flaw in its Containers service that could expose customer data across tenants. Additionally, Microsoft SharePoint vulnerability (CVE-2026-65660) has been added to CISA's KEV catalog, indicating it is being exploited in the wild. In the cybercrime arena, a Kosovo national faces severe penalties for operating a marketplace selling stolen data and fraud tools. As automated traffic surges, the ongoing evolution of AI continues to reshape the cybersecurity landscape, as noted in Cloudflare's annual founders' letter.
|
// AI-powered summary generated at 20:00
Agents Week explores how cloud infrastructure must evolve to serve autonomous agents rather than human browsers. Join us as we unpack the storage, execution, and security primitives needed for an agent-native web.
Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine. [...]
Hereâs an overview of some of last weekâs most interesting news, articles, interviews and videos: Nono: Open-source sandbox for AI agents AI coding agents run with the same permissions as their users, meaning they can access sensitive files, credentials, and production systems. A prompt injection, h...
Debian announced the fix of multiple vulnerabilities in libssh that could lead to denial of service, information disclosure, and arbitrary code execution, urging users to upgrade their packages.
After attacks hit 30+ Minnesota water systems, CISA urged utilities to remove internet-exposed PLCs and strengthen OT security. Between Sunday and Monday, July 26 and 27, a coordinated cyberattack hit operational technology (OT) systems at more than 30 community water utilities across the state, acc...
La Chambre des salariés (CSL) a confirmé avoir été victime d'une attaque informatique impliquant un accÚs non autorisé à certains de ses serveurs. L'incident est actuellement contenu, mais des investigations approfondies sont en cours pour déterminer l'origine, la période, l'étendue et les conséquen...
Le DNSC (Directoratul NaÈional de Securitate CiberneticÄ) a fourni son assistance Ă Techventures Bank S.A. aprĂšs qu'elle ait signalĂ© une cyberattaque par ransomware. L'incident a Ă©tĂ© notifiĂ© le 2 aoĂ»t 2026. Les autoritĂ©s collaborent avec la banque pour limiter les effets de l'attaque et enquĂȘter sur...
An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite.
A March 2021 firmware integr...
Le Magyar ĂllamkincstĂĄr (TrĂ©sor d'Ătat hongrois) a Ă©tĂ© victime d'une cyberattaque ciblant le rĂ©seau informatique de son service agricole et de dĂ©veloppement rural (Nemzeti KifizetĆ ĂgynöksĂ©g). L'incident a Ă©tĂ© dĂ©tectĂ© et les serveurs infectĂ©s ont Ă©tĂ© isolĂ©s. Les autoritĂ©s compĂ©tentes, dont le Centre...
A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]
Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group al...
Entre deux alertes cyber et un Wi-Fi dâhĂŽtel douteux, ZATAZ passe en mode Ă©tĂ© avec une playlist de cinq titres originaux pour accompagner vacances, trajets et pauses au soleil.
Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the companyâs enterprise marketing automation...
The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO.
The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.
The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE).
The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.
Plus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegramâs founder, xAI sues to stop a stateâs ânudificationâ ban, and the Democrats learn a lesson about getting scammed.
Both major AI labsâ models broke containment, escaped onto the internet, and hacked other companies. If a human had done that, the law would likely be against them. But a bot?
Debian issued a security advisory for libgd2, addressing a vulnerability that could lead to denial of service or arbitrary code execution, urging users to upgrade their packages.
Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses.
Adform detected the incident on July 27, 2026, removed the malicious code, notified affected clients, and reported it to authoriti...