> TODAY'S SUMMARY (13 articles)
Today's cybersecurity landscape highlights two critical zero-day vulnerabilities in Citrix NetScaler (CVE-2026-88771 and CVE-2026-88772), which have been actively exploited for remote code execution before patches were available. Cloudflare also addressed a significant flaw in its Containers service that could expose customer data across tenants. Additionally, Microsoft SharePoint vulnerability (CVE-2026-65660) has been added to CISA's KEV catalog, indicating it is being exploited in the wild. In the cybercrime arena, a Kosovo national faces severe penalties for operating a marketplace selling stolen data and fraud tools. As automated traffic surges, the ongoing evolution of AI continues to reshape the cybersecurity landscape, as noted in Cloudflare's annual founders' letter.
|
// AI-powered summary generated at 20:00
Running a website means a single unpatched vulnerability can take it offline, harm your reputation, or require cleanup. Most compromises begin with automated attacks exploiting known software flaws, usually reported and disclosed already.
To keep you protected from these threats, we’ve compiled this...
Oracle Linux has released security updates for libXfont2, addressing CVEs 2026-56001 and 2026-56002, available for x86_64 and aarch64 architectures on the Unbreakable Linux Network.
Oracle Linux 10 released updated Pipewire RPMs addressing CVE-2026-5674, featuring version 1.4.11 for x86_64 and aarch64 architectures, improving audio functionalities and security.
Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers. [...]
Oracle released updated RPMs for Oracle Linux 10 addressing CVE-2026-16615, which concerns weak random number generation in PKCE implementation. Available for x86_64 and aarch64 architectures.
Oracle Linux has released updated RPM packages for version 10 addressing security vulnerabilities CVE-2026-59691 and CVE-2026-59692 in the gstreamer1-plugins-bad-free software.
The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages. [...]
Oracle Linux has released updated OpenSSH packages for version 10, addressing multiple CVEs related to security vulnerabilities, including remote-to-remote copying issues and memory management flaws.
Debian has issued a security advisory regarding Incus, addressing multiple vulnerabilities that could lead to privilege escalation or security restriction bypass. Users are urged to upgrade to version 6.0.4-2+deb13u9.
South Korea warned that nation-state actors are using phishing and compromised websites to silently infect citizens and businesses. South Korea agencies (The National Intelligence Service, the National Police Agency, the Korea Internet & Security Agency, and the Financial Security Institute) joi...
Debian Security Advisory DSA-6406-1 addresses multiple vulnerabilities in PHP 8.4 that could lead to denial of service, SQL injection, and arbitrary code execution, urging users to upgrade.
Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors' clipboards with ones controlled by an attacker. [...]
The Squid is a new scientific machine:
One of the technological breakthroughs was the onboard use of a spinning wheel confocal microscope, nicknamed the Squid, which uses lasers to scan microscopic details of how organisms are put together. “That opens up a whole new world of exploring. We could see...
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch.
The pos...
Had the hacks used conventional methods, someone would likely go to prison.
In April 2026, the Wordfence Bug Bounty Program received 1288 vulnerability submissions from our growing community of security researchers working to improve the overall security posture of the WordPress ecosystem. These submissions are reviewed, triaged, and processed by the Wordfence Threat Intell...
The president went against his intelligence agencies’ conclusions about Iran being the likely suspect in the campaign.
The post Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world appeared first on CyberScoop.
California lawmakers have amended A.B. 1709, but the core problem remains: the bill is still a ban on social media access for youth under 16, and it still threatens the privacy and First Amendment rights of all Californians.
Proponents of the bill may argue that the recent amendments represent a com...
Today, we’re releasing the HIPAA Security Rule on AWS: Technical Safeguards Implementation and Readiness Guidance. This helps covered entities and business associates configure, implement, and evidence compliance with the HIPAA Security Rule Technical Safeguard requirements (45 CFR §164.312) when bu...
The Senate Commerce Committee is set to consider S. 737, the SCREEN Act, a sweeping age-verification bill that would require online services to verify users’ ages before they can access any sexually explicit content. If this bill passes, it will force millions of adult internet users to give up thei...