> TODAY'S SUMMARY (13 articles)
Today's cybersecurity landscape highlights two critical zero-day vulnerabilities in Citrix NetScaler (CVE-2026-88771 and CVE-2026-88772), which have been actively exploited for remote code execution before patches were available. Cloudflare also addressed a significant flaw in its Containers service that could expose customer data across tenants. Additionally, Microsoft SharePoint vulnerability (CVE-2026-65660) has been added to CISA's KEV catalog, indicating it is being exploited in the wild. In the cybercrime arena, a Kosovo national faces severe penalties for operating a marketplace selling stolen data and fraud tools. As automated traffic surges, the ongoing evolution of AI continues to reshape the cybersecurity landscape, as noted in Cloudflare's annual founders' letter.
|
// AI-powered summary generated at 20:00
Artificial intelligence is rapidly changing education, and the way people search for information. Parents, teenagers, teachers, and schools are struggling with tough questions about when AI should, and should not, be used. It makes sense for Congress to hold hearings and examine how AI should be use...
OpenAI says it has reduced the price of two GPT-5.6 models, cutting Luna's API price by 80% and Terra's by 20% as it works to make its models more efficient. [...]
A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January 2025.
These targeted organiza...
The Cybersecurity and Infrastructure Security Agency said in a public alert on Thursday that facilities should “remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible."
L'Autorité néerlandaise de protection des données (AP) détaille les nouvelles obligations de transparence applicables aux systèmes d'intelligence artificielle à compter du 2 août 2026.À compter de cette date, les utilisateurs devront être informés lorsqu'ils interagissent avec un système d'intellige...
L'autorité italienne de protection des données (GPDP) a aujourd'hui publié une décision de sanction à l'encontre de TIM S.p.A. (comprenant le prononcé d'une amende de 9 516 000 €) pour des manquements systémiques liés à des campagnes de télémarketing illicites et à la gestion des droits des personne...
The outpost will have its own director, though no one has yet been named for the post, and support the command’s nascent Cyber Warfare Innovation Center (CIWC).
L'autorité espagnole sanctionne une société pour prospection téléphonique non sollicitée, rappelant que l'acquisition de données auprès d'un tiers n'exonère pas le responsable de traitement de sa propre obligation de vérifier la validité du consentement et de fournir l'information requise par le RGP...
L'autorité roumaine sanctionne un opérateur pour des failles de sécurité ayant conduit à une violation de données, notamment l'utilisation d'une plateforme non mise à jour et l'absence de politique de mots de passe robustes.Faits et contexteL'autorité roumaine de protection des données (ANSPDCP) a a...
A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement. [...]
The chart is interesting.
On the IPI benchmark, Opus 5 improved over Opus 4.8, reducing the probability of an attacker succeeding within 15 attempts from 5.5% to 2.0%, and from 0.5% to 0.2% on 1 attempt. It also improved on Sonnet 5 (5.9% at k=15) and Mythos 5 (2.6%), making it the most robust model...
Your board wants a business resilience strategy. Here's what that means, with a four-pillar framework, and a plan to build resilience fast.Â
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater systems sector. [...]
Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka.
According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted arc...
Document management systems store your most sensitive data. Here's what to look for — and why most platforms fall short on security.
Hopefully the company secures houses better than it locks down SaaS systems
A step-by-step guide to building a contingency plan. Learn about the key components, common mistakes to avoid, and how secure tools help.
Scammers are using fake V-Bucks offers and locker value sites to hijack Fortnite accounts.
Learn how email security protocols impact your organization's deliverability and which one is the most secure.
Your comprehensive step-by-step guide on how to attach emails in Gmail, Outlook, and Proton Mail.