> TODAY'S SUMMARY (13 articles)
Today's cybersecurity landscape highlights two critical zero-day vulnerabilities in Citrix NetScaler (CVE-2026-88771 and CVE-2026-88772), which have been actively exploited for remote code execution before patches were available. Cloudflare also addressed a significant flaw in its Containers service that could expose customer data across tenants. Additionally, Microsoft SharePoint vulnerability (CVE-2026-65660) has been added to CISA's KEV catalog, indicating it is being exploited in the wild. In the cybercrime arena, a Kosovo national faces severe penalties for operating a marketplace selling stolen data and fraud tools. As automated traffic surges, the ongoing evolution of AI continues to reshape the cybersecurity landscape, as noted in Cloudflare's annual founders' letter.
|
// AI-powered summary generated at 20:00
Here's how to organize and secure the most sensitive data in your internal documentation without slowing your business down.
Find out whether AI detectors are accurate, how they work, and the security risks they may expose your business to.
It’s a sign of the times: Security conference DefCon has added smart glasses to its list of banned audio- or video-recording devices.
The organizers have said that, with no consistent way to understand whether smart glasses are recording or not, they have taken the step to...
Noteworthy stories that might have slipped under the radar: parcel delivery company OnTrac hacked, Adobe patches, UK Department for Education loses 607,000 records.
The post In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research appeared first on SecurityWeek.
Iran has the “geopolitical motivations” and a recent history of targeting water systems, experts pointed out.
The post Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers appeared first on SecurityWeek.
Ubuntu released a security update addressing vulnerabilities in the Linux kernel for version 22.04 LTS, requiring users to update their systems and potentially recompile third-party kernel modules.
Whoever wins, we lose
A Chinese-speaking threat actor has been using DeepSeek’s AI models to orchestrate cyber-attacks targeting Asian organizations
Maxim Suhanov discovered that the NTFS file system implementation in the
Linux kernel did not properly validate file name length in certain
situations, leading to an out-of-bounds read. An attacker could use this to
construct a malicious NTFS image that, when mounted and operated on, could
expose se...
Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators.
Researchers named the operation Fuyao and attributed it to Zhejiang Fengwo IoT Technology Co....
Cette semaine, les données personnelles restent au cœur des alertes cyber. L'Hacktivisme politique semble faire son retour en France... ou pas !
OpenAI models going rogue, the first documented agentic ransomware operation, and an emergent AI-driven supply chain threat made for a packed July roundup
Debian announced multiple vulnerabilities in the Linux kernel, which could cause privilege escalation, denial of service, or information leaks, resolved in version 6.12.100-1 for the stable distribution.
This post is available as a printable one page handout in English and Spanish.
Recordings of law enforcement, whether by bystanders or by those directly encountering officers, can be powerful tools of government accountability and can support movements for social change. But recording officers can c...
Un pirate revendique un accès au CRM français d’ENI et diffuse des factures de professionnels et grands comptes.
Attackers are adapting established techniques to AI platforms, emerging technologies, and changing user behavior. ESET's new threat report examines the rise of malicious AI skills, AI-assisted malware, ClickFix attacks, record quishing activity, and ransomware tools designed to disable security soft...
A week into shutdown, 14,000 customers still have no restoration date and some are struggling to pay staff
Kaspersky Next XDR Expert and Kaspersky Next EDR Expert now support the Nutanix 7.3 hypervisor.
Google is creating a new naming scheme for the bad actors behind cybersecurity threats, hoping that it will help to standardize the way that attacks are reported. Spoiler: It won’t.
Security researchers use these naming schemes so that they can attribute attacks without nec...
Google says AI found and helped fix 1,072 Chrome security bugs in two releases, dramatically accelerating vulnerability detection and patching Google’s Chrome Security team published a detailed account of how AI models have transformed their vulnerability management pipeline, and the headline figure...