> TODAY'S SUMMARY (13 articles)
Today's cybersecurity landscape highlights two critical zero-day vulnerabilities in Citrix NetScaler (CVE-2026-88771 and CVE-2026-88772), which have been actively exploited for remote code execution before patches were available. Cloudflare also addressed a significant flaw in its Containers service that could expose customer data across tenants. Additionally, Microsoft SharePoint vulnerability (CVE-2026-65660) has been added to CISA's KEV catalog, indicating it is being exploited in the wild. In the cybercrime arena, a Kosovo national faces severe penalties for operating a marketplace selling stolen data and fraud tools. As automated traffic surges, the ongoing evolution of AI continues to reshape the cybersecurity landscape, as noted in Cloudflare's annual founders' letter.
|
// AI-powered summary generated at 20:00
Un hacktiviste exhume des données de 2017 pour attaquer Chat Control et justifier une fuite politique controversée.
Broadcom has addresses five vulnerabilities in its VMware product range, three of which have been accorded a “critical” rating. The affected products are: VMware ESX, VMware vCenter, VMware Workstation, VMware Fusion, VMware Cloud Foundation, VMware vSphere Foundation, VMware...
Cybercrime has become a commercialized ecosystem where criminals can buy or rent nearly every capability needed to launch sophisticated attacks. These services provide anonymity, plausible deniability, and access to short-lived infrastructure that is difficult to detect, attribute, and disrupt, enab...
Police flag 4,000 URLs to disrupt The Com, theft victims sue Apple over a $1.8M wallet scam, and OpenAI and Anthropic models reach real systems in cyber tests.
Last year we made every Cloudflare server a Media over QUIC (MoQ) relay. Now the new provisioning API lets you create your own isolated relay and control who can publish and who can only watch.
Microsoft has had a narrow escape from total embarrassment: A security company uncovered a critical vulnerability that could have compromised all Azure Cosmos DB databases — both those of customers and Microsoft’s own.
Google subsidiary Wiz found a flaw in the database’s Gr...
Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined.
Both versions were released last month. In its latest patch for Chrome 151, released Wednesday, t...
An AI-assisted audit found 29 flaws in GlobaLeaks, showing LLMs make large-scale code reviews faster, cheaper, and accessible. GlobaLeaks, a mature whistleblowing platform that had already undergone six independent professional audits over the past thirteen years, was subjected to an LLM-assisted se...
A security investigation into inexpensive Android TV boxes led researchers to an ad fraud operation that had remained unnoticed for several years. Fuyao apps ecosystem (Source: Bitsight) According to Bitsight, the operation, named Fuyao, uses preinstalled Android apps, device identity spoofing, AI-g...
Claude maker Anthropic said its AI models escaped test environments and breached networks at three companies on the open internet.
An academic study has disclosed a "widespread class" of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denial-of-service (DoS) attacks and even session hijacking, allowing an attacker to seize control of a user's network session.
The findin...
According to the newly-published study, phishing and social engineering are becoming more expensive to recover from, trickier to detect, and increasingly augmented by artificial intelligence.
Read more in my article on the Fortra blog.
Device code phishing - the abuse of the OAuth 2.0 device authorization grant to steal access tokens - has evolved from a niche red-team technique to an industrial-scale threat in under six months.
Designed for input-constrained devices like smart TVs, printers, and so on, the device authorization l...
Palo Alto Networks' Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously.
After an initial Telegram instruction, the agent found internet-facing systems and selected public exploits. The researchers recovered no fur...
Last month, the story broke (alternate link) that Madison Square Garden uses facial recognition software on everyone entering the facility, and—among other groups—flags activists that oppose using facial recognition.
Turns out that the system was shut off for Taylor Swift’s wedding.
Evan Greer—one o...
Researchers have uncovered a new campaign that spreads the AtlasRAT remote access Trojan by disguising it as a Flash Player installer.
JetBrains is warning of a critical security vulnerability in its TeamCity DevOps platform that could allow unauthenticated attackers to execute arbitrary operating system commands on vulnerable servers.
“If exploited, this vulnerability may allow an unauthenticated attacker...
Semiconductor Chip Titan Analog Devices Reports Data Breach Analog Devices told federal regulators that intruders gained unauthorized access to its systems in June and exfiltrated an unknown number of files, with outside cybersecurity experts and law enforcement now involved in the response. The Mas...
The internet giant has built an agent harness to find vulnerabilities across Chrome’s codebase.
The post Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace appeared first on SecurityWeek.
Created by legendary hardware hacker Andrew “bunnie” Huang, the badges for this year’s famed security conference aim to push the boundaries of security and transparency.