> TODAY'S SUMMARY (13 articles)
Today's cybersecurity landscape highlights two critical zero-day vulnerabilities in Citrix NetScaler (CVE-2026-88771 and CVE-2026-88772), which have been actively exploited for remote code execution before patches were available. Cloudflare also addressed a significant flaw in its Containers service that could expose customer data across tenants. Additionally, Microsoft SharePoint vulnerability (CVE-2026-65660) has been added to CISA's KEV catalog, indicating it is being exploited in the wild. In the cybercrime arena, a Kosovo national faces severe penalties for operating a marketplace selling stolen data and fraud tools. As automated traffic surges, the ongoing evolution of AI continues to reshape the cybersecurity landscape, as noted in Cloudflare's annual founders' letter.
|
// AI-powered summary generated at 20:00
SilverFox targeted a Japanese manufacturer with new DLL sideloading techniques, kernel drivers, and resilient ValleyRAT persistence mechanisms. Cato CTRL documented a new SilverFox campaign targeting a Japanese industrial manufacturer. The attack chain adds two previously undocumented DLL-sideloadin...
Anthropic affirme que, dans le cadre de tests cyber, Claude a compromis de vraies entreprises et publié un paquet malveillant sur PyPI.
Le post Anthropic l’avoue : Claude a piraté 3 entreprises pendant ses tests cyber a été publié sur IT-Connect.
Tracked as CVE-2026-63077, the security defect can be exploited without authentication via the agent polling protocol.
The post Critical Code Execution Vulnerability Patched in TeamCity appeared first on SecurityWeek.
Anthropic on Thursday became the latest artificial intelligence (AI) company to reveal that three of its models, including Claude Opus 4.7, Mythos 5, and an unnamed research model, had breached three unnamed organizations during cybersecurity testing without its knowledge.
The AI firm said the earl...
In this interview with Help Net Security, Eliran Almong, CEO of Cyviation, explains why airline cyber losses happen on the ground while the aircraft stays unmonitored. He walks through GNSS jamming that leaves no trace in a SIEM, and a PX4 Autopilot flaw his team disclosed where drone command channe...
In 2024, sysadmins expected AI to automate patch management optimization, vulnerability prioritization, infrastructure monitoring, and incident response within two years. Action1’s 2026 Survey Report: AI Impact on Sysadmins found that those expectations proved overly optimistic. The largest shortfal...
Finland stopped power transmissions with Russia at the start of the war in Ukraine, and two related telecom connections will stop at the end of this year, authorities said.
Founders pitching a cybersecurity seed round this summer are joining a line that keeps getting longer. Product Hunt launches hit their highest level since late 2023 last quarter, and the Census Bureau’s count of high-propensity business applications kept climbing. Seed deal volume in cyber ticked do...
Here’s a look at the most interesting products from the past week, featuring releases from BlackCloak, Contrast Security, Dropzone AI, PortSwigger, Realm Security, Reco, Root Evidence, and ZeroFox. BlackCloak extends deepfake protection to the executive’s trusted circle Deepfakes have made one of ou...
Wrote and published malware during tests, which is apparently OK because leaky test environments were the real problem
In a review triggered by OpenAI’s Hugging Face incident, Anthropic discovered three of its AI models had breached real organizations during third-party evaluations.
Quatre jeux cyber ZATAZ pour décoder, enquêter, communiquer et tester sa logique pendant les vacances.
An “AI worm” can spread through Microsoft Word documents using Copilot as a vector, a prominent Norwegian AI researcher reported on Tuesday.
The report from Håkon Måløy, later confirmed by Microsoft, said that an attacker can conceal instructions in a document that is later...
A prominent Norwegian AI researcher on Tuesday posted details about an AI worm that is wreaking havoc in various Microsoft applications, including Word and Copilot.
The report from noted Norwegian AI researcher Håkon Måløy, now confirmed by Microsoft, said that an attacker...
Following OpenAI’s own incident, Anthropic reviewed its own evaluations and found three cases of Claude hacking external companies.
The post Anthropic says its AI accidentally hacked three companies during safety tests appeared first on CyberScoop.
One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies. [...]
One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies. [...]
Ubuntu released a security notice regarding OpenSSL vulnerabilities affecting multiple LTS versions, which could allow denial of service through crafted network traffic, requiring updates and a system reboot.
Le Technopark de Gyeongbuk a été victime d'une cyberattaque par rançongiciel (ransomware) qui a chiffré ses données. Bien que le système ait été restauré, l'incident a mis en lumière la nécessité urgente de renforcer les systèmes de sécurité des institutions publiques régionales. Les experts soulign...