> TODAY'S SUMMARY (13 articles)
Today's cybersecurity landscape highlights two critical zero-day vulnerabilities in Citrix NetScaler (CVE-2026-88771 and CVE-2026-88772), which have been actively exploited for remote code execution before patches were available. Cloudflare also addressed a significant flaw in its Containers service that could expose customer data across tenants. Additionally, Microsoft SharePoint vulnerability (CVE-2026-65660) has been added to CISA's KEV catalog, indicating it is being exploited in the wild. In the cybercrime arena, a Kosovo national faces severe penalties for operating a marketplace selling stolen data and fraud tools. As automated traffic surges, the ongoing evolution of AI continues to reshape the cybersecurity landscape, as noted in Cloudflare's annual founders' letter.
|
// AI-powered summary generated at 20:00
A coordinated cyberattack that targeted more than 30 Minnesota community water systems has alarmed industrial cybersecurity experts, not because it caused widespread disruption, but because it appears to represent the first distributed campaign against dozens of small utilitie...
AI coding agents are part of the developer toolchain. Tools like Kiro and Claude Code generate features, tests, and code refactors from natural-language prompts. A single agent can open dozens of pull requests (PRs) across your repositories in an afternoon. That productivity comes with a trade-off:...
A memo obtained by WIRED, issued by the water utilities information sharing group WaterISAC, links dozens of cyberattacks against Minnesota water utilities to Tehran.
Le groupe ExfilSquad, apparu le 26 juillet 2026, affirme détenir 130 Go de données Microsoft. 15 victimes revendiquées en un jour, mais aucune preuve solide.
Le post Microsoft visé par ExfilSquad : 8 millions d’enregistrements revendiqués, mais très peu de preuves a été publié sur IT-Connect.
Le script publicitaire d'Adform a été compromis pour distribuer un clipper destiné à détourner des transactions crypto. Voici ce que l'on sait sur cet incident.
Le post Adform piraté : un script publicitaire a volé des cryptomonnaies pendant au moins une semaine a été publié sur IT-Connect.
The acquisition will add approximately 65 cybersecurity professionals to Bank of America’s operations in the United Kingdom.
The post Bank of America to Acquire Cybersecurity Firm MDSec appeared first on SecurityWeek.
La KB5101684 pour Windows 11 24H2 et 25H2 étend Windows Hello ESS aux lecteurs d'empreintes externes et permet de désinstaller un composant IA.
Le post Windows 11 KB5101684 : découvrez les nouveautés de cette mise à jour ! a été publié sur IT-Connect.
Les appels audio et vidéo sont désormais intégrés à WhatsApp Web, chiffrés de bout en bout, sans installer d'application. Une nouveauté attendue.
Le post WhatsApp : les appels audio et vidéo chiffrés arrivent dans votre navigateur Web a été publié sur IT-Connect.
Ely Kahn, Okta's chief product officer, told CyberScoop the deal enriches the company's current threat detection tools and gives it deeper visibility into AI agent activity across enterprise systems.
The post Okta’s deal for Permiso aims to close gaps in identity threat detection appeared first on C...
The health tech data giant, which handles vast amounts of patients' medical data, said hackers struck one of its protected health data stores.
Brand impersonation now drives initial access, using fake sites and apps to deliver malware, making rapid takedowns essential to disrupt attacks. Attackers recently poisoned more than 700 websites, including sites run by Harvard, Oxford, and DuckDuckGo. They used a fake Cloudflare page to trick visi...
The last two versions of Chrome have included more patches than the previous 23 combined.
In a filing for federal regulators, Massachusetts-based Analog Devices said intruders had exfiltrated data from its networks earlier this summer, but the scope of the incident is still under investigation.
The deal extends Okta's reach beyond identity management and into the realm of security operations, positioning the company to compete more directly on identity threat detection and response.
The post Okta to Acquire Identity Threat Detection Firm Permiso appeared first on SecurityWeek.
As experts have warned for the last two years, some companies — like Microsoft and now Google — are finding and patching an exponential number of bugs in their products, thanks to the use of LLMs and AI tools.
One expert said they were pleased by the guidance, which touches on open-weight AI models, patching and more.
The post CISA issues recommendations to federal agencies on open-source software security appeared first on CyberScoop.
Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview ca...
Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers. [...]
Amy hikes Virginia’s most difficult trail and muses on the persistent challenges of cybersecurity. The two aren't dissimilar.
Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. [...]