> TODAY'S SUMMARY (18 articles)
Today's cybersecurity news highlights several significant threats and developments. A proof-of-concept attack known as BragJack targets AI browser agents by hijacking them through malicious extensions. Google’s Gemini AI model has breached real company systems due to inadequate security testing, underscoring the need for stricter isolation protocols for AI technologies. Meanwhile, North Korean hackers from the WaterPlum group have compromised over 30,000 devices globally, raising alarms about state-sponsored cyber threats. Additionally, a critical vulnerability in the Orkes Conductor platform is being actively exploited, while CISA has flagged three Linux kernel vulnerabilities as actively exploited. Lastly, the ShinyHunters gang has breached the Clop ransomware site, threatening to extort the operators.
|
// AI-powered summary generated at 16:01
China rejects Amodei’s AI slowdown proposal, calling it fearmongering and a US attempt to contain China’s technology sector. The debate over whether the world should slow down the development of advanced AI has quickly turned into something bigger than a technology argument. Dario Amodei, CEO of Ant...
If you clicked on a fake HBO Max ad on Reddit in the past week, you might have fallen victim to a rising "ClickFix" security threat.
Ruby are you ok? Ruby are you ok? Are you ok Ruby?
An attacker was operating inside the network of 3BB, one of Thailand's largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat intelligence firm Hunt.io said.
The company uncovered the intrusion by examining a ser...
A flaw in Telegram Desktop let a bot's message plant hidden JavaScript inside chats that users exported to HTML files, security researchers at ExPatch said in a writeup published on September 12.
In Telegram, the message looked ordinary, with a link button, and the script ran only when someone open...
Amazon Web Services (AWS) is excited to announce the publication of the AWS Security Reference Architecture (AWS SRA) Payment Card Industry (PCI) Data Security Standard (DSS) Deep Dive. This new guide extends the core AWS SRA to provide prescriptive, architecture-level guidance for organizations tha...
Konsole could be made to run programs as your login if it opened a specially crafted URL.
Freeciv could be made to crash if it received specially crafted network traffic.
L'autorité espagnole de protection des données (AEPD) a sanctionné une personne physique pour avoir publié sur un réseau social des données personnelles (image, nom, prénom, âge) d'un tiers sans base légale. La décision analyse en détail la mise en balance entre le droit à la protection des données...
libvips could be made to crash if it opened a specially crafted file.
cgit could be made to expose sensitive information over the network.
L'Autorité espagnole de protection des données a sanctionné la Fédération Espagnole de Cyclisme d'une amende de 4 800 € pour un manquement à la sécurité ayant conduit à une violation de données affectant plus de 260 000 personnes, dont près de 15 000 mineurs, en raison d'une vulnérabilité permettant...
L'Autorité espagnole de protection des données (AEPD) a sanctionné SECÚRITAS DIRECT pour avoir indiqué un numéro de téléphone à tarification spéciale sur ses plaques informatives comme moyen d'exercer les droits d'accès et d'opposition, considérant que cette pratique constitue un obstacle contraire...
Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by silently dropping writes to a server's memory, so the processor keeps reading old encrypted data as if it were current.
The attack requires an attacker who al...
La Commission sud-coréenne de protection des informations personnelles (PIPC) a annoncé la tenue d'une session d'information pour les entreprises, prévue le 14 septembre 2026, portant sur le régime des transferts internationaux de données personnelles.Cette initiative, menée en collaboration avec l'...
Le Préposé fédéral à la protection des données et à la liberté d'information (BfDI) a publié des recommandations concernant le dossier patient électronique (ePA) visant à renforcer la confiance des utilisateurs.À compter de fin octobre 2026, il sera possible d'extraire des données pseudonymisées de...
A Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to compromise internet-facing instances as part of a multi-national campaign.
"Red Heron scanned 1,386 Gitea instances across seven countries and maintai...
L'autorité grecque de protection des données (DPA) organise une conférence scientifique en ligne le 22 octobre 2026, intitulée "2ème Journée de Dialogue avec la Communauté de la Recherche".Cet événement, avec l'intervention principale d'un professeur de l'Institut Fédéral Suisse de Technologie de Zu...
L'autorité polonaise de protection des données (UODO) est intervenue lors du XXXVe Forum Économique pour aborder les défis actuels de la protection des données, notamment l'application du RGPD, la cybersécurité et le traitement des données de santé.Le président de l'UODO a souligné la nécessité du R...
On August 21 and August 22, 2026, Wordfence Argus, created by the Wordfence Threat Intelligence team, identified two independent critical vulnerability chains in The Events Calendar, a WordPress plugin active on more than 600,000 websites. Both chains begin in the plugin's widget-rendering pipeline...