> TODAY'S SUMMARY (1 articles)
Today's cybersecurity landscape highlights several key trends and threats. Ransomware attacks continue to proliferate, with an emphasis on targeting critical infrastructure and healthcare sectors. Phishing remains a significant concern, leveraging social engineering tactics to exploit remote work vulnerabilities. Additionally, the rise of supply chain attacks underscores the need for enhanced security measures across third-party vendors. Zero-day vulnerabilities are being actively exploited, prompting organizations to prioritize patch management. Finally, the importance of cybersecurity awareness training is emphasized as a critical defense against human error.
|
// AI-powered summary generated at 04:00
Read the latest DFIR news – Go malware memory forensics, new iOS notification and Biome artifacts, AI assistant forensic traces, ALEAPP browser updates, and more.
Yesterday Anthropic published two new cryptanalysis results, both outputs of Claude Mythos, their (still) unreleased advanced model. The first of these results attacks a signature scheme called HAWK, while the second is an improved attack against reduced-round AES. Anthropic also released a blog pos...
OpenAI has published an update on the incident in which one of its agents escaped its sandbox and accessed Hugging Face infrastructure.
Ubuntu released USN-8622-1 addressing security vulnerabilities in the Linux kernel for versions 24.04 LTS and 26.04 LTS, requiring users to update and reboot their systems.
Ubuntu Security Notice USN-8623-1 addresses multiple vulnerabilities in the linux-nvidia-6.17 kernel, affecting Ubuntu 24.04 LTS, requiring users to update and reboot their systems.
AI agents are designed to improvise as they complete tasks, making broad permissions a growing security risk. Token Security explains why identity, intent-based access controls, and least privilege are becoming the foundation for securing agentic AI. [...]
​​Microsoft has released the KB5101684 preview cumulative update for Windows 11 24H2 and 25H2, which 42 bug fixes and additional feature improvements for the operating system. [...]
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- Arm Firmware Framework for ARMv8-A(FFA);
(CVE-2026-53354, CVE-2026-64520)
A new Mirai-derived IoT botnet can force an infected Linux device to reboot once its main process is killed, giving its persistence mechanisms another opportunity to relaunch it, Nozomi Networks Labs has found. The malware, dubbed Tengu, was discovered by a machine-learning system the company uses t...
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- Arm Firmware Framework for ARMv8-A(FFA);
(CVE-2026-53354, CVE-2026-64520)
More than 30 facilities disrupted in 'coordinated cyberattack,' though officials have yet to name a culprit
A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response.
Braham, Plymouth, South St. Paul and Maple Plain have publicly described a plant outage, communications failures or affected...
Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more than nine years.
According to Russian cybersecurity vendor F6, the threat actors have s...
ShinyHunters claimed the Ernst & Young data breach, threatening to leak stolen tax records unless the firm contacts the group by July 31. The ShinyHunters cybercrime group has taken responsibility for the recently disclosed data breach involving professional services firm Ernst & Young (EY),...
The agency said imports of advanced robots pose cybersecurity and other national security risks.
The post US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security appeared first on SecurityWeek.
Patchs Apple : contournements de Gatekeeper, accès root sur macOS, faille dans le noyau. Aucun zero-day, mais onze failles découvertes avec l'IA.
Le post Apple : plus de 200 failles patchées dans tous ses systèmes, dont 11 trouvées avec l’IA a été publié sur IT-Connect.
Broadcom patched a critical VMware ESXi VM escape flaw (CVE-2026-47876) that could let attackers run code on the host from a compromised virtual machine. Broadcom has released patches to address five vulnerabilities affecting VMware ESXi, vCenter, Workstation, and Fusion, including three rated criti...
Stairwell, the AI SOC that stops breaches no one else can, today announced the availability of Backstory, an agentic investigation platform that traces related malware variants, identifies affected systems, and maps the full blast radius of an incident in seconds, so enterprises know what happened,...
Research from Aryon reveals that each year, 3,731,699 short-lived cloud resources containing highly sensitive information are publicly exposed. This impacts any organization using AWS services that support public sharing. These exposures often last only minutes or hours, too briefly for periodically...
Cloudflare now supports post-quantum (PQ) authentication when connecting to customer origin servers via Authenticated Origin Pulls and Custom Origin Trust Store. This is the first step towards providing PQ authentication for all Cloudflare products.