[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (1 articles)

|

// AI-powered summary generated at 04:00

> Stolen Meta and Google ad accounts are worth more than the money they hold
Ad account theft, the systematic hijacking of Meta Business Manager and Google Ads accounts, has grown into a commodity-driven cybercrime economy complete with tiered pricing, escrow services, and money-back warranties for stolen accounts. Public reporting on this topic tends to focus on drained ad...
> NCSC Publishes Guidance to Aid Incident Response and Recovery
The National Cyber Security Centre has released a detailed framework to assist with incident response and recovery
> VPN Breach Exposes 58 Million Connection Logs Despite “No-Logs” Claims
A breached “no-logs” VPN exposed 58 million connection logs and millions of user, device, and payment records, contradicting its privacy claims. A threat actor on the Altenen cybercrime forum is distributing a 17 GB SQL database claimed to have been stolen from SplitVPN, formerly known as NotVPN, a...
> 1Password targets standing privileges with new access management capabilities
1Password has launched 1Password Privileged Access, extending the 1Password Unified Access platform with privileged access management (PAM). It enables just-in-time, least-privilege access to critical infrastructure and is accompanied by the public preview of 1Password Credential Broker for GitHub A...
> WhatsApp brings end-to-end encrypted voice and video calls to the web
WhatsApp has launched support for voice and video calls on the web, allowing users to make and receive calls directly from their browser without installing the desktop app. Web Calling (Source: WhatsApp) The new Web Calling feature is designed for people using shared or restricted computers, such as...
> How MFA gets hacked — and strategies to prevent it
The security benefits of multifactor authentication (MFA) are well-known, yet MFA continues to be poorly, sporadically, and inconsistently implemented, undercutting its effectiveness as a security tool while often saddling users with an extra workflow burden — one of many obst...
> Torq makes AI SOC investigations continuously self-learning
Torq has introduced Torq SOC Brain, a new layer of the Torq AI SOC Platform that continuously learns from historical investigations, analyst decisions, and organization-specific security operations to create a unified, self-learning AI SOC. While most autonomous investigation systems claim to be sel...
> Root Evidence puts real-world evidence at the center of vulnerability prioritization
Root Evidence has launched the Evidence Platform, a vulnerability management platform that prioritizes vulnerabilities based on evidence of real-world exploitation and financial impact rather than severity scores alone. The platform is designed to help security teams focus on the vulnerabilities mos...
> Critical Ubuntu 22.04 LTS Linux Kernel Issues With Patch USN-8620-2
Ubuntu 22.04 LTS addresses multiple Linux kernel vulnerabilities through a security update, enhancing system protections against potential exploits related to AMD processors and NTFS file systems.
> Abnormal AI extends behavioral security to identities, AI systems, and insider threats
Abnormal AI has announced the expansion of its Behavioral Security Platform across the enterprise, introducing three new products: Identity Threat Protection, AI Governance, and Infiltration Prevention. Together, the launch extends the behavioral AI that already secures over 4,500 customers1 to the...
> Ubuntu 20.04 LTS Linux Kernel Privilege Escalation Threat USN-8615-2
Ubuntu has addressed multiple security vulnerabilities in the linux-raspi and linux-raspi-5.4 kernels, affecting versions 20.04 and 18.04 LTS, requiring updates and potential reinstallation of third-party modules.
> Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks
State and federal agencies respond after intrusions disrupt automated controls at municipal water and wastewater utilities. The post Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks appeared first on SecurityWeek.
> Mend.io enhances application security with AI runtime protection and faster zero-day response
Mend.io has announced new capabilities across Mend AI and Mend AppSec to help organizations respond faster to both application risk and the expanding attack surface created by AI. Mend.io’s latest enhancements help teams identify meaningful risk, reduce manual investigation, accelerate response and...
> New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands
Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account. Tracked as CVE-2026-60004 (CVSS score: 9...
> USN-8620-2: Linux kernel (Azure FIPS) vulnerabilities
Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could use this to construct a malicious NTFS image that, when mounted and operated on, could expose se...
> USN-8615-2: Linux kernel (Raspberry Pi) vulnerabilities
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503) Several security issues w...
> Realm Security adds Detection Integrity and Data Haven Search to cut SIEM costs
Realm Security has announced two new capabilities. Detection Integrity proves that reducing SIEM log volume never breaks a threat detection. New search inside Realm Data Haven, the platform’s searchable retention layer, makes the data you keep out of the SIEM directly queryable when an analyst needs...
> Tines introduces AI-native platform for secure enterprise workflow automation
Tines has launched Tines 3B, an AI-native platform for building, running and governing enterprise workflows, applications and agents securely at scale. AI has made it possible for every employee to build software in minutes. The result is an explosion of vibe-coded software spread across the enterpr...
> Apple Patches Everything (July 2026), (Wed, Jul 29th)
I am a bit late with this summary, but this week Apple released updates to all its operating systems and Safari. The Safari update, as usual, targets macOS prior to macOS 26. macOS updates covered the two older versions (14 and 15), while other operating system patches only covered the current 26 ve...
> Ransomware report: VPNs in the crosshairs, AI attacks
Ransomware attacks were up year over year in June for the fourth consecutive month, according to the NCC Group, though attacks increased just 3% in Q2 2026 versus the previous quarter. VPNs and other network edge devices continue to be prime initial access targets. And an auto...