> TODAY'S SUMMARY (19 articles)
Today's cybersecurity landscape highlights several critical threats and vulnerabilities. Citrix confirmed two severe zero-day vulnerabilities in its NetScaler product, prompting CISA to mandate federal agencies patch their systems immediately. Additionally, a SQL injection vulnerability in Roundcube (CVE-2026-48842) is now actively exploited, endangering unpatched webmail servers. Microsoft has suspended a problematic update (KB5002907) that inadvertently disabled Office licenses for some users. Security experts continue to emphasize the importance of monitoring AI agent memory due to potential risks like API key exposure. Lastly, a recent Ubuntu vulnerability could allow attackers to execute arbitrary code through improperly handled file requests.
|
// AI-powered summary generated at 08:00
Researchers uncovered the 200,000-device Dysphoria botnet, which uses Ethereum and Solana domains to hide its command servers. QiAnXin XLab, jointly with China’s CNCERT, disclosed Dysphoria, a botnet that has compromised roughly 200,000 devices worldwide and uses Ethereum and Solana blockchain domai...
A regression affecting clipboard functionality in FreeRDP was introduced in an earlier security update. Users should update to resolve the issue in Ubuntu 26.04 LTS and 24.04 LTS.
A cyberattack of undetermined origin disrupted water treatment plants in at least 30 communities in Minnesota, according to the state's technology bureau.
The post Coordinated cyberattack disrupts water utilities in 30+ Minnesota communities appeared first on CyberScoop.
Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128.
The HAWK attack exploits a previously unused symmetry in the lattice behind the signature scheme. Anthropic's released implement...
Choosing the right cryptographic key management service on Amazon Web Services (AWS) starts with understanding the difference between AWS Key Management Service (AWS KMS) and AWS CloudHSM. Both provide key storage backed by a hardware security module (HSM) but serve very different needs. AWS KMS is...
The U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems in the event of a cyberattack or other major disruptions. [...]
A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering. [...]
USN-8561-1 fixed vulnerabilities in FreeRDP. Unfortunately, the upgrade to
version 3.30.0 introduced a regression in the clipboard functionality. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that FreeRDP contained multiple securi...
L'autorité espagnole sanctionne un propriétaire à hauteur de 6 000 € pour l'installation d'un système de vidéosurveillance dans les parties communes d'un appartement loué, en l'absence de base légale valide.Faits et contexteL'autorité espagnole de protection des données (AEPD) a publié le 28 juillet...
L'autorité espagnole de protection des données (AEPD) a clos une procédure de sanction initiée pour traitement illicite de données, en application du principe interdisant une double sanction pour les mêmes faits (*non bis in idem*), après que la personne concernée a été condamnée au pénal.Faits et c...
The post FBI sees Anthropic’s Mythos as a law enforcement challenge appeared first on CyberScoop.
L'autorité italienne de protection des données a infligé une amende de 2 000 000 € à un courtier en données américain pour avoir collecté et vendu illégalement les données de personnes en Italie, affirmant sa compétence sur la base du critère de suivi du comportement prévu par le RGPD.Faits et conte...
Amazon Web Services (AWS) is excited to announce that the latest version of Information Security Registered Assessors Program (IRAP) report (Phase 1a – full assessment) is now available through AWS Artifact. An independent Australian Signals Directorate (ASD) certified IRAP assessor completed the IR...
Microsoft dévoile MAI-Cyber-1-Flash, son premier modèle IA dédié à la cybersécurité, et Project Perception, ses agents rouges, bleus et verts.
Le post Microsoft dégaine MAI-Cyber-1-Flash et Project Perception pour la cybersécurité a été publié sur IT-Connect.
Des chercheurs révèlent qu'une clé Bluetooth unique, partagée par tous les boîtiers antivol KARR et SWDS, ouvre l'accès à 2,2 millions de véhicules.
Le post Cette faille dans le système d’antivol expose 2,2 millions de voitures, mais l’Europe est épargnée a été publié sur IT-Connect.
Recent reports have raised alarm about the use of PatronScan, an ID-checking and face-scanning system, at multiple LGBTQ+ bars in San Francisco’s Castro neighborhood. Much of the attention has focused on reports that the system photographs patrons as they enter venues and questions about whether tho...
On July 28th, 2026, our autonomous AI vulnerability intelligence agent, Wordfence PRISM, identified a critical Authentication Bypass backdoor in Advanced Responsive Video Embedder, a WordPress plugin with approximately 20,000 active installations, less than two hours after the malicious code was int...
Debian addresses two vulnerabilities in hplip that could lead to privilege escalation or code execution, urging users to upgrade to the fixed version 3.22.10+dfsg0-8.1+deb13u1.
Click To Pray expose 700 000 comptes via une faille idiote, avec un risque élevé de phishing ciblé et d’usurpation.
More organizers prohibit camera-equipped specs, even with prescription lenses