> TODAY'S SUMMARY (19 articles)
Today's cybersecurity landscape highlights several critical threats and vulnerabilities. Citrix confirmed two severe zero-day vulnerabilities in its NetScaler product, prompting CISA to mandate federal agencies patch their systems immediately. Additionally, a SQL injection vulnerability in Roundcube (CVE-2026-48842) is now actively exploited, endangering unpatched webmail servers. Microsoft has suspended a problematic update (KB5002907) that inadvertently disabled Office licenses for some users. Security experts continue to emphasize the importance of monitoring AI agent memory due to potential risks like API key exposure. Lastly, a recent Ubuntu vulnerability could allow attackers to execute arbitrary code through improperly handled file requests.
|
// AI-powered summary generated at 08:00
The first publicly documented cyberattack run end-to-end by an autonomous AI was an OpenAI benchmark test that escaped its sandbox and breached Hugging Face. In an incident post-mortem compiled with the input from Hugging Face and several hundred members of Cloud Security Alliance’s CISO community,...
En voyage, découvrez ce que votre fournisseur ou pirate voient et comment protéger vos données sur un Wi-Fi public.
VulnCheck says fewer than 2% of AI-assisted vulnerability discoveries have been weaponized, casting doubt on claims frontier models are handing attackers a major advantage
Debian issued advisory DSA-6401-1 on July 28, 2026, regarding multiple vulnerabilities in Samba that could lead to denial of service, domain takeover, information disclosure, or privilege escalation, urging an upgrade.
Three CVEs in Hugging Face diffusers let a malicious model repo run code on any machine that loads it
Analysis from vulnerability intelligence firm VulnCheck shows AI-discovered flaws aren't being exploited any faster than traditional ones.
The post AI-assisted security tools are finding more bugs, but the threat level has not changed appeared first on CyberScoop.
A new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its main process.
If that happens, Tengu's other persistence mechanisms get another chance to relaunch it. Nozomi Networks Labs observed the dropper reaching its ho...
Oasis Security recently raised $120 million in Series B funding for its agentic access management platform.
The post Cyera Acquiring Oasis Security in $1 Billion Deal appeared first on SecurityWeek.
An employee's email account had been compromised, allowing unauthorized access to "certain data," Bank of Baroda reported.
AI-assisted research uncovered Linux kernel use-after-free allowing root escalation
Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management Interface (IPMI) protocol to the public internet.
Of the 36,872 internet-exposed server-management interfaces running I...
Apple announced that dozens of vulnerabilities have been patched in each of its operating systems.
The post Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe appeared first on SecurityWeek.
A compromised SSO login can provide attackers with access to multiple enterprise applications and services. Specops Software explains how stronger passwords, phishing-resistant MFA, and identity hardening help secure modern SSO environments and the applications they protect. [...]
Customer funds safe, but 14,000 organizations may have to phone in time-sensitive payments
Learn how to classify business data, define protection levels, control access, and reduce exposure with a data classification framework.
JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment.
Artifactory is JFrog's software repository manager. OpenAI says the models then escalated privileges and moved laterally until they re...
Deepfakes have made one of our oldest assumptions unreliable: that you can trust a familiar face or voice. While the industry focuses mainly on building “in-line detection tools” that try to spot the fake, BlackCloak, the leader in Digital Executive Protection (DEP), built Impersonation Protection t...
Bugcrowd unveils Savant Pathseeker, the first solution in its Agentic Offensive Testing line. Savant Pathseeker gives security teams the speed and scale to test every external web application and API continuously, not just the assets that make it onto the pentest schedule, while providing the eviden...
Learn how to build an IT disaster recovery plan for your SMB, including RTO, RPO, backup testing, system priorities, and credential recovery.
Prescient Security has announced a series of capability expansions to Cait (Cacilian AI), its continuous AI-assisted penetration testing service. The updates which will roll out through summer 2026 add attack surface management (ASM), new asset testing types and expanded environment support, extendi...