> TODAY'S SUMMARY (19 articles)
Today's cybersecurity landscape highlights several critical threats and vulnerabilities. Citrix confirmed two severe zero-day vulnerabilities in its NetScaler product, prompting CISA to mandate federal agencies patch their systems immediately. Additionally, a SQL injection vulnerability in Roundcube (CVE-2026-48842) is now actively exploited, endangering unpatched webmail servers. Microsoft has suspended a problematic update (KB5002907) that inadvertently disabled Office licenses for some users. Security experts continue to emphasize the importance of monitoring AI agent memory due to potential risks like API key exposure. Lastly, a recent Ubuntu vulnerability could allow attackers to execute arbitrary code through improperly handled file requests.
|
// AI-powered summary generated at 08:00
Anyone could access other Click To Pray users' personal information. The flaw went unfixed for more than six months after it was reported.
The company claims MAI-Cyber-1-Flash tops Anthropic’s Mythos and OpenAI’s GPT-5.6 Sol in CyberGym testing.
The post Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model appeared first on SecurityWeek.
Oracle Linux 10 has released updated RPMs for libpq and libpq-devel, addressing CVE-2026-6477 by rebasing to upstream release 16.14, available on the Unbreakable Linux Network.
Oracle Linux 10 has an updated kernel package addressing CVE-2026-46323, including driver signing changes, certificate updates, and disabling signing for aarch64, reflecting multiple enhancements and conflicts.
Governments are switching, but I’m not sure it makes a difference:
…some municipalities, including Denver, Colorado, are ditching their Flock arrays. But keep in mind that if they’re only switching from Flock to another brand of license-plate readers, like Axon, it’s like a gambling addict trying to...
Oracle released updates for MariaDB Connector C on Oracle Linux 10 to address CVE-2026-44172, along with various related package versions for x86_64 and aarch64 architectures.
Oracle Linux 10 has released updates for several packages addressing security vulnerabilities associated with CVEs 2026-54512 and 2026-54513, including changes to Tomcat app server selection.
JetBrains has fixed a critical vulnerability (CVE-2026-63077) affecting TeamCity On-Premises and is urging admins to upgrade self-hosted servers as soon as possible. “For those who are unable to do so, we have released a security patch plugin,” noted Daniel Gallo, Solutions Engineering Lead at JetBr...
Oracle Linux 10 has received an update with new kernel RPMs addressing various security vulnerabilities and related CVEs, including fixes for memory leaks and permission issues.
Oracle released updated rpms for Oracle Linux 10 addressing CVE-2026-27145, featuring go-fdo-client version 1.0.0-4 rebuilt against an updated golang.
The AI models, datasets, and automated systems researchers depend on can be compromised in ways conventional cybersecurity tools aren’t designed to detect. A new project called VERITAS (VERified Infrastructure for Trustworthy AI in Science) aims to close that gap by establishing AI Assurance as a co...
Oracle Linux 10 has received RPM updates for the go-fdo-server package, addressing CVEs CVE-2026-27145 and CVE-2026-39821, with improvements made by rebuilding against updated golang.
Oracle Linux 10 has received updates for libreswan packages, addressing several CVEs, with new versions now available on the Unbreakable Linux Network for x86_64 and aarch64 architectures.
Codex’s /goal feature amplifies bug hunting, but getting good results requires the right prompt, the right scope, and the right number of outcomes per run. For Patch the Planet, our joint initiative with OpenAI to find and fix bugs in open-source software, we pointed Codex at some of the most widely...
Act Security tackles the spiraling patch problem caused by AI’s ability to find new vulnerabilities in existing cloud environments.
The post Act Security Emerges from Stealth to Fight the Patch Problem appeared first on SecurityWeek.
Coca Cola claims data was stolen from its Fairlife business after a recent ransomware attack
Tal Kollander’s history divides neatly into two halves: first as an active hacker and then as the block that stops hacks.
The post Hacker Conversations: Tal Kollander’s Journey From Black Hat to Hack Blocker appeared first on SecurityWeek.
Hackers Target US Firms in FastJson RCE Zero-Day Attacks Attackers are actively exploiting a critical remote code execution flaw in the open-source FastJson Java library, a widely used component in Alibaba-linked enterprise software, without needing user interaction or elevated privileges. Tracked a...
The startup will invest in expanding engineering and sales teams, accelerating ecosystem support, and expanding corporate partnerships.
The post Hush Security Raises $30 Million for AI Agent Governance appeared first on SecurityWeek.
Talos IR's Q2 report highlights a significant surge in phishing-based initial access and the weaponization of legitimate remote management tools. Learn how to sharpen your defenses.