> TODAY'S SUMMARY (19 articles)
Today's cybersecurity landscape highlights several critical threats and vulnerabilities. Citrix confirmed two severe zero-day vulnerabilities in its NetScaler product, prompting CISA to mandate federal agencies patch their systems immediately. Additionally, a SQL injection vulnerability in Roundcube (CVE-2026-48842) is now actively exploited, endangering unpatched webmail servers. Microsoft has suspended a problematic update (KB5002907) that inadvertently disabled Office licenses for some users. Security experts continue to emphasize the importance of monitoring AI agent memory due to potential risks like API key exposure. Lastly, a recent Ubuntu vulnerability could allow attackers to execute arbitrary code through improperly handled file requests.
|
// AI-powered summary generated at 08:00
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP
subsystem in the Linux kernel when handling socket buffer fragments. This
flaw is known as Fragnesia. A local attacker could use this to escalate
privileges, or possibly escape a container. (CVE-2026-43503)
Several security issues w...
It was discovered that the Linux kernel did not properly handle shared page
fragments during socket buffer operations, collectively known as Dirty
Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the
RxRPC networking subsystem when processing paged fragments. A local
attacker could...
Impacting on-premises deployments, the OS command injection allows attackers to access privileged internal functionality.
The post Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day appeared first on SecurityWeek.
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP
subsystem in the Linux kernel when handling socket buffer fragments. This
flaw is known as Fragnesia. A local attacker could use this to escalate
privileges, or possibly escape a container. (CVE-2026-43503)
Several security issues w...
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- RISC-V architecture;
- Cryptographic API;
- InfiniBand drivers;
- IOMMU subsystem;
- Network drivers;
- ST...
Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness.
The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configuration costs 50% less than its current...
In June 2026, Houston City College was the target of a ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from the college was later published publicly and included 832k unique email addresses along with names, addresses, phone numbers, academic records, and other personal inform...
In this Help Net Security interview, Brandy Wityak, VP of Complex Matters at LevelBlue, explains what happens in the hours after a shadow AI incident. She describes how quickly logs roll over, why firewall records of outbound traffic to AI platforms are often gone before responders arrive, and what...
Researchers tested top image editing models on Hugging Face and found they could easily create explicit deepfakes—and 1,000 image editing prompts show how people use the software.
A ticket comes in for a small bug fix. Hand it to the junior on your team and you wait a day, review something that half works, and sit down to explain what went wrong. Describe it to Claude and the patch merges before lunch. The second path wins on every number your team reports this quarter. It al...
The hacker claimed to have stolen the information of 2 million Origin Energy customers after breaching its systems.
The post Origin Energy Data Breach Affects 900,000 Australians appeared first on SecurityWeek.
Get practical insight from teams who’ve built, scaled and handed over engineering functions at enterprise level. Most engineering teams don’t fail because of bad engineers. They fail because performance is assumed. This playbook shows how high-performance teams are built intentionally across people,...
A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild.
The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave the way for arbitra...
Call of Duty Mobile players should watch out for a phishing campaign disguised as a free Call of Duty Points giveaway, Malwarebytes researchers have warned. Victims are asked to log in with their email address and password to claim free Call of Duty Points (CP), the game’s premium currency, before b...
Cloud Security Engineer Toyota Automated Logistics | USA | On-site – View job details As a Cloud Security Engineer, you will design and enforce security controls across Azure and on-premises environments, strengthen identity and access management, and maintain cloud security posture through policy a...
Summary OFAC designated Zaid Issam Ahmed al-Jebouri, an Iraqi national based in Istanbul, and two associates as Specially Designated Global…
The post OFAC Sanctions Members of Hamas Financing Network appeared first on Chainalysis.
Decades after it appeared in “The Terminator,” Skynet looks more like a forecast of the cyber incident in which a rogue AI system hacked into another AI company on its own.
The post For Some, So-Called ‘Skynet Day’ Came too Close to Sci-Fi After a Rogue Agent Hacked Into a Startup appeared first on...
Traveling enterprise employees beware: Think twice before you log onto that oh-so-convenient public Wi-Fi.
Since at least June, threat actors have been compromising “captive” Wi-Fi gateways and other portal appliances at hotels, conference centers, and similar shared venues...
Microsoft announced a new AI-powered service that enables enterprise security teams to continuously evaluate and update their organization’s security posture through a series of AI agents that can find vulnerabilities, simulate attacks, detect and triage potential threats, and...