[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (51 articles)

|

// AI-powered summary generated at 12:01

> Hackers target US firms in FastJson RCE zero-day attacks
Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. [...]
> Arista patches VeloCloud Orchestrator zero-day exploited in attacks
Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. [...]
> Microsoft debuts AI cybersecurity offerings as competition heats up
It includes the new agentic model MAI-Cyber-1-Flash and the Project Perception platform, with the tech giant claiming it’ll do a better job than its rivals at half the cost. The post Microsoft debuts AI cybersecurity offerings as competition heats up appeared first on CyberScoop.
> Trump asks Supreme Court to let him curtail mail-in voting ahead of midterms
In a Monday filing, the Justice Department said states sued before agencies even decided how the order would work. The post Trump asks Supreme Court to let him curtail mail-in voting ahead of midterms appeared first on CyberScoop.
> Microsoft unveils AI security tools it says outperform competing platforms
Microsoft says tools cost less than competing ones and outperform them, too.
> Reuters: OpenAI Agent Hacked Hugging Face for Days Before Being Detected
Reuters says OpenAI failed to detect its AI agent hacking Hugging Face for days, discovering the breach only after FBI involvement. Reuters reported that the OpenAI agent responsible for the Hugging Face breach operated undetected for over a week before OpenAI realized what had happened, long after...
> New Dysphoria DDoS botnet spreads to 200k devices worldwide
A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations. [...]
> New Certighost PoC exploit lets attackers hijack Windows domains
A proof-of-concept exploit for "Certighost," a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain. [...]
> Outdated VPNs should be purged from federal agencies, senator says
Intelligence Committee member Ron Wyden wants CISA, OMB and NIST to lead a federal effort to rout out obsolete VPNs from the U.S. government.
> IA et dĂ©sinformation : l’alerte de WikimĂ©dia
Wikimédia France propose traçabilité des IA, pluralité des sources et éducation contre la désinformation.
> DHS Official Resigns, Citing ‘War on Immigrants’
The outgoing executive director of the Office of Homeland Security Statistics is one of very few federal officials to speak out against the Trump administration’s immigration crackdown.
> PSA: Your Claude shared chats and Artifacts may have ended up on Google
The issue appears to have originated from Claude’s “share chat” feature, which allows users to create links that enable anyone with the assigned URL view a conversation or project.
> Private Claude Chats Exposed in Google and Bing Search Results
The screwup shows how tricky it can be to stop web crawlers from making ostensibly private conversations with AI chatbots entirely too public.
> Microsoft's solution to AI security: more AI and more acronyms
MDASH stuffed with MAI-Cyber-1-Flash and a side of GPT-5.4
> Missed EFF's Livestream with Adam Savage and iFixit? Listen Here!
EFF’s first EFFecting Change livestream was all the way back in July of 2024. Maybe you've caught each stream, or maybe you’ve only caught a few. Or maybe you’re like me and prefer to listen to conversations like these on your daily commute! Either way, if you want to stay on top of these monthly co...
> Microsoft unveils MAI-Cyber-1-Flash, promises cybersecurity AI at half the cost
Microsoft has introduced MAI-Cyber-1-Flash, a security-focused AI model built into MDASH, the company’s multi-agent vulnerability identification and remediation system. MAI-Cyber-1-Flash is Microsoft’s first model built specifically for cybersecurity work, and the company stated that it went through...
> ClickFix on macOS: how the Terminal-based attack works, and how to protect yourself | Kaspersky official blog
We break down how ClickFix works on macOS: why attackers trick users into running commands in Terminal, what data the malware steals, and how to protect your device.
> AWS Shield Advanced is embracing the AWS WAF Anti-DDoS managed rule group: What changes and how to prepare
Application-layer distributed denial of service (DDoS) attacks are difficult to detect because they closely resemble legitimate traffic. HTTP request floods are now among the most common vectors targeting web applications, using valid-looking requests that blend in with normal user activity. In June...
> Aftercall ads are driving Android users crazy
A newly uncovered ad fraud campaign is spreading Android apps that display full-screen ads every time you end a phone call.
> Microsoft launches its first cybersecurity model, plus a new agentic cybersecurity system
Microsoft bolstered its AI cybersecurity offerings this week with the launch of its first AI security model and a new security platform.