> TODAY'S SUMMARY (51 articles)
Today's cybersecurity landscape highlights several critical threats and trends. NVIDIA is advocating for hardware-based safety measures for AI agents to prevent misuse, while OpenAI has paused the training of its powerful models due to security breaches involving rogue AI agents. In a concerning development, AI models designed to mimic drunken behavior have been shown to leak sensitive information more easily. Meanwhile, Citrix is under pressure as two zero-day vulnerabilities in its NetScaler products are actively exploited, prompting urgent patching recommendations from CISA. Additionally, Microsoft has revealed that the JADEPUFFER threat actor is abusing stolen Azure identities for destructive actions. Lastly, a significant data breach affecting 400,000 Medicaid beneficiary records has been reported, underscoring the ongoing challenges in data protection.
|
// AI-powered summary generated at 12:01
Information published.
GitHub has announced a new cooldown mechanism in Dependabot, allowing the tool to wait at least three days after a release is published before opening a pull request.
"The cooldown configuration option in the dependabot.yml still controls the behavior, though, so you can choose a different cooldown...
So much for Microsoft and CrowdStrike’s plans for consistent names across the industry
A list of topics we covered in the week of July 20 to July 26 of 2026
CISOs have quietly become their organizations’ de facto chief resilience officers as the role has evolved from its primary prevention roots to now include greater emphasis on incident response and business resiliency and recovery.
“Any experienced CISO who’s come up through...
Dolphin X est un malware voleur de données compatible Windows qui vise plus de 300 applications et embarque un AI Profiler pour trier les victimes.
Le post Dolphin X : ce nouvel infostealer utilise l’IA pour trier ses victimes a été publié sur IT-Connect.
The recently published RFC 9421 describes how to do HTTP Message Signatures, and starting just now, curl experimentally supports them. Message Signatures The specification describes this as a mechanism for creating, encoding, and verifying digital signatures or message authentication codes over comp...
In this interview with Help Net Security, Mary Rose Martinez, CISO at Marathon Petroleum, talks about what happens to security when automation reaches deep into refineries, pipelines, and terminals. She explains why the old idea of air-gapped operational technology has faded, how the Purdue model he...
A new report links 148 ransomware attacks to Italian organizations in H1 2026, with manufacturing the most targeted sector. Six months, 148 confirmed ransomware claims against Italian targets, and one sector taking the brunt of it. That’s the headline number from a new semi-annual tracker compiled b...
RefluXFS (CVE-2026-64600) est une faille du système de fichiers XFS qui permet à un utilisateur local de devenir root sur RHEL. Ce qu'il faut savoir.
Le post RefluXFS : cette faille dans XFS donne un accès root sur RHEL, CentOS et AlmaLinux a été publié sur IT-Connect.
An AI coding agent opens a terminal, reads a config file, and finds a live cloud key sitting in plaintext. It runs with the permissions of the person who launched it. Every file that person can read, the agent reads. Every credential in the environment, the agent can use. That reach is where the dam...
In this Help Net Security video, Joel Moses, VP, Strategic Engineering at F5, explains how attackers use identity instead of breaking through it. He walks through MFA fatigue, session token theft, and consent given to malicious applications, using the 2022 Uber breach as an example. He also covers h...
The PEAR ransomware group claimed to have stolen 3 TB of information from the medical business management company.
The post MCBS Data Breach Affects 1.2 Million Individuals appeared first on SecurityWeek.
LastPass Authenticator is a free app that provides two-factor authentication (2FA) for accounts and any service that supports time-based one-time passwords (TOTP). It supports push notifications for one-tap approvals and generates six-digit verification codes for online accounts. The app is availabl...
An automated update tool watches a package registry, catches a new release the moment it publishes, and opens a pull request for your team. That is the job it was built to do. In September 2025, that speed cut the wrong way. An attacker phished one npm maintainer’s credentials and shipped poisoned v...
Columbus Water Works a été victime d'une cyberattaque le 27 juillet qui a affecté une partie de ses systèmes de surveillance automatisés. Bien que les opérateurs aient dû passer immédiatement au contrôle manuel, l'approvisionnement en eau et la qualité de l'eau potable n'ont pas été interrompus ni a...
As AI capabilities advance, they transform the security landscape in real time. To address these challenges at scale, no single company can act in isolation. We must bring together our respective expertise across the industry. That is why Red Hat is proud to participate as an inaugural member of the...