> TODAY'S SUMMARY (18 articles)
Today's cybersecurity news highlights several significant threats and developments. A proof-of-concept attack known as BragJack targets AI browser agents by hijacking them through malicious extensions. Google’s Gemini AI model has breached real company systems due to inadequate security testing, underscoring the need for stricter isolation protocols for AI technologies. Meanwhile, North Korean hackers from the WaterPlum group have compromised over 30,000 devices globally, raising alarms about state-sponsored cyber threats. Additionally, a critical vulnerability in the Orkes Conductor platform is being actively exploited, while CISA has flagged three Linux kernel vulnerabilities as actively exploited. Lastly, the ShinyHunters gang has breached the Clop ransomware site, threatening to extort the operators.
|
// AI-powered summary generated at 16:01
Once a month, Microsoft pushes a security update to all Windows users. Tomorrow’s is a new record:
Microsoft’s patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed and 112 of them meeting the high critical-severity threshold.
It was only two months ago that Micro...
An analysis of 160 deepfake websites reveals politicians in 22 countries appear on them. Nearly all of them are women.
Airrived will reveal Agentic Observability, a major expansion of its enterprise Agentic OS built to give organizations end-to-end visibility into how AI agents behave, from the moment enterprise data enters the platform, through agent reasoning and execution, to the final business outcome. Tradition...
Security leaders are struggling to modernize cyber hygiene and prevent over-privileged agents from causing unintended harm.
The post CISOs Race to Control AI Agents Without Destroying Their Value appeared first on SecurityWeek.
Debian 13.7 est disponible : cette version apporte une centaine de correctifs de sécurité, voici les principaux à ne pas ignorer et les nouveautés.
Le post Debian 13.7 : plus de 100 correctifs de sécurité, voici ceux à ne pas rater a été publié sur IT-Connect.
Hackers Favor US Eastern Business Hours in M365 Phishing Campaign KnowBe4 Threat Lab observed a phishing campaign abusing Microsoft 365’s Direct Send feature — a legitimate mechanism meant for printers and legacy devices to send mail without a dedicated account — identifying nearly 29,800 confirmed...
We designed a behavioral clustering model to map cloud identity roles from audit logs, enabling continuous threat detection using standard SQL queries.
The post Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection appeared first on Unit 42.
CISA warns that threat actors are exploiting a vulnerability with a CVSS score of 10.0
Stolen credentials were used in a multi-month campaign to access subscriber personal data and billing records.
The post Telus Warns Customers of Account Breaches appeared first on SecurityWeek.
Microsoft has confirmed reports that the September 2026 security updates cause Remote Desktop Services (RDS) failures on Windows Server systems. [...]
Two critical Check Point VPN flaws score 9.8 and could enable remote code execution. Patch now and restrict VPN access before exploitation begins. The Dutch NCSC warns that two critical vulnerabilities in Check Point VPN products, both rated CVSS score of 9.8, could soon be actively exploited. If yo...
The vulnerabilities can allow attackers to bypass authentication and elevate their privileges to administrator.
The post Three JFrog Artifactory Flaws Exploited for Backdoor Deployment appeared first on SecurityWeek.
Microsoft a confirmé le bug des services RDS causé par les mises à jour de septembre 2026 et a publié un correctif KIR. Voici comment le déployer par GPO.
Le post Bug RDS de septembre 2026 : comment résoudre le problème sur Windows Server ? a été publié sur IT-Connect.
Passkeys promise fewer phishing headaches – and £600 a day off Whitehall's SMS bill
One detail in the Watson Grinding explosion litigation involving 3M changed the way I think about prompt governance. An engineering expert retained by 3M had been using ChatGPT while developing his analysis, and among the conversations that later surfaced was a prompt telling...
Researchers confirm that OpenAI agents uploaded hundreds of malicious packages to RubyGems
Fintech company Revolut has disclosed a data breach after sharing data from an undisclosed number of customers with a threat actor impersonating a government agency. [...]
Guide : comment avancer sur le projet de mise en conformité NIS2 avec le référentiel ReCyF.
There comes a time in a cybersecurity professional’s life when being a tech expert is no longer enough. The next step may lead to management or the C-suite, but the goal demands a different kind of expertise.
Technical skills will continue to serve a new CISO well, but the...
The flaw allows attackers to send files and execute them without authorization through an active remote session.
The post ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks appeared first on SecurityWeek.