> TODAY'S SUMMARY (107 articles)
Today's cybersecurity landscape highlights several significant threats and trends. The FBI is dealing with a potential data breach affecting agents' personal information, while the ShinyHunters group has intensified its activities, targeting vulnerabilities in Oracle PeopleSoft and creating risks for the FBI. Meanwhile, Citrix NetScaler is facing critical zero-day vulnerabilities (CVE-2026-88771, CVE-2026-88772), which are actively exploited, prompting urgent patching recommendations from CISA. In cloud security, the JadePuffer ransomware operator is utilizing AI-driven attacks to compromise Azure environments, leading to the destruction of cloud resources. Additionally, a recent report indicates that over 80,000 organizations have suffered stolen AI logins, raising concerns about the operationalization of AI in cybercrime. Lastly, a $387.5 million breach at Bitget has highlighted ongoing vulnerabilities in cryptocurrency exchanges.
|
// AI-powered summary generated at 16:00
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Le Thermal Master P3 est-il la meilleure caméra thermique pour smartphone ? Notre test : capteur, mise au point manuelle, cas d'usage et avis.
Le post Test Thermal Master P3 : une caméra thermique de poche pour smartphone a été publié sur IT-Connect.
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Le club de hockey sur glace de Krefeld, les Krefeld Pinguine, a été victime d'une attaque par logiciel malveillant sur son site internet dans la nuit du 25 au 26 juillet. Le club a mis son site hors ligne pour prévenir d'autres dommages et garantir la sécurité des visiteurs. Les Pinguine travaillent...
Le groupe dentaire Primo Caredent a été victime d'une attaque informatique d'extorsion. L'incident pourrait également concerner le centre de Trebaseleghe. L'entreprise a alerté ses patients de ne pas payer ni répondre à des messages suspects, et les données des patients sont actuellement en cours d'...
(Security) hole-ier than thou
Zenith Bank a confirmé avoir été victime d'une cyberattaque qui a permis aux attaquants d'accéder à une quantité limitée d'informations client, notamment des adresses e-mail et des numéros de téléphone. La banque a assuré que les fonds et les comptes des clients sont restés en sécurité et que les sy...
Debian Security Advisory DSA-6400-1 addressed two vulnerabilities in Exim that could lead to privilege escalation for local attackers, recommending an upgrade to version 4.98.2-1+deb13u4.
Lower catch this year.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Blog moderation policy.
The administration set a target date of September for CISA to finalize the rule, but where the agency is headed remains a mystery to some.
The post Industry’s message on CIRCIA: Please ask us fewer questions about cyberattacks appeared first on CyberScoop.
EU fined Google €890M under the DMA for favoring its own services and restricting Play Store competition, with AI search features also under scrutiny. The European Commission hit Google with two fines totalling €890 million on Thursday for violating the Digital Markets Act, one for giving its own se...
Stop the spread (of online recruiting and propaganda)
OnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers. [...]
When an administrator introduces a rule change in AWS Network Firewall and network connectivity is disrupted, pinpointing the cause requires inspecting multiple points in the traffic path. The firewall gives you stateless and stateful rule engines, domain rules, and routing to the firewall endpoint...
Roughly 1 in 4 of those compromised IPs are based in the United States, Lumen’s Black Lotus Labs said. Botnets like IPIDEA have also rebounded quickly, surpassing their pre-disruption footprint.
The post Despite multiple takedowns, botnets continue to grow appeared first on CyberScoop.
Certighost (CVE-2026-54121) : cette faille dans AD CS permet à un utilisateur standard de compromettre un domaine Active Directory. Protégez-vous.
Le post Certighost (CVE-2026-54121) : un compte AD standard suffit pour usurper un contrôleur de domaine a été publié sur IT-Connect.
Summary The EU’s 21st Russia sanctions package introduces a transaction ban on 14 crypto-related service platforms across six jurisdictions: Georgia,…
The post The EU’s 21st Russia Sanctions Package Targets Crypto Platforms for Sanctions Evasion, Introduces Third-Country Ban Mechanism appeared first...
A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]
L'envoi de mots de passe en clair par courriel, y compris dans le message de bienvenue, constitue une violation de l'obligation de sécurité de l'article 32 du RGPD, et ce, même si les mots de passe sont chiffrés dans le système d'information du responsable de traitement.Faits et contexteL'autorité e...