> TODAY'S SUMMARY (107 articles)
Today's cybersecurity landscape highlights several significant threats and trends. The FBI is dealing with a potential data breach affecting agents' personal information, while the ShinyHunters group has intensified its activities, targeting vulnerabilities in Oracle PeopleSoft and creating risks for the FBI. Meanwhile, Citrix NetScaler is facing critical zero-day vulnerabilities (CVE-2026-88771, CVE-2026-88772), which are actively exploited, prompting urgent patching recommendations from CISA. In cloud security, the JadePuffer ransomware operator is utilizing AI-driven attacks to compromise Azure environments, leading to the destruction of cloud resources. Additionally, a recent report indicates that over 80,000 organizations have suffered stolen AI logins, raising concerns about the operationalization of AI in cybercrime. Lastly, a $387.5 million breach at Bitget has highlighted ongoing vulnerabilities in cryptocurrency exchanges.
|
// AI-powered summary generated at 16:00
The move stems from a Trump executive order as the administration continues to pursue cyber-enabled fraud and other crimes.
The post Rubio restricts visas for sextortionists, cyber scammers appeared first on CyberScoop.
Origin Energy has confirmed that an unauthorized party accessed and subsequently leaked customer data online, exposing sensitive personally identifiable information (PII), among others. [...]
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SharePoint and Check Point flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA)Â added DD-WRT, Langflow, and WordPress flaws to its Known Exploited Vulnerabilities (KEV)...
A malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the SectopRAT malware. [...]
The cybersecurity landscape has evolved beyond human scale. Today’s adversaries have replaced predictable, manual playbooks with machine-generated attack chains that can breach traditional controls in seconds. To bridge the gap, organizations must move past legacy, reactive co...
Google's selfie videos can be used for account access, AI Avatars, and age verification.
A vulnerability in libXpm affects Ubuntu 22.04, 24.04, and 26.04 LTS, potentially leading to crashes. Users are advised to update to corrected package versions to resolve the issue.
Ubuntu Security Notice USN-8598-1 addresses vulnerabilities in rsyslog affecting multiple versions of Ubuntu, which could allow remote attackers to cause denial of service. Updates are recommended.
Perhaps you’ve seen something that should sail out of cache get dragged back to the origin by a stray Set-Cookie or Cache-Control, headers that can be hard to change on the origin itself. Cache Response Rules is the fix, applied at the right time.
A timing discrepancy in PAM's pam_userdb module could expose sensitive information, affecting multiple Ubuntu releases. Users should update their systems and reboot for the fixes.
A vulnerability in libhttp-date-perl affects multiple Ubuntu versions, allowing specially crafted input to cause excessive resource usage and potential denial of service; updates are available.
AegisAI co-founders developed AI agents that quickly analyze each message as a human would, paying attention to small anomalies that even the most elaborate checklist wouldn’t catch.
A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client.
The payload goes after the last 90 days of email, the organization's entire email directory, the password saved in the browser and the codes kept for two-factor r...
Cisco Talos uncovered msaRAT, a Chaos ransomware RAT that hides C2 traffic by routing it through Chrome or Edge using the Chrome DevTools Protocol. Cisco Talos disclosed msaRAT, a Rust-based remote access trojan attributed to the Chaos ransomware group that routes its entire command-and-control chan...
MSG’s sprawling surveillance system can monitor guests down to the second. Its owners made an exception for the pop star’s rehearsal dinner.
Thorsten explores Q2 2026 stats, the artificial buffer zone of 2026, and why smart, prioritized patching is more critical than ever.
Laundry Bear exploited a zero-day vulnerability for five months before it was patched in July 2025, and the group is still actively exploiting vulnerable environments.
The post Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries appeared first on CyberSc...
An updated government advisory warns that Iranian hackers are exploiting systems used by water and energy providers.
EU regulators fined Google $1 billion for favoring its own services in search and restricting Play Store developers.
It was discovered that libinput did not properly escape device
properties. A local attacker could possibly use this issue to inject
arbitrary udev properties and execute arbitrary code as root.