[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (107 articles)

|

// AI-powered summary generated at 16:00

> Rubio restricts visas for sextortionists, cyber scammers
The move stems from a Trump executive order as the administration continues to pursue cyber-enabled fraud and other crimes. The post Rubio restricts visas for sextortionists, cyber scammers appeared first on CyberScoop.
> Australian energy provider Origin says data breach exposes client data
Origin Energy has confirmed that an unauthorized party accessed and subsequently leaked customer data online, exposing sensitive personally identifiable information (PII), among others. [...]
> U.S. CISA adds Microsoft SharePoint and Check Point SmartConsole flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SharePoint and Check Point flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added DD-WRT, Langflow, and WordPress flaws to its Known Exploited Vulnerabilities (KEV)...
> Fake Claude app promoted by Bing ads pushes SectopRAT malware
A malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the SectopRAT malware. [...]
> 4 ways AI-driven defense is rewriting the cybersecurity playbook
The cybersecurity landscape has evolved beyond human scale. Today’s adversaries have replaced predictable, manual playbooks with machine-generated attack chains that can breach traditional controls in seconds. To bridge the gap, organizations must move past legacy, reactive co...
> Forgot your Google password? Now you can log in with a selfie.
Google's selfie videos can be used for account access, AI Avatars, and age verification.
> Ubuntu 26.04 LTS libXpm Critical Crash Vulnerability CVE-2026-4367
A vulnerability in libXpm affects Ubuntu 22.04, 24.04, and 26.04 LTS, potentially leading to crashes. Users are advised to update to corrected package versions to resolve the issue.
> Ubuntu 26.04 Rsyslog Critical Denial of Service Vuln USN-8598-1
Ubuntu Security Notice USN-8598-1 addresses vulnerabilities in rsyslog affecting multiple versions of Ubuntu, which could allow remote attackers to cause denial of service. Updates are recommended.
> Introducing Cache Response Rules
Perhaps you’ve seen something that should sail out of cache get dragged back to the origin by a stray Set-Cookie or Cache-Control, headers that can be hard to change on the origin itself. Cache Response Rules is the fix, applied at the right time.
> Ubuntu 26.04 LTS Advisory 8601-1 PAM High Timing Attack
A timing discrepancy in PAM's pam_userdb module could expose sensitive information, affecting multiple Ubuntu releases. Users should update their systems and reboot for the fixes.
> Ubuntu 26.04 LTS 8599-1 libhttp-date-perl Critical Denial of Service
A vulnerability in libhttp-date-perl affects multiple Ubuntu versions, allowing specially crafted input to cause excessive resource usage and potential denial of service; updates are available.
> AegisAI, founded by former Google security execs, lands $36M to stop AI-driven spear phishing
AegisAI co-founders developed AI agents that quickly analyze each message as a human would, paying attention to small anomalies that even the most elaborate checklist wouldn’t catch.
> Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The payload goes after the last 90 days of email, the organization's entire email directory, the password saved in the browser and the codes kept for two-factor r...
> Chaos ransomware deploys browser-based msaRAT to evade network detection
Cisco Talos uncovered msaRAT, a Chaos ransomware RAT that hides C2 traffic by routing it through Chrome or Edge using the Chrome DevTools Protocol. Cisco Talos disclosed msaRAT, a Rust-based remote access trojan attributed to the Chaos ransomware group that routes its entire command-and-control chan...
> For Taylor Swift, Madison Square Garden’s Controversial Cameras Briefly Went Dark
MSG’s sprawling surveillance system can monitor guests down to the second. Its owners made an exception for the pop star’s rehearsal dinner.
> Don’t swing at everything
Thorsten explores Q2 2026 stats, the artificial buffer zone of 2026, and why smart, prioritized patching is more critical than ever.
> Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries
Laundry Bear exploited a zero-day vulnerability for five months before it was patched in July 2025, and the group is still actively exploiting vulnerable environments. The post Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries appeared first on CyberSc...
> US government says Iran-linked hackers are disrupting American water and energy providers
An updated government advisory warns that Iranian hackers are exploiting systems used by water and energy providers.
> EU fines Google $1 billion over its search and Play Store
EU regulators fined Google $1 billion for favoring its own services in search and restricting Play Store developers.
> USN-8602-1: libinput vulnerability
It was discovered that libinput did not properly escape device properties. A local attacker could possibly use this issue to inject arbitrary udev properties and execute arbitrary code as root.