> TODAY'S SUMMARY (107 articles)
Today's cybersecurity landscape highlights several significant threats and trends. The FBI is dealing with a potential data breach affecting agents' personal information, while the ShinyHunters group has intensified its activities, targeting vulnerabilities in Oracle PeopleSoft and creating risks for the FBI. Meanwhile, Citrix NetScaler is facing critical zero-day vulnerabilities (CVE-2026-88771, CVE-2026-88772), which are actively exploited, prompting urgent patching recommendations from CISA. In cloud security, the JadePuffer ransomware operator is utilizing AI-driven attacks to compromise Azure environments, leading to the destruction of cloud resources. Additionally, a recent report indicates that over 80,000 organizations have suffered stolen AI logins, raising concerns about the operationalization of AI in cybercrime. Lastly, a $387.5 million breach at Bitget has highlighted ongoing vulnerabilities in cryptocurrency exchanges.
|
// AI-powered summary generated at 16:00
EU regulators fined Google $1 billion for favoring its own services in search and restricting Play Store developers.
It was discovered that libinput did not properly escape device
properties. A local attacker could possibly use this issue to inject
arbitrary udev properties and execute arbitrary code as root.
PRISM, our autonomous AI researcher, is now our #1 vulnerability researcher. A look at AI's new threat landscape — and the new kind of defender it demands.
The post A New Threat Landscape Meets A New Kind of Defender appeared first on Wordfence.
A Kremlin-backed group known as Laundry Bear has been using a zero-click phishing technique to break into Zimbra webmail accounts worldwide, the U.S. and other nations said.
CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability. [...]
Phishing for dummies
Ukraine's CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence. [...]
Individuals connected to transnational cyber-scam operations face U.S. visa restrictions under a new policy announced by Secretary of State Marco Rubio.
Black Hat 2026 (Aug 1-6, 2026) brings together over 22,000 security practitioners, researchers, and CISOs who build, break, and defend enterprise infrastructure. They’re security professionals who push the limits of offensive and defensive security and demand proof over promises. As frontier securit...
Aftermarket dealer-installed KARR/SWDS security systems all use the same secure key, say UCSD researchers
International agencies issue joint alert over state-backed campaign exploiting a critical vulnerability in the Zimbra Collaboration Suite
Linux systems using the XFS filesystem suffer from a race condition that could enable an unprivileged local user to gain full root access.
The flaw affects systems with Linux kernel 4.11 or later that have enabled the XFS feature reflink, which permits the creation of copie...
Microsoft Teams and several Microsoft 365 services are experiencing an ongoing outage, with users reporting problems accessing Teams, SharePoint, Excel and the Microsoft 365 Admin Center. [...]
Experts say the era of AI bug hunting is here, so defenders will simply have to adapt to busier workloads
AgentForger allows an attacker to create, insert and remotely control an invisible autonomous AI agent inside a victim organization.
The post OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider appeared first on SecurityWeek.
Most of this week's trouble came dressed as something useful.
A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Other threats hid in open systems, weak code, and normal network traffic.
The threats change every w...
In the second quarter of 2026, the continuing effects of Microsoft’s disruption of the Tycoon2FA phishing platform contributed to sustained declines in several major phishing techniques, while threat actors expanded into Teams-based social engineering and employed increasingly automated and multi-st...
Apprenez à analyser les caches d'images Windows (IconCache et Thumbnail Cache) avec Thumbcache Viewer pour retrouver des traces d'activité en investigation.
Le post Forensic Windows – Partie 6 : analyser les caches d’images a été publié sur IT-Connect.
You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win.
The post Is Patching Dead? Vulnerability Management in the Post-Mythos Era appeared first on SecurityWeek.
Threat actors used credentials obtained from other companies to hack into Chick-fil-A One accounts.
The post Chick-fil-A Accounts Get Fried in Credential Stuffing Attack appeared first on SecurityWeek.