> TODAY'S SUMMARY (107 articles)
Today's cybersecurity landscape highlights several significant threats and trends. The FBI is dealing with a potential data breach affecting agents' personal information, while the ShinyHunters group has intensified its activities, targeting vulnerabilities in Oracle PeopleSoft and creating risks for the FBI. Meanwhile, Citrix NetScaler is facing critical zero-day vulnerabilities (CVE-2026-88771, CVE-2026-88772), which are actively exploited, prompting urgent patching recommendations from CISA. In cloud security, the JadePuffer ransomware operator is utilizing AI-driven attacks to compromise Azure environments, leading to the destruction of cloud resources. Additionally, a recent report indicates that over 80,000 organizations have suffered stolen AI logins, raising concerns about the operationalization of AI in cybercrime. Lastly, a $387.5 million breach at Bitget has highlighted ongoing vulnerabilities in cryptocurrency exchanges.
|
// AI-powered summary generated at 16:00
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.
Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
The latest investment round brings the total raised by Abstract to nearly $50 million.
The post Abstract Raises $25 Million to Expand Composable Security Operations Platform appeared first on SecurityWeek.
Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
Two disclosures, five days apart, described the same intrusion from opposite ends —
Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.
US government agencies have warned that Iranian cyber actors are targeting US-based Siemens and Schneider industrial equipment
Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic's Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the Mac.
Accomplish AI, which shared details of the...
Here's how to evaluate security, data sovereignty, and lock-in risk before you commit to a new cloud workspace.
Origin Energy said it was working to figure out how many Australians were affected by a recent data breach.
Check Point Warns of SmartConsole Zero-Day Exploited in Attacks Check Point patched CVE-2026-16232, an authentication bypass vulnerability in its SmartConsole GUI admin panel that allows unauthenticated attackers to obtain an application login token usable to authenticate with administrator privile...
A threat actor abused Anthropic’s Claude Artifacts feature to funnel users toward malware, Huntress researchers have disclosed. Employees at at least 29 organizations were compromised over two days in July, after searching for the Claude desktop app and clicking a sponsored Bing ad. The ad pointed t...
The Chaos ransomware group ran its command-and-control through the victim's own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead of the encryptor.
The implant never opens an outbound connection of its own. Its process talks t...
Researchers say OpenAI flaw let phishing bait create an autonomous corporate mole armed with employee access
Discover how a filepath.Join misconception caused cross-tenant path traversal vulnerabilities in Kubernetes CSI drivers.
Cobalt has introduced Cobalt Autonomous Pentest, a new offering that enables continuous offensive security across an organization’s application portfolio by delivering actionable penetration testing results in as little as 24 hours. AI-assisted development enables organizations to ship software fast...
SentinelOne’s new benchmark, built on the Fast16 case, shows which AI models can sustain a malware investigation and which cannot.
The post Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models appeared first on SecurityWeek.
A regression was introduced in Apache Commons BeanUtils affecting Ubuntu 16.04 LTS due to an incomplete fix for CVE-2014-0114 and CVE-2019-10086, which could allow arbitrary code execution.
The European Commission fined Google €890 million ($1 billion) on Thursday after finding the company had violated the European Union's Digital Markets Act (DMA), which ensures fair online competition. [...]