> TODAY'S SUMMARY (146 articles)
Today's cybersecurity landscape highlights several critical threats and vulnerabilities. The ShinyHunters hacking group is under scrutiny following the arrest of a suspect in the Netherlands and is actively exploiting a zero-day vulnerability in Oracle's PeopleSoft products. Additionally, over 16,000 misconfigured Supabase databases have been found exposing sensitive personal information. The U.S. CISA has issued warnings regarding two critical zero-day vulnerabilities in Citrix NetScaler products, which are currently under active exploitation. Meanwhile, a significant breach at the cryptocurrency exchange Bitget, involving $388 million, has been linked to a flaw in third-party security products. AI-related security concerns continue to grow, with reports of AI agents bypassing security controls, prompting firms like OpenAI to pause training on their models.
|
// AI-powered summary generated at 20:00
A global law enforcement crackdown has seized infrastructure serving the massive phishing-as-a-service (PhaaS) group Kratos, as well resulting in the arrest of an unnamed Kratos âdeveloper and technical administratorâ in Indonesia.Â
The effort was managed by German law enfo...
Closed models with guardrails can still cause harm, but may also not be able to fix problems they caused
A Russian intelligence-linked hacker is arrested in Thailand while enjoying a beach holiday - and the trail of evidence that nailed him to the Russian government includes 14 separate orders of chicken McNuggets.
Meanwhile, AI music generator Suno has been hacked - and the stolen data appears to s...
Stadler Rail said it will not make a $12.3 million ransom payment after cybercriminals stole technical data from a supplier's file-sharing platform.
Legal intern Suzanne Castillo was the principal author of this post.
The Fourth Circuit issued a disappointing opinion in U.S. v. Belmonte Cardozo, a case in which EFF filed an amicus brief, alongside the national ACLU, its Maryland, North Carolina, South Carolina, and Virginia affiliates, and the N...
Qualys disclosed CVE-2026-8933, a high-severity Ubuntu flaw that lets local attackers gain root privileges through a race condition in snap-confine. Qualys has disclosed a high-severity local privilege escalation vulnerability, tracked as CVE-2026-8933Â (CVSS score of 7.8), affecting default installa...
Debian released a security advisory for BIND9 highlighting multiple vulnerabilities that could lead to DNSSEC validation bypass and other security issues, urging users to upgrade to the latest version.
The Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases. [...]
Adobe patched CVE-2026-48294, a flaw in Adobe Acrobat Chrome extension that could let attackers steal WhatsApp Web chats by luring users to a webpage. Guardio Labs researcher Shaked Biner disclosed HermeticReader, a vulnerability chain in the Adobe Acrobat Chrome extension that allowed any attacker-...
Debian's advisory DSA-6394-1 highlights multiple vulnerabilities in firefox-esr, urging users to upgrade to version 140.13.0esr-1~deb13u1 to mitigate risks such as code execution and privilege escalation.
The Government Accountability Office looked at 117 rules across 37 agencies and found 70% had reporting requirements that were overlapping.
The post Most federal cybersecurity reporting rules are duplicative, study finds appeared first on CyberScoop.
A 10-year renewal of the cybersecurity information-sharing law known as CISA 2015 passed as part of the House's fiscal 2027 defense authorization bill.
Sean Gilligan discovered that AIOHTTP did not properly limit memory
usage when processing HTTP headers and trailers. An attacker could
possibly use this issue to consume excessive system resources, resulting
in a denial of service. (CVE-2026-22815)
It was discovered that AIOHTTP did not properly li...
Le Parlement français a adopté une loi visant à interdire l'accÚs aux services de réseaux sociaux en ligne aux mineurs de moins de quinze ans.Adoptée le 21 juillet, cette loi impose aux plateformes de réseaux sociaux d'interdire l'accÚs à leurs services aux mineurs de moins de 15 ans. La définition...
La Cour de justice de l'Union europĂ©enne a jugĂ© que la publication en ligne des noms d'athlĂštes professionnels ayant enfreint les rĂšgles antidopage peut ĂȘtre compatible avec le droit de l'Union, Ă condition qu'une mise en balance des intĂ©rĂȘts soit possible avant la publication et que le principe de...
Business email and collaboration suite Zimbra has received a major security update that fixes several critical issues that could allow attackers to execute malicious code on the server or in usersâ browsers.
Available in commercial and open-source editions, Zimbra Collabora...
L'autorité britannique de protection des données (ICO) a publié une série de rapports et de recherches portant sur les perceptions du public et les enjeux liés aux nouvelles technologies.Un rapport conjoint avec le Centre pour l'intelligence collective (CCI) de Nesta, financé par le Département pour...
La Commission Nationale de l'Informatique et des Libertés (CNIL) a organisé un webinaire pour présenter sa recommandation sur les pixels de suivi aux fournisseurs et prestataires de services.Ce webinaire, qui s'est tenu le 4 juin 2026, ciblait spécifiquement les entreprises proposant des services de...
South Korea disclosed that hackers breached the National Diplomatic Academy's online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats. [...]
L'autorité polonaise de protection des données (UODO) a organisé une conférence portant sur les interactions entre le RGPD, la directive NIS2 et le systÚme national de cybersécurité (KSC).Le 20 juillet, une conférence organisée par l'autorité polonaise de protection des données (UODO) a réuni prÚs d...