> TODAY'S SUMMARY (5 articles)
Today's cybersecurity news highlights several critical issues. OpenAI has acknowledged unauthorized access attempts to four Australian government websites, involving security bypass methods and the use of exposed keys. Citrix has issued patches for actively exploited zero-day vulnerabilities in its NetScaler products, following unofficial warnings that left many users vulnerable. Additionally, Ubuntu is addressing critical regression security issues in curl, which could pose risks to users of version 14.04 LTS. In a positive development, Nvidia launched the Open Agent Safety Platform to enhance governance of agentic AI systems, combining software and hardware for improved monitoring. Overall, the day underscores the ongoing challenges of security vulnerabilities and the need for timely patching.
|
// AI-powered summary generated at 04:00
Data belonging to more than 23 million users has been exposed following a breach at Paidwork, a platform that pays people for completing online microtasks. Paidwork markets itself as a way to earn money through simple tasks like watching ads, testing apps, and completing surveys, with most jobs payi...
Romania's land registry agency is still recovering from a cyberattack it called "the most serious technical incident in the institution's history."
As AI becomes embedded in customer experiences, internal workflows, and throughout the supply chain, security leaders are being asked to do more than manage risk. They are being asked to help the business make more informed decisions and move faster.
At the same time, AI ha...
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050.
Group-IB, which named the malware HollowGraph, says the approach move...
Attackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. About the vulnerability ServiceNow AI is a Platform-as-a-Service that lets organizations build and automate digital workflows. CVE-...
Extortion groups ShinyHunters and ShadowByt3$ claim they stole vast amounts of patient data. Those allegations have not been verified.
Flock Safety sits right at the center of the debate over where the line should be drawn between privacy and public safety. That’s why we’re bringing Flock’s founder and CEO Garrett Langley to the stage to speak about those very issues.
AI companies can find vulnerabilities and write patches. But only the government can build the long-term defense strategy America needs.
The post Why blocking AI models won’t stop the cyber threats they create appeared first on CyberScoop.
The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533.
The post SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch appeared first on SecurityWeek.
JadePuffer follow-up campaign deployed ENCFORGE locker built to destroy AI model artifacts
Choosing an AI SOC platform requires understanding how it will perform in your own environment, not just during an evaluation. Prophet Security shares a practical framework for assessing AI SOC solutions, including how to validate accuracy, operating models, long-term reliability, and production rea...
Updated the build numbers. This is an informational update only.
A researcher who discovered a critical vulnerability in WordPress has used OpenAI’s latest model to develop an exploit chain
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools.
The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs w...
Dutch intelligence says Russia hacks IP cameras to monitor NATO military logistics and weapons shipments to Ukraine. The Netherlands’ AIVD and MIVD, the civilian and military intelligence services, published a joint advisory on July 10 confirming that at least one Russian intelligence service is sys...
Italy’s data protection authority, the Garante per la Protezione dei Dati Personali, fined WINDTRE €1.7 million over “serious data security shortcomings” that let hackers breach its systems twice and exfiltrate personal data belonging to more than 365,000 customers. The regulator opened its investig...
It was discovered that SQLite did not properly handle NULL pointer
dereferences in the Session Extension when applying a corrupt changeset.
An attacker could possibly use this issue to cause SQLite to crash,
resulting in a denial of service. (CVE-2026-50812)
It was discovered that SQLite had a buff...
Transform SOC data chaos into autonomous intelligence with modern AI pipelines and agentic AI to empower human analysts.
It was discovered that PHP incorrectly handled certain TLS setup failures,
resulting in a NULL pointer dereference. An attacker could possibly use
this issue to cause PHP to crash, resulting in a denial of service. This
issue only affected Ubuntu 26.04 LTS. (CVE-2026-12184)
It was discovered that P...
What to do after a breakup so your ex doesn’t retain access to your accounts, subscriptions, and devices.