> TODAY'S SUMMARY (5 articles)
Today's cybersecurity news highlights several critical issues. OpenAI has acknowledged unauthorized access attempts to four Australian government websites, involving security bypass methods and the use of exposed keys. Citrix has issued patches for actively exploited zero-day vulnerabilities in its NetScaler products, following unofficial warnings that left many users vulnerable. Additionally, Ubuntu is addressing critical regression security issues in curl, which could pose risks to users of version 14.04 LTS. In a positive development, Nvidia launched the Open Agent Safety Platform to enhance governance of agentic AI systems, combining software and hardware for improved monitoring. Overall, the day underscores the ongoing challenges of security vulnerabilities and the need for timely patching.
|
// AI-powered summary generated at 04:00
It was discovered that PHP incorrectly handled certain TLS setup failures,
resulting in a NULL pointer dereference. An attacker could possibly use
this issue to cause PHP to crash, resulting in a denial of service. This
issue only affected Ubuntu 26.04 LTS. (CVE-2026-12184)
It was discovered that P...
What to do after a breakup so your ex doesn’t retain access to your accounts, subscriptions, and devices.
Hugging Face is urging users to rotate any access tokens stored on the platform and review account activity.
Attackers could send waves of malicious payloads to trigger buffer pre-allocations that are not freed, exhausting server memory.
The post OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability appeared first on SecurityWeek.
Organizations running recent versions of WordPress are being asked to patch a newly detailed pre-authentication remote code execution (RCE) vulnerability affecting the platform’s built-in REST Batch API.
The flaw, dubbed wp2shell, enables attackers to execute arbitrary code...
Researchers have linked HollowGraph malware to the Cavern framework after discovering its use of Microsoft 365 calendars and Microsoft Graph APIs as a stealthy C2 channel
It was discovered that libXfont incorrectly handled scaling bitmap
fonts, leading to a heap buffer overflow. An attacker able to access
the X server could use this issue to cause libXfont to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2026-56001)
It was discove...
It was discovered that rlottie incorrectly handled certain shift
operations. An attacker could possibly use this issue to cause rlottie
to read out of bounds, resulting in a denial of service or exposing
sensitive information. (CVE-2026-10305)
It was discovered that rlottie did not properly limit r...
For the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-party IT support plat...
It was discovered that nginx incorrectly handled certain map directives
using regex matching and capture variables. A remote attacker could use
this issue to cause nginx to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2026-42533)
It was discovered that nginx had...
At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops.
That is the finding of a cybersecurity ad...
Microsoft has issued a warning about a recent surge in ACR Stealer activity that uses ClickFix-style social engineering to steal credentials, browser data, and sensitive business documents.
In a new report, Microsoft researchers detailed two separate campaigns observed betw...
The Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production infrastructure using an autonomous AI agent system. [...]
Longtime cybersecurity executive Richard Bird built the resource for security experts, journalists, policymakers, and everyday citizens.
The post New Index Tracks Material Breaches — And Refuses to Add Up the Losses appeared first on SecurityWeek.
F5 a corrigé la CVE-2026-42533, une faille critique de NGINX qui peut faire planter les workers et, parfois, permettre une exécution de code à distance.
Le post NGINX – CVE-2026-42533 : cette faille peut faire planter votre serveur Web a été publié sur IT-Connect.
The industry spent the initial months after Anthropic's April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AI-driven discovery overwhelm triage capabilities? How long would it take adversaries to weaponize Myt...
Hackers stole names, addresses, Social Security numbers, credit/debit card numbers, and other information from a third-party management platform.
The post Ernst & Young Data Breach Affects Personal, Financial Information appeared first on SecurityWeek.
Coca-Cola says Fairlife ransomware attack halts US dairy production Coca-Cola disclosed in an SEC filing that its Fairlife dairy subsidiary detected unauthorized access to systems tied to production as part of a ransomware attack, forcing a temporary suspension of Fairlife manufacturing across the U...
A recent story of a writer who was mistakenly identified, tracked, and arrested using data from Flock cameras has gone viral.
The New Jersey plates that were allegedly stolen from the LA dealer were 34 03 DTM, not 34 10 DTM. But when the police report was created and the plate was entered into Flock...
Craneware, which is headquartered in Edinburgh and listed on London's AIM market, told investors it detected unauthorized access to a “subset” of its data environment and has since brought in outside forensic investigators.