> TODAY'S SUMMARY (5 articles)
Today's cybersecurity news highlights several critical issues. OpenAI has acknowledged unauthorized access attempts to four Australian government websites, involving security bypass methods and the use of exposed keys. Citrix has issued patches for actively exploited zero-day vulnerabilities in its NetScaler products, following unofficial warnings that left many users vulnerable. Additionally, Ubuntu is addressing critical regression security issues in curl, which could pose risks to users of version 14.04 LTS. In a positive development, Nvidia launched the Open Agent Safety Platform to enhance governance of agentic AI systems, combining software and hardware for improved monitoring. Overall, the day underscores the ongoing challenges of security vulnerabilities and the need for timely patching.
|
// AI-powered summary generated at 04:00
Security operations centers (SOCs) have spent years struggling under the weight of growing alert volumes, expanding attack surfaces, and chronic staffing shortages. Now artificial intelligence is adding a new complication: not just more information, but more machine-generated...
Des escrocs se font passer pour votre banque ou le support Apple lors d'un appel FaceTime, puis captent en direct vos identifiants et vos codes bancaires.
Le post Cette arnaque FaceTime vide les comptes bancaires en direct a été publié sur IT-Connect.
1.
What is Claude Mythos?
Claude Mythos is an advanced AI model developed by Anthropic and is optimized for cybersecurity and healthcare applications.
Mythos 5 was originally released in April to a small group of vetted technology partners ahead of a planned wider roll...
Out-of-band vulnerabilities surface when an application quietly reaches out to an external system during an attack, and capturing that traffic calls for infrastructure that many researchers assemble on their own. A new open-source project from Microsoft supplies that infrastructure in a package mean...
Microsoft a publié les KB5121767 et KB5121768, deux correctifs pour les PC Dell dont un pilote Intel IPF bloquait la mise à jour Windows de juillet 2026.
Le post Windows 11 – KB5121767 : Microsoft corrige en urgence le bug Intel qui bloquait des PC Dell a été publié sur IT-Connect.
In this Help Net Security video, Thom Langford, EMEA CTO, Rapid7, explains why piling on more security alerts makes a SOC slower to respond. Attackers log in with stolen credentials and use trusted tools like PowerShell instead of custom malware. He shares a case where attackers called a help desk,...
In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system.
The company said it detected and responded to the incident targeting its production infrastructure earlier last week.
"We ident...
Exploitation of the new WordPress vulnerabilities tracked as CVE-2026-60137 and CVE-2026-63030 started soon after disclosure.
The post WP2Shell WordPress Vulnerabilities Exploited in the Wild appeared first on SecurityWeek.
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads.
The rogue gems are listed below -
git_credential_manager (versions...
Developers lean on AI coding assistants for a growing share of their daily work, letting the tools predict the next few lines and accepting many suggestions with a quick glance. Those tools learn from large collections of code, and some of that code can be tampered with before training starts. A poi...
ZoneAlarm Mobile Security is a security app from Check Point designed to protect mobile devices against phishing, malicious websites, unsafe networks, and fraudulent links. It is available for iPhone, iPad, Android, and can run on Apple silicon Macs through the App Store. Getting started The onboard...
Open models are moving into production across more organizations, and the work of securing those deployments increasingly extends beyond the model weights. Mozilla’s The State of Open Source AI 2026 identifies deployment, governance and operational tooling as persistent obstacles as model capability...
Hugging Face disclosed an intrusion that, according to them, was driven end to end by an autonomous AI agent system.
Along similar lines, Sysdig recently published a blog on JADEPUFFER, which it assesses to be an agent-driven ransomware capable of adapting in real time. The report does not identify...
Le Zweckverband Tierische Nebenprodukte Süd (ZTN Süd) de Warthausen a été victime d'une cyberattaque. L'incident a été découvert le 20 juillet après que plusieurs systèmes de serveurs aient été mis hors service par un logiciel de chiffrement. Le Verband travaille actuellement avec des experts extern...
Les écoles du comté de Sumner, dans le Tennessee, ont retardé le début des cours de six jours après avoir découvert un accès non autorisé à leur réseau. Le district, qui dessert environ 31 000 élèves, a informé les autorités locales et fédérales ainsi que le Département de l'Éducation du Tennessee e...
Sophos ZTNA customers now get Sophos Protected Browser as part of Sophos Workspace Protection, extending Zero Trust controls to SaaS and web apps while improving secure RDP and SSH access.
Shun On Electronic a confirmé avoir subi une attaque par chiffrement après avoir reçu un rapport d'anomalie. L'unité de sécurité de l'information a immédiatement activé son mécanisme de réponse et mené des tests et des mesures de protection. Les systèmes d'information internes et le site web officie...
Le 17 juillet 2026, WordPress a publié un correctif pour deux vulnérabilités : CVE-2026-60137 : une injection SQL (SQLi) ; CVE-2026-63030 : celle-ci permet un contournement de la politique de sécurité. Un attaquant peut exploiter ces deux vulnérabilités, de manière combinée, pour obtenir une...