> TODAY'S SUMMARY (7 articles)
Today's cybersecurity news highlights several key trends and threats. Microsoft has made Windows Subsystem for Linux (WSL) containers generally available, allowing administrators to manage their use effectively. A Cisco survey indicates that most organizations require over six months to implement new security controls, with only 8% demonstrating strong defenses against evolving AI threats. Cloudflare is set to introduce post-quantum website certificates by early 2027, signaling a move towards enhancing encryption standards in anticipation of quantum computing risks. Additionally, a critical vulnerability has been identified in the Perl DBI module on Ubuntu 26.04 LTS, which could allow for denial of service or code execution attacks. Lastly, discussions around AI regulation are ongoing, with tech firms agreeing to self-police development practices.
|
// AI-powered summary generated at 04:00
ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities
Microsoft will begin rolling out passkeys as the default authentication experience for Microsoft Entra ID in the public cloud on September 1, 2026. Organizations with SMS or voice authentication enabled will automatically be enabled for passkeys. The next time users complete MFA, they will be prompt...
Five UK residents have been charged in relation to supplying Russian Coms fraud devices and apps
Début juin 2026, un pirate a déployé un script PowerShell vraisemblablement écrit par IA pour énumérer un Active Directory lors d'une cyberattaque.
Le post Des pirates utilisent un script PowerShell généré par IA contre l’Active Directory a été publié sur IT-Connect.
The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) has designated two individuals and a VPN service provider for enabling ransomware actors' and other cybercriminals' malicious activities, including ransomware attacks against Americans.
The VPN, named First VPN Service (1VPNS),...
Information published.
Information published.
When a company falls victim to a ransomware attack, it is not uncommon for it to turn to experts for help.
Specialist ransomware negotiation firms handle communications with criminal gangs on a victim's behalf.
What victims don't expect is that their trusted negotiator might be separately sha...
Information published.
Information published.
New macOS infostealer CrashStealer uses a signed app to bypass Gatekeeper, steals credentials and wallets, then AES-encrypts stolen data. Jamf Threat Labs first spotted CrashStealer in early May 2026 as a suspicious macOS sample uploaded to VirusTotal. By early July, in-the-wild detections confirmed...
Depuis le 14 juillet 2026, la CNIL exige le consentement pour les pixels de suivi dans les e-mails. On vous explique la règle et comment couper le pistage.
Le post Pixels de suivi dans les e-mails : ce que change la CNIL et comment bloquer le pistage a été publié sur IT-Connect.
A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service botnet for roughly two weeks in May, according to new research from JFrog.
The packages did not go after the developers who might install them. The operators used the regis...
CVSSv3 Score:
7.7
An Exposure of Resource to Wrong Sphere vulnerability [CWE-668] in FortiSanbox may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests.
Revised on 2026-07-14 00:00:00
CVSSv3 Score:
6.9
An Improper Restriction of Communication Channel to Intended Endpoints [CWE-923] vulnerability in FortiSIEM Windows Agent may allow an unauthorized attacker on the same local network to execute arbitrary code via spoofing the supervisors hostname when the Windows device...
Enterprises have worked for years to improve detection and response times in the face of increasingly sophisticated attacks that relied on manual hacking and living-of-the-land techniques. AI is now threatening to undo those efforts.
An increasing number of threat actors ar...
CVSSv3 Score:
5.9
A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS, FortiProxy and FortiPAM may allow a privileged authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via crafted HTTP requests.
Revised on 2026-07-14 0...
CVSSv3 Score:
6.1
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS, FortiProxy, FortiPAM and FortiSwitch-Manager Agentless SSL-VPN may allow an authenticated remote user to execute code or commands via crafted reques...
A new CMMC review and reform task force will conduct a comprehensive review of the program.
The post Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules appeared first on SecurityWeek.
CVSSv3 Score:
5.0
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiOS, FortiPAM, FortiProxy and FortiSwitch Manager may allow a privileged authenticated attacker with physical access to the device to delete the file system vi...