> TODAY'S SUMMARY (22 articles)
Today's cybersecurity news highlights several key issues:
1. Two former US Air Force members have been sentenced for running a million-dollar Business Email Compromise (BEC) scheme while in service.
2. A critical zero-day vulnerability in Citrix NetScaler is being actively exploited, with custom web shells identified for gaining root access.
3. High-severity vulnerabilities have been patched in popular cryptographic libraries OpenSSL and WolfSSL, emphasizing the need for timely updates.
4. A new variant of the Spectre attack has emerged, capable of stealing Linux root password hashes in under five minutes.
5. The EU Cyber Resilience Act will impose mandatory cybersecurity requirements starting December 2024, impacting digital products significantly.
These incidents underscore the ongoing threats in both exploitations of software vulnerabilities and advanced persistent threats.
|
// AI-powered summary generated at 08:01
Threat actors have been targeting Balbooa Forms and iCagenda Joomla extension flaws for remote code execution.
The post Organizations Warned of Exploited Joomla Extension Vulnerabilities appeared first on SecurityWeek.
Anthropic has extended a limited-time promotion that increases weekly usage limits in Claude Code by 50% through July 19, 2026, at 11:59 PM PT. When the promotion ends, weekly usage limits will return to their standard levels without any changes to users’ plans or billing. The promotion is available...
Picture the moment after an AI issue is reported.
A security analyst is reviewing a ticket reporting that an internal AI tool produced the wrong recommendation in a live business workflow. The risk is not theoretical anymore. Someone wants to know whether this is a security...
Moving from tool approval to true governance is the only way for CISOs to keep pace with the accelerating velocity of software risk.
The post AI-generated code has made security debt a governance problem appeared first on CyberScoop.
Australian Cyber Security Centre warns CMS users of mass scanning and exploitation campaign
The company notified customers to manually shut down their servers while it is investigating a credible threat.
The post Progress Prompts ShareFile Storage Zone Controller Shutdown Amid Security Concerns appeared first on SecurityWeek.
The WorldLeaks extortion group claimed to have stolen 720 GB of data from the healthcare testing and laboratory services provider.
The post Centers Laboratory Data Breach Affects 540,000 Individuals appeared first on SecurityWeek.
Australia warns of a global campaign exploiting CMS flaws to deploy webshells on WordPress, Joomla, and other websites. Australia’s Signals Directorate has issued an alert about a large-scale exploitation campaign actively targeting content management systems (CMS) worldwide, with many small and med...
An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing switched on. The command that did it: python3 -m http.server 8080, was still sitting in the readable .bash_history.
From that one lapse, French security firm Lexfo ...
Des utilisateurs de Windows 11 rapportent que Cross Device Service, lié à Mobile Connecté, sature la RAM (parfois plus de 30 Go). Microsoft n'a rien confirmé.
Le post Windows 11 : ce composant lié à Mobile Connecté engloutit la RAM de votre PC a été publié sur IT-Connect.
A list of topics we covered in the week of July 6 to July 12 of 2026
At Amazon Web Services (AWS), artificial intelligence is already compressing security work that once took months into minutes.
In the old world, human red teams would find vulnerabilities, write reports, refine those reports, and eventually hand them to defenders, who would...
Debian 13.6 apporte une série de correctifs de sécurité et met à jour fwupd pour accompagner l'expiration du certificat UEFI Secure Boot. Ce qu'il faut savoir.
Le post Debian 13.6 est disponible : découvrez les changements principaux a été publié sur IT-Connect.
Excel, post-it, e-mails : structurez enfin vos accès. Risques, critères de choix et bonnes pratiques du gestionnaire de mots de passe en entreprise.
Le post Gestionnaire de mots de passe en entreprise : pourquoi et comment franchir le pas a été publié sur IT-Connect.
We have made real progress in software supply chain security, improving visibility into software components, authenticity and build integrity. Much of this progress traces back to Executive Order 14028, which pushed agencies, contractors and enterprises to invest in SBOMs, signing and provenance. Al...
Microsoft va déployer le rappel d'e-mails inter-tenant sur Exchange Online dès août 2026, via une liste d'autorisation gérée par l'organisation.
Le post Microsoft 365 : rappeler un e-mail envoyé à une autre entreprise, bientôt possible a été publié sur IT-Connect.
Running a large language model against a live cloud account to hunt for security holes comes with an obvious hazard. An agent that holds real credentials and a mandate to poke around can delete a bucket, flip a permission, or leak a secret on its way to a finding. Cynative, an open-source security r...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation in the wild.
The vulnerabilities, both...
Microsoft has published a guide explaining the Windows servicing model, outlining the purpose of monthly security updates, optional preview releases, hotpatch updates, and the mechanisms used to deliver new features throughout the year. “Most individuals and organizations regularly deploy monthly se...
Meta a lancé Muse Image, un générateur IA capable de puiser dans les photos des comptes Instagram. Voici comment désactiver cette réutilisation par défaut.
Le post Muse Image : comment empêcher Meta de piocher dans vos photos Instagram ? a été publié sur IT-Connect.