> TODAY'S SUMMARY (111 articles)
Today’s cybersecurity landscape highlights several significant threats and trends:
1. A massive data breach in Arizona courts has exposed sensitive foster care records, affecting over 150,000 individuals and raising serious privacy concerns.
2. Cisco has issued urgent alerts regarding a zero-day vulnerability in its SD-WAN Manager, actively exploited by attackers to gain administrative access.
3. Google reports that AI-driven vulnerability discoveries are increasingly linked to remote code execution risks, indicating a shift in threat dynamics.
4. The Citrix NetScaler vulnerabilities are under active exploitation, with reports of sophisticated phishing campaigns targeting government and finance sectors.
5. Multiple high-severity vulnerabilities in common software, including OpenSSL and TeamViewer, necessitate immediate patching to safeguard systems.
6. Ukrainian researchers have raised alarms about mobile malware targeting iOS and Android devices, linked to ongoing state-sponsored attacks.
These developments underscore the urgency for organizations to enhance their cybersecurity measures and stay informed of emerging threats.
|
// AI-powered summary generated at 16:00
Several security issues were fixed in curl.
Several security issues were fixed in libheif.
Hackers compromised the Injective Labs SDK project's GitHub repository and used it to publish a malicious package on the Node Package Manager (npm) that stole cryptocurrency wallet private keys and mnemonic seed phrases. [...]
Several security issues were fixed in libsoup.
Xianrui Dong discovered that libheif had an out-of-bounds read in its
HEIF sequence track parser. An attacker could possibly use this issue
to cause a denial of service or obtain sensitive information. This issue
only affected Ubuntu 26.04 LTS. (CVE-2026-47254)
Junyi Liu discovered that libheif had...
Harry Sintonen discovered that curl incorrectly handled credentials when
following HTTP redirects in conjunction with .netrc files. An attacker
could possibly use this issue to obtain sensitive information. This issue
only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS.
(CVE-2024-...
Cisco Talos’ Vulnerability Discovery & Research team recently disclosed three vulnerabilities in WolfSSF, fourteen in GeoVision, and one vulnerability in VTK-DICOM.The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s third-party v...
Datadog Security Labs is warning of "several overlapping campaigns" that are systematically enumerating corporate GitHub organizations, repositories, and user accounts through the GitHub API.
"Operators rely on automated scraping tooling with custom or legitimate-sounding user agents, leveraging Gi...
Users are always seeking more control over their social networking experience to make it better, whether to improve privacy or enhance flexibility. Interoperability between social networking platforms like Facebook and TikTok has so many benefits that solve those issues. Â
Say you’re on multiple pla...
GodDamn ransomware uses the signed PoisonX driver to disable security tools, marking a more advanced version of the Beast ransomware family. Symantec’s Threat Hunter Team found a new ransomware family called GodDamn that first appeared in the wild on May 21, 2026, and analyzed an attack that took pl...
Microsoft has taken apart a destructive Windows backdoor it calls GigaWiper. What stands out is how it is built: not one tool but three older destructive programs bolted into one, offered as commands the operator can choose from.
Each is a different way to break a machine: wipe the whole disk, over...
With Wimbledon's help, Hazel argues against the popular myth that "Attackers only need to be right once, but defenders need to be right 100% of the time."
La Cour de justice de l'Union européenne a clarifié l'articulation entre le RGPD et la liberté d'expression, jugeant qu'une législation nationale ne peut exclure l'application du règlement pour une base de données de condamnations pénales qui ne poursuit pas une finalité journalistique.L'affaire éma...
Le non-respect du délai de réponse à une demande d'accès à des enregistrements de vidéosurveillance, entraînant leur suppression, constitue une double violation du droit d'accès (article 15) et du droit à la limitation du traitement (article 18), la conservation des images étant justifiée par l'inté...
The anti-fraud crackdown, dubbed Operation First Light, identified more than 142,000 victims of various social-engineering scams.
The post Interpol cybercrime crackdown nets 5,800 arrests across 97 countries appeared first on CyberScoop.
L'autorité néerlandaise de protection des données (AP) recommande aux fournisseurs et utilisateurs de systèmes d'intelligence artificielle d'adhérer à un code de bonnes pratiques publié par la Commission européenne, détaillant les futures obligations de transparence.À compter du 2 août 2026, de nouv...
L'autorité italienne de protection des données (GPDP) a sanctionné la société Character Technologies, Inc. pour de multiples manquements liés à son service d'intelligence artificielle générative, notamment en matière de transparence, de protection des mineurs et de licéité de l'entraînement de ses m...
A new data-extortion group called Helix is using identity-focused tactics such as voice phishing (vishing), device code phishing, and multi-factor authentication (MFA) abuse to steal data from SharePoint environments. [...]
La Commission Nationale de l'Informatique et des Libertés (CNIL) rappelle les conditions de licéité encadrant la mise en place par un employeur de dispositifs de contrôle de l’activité de son personnel.Un tel dispositif doit respecter trois conditions cumulatives pour être licite. Premièrement, il d...
L'autorité espagnole de protection des données (AEPD) a publié une décision constatant une infraction de l'Université Complutense de Madrid (UCM) pour des manquements en lien avec le principe de minimisation des données, suite à la divulgation de la condition de victime de violence de genre d'une ca...