> TODAY'S SUMMARY (111 articles)
Today’s cybersecurity landscape highlights several significant threats and trends:
1. A massive data breach in Arizona courts has exposed sensitive foster care records, affecting over 150,000 individuals and raising serious privacy concerns.
2. Cisco has issued urgent alerts regarding a zero-day vulnerability in its SD-WAN Manager, actively exploited by attackers to gain administrative access.
3. Google reports that AI-driven vulnerability discoveries are increasingly linked to remote code execution risks, indicating a shift in threat dynamics.
4. The Citrix NetScaler vulnerabilities are under active exploitation, with reports of sophisticated phishing campaigns targeting government and finance sectors.
5. Multiple high-severity vulnerabilities in common software, including OpenSSL and TeamViewer, necessitate immediate patching to safeguard systems.
6. Ukrainian researchers have raised alarms about mobile malware targeting iOS and Android devices, linked to ongoing state-sponsored attacks.
These developments underscore the urgency for organizations to enhance their cybersecurity measures and stay informed of emerging threats.
|
// AI-powered summary generated at 16:00
Hackers exploited a zero-day vulnerability in a third-party system to access a KDDI email system for ISPs.
The post 12 Million Impacted by Data Breach at Japanese Telco KDDI appeared first on SecurityWeek.
Microsoft has finally released a security update for its Microsoft Malware Protection Engine, which fixes CVE-2026-50656, the Windows Defender local privilege escalation vulnerability triggered by the RoguePlanet exploit. The vulnerability and the fix CVE-2026-50656 is due to improper link resolutio...
An alternate path to Cyber Essentials Plus certification, without compromising the integrity of the scheme.
Survey of cybersecurity leaders by MetaCompliance finds that many feel boards are uninterested in ever-evolving cyber risks
Affecting every major distribution since 2011, the Linux kernel vulnerability allows attackers to gain root access.
The post 15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google appeared first on SecurityWeek.
It was discovered that Expat used insufficient entropy when generating
hash salt values for its internal hash table. An attacker could use this
to craft an XML document that triggers hash flooding, leading to a
denial of service.
Operation First Light 2026, coordinated by Interpol and funded by the Chinese government, has led to 5,811 arrests
Découverte à l'aide d'une IA, GhostLock (CVE-2026-43499) est une faille du noyau Linux présente depuis 2011. Elle permet à un utilisateur local de devenir root.
Le post GhostLock : cette faille Linux vieille de 15 ans offre un accès root sur la majorité des distributions a été publié sur IT-Connect.
The RoguePlanet zero-day is now fixed in Microsoft Defender. Here's how to make sure your system is protected.
Criminals who pose as police officers, romantic partners, and business suppliers have built fraud operations that reach across continents. A four-month enforcement campaign against these schemes wrapped up, and police in 97 countries and territories took part. Thousands of arrests The campaign, call...
Accenture confirms breach after hacker offers stolen data for sale IT services giant Accenture confirmed a security breach after a threat actor calling themselves “888” claimed to have stolen 35 GB of data, including source code, RSA and SSH keys, Azure personal access tokens, and configuration file...
Because of the way they are trained, large language models capture only a slice of human language. They’re trained on the written word, from textbooks to social media posts, and our speech as captured in movies and on television. These models have minimal access to the unscripted conversations we ha...
Microsoft has announced plans to disable Outlook Web Access (OWA) Light, the lightweight version of the Outlook Web App email client, in a future Exchange Server update. [...]
Everyone seems to have announced a clearinghouse over the past few weeks. We did too. Ours is called Athena, and the main thing that sets it apart is that it was already real and running when we announced it — built quietly months earlier, heads down, taking findings and shipping fixes, because cust...
Wiz discovered GhostApproval, a symlink flaw in six major AI coding assistants that bypasses approval
Millions of developers share their keyboard with GitHub Copilot. Inside Visual Studio Code, it opens their files, writes and edits code, runs scripts, and reworks its own output across many turns. The safety testing that vets these agents still runs on chatbot rules: one harmful prompt, one response...
Cybersecurity researchers have flagged a new ransomware family called GodDamn that employs the PoisonX kernel driver to neutralize security software as part of its defense evasion strategy.
According to a new report published by the Threat Hunter Team from Symantec, the ransomware was first publicl...
The privilege escalation vulnerability tracked as CVE-2026-50656 has been patched with a Microsoft Malware Protection Engine update.
The post Microsoft Patches Defender ‘RoguePlanet’ Vulnerability appeared first on SecurityWeek.
Microsoft fixed RoguePlanet (CVE-2026-50656), a Defender flaw allowing local attackers to gain higher privileges through the Malware Protection Engine. Microsoft released security updates for RoguePlanet, a vulnerability tracked as CVE-2026-50656 (CVSS score of 7.8) affecting the Malware Protection...
Hackers accessed the institution’s internal network and deleted two drives containing employee, student, and university data.
The post Mount Royal University Confirms Data Stolen in Ransomware Attack appeared first on SecurityWeek.