> TODAY'S SUMMARY (143 articles)
Today's cybersecurity news highlights several critical threats and trends:
1. A breach of the Dutch Institute for Vulnerability Disclosure was enabled by two zero-day vulnerabilities in the Zammad ticketing system, emphasizing the risks associated with open-source software.
2. The Pentagon is under scrutiny following a data breach that exposed personal records of millions of military personnel, raising concerns over data security practices.
3. WatchGuard has patched a severe flaw in its Fireware OS, which could allow remote code execution on its appliances, while Cisco's SD-WAN Manager faces similar vulnerabilities being actively exploited.
4. Reports indicate a significant rise in vulnerability disclosures, now exceeding 10,000 monthly, driven by AI advancements that also enable more frequent exploitation of these weaknesses.
5. Attackers are increasingly leveraging AI and custom ChatGPT features to deliver malware, showcasing the evolving tactics in cybercrime.
These incidents underscore the growing sophistication of cyber threats and the urgent need for robust security measures across organizations.
|
// AI-powered summary generated at 20:00
Developers who build with AI coding agents grab capabilities off public marketplaces the same way they grab packages from npm or PyPI. The add-ons are called agent skills. Each one is a little bundle of plain-English instructions, scripts, and files that a tool such as Claude Code or OpenAI Codex lo...
Microsoft has released a security patch to address a Defender zero-day vulnerability known as "RoguePlanet," disclosed after the June 2026 Patch Tuesday. [...]
A direct message arrives on Reddit from a stranger, and it invites a reply. That reply is the point. This scheme runs on social engineering, with no malware and no malicious links, and it has spread across Reddit, Discord, and similar platforms. The goal is a single piece of information: a login or...
Ask an AI coding agent to scan open-source code for security holes, and it might run the attacker's code on your own machine instead.
That is the finding in a proof-of-concept published Wednesday by the AI Now Institute, an attack it calls "Friendly Fire." It works against Anthropic's Claude Code a...
Developers are pushing code and opening pull requests across economy borders at a rate GitHub has rarely seen. Outbound collaboration, the sum of git pushes and pull requests sent from developers in one economy to public repositories in another, grew by 16% from Q4 2025 to Q1 2026, according to the...
Outlook va permettre de créer des réponses automatiques basées sur des règles, avec modèles et conditions. pour ne plus répondre pareil à tout le monde.
Le post Outlook va proposer des réponses automatiques basées sur des règles a été publié sur IT-Connect.
Tracked as CVE-2026-11405, the vulnerability allows unauthenticated attackers to access a device's web management interface.
The post Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices appeared first on SecurityWeek.
McAfee Mobile Security for iOS combines scam protection, web protection, VPN, Wi-Fi security, and device security checks in a single app. It is also available for Android. After downloading the app from the App Store, I created an account and completed a short onboarding process. The app asks whethe...
Network analysts who open packet captures in Wireshark push untrusted data through a large set of protocol dissectors, and each parser is a spot where a malformed frame can trip up the software. The 4.6.7 maintenance release closes twelve of those weak points. The fixes reach from cellular signaling...
Fraudsters spent 2025 investing in scale. New routes, new tools, and higher message volumes moved through the SMS, voice, and chat channels that businesses rely on to reach customers. Money follows that activity. The Communications Fraud Control Association puts global telecom fraud losses at around...
Researchers at Wiz found that a flaw in six popular AI coding assistants lets a booby-trapped code project quietly take control of a developer's computer. The assistant asks permission to edit one harmless-looking file, but the write lands on a sensitive one instead.
The affected tools are Amazon Q...
Cybersecurity researchers have disclosed details of a new threat actor dubbed Lurking Lizard that has been operating an end-to-end malicious residential proxy business using an infrastructure comprising more than 230 lookalike domains.
The activity dates back to at least August 2022, according to D...
Antivirus vendors and security startups keep shipping AI features that promise to read malware the way a seasoned analyst would. The results inside security teams tell a quieter story. A new paper argues that static analysis of software, the job of deciding whether a program is malicious by examinin...
[This is a Guest Diary by Jason Callahan, an ISC intern as part of the SANS.edu BACS program]
Les sites web des municipalités de Baraolt et de Ghidfalău sont hors service depuis plusieurs jours après avoir été la cible d'une cyberattaque. Les autorités locales travaillent avec des entreprises de maintenance pour rétablir les plateformes. Le maire de Baraolt a annoncé qu'il demanderait le sou...
Le Loyalist College fait face à des problèmes techniques majeurs à l'échelle de l'établissement, ayant mis hors service ses systèmes, services, internet et courriels. Un membre du personnel a indiqué à Quinte News que la perturbation était due à une menace cybernétique provenant d'une source externe...
De multiples vulnérabilités ont été découvertes dans les produits Juniper Networks. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, un déni de service à distance et une atteinte à la confidentialité des données.
De multiples vulnérabilités ont été découvertes dans les produits Palo Alto Networks. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.