> TODAY'S SUMMARY (143 articles)
Today's cybersecurity news highlights several critical threats and trends:
1. A breach of the Dutch Institute for Vulnerability Disclosure was enabled by two zero-day vulnerabilities in the Zammad ticketing system, emphasizing the risks associated with open-source software.
2. The Pentagon is under scrutiny following a data breach that exposed personal records of millions of military personnel, raising concerns over data security practices.
3. WatchGuard has patched a severe flaw in its Fireware OS, which could allow remote code execution on its appliances, while Cisco's SD-WAN Manager faces similar vulnerabilities being actively exploited.
4. Reports indicate a significant rise in vulnerability disclosures, now exceeding 10,000 monthly, driven by AI advancements that also enable more frequent exploitation of these weaknesses.
5. Attackers are increasingly leveraging AI and custom ChatGPT features to deliver malware, showcasing the evolving tactics in cybercrime.
These incidents underscore the growing sophistication of cyber threats and the urgent need for robust security measures across organizations.
|
// AI-powered summary generated at 20:00
McAfee Mobile Security for iOS combines scam protection, web protection, VPN, Wi-Fi security, and device security checks in a single app. It is also available for Android. After downloading the app from the App Store, I created an account and completed a short onboarding process. The app asks whethe...
Tracked as CVE-2026-11405, the vulnerability allows unauthenticated attackers to access a device's web management interface.
The post Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices appeared first on SecurityWeek.
Network analysts who open packet captures in Wireshark push untrusted data through a large set of protocol dissectors, and each parser is a spot where a malformed frame can trip up the software. The 4.6.7 maintenance release closes twelve of those weak points. The fixes reach from cellular signaling...
Fraudsters spent 2025 investing in scale. New routes, new tools, and higher message volumes moved through the SMS, voice, and chat channels that businesses rely on to reach customers. Money follows that activity. The Communications Fraud Control Association puts global telecom fraud losses at around...
Researchers at Wiz found that a flaw in six popular AI coding assistants lets a booby-trapped code project quietly take control of a developer's computer. The assistant asks permission to edit one harmless-looking file, but the write lands on a sensitive one instead.
The affected tools are Amazon Q...
Cybersecurity researchers have disclosed details of a new threat actor dubbed Lurking Lizard that has been operating an end-to-end malicious residential proxy business using an infrastructure comprising more than 230 lookalike domains.
The activity dates back to at least August 2022, according to D...
Antivirus vendors and security startups keep shipping AI features that promise to read malware the way a seasoned analyst would. The results inside security teams tell a quieter story. A new paper argues that static analysis of software, the job of deciding whether a program is malicious by examinin...
[This is a Guest Diary by Jason Callahan, an ISC intern as part of the SANS.edu BACS program]
Les sites web des municipalités de Baraolt et de Ghidfalău sont hors service depuis plusieurs jours après avoir été la cible d'une cyberattaque. Les autorités locales travaillent avec des entreprises de maintenance pour rétablir les plateformes. Le maire de Baraolt a annoncé qu'il demanderait le sou...
La Fondation Wagerenhof, une institution pour personnes handicapées à Uster, a été victime d'une cyberattaque par ransomware. L'attaque, qui a eu lieu le 9 juillet, a bloqué l'accès à ses systèmes informatiques et chiffré des données. Bien que la fondation refuse de payer la rançon, elle anticipe un...
A malicious commit disguised as SDK telemetry briefly compromised @injectivelabs/sdk-ts, exfiltrating wallet mnemonics and private keys.
La société Kaneko a annoncé avoir été victime d'une infection par rançongiciel sur certains de ses serveurs. L'accès non autorisé a été détecté le 9 juillet 2026. La société a immédiatement isolé son réseau externe et a mis en place un comité de crise. Bien que l'accès non autorisé aux données opéra...
Le Loyalist College fait face à des problèmes techniques majeurs à l'échelle de l'établissement, ayant mis hors service ses systèmes, services, internet et courriels. Un membre du personnel a indiqué à Quinte News que la perturbation était due à une menace cybernétique provenant d'une source externe...
De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
De multiples vulnérabilités ont été découvertes dans GitLab. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une injection de code indirecte à distance (XSS) et un contournement de la politique de sécurité.
Le comté de Greene, en Géorgie, a dû mettre hors ligne son réseau gouvernemental après avoir découvert un incident de cybersécurité le 9 juillet. Cet incident a perturbé le traitement des paiements et les services des bureaux fiscaux, judiciaires et administratifs. Les spécialistes en cybersécurité...
De multiples vulnérabilités ont été découvertes dans Microsoft Azure Linux. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
De multiples vulnérabilités ont été découvertes dans Wireshark. Elles permettent à un attaquant de provoquer un déni de service à distance et une atteinte à la confidentialité des données.
A 15-year-old boy asked a chatbot for help - and cancelled nearly 47,000 anime streaming subscriptions in under four hours. Meanwhile, researchers have documented the first fully autonomous, agentic AI-driven ransomware attack, "JadePuffer". What does this tell us about the future of cybersecurity?...