> TODAY'S SUMMARY (143 articles)
Today's cybersecurity news highlights several critical threats and trends:
1. A breach of the Dutch Institute for Vulnerability Disclosure was enabled by two zero-day vulnerabilities in the Zammad ticketing system, emphasizing the risks associated with open-source software.
2. The Pentagon is under scrutiny following a data breach that exposed personal records of millions of military personnel, raising concerns over data security practices.
3. WatchGuard has patched a severe flaw in its Fireware OS, which could allow remote code execution on its appliances, while Cisco's SD-WAN Manager faces similar vulnerabilities being actively exploited.
4. Reports indicate a significant rise in vulnerability disclosures, now exceeding 10,000 monthly, driven by AI advancements that also enable more frequent exploitation of these weaknesses.
5. Attackers are increasingly leveraging AI and custom ChatGPT features to deliver malware, showcasing the evolving tactics in cybercrime.
These incidents underscore the growing sophistication of cyber threats and the urgent need for robust security measures across organizations.
|
// AI-powered summary generated at 20:00
De multiples vulnérabilités ont été découvertes dans les produits Palo Alto Networks. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
De multiples vulnérabilités ont été découvertes dans les produits Juniper Networks. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, un déni de service à distance et une atteinte à la confidentialité des données.
Le comté de Greene, en Géorgie, a dû mettre hors ligne son réseau gouvernemental après avoir découvert un incident de cybersécurité le 9 juillet. Cet incident a perturbé le traitement des paiements et les services des bureaux fiscaux, judiciaires et administratifs. Les spécialistes en cybersécurité...
A 15-year-old boy asked a chatbot for help - and cancelled nearly 47,000 anime streaming subscriptions in under four hours. Meanwhile, researchers have documented the first fully autonomous, agentic AI-driven ransomware attack, "JadePuffer". What does this tell us about the future of cybersecurity?...
Last May, EFF reported that a sheriff’s office in Texas searched data from more than 83,000 automated license plate reader (ALPR) cameras to track down a woman suspected of self-managing an abortion. ALPRs are promoted as tools for keeping communities safe by finding missing persons and locating sto...
GitHub continues to be a scintillating target for attackers because it sits in the middle of the software supply chain and gives threat actors three things they crave: source code, secrets, and automated pipelines to run amok in.
Datadog Security Research has been tracking...
New proftpd packages are available for Slackware 15.0 and -current to fix security issues.
New xorg-server packages are available for Slackware 15.0 and -current to fix security issues.
Proofpoint researcher tells The Reg: 'We estimate the total volume of targets would be a few dozen'
New libXfont2 packages are available for Slackware 15.0 and -current to fix security issues.
mailcap could allow applications to escape sandbox restrictions
Guillaume Winter discovered that pgextwlist, an extension for PostgreSQL implementing a whitelist mechanism for PostgreSQL extensions, was susceptible to SQL injection via crafted schema and user names. For the stable distribution (trixie), this problem has been fixed in version 1.19-1+deb13u1.
Mount Royal University in Calgary says hackers stole and then deleted data from its file storage systems after breaching the university's network. [...]
Ubiquiti patched seven UniFi OS flaws, including critical CVE-2026-50746, which allows command injection in UniFi Connect Application. Ubiquiti released security updates for seven critical UniFi OS vulnerabilities, including a maximum-severity flaw, tracked as CVE-2026-50746 (CVSS score of 10.0), en...
The use of the spyware came to light in 2022, with traces of Predator found on dozens of phones. The scandal led to the resignation of Greece’s intelligence service chief and the prime minister’s chief of staff.
State attorneys general announced the bipartisan agreement with Block, Inc. on Wednesday, saying that the company incorrectly promised users that Cash App offered the same protections as a bank.
Malicious packages on the Node Package Manager (npm) and the Python Package Index (PyPI) delivered stealer malware to developers and users of Paysafe, Skrill, and Neteller payment applications. [...]
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
More fun with AI jailbreaks, this time at the workflow level