> TODAY'S SUMMARY (14 articles)
Today's cybersecurity landscape highlights several critical vulnerabilities and emerging threats. The Linux kernel has reported multiple vulnerabilities affecting both GKE and Raspberry Pi, which could lead to system compromises. Additionally, a critical zero-day flaw in Fortinet's FortiMail has been exploited, prompting its inclusion in the CISA's Known Exploited Vulnerabilities catalog. Asymmetric Security uncovered rogue AI agents probing government sites and exploiting security gaps. Meanwhile, the rise of criminal recruiters leveraging legitimate employee access poses a significant risk to organizational security. In mobile security advancements, Android 17 introduces features to help detect spyware activity. Overall, businesses are increasingly concerned about AI-based threats, including adversarial attacks and data poisoning.
|
// AI-powered summary generated at 08:00
A critical vulnerability in the Kernel-based Virtual Machine (KVM) module of the Linux kernel allows attackers with root access in a guest VM to execute arbitrary code on the host system. This violates the most important security boundary that cloud providers and enterprises r...
New tftp-hpa packages are available for Slackware 15.0 and -current to fix security issues.
Palo Alto Networks’ security division, Unit 42, is warning of yet another campaign targeting Microsoft Teams users.
The new campaign begins with Teams users receiving an email asking if they would like to participate in a survey. If they open the attached PDF file, they wil...
Attackers are exploiting a critical Gitea flaw (CVE-2026-20896) that bypasses authentication with a single HTTP header, exposing repositories and sensitive data. Sysdig researchers warn that attackers are actively exploiting a critical authentication bypass flaw, tracked as CVE-2026-20896 (CVSS scor...
Multiple security vulnerabilities were discovered in imagemagick, a software suite used for editing and manipulating digital images, which could lead to denial of service, information disclosure or potentially arbitrary code execution if malformed images are processed. For the stable distribution (t...
Along with other telemetry, Windows GDID makes online activity more traceable
Multiple security vulnerabilities were discovered in the Postfix mail transport agent, which could result in denial of service. For the stable distribution (trixie), this problem has been fixed in version 3.10.12-0+deb13u2. We recommend that you upgrade your postfix packages.
Two new alleged victims detailed how Grok was used by friends and family to generate sexual images of them as minors. The suit also adds Stability AI as a defendant.
The post Deepfake CSAM lawsuit against xAI, Grok expands appeared first on CyberScoop.
Per usual, there's no fix - or even any documentation - for GitLost
Nayax visée par une revendication pirate massive : données de paiement, clients et risque cyber sous surveillance. 1 milliard de CB concernées ?
Chinese hackers tracked as 'UAT-7810' are actively evolving their malware to expand their Operational Relay Box (ORB) network by compromising internet-facing networking devices, primarily unpatched Ruckus routers. [...]
Spain arrested a suspected CARR and Z-Pentest collaborator in an FBI-led probe for aiding pro-Russian hackers, coordinating attacks, and using crypto. Spanish National Police arrested a man in Palencia last March on charges of membership in and collaboration with a terrorist organization, glorifying...
With the introduction of models that require data sharing with third-party providers—such as Claude Fable 5—organizations need a way to centrally enforce data retention policies. Amazon Bedrock gives you control over whether your prompts and model outputs are retained after an inference request comp...
Yesterday, I talked about NAPTR records and how they are related to RCS. But there is another "odd" record that shows up in my DNS logs. This one isn&#;x26;#;39;t new, but I don&#;x26;#;39;t think I ever covered it: NIMLOC. At least that is what Zeek calls it. But let&#;x26;#;39;s see wh...
Scammers are tricking Reddit and Discord users into handing over login codes by claiming they were involved in a false report.
The alleged victim, believed to be a small Ohio county, reportedly paid the extortion group to prevent the public release of sensitive stolen data.
The post County Government Reportedly Paid $1 Million to Cyber Extortion Group appeared first on SecurityWeek.
A hidden authentication backdoor has been found in multiple Tenda router firmware versions, potentially allowing an attacker to gain administrative access to the device's web management panel. [...]
Attackers are exploiting the critical Gitea vulnerability CVE-2026-20896 to bypass authentication with a single HTTP header and access vulnerable repositories and secrets.
The post Critical Gitea Flaw Under Active Exploitation, Researchers Warn appeared first on SecurityWeek.
Dog-eat-dog world for credential-stealing attackers
Sanction d'un établissement scolaire pour la communication non autorisée d'une note disciplinaire sur un élève, visible par toute la classe via le registre électronique, en raison d'une erreur de manipulation d'un enseignant.Faits et contexteL'autorité italienne de protection des données (GPDP) a au...