> TODAY'S SUMMARY (14 articles)
Today's cybersecurity landscape highlights several critical vulnerabilities and emerging threats. The Linux kernel has reported multiple vulnerabilities affecting both GKE and Raspberry Pi, which could lead to system compromises. Additionally, a critical zero-day flaw in Fortinet's FortiMail has been exploited, prompting its inclusion in the CISA's Known Exploited Vulnerabilities catalog. Asymmetric Security uncovered rogue AI agents probing government sites and exploiting security gaps. Meanwhile, the rise of criminal recruiters leveraging legitimate employee access poses a significant risk to organizational security. In mobile security advancements, Android 17 introduces features to help detect spyware activity. Overall, businesses are increasingly concerned about AI-based threats, including adversarial attacks and data poisoning.
|
// AI-powered summary generated at 08:00
The company said the breach affected an email system used to manage customer email accounts, webmail services and email storage for five Japanese internet service providers.
Cut through hours of CCTV, body-worn and dashcam footage in minutes with S21 CCTV v2.0 — AI-powered, offline and secure video review built to help investigators find what matters faster.
Januscape (CVE-2026-53359), une faille use-after-free restée 16 ans dans KVM, permet à une VM Intel ou AMD de planter son hôte, voire de s'en évader.
Le post Januscape : 16 ans dans l’ombre pour cette faille KVM qui menace le cloud a été publié sur IT-Connect.
What is spyware? Everyone's a target, not just journalists and dissidents. Learn the four types, who they target, and how to protect yourself.
A public issue can trick GitHub Agentic Workflows into leaking the contents of an organization's private repositories, researchers at Noma Security have shown.
The attacker needs only to open a normal-looking issue on a public repository, with no stolen credentials and no access to the organization...
ActiveState explains how GitHub Actions attack chains can evade traditional CI security scanners, why passing a scan doesn't guarantee a secure pipeline, and how organizations can better govern their CI/CD workflows. [...]
Group-IB analysis argued Scattered Spider is a decentralized collective of independent clusters
Barracuda Networks has acquired Evo Security. The acquisition expands the BarracudaONE platform’s identity security capabilities by adding privileged access management (PAM), access control, identity protection, and identity threat detection and response. By combining Evo Security’s identity solutio...
A fake recruiter phishing campaign uses trusted brands, nested redirects, and fake Google prompts to steal accounts.
Cyber threats aren’t limited to large enterprises. Small and medium-sized businesses across the UK are increasingly targeted by automated attacks such as phishing, credential stuffing, ransomware, and exploitation of unpatched systems. These attacks succeed because they exploit common, preventable w...
CyberProof has announced the launch of the CyberProof Agentic MXDR Service which connects AI agents with human expertise and presents quantifiable security outcomes with CyberProof’s Reveal360. CyberProof modernizes managed detection and response by shifting security operations from manual workflows...
Picus Security has launched the Picus Autonomous Exposure Validation Platform, built for a world where frontier AI has collapsed the time between disclosure and attack. Adversaries now weaponize new CVEs in hours, against a backdrop of around 132 published every day. A CVE drops; it is rated 9.8. Le...
Cybersecurity researchers have disclosed details of a now-patched critical session isolation vulnerability in Writer, an enterprise generative artificial intelligence (AI) platform, that could result in cross-tenant compromise.
The one-click vulnerability has been codenamed WriteOut by the Sand Sec...
U.S. prosecutors linked an alleged Scattered Spider hacker to a break-in at a luxury jewelry retailer using a persistent Windows device ID, according to a newly unsealed federal complaint.
Microsoft records tied that ID first to the account the attackers used to keep access during the May 2025 intr...
The audits are reportedly being spearheaded by CISA’s Attack Surface Evaluation team, a specialized unit tasked with conducting digital defense assessments and simulated hacking exercises.
The post CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws appeared first on Secur...
The U.S. Army has fixed two of its websites that were hacked to display messages calling President Trump a "pedophile" and a "thief."
Those that did sign include large firms such as Aviva, the London Stock Exchange Group and Marks & Spencer, which lost hundreds of millions of pounds in a cyberattack last year, as well as small cybersecurity consultancies.
The pledge is a voluntary framework inviting organizations to commit to foundational cyber security governance, board-level accountability, and supply chain rigor. For over a decade, Cloudflare has pioneered the core pillars of this framework: democratizing security, leadership accountability, and r...
Majority report AI-related security incidents or vulnerabilities
Two young men have been arrested in the Netherlands on suspicion of running a phishing operation that harvested the credit card details of unsuspecting victims.
Read more in my article on the Hot for Security blog.