> TODAY'S SUMMARY (36 articles)
Today's cybersecurity landscape highlights significant threats and vulnerabilities. A major incident involved hackers hijacking Microsoft's official X account to promote a cryptocurrency scheme, showcasing the ongoing risks of social media exploitation. Additionally, a critical zero-day vulnerability in Fortinet's FortiMail is actively being exploited, prompting urgent action from users and inclusion in the U.S. CISA's Known Exploited Vulnerabilities catalog. On the espionage front, a China-aligned group has been phishing AI policy experts by impersonating US officials, emphasizing the trend of targeting high-profile individuals. Meanwhile, AI agents are increasingly being linked to SQL injection attacks against government sites, raising concerns about the security of AI applications. Lastly, law enforcement has made arrests in the KillSec ransomware group, reflecting ongoing efforts to combat cybercrime.
|
// AI-powered summary generated at 12:00
New mutt packages are available for Slackware 15.0 and -current to fix a security issue.
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. For the stable distribution (trixie), these problems have been fixed in version 6.12.95-1.
Multiple security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in information disclosure, code execution via unsafe deserialisation or cross-site scripting. For the stable distribution (trixie), these problems have been fixed in version 1:1.43.9+df...
Medtronic says a ShinyHunters attack exposed the personal and medical data of over 3.8 million people. Products and operations were unaffected. Medtronic is notifying 3,834,294 individuals after a cyberattack by the ShinyHunters extortion group exposed personal and medical information. In April 2026...
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Hijacked npm Packages Use Novel VSCode Autorun and Blockchain Dead Drops to Deploy a Credential/Crypto Stealer  Building a CI/CD pipeline for Sigm...
Financial institutions are putting their clients at risk in the name of convenience.
Flipper Devices says development of the Flipper Zero firmware will continue, albeit with a smaller internal team and greater reliance on community contributions. [...]
Multiple security vulnerabilities were discovered in the BIRD internet routing daemon, which could result in denial of service. For the stable distribution (trixie), this problem has been fixed in version 3.1.7-0+deb13u1. We recommend that you upgrade your bird3 packages.
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the stable distribution (trixie), these problems have been fixed in version 150.0.7871.46-1~deb13u1.
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Companies keep bolting AI onto their products, and the security bill is coming due Companies keep bolting AI and LLM features onto their products, and the security results are starting to show a pattern...
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. U.S. Government Agency Paid $1M to Data Extortion...
New libseccomp packages are available for Slackware 15.0 and -current to fix security issues.
New libevent packages are available for Slackware 15.0 and -current to fix security issues.
Une enquête a été lancée suite au dysfonctionnement d'une application interne liée au site web de la Police du Kerala, qui gère les fichiers internes. Les autorités soupçonnent une cyberattaque, bien que la police ait affirmé qu'aucune fuite de données n'a eu lieu. L'application est hors service dep...
New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.
Le comté de Pennington, dans le Dakota du Sud, est en train de gérer un incident de cybersécurité affectant certaines parties de son réseau. En réponse, la plupart des bureaux publics du comté seront fermés le lundi 6 juillet, tandis que les autorités travaillent à la restauration sécurisée des syst...
La MSGás, compagnie de gaz de l'État de Mato Grosso do Sul, a notifié ses clients d'un incident de cybersécurité. Un attaque par ransomware a potentiellement exposé des données personnelles telles que le nom, le CPF et l'adresse. La compagnie a pris des mesures pour isoler les systèmes, révoquer les...
A U.S. government agency paid $1M to Kairos, a group focused on data theft and extortion rather than ransomware, Ransom-ISAC reports. A new case study from Ransom-ISAC reconstructs a complete data-extortion incident involving a U.S. government body and a threat actor called Kairos, using a leaked ne...
Alibaba has reportedly classified Claude Code as high-risk software.
Researchers identified what they believe is the first documented case of a ransomware operation, JadePuffer, conducted entirely by a large language model (LLM) agent. [...]