> TODAY'S SUMMARY (114 articles)
Today's cybersecurity landscape highlights several critical concerns. The Warlock ransomware group has escalated its attacks on critical infrastructure, exploiting SharePoint vulnerabilities across various sectors. A significant breach at Frontline Education has exposed sensitive employee data from multiple school districts, raising alarms about third-party software vulnerabilities. Additionally, a zero-day vulnerability in Fortinet's FortiMail is currently being exploited, prompting urgent calls for patches. On the legislative front, bipartisan efforts are underway to regulate automated license plate readers (ALPRs) and site-blocking measures, indicating growing scrutiny over surveillance technologies. As AI continues to advance, concerns about its misuse in cyberattacks are surfacing, with reports of AI agents attempting SQL injection on government sites. Overall, the interplay of AI advancements and critical infrastructure vulnerabilities remains a pressing issue in the cybersecurity domain.
|
// AI-powered summary generated at 20:00
Hackers are targeting NetScaler appliances using public PoC code to retrieve arbitrary memory content in the HTTP response.
The post New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure appeared first on SecurityWeek.
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)
Several security issues were discovered in the Linux kernel.
An attacker could po...
Attackers need little more than a valid SharePoint account to execute code on vulnerable on-prem servers
A top Democrat on the Senate's Intelligence Committee warned that the information accessed on a Homeland Security intelligence-sharing network may risk national security.
Added Edge software to the Security Updates table. Customers that are running supported version of Edge are encouraged to update to the indicated version to be protected from this vulnerability.
Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
ConsentFix and ClickFix attacks steal Microsoft 365 tokens in seconds using fake prompts and OAuth flows. Learn how these MFA bypass tactics work and how to defend against them. [...]
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.
It was discovered that the nghttp2 nghttpx proxy incorrectly handled
HTTP/1.1 Upgrade requests that included a Content-Length header and body.
A remote attacker could possibly use this issue to perform HTTP request and
response smuggling attacks against backend services.
Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.
Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
A suspected Scattered Spider member has been extradited to the United States to face charges linked to cyberattacks against U.S. companies, including the breach of a luxury jewelry retailer that led to an $8 million cryptocurrency ransom demand after attackers stole company data. The retailer’s secu...
It was discovered that LibVNCServer incorrectly handled the Tight decoder
in libvncclient. A remote attacker could use this issue to cause
LibVNCServer to crash, resulting in a denial of service, or possibly
execute arbitrary code.
As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production.
The post How to Conduct a Successful Audit of AI-Driven Software Development appeared first on SecurityWeek.
The threat actor known as ToddyCat has been attributed to a new malware called Umbrij that's designed to gain surreptitious access to a victim's email correspondence via the Google API.
"In this campaign, the attackers focused their attention on corporate email communications hosted on Gmail, targe...
Company that also makes insulin pumps and other devices tells users what was exposed months after ShinyHunters attack
iboss has launched the AI Security Platform, a new service that gives any organization visibility into the AI tools its people are using, free of charge. Signup is instant, deployment takes an afternoon, and a complete AI footprint appears within hours. Organizations that want to go beyond visibilit...
Infosecurity spoke with the researcher who dumped over 30 proof-of-concept exploits without disclosing the vulnerabilities first
A new WinRAR update fixes a serious security flaw, but without automatic updates many users could miss the patch.