> TODAY'S SUMMARY (17 articles)
Today's cybersecurity news highlights several significant threats and developments. A federal judge deemed the use of Flock for license plate searches as unconstitutional, raising concerns about mass surveillance. In a notable arrest, a member of the ShinyHunters hacking group was detained in Jordan and is cooperating with the FBI. Meanwhile, the Warlock group continues to exploit Microsoft SharePoint vulnerabilities to deploy ransomware. A data breach at the Technical University of Denmark has potentially exposed the information of 200,000 users. Additionally, new vulnerabilities were patched in Fortra's BoKS and GitLab's AI Gateway, underscoring ongoing security risks in software. Lastly, a new ransomware group, N0n, has emerged, indicating an uptick in cyber extortion activities.
|
// AI-powered summary generated at 20:00
Cybersecurity researchers have discovered a set of malicious npm packages that are designed to deliver a Windows-based remote access trojan (RAT).
The list of identified packages, is below -
aes-decode-runner-pro (145 downloads)
postcss-minify-selector (256 downloads)
postcss-minify-selecto...
OpenAI expanded Daybreak, its cybersecurity initiative that combines AI models, Codex Security, security researchers, maintainers, industry partners, and access controls to support vulnerability discovery and remediation. Organizations can use the initiative to identify, validate, and fix software v...
F5 has introduced the F5 AI Security Platform to give CISOs continuous visibility, governance, and protection across enterprise AI applications, models, agents, and the APIs connecting them. F5 also announced the acquisition of SurePath AI, as a key component in the launch of the new F5 AI Security...
Federal agencies are required to transition high-value assets and high-impact systems to use PQC by the end of 2030 and 2031.
The post Trump Signs Executive Order Accelerating Post-Quantum Cryptography Migration appeared first on SecurityWeek.
The Five Eyes Alliance has published a rare call to action for organizations facing AI threats
Attackers are abusing Outlook Groups and Microsoft 365 collaboration features to make phishing campaigns appear routine, according to Fortra. âThe technique shifts malicious intent away from a single phishing email into a trusted productivity workflow. A user may see what looks like a normal group a...
Attackers backdoored ShapedPlugin Pro updates, deploying malware that steals credentials, 2FA secrets, and grants full site access. If you installed a ShapedPlugin Pro plugin between April and June 2026 and kept it updated, your site may be compromised. Not because you did something wrong, but becau...
A feature update of ESET Secure Authentication 4.35.3.0 has been released.
Squidbleed (CVE-2026-47729) : une faille prĂ©sente depuis 1997 dans le proxy Squid permet de voler en clair les requĂȘtes HTTP d'autres utilisateurs.
Le post Squidbleed : une faille vieille de 29 ans fait fuiter les identifiants des utilisateurs du proxy Squid a été publié sur IT-Connect.
Squidbleed is a 29-year-old Squid Proxy flaw that can leak credentials, tokens, and other usersâ HTTP data through a memory overread. Researchers at Calif.io have disclosed CVE-2026-47729, a memory leak vulnerability in Squid Proxy that was introduced in 1997 and has remained undetected through near...
For years, cybersecurity professionals have been repeating the same warning: Every company will eventually be breached.
Fine. Letâs accept that.
Then why do so many organizations still behave as if the near sole purpose of cybersecurity is to prevent the breach from ever...
Threat actors gained access to personal and protected health information that Xsolis received from its clients.
The post Xsolis Data Breach Affects 1.4 Million Individuals appeared first on SecurityWeek.
Direct messages sent via WhatsApp are being used to distribute malicious Visual Basic Script (VBScript) files that lead to the installation of legitimate Remote Monitoring and Management (RMM) software.
Per findings from Kaspersky, the active campaign is targeting users of WhatsApp Desktop and What...
A research team has built a system that teaches AI agents to hunt for software bugs by writing the audit method down as plain text. The system, called EVOHUNT, keeps the underlying AI model fixed and improves only an external âplaybookâ that tells the agent how to work. One result stands out for any...
Bosses told to step up and get cybersecurity right
Smart TVs in living rooms run small apps that show fish tanks, clocks, solitaire games, and slideshows of puppies. A share of those apps can also send other peopleâs internet traffic out through the home connection. Spur Intelligence scanned 6,038 apps across LG webOS and Samsung Tizen and found 2,0...
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
Researchers at Malwarebytes identified dozens of websites claiming to offer free access to FIFA World Cup matches. Instead of streaming games, the sites directed visitors through a chain of advertising pages designed to generate revenue for their operators. Fake World Cup streaming website (Source:...
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: