> TODAY'S SUMMARY (17 articles)
Today's cybersecurity news highlights several significant threats and developments. A federal judge deemed the use of Flock for license plate searches as unconstitutional, raising concerns about mass surveillance. In a notable arrest, a member of the ShinyHunters hacking group was detained in Jordan and is cooperating with the FBI. Meanwhile, the Warlock group continues to exploit Microsoft SharePoint vulnerabilities to deploy ransomware. A data breach at the Technical University of Denmark has potentially exposed the information of 200,000 users. Additionally, new vulnerabilities were patched in Fortra's BoKS and GitLab's AI Gateway, underscoring ongoing security risks in software. Lastly, a new ransomware group, N0n, has emerged, indicating an uptick in cyber extortion activities.
|
// AI-powered summary generated at 20:00
Stung by a surge in cyberattacks that have run amok in developer environments, GitHub has strengthened the security of actions/checkout to block ‘pwn request’ attacks that exploit insecure use of the pull_request_target workflow trigger to run an attacker’s code with the workf...
A plethora of pwn-prevention, including a 'Patch The Planet' pledge
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
À partir du 8 juillet 2026, Anthropic pourra demander aux utilisateurs de Claude une pièce d'identité : et si c'était pour donner un accès à Fable 5 ?
Le post Claude : Anthropic va vérifier l’âge et l’identité de ses utilisateurs dès le 8 juillet a été publié sur IT-Connect.
Several security issues were fixed in the Linux kernel.
An ongoing malware campaign is targeting WhatsApp users in multiple countries with deceptive messages that push VBScript files, leading to remote system access. [...]
Une simple inscription comme agent de football ouvrait l'accès aux systèmes de production de la Coupe du monde 2026 : flux TV, scores, commentaires.
Le post Coupe du monde 2026 : une faille FIFA permettait de détourner les flux TV mondiaux a été publié sur IT-Connect.
A judge said the administration’s database violates the Privacy Act, the Social Security Act and the Administrative Procedures Act.
The post Court rules SAVE database illegal, orders it dismantled appeared first on CyberScoop.
Unit 42 research details how attackers could exploit global name uniqueness in bucket hijacking to redirect cloud data streams across major CSPs.
The post The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration appeared first on Unit 42.
The JaredFromSubway Ethereum MEV (Maximal Extractable Value) bot suffered a $15 million loss after an attacker manipulated the opportunity-detection logic by creating fake cryptocurrency trading opportunities. [...]
Several security issues were fixed in libxml2.
A newly disclosed FFmpeg flaw dubbed 'PixelSmash' could be exploited for remote code execution on Jellyfin servers under certain conditions, and can also trigger a denial-of-service condition in applications like Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio. [...]
WhatsApp accounts were hijacked to spread fake debt notices that install remote access software, giving attackers control of victims’ PCs. Kaspersky published a technical analysis this week of an active malware campaign that spreads through WhatsApp messages and ends with a remote management tool si...
Makers of Chrome, Edge, Firefox back bot-fraud defense called Private Access Control Tokens
Security firm SOCRadar says the large-scale FortiBleed campaign targeting Fortinet FortiGate devices used custom sniffers to harvest authentication secrets from compromised firewalls and steal credentials. [...]
Both EOs are expected to be signed as soon as Monday per an industry source with knowledge of timing. The White House has a signing ceremony scheduled this afternoon.Â
The post Trump administration to order agencies to speed up post-quantum migration, boost industry appeared first on CyberScoop.
As yet another extortion crew Icarus exploits Salesforce-linked integrations
Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed. For the stable distribution (trixie), these problems have been fixed in version 7:7.1.5-0+...
The incident comes as Tata Electronics expands its role in global technology supply chains.