> TODAY'S SUMMARY (7 articles)
Today's cybersecurity landscape highlights several critical threats and trends. Anthropic is seeking voice data from Claude users to enhance AI model training, raising privacy concerns. A 16-year-old researcher recently exploited a Microsoft analytics service, gaining access to 17 trillion records, showcasing vulnerabilities in major platforms. Meanwhile, Warlock ransomware continues to target critical infrastructure by exploiting year-old SharePoint flaws. In law enforcement news, a suspect linked to the ShinyHunters extortion group has been detained in Jordan, aiding the FBI in identifying other members. Additionally, the China-aligned group TA419 is actively conducting phishing campaigns against U.S. AI policy experts, emphasizing the increasing focus on cyber espionage in sensitive sectors.
|
// AI-powered summary generated at 12:00
The U.S. Federal Bureau of Investigation (FBI) warned that criminals are using couriers to collect money from victims of cryptocurrency investment scams, also known as pig butchering or romance baiting. [...]
A group made up of dozens of cybersecurity experts urged the White House to remove export control restrictions on Anthropic’s models Fable and Mythos, arguing that the order is going to limit the ability of cybersecurity defenders to secure their software and products.
A China-linked cyber espionage group known as Velvet Ant spent nearly a decade inside the internal network of an unnamed organization without being detected, according to the results of a forensic investigation published by cybersecurity firm Sygnia. The group’s defining characteristic is the abilit...
Mackay Sugar was targeted in a cyberattack carried out by a threat group known as The Gentlemen.
The post Ransomware Attack Shuts Down Mills of Australia’s Second-Largest Sugar Producer appeared first on SecurityWeek.
A single click on a trusted Microsoft link could have let an attacker pull emails, calendar details, and indexed files out of Microsoft 365 Copilot Enterprise Search.
Researchers at Varonis Threat Labs chained three bugs into a one-click exfiltration path they call SearchLeak. Because the link poin...
According to customer complaints, the disruption affected a range of services used by businesses, leading to interruptions in cash register operations, difficulties selling certain regulated goods, loss of access to customer portals and corporate email and problems with electronic human resources do...
Delinea and Cyera announced a product integration that connects privileged access to sensitive data exposure, automatically correlating identities with the data they can access. Together, Delinea and Cyera help security teams identify, prioritize, and remediate the highest-risk access paths across e...
This week on the Lock and Code podcast, we revisit an episode from 2024 with David Chiu that shows the progress made against deepfake porn.
Anthropic has been ordered by the US government to cut off its newest Claude Fable 5 and Mythos 5 models for fear of abuse.
Explore a selection of the latest DFIR employment opportunities in this week’s Forensic Focus jobs round-up.
Google’s Threat Intelligence Group has been tracking the cyberespionage group as UNC6508 since early 2025.
The post Chinese Hackers Target Medical, Military, and AI Research in North America appeared first on SecurityWeek.
nginx could be made to consume excessive resources if it received specially crafted network traffic.
USN-8405-1 introduced a regression in CUPS
Employees are increasingly building automations, agents, and apps with AI tools outside traditional security oversight. Tines explores how CISOs are handling AI-driven code sprawl, shadow tooling, and governance challenges. [...]
tmux could be made to crash if it received specially crafted input.
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information.
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information.
Google Threat Intelligence Group (GTIG) has identified a sophisticated campaign attributed to UNC6508, a People's Republic of China (PRC)-nexus threat actor, targeting institutions in the North American academic, medical, and military research community. While remaining undetected for over a year, t...
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information.
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information.