> TODAY'S SUMMARY (7 articles)
Today's cybersecurity landscape highlights several critical threats and trends. Anthropic is seeking voice data from Claude users to enhance AI model training, raising privacy concerns. A 16-year-old researcher recently exploited a Microsoft analytics service, gaining access to 17 trillion records, showcasing vulnerabilities in major platforms. Meanwhile, Warlock ransomware continues to target critical infrastructure by exploiting year-old SharePoint flaws. In law enforcement news, a suspect linked to the ShinyHunters extortion group has been detained in Jordan, aiding the FBI in identifying other members. Additionally, the China-aligned group TA419 is actively conducting phishing campaigns against U.S. AI policy experts, emphasizing the increasing focus on cyber espionage in sensitive sectors.
|
// AI-powered summary generated at 12:00
1Password has announced 1Password Credential Broker, a new product that securely brokers credentials, tokens, and federated access from 1Password to trusted requesters. The 1Password Credential Broker is available in private beta today, with support for GitHub Actions and a roadmap that extends trus...
Mesa could be made to crash or run programs if it received specially crafted input.
Novo Nordisk suffered a cyberattack where clinical trial data was copied. The breach is confirmed, but no threat actor has claimed responsibility. The Danish pharmaceutical giant Novo Nordisk disclosed a cybersecurity breach that resulted in unauthorized access to internal IT systems and the theft o...
It was discovered that tmux incorrectly handled image cleanup, leading to
a use-after-free vulnerability. A local attacker could possibly use this
issue to cause tmux to crash, resulting in a denial of service.
Trust3 AI has announced AgentDOS, an enterprise control plane that provides visibility into AI agents, including real-time token consumption monitoring across platforms such as Databricks Agent Bricks and Microsoft Copilot Studio. As enterprises rapidly scale AI adoption, a new class of risk is emer...
NewCore argues the next challenge in enterprise security will be managing AI agents, not people.
Cloudflare is deepening our investment in AI with the addition of team members from Ensemble AI, focusing on machine learning infrastructure and efficiency.
A critical vulnerability chain dubbed SearchLeak in Microsoft 365 Copilot Enterprise could allow attackers to steal sensitive data from a target's mailbox, OneDrive, or SharePoint account through a specially crafted URL. [...]
The startup has built a security-first identity platform to protect humans, machines, and AI agents.
The post NewCore Emerges From Stealth Mode With $66 Million in Funding appeared first on SecurityWeek.
Omada has announced Omada Agent Governance, a new solution designed to help organizations bring the same governance discipline to AI agents and non-human identities that they already apply to people. AI agents are rapidly becoming a new class of digital actor inside enterprises. They connect to syst...
Enterprises using the open-source AI orchestration platform Langflow are being urged to patch a high-severity path traversal flaw amid active exploitation, despite a fix having been available for more than two months.
The bug, which stems from improper handling of filenames...
USN-8398-1 fixed a vulnerability in nginx. The update caused a regression
and was temporarily reverted in USN-8398-2. This update introduces a
complete fix for CVE-2026-49975.
We apologize for the inconvenience.
Original advisory details:
It was discovered that nginx incorrectly handled certain...
The ShinyHunters extortion gang stole personal information from more than 137,000 school staff accounts in a Salesforce data theft attack that targeted the widely used Infinite Campus K-12 student information system in March. [...]
A Ukrainian national pleaded guilty to conspiracy to commit wire fraud in connection with the deployment of Conti ransomware, which targeted more than 1,000 victims worldwide. According to the U.S. Department of Justice, 44-year-old Oleksii Oleksiyovych Lytvynenko joined the Conti conspiracy in or a...
According to the company, the directive cited national security authorities. It appears to be the first time such authorities have been used to curtail the export of AI models rather than chips or hardware.
Red Sift has announced a partnership with GMO GlobalSign to provide organizations with a direct path from email authentication to verified brand visibility in the inbox. Red Sift OnDMARC is now available through GMO GlobalSign, enabling secure outbound email protection and the activation of Brand In...
PowerToys 0.100 est disponible : entre Dock multi-écrans, galerie d'extension pour la palette de Commandes... Découvrez les nouveautés de cette version.
Le post PowerToys 0.100 est disponible : une galerie d’extensions pour la Palette de commandes a été publié sur IT-Connect.
A single support ticket became the front door to 275 million student records. The Canvas breach shows how quickly untrusted user content can become a serious security incident when it is rendered inside privileged internal tooling. This was not an exotic attack chain; it was stored XSS, over-scoped...
USN-8405-1 fixed vulnerabilities in CUPS. The update introduced a
regression that cause CUPS to crash when parsing certain large printer PPD
files. This update fixes the problem.
Original advisory details:
Ariel Silver discovered that CUPS incorrectly handled username comparisons
during authoriz...
Modern phishing, BEC, and account takeover attacks increasingly bypass traditional email defenses and create operational strain for security teams. This webinar explores how behavioral AI can help automate detection, investigation, and remediation to reduce alert fatigue and accelerate response time...