> TODAY'S SUMMARY (14 articles)
Today's cybersecurity landscape highlights several critical threats and developments. Debian has issued advisories for significant vulnerabilities, including an authentication bypass in ruby-rack-session and multiple denial-of-service and arbitrary code execution vulnerabilities in Wireshark. The FBI is making progress against the ShinyHunters group with the arrest of a suspect in Jordan who is cooperating with investigators. Additionally, the China-aligned cyber espionage group TA419 is targeting U.S. AI policy experts with sophisticated credential phishing attacks. Meanwhile, Warlock ransomware continues to exploit unpatched SharePoint vulnerabilities to attack critical infrastructure globally. These incidents underscore the ongoing challenges posed by advanced persistent threats and the evolving tactics of cybercriminals.
|
// AI-powered summary generated at 20:00
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced a new Binding Operational Directive, 26-04, that prioritizes security updates for Federal Civilian Executive Branch (FCEB) agencies. [...]
A zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft PeopleTools is being exploited in the wild, Charles Carmakal, CTO at cybersecurity firm Mandiant, part of Google Cloud, warned today. The warning comes a day after Oracle published an out-of-band security alert about the flaw, which is r...
Organizations are aware of the challenges that new technologies like AI bring: but cybersecurity staff struggle to make time for the required training during working hours
Dmitry Tantsur and Tuomo Tanskanen discovered that Ironic did not
properly validate file paths when handling ISO images. A privileged
authenticated remote user could use this issue to perform path
traversal via a crafted ISO image and overwrite arbitrary files on
the Ironic conductor. (CVE-2026-4868...
The new open-source project could serve as the basis for a future of apps with features as complex as Slack, Discord, or Google Docs—but with added protection against surveillance.
Disclosed in March, the security defect enables unauthenticated attackers to write files to arbitrary locations on the system.
The post Hackers Exploit Langflow Vulnerability for Remote Code Execution appeared first on SecurityWeek.
A PowerShell script included in patch files appears to be triggering false positives by multiple security engines.
The post Siemens Says Desigo CC Files Flagged as Malware by Security Engines appeared first on SecurityWeek.
We explain what data was exposed, the potential risks, and the steps you should take now.
For thirty years, vulnerability management ran on a buffer: the months between when a vulnerability was found and when someone could figure out how to weaponize it. The solution was straightforward enough; triage by severity, schedule the fix, validate, and move on. The buffer was what made that wor...
New revelations by Group-IB expose the full scale of the decade-old SniperDz phishing operation
Last June during Pride, we launched a new initiative—LGBT Q&A—where we answered your most pressing queer-related digital rights questions on EFF’s Instagram and TikTok accounts. No question was too big or too small! You asked us things like what pictures to use on dating apps; how to remove your...
The 13 websites purported to be affiliated with consulting companies that advertised job openings for current and former holders of security clearances
The post FBI Seizes 13 Websites That Officials Say Were Used by China to Target and Recruit US Workers appeared first on SecurityWeek.
In digital forensics, the wrong cable can turn a phone extraction from minutes into hours — Alex Coley explains why bandwidth labels are only part of the story in MSAB’s latest blog.
The surveillance company Leonardo wants more data:
A surveillance company plans to add sensors to automatic license plate readers (ALPRs) that would mean the devices, as well as capture the license plate of passing vehicles, would also sweep up unique identifiers of mobile phones, wearables, and oth...
ESET PROTECT Hub version 2.7.0 has been released.
GreatXML bypasses BitLocker via Defender offline scan artifacts, giving SYSTEM shell in Recovery Mode. No patch exists. Any machine that ran an offline scan is vulnerable. On June 10, security researcher Chaotic Eclipse (aka Nightmare Eclipse) published a new working exploit dubbed GreatXML that byp...
Apple and Google have three months to block nude images on children's phones. They're not allowed to collect any data while they do it.
The security defects could allow attackers to create or modify arbitrary files and access and modify protected resources.
The post Splunk, Palo Alto Networks Patch Severe Vulnerabilities appeared first on SecurityWeek.
ServiceNow tells customers a bug left some of their data exposed to the internet Cloud platform giant ServiceNow has notified enterprise customers that a software bug was allowing unauthenticated users to access data stored in customer instances without requiring credentials. The flaw, patched on Ju...
Federal authorities have seized 13 internet domains allegedly used to target current and former U.S. government employees and military personnel with access to classified and sensitive information.
The post FBI seizes 13 websites linked to alleged Chinese intelligence-gathering effort appeared first...