> TODAY'S SUMMARY (14 articles)
Today's cybersecurity landscape highlights several critical threats and developments. Debian has issued advisories for significant vulnerabilities, including an authentication bypass in ruby-rack-session and multiple denial-of-service and arbitrary code execution vulnerabilities in Wireshark. The FBI is making progress against the ShinyHunters group with the arrest of a suspect in Jordan who is cooperating with investigators. Additionally, the China-aligned cyber espionage group TA419 is targeting U.S. AI policy experts with sophisticated credential phishing attacks. Meanwhile, Warlock ransomware continues to exploit unpatched SharePoint vulnerabilities to attack critical infrastructure globally. These incidents underscore the ongoing challenges posed by advanced persistent threats and the evolving tactics of cybercriminals.
|
// AI-powered summary generated at 20:00
Information published.
Information published.
JDY botnet scans SOHO/IoT devices globally to map services and targets, especially US military networks. Lumen’s Black Lotus Labs reported the resurgence of the JDY botnet, a covert reconnaissance network tied to Chinese state-sponsored hacking groups including Volt Typhoon. The network was first sp...
Information published.
Information published.
À peine la faille YellowKey corrigée, une nouvelle zero-day nommée GreatXML menace BitLocker sur les machines Windows. Voici ce que l'on sait.
Le post Microsoft corrige la faille YellowKey, il révèle GreatXML pour contourner BitLocker ! a été publié sur IT-Connect.
Information published.
Information published.
The University of Nottingham confirmed on Wednesday that a hacking group gained access to its student records system in a breach affecting both current students and alums. [...]
Information published.
Information published.
Crypt-SaltedHash incorrectly generated random numbers.
Information published.
Information published.
The CEO thought this was the best way to deal with some email issues
Information published.
Information published.
It was discovered that .NET did not properly handle link resolution before
file access. A local attacker could use this issue to perform unauthorized
file tampering and write arbitrary files outside of the intended extraction
directory. (CVE-2026-45491)
It was discovered that .NET did not properly...
The company warned about zero-day attacks exploiting the Exchange Server vulnerability CVE-2026-42897 on May 14.Â
The post Microsoft Patches Exploited Exchange Server Vulnerability appeared first on SecurityWeek.
GitHub has announced what it said are "breaking changes" coming to npm version 12, one of which turns off install scripts by default to combat software supply chain threats.
The changes aim to combat attack techniques that abuse the "npm install" command to trigger the execution of malicious code u...