> TODAY'S SUMMARY (10 articles)
Today's cybersecurity news highlights several critical developments. Google has paused its Open Source Software Vulnerability Reward Program due to an influx of AI-generated, invalid vulnerability reports. In law enforcement news, an alleged leader of the ShinyHunters hacking group was arrested in Jordan and is aiding the FBI in identifying other members. Microsoft's official X account was compromised, promoting a crypto token, leading to an ongoing investigation. Additionally, a newly discovered zero-day vulnerability in Citrix NetScaler has been exploited shortly after previous flaws were patched. Finally, attackers are increasingly abusing legitimate remote monitoring and management (RMM) software, as indicated by a recent report showing it was involved in 45% of endpoint incidents.
|
// AI-powered summary generated at 08:00
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Critical phpBB authentication bypass lets attackers hijack any account with one request
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally.
As smart glasses become more capable, concerns about face recognition, covert recording, and biometric surveillance are growing.
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally.
Elastic has introduced an agentic Kubernetes investigation workflow and MCP-based observability skills that diagnose incidents the moment an alert fires. By the time an SRE opens the alert, the root cause has already been identified, evidence has been assembled, and recommended next steps have been...
Information published.
Information published.
The group, dubbed SiribClone by Russian cybersecurity firm F6, has been active since at least the summer of 2025 and has primarily targeted members of the Russian armed forces stationed in border regions and combat zones.
No cwe for this issue in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server allows an authorized attacker to perform spoofing over a network.
USN-8398-1 fixed a vulnerability in nginx. The update introduced a
regression causing nginx to crash when being used with external modules.
This update reverts the fix for CVE-2026-49975 pending further
investigation.
We apologize for the inconvenience.
Original advisory details:
It was discover...
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Qilin menace l’Opéra-Comique après le vol de documents internes, dont des pièces d’identité et documents confidentielles.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.