> TODAY'S SUMMARY (10 articles)
Today's cybersecurity news highlights several critical developments. Google has paused its Open Source Software Vulnerability Reward Program due to an influx of AI-generated, invalid vulnerability reports. In law enforcement news, an alleged leader of the ShinyHunters hacking group was arrested in Jordan and is aiding the FBI in identifying other members. Microsoft's official X account was compromised, promoting a crypto token, leading to an ongoing investigation. Additionally, a newly discovered zero-day vulnerability in Citrix NetScaler has been exploited shortly after previous flaws were patched. Finally, attackers are increasingly abusing legitimate remote monitoring and management (RMM) software, as indicated by a recent report showing it was involved in 45% of endpoint incidents.
|
// AI-powered summary generated at 08:00
Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally.
Critical phpBB authentication bypass lets attackers hijack any account with one request
As smart glasses become more capable, concerns about face recognition, covert recording, and biometric surveillance are growing.
Elastic has introduced an agentic Kubernetes investigation workflow and MCP-based observability skills that diagnose incidents the moment an alert fires. By the time an SRE opens the alert, the root cause has already been identified, evidence has been assembled, and recommended next steps have been...
The group, dubbed SiribClone by Russian cybersecurity firm F6, has been active since at least the summer of 2025 and has primarily targeted members of the Russian armed forces stationed in border regions and combat zones.
USN-8398-1 fixed a vulnerability in nginx. The update introduced a
regression causing nginx to crash when being used with external modules.
This update reverts the fix for CVE-2026-49975 pending further
investigation.
We apologize for the inconvenience.
Original advisory details:
It was discover...
Qilin menace l’Opéra-Comique après le vol de documents internes, dont des pièces d’identité et documents confidentielles.
Filigran has announced XTM One, an AI-native agentic layer that automates Continuous Threat Exposure Management (CTEM) workflows across the Filigran XTM Platform. XTM One introduces a dedicated AI orchestration layer that connects OpenCTI and OpenAEV into a single, continuous workflow. Security team...
Signal alerte contre un projet britannique de scan des appareils, jugé dangereux pour la vie privée et la cybersécurité.
Compare internal communication software to find tools that keep every message, file, and meeting your team exchanges private.
Rockwell Automation has announced the launch of three enhanced offerings within the SecureOT solution suite: OT Cybersecurity Assessment Suite, SecureOT Platform Managed Services and Managed Secure Remote Access (MSRA). Facing an increasing volume of alerts and limited visibility into operational te...
Facebook, Instagram, and WhatsApp account for more than two thirds of fraud reports made by Lloyds customers.
Atsign’s AI Architect applies cryptographic protections to agentic software development, aiming to prevent attackers from exploiting vulnerabilities by making application identities effectively invisible.
The post New Platform Uses Cryptographic Invisibility to Protect AI-Built Applications appeared...
Un pirate informatique revendique deux fuites massives touchant l’immobilier français et décrit des accès obtenus grâce à des messageries compromises.
Encrypted messaging app warns device-level checks could be repurposed for censorship
Two Russia-aligned cyber attack campaigns have continued to exploit a security flaw in WinRAR to target Ukrainian organisations, almost a year after patches for the vulnerability were released.
The activity has been attributed by Trend Micro to Earth Dahu (aka Gamaredon) and SHADOW-EARTH-066 (aka U...
The flaws could lead to the disclosure of sensitive information, memory corruption, and disruption of normal system usage.
The post SAP Patches Critical NetWeaver, Commerce Vulnerabilities appeared first on SecurityWeek.
Google paid researcher a tidy $55K bounty for its discovery
University of Toronto researchers have built and tested a proof-of-concept AI-driven computer worm that uses a locally hosted open-weight large language model to reason its way through a network, generate tailored attack strategies for each target it encounters, and replicate itself, all without hum...
Check Point has issued emergency hotfixes for a pair of vulnerabilities affecting VPN deployments that still use the deprecated Internet Key Exchange version 1 (IKEv1) protocol, warning that one of the flaws is already being exploited in the wild.
The more serious issue all...