> TODAY'S SUMMARY (34 articles)
Today's cybersecurity landscape highlights several critical threats and trends. A significant zero-day vulnerability (CVE-2026-88) in Citrix NetScaler has been actively exploited, prompting urgent updates for affected systems. Similarly, the Rejetto HFS flaw (CVE-2026-61500) is being targeted, allowing attackers to gain administrative access and execute remote code. In the realm of healthcare, a bipartisan bill has been passed to strengthen cybersecurity measures, following over 730 breaches affecting hundreds of millions of Americans last year. On the AI front, Google has paused its open-source bug bounty program due to a surge in invalid, AI-generated vulnerability reports. Additionally, recent arrests connected to cybercrime groups like ShinyHunters signal ongoing efforts to combat organized hacking networks.
|
// AI-powered summary generated at 12:00
Une vulnérabilité a été découverte dans Moodle. Elle permet à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur. Le greffon Socialwall doit être désactivé voire désinstallé.
De multiples vulnérabilités ont été découvertes dans Apache HTTP Server. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, un déni de service à distance et une injection de code indirecte à distance (XSS).
La Université de Konan a annoncé avoir été victime d'une cyberattaque par rançongiciel (ransomware) qui a affecté son serveur de gestion administratif (Active Directory) et une partie de son serveur de fichiers pour le personnel administratif. L'incident a été détecté le 9 juin 2026 et confirmé comm...
De multiples vulnérabilités ont été découvertes dans Apereo CAS. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
L'Université de Nottingham a été victime d'une cyberattaque majeure attribuée au groupe de cybercriminels ShinyHunters. L'incident a permis aux pirates d'accéder à une quantité importante de données dans le système de dossiers des étudiants (plateforme Campus Solutions), incluant des informations pe...
Le responsable du Centre national de cybersécurité de Lituanie (NKVC), Antanas Aleknavičius, a déclaré que les institutions du pays ne font pas face à une cyberattaque coordonnée, malgré deux incidents majeurs récents. Le dernier incident a entraîné la fuite de 62 000 dossiers contenant des données...
Learn more and share your feedback with the team on the Sophos Workspace Protection Community.Categories: Products & ServicesTags: network, Workspace Protection
La Banque Centrale de Libye (CBL) a annoncé avoir été la cible d'une cyberattaque touchant certains de ses systèmes et services techniques. Les équipes de cybersécurité ont détecté l'incident immédiatement et ont isolé les systèmes affectés pour limiter l'impact. Bien que des analyses forensiques so...
Just days after a damning WIRED report exposed that Meta had quietly embedded facial recognition technology (FRT) code into millions of phones, the tech giant has quietly acquiesced in demands to reverse course.
Last week, researchers identified code in Meta AI, a companion app for its line of smart...
Several U.S. states are pushing to ban young people from social media entirely. This marks the latest wave of censorship bills masquerading as “children’s online safety” measures, with states like Massachusetts, Idaho, Minnesota, North Carolina, South Carolina, Illinois, and EFF’s home state of Cali...
Attackers are increasingly targeting collaboration platforms like Microsoft Teams. Learn the risks and key steps to strengthen your organization's security.
The post When “Hi, This Is IT” Comes Through Microsoft Teams appeared first on Unit 42.
Several security issues were fixed in Net::CIDR::Lite.
Several security issues were fixed in Netty.
When an unsolicited job offer sounds too good to be true …
New variants of the NFCShare Android malware are being distributed as fake updates for legitimate banking apps hosted on GitHub. [...]
USN-8349-1 introduced regressions in rsync.
SoFi Hong Kong is warning that it suffered a data breach after hackers gained access to a database at a third-party vendor containing customer information. [...]
Cisco warns customers of an actively exploited high-severity vulnerability in Catalyst SD-WAN Manager, an enterprise network management system that has been targeted by hackers multiple times in the past. Located in the command-line interface, the flaw allows authenticated att...
At WWDC 26, Apple announced an Apple Intelligence-powered feature that can automatically fix weak and compromised passwords. This works in Safari, and it's rolling out with iOS 27. [...]
Read all about the latest AWS security features, compliance updates, and hands-on resources in our new, monthly digest posts. You’ll find expert blog posts, new service capabilities, code samples, and workshops. AWS Security Blog posts This month’s AWS Security Blog posts covered AI security, networ...