> TODAY'S SUMMARY (87 articles)
Today's cybersecurity landscape highlights several critical threats and trends. A major data breach in Denmark has compromised the personal information of approximately 8.8 million individuals, raising concerns over third-party access to sensitive government databases. In the U.S., a ransomware attack on the University of Illinois Chicago's medical school has resulted in the theft of information from its servers. Additionally, Citrix is facing serious challenges as attackers exploit a newly discovered zero-day vulnerability in its NetScaler products, prompting CISA to issue warnings about potential system outages. On the software front, Debian's latest kernel security update reveals over a thousand vulnerabilities, urging users to patch their systems promptly. Meanwhile, Google has suspended its open-source bug bounty program due to an influx of AI-generated vulnerability reports, reflecting ongoing challenges in managing AI's impact on cybersecurity.
|
// AI-powered summary generated at 16:00
It was discovered that nginx incorrectly handled certain cookie headers in
the HTTP/2 implementation. A remote attacker could possibly use this issue
to cause nginx to consume excessive resources, resulting in a denial of
service.
Business data security can affect how you find customers, win deals, and scale without stopping to untangle early mistakes. Learn how.
Business data security shapes trust, compliance, and how fast you can scale. Here's how to get it right early.
A Qilin ransomware affiliate is believed to be exploiting CVE-2026-50751, an authentication bypass vulnerability in Check Point VPN Remote Access and Mobile Access, the company announced on Monday. About CVE-2026-50751 Check Point Remote Access VPN enables and secures connections between corporate n...
A widely used JavaScript implementation of Google’s Protocol Buffers format is placing too much trust in untrusted data, exposing affected applications to remote code execution and other attacks.
Researchers at Cyera have disclosed six vulnerabilities affecting “protobuf.js...
It was discovered that libjxl did not properly handle certain crafted PBM
images. An attacker could possibly use this issue to cause libjxl to crash,
resulting in a denial of service, or execute arbitrary code.
The flaw allows attackers to execute arbitrary code remotely and has been exploited in the wild for two months.
The post Everest Forms Vulnerability Exploited to Hack WordPress Sites appeared first on SecurityWeek.
Zuckercorp says surveillance-for-hire vendor was still running phishing operations after federal court told it to knock it off
Mythos is real. I know a big chunk of the industry thinks it's a marketing stunt, and I get why. I get it. But I've seen the findings, and they're bad. These aren't "whoops, this line right here is wrong, and that's RCE." They're novel combinations of a few dozen issues out of thousands of things ev...
Ridge Security has announced the release of RidgeBot 7.0, an update to its automated security validation platform that introduces automated Windows Active Directory penetration testing capabilities. The new version enables organizations to conduct end-to-end domain compromise simulations, helping se...
Hackers accessed personal information stored on certain Lansing Community College systems in February 2025.
The post 174,000 Impacted by Lansing Community College Data Breach appeared first on SecurityWeek.
ConnectSecure has announced the launch of Patch 360, a patch management solution built for managed service providers (MSPs) to reduce deployment risk while accelerating vulnerability remediation. Patch management has long followed a “deploy-and-hope” model, with teams addressing critical issues only...
The University of Oxford disclosed a new data breach last week after being informed by its third-party provider, Group GTI, that its CareerConnect career services platform had been compromised. [...]
VS Code retarde les mises à jour d’extensions de 2 heures pour freiner les attaques sur la chaîne d’approvisionnement. Voici comment ça fonctionne.
Le post VS Code : un délai de 2 heures sur les mises à jour pour vous protéger des attaques a été publié sur IT-Connect.
In April, Anthropic initated Project Glasswing. The idea was to let companies use their new model to find and fix vulnerabilities in their own software. It was a fantastic PR move, and so many press outlets have uncritically parroted Anthropic’s claims that it’s now common wisdom that Mythos is bett...
Cybercriminals are hiding malware in cracked and repacked games, infecting more than 400,000 devices worldwide.
UNC3753 phones staff posing as IT, hijacks screen sessions, steals sensitive legal files, and now sends operatives physically into offices to plug in USB drives. Google Mandiant and the Google Threat Intelligence Group published a detailed report documenting an active extortion campaign carried out...
Focusing on hacking law firms in the US, the ransomware group relies on fast flux to hide its C&C infrastructure.
The post Silent Ransom Group Uses DNS Fast Flux in Attacks appeared first on SecurityWeek.
At Infosecurity Europe 2026, OWASP’s Ariel Fogel warned that prompt injection remains an “unresolved problem” within generative AI architecture
A China-nexus cyber espionage group has been observed deploying a BSD variant of a known backdoor called BRICKSTORM, as well as two other malware families codenamed PLENET (aka GRIMBOLT) and AGENTPSD to target Linux systems.
The activity has been attributed by Volexity to a threat cluster it tracks...