> TODAY'S SUMMARY (114 articles)
Today's cybersecurity landscape reveals several critical threats and trends. A member of the ShinyHunters hacking group has been detained in Jordan, cooperating with the FBI amid ongoing investigations into a significant data breach involving employee information. Meanwhile, vulnerabilities in Citrix NetScaler and Rejetto HFS have been actively exploited, with warnings from CISA regarding their severity and potential impact. Additionally, Denmark's population registry suffered a breach affecting 8.8 million individuals, raising concerns about data security in governmental databases. In the healthcare sector, IQVIA faced a hefty fine for inadequate data anonymization, underscoring the ongoing scrutiny over data protection practices. Lastly, Google has paused its open-source bug bounty program due to an influx of invalid AI-generated reports, reflecting challenges in managing AI vulnerabilities.
|
// AI-powered summary generated at 20:00
The package bundles two draft laws — a Chips Act 2.0 and a Cloud and AI Development Act (CADA) — alongside an Open Source Strategy and a roadmap for digitalizing the energy system.
Cisco warns of CVE-2026-20245 in SD-WAN Manager, a flaw that can lead to root access via file upload command injection; no patch or workaround yet. Cisco warns of a privilege escalation flaw, tracked as CVE-2026-20245 (CVSS base score of 7.8), in Cisco Catalyst SD-WAN Manager, the platform formerly...
Researchers have prototyped an AI-powered internet worm.
The coolest thing about the prototype is that it carries its own LLM with it, and runs it on computers that have been broken into.
This is the closest to John Brunner’s original 1975 conception of a computer worm that I’ve seen.
Other noteworthy stories that might have slipped under the radar: Ultrahuman data leak, The Gentlemen ransomware analysis, Hola Browser bundles miner.
The post In Other News: Anthropic Maps AI Threats, Unpatched Comodo Flaw, Palantir Chief Eyed for CISA appeared first on SecurityWeek.
Those receiving aid in the famine-threatened, war-torn territory told support will remain
AI Gateway now features real-time spend limits to prevent runaway token bills across multiple AI providers. By integrating with Cloudflare Access, companies can use identity-driven budgets and policies.
US Treasury sanctions Iran's largest crypto exchange, PRC-linked TA4922 expands phishing to Europe and Africa, attackers exploit Palo Alto VPN bypass.
Cybersecurity researchers have discovered a previously unreported threat cluster dubbed OP-512 (where "OP" stands for "opponent") that has been observed targeting Microsoft Internet Information Services (IIS) servers to deploy a bespoke web shell framework.
ReliaQuest has assessed with moderate to...
Ongoing cyber-attacks on automated tank gauges (ATGs) could result in fuel tanks being drained without businesses noticing, the US Cybersecurity & Infrastructure Security Agency has warned. Connected ATGs are widely deployed in gas stations, as well as on military bases, i...
Postfix could be made to crash if it received specially crafted network traffic.
Dashlane has disclosed new details about a brute-force attack that let a threat actor access some customer accounts and copy encrypted vaults. Dashlane said it found no evidence that the attackers compromised its internal systems. The company first acknowledged the incident on May 31 after users rep...
Several security issues were fixed in Robocode.
Several security issues were fixed in Exim.
The ShinyHunters extortion group leaked roughly 234 GB of data allegedly stolen from the dental benefits administrator.
The post Hackers Leak DentaQuest Information Impacting 2.6 Million appeared first on SecurityWeek.
Several security issues were fixed in Tomcat.
Lloyds Banking Group shared its approach for securing agentic AI workflows, with a mix of hands on experimentation and cross functional governance
Eighteen months ago, the AI SOC was a marketing line. Today it's a budget item. The category has crossed over from interesting to inevitable, with billions of dollars now flowing into AI-powered security operations platforms, agentic SOC tools, and AI co-pilots built into every layer of the security...
Over 100 bugs are critical or high-severity, mainly use-after-free and insufficient validation of untrusted input flaws.
The post Chrome 149 Patches 429 Vulnerabilities appeared first on SecurityWeek.
Hackers Spied on a Stock Exchange Executive’s Outlook Mailbox for Five Months Unknown attackers spent at least five months quietly inside the Outlook mailbox of a senior executive at a major global stock exchange, exfiltrating the inbox in small, repeated batches and routing the stolen data through...
Let’s Encrypt plans to pursue a post-quantum-safe Web PKI through Merkle Tree Certificates (MTCs), a new approach that adds post-quantum authentication to the web without sacrificing the speed and reliability that have made TLS universal. The project is targeting late 2026 for a staging environment...