> TODAY'S SUMMARY (3 articles)
Today's cybersecurity news highlights several significant threats. A security researcher has identified a KVM guest-host escape flaw in Firecracker MicroVMs, potentially impacting AWS environments. Dell has released patches for 18 critical vulnerabilities in its Container Storage Modules (CSM), which could allow attackers to gain unauthorized access to storage and Kubernetes systems. Additionally, the hacking group ShinyHunters has exploited a zero-day vulnerability in PeopleSoft, raising alarms about increased risks for enterprises using the Oracle software. Organizations are advised to implement stringent security measures in response to these emerging threats.
|
// AI-powered summary generated at 04:00
FSB claims large-scale snoop op compromised phones of senior officials, but gives no technical evidence to back allegations
Anthropic is expanding Project Glasswing, its security vulnerability program, and access to Mythos to 150 organizations across 15 countries — targeting critical infrastructure in power, water, healthcare, and communications where a cyberattack could affect 100 million people.
Google says the Android vulnerability CVE-2025-48595 has been exploited in limited, targeted attacks.
The post Android Update Patches Exploited Zero-Day, 123 Other Vulnerabilities appeared first on SecurityWeek.
AI-powered attacks and shadow AI adoption are creating new security risks inside the browser. Push Security explains why browser visibility is becoming critical for both threat detection and AI governance. [...]
Several security issues were fixed in the Linux kernel.
Roughly 150 new organizations across critical infrastructure sectors will gain access to Claude Mythos Preview, Anthropic's most capable — and most restricted — AI model.
The post Anthropic expanding access to Project Glasswing appeared first on CyberScoop.
USN-8238-1 fixed a vulnerability in EditorConfig. This update contains the
corresponding fix for Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,
and Ubuntu 22.04 LTS.
Original advisory details:
It was discovered that EditorConfig incorrectly handled specially crafted
configuration files. A l...
Only approximately 50 companies have had access to Mythos until now and they have found thousands of vulnerabilities in their products.
The post Anthropic Expanding Mythos Access to 150 New Organizations appeared first on SecurityWeek.
Several security issues were fixed in MySQL.
Noma has announced the launch of Noma Agent Access Control, which helps security teams discover, govern, and enforce access policies for AI agents and Model Context Protocol (MCP) servers throughout the enterprise. AI agents and MCP servers have proliferated across developer environments faster than...
It was discovered that the Linux kernel did not properly handle shared page
fragments during socket buffer operations, collectively known as Dirty
Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the
RxRPC networking subsystem when processing paged fragments. A local
attacker could...
Tuskira launched Quell, its exposure-led zero-day defense capability. Quell helps enterprises survive the window between a zero-day’s disclosure and a patch by determining which zero-days are reachable in their environment, whether existing controls would stop them, and which compensating control ch...
Bayer’s security awareness training now focuses on psychological approaches rather than technical methods for detecting social engineering
According to the company’s preliminary analysis, a compromised GitHub account was used to push the malicious code out to customers, hitting 32 packages downloaded roughly 117,000 times a week.
Meta has expanded its Teen Accounts 13+ content settings globally on Instagram, Facebook, and Messenger. The safeguards are designed to help young users see age-appropriate content by default. The company also introduced Limited Content on Instagram for parents seeking stricter restrictions. Meta pl...
OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack A malicious supply chain campaign has been stealing OpenAI Codex authentication tokens through a popular npm package called codexui-android, which draws over 29,000 weekly downloads by advertising itself as a legiti...
It was discovered that Apache Tomcat Connectors used incorrect default
permissions for shared memory on Unix-like systems. A local attacker
could possibly use this issue to view or modify mod_jk configuration
data in shared memory, resulting in sensitive information exposure or a
denial of service.
Microsoft a ajouté la fonction Device Soft Delete à Entra ID, ce qui permet de restaurer les appareils supprimés accidentellement dans un délai de 30 jours.
Le post Microsoft Entra ID : la suppression réversible arrive enfin pour les appareils a été publié sur IT-Connect.
Le 29 mai 2026, l'équipe de développement de Wine a publié la version 11.10 de sa célèbre couche de compatibilité pour Linux : voici les principales nouveautés.
Le post Linux : Wine 11.10 ajoute VKD3D 2.0 et d’autres nouveautés ! a été publié sur IT-Connect.
It was discovered that libeconf did not properly check the size of
input when copying data to a buffer. An attacker could possibly use
this issue to cause libeconf to crash, resulting in a denial of
service.