> TODAY'S SUMMARY (22 articles)
Today's cybersecurity news highlights several critical vulnerabilities and emerging threats. Dell has addressed multiple serious flaws in its PowerEdge servers, particularly a critical vulnerability (CVE-2026-86360) that allows for root access, urging customers to apply patches immediately. Similarly, a major flaw in Atlassian's Data Center products permits unauthenticated attackers to access sensitive files, requiring immediate user action. Additionally, Denmark reported a significant data breach exposing personal information of 8.8 million individuals. The ClingSTUN Linux backdoor is also a concern, exploiting IoT devices through public STUN servers. Lastly, new ClickFix attacks are leveraging browser cache to execute malicious payloads, indicating a shift in attack vectors. Organizations are advised to bolster their security measures in light of these threats.
|
// AI-powered summary generated at 08:01
GREYVIBE, a Russia-linked group active since 2025, targets Ukraine with AI-assisted malware and five attack chains. Researchers say it’s part spy op, part crime gang. Security firm WithSecure has been tracking a previously unknown Russian-linked APT group called GREYVIBE since at least August 2025....
Threat actors are abusing ChatGPT's content-sharing feature to display fake OpenAI outage pages that direct users to download malware disguised as the ChatGPT desktop application. [...]
Zachary Sweeney allegedly traveled to New York, Indiana, Missouri and Georgia to meet and harm numerous victims in person. The FBI began investigating him in 2023.
The post Tennessee man linked to 764 accused of series of crimes against children dating back to 2022 appeared first on CyberScoop.
California Attorney General Rob Bonta filed a lawsuit against 23andMe, now Chrome Holding Co., over the company's failure to protect sensitive customer genetic and personal information. [...]
Cybersecurity researchers have disclosed details of a vulnerability in OpenAI ChatGPT that leverages the artificial intelligence (AI) assistant's implicit trust in Markdown links and images to trigger prompt injections and open the door to phishing attacks.
The technique has been codenamed ChatGPhi...
La Commission nationale de l'informatique et des libertés (CNIL) a rendu public l'ordre du jour de sa séance plénière du 12 mai 2026.
Partie I (avec débats): :
* Présentation de la stratégie nationale de cybersécurité : audition du directeur général de l’ANSSI ;
* Communication relative à l...
L'autorité autrichienne de protection des données a reçu plusieurs centaines de notifications de violation de données de la part de photographes et studios photo autrichiens, suite à une cyberattaque visant la société allemande Portraitbox GmbH.Ces photographes et studios photo utilisent les logicie...
A public spat between Microsoft and an independent security researcher reopens a long-running debate over who is responsible for securing software.
L'Agence espagnole de protection des données (AEPD) a publié une décision de sanction à l'encontre de CAIXABANK, S.A., comprenant le prononcé d'une amende de 500 000 €, pour des manquements en lien avec la protection des données dès la conception et par défaut. Cette affaire débute par deux plaintes...
La Commission européenne a publié un projet de lignes directrices visant à clarifier la classification des systèmes d'intelligence artificielle (IA) à haut risque en vertu de la loi sur l'IA.Ces orientations sont destinées à aider les fournisseurs, les déployeurs et les autorités de surveillance du...
OTP bots exploit one-time passwords for account takeover attacks. Learn how to protect your business and customers.
L'autorité espagnole de protection des données (AEPD) a publié plus de 1 500 rapports juridiques afin d'améliorer la sécurité juridique et de faciliter leur réutilisation.Cette publication, datée du 28 mai 2026, met à disposition des professionnels plus de 1 500 rapports élaborés en réponse à des co...
In March 2026, the Wordfence Bug Bounty Program received 1718 vulnerability submissions from our growing community of security researchers working to improve the overall security posture of the WordPress ecosystem. These submissions are reviewed, triaged, and processed by the Wordfence Threat Intell...
Noteworthy stories that might have slipped under the radar: Trump Mobile exposes customer data, phishers target the 2026 FIFA World Cup, CISA responds to recent supply chain attacks.
The post In Other News: Trump Mobile Data Breach, FIFA World Cup Phishing, CISA Responds to Supply Chain Attacks app...
California AG claims genetics biz downplayed 2023 mega-leak while paying ransom to attacker
As AI agents become more numerous and more communicative, keeping track of where to find them is becoming increasingly important. Numerous proprietary agent registries are on the market, but the Linux Foundation suggests we simply extend the distributed, open Domain Name Syste...
Learn how to connect with clients securely over video conferencing without risking your data or reputation.
A report from the Commerce Inspector General details how mismanagement allowed a backlog of 27,000 unprocessed security flaws to grow unchecked, while the agency duplicated work with a similar CISA program.
The post Federal audit reveals NIST’s NVD is plagued by poor planning and duplication appeare...
Microsoft is named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection.
The post Microsoft is named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection appeared first on Microsoft Security Blog.
Corée du Sud et Thaïlande ciblent les fraudes télécoms, entre initiés, SMS blasters et usurpations bancaires.