> TODAY'S SUMMARY (22 articles)
Today's cybersecurity news highlights several critical vulnerabilities and emerging threats. Dell has addressed multiple serious flaws in its PowerEdge servers, particularly a critical vulnerability (CVE-2026-86360) that allows for root access, urging customers to apply patches immediately. Similarly, a major flaw in Atlassian's Data Center products permits unauthenticated attackers to access sensitive files, requiring immediate user action. Additionally, Denmark reported a significant data breach exposing personal information of 8.8 million individuals. The ClingSTUN Linux backdoor is also a concern, exploiting IoT devices through public STUN servers. Lastly, new ClickFix attacks are leveraging browser cache to execute malicious payloads, indicating a shift in attack vectors. Organizations are advised to bolster their security measures in light of these threats.
|
// AI-powered summary generated at 08:01
Carnival Cruise Confirms Data Breach Affecting Nearly 6 Million People Carnival Corporation, the world’s largest cruise line operator, began notifying nearly 6 million customers this week that their personal data was stolen in an April breach after attackers gained access to an employee account thro...
Google says the Chrome Device Bound Session Credentials (DBSC) security feature is now generally available and is rolling out to all users to prevent account takeovers. [...]
Cybercriminals are impersonating Signal Support to steal backup recovery keys, giving them access to victims' entire message archives.
You and me go ChatGPhish-ing in the dark
Researchers say 'GREYVIBE' crew used AI tools throughout a campaign targeting Ukrainian military and government
Attackers are delivering a broad-spectrum infostealer to enterprise computers by exploiting a known vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS). “The [malicious] payload was presented as a Fortinet endpoint update and executed through FortiClient-managed VPN scri...
A previously undocumented threat actor dubbed GREYVIBE has been attributed to ongoing and persistent attacks targeting Ukraine and Ukraine-related entities since at least August 2025.
GREYVIBE, per WithSecure, is assessed to be a Russian-speaking group operating broadly in the Russian time zone, wi...
Digital Intelligence Lab (DIL) launches an observatory for reading cyber events as what they actually are: signals of a broader social and geopolitical reality. The timing rarely lies, and the connection between real-world events and cyber activity is no longer a theoretical framework. It is a docum...
Attorney General Rob Bonta filed the lawsuit against Chrome Holding Co., which 23andMe rebranded under after filing for bankruptcy last March.
The post California Sues 23andMe, Alleging It Failed to Protect User Data in 2023 Breach appeared first on SecurityWeek.
A North Carolina man was sentenced to more than 10 years in prison for selling the personal information of over 7 million elderly Americans to Jamaican scammers. [...]
Younger Americans have soured on the second Donald Trump presidency, but they are not protesting it.
Despite an unpopular Iran war and an even more unpopular Trump administration, college campus protests nationwide have gone silent. And at many schools, student activism is virtually nonexistent.
Thi...
Websites have spent years collecting information about visitors through browser fingerprinting, tracking scripts, and other techniques designed to identify devices and monitor behavior. Researchers have demonstrated another method that relies on something most users would never expect a website to o...
A researcher dropped 6 Windows zero-days with no warning. Three are now exploited in the wild. Microsoft is angry. The researcher says Microsoft ignored them first. Over the past month, a researcher going by Chaotic Eclipse, also known as Nightmare-Eclipse, publicly released details of six unpatched...
USN-8338-1 fixed vulnerabilities in Apache HTTP Server. The update
introduced a regression that prevented mod_http2 from loading on Ubuntu
18.04 LTS. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Apache HTTP Server incorrectl...
Shadow AI used to mean employees pasting things they shouldn't into ChatGPT. It now means something bigger: employees building full applications with AI, wiring them into production systems, and publishing them on the open internet. Without Security or IT in the loop.
The artifact moved from a prom...
Telco giant says no sensitive data was taken, though names, addresses, phones, and emails are now out there
The browser update resolves critical-severity security defects that could potentially lead to remote code execution.
The post Chrome 148 Update Patches 151 Vulnerabilities appeared first on SecurityWeek.
A Google security engineer was charged with insider trading after winning $1.2 million using confidential company data to place bets on the cryptocurrency-based Polymarket decentralized prediction market. [...]
A newly documented phishing campaign is targeting professionals with fake LinkedIn business emails and abusing a trusted service operated by Adobe. The attack from the victim’s perspective The attack starts with an email that looks, at first glance, like a routine business inquiry: someone wants to...
From a research-driven pilot, the Cybersecurity Communities of Support (CyCOS) is about to be handed over to CIISec