> TODAY'S SUMMARY (61 articles)
Today's cybersecurity landscape reveals several critical threats and trends. A data breach at Denmark's Central Population Register exposed the personal information of 8.8 million individuals, highlighting vulnerabilities in data access protocols. Meanwhile, a new Linux malware strain, ClingSTUN, is transforming vulnerable IoT devices into proxy nodes, leveraging public infrastructure for malicious traffic routing. Apple is tightening full disk access controls in macOS to mitigate AI-related risks, reflecting a growing concern over AI's potential threats. Additionally, credential stuffing attacks have compromised Domino's customer accounts, and a critical flaw in Dell System Update allows attackers to gain root access, prompting immediate patching. As AI accelerates the weaponization of known vulnerabilities, organizations must prioritize robust security measures to counter these evolving risks.
|
// AI-powered summary generated at 12:01
It was discovered that pip incorrectly handled TLS certificate
verification in session connections. If a session was first used with
certificate verification disabled, subsequent requests to the same host
would also skip verification regardless of the session's current settings.
A remote attacker co...
Using the data collected over the past year and using Kibana these two ES|QL query to summarize the data, this shows the list of the most uploaded threat to two DShield sensors (local and cloud) over the past year. I have sorted the activity by months that shows the evolution of files uploaded to th...
Carnival disclosed a data breach affecting nearly 6 million people after hackers used social engineering to access employee accounts. Carnival Corporation is notifying nearly 6 million people after a data breach exposed personal information. According to the notification shared with the Maine Attorn...
On March 24th, 2026, we received a submission for an Unauthenticated Administrator Account Creation vulnerability in WP Maps Pro, a WordPress plugin with more than 15,000 sales. This vulnerability makes it possible for unauthenticated attackers to create new administrator accounts on the affected si...
The FBI is warning of fake websites impersonating FIFA ahead of the 2026 World Cup, to steal personal and financial information, sell fake tickets and hospitality packages, and push other fraud related to the event. [...]
A new hacking campaign is trying to trick Signal users to give up their secret recovery key, which can be used to access online backups containing past messages.
Network administrators face a persistent challenge: maintaining domain blocklists and allowlists that keep pace with the internet. New websites and services emerge daily, and keeping these lists current requires constant manual updates that leave gaps in coverage. This challenge intensifies when man...
It’s part of a series of examinations at the House Homeland Security Committee that now will include a public event.
The post House panel poised to hold hearing centered on AI impact on cyber appeared first on CyberScoop.
Researchers warn GreyVibe’s extensive use of ChatGPT, Gemini, and other AI tools offers a glimpse into how future cybercriminal and state-aligned groups will operate.
The post Russia-Linked ‘GreyVibe’ Attackers Use AI to Supercharge Cyberattacks appeared first on SecurityWeek.
USN-8229-1 fixed a vulnerability in sed. This update provides the
corresponding update for Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
Original advisory details:
Michał Majchrowicz and Marcin Wyczechowski discovered that sed
incorrectly handled symbolic links when performing in-place edits.
A local...
It was discovered that Vim did not properly handle backticks in tag
filenames. An attacker could possibly use this issue to execute
arbitrary commands.
Michele Spagnuolo allegedly placed multiple trades on the prediction marketplace, abusing internal access to Google’s nonpublic data on the most searched people in 2025.
The post Google security engineer accused of turning confidential search trends into $1.2M win on Polymarket appeared first on Cyb...
In this newsletter, Thor breaks down why you should stop relying solely on CVSS and start using EPSS and GCVE to focus your patching efforts on the threats that actually matter.
Pay Tel secured the publicly exposed data after security researchers discovered the leak containing callers' sensitive ID documents and inmate communications.
It was discovered that multipart had an ambiguous regular expression
alternation when handling certain HTTP header values. A remote attacker
could possibly use this issue to cause multipart to use excessive
resources, leading to a denial of service.
Hackers are exploiting an authentication bypass vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS) to deliver an undocumented credential stealer called EKZ. [...]
A critical security vulnerability has been disclosed in Gogs, a popular open-source self-hosted Git service, that allows an authenticated user to execute arbitrary code under certain conditions.
The security flaw, per Rapid7, is rated 9.4 on the CVSS scoring system. It does not have a CVE identifie...
The funding round was led by Balderton Capital, with additional support from Crosspoint Capital and previous investors General Catalyst and Ten Eleven Ventures.
The post Geordie Raises $30 Million for AI Security and Governance Platform appeared first on SecurityWeek.
L'Agence espagnole de protection des données (AEPD) a saisi le Comité européen de la protection des données (CEPD) au sujet d'une étude sur l'accès potentiel de tiers aux conversations des utilisateurs de systèmes d'intelligence artificielle.L'AEPD a transmis une note d'information au CEPD, basée su...
L'autorité française de protection des données (CNIL) a publié une décision de sanction à l'encontre de la société IQVIA OPERATIONS FRANCE, comprenant le prononcé d'une amende de 5 000 000 €, pour des manquements en lien avec la gestion d'entrepôts de données de santé. Cette affaire débute par plusi...