> TODAY'S SUMMARY (132 articles)
Today's cybersecurity landscape highlights several critical issues and emerging threats. A significant privacy battle is brewing in California over updates to wiretapping laws that may limit private lawsuits against internet tracking. At the Pwn2Own Ireland event, hackers successfully exploited 32 zero-day vulnerabilities, showcasing the rapid pace at which security flaws are being targeted. In a concerning data breach, the FBI has removed a contractor linked to the exposure of sensitive employee information due to a missed patch, raising alarms about operational security in federal agencies. Meanwhile, ASOS confirmed a data breach that involved unauthorized push notifications claiming to leak customer data. Additionally, multiple vulnerabilities affecting Atlassian products and a critical flaw in Dell's System Update could allow attackers to gain unauthorized access. Overall, there is an evident rise in exploitation of known vulnerabilities and an increasing trend in data breaches across various sectors.
|
// AI-powered summary generated at 20:00
CrowdStrike, in partnership with Google and the Shadowserver Foundation, has announced the simultaneous disruption of all command-and-control (C2) channels associated with GlassWorm, a persistent software chain campaign targeting software developers through malicious packages and extensions.
"Since...
Most organizations still picture cyber defense as a fortress problem: build stronger walls, add more guards, buy another detection engine. But modern incidents rarely crash through the front gate. They drift in disguised as routine activity, hide inside legitimate processes, and quietly accumulate r...
The FBI has warned that attackers are using a new phishing kit to gain long-term access to Microsoft Outlook, Teams, and OneDrive accounts.
Catalin Dragomir previously pleaded guilty to selling access to an Oregon state government office’s network.
The post Romanian Hacker Sentenced to Prison in US for Selling Access to State Network appeared first on SecurityWeek.
Glassworm infected developers through poisoned tools and packages until a coordinated takedown killed all four of its C2 channels at once. On May 26, 2026, at 14:00 UTC, CrowdStrike Counter Adversary Operations team, working with Google and the Shadowserver Foundation, killed all four command-and-co...
When an employee installs an AI writing assistant, connects a coding copilot to their IDE, or starts summarizing meetings with a new browser tool, they are doing exactly what a productive employee should do: finding faster ways to work.
Across most organizations today, employees are running three t...
AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites Microsoft warned that attackers are adapting SEO poisoning techniques for AI-generated software recommendations, pushing users toward fake utility download sites that deploy ScreenConnect for persistence before launching crypto...
Group-IB uncovered Ghost Stadium phishing and 4300 fake FIFA World Cup domains targeting fans
GLPI, grâce à son plugin nommé Carbon, accompagne les entreprises dans le suivi de l'empreinte carbone de leurs actifs informatiques. Voici une présentation.
Le post GLPI Carbon : mesurez l’empreinte énergétique de vos actifs informatiques a été publié sur IT-Connect.
Apple has published its post-quantum cryptography implementations in corecrypto, together with mathematical proofs and verification tools for independent expert evaluation, allowing external researchers to review the work and reproduce the company’s analysis. Post-quantum cryptography is designed to...
The new funding, led by BDC Capital’s StrongNorth Fund, will accelerate Lastwall’s North American expansion.
The post Lastwall Raises $11.5 Million for Quantum-Resilient Identity Platform appeared first on SecurityWeek.
As AI accelerates phishing, session hijacking, and credential abuse, security teams are racing to close the gap between attacker speed and defensive response.
The post The Credential Crisis: How Stolen Credentials Defeat Modern Security appeared first on SecurityWeek.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. federal agencies four days to secure their servers against a critical vulnerability in the LiteSpeed cPanel user-end plugin, which is actively being exploited in attacks. [...]
Malicious repositories and disguised symlinks can trick AI coding agents into silently installing attacker-controlled MCP servers capable of stealing secrets, compromising CI pipelines, and deploying malicious code.
The post ‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery S...
Security firms took down all four command-and-control (C&C) channels used by the GlassWorm malware.
The post GlassWorm Botnet Disrupted appeared first on SecurityWeek.
Cybersecurity researchers have disclosed a security flaw in Gitea, an open-source, self-hosted platform for version control, that allows unauthenticated remote attackers to pull private container images from Gitea deployments without requiring an account, password, or other credentials.
The vulnera...
EvidenceForge generates high-quality, realistic, and consistent datasets across multiple log formats, enabling teams to effectively train personnel and validate detection models without the need for complex manual simulations.
Cox Media said it could spy on users through their devices and use the information for targeted advertising, except it wasn't true.
MDASH, c'est le nom système IA spécialisé dans la découverte de vulnérabilités mis au point par Microsoft. Il serait plus performant que Claude Mythos.
Le post MDASH : l’IA de Microsoft plus efficace que Claude Mythos pour trouver des failles a été publié sur IT-Connect.
The attack was claimed by a hacktivist group, but evidence showed it used infrastructure linked to Iranian government threat actors.
The post LA Metro Cyberattack Linked to Iranian State-Sponsored Hackers appeared first on SecurityWeek.