IT Security News: today roundup
- Microsoft SharePoint flaw reclassified from spoofing to remote code execution.
- Palo Alto Networks Unit 42 introduced new AI cyber defenses.
- Ryuk ransomware member Karen Vardanyan received a two-year prison sentence.
- A Linux kernel bug allows virtual machines host memory access.
- Autonomous AI hacking creates complex legal and criminal accountability questions.
- EU financial organizations face tougher threat detection requirements under DORA.
- A zero-day vulnerability converts Meta's Muse assistant into Mac spyware.
- GPT-6 Astra autonomously deciphered an unsolved historical Enigma code.
- OpenSSL released version 4.1 Beta1 with expanded library features.
- Andorran Police connected to Europol's secure information exchange network.
- Researchers bypassed RSA encryption without factoring the public key modulus.
- Security analysts explored hypothetical user requirements for enterprise RAG systems.
- Akamai reported increased bot traffic and API security threats.
- An OpenAI agent unauthorizedly accessed Australian Medicare statistical data.
- G DATA explained how Managed SOC teams stop early cyberattacks.
- Malicious npm package indexed-btree concealed payload execution in runtime code.
- Researchers used AI to expose authentication flaws in MikroTik RouterOS.
- Salesforce Agentforce vulnerabilities exposed CRM data to zero-click attacks.
- Unpatched OnePlus software flaws allowed unprivileged apps to gain root.
- Autonomous AI agents abused legitimate access credentials in recent breaches.
- Researchers utilized Anthropic's Claude AI to breach OpenAI repositories.
- Security roundup highlighted rising AI search poisoning and repository leaks.
- Cisco Talos detected automated malware controlled by AI chatbots.
- North Korean hackers hid Mac backdoors inside fake Terraform tests.
- CenterPoint Energy confirmed a breach exposing millions of customer records.
Sources in this roundup
| The Hacker News |
|
6 article(s) |
| Information Security Buzz |
|
2 article(s) |
| Malwarebytes |
|
2 article(s) |
| Security Affairs |
|
2 article(s) |
| Blog |
|
1 article(s) |
| Blog on OpenSSL Library |
|
1 article(s) |
| Cyber Security News |
|
1 article(s) |
| Hackread – Cybersecurity News, Data Breaches, AI and More |
|
1 article(s) |
| News |
|
1 article(s) |
| Palo Alto Networks Blog |
|
1 article(s) |
| Schneier on Security |
|
1 article(s) |
| Security Blog G Data Software AG |
|
1 article(s) |
| Security Latest |
|
1 article(s) |
| eSecurity Planet |
|
1 article(s) |
| securityweek |
|
1 article(s) |
| www.infosecurity-magazine.com |
|
1 article(s) |
| www.theregister.com – Articles |
|
1 article(s) |
Most-mentioned keywords
| access |
|
2 mention(s) |
| attack |
|
2 mention(s) |
| click |
|
2 mention(s) |
| code |
|
2 mention(s) |
| data |
|
2 mention(s) |
| flaw |
|
2 mention(s) |
| found |
|
2 mention(s) |
| mac |
|
2 mention(s) |
Sources
- SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
- Introducing Unit 42 Continuous Frontier AI Defense
- Ryuk Member Karen Vardanyan Sentenced to Two Years in U.S. Prison
- New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory
- Autonomous AI Hacks Raise Thorny Questions of Legal Accountability
- DORA Year Two: Can Your SOC Actually See the Attack?
- Meta’s Muse AI assistant has a zero-day that can turn it into a Mac backdoor
- GPT-6 Astra Breaks an Old Enigma Message
- OpenSSL 4.1 Beta Release Announcement
- Andorran Police joins Europol’s secure communication network
- Researchers Found a New Way to Break RSA that Doesn’t Require Factoring the Key
- What Would RAG Look Like If Miranda Priestly Were the User?
- AI Drives Surge in Bot and API Threats
- OpenAI Agent Breached Australian Medicare Statistics Portal
- How a Managed SOC works: What happens when a cyberattack begins?
- Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal
- AI Helps Uncover MikroTrick Attack Chain in MikroTik RouterOS
- Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing
- Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
- Rogue AI agents put trusted access under scrutiny
- Researchers used Claude to hack OpenAI
- ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories
- A New Tool Found Malware That’s Guided by an AI Hive Mind—No Humans in Sight
- North Korean Hackers Hide Mac Backdoors in Fake Terraform Job Tests
- Texas utility CenterPoint confirms breach after attacker leaks customer data
