IT Security News: today roundup
- A new Citrix NetScaler zero-day flaw causes denial-of-service conditions.
- Attackers are scanning Rejetto HFS servers for critical RCE flaws.
- Fake Zoom installers are deploying the CloudSyncD backdoor on macOS.
- AI agents need action-level security controls to prevent data leaks.
- Attackers are exploiting a Rejetto HFS flaw discovered by AI.
- Complex role-based access control chains complicate database maintenance tasks.
- Italy fined IQVIA $7.8 million over poor health data anonymization.
- FBI confirmed multiple arrests linked to the ShinyHunters hacking group.
- A Microsoft Exchange flaw allows attackers to read user mailboxes.
- Technical University of Denmark suffered a breach exposing 200,000 records.
- Europol awarded innovation honors to Spanish, Danish, and Dutch police.
- Authorities dismantled a human trafficking network exploiting Indian restaurant workers.
- Zero-day vulnerabilities in Zammad enabled an AI agent server breach.
- A judge dismissed journalists' Pegasus spyware lawsuit against NSO Group.
- Chinese threat group TA419 impersonated officials to target AI experts.
- Enterprise AI workflows require specialized data governance for unstructured documents.
- Timor-Leste authorities arrested 16 suspects running Japanese police phone scams.
- MI5 warned UK academics against China-backed intelligence research funding.
- Malicious HEIC image uploads can trigger code execution on WordPress.
- Hackers targeted US AI policy experts using Microsoft credential phishing.
- ZachXBT infiltrated Lazarus Group’s crypto laundering network after Bybit breach.
- A data breach exposed personal records of 8.8 million Danes.
- Bromcom exposed email addresses through an unmaintained legacy sign-on service.
- Hackers exploited 24 IoT vulnerabilities to deploy the ClingSTUN backdoor.
- Debian released a kernel update addressing over 1,300 security flaws.
Sources in this roundup
| CySecurity News – Latest Information Security and Hacking Incidents |
|
5 article(s) |
| Cyber Security News |
|
4 article(s) |
| www.theregister.com – Articles |
|
4 article(s) |
| BleepingComputer |
|
3 article(s) |
| DZone Security Zone |
|
2 article(s) |
| Hackread – Cybersecurity News, Data Breaches, AI and More |
|
2 article(s) |
| News |
|
2 article(s) |
| Security Affairs |
|
1 article(s) |
| The Hacker News |
|
1 article(s) |
| darkreading |
|
1 article(s) |
Most-mentioned keywords
| data |
|
3 mention(s) |
| security |
|
3 mention(s) |
| against |
|
2 mention(s) |
| attackers |
|
2 mention(s) |
| authenticated |
|
2 mention(s) |
| backdoor |
|
2 mention(s) |
| breach |
|
2 mention(s) |
| china |
|
2 mention(s) |
Sources
- Citrix NetScaler security snafus get even worse amid more 0-day reports
- Rejetto HFS servers now actively scanned for critical RCE flaw
- CloudSyncD Backdoor Spread Through Fake Zoom Installer Targeting macOS
- Authenticated Doesn’t Mean Safe: Why AI Agents Need Action-Level Security
- Anthropic Mythos Found A Bug in Rejetto HFS. Attackers Are Now Exploiting It.
- Nobody Designs an RBAC Mess; Everyone Ends Up With One
- IQVIA fined $7.8 million for failing to properly anonymize health data
- FBI confirms 'multiple' arrests related to ShinyHunters hack
- Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes
- DTU Data Breach Exposes Information of 200,000 People
- Spain, Denmark and the Netherlands win Europol 2026 Excellence Awards in Innovation
- International investigation identifies over 70 potential victims exploited in Indian restaurants
- Zammad Zero-Day Chain Lets AI Agent Hijack Sessions, Execute Code and Escalate to Root
- California Court Dismisses El Faro Journalists' Pegasus Spyware Lawsuit Against NSO Group for Second Time
- Chinese Hackers Impersonate US Officials for AI Cyber Espionage
- Building Enterprise File-Heavy AI Workflows: From Secure Uploads to Governed Document Intelligence
- 16 Suspects Detained in Timor-Leste for Japanese Police Impersonation Scam
- China's Ministry Allegedly Funded Research Involving 100+ Academics
- Malicious HEIC Images Can Trigger Remote Code Execution on WordPress Servers
- China-Aligned TA419 Uses Microsoft AitM Phishing Against U.S. AI Policy Experts
- Researcher Infiltrates Lazarus Group’s Crypto Laundering Network After $1.5B Bybit Hack
- Denmark population registry data breach affects 8.8 million people
- Legacy sign-on service comes back to bite school software provider Bromcom
- Hackers Exploit 24 IoT Vulnerabilities to Install ClingSTUN Linux Backdoor
- Debian's latest kernel security update has 1,313 reasons to patch
