InfoSecDash — Cybersecurity news in English, summarized with AI, with a Defense Path
Signal of the day
AI-powered cybersecurity radar with a Defense Path, updated every 30 minutes.
Advertisement · 728×90
Vulnerabilities
- Researchers Successfully Escape OpenAI Codex Sandbox to Execute Commands
- Researchers Chain Multiple Flaws to Compromise OpenAI Employee Accounts and Internal Code Repository
- SolarWinds Releases Patches for Critical Access Rights Manager Vulnerability
- Critical Unauthenticated Remote Code Execution in Orkes Conductor Workflow Platform Under Active Exploitation
- CISA Alerts on Three Critical Linux Kernel Vulnerabilities Under Active Exploitation
- Public Exploits Released for Four Critical Linux Kernel Vulnerabilities
Ransomware
- Beyond the Ransom: The Full Financial Impact of Ransomware Attacks
- Ukrainian Conti Ransomware Developer Sentenced to Four Years in U.S. Prison
- New Android Malware Combines Ransomware and Spyware to Encrypt Files and Steal Data
- CISA Warns of Active Exploitation of Critical WatchGuard Firewall Flaw by Ransomware Groups
- Over 5,400 compromised websites distribute ClickFix malware via blockchain
- StreamRat Banking Trojan Distributed via Fake Streaming Ads on Meta Targeting Spanish-Speaking Users
Data breaches
- TanStack Supply Chain Attack Led to Breach of 170 CrowdSec Private GitHub Repositories
- Brevo Supply Chain Attack Injects Malicious Scripts on Customer Websites
- Gyazo Security Breach Exposes 23.62 Million User Records
- Spanish Data Protection Authority Reports First AI-Powered Data Breach
- CenterPoint Energy Confirms Customer Data Stolen in Cyberattack
- Flaw in Japan's Digital Agency VPN exposes 246,000 government employee records
Phishing and fraud
- N0va: New Phishing Kit Targeting US and European Businesses
- Threat Actors Exploit Passkey Phishing to Hijack Microsoft Cloud Accounts and Steal Data
- Cybercriminals Generate 1 Million Personalized Fraud Emails in Just Three Days
- Cybercriminals Exploit Passkey and SSO Trust in Phishing Campaigns Targeting Microsoft 365
- Over 347,000 Trezor Users Targeted With Phishing Emails Following Brevo Platform Compromise
- Trezor Users Targeted in Massive Phishing Campaign Following Brevo Data Breach
Threat intelligence
- npm Malware Campaign Hides Malicious Code in Runtime Behavior to Bypass Security Defenses
- BragJack Attacks Hijack AI Assistants via Malicious Browser Extensions
- North Korean WaterPlum Hackers Compromised 30,000 Devices and Stole Millions in Cryptocurrency
- Google's Gemini AI Gained Unauthorized Access to Corporate Systems During Security Test
- Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for Command and Control
- Abandoned CDN Domain Re-Registered, Leaving Thousands of Sites at Risk
Tools and defense
- Security Leaders' Guide to Autonomous AI-Powered Penetration Testing
- Anthropic Develops Tool for Claude to Analyze Personal Financial Data
- AI Security Spending Surges Despite Unproven Returns
- Microsoft investigates disappearance of Copilot buttons in classic Outlook
- Homebrew 7.0.0 launches native GUI and strengthens security controls
- WordPress deploys automated security screening for plugin updates before release
Regulation and policy
- CISA Abandons Weekly Vulnerability Roundups in Favor of Risk-Based Prioritization
- Windows 11 24H2 Home and Pro Support Ending in October
- OpenAI Discloses Six Incidents of Anomalous Behavior in AI Models
- Microsoft Releases Workaround for Windows Domain Login Authentication Issues
- Windows Server 2022 Reaches End of Mainstream Support Next Month
- Microsoft Releases Emergency Patches Following Major Patch Tuesday Update Issues
Classroom
- Identity Visibility in 2026: The Foundation of Identity Security
- How to Determine if a Newly Disclosed Vulnerability Is Exploitable in Your Environment
- Maintaining Career Momentum During Challenging Times in Tech
- Webinar: Critical decisions in the first hours following a Google Workspace breach detection
- Why Testing Individual Techniques Falls Short: The Critical Need to Evaluate Complete Attack Chains
- Patch Automation: Balancing Speed with Quality Control
Other
- OpenAI Reports ChatGPT Outage Causing Image Generation Failures and File Upload Delays
- OpenAI Rolls Out ChatGPT Astra, Its Most Powerful Model, to Plus Subscribers
- Microsoft Investigating Issue Preventing Teams Desktop Client Launch on Windows
- Microsoft Addresses Exchange Online Outage Causing Email Delays and Server Busy Errors
- OpenAI Confirms Major ChatGPT Outage Before Astra Model Launch
- Anthropic Confirms Claude Outage Affecting Multiple AI Models