InfoSecDash — Cybersecurity news in English, summarized with AI, with a Defense Path
Signal of the day
AI-powered cybersecurity radar with a Defense Path, updated every 30 minutes.
Advertisement · 728×90
Vulnerabilities
- Critical KVM Flaw Enables L1 Guest Escape to Linux Host Systems
- Cisco Releases Patches for 12 Critical SD-WAN and IOS XE Vulnerabilities
- Researchers Discover Attack Bypassing Spectre v2 Defenses on Intel and AMD Processors
- Weak Random Number Generator in CryptoJS Behind $5.7 Million in Crypto Wallet Drains
- Attackers Exploit SQL Injection in Oracle to Execute Code Compiled Inside Database Engine
- AWS, Google, and Vercel Patch Flaws Allowing Tool Execution in AI Agents Without Model Authorization
Ransomware
- Ransom Cartel Creator Sentenced to 16 Years in Prison for Ransomware-as-a-Service Operation
- Ransom Cartel Ransomware Creator Sentenced to 16 Years in Prison
- 18 Malicious npm Packages Delivering Cross-Platform RAT to Alibaba Tool Users Discovered
- INC Ransomware Group Intensifies Attacks Exploiting SonicWall VPN Vulnerabilities
- River Bank Confirms Attackers Deleted Stolen Data in Ransomware Incident
- Ransomware gang exploits recent SonicWall vulnerabilities for privileged access
Data breaches
- Cybercriminal Pleads Guilty to Massive Snowflake Breaches Impacting 100 Million People
- Canadian man pleads guilty in Snowflake data-theft extortion scheme
- Thousands of n8n API Tokens Exposed in Public GitHub Repositories
- Open VSX Removes 77 Malicious Evil Twin Extensions Impersonating Developer Tools
- 77 Malicious Extensions Found Harvesting Developer Data from Open VSX
- Self-Propagating Malware Infects Over 1,300 npm Packages in Supply Chain Attack
Phishing and fraud
- Kali365 Exploits Microsoft Authentication to Compromise US Enterprises
- Greatness Phishing Platform Escalates Attacks on Microsoft 365 Users
- Greatness Phishing Platform Adds Device Code Technique to Bypass Multi-Factor Authentication
- Fraudulent Adobe and Zoom Updates Distribute ScreenConnect for Unauthorized Remote Access
- Device Code Phishing Attacks Surge 1,500% in 2026
- Device Code Phishing Emerges as the Fastest-Growing Threat of 2026
Threat intelligence
- Multiple Critical Threats This Week: Samsung Remote Execution, iCloud Backdoor Attempts, and 27+ Stories
- Over 4,400 Rockwell PLCs Exposed Online, Including 22 in Cities Targeted by Water Utility Attacks
- Over 250 ClickFix Domains Employ Browser Fingerprinting to Conceal macOS Malware Lures
- OpenAI Shuts Down Cambodian Scammers Abusing ChatGPT
- Illegal Service Selling Unauthorized Access to Anthropic AI Models Uncovered
- Compromised npm Packages Use Blockchain Technique to Conceal Command-and-Control Servers
Tools and defense
- Varonis launches real-time control system to prevent AI agents from exceeding their scope
- Microsoft Distributed $20 Million to 500 Security Researchers Through Bug Bounty Program
- Researchers Develop Tool to Trace AI-Generated Videos Back to Their Source
- Anthropic: AI Breaches Stemmed from Misconfiguration, Not Model Flaws
- Security Vendors Showcase Latest Innovations at Black Hat USA 2026
- Visa Acquires Fraud Intelligence Firm BioCatch for $2.4 Billion
Regulation and policy
- New York Funds $9 Million Cybersecurity Initiative Across 153 Water Systems
- CISA Updates SBOM Guidance with New Fields, but Experts Question Real Risk Management Impact
- CISA alerts to spike in attacks targeting water systems
- Interpol Deploys Global System to Stop Fraudulent Payment Flows
- DROP Platform Enables Californians to Minimize Their Digital Footprint
- European Union Establishes Specialized Task Force to Combat AI Deepfakes, Illicit Content, and Cyber Attacks
Classroom
- The CISO Paradox: Accountability Without Real Authority Drives Burnout
- AI in Security Operations: Where It Actually Delivers Value
- Certificate and Key Inventory Management: Foundation of Security
- Effective Compliance: Why Core Questions Outperform Complex Frameworks
- Claude Mythos: Evaluating Real Security Impact Beyond the Hype
- Two Decades of Cybersecurity: What Has Changed and What Endures
Other
- Horizon3 Secures $250 Million in Funding to Accelerate Expansion
- OpenAI Unveils Astra, Advanced AI Model That Solves Complex Mathematical Problems
- OpenAI Slashes Costs of Its New GPT 5.6 Models
- Anthropic's Claude Service Experiences Global Outage
- ThreatLocker Secures $190 Million in Series F Funding
- ASUS Chromebooks Refurbished Units Available at Reduced Prices