SecurityWeek
WIEDZA Z SIECI
Newsy
schneier
New Attack Against RSA
ArsTechnica is reporting on a “new” attack against RSA, one that bypasses factoring. First, this attack isn’t new. The original research is from 2007 . What is new is the implementation. Second, it is a forgery attack. It allows an attacker to forge digital signatures. It does not recover the private key from the public key. Third, the attack only works against pure signatures. That is, signatures without any formatting or padding. This is not generally how we use RSA in practice. Fourth, speed is all relative. This is not a polynomial-time algorithm; it’s a subexponential-time algorithm. But …Czytaj całość ↵Źródło — otwiera w nowej karcieSecurityWeek
Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
The extortion group has modified its exploit in new attacks targeting the PeopleSoft vulnerability CVE-2026-35273. The post Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign appeared first on SecurityWeek .Czytaj całość ↵Źródło — otwiera w nowej karcieSecurityWeek
New Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy Protections
A New Mexico jury has found Facebook liable for deceiving users about privacy protections on the platform. The post New Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy Protections appeared first on SecurityWeek .Czytaj całość ↵Źródło — otwiera w nowej karcieSecurityWeek
Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog
The platform combines open source software and a reference system design to keep AI agents within set boundaries. The post Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog appeared first on SecurityWeek .Czytaj całość ↵Źródło — otwiera w nowej karcieSecurityWeek
Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability
The company says the measure was precautionary and that it has no evidence of Kiteworks or customer systems being compromised. The post Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability appeared first on SecurityWeek .Czytaj całość ↵Źródło — otwiera w nowej karciebleeping
Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist
Cryptocurrency exchange Bitget has resumed Bitcoin withdrawals suspended after suspected North Korean hackers breached its systems last week and stole over $350 million. [...]Czytaj całość ↵Źródło — otwiera w nowej karciebleeping
US soldier gets 70 months in prison for extorting 10 tech, telecom firms
A former U.S. Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024. [...]Czytaj całość ↵Źródło — otwiera w nowej karcieSecurityWeek
Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug
Citrix has released patches for the critical NetScaler vulnerabilities tracked as CVE-2026-88771 and CVE-2026-88772. The post Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug appeared first on SecurityWeek .Czytaj całość ↵Źródło — otwiera w nowej karciebleeping
CISA orders feds to patch exploited Citrix flaws by Wednesday
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the weekend to secure their systems against attacks exploiting two critical Citrix NetScaler vulnerabilities. [...]Czytaj całość ↵Źródło — otwiera w nowej karcieSANS ISC
bleeping
OpenAI is preparing “o,” an always-on ChatGPT assistant that could handle email
OpenAI is testing a new always-on assistant called "o", and references to the unannounced feature briefly showed up on the company's website. [...]Czytaj całość ↵Źródło — otwiera w nowej karciebleeping
Citrix confirms two NetScaler RCE zero-days exploited in attacks
Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws. [...]Czytaj całość ↵Źródło — otwiera w nowej karcieSANS ISC
Wireshark 4.6.9 Released, (Sun, Sep 27th)
Wireshark release 4.6.9 fixes 19 vulnerabilities and 16 bugs.Czytaj całość ↵Źródło — otwiera w nowej karciebleeping
Cloudflare fixes Containers cross-tenant flaw exposing customer data
Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers' containers on the same physical host. [...]Czytaj całość ↵Źródło — otwiera w nowej karciebleeping
Anthropic turns Claude into an AI marketplace with 2,000+ plugins and connectors
Anthropic has just announced a new Claude Marketplace, and it brings all AI-related tools into one place, including plugins, connectors, agents, and more. [...]Czytaj całość ↵Źródło — otwiera w nowej karcieSecurityWeek
Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
CISA added CVE-2026-65660 to its KEV catalog, giving federal agencies a patching deadline of September 28. The post Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks appeared first on SecurityWeek .Czytaj całość ↵Źródło — otwiera w nowej karciebleeping
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers. [...]Czytaj całość ↵Źródło — otwiera w nowej karcieSecurityWeek
China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks
The US and China agreed to set up a communication mechanism for artificial intelligence-related incidents. The post China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks appeared first on SecurityWeek .Czytaj całość ↵Źródło — otwiera w nowej karciebleeping