LIVE · cybersecurity feed
Live wire
security

A tale of two eras

In this week’s newsletter, Amy reminisces on the tech toys of their childhood, inspired by a hilarious lesson about why your digital privacy shouldn't be left on an open channel.

zeroday.news · 51d ago

The cybersecurity landscape is rapidly evolving, with artificial intelligence now capable of discovering and exploiting vulnerabilities at a speed that outpaces human patching efforts. This accelerated threat environment necessitates a fundamental shift in security strategies, moving away from a sole reliance on patching towards a more resilient, multi-layered defense.

Yuri Kramarz of Cisco Talos highlighted this critical change, explaining that advanced AI models can now identify and weaponize zero-day vulnerabilities within minutes. This capability effectively collapses the traditional vulnerability lifecycle, making traditional vulnerability management insufficient on its own. The speed at which threats emerge and are exploited has become a significant multiplier in the risk equation, meaning organizations can no longer solely depend on patching to maintain security.

In this new reality, the focus must shift from absolute prevention to effective absorption, detection, and survival of initial attacks. Organizations need to accept that some exploitation attempts will inevitably succeed. Therefore, the true measure of security lies in an environment's ability to withstand and recover from these breaches.

To adapt, security professionals are advised to reinforce foundational security principles. This includes widespread implementation of multi-factor authentication (MFA), hardening systems according to established benchmarks like CIS, and employing strict network segmentation to limit the potential damage of any successful intrusion.

Since hardened systems only serve to slow down attackers, the deployment of behavioral-based detection tools is crucial. Endpoint detection and response (EDR), network detection and response (NDR), and extended detection and response (XDR) solutions can identify post-exploitation activities that signature-based methods might miss.

Furthermore, regular validation of these security controls through penetration testing and purple team exercises is essential. These activities help ensure that incident response plans are well-rehearsed and effective, transforming them from theoretical documents into practiced procedures.

In other cybersecurity news, U.S. federal agencies have been given a three-day deadline by CISA to address a VPN vulnerability that is actively being exploited. The bug affects remote access tools, firewalls, and VPNs from Check Point Software. Separately, Microsoft has patched two high-severity zero-day vulnerabilities, one of which allows for local privilege escalation, potentially granting attackers full system control.

WhatsApp has reported that NSO Group, a spyware firm, has violated a court order prohibiting hacking activities. The messaging app stated that NSO Group attempted to trick users into clicking malicious links through social engineering tactics. Additionally, a single misplaced exclamation point in the Linux kernel's nf_tables implementation created a use-after-free vulnerability, a memory corruption flaw that attackers can exploit.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.