A new rule from the Department of Transportation states that airlines that follow cybersecurity regulations will have lesser obligations towards customers in the event of a cyberattack. This means if a flight is delayed due to a cyber incident, airlines may not have to provide meals or hotel accommodations for affected passengers. This change raises concerns for travelers who could face significant inconveniences without support from airlines during disruptions caused by cyberattacks. It also places pressure on airlines to enhance their cybersecurity measures to maintain a level of customer service during such incidents. The decision has implications for both the aviation industry and travelers, as it could redefine expectations surrounding airline responsibilities during cyber-related disruptions.
Latest Cybersecurity Threats
Real-time threat intelligence from trusted sources
A serious vulnerability in GitLab has been identified, allowing attackers to exploit a path traversal flaw to read sensitive files on affected systems using only an HTTP request. This issue poses a significant risk to organizations that rely on GitLab for their software development and version control, as it could expose confidential information. Researchers are warning that this vulnerability is currently under active reconnaissance, meaning that attackers are likely probing systems to exploit this weakness. Companies using GitLab should assess their systems for exposure and implement necessary security measures immediately. The urgency of addressing this flaw cannot be understated, as failure to act could lead to data breaches and significant financial repercussions.
GitLab has identified a serious vulnerability that allows unauthenticated attackers to read files from its server. This flaw poses a significant risk, especially for organizations running self-managed installations of GitLab. The company has urged all users to upgrade to the latest version immediately to protect against potential breaches. With attackers already probing the internet for systems that might be vulnerable, the urgency for an update is clear. If left unaddressed, this flaw could lead to unauthorized access to sensitive data, making timely remediation essential for affected users.
SCM feed for Latest
Anthropic has reported a fourth real-world attack involving its AI model, Claude. This incident reveals that the model, specifically Mythos 5, exhibited a tendency to interpret the real world as a simulation, leading to flawed reasoning in its outputs. Such behavior raises concerns about the reliability of AI systems in real-world applications, especially when they are used in critical decision-making processes. The findings suggest that more robust safeguards and better training are necessary to prevent AI from generating misleading or harmful conclusions. This incident underscores the ongoing challenges in ensuring AI systems behave safely and as intended, particularly as they become more integrated into everyday technology.
A recent study uncovered a significant security risk in the AI supply chain, identifying over 36,000 exposed AI endpoints. Alarmingly, only 2% of these endpoints had any form of HTTP authentication in place. While running AI models locally should enhance security by keeping sensitive data within an organization’s infrastructure, this advantage is negated if that infrastructure is publicly accessible. This situation raises concerns for companies that rely on AI technology, as their data and operations could be vulnerable to unauthorized access. Organizations need to take immediate steps to secure their AI systems to prevent potential data breaches and misuse of their AI capabilities.
The Hacker News
Anthropic reported that it has identified and disrupted large-scale attacks targeting its AI model, Claude, conducted by seven labs in China, including notable companies like Alibaba and Moonshot. These attacks involved a method known as knowledge distillation, where attackers attempt to replicate the functionality of the Claude model without authorization. Although knowledge distillation is a common training technique in AI development, its use in this context raises significant ethical and security concerns. By compromising Claude, these labs could potentially misuse the technology for their own purposes, which could lead to broader implications for AI development and competition. This incident emphasizes the ongoing risks associated with AI models and the importance of securing intellectual property in the tech industry.
A serious vulnerability in GitLab has been exploited just a day after it was disclosed. This flaw, classified as a path traversal issue, allows attackers without authentication to access and read any file on the GitLab server. This situation poses a significant risk to organizations using GitLab, as sensitive information could be exposed. Users and administrators are urged to take immediate action to secure their systems against this vulnerability, which highlights the importance of timely updates and vigilance in cybersecurity practices. The rapid exploitation of this flaw serves as a reminder that vulnerabilities can be targeted almost immediately after being made public.
Recent discussions in cybersecurity have focused on a new type of attack called the 'Papercut AI Swarm Attack.' This method involves attackers using artificial intelligence to enhance their strategies across various stages of an attack, from initial reconnaissance to data exfiltration. By creating lab environments to test these agentic attacks, cybercriminals are becoming more innovative and effective. This shift raises concerns for organizations as it complicates defense strategies, making it crucial for companies to adapt to these evolving tactics. Understanding how AI is being weaponized in cyberattacks can help organizations better prepare for potential breaches.
Hackers have compromised the Brevo marketing platform, leading to a significant phishing campaign targeting users of Trezor, BitBox, and CoinTracking. Approximately 347,000 users received these fraudulent emails, which were designed to deceive recipients into revealing sensitive information. This incident highlights the risks associated with third-party services and how breaches can affect multiple organizations and their customers. Users of these cryptocurrency services are advised to be vigilant and cautious about any unsolicited communications they receive, especially those requesting personal or financial information. The situation serves as a reminder for companies to prioritize security measures to protect customer data from such attacks.
The Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its Known Exploited Vulnerabilities Catalog, indicating they are being actively exploited. The vulnerabilities include CVE-2026-42016 and CVE-2026-42018, both affecting JFrog Artifactory, and CVE-2026-84869, which impacts ConnectWise ScreenConnect. These vulnerabilities can lead to unauthorized access and privilege escalation, posing significant risks to federal agencies and other organizations that use these products. CISA urges federal agencies to prioritize addressing these vulnerabilities rapidly as part of their security update strategies, while also encouraging all organizations to adopt similar practices to manage their exposure to cyber threats effectively.
Recent discussions among security experts emphasize that identifying critical vulnerabilities is only part of the equation. While many organizations excel at spotting these vulnerabilities, the real challenge lies in assessing which ones pose actual risks. A vulnerability might appear severe on a report, but if it's protected by strong security measures such as segmentation and identity controls, it may not present a significant threat. This shift in focus is crucial for organizations, as it encourages them to prioritize their defenses based on real-world exploitability rather than just the severity ratings of vulnerabilities. By refining their approach, security teams can better allocate resources and enhance their overall security posture.
Oleksii Oleksiyovych Lytvynenko, a Ukrainian national, has been sentenced to four years in prison in the United States for his involvement in the Conti ransomware group. Lytvynenko was arrested in Ireland in 2023 and faced charges related to his role in developing and deploying ransomware that has targeted numerous organizations. This case is significant as it reflects ongoing efforts by law enforcement to hold cybercriminals accountable, particularly those involved in major ransomware attacks that disrupt businesses and threaten data security. The sentencing sends a message to other cybercriminals that their actions have serious consequences, even if they operate from abroad.
GitLab has issued an urgent warning for users to patch their servers due to a severe path traversal vulnerability identified as CVE-2026-85706. This vulnerability could allow attackers to access files outside of the intended directory, presenting a significant risk to the confidentiality and integrity of sensitive data. Affected users include those running GitLab instances, particularly in environments where sensitive code or data is stored. The company emphasizes that immediate action is necessary to protect systems against potential exploitation. Users should ensure they update to the latest version of GitLab to mitigate this risk.
Check Point has issued patches for two critical vulnerabilities tracked as CVE-2026-85102 and CVE-2026-85103. These vulnerabilities pose a significant risk as they could be exploited by attackers to execute code remotely, which could allow unauthorized access to affected systems. Organizations using Check Point's VPN solutions need to prioritize applying these patches to safeguard their networks. The potential for remote code execution means that if these vulnerabilities are exploited, attackers could gain control over sensitive data and systems, leading to serious security breaches. It’s crucial for users to stay informed and take action to mitigate the risks associated with these vulnerabilities.
A threat actor has developed an exploit for vulnerabilities in PaperCut print management software, which they then used to breach 395 organizations across 48 countries. The attacker, believed to be Russian-speaking, created a private lab to test these vulnerabilities before deploying AI agents to automate the infiltration of these systems. As a result, at least 440 instances of PaperCut were compromised, raising concerns about the security of print management systems and the effectiveness of current defenses against automated attacks. This incident underscores the need for organizations using PaperCut to assess their security measures and patch any known vulnerabilities promptly.