Microsoft has addressed a significant vulnerability in its Defender software, identified as RoguePlanet (CVE-2026-50656). This flaw allows local attackers to escalate their privileges by exploiting the Malware Protection Engine, which is integral to Defender's malware scanning and removal functions. The vulnerability has a CVSS score of 7.8, indicating a high severity level. Users of Microsoft Defender should ensure they apply the latest security updates to protect against potential exploitation. This fix is crucial as it mitigates the risk of unauthorized access and control over affected systems, which could lead to further security breaches.
Latest Cybersecurity Threats
Real-time threat intelligence from trusted sources
Mount Royal University has confirmed that it suffered a ransomware attack, which allowed hackers to access its internal network. During the breach, the attackers deleted two drives that contained sensitive information, including data related to employees, students, and the university itself. This incident raises significant concerns about the security of educational institutions, which often store large amounts of personal data. Affected individuals may face risks such as identity theft if their information is misused. The university's response to this breach will likely be closely watched, as it highlights ongoing vulnerabilities in the education sector regarding cybersecurity.
BleepingComputer
In a significant global crackdown on fraud, law enforcement agencies have arrested 5,811 suspects across 97 countries and confiscated $293 million in illegal assets. This operation, which involved collaboration between various international police forces, aimed to dismantle networks involved in scams and financial fraud. The arrests included individuals associated with tech support scams, online shopping fraud, and money laundering. These efforts are crucial in combating the growing trend of online fraud, which affects countless victims worldwide and undermines trust in digital transactions. The scale of this operation underscores the need for continued vigilance and cooperation among nations to tackle cybercrime effectively.
Infosecurity Magazine
More than 70 cybersecurity firms have come together to support the CREST AI Charter, which outlines guidelines for the responsible use of artificial intelligence in security practices. The charter aims to promote ethical standards in AI applications, ensuring that these technologies are used to enhance security rather than compromise it. By establishing a framework for the responsible deployment of AI, the initiative seeks to build trust and accountability among organizations and their clients. This collaboration is particularly significant as the use of AI in cybersecurity continues to grow, raising concerns about potential misuse. The charter encourages companies to adopt best practices, which could lead to improved security outcomes for users and organizations alike.
Microsoft has addressed a significant vulnerability in its Defender antivirus software, dubbed RoguePlanet, which was made public nearly a month ago. This flaw, tracked as CVE-2026-50656, has a CVSS score of 7.8, indicating a high risk of privilege escalation. It affects the Microsoft Malware Protection Engine, specifically the 'mpengine.dll' component responsible for scanning and cleaning malware. If exploited, this vulnerability could allow attackers to gain SYSTEM privileges on affected systems, posing a serious security risk. Users of Microsoft Defender are urged to apply the latest security updates to protect their systems from potential exploitation.
A recent survey has revealed that security leaders in European organizations may be overestimating the safety of their collaboration tools and platforms. The study indicates a significant gap between the perceived security of these tools and the actual risks they pose. This confidence could lead to dangerous complacency, as organizations may not be taking necessary precautions to protect sensitive information shared through these platforms. With remote work becoming more common, the reliance on collaboration tools has increased, making it essential for companies to properly assess their security measures. The findings suggest that organizations need to reevaluate their security protocols to mitigate potential vulnerabilities.
AssuranceAmerica, an American insurance company, recently reported a significant data breach affecting approximately 6.9 million drivers. Attackers gained unauthorized access to the company's systems earlier this year, compromising sensitive personal information. This breach raises concerns for those affected, as their driver records may include critical details such as names, addresses, and potentially more sensitive data. The incident emphasizes the ongoing risks that companies face regarding data security and the importance of robust protective measures. Affected individuals are advised to monitor their accounts for unusual activity and consider taking steps to protect their personal information.
Infosecurity Magazine
Researchers at ESET have discovered a significant increase in the presence of malicious AI agents embedded within open source tool repositories. These agents are designed to exploit vulnerabilities in software and can potentially lead to cyber-attacks, putting users at risk. The findings indicate that attackers are increasingly targeting open source tools, which are widely used in various applications and by many developers. This trend raises alarms for individuals and organizations relying on these tools for their projects, as it exposes them to significant security threats. Users should be vigilant and ensure they are downloading software from trusted sources and keeping their systems updated.
Google has released an update for Chrome, version 150, which addresses 27 vulnerabilities, including 13 use-after-free bugs. Among these, two have been classified as critical-severity flaws, which could potentially allow attackers to execute arbitrary code. This update is crucial for users of the Chrome browser, as it helps protect against these serious security risks. Users are encouraged to install the update promptly to ensure their systems remain secure. Regular updates are essential, as they often close vulnerabilities that could be exploited by cybercriminals.
Researchers from the AI Now Institute have discovered a significant flaw in AI coding agents, specifically Anthropic's Claude Code and OpenAI's Codex. Their proof-of-concept, termed 'Friendly Fire', reveals that these AI systems can inadvertently execute malicious code when tasked with scanning open-source projects for vulnerabilities. This occurs when the AI operates in an autonomous mode that allows it to approve and run code without human oversight. The implications of this are serious, as it could lead to unintentional security breaches on users' machines, potentially exposing sensitive information or allowing further attacks. Developers and organizations using these AI tools need to be aware of this risk and implement safeguards to prevent such incidents.
In 2025, fraudsters significantly expanded their operations, focusing on SMS, voice, and chat channels, which businesses use to communicate with customers. The Communications Fraud Control Association reported that global telecom fraud losses reached approximately $42 billion, an increase of several billion from the previous year. This surge in fraudulent activity coincided with a rise in blocked messages, indicating that companies are ramping up their defenses against these scams. Infobip, a major communications platform, reported handling billions of messages, reflecting the scale of the issue. As attackers become more sophisticated, businesses need to implement stronger blocking mechanisms to protect their communications and customer interactions.
Researchers have identified a new cyber threat group known as Lurking Lizard, which has been running a malicious residential proxy service since at least August 2022. This operation utilizes over 230 fake domains that mimic legitimate software, specifically targeting users looking to download 7-Zip, a popular file compression tool. Instead of the genuine software, unsuspecting users end up installing a malicious version that turns their devices into proxy nodes. This not only compromises the users' systems but also allows the attackers to route internet traffic through these hijacked devices, potentially masking their own activities. The scale of this operation raises concerns about user privacy and the security of the internet at large.
Mexico's cybersecurity plan is facing a significant challenge as it enters a critical phase during the FIFA World Cup. The country is still in the process of expanding its cybersecurity infrastructure and must now demonstrate its effectiveness in protecting against potential cyber threats during this high-profile international event. With increased online activity and heightened attention from cybercriminals, the stakes are high for both national security and the integrity of the tournament. The outcome of this test could influence future investments in Mexico's cybersecurity capabilities and set a precedent for how the nation handles digital threats in major events. As the World Cup approaches, officials are under pressure to ensure that systems remain secure and resilient against attacks.
A lone attacker successfully breached a large AWS cloud environment in just 72 hours by exploiting artificial intelligence workflows, taking advantage of cloud vulnerabilities, and using stolen credentials. This incident targeted a significant Amazon customer, resulting in an extortion attempt. The implications are serious, as it showcases how AI can be manipulated for malicious purposes and emphasizes the need for stronger security measures in cloud environments. Organizations using cloud services should be especially vigilant about credential management and vulnerability assessments to prevent similar attacks. This incident serves as a warning for companies relying on cloud infrastructure to enhance their security protocols.
Security Affairs
Ubiquiti has addressed seven vulnerabilities in its UniFi OS, among which is a critical flaw designated as CVE-2026-50746. This particular vulnerability, with a maximum severity score of 10.0, allows for command injection attacks within the UniFi Connect Application, affecting versions 3.4.16 and earlier. This means that attackers could potentially execute arbitrary commands on the affected systems, leading to possible unauthorized access or control. Users of the UniFi Connect Application are urged to update their software to safeguard against these vulnerabilities. The implications of these flaws are significant, as they could expose sensitive data and disrupt services for organizations relying on Ubiquiti's solutions.