Curated Feed

Security Intelligence Digests

Latest AI and Cyber Security news with Refract Digests—curated insights from trusted sources with BLUF summaries and actionable analysis. (56 articles)

Krebs on Security

LG to Ban Residential Proxies from Smart TV Apps

LG Electronics plans to suspend smart TV apps that convert televisions into residential proxy nodes, following findings that over 42% of webOS store apps allowed unauthorized traffic routing.

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less...

View More
Krebs on Security

Microsoft Patches a Record 570 Security Flaws

Microsoft released a record 570 security patches this month, nearly tripling last month's count, driven largely by AI-assisted vulnerability discovery.

Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant ...

View More
Krebs on Security

Lessons Learned from CISA’s Recent GitHub Leak

CISA released a postmortem after a contractor exposed internal credentials, including AWS keys, on GitHub for six months before external notification.

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys --...

View More
Krebs on Security

Who Runs the Ransomware Group ‘The Gentlemen?’

A new ransomware group called The Gentlemen is rapidly growing by offering hackers an unusually high 90% cut of ransoms. Investigators are now uncovering clues about the real identity behind the group's administration.

A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strateg...

View More
Schneier on Security

NSO Group Hacking WhatsApp Despite Court Order

NSO Group has been caught phishing WhatsApp users in direct violation of a court order, despite previous legal restrictions on their activities.

WhatsApp has caught the NSO Group phishing its users, in violation of a court order.

View More
Dark Reading

Nightmare-Eclipse Drops Yet Another Microsoft Exploit, RoguePlanet

A disgruntled researcher has released a proof-of-concept exploit for a Windows Defender bug that allows attackers to take over systems. This action escalates an ongoing public feud between the researcher and Microsoft.

The disgruntled researcher released yet another PoC for a Windows Defender bug that allows for system takeover, showing no signs of abandoning their ongoing feud with Microsoft.

View More
Krebs on Security

A Record-Breaking Patch Tuesday for June 2026

Microsoft released a record-breaking 200 security patches this month, including critical fixes for vulnerabilities where exploit code is already public.

Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company's monthly Patch Tuesda...

View More
Schneier on Security

GPS As a Key Distribution Platform

Researchers discovered the U.S. military has used public GPS satellites to secretly broadcast encryption keys for nearly two decades. This means everyday GPS devices have unknowingly received hidden government data for years.

This is interesting: The U.S. military has likely been quietly broadcasting codes for its global encryption network using public GPS for nearly 20 years, turning each satellite into a hidden “numbers ...

View More
Dark Reading

Blame AI: Patch Tuesday Hits Record 206 CVEs

Artificial intelligence is accelerating vulnerability discovery, leading to a record 206 CVEs in a single Patch Tuesday cycle.

Voluminous patch updates could soon be the norm, as artificial intelligence accelerates the speed and scale of vulnerability discovery.

View More
Dark Reading

Microsoft Exchange Flaw Lets Attackers Spoof Any Email Address

A critical flaw named Ghost-Sender allows attackers to spoof any email address by exploiting Microsoft Exchange hybrid configurations paired with third-party filters.

"Ghost-Sender" uses Exchange Online or on-premises in hybrid mode with a third-party mail server or spam filter to achieve this level of spoofing.

View More