Visualização normal

Ontem — 7 de Setembro de 2026Stream principal
  • ✇Cybersecurity News
  • CVE-2026-86218 (CVSS 10): N-central Pre-Auth RCE Exploited in the Wild Do Son
    The N-able N-central vulnerability CVE-2026-86218 is a CVSS 10 pre-auth RCE reported exploited in the wild. Apply 2026.3 HF4 immediately. Related Posts: MikroTrick PoC: RouterOS Admin Rights Exploited In Wild AI Agent Coordination: The Unprecedented OpenAI Breakout Roundcube Security Update Fixes 12 Webmail Flaws The post CVE-2026-86218 (CVSS 10): N-central Pre-Auth RCE Exploited in the Wild appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Linux Kernel 7.1 Reaches End of Life Do Son
    The Linux Kernel 7.1 EOL has officially arrived. Discover the final updates and learn why you must upgrade to the latest stable LTS releases immediately. Related Posts: CERN to Move 2,200 Accelerator Control Machines to Debian 13 Debian 11 Reaches End of Long Term Support Linux Nears USB4 Support for Apple Silicon The post Linux Kernel 7.1 Reaches End of Life appeared first on Daily CyberSecurity.
     

Linux Kernel 7.1 Reaches End of Life

Por:Do Son
7 de Setembro de 2026, 00:33

The Linux Kernel 7.1 EOL has officially arrived. Discover the final updates and learn why you must upgrade to the latest stable LTS releases immediately.

Related Posts:

The post Linux Kernel 7.1 Reaches End of Life appeared first on Daily CyberSecurity.

Antes de ontemStream principal
  • ✇Cybersecurity News
  • StyleSmuggler: Magento Zero-Day RCE Exploited in the Wild Do Son
    StyleSmuggler, a Magento zero-day, gives unauthenticated remote code execution and is exploited in the wild. No patch yet. Mitigate now. Related Posts: CVE-2026-86218 (CVSS 10): N-central Pre-Auth RCE Exploited in the Wild MikroTrick PoC: RouterOS Admin Rights Exploited In Wild AI Agent Coordination: The Unprecedented OpenAI Breakout The post StyleSmuggler: Magento Zero-Day RCE Exploited in the Wild appeared first on Daily CyberSecurity.
     
  • ✇Security | CIO
  • Salesforce offers more Agentforce credits to drive adoption
    Salesforce is updating some of the editions, or pricing tiers, of Agentforce Sales and Agentforce Service, a year after their rebrand from Sales Cloud and Service Cloud. The top three now bundle AI agents, analytics, Slack, security, and support with larger allocations of Flex Credits; two of the tiers are also increasing in price. The Core edition replaces the old Enterprise edition, and its price goes up from $175 per user per month to $195, and now includes 500,000 Flex
     

Salesforce offers more Agentforce credits to drive adoption

4 de Setembro de 2026, 11:21

Salesforce is updating some of the editions, or pricing tiers, of Agentforce Sales and Agentforce Service, a year after their rebrand from Sales Cloud and Service Cloud. The top three now bundle AI agents, analytics, Slack, security, and support with larger allocations of Flex Credits; two of the tiers are also increasing in price.

The Core edition replaces the old Enterprise edition, and its price goes up from $175 per user per month to $195, and now includes 500,000 Flex Credits. Advanced edition costs $395 per user per month and includes 1 million credits, replacing the $350 per month Unlimited edition. The Max edition replaces the old Agentforce 1 tier and now includes 2.75 million credits instead of 1 million for the same $550 per month fee, Salesforce said in a blog post.

The lowest tiers, Starter and Pro Suite, remain unchanged in features and price, although there is a hint that Salesforce is renaming the latter to Professional edition.

What is new in Agentforce Sales?

The new editions bring several capabilities to the base subscription of Agentforce Sales that were previously sold separately: The Core edition now includes Momentum, Slack Business+, and Tableau Next, while the Advanced edition adds Sales Programs, the Premier Success Plan, and additional security and data-protection capabilities. Max edition adds Agentforce for Sales, Agentforce Coworker, Salesforce Spiff, Sales Planning, Sales Programs, Salesforce Maps, Slack Enterprise+, and additional Tableau Next capabilities.

Under the previous Enterprise and Unlimited editions, Sales Programs was an add-on, Tableau Next was available through a separate Tableau+ purchase, and Agentforce itself had to be purchased separately.

What is new in Agentforce Service?

The new editions of Agentforce Service also incorporate capabilities that previously required additional purchases.

The Core edition includes case management, self-service Help Center, Slack Business+, and Slackbot; Advanced adds Agentforce Help Agent, Premier Success Plan, full sandbox, Backup & Recover, and Data Detect, and Max adds Service Rep Assistant, Workforce Engagement, Quality Management, IT Service, unmetered Agentforce Coworker access, and a library of service agent templates.

Under the previous Enterprise and Unlimited editions, Agentforce was available as a separate purchase, while capabilities such as additional security, data protection, and workforce-management tools were also packaged separately or reserved for higher-tier offerings.

Procurement simplicity could come at the cost of visibility

Salesforce said the new editions deliver from 50% to 70% greater value than those they replace, but realizing that value may not be straightforward, analysts warned, particularly as enterprises move from experimenting with Agentforce to deploying agents at scale.

While bundling more AI, analytics, security, Slack, and support capabilities into the subscriptions could simplify procurement of Salesforce products for enterprises, the economics could become more complicated once customers start consuming their included Flex Credits, said Manoj Chandra Jha, principal analyst at Nord-IQ Research.

That is because bundling more capabilities into a single subscription reduces the line-item visibility CIOs previously relied on, and most enterprise finance teams are still learning how to forecast for credit consumption, he said.

Without that visibility CIOs will find it hard to assess how Salesforce’s offerings compare with competing products, particularly when they are trying to determine the cost of specific capabilities or decide which components of a broader bundle are delivering value, he said.

Salesforce may be exaggerating the real value of the new editions, said Pareekh Jain, principal analyst at Pareekh Consulting.

“While CIOs may get more capabilities in a single package, they will still need to assess how much of that functionality employees actually use. A package may offer 60% more theoretical value, but that benefit can disappear if much of the bundled functionality or Flex Credits goes unused,” he said.

Overuse is also a problem, said Jha: As agent usage grows, enterprises could consume their included Flex Credits more quickly and eventually need to purchase additional credits, making actual usage a more important measure of value that CIOs should follow rather than the headline savings attached to the new editions, Jha noted.

New editions targeted at accelerating adoption

While Salesforce talks of value for money, analysts see its real goal with the new editions as accelerating Agentforce adoption.

Investment analysts raised concerns about questioned Agentforce’s customer traction in July, citing enterprise data readiness and the product’s maturity as factors holding back broader adoption. Salesforce, however, has pushed back, pointing instead to growth in deployments and usage.

Nevertheless, said Jha, “With Agentforce running at only a fraction of Salesforce’s 150,000-plus customer base, and analysts pinning the drag on messy enterprise data, folding security and analytics into every tier looks like Salesforce neutralizing the objection before a prospect can raise it.”

Salesforce said last month that its customers had increased their average number of agents from five in February 2025 to 13 by April 2026, while the average number of agent actions per account grew at a 31% compound monthly growth rate over the same period.

Jha sees the updated editions as aimed primarily at Salesforce’s existing customer base, giving companies already using its products more incentives and capacity to expand their use of Agentforce, rather than as a draw for new customers.

Salesforce said the new editions for Agentforce Sales and Agentforce Service are already available, and will soon be joined by new editions for Agentforce Industry.

Existing Agentforce 1 edition customers can upgrade to the new Max edition at no additional cost, the company said, adding that in the future, Max editions across its Sales and Service offerings will also include an allocation for Headless 360.

  • ✇Cybersecurity News
  • Debian 11 Reaches End of Long Term Support Do Son
    Debian 11 LTS ends on August 31, 2026. Discover upgrade options and extended paid support details for enterprises still running the older Linux version. Related Posts: Linux Nears USB4 Support for Apple Silicon Debian AI Policy: Responsible Generative AI Use Wins Vote California Exempts Linux from Age Verification The post Debian 11 Reaches End of Long Term Support appeared first on Daily CyberSecurity.
     

Debian 11 Reaches End of Long Term Support

Por:Do Son
1 de Setembro de 2026, 22:18

Debian 11 LTS ends on August 31, 2026. Discover upgrade options and extended paid support details for enterprises still running the older Linux version.

Related Posts:

The post Debian 11 Reaches End of Long Term Support appeared first on Daily CyberSecurity.

  • ✇Cybersecurity News
  • FreeRDP 3.31.0 Fixes Pre-Auth RCE Chain in Server Do Son
    FreeRDP 3.31.0 patches 5 server-role flaws, including a pre-auth remote code execution chain affecting GNOME Remote Desktop and KDE krdp. Related Posts: Critical Google Chrome Vulnerabilities Patched in New Update CVE-2026-80047: Hugging Face Transformers Library Vulnerability CVE-2026-68162: Linux Kernel Root Escalation PoC Public The post FreeRDP 3.31.0 Fixes Pre-Auth RCE Chain in Server appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • CVE-2026-62911 Exchange Server Pre-Auth RCE PoC Released Do Son
    Security researchers released technical details and PoC code for CVE-2026-62911, a critical Exchange Server pre-auth RCE flaw. Related Posts: CVE-2026-81934: Redis RCE PoC Exploit Now Public CVE-2026-78319: SAUTER Controller RCE Flaw Disclosed CVE-2026-82329 Exploited: JFrog Artifactory Admin Takeover The post CVE-2026-62911 Exchange Server Pre-Auth RCE PoC Released appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Debian AI Policy: Responsible Generative AI Use Wins Vote Do Son
    Debian's AI policy vote picked "Responsible Use of Generative AI": AI is neither banned nor endorsed, with full accountability left to contributors. Related Posts: Linux Nears USB4 Support for Apple Silicon California Exempts Linux from Age Verification Ubuntu 26.04.1 LTS Released with Crucial Bug Fixes The post Debian AI Policy: Responsible Generative AI Use Wins Vote appeared first on Daily CyberSecurity.
     

Debian AI Policy: Responsible Generative AI Use Wins Vote

Por:Do Son
31 de Agosto de 2026, 10:02

Debian's AI policy vote picked "Responsible Use of Generative AI": AI is neither banned nor endorsed, with full accountability left to contributors.

Related Posts:

The post Debian AI Policy: Responsible Generative AI Use Wins Vote appeared first on Daily CyberSecurity.

  • ✇Cybersecurity News
  • OpenClaw Unleashes Massive Update Do Son
    The open-source OpenClaw AI agent project just released its largest update ever. Discover how this accidental 2.0 upgrade transforms the user experience. Related Posts: Gemini Notebook Adopts Dynamic Quota System AI Crawlers Burden git.kernel.org With Millions of Requests Judge Blocks Pentagon Anthropic Blacklist The post OpenClaw Unleashes Massive Update appeared first on Daily CyberSecurity.
     

OpenClaw Unleashes Massive Update

Por:Do Son
31 de Agosto de 2026, 07:32

The open-source OpenClaw AI agent project just released its largest update ever. Discover how this accidental 2.0 upgrade transforms the user experience.

Related Posts:

The post OpenClaw Unleashes Massive Update appeared first on Daily CyberSecurity.

  • ✇Cybersecurity News
  • California Exempts Linux from Age Verification Do Son
    California passes AB-1856, exempting open-source operating systems like Linux from the burdensome age verification mandates of the Digital Age Assurance Act. Related Posts: Debian AI Policy: Responsible Generative AI Use Wins Vote Ubuntu 26.04.1 LTS Released with Crucial Bug Fixes Framework Laptop 12: Upgraded with Intel Core Series 3 The post California Exempts Linux from Age Verification appeared first on Daily CyberSecurity.
     

California Exempts Linux from Age Verification

Por:Do Son
31 de Agosto de 2026, 04:55

California passes AB-1856, exempting open-source operating systems like Linux from the burdensome age verification mandates of the Digital Age Assurance Act.

Related Posts:

The post California Exempts Linux from Age Verification appeared first on Daily CyberSecurity.

  • ✇Cybersecurity News
  • CVE-2026-71362 Exploited: Adobe Commerce Account Takeover, Details and PoC are Public Do Son
    Attackers exploit CVE-2026-71362, an unauthenticated Adobe Commerce account takeover flaw (CVSS 9.1). Details and PoC are public. Patch now. Related Posts: Critical MongoDB Security Vulnerabilities Require Immediate Patching CVE-2026-73125: Ebyte NA111-M Flaws Let Attackers Fully Compromise the Device D-Link DIR-X1860Z Flaw Lets Attackers Change the Admin Password Without Login The post CVE-2026-71362 Exploited: Adobe Commerce Account Takeover, Details and PoC are Public appeared first on Dai
     

Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more

28 de Agosto de 2026, 07:23
More than 1,000 organisations, 500,000 stolen credentials, and one self-propagating worm named after a Dune sandworm - two men now face charges over TeamPCP's global hacking spree. Read more in my article on the Hot for Security blog.
  • ✇Cybersecurity News
  • Dell Cloud Disaster Recovery CVE-2026-70419 (CVSS 9.1) Allows Command Execution Do Son
    Dell patched 5 Cloud Disaster Recovery flaws. The top bug, CVE-2026-70419 (CVSS 9.1), allows command execution. Update to CDR 20.3 now. Related Posts: CVE-2026-19042: TeamViewer Command Injection Enables Remote Code Execution CVE-2026-72137 (CVSS 9.8): Linux Kernel Flaw Enables Root Privilege Escalation, PoC Public CISA Adds Six Exploited Vulnerabilities Including Citrix NetScaler Flaw The post Dell Cloud Disaster Recovery CVE-2026-70419 (CVSS 9.1) Allows Command Execution appeared first on D
     
  • ✇Security | CIO
  • Salesforce, Anthropic partner to deliver Claudeforce
    Salesforce and Anthropic today announced they have expanded their strategic partnership to deliver Claudeforce, enabling customers of both companies to leverage Salesforce data, workflows, business logic, actions, and governance within Claude. “What we’re seeing is that when people stop using Salesforce through the traditional human interface and start using it through an agentic interface, it dramatically increases the value of Salesforce,” Patrick Stokes, president of
     

Salesforce, Anthropic partner to deliver Claudeforce

26 de Agosto de 2026, 17:23

Salesforce and Anthropic today announced they have expanded their strategic partnership to deliver Claudeforce, enabling customers of both companies to leverage Salesforce data, workflows, business logic, actions, and governance within Claude.

“What we’re seeing is that when people stop using Salesforce through the traditional human interface and start using it through an agentic interface, it dramatically increases the value of Salesforce,” Patrick Stokes, president of Applications & Marketing at Salesforce, told CIO.com on Wednesday. “They’re using Salesforce more than they ever have before.”

Stokes explained that momentum around the Claudeforce partnership began building after Salesforce’s TDX 2026 developer conference earlier this year. At the conference, Salesforce announced Headless 360, a platform that packaged Salesforce’s AI and developer tools into a headless, API-driven layer designed to help enterprise teams build agent-first workflows. It allowed AI clients like Claude or ChatGPT to read, write, and reason over Salesforce data without the traditional browser-based UI.

“It was a very popular decision among developers,” Stokes said. “Salesforce was actively endorsing people using Salesforce through an agentic interface rather than through the UI that we have had in place for 27 years.”

Developers immediately started hooking MCP servers up to their own agents. And Salesforce watched them struggle to scale their efforts.

“How do you do it for 100 or 1,000 users?” Stokes asked. “How do you deal with managed authentication to make sure it’s using the permissions of the user inside Salesforce? All the things that are necessary in order to scale this out weren’t really in place.”

Anthropic, the company behind Claude, was seeing the same thing. Its sales teams were using Salesforce through Claude and struggling to scale it. The two companies worked together to create a solution and decided to productize the result as Claudeforce.

Prebuilt sales skills and token consumption

The first fruit of the Claudeforce partnership is Salesforce in Claude, a plugin with 37 prebuilt sales skills. Stokes said these skills will enable sellers and agents to reason over live revenue context, automate pipeline updates, and take governed action within Claude. Claude-powered agents can access Salesforce data, workflows, and rules directly.

“We’ve been using it internally and so has Anthropic and some pilot customers for some time,” Stokes said. “It’s really highlighting what we think is a new way to work where the user is way faster than they’ve ever been before.”

According to Stokes, Salesforce users are leveraging Claudeforce to vibe code their own CRM interfaces, creating purpose-built command centers for how they want to run their teams. They’ve also been using it for forecasting.

“You just ask the question, and it’s going to go out and analyze the data and use its intelligence to try to tell you what to do,” he said.

He did note that customers will have to evaluate their own appetite for token consumption when it comes to leveraging Claudeforce.

“We’re starting to see early signs of what the token use looks like,” he said. “The token consumption is certainly not zero, but it is nowhere close to approaching the amount of consumption that you would find in a development use case.”

As part of the Claudeforce partnership, Salesforce is embedding Claude directly into Slack. Claude will be the default model for Slack, powering Slackbot, augmenting team decision-making via Claude Tag, and accelerating multiplayer coding through Slack Code.

The partners plan to introduce more integrations across Claude, Salesforce, and Slack over time. The Salesforce in Claude elements of Claudeforce are available to some pilot customers now and the partners said they expect to launch an open beta in September. They will launch additional prebuilt skills starting in the third quarter.

  • ✇Cybersecurity News
  • PoC Released for Redis RCE Use-After-Free Flaw Do Son
    A public PoC exploits a Redis RCE use-after-free flaw tied to CVE-2026-23479, running system commands as the Redis server. Update to 8.8.2. Related Posts: GitLab Updates Fix Arbitrary Command Execution Vulnerability FreeBSD Patches Eight Kernel Vulnerabilities UniFi CVE-2026-77537 (CVSS 10.0): Command Injection Flaws Hit 22 Ubiquiti Products The post PoC Released for Redis RCE Use-After-Free Flaw appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Unpatched Kaltura Server Flaws Enable Code Execution Do Son
    Two unpatched Kaltura server flaws (CVE-2026-19912, CVE-2026-19913) allow attackers to execute code and read files. Learn how to mitigate these risks. Related Posts: GitLab Updates Fix Arbitrary Command Execution Vulnerability FreeBSD Patches Eight Kernel Vulnerabilities UniFi CVE-2026-77537 (CVSS 10.0): Command Injection Flaws Hit 22 Ubiquiti Products The post Unpatched Kaltura Server Flaws Enable Code Execution appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • CVE-2026-77136: TYPO3 Powermail RCE Flaw Exploited in the Wild Do Son
    A critical TYPO3 Powermail RCE flaw (CVE-2026-77136) is actively exploited in the wild. Update immediately to prevent server compromise and data leaks. Related Posts: Public PoC for CVE-2026-52923 Allows Attackers to Escalate to Root Privilege Weidmueller Router Flaw CVE-2026-63586 With CVSS 9.8 Allows Attackers To Execute Arbitrary Commands With Root Privileges Fake AI PoCs Flood Exploit Repositories in 2026 The post CVE-2026-77136: TYPO3 Powermail RCE Flaw Exploited in the Wild appeared fir
     
  • ✇Cybersecurity News
  • CVE-2026-19874: Metal Gear Online 3 RCE Flaw Do Son
    Metal Gear Online 3 RCE vulnerability CVE-2026-19874 fixed. Update the game to prevent attackers from executing remote code on your system. Related Posts: Public PoC for CVE-2026-52923 Allows Attackers to Escalate to Root Privilege CVE-2026-77136: TYPO3 Powermail RCE Flaw Exploited in the Wild Weidmueller Router Flaw CVE-2026-63586 With CVSS 9.8 Allows Attackers To Execute Arbitrary Commands With Root Privileges The post CVE-2026-19874: Metal Gear Online 3 RCE Flaw appeared first on Daily Cyb
     
  • ✇Cybersecurity News
  • Australia Warns of Hackers Exploiting TeamCity Flaw, PoC Public Do Son
    TeamCity CVE-2026-63077 enables unauthenticated remote code execution. Exploited in the wild with a public PoC. Patch your servers now. Related Posts: CVE-2026-14669: PoC Code Enables RCE in PostgreSQL TP-Link Fixes Three High-Severity TL-MR6400 Router Flaws CVE-2026-74480 (CVSS 9.8): Linux Kernel Privilege Escalation PoC Public The post Australia Warns of Hackers Exploiting TeamCity Flaw, PoC Public appeared first on Daily CyberSecurity.
     
  • ✇ASEC BLOG
  • July 2026 Threat Trend Report on Ransomware ATCP
    Purpose and Scope The July 2026 Threat Trend Report on Ransomware summarizes major Korean & global ransomware issues based on statistics regarding the quantity of new ransomware samples, the number of compromised systems, and statistics on targeted businesses. Statistics on targeted businesses were compiled based on information published on DLS (Dedicated Leak Sites, also referred […]
     

July 2026 Threat Trend Report on Ransomware

Por:ATCP
23 de Agosto de 2026, 12:00
Purpose and Scope The July 2026 Threat Trend Report on Ransomware summarizes major Korean & global ransomware issues based on statistics regarding the quantity of new ransomware samples, the number of compromised systems, and statistics on targeted businesses. Statistics on targeted businesses were compiled based on information published on DLS (Dedicated Leak Sites, also referred […]
❌
❌