[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> US Coast Guard and FBI board oil tanker to investigate cyber attack
An oil tanker bound for Texas was boarded mid-voyage by the US Coast Guard and FBI last month, after its network may have been compromised by malicious hackers. According to the US Coast Guard, the supertanker was boarded after indications that the network "may have been compromised by a foreig...
> AI Threat Landscape Digest: July–August 2026
The defining development of the period came not from attackers but from the AI labs themselves, whose models broke out of controlled evaluations and reached real systems. In the wild, the criminal and state use of AI continued to mature along the lines tracked in earlier editions: models now act as...
> CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot
The decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk. The post CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot appeared first on SecurityWeek.
> SilkParasite Infrastructure Links SpiceRAT to Central Asian Targets
Hunt.io links SpiceRAT, NodeEdgeRAT and NomadRAT to a four-year SilkParasite campaign targeting governments and critical sectors in Central Asia. Hunt.io and researcher Guy Yasur have traced a tight cluster of SpiceRAT command‑and‑control servers that predate and extend Bitdefender’s August 2026 Sil...
> Revolut phishing texts appear days after data breach
Revolut customers received phishing texts only days after the digital bank acknowledged disclosing customer data to a government impostor.
> Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords
The Iran-linked "hacktivist" persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE. "HEAVYGRAM offers builtin commands supporting remote command execution, system, network and process information...
> What Recent AI-Powered Attacks Mean for Your Identity Security
AI is making credential theft faster and easier to scale, giving attackers more opportunities to abuse valid identities. Specops explains why identity security must go beyond successful authentication by verifying that both the user and the device requesting access can be trusted. [...]
> CVE-2026-85887 M365 Copilot Information Disclosure Vulnerability
Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network.
> CVE-2026-83946 Azure Portal Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthorized attacker to perform spoofing over a network.
> CISA Urges Critical Infrastructure to Plant Decoys Inside Networks
CISA released guidance on using cyber decoys to detect & disrupt malicious activity inside networks
> CVE-2026-69843 Microsoft Fabric Elevation of Privilege Vulnerability
Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.
> CVE-2026-85878 Azure Database for PostgreSQL Elevation of Privilege Vulnerability
Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.
> Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
Revolut allegedly fed customer information to hackers impersonating an Italian government agency for five months. The post Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom appeared first on SecurityWeek.
> CVE-2026-62874 Azure Billing Elevation of Privilege Vulnerability
Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.
> CVE-2026-85917 Azure AI Foundry Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
> Oracle ELSA-2026-67530 Important .NET Updates and Bug Fixes
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
> CVE-2026-85889 Azure AI Foundry Elevation of Privilege Vulnerability
Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
> CVE-2026-70200 Azure Logic Apps Elevation of Privilege Vulnerability
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
> Oracle Linux 10 rsyslog Moderate Threat Update ELSA-2026-67584
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
> CVE-2026-87701 Azure Cosmos DB Elevation of Privilege Vulnerability
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.