[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (48 articles)

|

// AI-powered summary generated at 12:00

> Multiples vulnérabilités dans Progress MOVEit Automation (21 mai 2026)
De multiples vulnérabilités ont été découvertes dans Progress MOVEit Automation. Elles permettent à un attaquant de provoquer un déni de service à distance, un contournement de la politique de sécurité et un problème de sécurité non spécifié par l'éditeur.
> Vulnérabilité dans Drupal (21 mai 2026)
Une vulnérabilité a été découverte dans Drupal. Elle permet à un attaquant de provoquer une injection SQL (SQLi). L'éditeur précise que la vulnérabilité CVE-2026-9082 affecte uniquement les applications qui utilisent PostgreSQL comme système de gestion de base de données. Cependant, il recommande...
> Government of the Northern Mariana Islands (CNMI)
Une cyberattaque a affecté certains comptes de messagerie gouvernementaux aux îles Mariannes du Nord (CNMI), entraînant une perte d'accès pour certains utilisateurs et potentiellement ralentissant le travail gouvernemental. L'Office of Information Technology (OIT) a lancé des protocoles de sécurité...
> Multiples vulnérabilités dans ISC BIND (21 mai 2026)
De multiples vulnérabilités ont été découvertes dans ISC BIND. Elles permettent à un attaquant de provoquer un déni de service à distance et un problème de sécurité non spécifié par l'éditeur.
> [webapps] Cockpit 359 - RCE
Cockpit 359 - RCE
> [webapps] BookStack 25.12.1 - Denial of Service
BookStack 25.12.1 - Denial of Service
> Unpatchable Vulnerabilities of Kubernetes: CVE-2021-25740
A look at how Kubernetes CVE-2021-25740 allows users with EndpointSlice access to redirect traffic via shared ingress and load balancer services.
> [local] Lenovo LegionSpace 1.7.11.2 - 'DAService' Unquoted Service Path
Lenovo LegionSpace 1.7.11.2 - 'DAService' Unquoted Service Path
> [webapps] solaredge - (CSRF-OOB-Injection)
solaredge - (CSRF-OOB-Injection)
> Drupal admins rushing to patch maximum severity SQL injection vulnerability
Administrators of the Drupal open source content management platform are rushing to install an emergency patch issued today to fix a “highly critical” SQL injection vulnerability in the application’s core. While the vulnerability only affects websites that use the PostgreSQ...
> [webapps] FUXA 1.2.9 - RCE
FUXA 1.2.9 - RCE
> OFAC Sanctions Sinaloa Cartel Fentanyl Trafficking and Crypto Laundering Network
Summary The Department of the Treasury’s Office of Foreign Assets Control (OFAC) sanctioned more than a dozen individuals and entities… The post OFAC Sanctions Sinaloa Cartel Fentanyl Trafficking and Crypto Laundering Network appeared first on Chainalysis.
> USN-8289-1: Linux kernel (NVIDIA) vulnerabilities
It was discovered that the Linux kernel algif_aead module did not properly handle in-place cryptographic operations. This flaw is known as Copy Fail. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-31431) Several security issues were discovered in t...
> Smashing Security podcast #468: High-speed train hacks and homicidal lawnmowers
A 23-year-old radio enthusiast spent ÂŁ300 on a piece of kit from the internet, and used it to bring four packed high-speed trains to a screeching halt. His defence in court? Possibly the most creative excuse we've heard all year. Meanwhile, owners of $4,000 robot lawnmowers are discovering that t...
> Xi and Putin pledge closer cooperation on AI, cyberspace and satellite systems
In a lengthy joint statement, Moscow and Beijing pledged closer cooperation on satellite internet technologies and joint work on software development and open-source initiatives — part of a broader effort to reduce reliance on Western technology and build a more independent technological ecosystem c...
> Europe dismantles VPN service used by cybercriminals to hide ransomware attacks
The international operation targeted a service known as First VPN, which had been marketed for years on Russian-speaking cybercrime forums as a secure way for criminals to evade law enforcement.
> Oracle Linux 10 nginx Critical Denial of Service Issues ELSA-2026-18063
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
> Oracle Linux 9 nginx Critical CVE-2026-42945 Arbitrary Code Execution
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
> Slackware 15.0 Rsync Major Security Update for Privilege Escalation DoS
New rsync packages are available for Slackware 15.0 and -current to fix security issues.
> Oracle Linux 8 Nginx Important Patch ELSA-2026-18041 Code Execution Risk
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: