[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (105 articles)

|

// AI-powered summary generated at 16:00

> Discord rolls out end-to-end encryption on voice, video calls
Discord announced that all voice and video calls through the communication platform are now protected by default with end-to-end encryption (E2EE). [...]
> Ubuntu 20.04 18.04 Linux Kernel Key Privilege Escalation Update USN-8280-1
Several security issues were fixed in the Linux kernel.
> Ubuntu 18.04 Linux Kernel Important Escalation Threat USN-8281-1
Several security issues were fixed in the Linux kernel.
> FBI: Americans lost over $388 million to scams using crypto ATMs in 2025
The FBI says Americans have lost over $388 million last year to scams using cryptocurrency kiosks, also known as crypto ATMs or Bitcoin ATMs. [...]
> Ubuntu 25.10 Kernel Critical Copy Failure Leads to Privilege Escalation
Several security issues were fixed in the Linux kernel.
> Ubuntu 24.04 LTS Kernel Update Raises Serious Privilege Escalation Risks
Several security issues were fixed in the Linux kernel.
> Microsoft Self-Service Password Reset abused in Azure data theft attacks
A threat actor targeting Microsoft 365 and Azure production environments is stealing data in attacks that abuse legitimate applications and administration features. [...]
> Ubuntu 22.04 LTS Security Advisory USN-8279-1 Linux Kernel Critical Update
Several security issues were fixed in the Linux kernel.
> Drupal is rolling out an emergency security update on May 20. You cannot miss it
Drupal Is Pushing an Emergency Security Update Tomorrow. If You Run a Drupal Site, This Is Not One to Miss. Something significant is coming out of the Drupal project tomorrow, and the way the announcement is worded should be enough to get any site administrator’s attention. The Drupal Security Team...
> Ubuntu 20.04 LTS Highlight.js Critical Denial of Service USN-8276-1
Highlight.js could be made to crash if it received specially crafted input.
> AntV data visualization tool the latest to be hit by ongoing npm supply chain attacks
The world’s largest open-source registry, node package manager (npm), has been hit by another fast-moving malware attack, this time targeting the widely-used AntV enterprise data visualization tool. Unlike last week’s high-profile npm attack on TanStack, which exploited a c...
> Huawei zero-day attack behind last year’s crash of Luxembourg's entire telecoms network
There is no evidence that the incident has recurred, but the flaw remains unexplained and has not been publicly acknowledged by the company.
> USN-8276-1: Highlight.js vulnerability
It was discovered that Highlight.js used plain JavaScript objects for internal language name lookups, making them susceptible to prototype pollution attacks. An attacker could use this to cause a denial of service or unexpected application behaviour.
> Ubuntu 16.04 Smarty Important Cross-Site Scripting Risk USN-8272-1
Smarty could be made to run malicious JavaScript in the user's browser if it received specially crafted input.
> Microsoft dismantled malware-signing network Fox Tempest
Microsoft disrupted Fox Tempest, a malware-signing-as-a-service (MSaaS) that allowed attackers to sign malware with fake trusted certificates. Microsoft said it disrupted a cybercrime operation run by a threat actor named Fox Tempest, which helped threat actors sign malware with short-lived certific...
> America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames
I wonder what's in 'external-secret-repo-creds.yaml' and 'AWS-Workspace-Firefox-Passwords.csv'?
> UK regulator to require tech firms to tackle deepfakes, non-consensual intimate images
The regulator’s announcement said the change is being made due to the “urgent need to better protect women and girls online.”
> Slackware 15.0 mozilla-thunderbird Important Security Issues Fix
New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.
> Slackware 15.0 crucially updates to fix root vulnerability in haveged
New haveged packages are available for Slackware 15.0 and -current to fix a security issue.
> How businesses can detect and prevent account takeover attacks
Learn what an account takeover is, how it can happen, and how businesses can detect and prevent attacks.