[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (105 articles)

|

// AI-powered summary generated at 16:00

> Slackware 15.0 crucially updates to fix root vulnerability in haveged
New haveged packages are available for Slackware 15.0 and -current to fix a security issue.
> Slackware 15.0 mozilla-firefox Critical Security Update for 2026-139-02
New mozilla-firefox packages are available for Slackware 15.0 and -current to fix security issues.
> How businesses can detect and prevent account takeover attacks
Learn what an account takeover is, how it can happen, and how businesses can detect and prevent attacks.
> Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps
Cybersecurity researchers have disclosed details of a new ad fraud and malvertising operation dubbed Trapdoor targeting Android device users. The activity, per HUMAN's Satori Threat Intelligence and Research Team, encompassed 455 malicious Android apps and 183 threat actor-owned command-and-control...
> Microsoft disrupts Fox Tempest malware-signing-as-a-service platform tied to ransomware gangs
The company unsealed a legal case in U.S. District Court on Tuesday detailing the disruption of Fox Tempest — a popular service that has operated since May 2025 and provides cybercriminals with code signing tools.
> CNIL
La Commission Nationale de l'Informatique et des Libertés (CNIL) a publié son rapport d'activité pour l'année 2025, mettant en lumière une augmentation significative des plaintes, un montant total de sanctions inédit et un nombre record de notifications de violations de données.L'année 2025 a été ma...
> AEPD - autorité espagnole
L'autorité espagnole de protection des données (AEPD) a publié une décision de sanction à l'encontre d'un syndicat de copropriétaires, comprenant le prononcé d'une amende de 1 000 €, pour des manquements liés au principe de confidentialité. Cette affaire débute par une plainte signalant la publicati...
> Drupal to Patch Highly Critical Vulnerability at Risk of Quick Exploitation
Drupal says attackers may develop an exploit for the vulnerability within hours or days. The post Drupal to Patch Highly Critical Vulnerability at Risk of Quick Exploitation appeared first on SecurityWeek.
> AEPD - autorité espagnole
L'Agence Espagnole de Protection des Données (AEPD) a publié une décision de sanction à l'encontre d'une personne physique mineure, comprenant le prononcé d'une amende de 1 200 €, pour des manquements liés à la publication sur un réseau social d'une vidéo montrant l'agression d'un autre mineur. Cett...
> Microsoft plans to improve Windows 11 driver quality in 2026
Microsoft plans to raise the quality bar of Windows 11 drivers, as drivers "sit at the heart of every Windows experience" and connect the OS to the "silicon, components, and peripherals." [...]
> Governing infrastructure as code using pattern-based policy as code
Organizations often struggle to enforce security and compliance requirements consistently across their cloud infrastructure. In one environment, a workload might be deployed in an AWS Region that was never approved for that class of data. In another, a security group might allow broader access than...
> Microsoft blames macOS update for undismissible Teams location prompts
Microsoft has confirmed user reports that the Teams team collaboration app is displaying non-dismissible location prompts on some macOS systems. [...]
> Microsoft Disrupts Malware-Signing Service Run by ‘Fox Tempest’ 
 Fox Tempest provides a service that cybercriminals use to distribute ransomware and other malware disguised as legitimate software. The post Microsoft Disrupts Malware-Signing Service Run by ‘Fox Tempest’  appeared first on SecurityWeek.
> Clear your calendar, Drupal user: You have a critically urgent patch to install
The org’s staying mum on the details, but Wednesday’s fixes reach back to unsupported 8.9 branches
> Biometrics, diagnoses, and bank details exposed in major healthcare breach
NYC Health + Hospitals says attackers accessed its systems for months through a third-party vendor compromise, affecting at least 1.8 million people.
> Tools for spotting and disabling AI systems in an enterprise
Key methods for cutting off AI access to an organization’s core IT assets.
> TP-Link, Photoshop, OpenVPN, Norton VPN vulnerabilities
Cisco Talos’ Vulnerability Discovery & Research team recently disclosed eight vulnerabilities in TP-Link, and one each in Adobe Photoshop, OpenVPN, and Gen Digital's Norton VPN.The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s...
> Hackers have compromised dozens of popular open source packages in an ongoing supply chain attack
The attacks are part of a wider campaign known as Mini Shai-Hulud, which has already compromised several open source projects and, in turn, developers and companies that use them.
> Mini Shai-Hulud returns, compromising hundreds of npm packages
Another malware wave is washing through open-source software repos, stealing publishing tokens, installing OS‑level backdoors and persisting in developer tools and CI pipelines. The post Mini Shai-Hulud returns, compromising hundreds of npm packages appeared first on CyberScoop.
> GitHub scales back bug bounties, reminds users security is their responsibility too
Faced with the growing volume of submission to its bug bounty program, GitHub is replacing cash bounties with swag rewards for reports with low security impact — and asking researchers to stop submitting reports that are low quality or about things that aren’t its fault. Th...