[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (151 articles)

|

// AI-powered summary generated at 20:00

> Multiples vulnérabilités dans les produits Mattermost (19 mai 2026)
De multiples vulnérabilités ont été découvertes dans les produits Mattermost. Elles permettent à un attaquant de provoquer un problÚme de sécurité non spécifié par l'éditeur.
> Multiples vulnérabilités dans GLPI (19 mai 2026)
De multiples vulnérabilités ont été découvertes dans GLPI. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données et un contournement de la politique de sécurité.
> Delano Public Schools
Les classes ont été annulées à Delano, Minnesota, mercredi suite à un incident cyber. Le district scolaire a indiqué que l'incident s'était produit lundi soir et que l'internet a été coupé immédiatement aprÚs la compromission du réseau. Le district n'a pas confirmé s'il s'agissait d'une attaque, mai...
> GitHub
Le 20 mai, GitHub a publiĂ© les rĂ©sultats de son enquĂȘte sur une intrusion dans ses rĂ©fĂ©rentiels internes, rĂ©sultant d'une attaque menĂ©e Ă  l'aide d'une extension malveillante de Visual Studio Code (VS Code). Cette attaque a visĂ© les appareils d'un employĂ© la veille, et GitHub a pris des mesures pour...
> Multiples vulnérabilités dans les produits Microsoft (19 mai 2026)
De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoquer un problÚme de sécurité non spécifié par l'éditeur.
> Scottsboro Police Department
La police de Scottsboro a stoppé rapidement une tentative d'attaque de cybersécurité contre ses serveurs avant que des données ne soient accédées ou prises. Aucune perturbation des services publics n'a été signalée. La police n'a trouvé aucune preuve que des informations identifiantes, photos, vidéo...
> Rhomberg Bau Gruppe
Des parties de la groupe Rhomberg-Bau ont Ă©tĂ© victimes d'une cyberattaque oĂč des inconnus ont pĂ©nĂ©trĂ© le rĂ©seau de l'entreprise et ont exfiltrĂ© des donnĂ©es. L'entreprise a coupĂ© complĂštement certaines de ses systĂšmes (finances, calculs de projet) pour prĂ©venir de nouveaux attaques. Les travaux sur l...
> Do fear the Reaper - stealer swipes macOS users' passwords, wallets, then backdoors them
While also spoofing all the trusted domains - Apple, Microsoft, and Google - in the same attack
> Kinsmen Foundation
Des informations de contact et des adresses e-mail ont potentiellement été compromises lors d'un incident de cybersécurité chez Kinsmen Foundation. Bien que l'accÚs non autorisé ait été obtenu à certaines applications, les opérations et services réguliers n'ont pas été affectés. Les autorités polici...
> How Storm-2949 turned a compromised identity into a cloud-wide breach
Storm-2949 turned stolen credentials into a cloud-wide breach, moving from identity compromise to large-scale data theft without using malware. This incident shows how threat actors can exploit trusted systems to operate undetected. The post How Storm-2949 turned a compromised identity into a cloud-...
> INTERPOL ‘Operation Ramz’ seizes 53 malware, phishing servers
More than 200 individuals were arrested for cybercrime activities during INTERPOL's Operation Ramz, which focused on the Middle East and North Africa. [...]
> Shai-Hulud copycat worm infects yet another npm package
Plus three other stealers in three other packages, all from the same scumbag
> SHub macOS infostealer variant spoofs Apple security updates
A new variant of the 'SHub' macOS infostealer uses AppleScript to show a fake security update message and installs a backdoor. [...]
> Addi - 34,532,941 breached accounts
In March 2026, the Colombian fintech company Addi identified unauthorised activity on its platform and advised customers that "it is possible that your personal information may have been compromised". The "pay or leak" extortion group ShinyHunters subsequently claimed responsibility and published a...
> More than 200 arrested in cyber raids aimed at Middle East scam networks
Investigators found hundreds of compromised devices that were used as part of the cybercriminal operation and notified device owners as part of the raids.
> CISA Admin Leaked AWS GovCloud Keys on Github
Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public arch...
> AI might cut false positives, but it won’t stop the slop 
Anthropic and OpenAI promise their latest tools will find more vulnerabilities. Cybersecurity employees say they’re already flooded with AI-generated reports. The post AI might cut false positives, but it won’t stop the slop  appeared first on CyberScoop.
> Microsoft May security patch fails for some due to boot partition size glitch
“Something didn’t go as planned. Undoing changes.” That’s all the clue some Windows 11 users will get when Microsoft’s May Security Update fails to install because of insufficient free space on the EFI System Partition (ESP), leaving their systems unprotected by the dozens of...
> TeamPCP Supply Chain Campaign: Activity Through 2026-05-17, (Mon, May 18th)
Since the last update, the TeamPCP supply chain campaign produced its loudest stretch since the March Trivy disclosure: an officially confirmed Checkmarx Jenkins plugin compromise and a new self-spreading Mini Shai-Hulud worm across npm and PyPI.
> What to Do When a Third-Party Data Breach Puts Your Website at Risk
Data breach notification letters have become a familiar routine. They usually start with “We value your privacy” and offer a year of free credit monitoring. But the most important part is often hidden in the middle: A list of what actually got out. A leaked email address is not a leaked admin passwo...