[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> CVE-2026-6477 PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory
Information published.
> CVE-2026-6637 PostgreSQL refint allows stack buffer overflow and SQL injection
Information published.
> OpenAI change ses certificats après le hack TanStack
OpenAI impose une mise à jour macOS après une attaque supply chain visant TanStack et des paquets npm. Un groupe de pirate lance un concours "hacker la supply chain".
> CVE-2026-6638 PostgreSQL REFRESH PUBLICATION allows SQL injection via table name
Information published.
> CVE-2026-6473 PostgreSQL server undersizes allocations, via integer wraparound
Information published.
> THORChain perd 10,7 millions de dollars
THORChain perd 10,7 millions de dollars après la compromission d’un coffre-fort du protocole crypto
> CVE-2026-6478 PostgreSQL discloses MD5-hashed passwords via covert timing channel
Information published.
> CVE-2026-44673 libyang: lyb_read_string() integer overflow → heap buffer overflow
Information published.
> Test Kingston IronKey Locker+ 50 G2 : une clé USB avec du chiffrement matériel
Kingston a dévoilé sa clé USB IronKey Locker+ 50 G2, avec du chiffrement matériel destiné à protéger vos données contre les attaques physiques et logiques. Le post Test Kingston IronKey Locker+ 50 G2 : une clé USB avec du chiffrement matériel a été publié sur IT-Connect.
> Friday Squid Blogging: Bigfin Squid
Article about the bigfin squid. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.
> Chanhassen Dinner Theatres
Chanhassen Dinner Theatres a dû suspendre temporairement certaines représentations en raison d'une attaque détectée sur son réseau informatique, ce qui a contraint le théâtre à déconnecter ses systèmes par mesure de précaution. L'organisation travaille d'arrache-pied avec des experts externes pour r...
> Universitat de València
Le groupe de ransomware NOVA a piraté les systèmes de l'Université de Valence, dérobant 300 Go de données. Bien que les pirates aient affirmé détenir des informations sur le personnel et les étudiants, l'université a précisé que seul le serveur d'un chercheur principal avait été touché, et que seule...
> Colorado governor commutes prison sentence for election denier Tina Peters 
Peters was sentenced to nine years for stealing voting data and has been publicly unrepentant. But Colorado Governor Jared Polis has been hinting at the decision for months.  The post Colorado governor commutes prison sentence for election denier Tina Peters  appeared first on CyberScoop.
> HDFC Asset Management Company
L'action de HDFC Asset Management Company a chuté de 3,8 % le lundi suite à la déclaration d'une cyberattaque sur son infrastructure informatique. L'incident a eu lieu le 16 mai et la société travaille à contenir l'incident. La chute du cours est survenue après que la société ait été informée par un...
> Outlook – CVE-2026-40361 : cette faille zero-click menace les entreprises, patchez !
Le Patch Tuesday de mai 2026 publié par Microsoft corrige une faille de type zero-click affectant Outlook (et Word) : CVE-2026-40361. Voici comment se protéger. Le post Outlook – CVE-2026-40361 : cette faille zero-click menace les entreprises, patchez ! a été publié sur IT-Connect.
> Pwn2Own Berlin 2026, Day Two: $385,750 more, Microsoft Exchange falls, and the running total crosses $900K
Day two of Pwn2Own Berlin 2026 saw $385,750 earned for 15 zero-days, bringing the total to $908,750 and 39 vulnerabilities over two days. During the second day of Pwn2Own Berlin 2026, security researchers earned $385,750 after successfully demonstrating 15 unique zero-day vulnerabilities affecting p...
> Debian DSA-6277-1 OpenJPEG2 Critical Integer Overflow DoS Risk
An integer overflow has been discovered in OpenJPEG, a JPEG 2000 image compression/decompression library, which could result in denial of service or potentially the execution of arbitrary code if malformed images are opened. For the oldstable distribution (bookworm), this problem has been fixed
> Debian Bookworm ffmpeg Critical Arbitrary Code Execution DSA-6276-1
Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed. For the oldstable distribution (bookworm), this problem has been fixed in version 7:5.1.9-...
> Expired domain leads to supply chain attack on node-ipc npm package
A popular npm package called node-ipc has been compromised, with hackers publishing malicious versions that bundle credential stealing malware. The root cause of the compromise was an expired domain name that attackers managed to register in order to hijack a maintainer’s acco...
> Slackware 15.0 dnsmasq Important security update 2026-135-01
New dnsmasq packages are available for Slackware 15.0 and -current to fix security issues.