[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> Slackware 15.0 Kernel Significant Process Trace Weakness Notice-2026-135-03
New kernel packages are available for Slackware 15.0 and -current to fix a security issue.
> Exchange Server zero-day vulnerability can be triggered by opening a malicious email
A newly discovered zero-day vulnerability in Microsoft Exchange Server has experts declaring an emergency and urging CSOs to think about the need to abandon on-premises email solutions. “Because it’s already being exploited in the wild, this isn’t a ‘patch next week situati...
> Here’s how the FTC plans to enforce the Take It Down Act
The commission will dole out  hefty fines and promises investigations for Take It Down Act violators. Experts say questions remain around the agency’s resources and priorities.   The post Here’s how the FTC plans to enforce the Take It Down Act appeared first on CyberScoop.
> More than $10 million stolen from crypto platform THORChain
THORChain officials said the investigation into the incident is ongoing but explained that one of their six vaults was compromised, leading to a loss of about $10.7 million.
> Funnel Builder WordPress plugin bug exploited to steal credit cards
A critical vulnerability in the Funnel Builder plugin for WordPress is being actively exploited to inject malicious JavaScript snippets into WooCommerce checkout pages. [...]
> A hotel check-in system left a million passports and driver’s licenses open for anyone to see
The tech company that maintains the hotel check-in system set its cloud storage to public, allowing anyone to access customers' data without a password.
> GPDP - autorité italienne
L'autorité italienne de protection des données (GPDP) a publié une décision de sanction à l'encontre de Framos Italia s.r.l. en liquidation, comprenant le prononcé d'une amende de 5 000 €, pour des manquements en lien avec la gestion des comptes de messagerie d'un ancien salarié et le non-respect de...
> GPDP - autorité italienne
L'autorité italienne de protection des données (GPDP) a émis un rappel à l'ordre ferme aux médias concernant le respect de la protection des données dans le cadre d'une affaire criminelle médiatisée.Cette intervention fait suite à la publication, sur une plateforme télévisuelle en ligne, de l'audio...
> Debian Trixie Linux Critical Privilege Escalation Denial Service DSA-6274-1
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. For the stable distribution (trixie), these problems have been fixed in version 6.12.88-1.
> GPDP - autorité italienne
L'autorité italienne de protection des données (GPDP) a publié une décision de sanction à l'encontre de la société Io e te s.r.l.s. (comprenant le prononcé d'une amende de 2 000 €) pour des manquements en lien avec l'utilisation d'un système de vidéosurveillance dans un commerce. Cette affaire début...
> Debian Bookworm Linux Critical Local Escalation DSA-6275-1 CVE-2026-46333
One vulnerability has been discovered in the Linux kernel that may lead to a local privilege escalation. For the oldstable distribution (bookworm), this problem has been fixed in version 6.1.172-1. We recommend that you upgrade your linux packages.
> Microsoft Exchange, Windows 11 hacked on second day of Pwn2Own
​During the second day of Pwn2Own Berlin 2026, competitors collected $385,750 in cash awards after exploiting 15 unique zero-day vulnerabilities in multiple products, including Windows 11, Microsoft Exchange, and Red Hat Enterprise Linux for Workstations. [...]
> The AWS AI Security Framework: Securing AI with the right controls, at the right layers, at the right phases
TL;DR for busy executives The AWS AI Security Framework helps security leaders move fast and stay secure with AI. Security compounds from day 1 as workloads evolve from prototype to production to scale. Assess first. Request a no-cost SHIP engagement to baseline your posture and build a prioritized...
> How to manage subscriptions securely | Kaspersky official blog
How can family subscriptions turn into a cyberthreat? What kind of phishing emails are scammers sending to subscribers? And most importantly, how do you use these services safely? We cover all this and more in this post.
> Popular node-ipc npm package compromised to steal credentials
Hackers have injected credential-stealing malware into newly published versions of node-ipc, a popular inter-process communication package, in a new supply chain attack targeting npm. [...]
> Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access
The Russian state-sponsored hacking group known as Turla has transformed its custom backdoor Kazuar into a modular peer-to-peer (P2P) botnet that's engineered for stealth and persistent access to compromised hosts. Turla, per the U.S. Cybersecurity and Infrastructure Security Agency...
> If you don’t control your data, who does? A European strategist explains
Austrian data strategist Fritz Fahringer explains how European businesses can reclaim data sovereignty with everyday tools.
> Debian DSA-6273-1 Chromium Critical Code Exec Denial of Service
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 148.0.7778.167-1~deb12u1.
> Avada Builder WordPress plugin flaws allow site credential theft
Two vulnerabilities in the Avada Builder plugin for WordPress, with an estimated one million active installations, allow hackers to read arbitrary files and extract sensitive information from the database. [...]
> US orders travelers on Air Force One to throw away gifts, pins, and burner phones after China trip
People who travelled to Beijing for a summit between the United States and China had to throw away items they received during the trip before boarding Air Force One, presumably for security reasons.