[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (51 articles)

|

// AI-powered summary generated at 12:00

> CVE-2026-43249 9p/xen: protect xen_9pfs_front_free against concurrent calls
Information published.
> CVE-2026-31767 drm/i915/dsi: Don't do DSC horizontal timing adjustments in command mode
Information published.
> Hundreds of Malicious Packages Force RubyGems to Suspend Registrations
More than 500 packages were pushed during the attack, but the target appears to have been RubyGems itself rather than users. The post Hundreds of Malicious Packages Force RubyGems to Suspend Registrations appeared first on SecurityWeek.
> CVE-2026-41256 jq: Embedded NUL truncates top-level jq programs loaded with -f
Information published.
> CVE-2026-40612 jq: Stack overflow via unbounded recursion in jv_contains
Information published.
> Patch Tuesday – Mai 2026 : pas de zero-day, mais 120 failles corrigées !
Le Patch Tuesday de Mai 2026 révélé par Microsoft permet de corriger 120 failles de sécurité, dont 17 vulnérabilités critiques. Voici l'essentiel à savoir. Le post Patch Tuesday – Mai 2026 : pas de zero-day, mais 120 failles corrigées ! a été publié sur IT-Connect.
> CVE-2026-43895 jq: Embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts
Information published.
> CVE-2026-43896 jq: Stack Overflow in Recursive Object Merge
Information published.
> Versa CSPM brings continuous visibility to cloud risk and compliance exposure
Versa has announced Versa Cloud Security Posture Management (CSPM), extending the VersaONE Universal SASE Platform to provide continuous visibility, prioritization, and remediation of cloud risk across environments. With CSPM, Versa combines secure access protection and cloud posture risk on a singl...
> CVE-2026-43894 jq: Wild stack write via signed-integer overflow in decNumber D2U() macro
Information published.
> Windows 11 KB5089549 : découvrez les nouveautés de la mise à jour de mai 2026
Microsoft a publié les nouvelles mises à jour cumulatives de mai 2026 pour Windows 11 : KB5089549 et KB5087420. Voici l'essentiel à savoir. Le post Windows 11 KB5089549 : découvrez les nouveautés de la mise à jour de mai 2026 a été publié sur IT-Connect.
> Windows 10 KB5087544 : le point sur la mise Ă  jour ESU de mai 2026
KB5087544 : la mise à jour ESU de mai 2026 pour Windows 10 a été publiée par Microsoft. Voici les principales améliorations apportées par cette update. Le post Windows 10 KB5087544 : le point sur la mise à jour ESU de mai 2026 a été publié sur IT-Connect.
> Linux Kernel Vulnerability copy.fail - CVE-2026-31431
CVSSv3 Score: 7.8 CVE-2026-31431In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in alg...
> Android Adds Intrusion Logging for Sophisticated Spyware Forensics
Google on Tuesday unveiled a new opt-in Android feature called Intrusion Logging for storing forensic logs to better analyze sophisticated spyware attacks. Intrusion Logging, available as part of Advanced Protection Mode, enables "persistent and privacy-preserving forensics logging to allow for inve...
> Canada Life - 237,810 breached accounts
In April 2026, Canada Life was the victim of a "pay or leak" extortion campaign by the ShinyHunters group. The group subsequently published the data which contained over 200k unique email addresses along with names, phone numbers, physical addresses and, in some cases, customer support tickets. In t...
> ICS Patch Tuesday: New Security Advisories From Siemens, Schneider, CISA
Many ICS vendors have not released new advisories for the May 2026 Patch Tuesday. The post ICS Patch Tuesday: New Security Advisories From Siemens, Schneider, CISA appeared first on SecurityWeek.
> [GUEST DIARY] Tearing apart website fraud to see how it works., (Wed, May 13th)
&#;x26;#;x5b;This is a Guest Diary by Joshua Nikolson, an ISC Intern and part of the SANS.edu Bachelor&#;x26;#;39;s degree in Applied Cybersecurity (BACS) program.]
> Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub
Where it’s been well and truly forked, seemingly without Microsoft’s code locker noticing
> Critical Fortinet vulnerabilities fixed in FortiSandbox and FortiAuthenticator
Fortinet patched critical flaws in FortiSandbox and FortiAuthenticator that could let attackers remotely execute code on unpatched systems. Fortinet addressed two critical vulnerabilities affecting FortiSandbox and FortiAuthenticator. The flaws could allow attackers to execute arbitrary commands or...
> NetSPI AI-powered Continuous Pentesting identifies high-impact vulnerabilities
NetSPI launched AI-powered Continuous Pentesting offerings, designed to help organizations continuously identify, validate and reduce risk across dynamic external and cloud environments. Organizations are managing an expanding number of potential entry points as new internet-facing resources, includ...