[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (126 articles)

|

// AI-powered summary generated at 20:01

> CVE-2026-40418 Microsoft Office Click-To-Run Elevation of Privilege Vulnerability
Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.
> CVE-2026-35436 Microsoft Office Click-To-Run Elevation of Privilege Vulnerability
Insufficient granularity of access control in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.
> Free OnlyFans Lure Used to Spread Cross-Platform CRPx0 Malware
CRPx0 is a complex, stealthy malware campaign that targets macOS and Windows systems, and appears to have Linux capabilities in development. The post Free OnlyFans Lure Used to Spread Cross-Platform CRPx0 Malware appeared first on SecurityWeek.
> CVE-2026-40420 Microsoft Office Click-To-Run Elevation of Privilege Vulnerability
Improper access control in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.
> CVE-2026-41097 Secure Boot Security Feature Bypass Vulnerability
Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
> General Motors to pay $12.75 million over driver data sales
General Motors has agreed to a $12.75 million settlement with California over allegations that it unlawfully sold drivers’ location and behavioral data to brokers, marking the largest penalty in the history of the state’s Consumer Privacy Act. Prosecutors say GM made approximately $20 million nation...
> CVE-2026-40381 Azure Connected Machine Agent Elevation of Privilege Vulnerability
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
> CVE-2026-41103 Microsoft SSO Plugin for Jira & Confluence Elevation of Privilege Vulnerability
Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a network.
> Instructure strikes deal with hackers who breached it twice
The maker of the Canvas school software said it "reached an agreement" with the hackers, but provided no guarantees that the hackers would not release the data or keep their word.
> CVE-2026-41613 Visual Studio Code Elevation of Privilege Vulnerability
Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
> CVE-2026-42823 Azure Logic Apps Elevation of Privilege Vulnerability
Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
> Password security: Why breaches still happen
Even with strong passwords and MFA, breaches still happen. See the hidden gaps, common risks, and how to close them effectively.
> CVE-2026-42832 Microsoft Office Spoofing Vulnerability
Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.
> CVE-2026-42833 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
Execution with unnecessary privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
> Phishing awareness training: How to prepare your team to recognize attacks
Learn how to build phishing awareness training that helps employees recognize attacks, report them quickly, and reduce risk in your organization.
> CVE-2025-54518 AMD: CVE-2025-54518 CPU OP Cache Corruption
This vulnerability was found and addressed by AMD. We are documenting it in the Security Update Guide to encourage customers to install the May 2026 version of Windows as soon as possible. The vulnerability assigned to this CVE is in certain processor models offered by AMD. The mitigation for this...
> CVE-2026-42893 Microsoft Outlook for iOS Tampering Vulnerability
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network.
> Deal Reached With Hackers to Delete Data Stolen From the Canvas Educational Platform
The company that operates online learning system Canvas said it struck a deal with hackers to delete the data they pilfered in a cyberattack that created chaos for students, many of them in the middle of finals. The post Deal Reached With Hackers to Delete Data Stolen From the Canvas Educational Pla...
> CVE-2026-40403 Windows Graphics Component Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute code locally.
> CVE-2026-41086 Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability
Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.