[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> Pressure mounts on Canvas as data leak extortion deadline looms
Attackers affiliated with The Com are threatening to leak data from more than 8,800 school systems if Instructure doesn’t pay a ransom. The post Pressure mounts on Canvas as data leak extortion deadline looms appeared first on CyberScoop.
> Double Canvas breach acknowledged as ShinyHunters sets new pay-or-leak deadline
May 12 
 time is ticking for nearly 9,000 schools
> GM agrees to $12.75M California settlement over sale of drivers’ data
California Attorney General Rob Bonta announced a proposed $12.75 million settlement agreement with General Motors (GM) over allegations that the company violated the California Consumer Privacy Act (CCPA). [...]
> Welcoming the Bangladesh Government to Have I Been Pwned
Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSiteToday, we welcome the 43rd government onboarded to Have I Been Pwned's free gov service, Bangladesh. The BGD e-GOV CIRT department now has full access t...
> Apple Patches Everything, (Mon, May 11th)
Apple today released its typical feature update across it&#;x26;#;39;s operating systems (iOS, iPadOS, macOS, tvOS, watchOS, vision OS). With this update, Apple patched 84 different vulnerabilities. Updates are available for the "26" series of operating systems, as well as for the previous "18"...
> Official CheckMarx Jenkins package compromised with infostealer
Checkmarx warned over the weekend that a rogue version of its Jenkins Application Security Testing (AST) plugin had been published on the Jenkins Marketplace. [...]
> New GhostLock tool abuses Windows API to block file access
A security researcher has released a proof-of-concept tool named GhostLock that demonstrates how a legitimate Windows file API can be abused in attacks to block access to files stored locally or on SMB network shares. [...]
> Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools
Unit 42 analyzes AD CS exploitation through template misconfigurations and shadow credential misuse while offering behavioral detection for defenders. The post Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools appeared first on Unit 42.
> Google Chrome 148 : cette version historique corrige 127 vulnérabilités
Google a publié Chrome 148, la nouvelle version stable de son navigateur web, et elle a une particularité : elle permet de corriger 127 failles de sécurité. Le post Google Chrome 148 : cette version historique corrige 127 vulnérabilités a été publié sur IT-Connect.
> Cookie thieves caught stealing dev secrets via fake Claude Code installers
New IElevator2 COM interface? No problem
> Sophos State of Identity Security 2026
> Canada’s Bill C-22 Is a Repackaged Version of Last Year’s Surveillance Nightmare
Last year, the Canadian government pushed Bill C-2, which would erode Canadian digital rights in the name of “border security.” The bill was so bad it didn’t even make it to committee because of the backlash from the privacy community. Now, the spring’s worst sequel, Bill C-22, aka The Lawful Access...
> EFF to Fourth Circuit: Electronic Device Searches at the Border Require a Warrant
EFF, along with the national ACLU, the ACLU affiliates in Maryland, North Carolina, South Carolina, and Virginia, and the National Association of Criminal Defense Lawyers (NACDL) filed an amicus brief in the U.S. Court of Appeals for the Fourth Circuit urging the court to require a warrant for borde...
> Texas sues Netflix over alleged data practices that create ‘surveillance machinery’ without user consent
In addition to fines, Texas is asking a judge to prevent Netflix from illegally collecting and sharing user data and to mandate that the company no longer use autoplay by default on kids’ profiles.
> Debian DSA-6264-1 Dnsmasq Important Denial of Service CVE-2026-2291
Multiple security vulnerabilities have been discovered in Dnsmasq, a lightweight DNS forwarder and DHCP server, which could result in cache poisoning, bypass of security controls, denial of service or local privilege escalation. For the oldstable distribution (bookworm), these problems have been fix...
> iOS 26.5 is out, bringing encrypted RCS messaging to iPhone and Android users
Apple is bringing long-awaited end-to-end encryption to Rich Communication Services (RCS) messaging between iPhone and Android users in iOS 26.5. The feature is launching in beta for iPhone users running iOS 26.5 on supported carriers and Android users using the latest version of Google Messages. “W...
> ClaudeBleed : la faille dans l’extension Chrome d’Anthropic qui menace vos donnĂ©es
ClaudeBleed, c'est le nom d'une faille critique dĂ©couverte dans l'extension "Claude in Chrome" d'Anthropic. Quels sont les risques ? Voici l'essentiel Ă  savoir. Le post ClaudeBleed : la faille dans l’extension Chrome d’Anthropic qui menace vos donnĂ©es a Ă©tĂ© publiĂ© sur IT-Connect.
> Ubuntu 18.04 LTS Security Advisory USN-8267-1 Kernel Critical Issues
Several security issues were fixed in the Linux kernel.
> TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack
Checkmarx has confirmed that a modified version of the Jenkins AST plugin was published to the Jenkins Marketplace. "If you are using Checkmarx Jenkins AST plugin, you need to ensure that you are using the version 2.0.13-829.vc72453fa_1c16 that was published on December 17, 2025 or previously," the...
> Identity security firm SailPoint discloses GitHub repository breach
SailPoint disclosed a GitHub repository breach on April 20. The company contained the incident and said no customer data was affected. SailPoint is a cybersecurity company that provides identity security and identity governance solutions for enterprises. Its products help organizations manage and co...