[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (1 articles)

|

// AI-powered summary generated at 04:00

> CVE-2025-14179 SQL injection in pdo_firebird via NUL bytes in quoted strings
Information published.
> CVE-2026-7262 NULL pointer dereference in SOAP apache:Map decoder with missing <value>
Information published.
> Claude Mythos et la faille FreeBSD : l’IA a-t-elle vraiment fait une découverte inédite ?
La vulnérabilité CVE-2026-4747 de FreeBSD, vieille de décennies, suggère que l’IA peut aussi recycler des failles existantes notamment via le pattern-matching. Le post Claude Mythos et la faille FreeBSD : l’IA a-t-elle vraiment fait une découverte inédite ? a été publié sur IT-Connect.
> CVE-2026-6735 XSS within PHP-FPM status endpoint
Information published.
> CVE-2026-6722 Use-After-Free in SOAP using Apache map
Information published.
> Crimenetwork : la police met fin à cette renaissance pirate
Crimenetwork démantelé : arrestation à Majorque, cryptos, données saisies et enquête cyber allemande.
> CVE-2026-7258 Out-of-bounds read in urldecode() on NetBSD
Information published.
> CVE-2026-42258 net-imap: Command Injection via unvalidated Symbol inputs
Information published.
> Fuites de données pour Meetic et LDLC
Un hacker annonce le piratage des bases de données de Meetic France et de LDLC. Bis repetita ?
> CVE-2026-42257 net-imap: Command Injection via "raw" arguments to multiple commands
Information published.
> CVE-2026-7261 SoapServer session-persisted object use-after-free via SOAP header fault
Information published.
> Resurrected ‘Crimenetwork’ Marketplace Taken Down, Administrator Arrested
The second iteration of the German-speaking online crime marketplace had over 22,000 users and more than 100 sellers. The post Resurrected ‘Crimenetwork’ Marketplace Taken Down, Administrator Arrested appeared first on SecurityWeek.
> CVE-2026-45186
Information published.
> CVE-2026-42246 net-imap vulnerable to STARTTLS stripping via invalid response timing
Information published.
> Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads
A malicious Hugging Face repository managed to take a spot in the platform's trending list by impersonating OpenAI's Privacy Filter open-weight model to deliver a Rust-based information stealer to Windows users. The project, named Open-OSS/privacy-filter, masqueraded as its legitimate counterpart, r...
> CVE-2026-42256 net-imap: Denial of service via high iteration count for `SCRAM-*` authentication
Information published.
> A week in security (May 4 – May 10)
A list of topics we covered in the week of May 4 to May 10 of 2026
> Instagram removed end-to-end encryption for DMs. What should users do?
Instagram removes direct messages (DM) end-to-end encryption May 8, 2026, letting Meta access chats. Users should download backups amid privacy concerns and U.S. law pressure. Starting May 8, 2026, Instagram users who previously enabled end-to-end encryption in direct messages will lose that protect...
> Introducing RAPTR
I'm happy to announce that we are releasing the beta version of RAPTR, a fully open source, API driven collaboration platform built specifically for red and purple team engagements.
> Linux : Dell et Lenovo rejoignent le projet Linux Vendor Firmware Service
L'adhésion de Lenovo et Dell au Linux Vendor Firmware Service est un nouveau signal positif aux utilisateurs de Linux envoyé par deux géants du PC. Le post Linux : Dell et Lenovo rejoignent le projet Linux Vendor Firmware Service a été publié sur IT-Connect.