[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (1 articles)

|

// AI-powered summary generated at 04:00

> Debian Bookworm Corosync Critical DoS Memory Disclosure DSA-6261-1
Two security vulnerabilities were discovered in the Corosync cluster engine, which could result in denial of service or memory disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 3.1.7-1+deb12u2. For the stable distribution (trixie), these problems have b...
> Debian Bookworm Tor Important DoS Issues DSA-6260-1 CVE-2026-44597
Multiple security vulnerabilities were discovered in Tor, a connection- based low-latency anonymous communication system, which could result in denial of service. For the oldstable distribution (bookworm), these problems have been fixed in version 0.4.9.8-0+deb12u1.
> Security Affairs newsletter Round 576 by Pierluigi Paganini – INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Quasar Linux RAT (QLNX): A Fileless Linux Implant...
> CVE-2026-33079 Mistune ReDoS in LINK_TITLE_RE allows denial of service with crafted Markdown titles
Information published.
> CVE-2026-42501 Malicious module proxy can bypass checksum database in cmd/go
Information published.
> Week in review: cPanel vulnerability actively exploited, DigiCert breach, LinkedIn job scams
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Your work apps are quietly handing 19 data points to someone Office work in 2026 relies on mobile apps used alongside personal tools like banking and messaging. Ten widely used workplace apps, including...
> CVE-2026-42499 Quadratic string concatenation in consumePhrase in net/mail
Information published.
> CVE-2026-39836 Panic in Dial and LookupPort when handling NUL byte on Windows in net
Information published.
> Direction générale de la Comptabilité publique et du Trésor
La Direction générale de la Comptabilité publique et du Trésor (DGCPT) a annoncé une perturbation de ses systèmes d'information depuis le dimanche 10 mai 2026, suite à un incident non précisé. Cette panne survient quelques mois après une attaque de cyber-extorsion ayant touché la Direction générale...
> CVE-2026-41889 pgx: SQL Injection via placeholder confusion with dollar quoted string literals
Information published.
> CVE-2026-39826 Escaper bypass leads to XSS in html/template
Information published.
> Notin
Le fournisseur de services informatiques Notin.es a été victime d'une nouvelle attaque par rançongiciel, cette fois menée par le groupe Crypto24 utilisant le ransomware de Lockbit 5.0. Cette cyberattaque a affecté au moins quinze offices notariaux en Espagne, entraînant l'interruption de leurs servi...
> CVE-2026-39825 ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil
Information published.
> CVE-2026-39820 Quadratic string concatentation in consumeComment in net/mail
Information published.
> JDownloader site hacked to replace installers with Python RAT malware
The website for the popular JDownloader download manager was compromised earlier this week to distribute malicious Windows and Linux installers, with the Windows payload found deploying a Python-based remote access trojan. [...]
> CVE-2026-39819 Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Information published.
> CVE-2026-39817 Invoking "go tool pack" does not sanitize output paths in cmd/go
Information published.
> Forensic Windows – Partie 3 : surveiller l’exécution des programmes avec Prefetch
Maîtrisez l’utilisation du Prefetch dans Windows pour identifier les programmes exécutés, en exploitant des outils comme WinPrefetchView et PECmd. Le post Forensic Windows – Partie 3 : surveiller l’exécution des programmes avec Prefetch a été publié sur IT-Connect.
> CVE-2026-39823 Bypass of meta content URL escaping causes XSS in html/template
Information published.
> CVE-2026-33814 Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net
Information published.