[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> CVE-2026-69399 Azure Arc Elevation of Privilege Vulnerability
Information published.
> CVE-2026-77903 Microsoft Dataverse Elevation of Privilege Vulnerability
Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.
> CISA Urges Critical Infrastructure to Plant Decoys Inside Networks
CISA released guidance on using cyber decoys to detect & disrupt malicious activity inside networks
> CVE-2026-69865 Microsoft Container Registry Elevation of Privilege Vulnerability
Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.
> CVE-2026-70009 Azure Arc Elevation of Privilege Vulnerability
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
> Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
Revolut allegedly fed customer information to hackers impersonating an Italian government agency for five months. The post Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom appeared first on SecurityWeek.
> CVE-2026-55946 Microsoft Copilot Information Disclosure Vulnerability
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.
> Oracle ELSA-2026-67530 Important .NET Updates and Bug Fixes
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
> Oracle Linux 10 rsyslog Moderate Threat Update ELSA-2026-67584
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
> Hackers claim breach of Russian election systems days before parliamentary vote
An anonymous hacking group claimed to have broken into computer systems connected to Russia’s election infrastructure just days before the country begins voting for a new parliament.
> Oracle 10 Tesseract Key Security Advisory ELSA-2026-67830 CVE-2026-73066
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
> Oracle Linux 10 Coreutils Moderate Vulnerability Fixes ELSA-2026-67886
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
> Authorities seize popular, long-running DDoS-for-hire service domains
Cybercriminals used NightmareStresser to launch hundreds of thousands of DDoS attacks since at least 2022. Threat actors behind the operation claimed links to Russia. The post Authorities seize popular, long-running DDoS-for-hire service domains appeared first on CyberScoop.
> Oracle Linux 10 libevent Important Security Advisory ELSA-2026-67909
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
> Self-modifying AI agents expose a blind spot in enterprise security
As debate over AI safety intensifies, new research is drawing attention to a more immediate risk for enterprises: AI agents that can alter the models they rely on while carrying out routine tasks. Researchers at AI security firm Irregular asked a coding agent to solve a sof...
> Congress eyes new support for Cyber Command after recent suicide deaths
Congressional sources say they view the deaths of U.S. Cyber Command personnel as an inflection point, especially as the Pentagon’s appetite for cyber capabilities grows following successful contributions to high-profile missions against Iran and Venezuela.
> Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE
Six months after Iranian drone strikes tore through its Middle East infrastructure, Amazon Web Services (AWS) has acknowledged the permanent loss of customer data in Bahrain and the UAE. In two updates posted September 15, AWS said it can no longer recover customer data and resources stored in its M...
> Windows 11 24H2 Home and Pro reach end of support in October
Microsoft reminded customers this week that devices running Windows 11 24H2 Home and Pro editions will stop receiving updates next month. [...]
> DPRK and Iran are Leading a 5.2x Surge YoY in Blockchain-Assisted Cyberattacks
Summary Cyber threat actors are using public blockchains to hide malware instructions on blockchains, making it nearly impossible to seize… The post DPRK and Iran are Leading a 5.2x Surge YoY in Blockchain-Assisted Cyberattacks appeared first on Chainalysis.
> A fake ChatGPT billing email is after your OpenAI password
A fake ChatGPT billing email is steering users to a copy of the OpenAI login page that keeps whatever username and password they type. Josh Varden of Cofense’s Phishing Defense Center traced the email’s payment button through a Google redirect to the attacker’s page. The lure targets ChatGPT users o...