[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (44 articles)

|

// AI-powered summary generated at 12:00

> Legacy Security Tools Are Failing Data Protection, Capital One Software Report Finds
Traditional network security tools are undermining data protection, with Forrester and Capital One Software research warning AI adoption is impossible without rethinking data security
> Police arrest SMS blaster crew that sent malicious messages to thousands across Toronto
Toronto police said this is the "first known instance" of an SMS blaster being used in Canada.
> USN-8254-1: Linux kernel vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network drivers; - NVME drivers; - Netfilter; (CVE-2026-23112, CVE-2026-23231, CVE-2026-23273)
> Massive AI investment scam network spans 15,500 domains
AI investment scammers abused the Keitaro ad-tracking platform to cloak their campaign, exposing it only to likely targets.
> Claude Code OAuth Tokens Can Be Stolen Through Stealthy MCP Hijacking
Mitiga researchers say attackers can silently redirect Claude Code MCP traffic, intercept OAuth tokens, and maintain persistent access to connected SaaS platforms. The post Claude Code OAuth Tokens Can Be Stolen Through Stealthy MCP Hijacking appeared first on SecurityWeek.
> USN-8253-1: Postfix vulnerability
Kamil Frankowicz discovered that Postfix incorrectly handled certain enhanced status codes. A remote attacker could possibly use this issue to cause Postfix to crash, resulting in a denial of service.
> Knowledge Base Digest - April 2026
Articles Are Dimension and WebBlocker Server affected by the Linux kernel vulnerabilities (CVE-2026-23268 and CVE-2026-23269)? ThreatSync remediation response actions do not block wireless client connections to some types of malicious access points Block or disable weak CBC ciphers for Firebox web...
> Cline Kanban Flaw Lets Websites Hijack AI Coding Agents
Oasis Security finds critical Cline kanban WebSocket flaw exposing AI coding agents to hijack
> Cisco patches high-severity flaws enabling SSRF, code execution attacks
Cisco fixed several high‑severity flaws in its enterprise products, including SSRF bugs in Unity Connection that could enable code execution or service disruption. Cisco released patches for multiple high‑severity vulnerabilities affecting its enterprise products. Successful exploitation could allow...
> Chrome 148 Rolls Out With 127 Security Fixes
The fresh browser update resolves critical-severity integer overflow and use-after-free vulnerabilities. The post Chrome 148 Rolls Out With 127 Security Fixes appeared first on SecurityWeek.
> Ubuntu 25.10 libpng Critical DoS Vulnerabilities USN-8251-1 CVE-2026-33416
Several security issues were fixed in libpng.
> Ubuntu 26.04 LTS USN 8250-1 lcms2 Critical Denial of Service
Little CMS could be made to crash if it opened a specially crafted ICC profile.
> The Browser Is Breaking Your DLP: How Data Slips Past Modern Controls
Your security controls aren't failing, they're missing where most of today's work actually happens. Keep Aware shows how browser activity like copy/paste and AI prompts bypass traditional protections. [...]
> Ubuntu 25.10 dpkg Important Denial of Service Risk USN-8249-1
dpkg could be made to stop responding if it opened a specially crafted file.
> Chromium: CVE-2026-8016 Use after free in WebRTC
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026 ) for more information.
> 2 days left: Get 50% off a second pass to TechCrunch Disrupt 2026
Two days left to save up to $410 on your pass, and get a second one at 50% off to TechCrunch Disrupt 2026. Offer ends May 8, 11:59 p.m. PT. Register now.
> OpenAI and Anthropic LLMs Used in Critical Infrastructure Cyber-Attack, Warns Dragos
Commercial AI models were used to help plan and conduct cyber-attack against operational technology of a water and drainage facility, say researchers
> CVE-2026-26164 M365 Copilot Information Disclosure Vulnerability
Improper neutralization of special elements in output used by a downstream component ('injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.
> CVE-2026-26129 M365 Copilot Information Disclosure Vulnerability
Improper neutralization of special elements in M365 Copilot allows an unauthorized attacker to disclose information over a network.
> Chromium: CVE-2026-8021 Script injection in UI
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026 ) for more information.