[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (109 articles)

|

// AI-powered summary generated at 20:00

> CVE-2026-43073 x86-64: rename misleadingly named '__copy_user_nocache()' function
Information published.
> CVE-2026-33190 CoreDNS TSIG authentication bypass on encrypted DNS transports
Information published.
> La Ville de Quiberon nouvelle victime du ransomware Qilin
Le dimanche 3 mai 2026, le système informatique de la municipalité de Quiberon a été frappé par une cyberattaque orchestrée par le ransomware Qilin. Le post La Ville de Quiberon nouvelle victime du ransomware Qilin a été publié sur IT-Connect.
> CVE-2026-32936 CoreDNS DoH GET path missing size validation causes CPU and memory amplification
Information published.
> CVE-2026-32934 CoreDNS DNS-over-QUIC unbounded goroutine growth leads to denial of service
Information published.
> Claude AI Guided Hackers Toward OT Assets During Water Utility Intrusion
Dragos has published a report describing how threat actors used Claude AI in an attack on a water and drainage utility in Mexico. The post Claude AI Guided Hackers Toward OT Assets During Water Utility Intrusion appeared first on SecurityWeek.
> CVE-2026-33489 CoreDNS transfer plugin subzone ACL bypass via lexicographic zone comparison
Information published.
> USN-8179-4: Linux kernel (GCP) vulnerabilities
Josh Eads, Kristoffer Janke, Eduardo Vela Nava, Tavis Ormandy, and Matteo Rizzo discovered that some AMD Zen processors did not properly verify the signature of CPU microcode. This flaw is known as EntrySign. A privileged attacker could possibly use this issue to cause load malicious CPU microcode c...
> Gemini Nano : Google Chrome déploie une IA de 4 Go, sans rien vous demander
Que ce soit sur macOS, Windows ou Linux, Google Chrome télécharge un modèle d'intelligence artificielle : Gemini Nano, d'une taille de 4 Go, sans votre accord. Le post Gemini Nano : Google Chrome déploie une IA de 4 Go, sans rien vous demander a été publié sur IT-Connect.
> Ten years later, has the GDPR fulfilled its purpose?
This year marks the 10th anniversary of the EU’s adoption of the General Data Protection Regulation, which became mandatory for all companies beginning on May 25, 2018. The aim of the GDPR was simple, but important: to improve individuals’ control over their personal data....
> Fixing the password problem is as easy as 123456
How come it’s still possible to ‘secure’ an online account with a six-digit string?
> U.S. CISA adds a flaw in Palo Alto Networks PAN-OS to its Known Exploited Vulnerabilities catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Palo Alto Networks PAN-OS to its Known Exploited Vulnerabilities catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a flaw in the Palo Alto Networks PAN-OS, tracked as CVE-2026-0300 (CVSS scor...
> Woflow - 447,593 breached accounts
In March 2026, the AI-driven merchant data platform Woflow was named as a victim by the ShinyHunters data extortion group. The group subsequently published tens of thousands of files allegedly obtained from the company, comprising more than 2TB of data. The trove included hundreds of thousands of em...
> Ubuntu 22.04 Slurm Critical Access Control Denial of Service USN-8236-1
Several security issues were fixed in Slurm.
> Ubuntu 26.04 LTS Swish-e Critical Code Execution Threat USN-8240-1
Several security issues were fixed in Swish-e.
> Palo Alto Networks alerte sur une nouvelle zero-day déjà exploitée (CVE-2026-0300)
Palo Alto Networks (PAN-OS) : une faille de sécurité zero-day (CVE-2026-0300) exploitable sans authentification et déjà exploitée par des cybercriminels. Le post Palo Alto Networks alerte sur une nouvelle zero-day déjà exploitée (CVE-2026-0300) a été publié sur IT-Connect.
> WordPress : le plugin Slider Revolution doit être mis à jour (CVE-2026-6692)
Une vulnérabilité a été corrigée dans Slider Revolution, un plugin WordPress. Elle permet un attaquant de compromettre totalement un site web. Le post WordPress : le plugin Slider Revolution doit être mis à jour (CVE-2026-6692) a été publié sur IT-Connect.
> Open-source MCP server monitoring for Python apps
Pythonic Model Context Protocol servers handle tool calls, session events, module imports, and subprocess activity. BlueRock has released MCP Python Hooks, an open source runtime sensor that gives developers a way to capture those signals without modifying application code. What the sensor captures...
> vm2 Node.js Library Vulnerabilities Enable Sandbox Escape and Arbitrary Code Execution
A dozen critical security vulnerabilities have been disclosed in the vm2 Node.js library that could be exploited by bad actors to break out of the sandbox and execute arbitrary code on susceptible systems. vm2 is an open-source library used to run untrusted JavaScript code inside a secure sandbox by...
> Multi-model AI is creating a routing headache for enterprises
Application teams are moving AI inference into production systems that support business operations. Enterprises are expanding traffic management, identity controls, observability, and routing systems for multiple AI models and environments. F5’s 2026 State of Application Strategy Report found that 7...