> TODAY'S SUMMARY (109 articles)
Today's cybersecurity landscape reveals several critical developments. AWS AgentCore's security vulnerabilities, including weak VM isolation and excessive permissions, have been exposed, potentially facilitating attacks. In international law enforcement, Japan has extradited a Russian national linked to the Qilin ransomware gang to Germany, where further arrests have occurred, despite ongoing attacks by the group. The FBI has also arrested members of the ShinyHunters extortion group, underscoring the persistent threat of data breaches. Meanwhile, unpatched vulnerabilities in the AhsayCBS backup platform are being actively exploited for webshell deployment and cryptocurrency mining. A noticeable trend is the shift in ransomware tactics, with attackers increasingly opting for data theft rather than encryption. Lastly, the U.S. and allies have disrupted Chinese state-sponsored hacking tools, illustrating ongoing geopolitical cybersecurity tensions.
|
// AI-powered summary generated at 20:00
Information published.
Information published.
Le dimanche 3 mai 2026, le système informatique de la municipalité de Quiberon a été frappé par une cyberattaque orchestrée par le ransomware Qilin.
Le post La Ville de Quiberon nouvelle victime du ransomware Qilin a été publié sur IT-Connect.
Information published.
Information published.
Dragos has published a report describing how threat actors used Claude AI in an attack on a water and drainage utility in Mexico.
The post Claude AI Guided Hackers Toward OT Assets During Water Utility Intrusion appeared first on SecurityWeek.
Information published.
Josh Eads, Kristoffer Janke, Eduardo Vela Nava, Tavis Ormandy, and Matteo
Rizzo discovered that some AMD Zen processors did not properly verify the
signature of CPU microcode. This flaw is known as EntrySign. A privileged
attacker could possibly use this issue to cause load malicious CPU
microcode c...
Que ce soit sur macOS, Windows ou Linux, Google Chrome télécharge un modèle d'intelligence artificielle : Gemini Nano, d'une taille de 4 Go, sans votre accord.
Le post Gemini Nano : Google Chrome déploie une IA de 4 Go, sans rien vous demander a été publié sur IT-Connect.
This year marks the 10th anniversary of the EU’s adoption of the General Data Protection Regulation, which became mandatory for all companies beginning on May 25, 2018.
The aim of the GDPR was simple, but important: to improve individuals’ control over their personal data....
How come it’s still possible to ‘secure’ an online account with a six-digit string?
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Palo Alto Networks PAN-OS to its Known Exploited Vulnerabilities catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a flaw in the Palo Alto Networks PAN-OS, tracked as CVE-2026-0300 (CVSS scor...
In March 2026, the AI-driven merchant data platform Woflow was named as a victim by the ShinyHunters data extortion group. The group subsequently published tens of thousands of files allegedly obtained from the company, comprising more than 2TB of data. The trove included hundreds of thousands of em...
Several security issues were fixed in Slurm.
Several security issues were fixed in Swish-e.
Palo Alto Networks (PAN-OS) : une faille de sécurité zero-day (CVE-2026-0300) exploitable sans authentification et déjà exploitée par des cybercriminels.
Le post Palo Alto Networks alerte sur une nouvelle zero-day déjà exploitée (CVE-2026-0300) a été publié sur IT-Connect.
Une vulnérabilité a été corrigée dans Slider Revolution, un plugin WordPress. Elle permet un attaquant de compromettre totalement un site web.
Le post WordPress : le plugin Slider Revolution doit être mis à jour (CVE-2026-6692) a été publié sur IT-Connect.
Pythonic Model Context Protocol servers handle tool calls, session events, module imports, and subprocess activity. BlueRock has released MCP Python Hooks, an open source runtime sensor that gives developers a way to capture those signals without modifying application code. What the sensor captures...
A dozen critical security vulnerabilities have been disclosed in the vm2 Node.js library that could be exploited by bad actors to break out of the sandbox and execute arbitrary code on susceptible systems.
vm2 is an open-source library used to run untrusted JavaScript code inside a secure sandbox by...
Application teams are moving AI inference into production systems that support business operations. Enterprises are expanding traffic management, identity controls, observability, and routing systems for multiple AI models and environments. F5’s 2026 State of Application Strategy Report found that 7...