[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (1 articles)

|

// AI-powered summary generated at 00:01

> One in Eight Workers Has Sold Their Corporate Logins
Cifas says that 13% of employees admit selling company credentials to a former colleague
> Windows Phone Link Exploited by CloudZ RAT to Steal Credentials and OTPs
Cybersecurity researchers have disclosed details of an intrusion that involved the use of a CloudZ remote access tool (RAT) and a previous undocumented plugin dubbed Pheno with the aim of facilitating credential theft. "According to the functionalities of the CloudZ RAT and Pheno plugin, this was wi...
> Government, Scientific Entities Hit via Daemon Tools Supply Chain Attack
While trojanized Daemon Tools versions were installed worldwide, a sophisticated backdoor was dropped only on a dozen systems. The post Government, Scientific Entities Hit via Daemon Tools Supply Chain Attack appeared first on SecurityWeek.
> CVE-2026-43037 ip6_tunnel: clear skb2->cb[] in ip4ip6_err()
Information published.
> CVE-2026-43964
Information published.
> Les patrons de l’IA face à la violence
Attaques contre Sam Altman : l’IA devient un enjeu de sécurité, entre peur existentielle et radicalisation.
> Faille Apache : deux simples trames suffisent à faire un déni de service (CVE-2026-23918)
Protégez vos serveurs Apache contre la faille CVE-2026-23918 dans le module HTTP/2. Cette vulnérabilité peut entraîner un DoS, et même une RCE. Le post Faille Apache : deux simples trames suffisent à faire un déni de service (CVE-2026-23918) a été publié sur IT-Connect.
> Couvrez ce mot de passe, que je ne saurais voir
Mots de passe affichés, Wi-Fi exposé, accès sensibles visibles : ZATAZ rappelle, exemples à l’appui, pourquoi la négligence reste l’un des meilleurs alliés des cybercriminels.
> Malicious PyTorch Lightning update hits AI supply chain security
A malicious PyTorch Lightning update (v2.6.3) on PyPI spread briefly, stealing credentials and raising major concerns about AI supply chain security. A malicious update of the PyTorch Lightning library exposed developers to credential theft and remote compromise. Attackers uploaded version 2.6.3 to...
> The Hardcoded Horror Show : des compromissions les plus humiliantes de l’histoire ?
FulcrumSec accuse des géants d’avoir exposé des secrets critiques dans leurs codes et dépôts privés.
> Oracle Debuts Monthly Critical Security Patch Updates
Containing fixes for critical-severity vulnerabilities, the monthly rollouts will focus on addressing priority issues faster. The post Oracle Debuts Monthly Critical Security Patch Updates appeared first on SecurityWeek.
> Des pirates ciblent les failles de l’IA santé
Le pirate FulcrumSec accuse des startups IA santé de failles cloud et de fuites de données médicales sensibles.
> Palo Alto PAN-OS Flaw Under Active Exploitation Enables Remote Code Execution
Palo Alto Networks has released an advisory warning that a critical buffer overflow vulnerability in its PAN-OS software has been exploited in the wild. The vulnerability, tracked as CVE-2026-0300, has been described as a case of unauthenticated remote code execution. It carries a CVSS score of 9.3...
> USN-8236-1: Slurm vulnerabilities
It was discovered that Slurm did not correctly handle certain file system operations. An attacker could possibly use this issue to modify files or leak sensitive information. This issue only affected Ubuntu 22.04 LTS. (CVE-2023-41914) Ryan Hall discovered that Slurm did not correctly enforce certai...
> DAEMON Tools : des milliers de PC infectés via les versions officielles
Depuis début avril 2026, les programmes d'installation de DAEMON Tools sont infectés par un logiciel malveillant suite à une attaque de type supply-chain. Le post DAEMON Tools : des milliers de PC infectés via les versions officielles a été publié sur IT-Connect.
> CrowdStrike Named a Leader in the First-Ever Gartner® Magic Quadrant™ for Cyberthreat Intelligence Technologies
> Proton Mail déploie le chiffrement post-quantique : voici comment l’activer
Tous les utilisateurs de Proton Mail peuvent désormais activer la protection post-quantique sur leur compte afin de protéger leurs e-mails des futures menaces. Le post Proton Mail déploie le chiffrement post-quantique : voici comment l’activer a été publié sur IT-Connect.
> Palo Alto Networks to Patch Zero-Day Exploited to Hack Firewalls
CVE-2026-0300 affects the Captive Portal service of PAN-OS software on PA and VM series firewalls. The post Palo Alto Networks to Patch Zero-Day Exploited to Hack Firewalls appeared first on SecurityWeek.
> Ubuntu 26.04 Docker Critical Security Threats USN-8230-1 CVE-2026-33747
Several security issues were fixed in Docker.
> USN-8230-1: Docker vulnerabilities
It was discovered that BuildKit, contained within Docker, incorrectly handled file path validation when processing frontend API messages. An attacker could possibly use this issue to write files outside of the intended state directory. (CVE-2026-33747) It was discovered that BuildKit, contained wit...