[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (3 articles)

|

// AI-powered summary generated at 08:00

> CVE-2026-6845 Binutils: binutils: denial of service via crafted elf file
Information published.
> CVE-2026-7598 libssh2 userauth.c userauth_password integer overflow
Information published.
> Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: The AI criminal mastermind is already hiring on gig platforms Labor-hire platforms let anyone with a credit card post a task and pay a stranger to complete it. The RentAHuman platform extends that model...
> CVE-2026-43058 media: vidtv: fix pass-by-value structs causing MSAN warnings
Information published.
> CISO Diaries: Victor-Andrei Nicolae on Practical Security, Patience, and AI-Driven Defense
Security leadership is often associated with emerging threats and advanced technologies, but much of the role comes down to disciplined execution, thoughtful decision-making, and balancing protection with business continuity. In CISO Diaries, we speak with leading CISOs around the world to understan...
> CISA Adds Actively Exploited Linux Root Access Bug CVE-2026-31431 to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a recently disclosed security flaw impacting various Linux distributions to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The vulnerability, tracked as CVE-2026-3...
> 1,800 Developers Hit in Mini Shai-Hulud Supply Chain Attack Across PyPI, NPM, and PHP
What happened A supply chain attack campaign attributed to TeamPCP, dubbed Mini Shai-Hulud, has compromised packages across the PyPI, NPM, and PHP ecosystems over a two-day period, affecting over 1,800 developer repositories containing stolen credentials. The campaign was first identified on April 2...
> ConsentFix v3 Automates OAuth Abuse to Bypass MFA and Hijack Azure Accounts
What happened A third iteration of the ConsentFix attack technique has been circulating on hacker forums, introducing automation and scalability to a method that abuses Microsoft Azure’s OAuth2 authorization code flow to hijack accounts without passwords and despite multi-factor authentication being...
> Ville de Quiberon
La Ville de Quiberon a été victime d'une cyberattaque qui a affecté son système informatique, comme l'a annoncé la commune." Des perturbations temporaires des services municipaux sont signalées, incitant les usagers à reporter leurs démarches non urgentes.", précisent les autorités locales qui ont m...
> FBI Links Cybercriminals to Sharp Surge in Cargo Theft Attacks
What happened The FBI issued a public service announcement on April 30, 2026, warning the US transportation and logistics industry of a sharp rise in cyber-enabled cargo theft, with estimated losses in the United States and Canada reaching nearly $725 million in 2025. That represents a 60% increase...
> Edtech Firm Instructure Discloses Cyber Incident, Probes Impact
What happened Instructure, the company behind the Canvas learning management system, has disclosed that it recently suffered a cybersecurity incident perpetrated by a criminal threat actor and is now investigating its scope with the help of outside forensics experts. The disclosure was made by Chief...
> Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks
A new disclosed cPanel flaw tracked as CVE-2026-41940 is being mass-exploited to breach websites and encrypt data in "Sorry" ransomware attacks. [...]
> Congress Punts FISA Section 702 Renewal to June
What happened Congress approved a 45-day extension of Section 702 of the Foreign Intelligence Surveillance Act on Thursday, hours before the program was set to lapse, pushing the next deadline to June 12. President Trump is expected to sign the legislation before the midnight deadline. The path to t...
> Ameriprise Financial Data Breach Exposes Personal Information of 48,000 Customers
What happened Ameriprise Financial has disclosed a data breach affecting nearly 48,000 individuals across the United States, following unauthorized access to stored company data and files that began on March 2, 2026. The company detected the intrusion on March 18, approximately 16 days after it bega...
> Debian Trixie Incus Critical DoS Security Advisory DSA-6244-1
Multiple security issues were discovered in Incus, a system container and virtual machine manager, which could result in denial of service, For the stable distribution (trixie), these problems have been fixed in version 6.0.4-2+deb13u7. We recommend that you upgrade your incus packages.
> Dayton Mayor Demands Accountability After License Plate Reader Data Breach
What happened Dayton, Ohio Mayor Shenise Turner-Sloss and Commissioner Darryl Fairchild issued a public statement on May 2, 2026, demanding accountability after the city’s Automated License Plate Readers were pulled from service following confirmation that data collected through the technology was s...
> Ubuntu 20.04 Chrome Key Security Update PSA-2026-456-07
New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.
> Slackware 15.0 gnutls Critical Security Issue CVE-2026-33846 2026-122-02
New gnutls packages are available for Slackware 15.0 and -current to fix a security issue.
> I Mapped Every Major Startup Credit Program for 2026. Most Founders Are Leaving $500K+ on the Table
Founders raise venture money to extend runway. Then they leave six figures of free credits sitting in a portal they never logged into. After watching this happen for a decade, I built a public directory of every major program. Here's what I learned mapping the landscape. The post I Mapped Every Majo...
> Fedora 38.0 Core Security Alert on Threat Exposure SSA-2023-789-01
New kernel packages are available for Slackware 15.0 and -current to fix a security issue.