[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (14 articles)

|

// AI-powered summary generated at 16:00

> [webapps] Python-Multipart 0.0.22 - Path Traversal
Python-Multipart 0.0.22 - Path Traversal
> [local] Windows 11 23H2 - Denial of Service (DoS)
Windows 11 23H2 - Denial of Service (DoS)
> KasadaIQ’s Q1 Insights: How AI Became Adversary Infrastructure
KasadaIQ’s Q1 2026 Threat Intelligence Report highlights a structural shift in automated threats: AI is now embedded across the adversary lifecycle. From large-scale account commoditization to verification bypass and AI agent exploitation, organizations face a rapidly evolving and industrialized thr...
> [local] Google Chrome 145.0.7632.75 - CSSFontFeatureValuesMap
Google Chrome 145.0.7632.75 - CSSFontFeatureValuesMap
> [webapps] SUSE Manager 4.3.15 - Code Execution
SUSE Manager 4.3.15 - Code Execution
> Smashing Security podcast #465: This developer wanted to cheat at Roblox. It cost millions
A developer at an AI startup wanted to cheat at Roblox. They downloaded a dodgy script on their work laptop. That one decision triggered a cascade of failures that ended with a $2 million data breach affecting hundreds of thousands of organisations. All for some free in-game currency. Meanwhile,...
> [webapps] deephas 1.0.7 - Prototype Pollution
deephas 1.0.7 - Prototype Pollution
> [webapps] Erugo 0.2.14 - Remote Code Execution (RCE)
Erugo 0.2.14 - Remote Code Execution (RCE)
> Official SAP npm packages compromised to steal credentials
Multiple official SAP npm packages were compromised in what is believed to be a TeamPCP supply-chain attack to steal credentials and authentication tokens from developers' systems. [...]
> [webapps] Cybersecurity AI (CAI) Framework 0.5.10 - Command Injection
Cybersecurity AI (CAI) Framework 0.5.10 - Command Injection
> [webapps] Camaleon CMS v2.9.0 - Path Traversal
Camaleon CMS v2.9.0 - Path Traversal
> House approves spy program on second attempt, Senate fate murky
The bill, which passed 235-191, would renew Section 702 of the Foreign Intelligence Surveillance Act for three years.
> [webapps] Js2Py 0.74 - RCE
Js2Py 0.74 - RCE
> Visual Studio Code 1.118 adds auto model selection to Copilot CLI
Microsoft’s editor releases continue on a monthly cadence, with the Insiders build of Visual Studio Code 1.118. The update concentrates on the Copilot CLI integration, session management in the Agents app, and an opt-in path for TypeScript 7.0. Copilot CLI gains auto model selection Two separate ent...
> Popular WordPress redirect plugin hid dormant backdoor for years
The Quick Page/Post Redirect plugin, installed on more than 70,000 WordPress sites, had a backdoor added five years ago that allows injecting arbitrary code into users' sites. [...]
> EFF Submission to UN Report on the Role of Media in the Context of Israel’s Policies Toward Palestinians
The UN Special Rapporteur on the situation of human rights in the Palestinian territories occupied since 1967 recently announced a study addressing the killings and attacks against Palestinian journalists and media workers, the destruction of media infrastructure in Gaza, and the production and diss...
> Researchers built a chatbot that only knows the world before 1931
What happens when you strip the internet out of AI? Researchers built a chatbot that only knows the world before 1931.
> US, China partner on scam center takedown in Dubai
The Justice Department said the operation began last year following “numerous” victim complaints to the FBI by U.S. victims who lost millions through cryptocurrency investment fraud schemes.
> Survey Sees Rising Demand for Senior Cybersecurity Pros in Age of AI
A global survey of 2,750 cybersecurity and IT professionals published this week finds that for the third consecutive year a lack of cybersecurity skills is cited as the top cause of security breaches (56%), with 51% reporting they specifically need individuals with senior-level skills. Conducted by...
> Hackers exploit RCE flaws in Qinglong task scheduler for cryptomining
Hackers are exploiting two authentication bypass vulnerabilities in the Qinglong open-source task scheduling tool to deploy cryptominers on developers' servers. [...]