[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> Don't pay Vect a ransom - your data's likely already wiped out
'Full recovery is impossible for anyone, including the attacker' Organizations hit by the wave of Trivy and LiteLLM supply-chain compromises that paid Vect in hopes of recovering their data likely did not get much back, according to Check Point Research. That's because the ransomware Vect uses isn't...
> Cyber Insurance Data Gives CISOs New Ammo for Budget Talks
Boards may ignore alerts, but they listen to losses: new data from Resilience links security gaps directly to financial impact. The post Cyber Insurance Data Gives CISOs New Ammo for Budget Talks appeared first on SecurityWeek.
> Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git Push
Cybersecurity researchers have disclosed details of a critical security vulnerability impacting GitHub.com and GitHub Enterprise Server that could allow an authenticated user to obtain remote code execution with a single "git push" command. The flaw, tracked as CVE-2026-3854 (CVSS score: 8.7), is a...
> Why Sharing a Screenshot Can Get You Jailed in the UAE
The war in Iran has drawn attention to arrests in the United Arab Emirates over online content, but the legal framework behind that enforcement has existed for years.
> Paragon is not collaborating with Italian authorities probing spyware attacks, report says
Despite promising to help determine what happened with the hacks targeting journalists and activists in Italy, Israeli-American spyware maker Paragon has reportedly not responded to authorities’ requests for information.
> How bail bond scams are using AI to target families
A call saying someone you love has been arrested and needs money ASAP can feel so real that you act before you think. Learn how bail bond scams work and what to watch for to help protect you and your family from falling for the scheme. The post How bail bond scams are using AI to target famili...
> Brazilian LofyGang Resurfaces After Three Years With Minecraft LofyStealer Campaign
A cybercrime group of Brazilian origin has resurfaced after more than three years to orchestrate a campaign that targets Minecraft players with a new stealer called LofyStealer (aka GrabBot). "The malware disguises itself as a Minecraft hack called 'Slinky,'" Brazil-based cybersecurity company ZenoX...
> Open is Not Costless: Reclaiming Sustainable Infrastructure
For years, the software industry treated public package registries like a law of nature. They were simply there. Immutable, invisible, and somehow outside the normal rules of cost, capacity, and responsibility. The post Open is Not Costless: Reclaiming Sustainable Infrastructure appeared first...
> USN-8219-1: UltraJSON vulnerabilities
Cameron Criswell discovered that UltraJSON contained a memory leak that would occur when parsing large integers. An attacker could possibly use this issue to cause UltraJSON to crash, resulting in a denial of service. This issue only affected Ubuntu 24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CV...
> Cyber Command, NSA chief warns foreign adversaries likely to target midterms
Army Gen. Joshua Rudd told lawmakers “we are postured and ready to support as required or tasked, making sure that we safeguard our elections.”
> Police arrest 10 suspected members of Black Axe cybercrime gang
A coordinated police operation in Switzerland has targeted suspected members of the Black Axe criminal network. On 28 April 2026, authorities carried out house searches across several Swiss cantons, leading to 10 arrests, including the Black Axe ‘Regional Head’ for Southern Europe. Most of those arr...
> CNIL
La Commission Nationale de l'Informatique et des Libertés (CNIL) a approuvé le code de conduite proposé par l'Alliance du Commerce, destiné aux professionnels du secteur de l'habillement et de la chaussure.Ce code, premier de portée nationale approuvé par l'autorité, vise à aider les enseignes et ma...
> Datatilsynet - autorité norvégienne
L'autorité norvégienne de protection des données (Datatilsynet) a annoncé la clôture d'une procédure d'inspection initiée en 2023 à l'encontre de l'Administration norvégienne du travail et de la protection sociale (NAV), tout en programmant un nouveau contrôle pour 2026.L'inspection initiale, menée...
> Vimeo Confirms User and Customer Data Breach
The ShinyHunters group is threatening to leak stolen files unless Vimeo agrees to pay a ransom. The post Vimeo Confirms User and Customer Data Breach appeared first on SecurityWeek.
> ICO - autorité britannique
L'autorité britannique de protection des données (ICO) a publié des lignes directrices finales concernant une nouvelle disposition d'option de retrait pour la prospection directe par voie électronique destinée aux organisations caritatives.Cette nouvelle règle, introduite par la loi sur les données...
> AEPD - autorité espagnole
L'Agence espagnole de protection des données (AEPD) a publié une décision de sanction à l'encontre de GESCONSULT, S.A. S.G.I.I.C. (comprenant le prononcé d'une amende de 3 000 €) pour des manquements en lien avec la communication de données personnelles sans base légale. Cette affaire débute par une...
> AI Tokenomics: Cost, Risk & AI Dependency (2026)
AI tokenomics is reshaping cost, risk, and control. Learn how token-based pricing impacts AI usage and how to prepare. The post AI Tokenomics: Cost, Risk & AI Dependency (2026) appeared first on Security Boulevard.
> ANSPDCP - autorité roumaine
L'Autorité nationale de surveillance du traitement des données à caractère personnel (ANSPDCP) a publié une décision de sanction à l'encontre de CROWD ENTERTAINMENT LIMITED, comprenant le prononcé d'une amende de 35 000 €, pour des manquements liés à l'exactitude et à la minimisation des données. Ce...
> Access control with IAM Identity Center session tags
As organizations expand their Amazon Web Services (AWS) footprint, managing secure, scalable, and cost-efficient access across multiple accounts becomes increasingly important. AWS IAM Identity Center offers a centralized, unified solution for managing workforce access to AWS accounts. It simplifies...
> Minnesota’s CISOs: Homegrown Talent Securing Finance, Insurance, and Beyond
Minnesota has produced a quietly strong CISO community, particularly in financial services and insurance. The leaders in this feature are based in the Twin Cities metro or built the core of their careers there, and their work spans credit unions, community banking, wealth management, payment technol...