A 21-year-old man suspected of conducting approximately 100 data breaches since late 2025 - including a hack of the French Ministry of National Education that exposed records on almost a quarter of a million employees - has been arrested at his home in western France.
Read more in my article on t...
After addressing a widespread outage that affected Outlook.com users worldwide on Monday, Microsoft has asked iPhone users to re-enter their credentials to regain access to their Outlook and Hotmail accounts via the default Mail app. [...]
The National Cyber Security Centre has warned against measuring SOCs with ticket-based metrics
The threat detection startup will invest in accelerating its engineering and go-to-market efforts.
The post Spectrum Security Emerges From Stealth Mode With $19 Million appeared first on SecurityWeek.
It was discovered that NLTK incorrectly handled file extraction when
opening a maliciously crafted zip file. An attacker could possibly use this
issue to create or overwrite files on the system and execute arbitrary
code.
L'intelligence artificielle va s'inviter dans Ubuntu en 2026 : Canonical prépare déjà le terrain, tout en misant sur une approche locale.
Le post Ubuntu devrait intégrer de l’IA en 2026 : voici ce que l’on sait a été publié sur IT-Connect.
Arctic Wolf attributed this large-scale spear-phishing campaign to BlueNoroff, a financially motivated subgroup of the Lazarus Group
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-46299 Google Big Sleep discovered that processing maliciously crafted web content may disclose internal states of the app.
A Chinese national accused of being a member of the Silk Typhoon hacking group has been extradited to the U.S. from Italy.Â
Xu Zewei, 34, was arrested in July 2025 by Italian authorities for his alleged links to the Chinese state-sponsored threat group and for orchestrating cyber attacks against Ame...
Ludvig Pedersen discovered that the System.Security.Cryptography.Xml
library in .NET incorrectly handled certain XML inputs. An attacker could
possibly use this issue to consume excessive resources, resulting in a
denial of service. (CVE-2026-33116, CVE-2026-26171)
Ludvig Pedersen and Kevin Jones d...
The increase is being driven by powerful privacy laws in states like California, new interstate partnerships and a renewed focus on the privacy impacts of AI and automation.
The post U.S. companies hit with record fines for privacy in 2025 appeared first on CyberScoop.
NCSC’s SilentGlass blocks malicious HDMI/DisplayPort links, protecting monitors from hardware attacks. Now commercialized for global use. The UK’s National Cyber Security Centre (NCSC) has launched SilentGlass, a new device to protect one of the most overlooked parts of modern IT systems: the physic...
It was discovered that the Microsoft.AspNetCore.DataProtection library in
.NET did not properly verify cryptographic signatures under certain
conditions. A remote attacker could possibly use this issue to elevate
privileges.
Microsoft vient de mettre en ligne la version 0.99.0 de PowerToys, avec deux nouveaux outils : Grab And Move et Power Display. Voici les nouveautés.
Le post PowerToys 0.99 est disponible : Microsoft introduit Grab And Move et Power Display a été publié sur IT-Connect.
On paper, the vast majority of crisis plans look reasonable, actionable and complete. Once the rubber hits the road, however, chaos emerges quickly.
An administrative role meant for artificial intelligence (AI) agents within Microsoft Entra ID could enable privilege escalation and identity takeover attacks, according to new findings from Silverfort.
Agent ID Administrator is a privileged built-in role introduced by Microsoft as part of its agent...
The ShinyHunters cybercrime group claimed to have stolen 9 million records containing personal information from Medtronic.
The post Medtronic Hack Confirmed After ShinyHunters Threatens Data Leak appeared first on SecurityWeek.
Microsoft a annoncé des évolutions pour Windows Update, avec un objectif : redonner le contrôle aux utilisateurs et mettre fin aux redémarrages intempestifs.
Le post Windows Update : les nouvelles options qui vous redonnent (enfin) le contrôle a été publié sur IT-Connect.
Software supply chains have quietly become one of the most critical and most vulnerable foundations of modern enterprises. Today, applications are no longer monolithic systems built entirely in-house. Instead, they are complex assemblies of open-source libraries, third-party packages, container imag...