[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TVE-2026-04: TP-Link HTTP authentication bypass
An attacker sending a malformed HTTP POST request over LAN to a TP-Link Smart camera device can trigger the vulnerability described here. This report describes an authentication bypass vulnerability in the HTTP server implementation. The vulnerability we are disclosing in this advisory affected a wi...
> TAPOcalypse Now: Exploiting TP-Link Smart Devices From Anywhere
Summary Following our hacking of Xiaomi home security cameras, we have decided to look at another market dominating vendor in our region, TP-LINK. In this post, we describe the major findings from our review of new generation TAPO security cameras: a pre-auth RCE stack BOF that can be exploited not...
> Vos données ont-elles déjà fuité ?
Vérifier une fuite de données avec ZATAZ : moteurs France et monde, veille premium et risques cyber.
> CVE-2026-34124: TP-Link HTTP GET stack buffer overflow
An attacker sending a malformed HTTP POST request over LAN to a TP-Link Smart camera device can trigger the vulnerability described here. This report describes a stack buffer overflow, which leads to denial of service and may potentially lead to remote code execution. The vulnerability we are disclo...
> CVE-2026-34121: TP-Link HTTP authentication bypass
An attacker sending a malformed HTTP POST request over LAN to a TP-Link Smart camera device can trigger the vulnerability described here. This report describes an authentication bypass vulnerability in the HTTP server implementation. The vulnerability we are disclosing in this advisory affected a wi...
> Avril noir pour les forums pirates : arrestations, disparitions et fuite revendiquée contre DarkForums
Avril noir pour les forums pirates : HexDex risque 10 ans de prison, DarkForums visé par une fuite de données !
> CVE-2026-34120: TP-Link HTTP POST body heap buffer overflow
An attacker sending a malformed HTTP POST request over LAN to a TP-Link Smart camera device can trigger the vulnerability described here. This report describes a heap buffer overflow, which leads to remote code execution. The vulnerability we are disclosing in this advisory affected a wide range of...
> CVE-2026-34119: TP-Link HTTP POST body heap buffer overflow
An attacker sending a malformed HTTP POST request over LAN to a TP-Link Smart camera device can trigger the vulnerability described here. This report describes a heap buffer overflow, which leads to remote code execution. The vulnerability we are disclosing in this advisory affected a wide range of...
> Ongoing supply-chain attack 'explicitly targeting' security, dev tools
Vendor confirms repo data exposure after Lapsus$ claims source code, secrets dump
> CVE-2026-34118: TP-Link HTTP POST body heap buffer overflow
An attacker sending a malformed HTTP POST request over LAN to a TP-Link Smart camera device can trigger the vulnerability described here. This report describes a heap buffer overflow, which leads to remote code execution. The vulnerability we are disclosing in this advisory affected a wide range of...
> CVE-2026-0651: TP-Link HTTP GET path traversal
An attacker sending a malformed HTTP POST request over LAN to a TP-Link Smart camera device can trigger the vulnerability described here. This report describes a path traversal which can lead to leaking secrets. The vulnerability we are disclosing in this advisory affected a wide range of TP-Link de...
> Ongoing supply-chain attack 'explicitly targeting' security, dev tools
Vendor confirms repo data exposure after Lapsus$ claims source code, secrets dump Software security testing outfit Checkmarx has become the latest organization caught up in an ongoing attack on security-tool providers. The biz said data posted online appears to have come from one of its GitHub repos...
> CVE-2025-8065: TP-Link ONVIF stack buffer overflow
An attacker sending a malformed ONVIF request over LAN to a TP-Link Smart camera device can trigger the vulnerability described here. This report describes a stack buffer overflow, which leads to pre-auth remote code execution via LAN or WAN (through browser). The vulnerability we are disclosing in...
> The GUARD Act Isn’t Targeting Dangerous AI—It’s Blocking Everyday Internet Use
Lawmakers in Congress are moving quickly on the GUARD Act, an age-gating bill restricting minors’ access to a wide range of online tools, with a key vote expected this week. The proposal is framed as a response to alarming cases involving “AI companions” and vulnerable young users. But the text of t...
> Robinhood account creation flaw abused to send phishing emails
Online trading platform Robinhood's account creation process was exploited by threat actors to inject phishing messages into legitimate emails, tricking users into believing their accounts had suspicious activity. [...]
> Slackware 15.0 Proftpd Critical SQL Injection Bypass Advisory 2026-118-01
New proftpd packages are available for Slackware 15.0 and -current to fix a security issue.
> Pitney Bowes - 8,243,989 breached accounts
In April 2026, the hacking collective ShinyHunters claimed to have obtained data from Pitney Bowes as part of a broader extortion campaign that also named several other organisations. After negotiations allegedly failed, the group publicly released the data which included 8.2M unique email addresses...
> Football et faux billets : l’alerte cyber autour de Lens-Nice
Faux site Lens-Nice : ZATAZ révèle une fausse billetterie et un abonnement caché derrière la finale de la coupe de France de football : Lens-Nice.
> Congress Must Reject New Insufficient 702 Reauthorization Bill
Speaker Johnson has introduced a new fig leaf over the American surveillance state, the Foreign Intelligence Accountability Act. Introduced with only days to go before Section 702 of the Foreign Intelligence Surveillance Act (FISA) expires and the U.S. government loses one of its most invasive surve...
> GlassWorm malware attacks return via 73 OpenVSX "sleeper" extensions
A new wave of the Glassworm campaign is targeting the OpenVSX ecosystem with 73 "sleeper" extensions that turn malicious after an update. [...]