[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (4 articles)

|

// AI-powered summary generated at 12:01

> GoGra : ce malware Linux est piloté avec l’API Microsoft Graph et Outlook
Une variante Linux de la backdoor GoGra a été identifiée. Sa particularité : elle s'appuie sur l'API Microsoft Graph pour communiquer avec les pirates. Le post GoGra : ce malware Linux est piloté avec l’API Microsoft Graph et Outlook a été publié sur IT-Connect.
> IT spending to hit $6.31 trillion record, thanks to AI
Global spending on IT is expected to reach $6.31 trillion in 2026, according to the latest quarterly forecast from Gartner, marking a 13.5% increase from the previous year. The forecast shows that growth is spread across all major segments, though not evenly. Much of the increase is tied to ongoing...
> Weak security means attackers could disable all of a city's public EV chargers
Demonstrated in China, probably applicable elsewhere
> Weak security means attackers could disable all of a city's public EV chargers
Demonstrated in China, probably applicable elsewhere Black Hat Asia  Developers of rented internet of things infrastructure – stuff like public EV chargers and shared e-bikes – are prioritizing user convenience over security, and leaving themselves exposed to wide-scale denial of service attacks on...
> Where AI in CI/CD is working for engineering teams
Developers have folded AI into daily coding work. Still, the same tools remain largely absent from the systems that validate and ship software. New research from JetBrains points to a widening gap between how engineers write code on their own machines and what runs inside continuous integration and...
> ISC Stormcast For Friday, April 24th, 2026 https://isc.sans.edu/podcastdetail/9906, (Fri, Apr 24th)
> Carnival - 7,531,359 breached accounts
In April 2026, the notorious hacking collective ShinyHunters claimed they had obtained a substantial volume of data belonging to the Carnival cruise operator and attempted to extort the organisation to prevent the data from being leaked. The following week, the group published the data publicly, whi...
> Runtime Analytics Cuts Millions of Alerts to What Matters
TL;DR Research from Contrast Security's Software Under Siege 2025 report reveals that applications face an average of 81 viable attacks per month that reach actual vulnerabilities, while perimeter-based detection tools generate overwhelming alert volumes with minimal correlation to real-world...
> Zero Trust Architecture for Sidecar-Based MCP Servers
Learn how to secure sidecar-based MCP servers using Zero Trust Architecture and post-quantum security to prevent tool poisoning and lateral movement. The post Zero Trust Architecture for Sidecar-Based MCP Servers appeared first on Security Boulevard.
> Ubuntu 25.10 jq Significant Denial of Service USN-8202-1 Update Release
Several security issues were fixed in jq.
> Fitjar kommune
Une interruption de la production d'eau potable a eu lieu suite à un incident au site de traitement des eaux de Fitjar kommune, qui enquête sur une possible cyberattaque. Les autorités nationales ont été alertées de cet événement, et la municipalité craint un piratage de données. Il n'est pas encore...
> East Inc.
East Inc. a confirmé avoir subi un accès non autorisé à son réseau interne par des tiers le 24 avril. Bien qu'aucune fuite d'informations vers l'extérieur n'ait été confirmée à ce stade, l'entreprise a immédiatement pris des mesures et signalé l'incident aux autorités compétentes. Des enquêtes sont...
> Confidential clusters for Red Hat OpenShift: Developer Preview now available on Microsoft Azure with AMD SEV-SNP
Extending confidential computing from individual workloads to the entire cluster is a new frontier in cloud-native security.Today, Red Hat is announcing the Developer Preview of confidential clusters for Red Hat OpenShift, a new feature of OpenShift that extends confidential computing to the cluster...
> Medtronic plc
Medtronic plc a annoncé qu'un tiers non autorisé avait accédé à des données de certains de ses systèmes informatiques le 24 avril 2026. L'entreprise a immédiatement pris des mesures pour contenir l'incident et a engagé des experts externes pour mener son enquête. À ce stade, Medtronic n'a identifié...
> Multiples vulnérabilités dans Traefik (24 avril 2026)
De multiples vulnérabilités ont été découvertes dans Traefik. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données et un contournement de la politique de sécurité.
> Multiples vulnérabilités dans le noyau Linux de Red Hat (24 avril 2026)
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation de privilèges et un déni de service à distance.
> Communicating Cyber Risk to the Board: Executive Reporting Best Practices
Key Takeaways Why Cyber Risk Gets Lost in Translation Most CEOs can recite their quarterly benchmarks and revenue figures down to the decimal point. However, when asked to define their organization’s cyber risk exposure, the answers typically drift into the vague and anecdotal. This disconnect is oc...
> Vulnérabilité dans Microsoft Edge (24 avril 2026)
Une vulnérabilité a été découverte dans Microsoft Edge. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.
> Multiples vulnérabilités dans les produits IBM (24 avril 2026)
De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
> Bitwarden CLI password manager trojanized in supply chain attack
Researchers warn of a new software supply chain attack that resulted in a malicious version of Bitwarden CLI, the terminal version of the extremely popular open-source password manager. The attack is believed to be related to the string of recent supply chain compromises attri...