[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (13 articles)

|

// AI-powered summary generated at 16:01

> CVE-2026-31505 iavf: fix out-of-bounds writes in iavf_get_ethtool_stats()
Information published.
> CVE-2026-31440 dmaengine: idxd: Fix leaking event log memory
Information published.
> Recent Microsoft Defender Vulnerability Exploited as Zero-Day
The flaw allows attackers to access the SAM database, extract NTLM hashes, and gain System privileges. The post Recent Microsoft Defender Vulnerability Exploited as Zero-Day appeared first on SecurityWeek.
> CVE-2026-31497 Bluetooth: btusb: clamp SCO altsetting table indices
Information published.
> CVE-2026-31523 nvme-pci: ensure we're polling a polled queue
Information published.
> Pass the key, passwords have passed their sell-by date
NCSC passes judgment: passkeys pass muster, passwords fail The UK's National Cyber Security Centre (NCSC) has officially endorsed passkeys as the default authentication standard, marking the first time the agency has told consumers to move away from passwords entirely.…
> CVE-2026-31462 drm/amdgpu: prevent immediate PASID reuse case
Information published.
> CVE-2026-31504 net: fix fanout UAF in packet_release() via NETDEV_UP race
Information published.
> Roblox clamps down on chats and age checks as legal pressure builds
Roblox is paying millions to settle child safety claims while rolling out strict age checks and chat limits that could reshape how kids use the platform.
> CVE-2026-31458 mm/damon/sysfs: check contexts->nr before accessing contexts_arr[0]
Information published.
> CVE-2026-31506 net: bcmasp: fix double free of WoL irq
Information published.
> Microsoft Graph API misused by new GoGra Linux malware for hidden communication
A new GoGra Linux malware uses Microsoft Graph API and an Outlook inbox to deliver payloads, making it stealthy and hard to detect. A new Linux version of the GoGra backdoor uses Microsoft’s Graph API and an Outlook inbox to deliver malicious payloads stealthily. The malware is linked to the Harvest...
> CVE-2026-31527 driver core: platform: use generic driver_override infrastructure
Information published.
> CVE-2026-31452 ext4: convert inline data to extents when truncate exceeds inline size
Information published.
> Every Employee is Getting an AI Assistant, But Is Security Infrastructure Ready?
2 min readThere’s a conversation happening inside almost every enterprise right now. Leadership has decided that AI agents are going to change how the organization works. Claude for Work licenses are being purchased. Rollouts are being planned. Employees are being told that their personal AI assis...
> CVE-2026-31455 xfs: stop reclaim before pushing AIL during unmount
Information published.
> CVE-2026-31476 ksmbd: do not expire session on binding failure
Information published.
> USN-8202-1: jq vulnerabilities
It was discovered that jq did not correctly handle certain string concatenations. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue was addressed in Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and...
> CVE-2026-31488 drm/amd/display: Do not skip unrelated mode changes in DSC validation
Information published.
> CVE-2026-31516 xfrm: prevent policy_hthresh.work from racing with netns teardown
Information published.