[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> CVE-2026-69345 Microsoft Standard XPS Information Disclosure Vulnerability
Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.
> CVE-2026-69347 Windows Fast FAT Driver Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.
> Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours. Google Threat Intellig...
> CVE-2026-69338 Remote Desktop Gateway Service Elevation of Privilege Vulnerability
Use after free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges over a network.
> CVE-2026-69339 Windows MIDI Service Module Information Disclosure Vulnerability
Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information locally.
> Threat actors are giving AI agents a bigger role in cyberattacks
AI agents are automating parts of cyberattacks with less human involvement, including vulnerability scanning, credential harvesting, and troubleshooting, according to Google Threat Intelligence Group’s Q3 2026 AI Threat Tracker. (Source: Google) The report draws on Mandiant incident response engagem...
> CVE-2026-69333 Windows Win32k Elevation of Privilege Vulnerability
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
> CVE-2026-69337 Windows Registry Elevation of Privilege Vulnerability
Double free in Windows Registry allows an authorized attacker to elevate privileges over a network.
> Mars Security brings threat intelligence to detection in real time
Mars Security has announced Real-Time Intel-Based Detection, a capability that turns newly published threat intelligence into validated, ready-to-deploy detection rules within minutes of release. Built by former offensive operators, the new capability converts advisories from CISA, Mandiant, and oth...
> CVE-2026-69366 Windows Kernel Elevation of Privilege Vulnerability
Use after free in Windows Kernel allows an authorized attacker to elevate privileges over a network.
> CVE-2026-69310 Windows DNS Elevation of Privilege Vulnerability
Use after free in Windows DNS allows an authorized attacker to elevate privileges locally.
> “Zero-click” WeChat worm could hijack accounts and spread via a single call
Researchers with security company Calif have discovered, weaponized, and privately reported to Tencent a critical vulnerability that allowed them to create “WeWorm”, a worm that spreads via WeChat calls without any user interaction. During its rampage, the WeWorm compromises the WeChat account of ea...
> CVE-2026-69336 Microsoft Standard XPS Elevation of Privilege Vulnerability
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.
> CVE-2026-69325 Microsoft JScript Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft JScript allows an unauthorized attacker to execute code over a network.
> Adobe fixes critical Magento zero-day exploited to backdoor servers
Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. [...]
> CVE-2026-69296 Windows Device Association Service Elevation of Privilege Vulnerability
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges over a network.
> CVE-2026-69279 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
> BigBear phishing crew nets thousands of Microsoft 365 credentials
Researchers got inside the crooks' admin panel and found 5,137 stolen records tied to 461 organizations
> CVE-2026-69307 Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
> CVE-2026-69292 Remote Desktop Gateway Service Elevation of Privilege Vulnerability
Double free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges locally.