[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> CVE-2026-68781 Microsoft SQL Server Information Disclosure Vulnerability
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
> CVE-2026-67633 Microsoft SQL Server Denial of Service Vulnerability
Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network.
> Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours. Google Threat Intellig...
> CVE-2026-67631 Microsoft SQL Server Remote Code Execution Vulnerability
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
> CVE-2026-67630 Microsoft SQL Server Information Disclosure Vulnerability
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
> Threat actors are giving AI agents a bigger role in cyberattacks
AI agents are automating parts of cyberattacks with less human involvement, including vulnerability scanning, credential harvesting, and troubleshooting, according to Google Threat Intelligence Group’s Q3 2026 AI Threat Tracker. (Source: Google) The report draws on Mandiant incident response engagem...
> CVE-2026-67629 Microsoft SQL Server Information Disclosure Vulnerability
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
> CVE-2026-67373 Microsoft SQL Server Remote Code Execution Vulnerability
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
> Mars Security brings threat intelligence to detection in real time
Mars Security has announced Real-Time Intel-Based Detection, a capability that turns newly published threat intelligence into validated, ready-to-deploy detection rules within minutes of release. Built by former offensive operators, the new capability converts advisories from CISA, Mandiant, and oth...
> CVE-2026-67370 Microsoft SQL Server Elevation of Privilege Vulnerability
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
> CVE-2026-67368 Microsoft SQL Server Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network.
> “Zero-click” WeChat worm could hijack accounts and spread via a single call
Researchers with security company Calif have discovered, weaponized, and privately reported to Tencent a critical vulnerability that allowed them to create “WeWorm”, a worm that spreads via WeChat calls without any user interaction. During its rampage, the WeWorm compromises the WeChat account of ea...
> CVE-2026-50349 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
> CVE-2026-55007 Microsoft Exchange Server Remote Code Execution Vulnerability
Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
> Adobe fixes critical Magento zero-day exploited to backdoor servers
Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. [...]
> CVE-2026-62801 Microsoft PowerShell Security Feature Bypass Vulnerability
Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthorized attacker to bypass a security feature over a network.
> CVE-2026-57098 Microsoft Remote Desktop App for Windows Information Disclosure Vulnerability
Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network.
> BigBear phishing crew nets thousands of Microsoft 365 credentials
Researchers got inside the crooks' admin panel and found 5,137 stolen records tied to 461 organizations
> CVE-2026-77482 Microsoft SQL Server Remote Code Execution Vulnerability
Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
> CVE-2026-85360 Windows Kernel Elevation of Privilege Vulnerability
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.