[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on. Elsewhere, a trusted software sour...
> Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication
Attackers are exploiting a chain of RouterOS vulnerabilities to hijack MikroTik devices with SSH open to the internet, CERT Polska found. CERT Polska, Poland’s national CSIRT team, have discovered six vulnerabilities in RouterOS and coordinated their disclosure with MikroTik. Among the six, two comb...
> NCSC Warns Shadow AI Creates New Security Risks
NCSC warns unapproved AI tools can expose corporate data and create new security risks
> USN-8734-1: PHP vulnerabilities
It was discovered that PHP incorrectly handled Apache map decoding in SOAP servers with a typemap configured. A remote attacker could use this issue to cause a NULL pointer dereference, resulting in a denial of service. (CVE-2026-7262) It was discovered that PHP incorrectly handled signed integer o...
> Chaotic Eclipse Released A PoC For NVIDIA GreenSection Memory Corruption Zero-Day
Chaotic Eclipse released GreenSection, a PoC exploit for an Nvidia GreenSection Memory Corruption Zero-Day Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Nvidia. The researcher named the exploit Gree...
> LG TV flaws could let attackers listen in, even in standby mode
Testing found that LG smart TVs can track viewing and scan home networks, while security flaws could let attackers record conversations.
> Hackers drain $320M in Bitcoin from Liquid Network, claim they're the good guys
Self-described white hats promise to return 'most' of the 4,000 BTC once the vulnerability is fixed
> Mathspace discloses data breach affecting over 1 million people
Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after breaching its Metabase internal reporting system. [...]
> FalconFlank : une faille zero-day dans CrowdStrike Falcon menace Windows
La nouvelle faille zero-day FalconFlank donne les privilèges SYSTEM sur Windows en détournant la remédiation des macros Office de CrowdStrike Falcon. Le post FalconFlank : une faille zero-day dans CrowdStrike Falcon menace Windows a été publié sur IT-Connect.
> Oracle Linux 8 ELSA-2026-63163-0 Important Container Tools Security
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
> Oracle Linux 9 Kernel Vulnerabilities Advisory ELSA-2026-500249 Overview
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
> Bon plan : le mini-PC Geekom IT13 Max a le droit à 150 euros de réduction immédiate
Anniversaire Geekom : le mini PC IT13 Max (Core Ultra 9 185H, 24 Go, 500 Go) passe à 649 € au lieu de 799 € avec le code réservé aux lecteurs d'IT-Connect. Le post Bon plan : le mini-PC Geekom IT13 Max a le droit à 150 euros de réduction immédiate a été publié sur IT-Connect.
> N-able Releases Hotfix for Critical Remote Code Execution Vulnerability
The vulnerability, CVE-2026-86218, was allocated a maximum-severity rating by the software provider itself
> USN-8733-1: Gzip vulnerabilities
Michał Majchrowicz and Marcin Wyczechowski discovered that Gzip's gzexe utility created temporary files in an insecure manner when mktemp was unavailable. A local attacker could possibly use this issue to overwrite arbitrary files. (CVE-2026-41991) Elias Hasas, Michał Majchrowicz and Marcin Wyczech...
> Trezor data breach impact now reaches 81,000 customers
Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S. customers. [...]
> Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits
The proof-of-concept (PoC) exploits lead to privilege escalation, spawning a shell with System privileges. The post Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits appeared first on SecurityWeek.
> Sam Altman calls GPT-6 Astra rollout ‘messy’ as enterprise users wait for access
OpenAI’s rollout of its GPT-6 Astra model ran into early access issues after paying ChatGPT users were unable to use the system shortly after launch, prompting CEO Sam Altman to apologize and say the release had been “messy.” “First, sorry for the messy rollout,” OpenAI CEO...
> North Korean Hackers Deploy New Linux Espionage Toolkit
The stealthy toolkit embeds a backdoor in HAProxy and targets automotive and media organizations in South Korea for long-term surveillance. The post North Korean Hackers Deploy New Linux Espionage Toolkit appeared first on SecurityWeek.
> OpenAI Agents Hijack Another Victim Website
OpenAI agents made 15,000–18,000 autonomous edits to a German wiki over three months, evading moderation and echoing tactics seen in the Hugging Face breach. The post OpenAI Agents Hijack Another Victim Website appeared first on SecurityWeek.
> Rhysida Publishes Berlin Government Data After €2m Extortion Demand Refused
The ransomware group’s published dataset reportedly includes Berlin state employee data, as well as highly sensitive emergency plans