Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on.
Elsewhere, a trusted software sour...
Attackers are exploiting a chain of RouterOS vulnerabilities to hijack MikroTik devices with SSH open to the internet, CERT Polska found. CERT Polska, Poland’s national CSIRT team, have discovered six vulnerabilities in RouterOS and coordinated their disclosure with MikroTik. Among the six, two comb...
NCSC warns unapproved AI tools can expose corporate data and create new security risks
It was discovered that PHP incorrectly handled Apache map decoding in SOAP
servers with a typemap configured. A remote attacker could use this issue
to cause a NULL pointer dereference, resulting in a denial of service.
(CVE-2026-7262)
It was discovered that PHP incorrectly handled signed integer o...
Chaotic Eclipse released GreenSection, a PoC exploit for an Nvidia GreenSection Memory Corruption Zero-Day Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Nvidia. The researcher named the exploit Gree...
Testing found that LG smart TVs can track viewing and scan home networks, while security flaws could let attackers record conversations.
Self-described white hats promise to return 'most' of the 4,000 BTC once the vulnerability is fixed
Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after breaching its Metabase internal reporting system. [...]
La nouvelle faille zero-day FalconFlank donne les privilèges SYSTEM sur Windows en détournant la remédiation des macros Office de CrowdStrike Falcon.
Le post FalconFlank : une faille zero-day dans CrowdStrike Falcon menace Windows a été publié sur IT-Connect.
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
Anniversaire Geekom : le mini PC IT13 Max (Core Ultra 9 185H, 24 Go, 500 Go) passe à 649 € au lieu de 799 € avec le code réservé aux lecteurs d'IT-Connect.
Le post Bon plan : le mini-PC Geekom IT13 Max a le droit à 150 euros de réduction immédiate a été publié sur IT-Connect.
The vulnerability, CVE-2026-86218, was allocated a maximum-severity rating by the software provider itself
Michał Majchrowicz and Marcin Wyczechowski discovered that Gzip's gzexe
utility created temporary files in an insecure manner when mktemp was
unavailable. A local attacker could possibly use this issue to overwrite
arbitrary files. (CVE-2026-41991)
Elias Hasas, Michał Majchrowicz and Marcin Wyczech...
Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S. customers. [...]
The proof-of-concept (PoC) exploits lead to privilege escalation, spawning a shell with System privileges.
The post Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits appeared first on SecurityWeek.
OpenAI’s rollout of its GPT-6 Astra model ran into early access issues after paying ChatGPT users were unable to use the system shortly after launch, prompting CEO Sam Altman to apologize and say the release had been “messy.”
“First, sorry for the messy rollout,” OpenAI CEO...
The stealthy toolkit embeds a backdoor in HAProxy and targets automotive and media organizations in South Korea for long-term surveillance.
The post North Korean Hackers Deploy New Linux Espionage Toolkit appeared first on SecurityWeek.
OpenAI agents made 15,000–18,000 autonomous edits to a German wiki over three months, evading moderation and echoing tactics seen in the Hugging Face breach.
The post OpenAI Agents Hijack Another Victim Website appeared first on SecurityWeek.
The ransomware group’s published dataset reportedly includes Berlin state employee data, as well as highly sensitive emergency plans