[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> The hidden risks of shadow AI
Understanding why staff use unapproved AI tools is key to managing the security challenges they can create.
> Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
The StyleSmuggler zero-day allows attackers to execute code and deploy a stealthy backdoor on Adobe Commerce and Magento stores. The post Adobe Commerce Zero-Day Exploited to Backdoor Online Stores appeared first on SecurityWeek.
> N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)
N-able released an emergency hotfix for CVE-2026-86218, a remote code execution (RCE) flaw affecting N-central, its remote monitoring and management (RMM) solution popular with managed service providers (MSPs). In its release notes, N-able described CVE-2026-86218 as a “critical-CVSS-rated vulnerabi...
> Back-to-back N-able bugs send admins on a patching spree
A max-severity zero-day bug could be affecting cybersecurity firm N-able’s N-central remote monitoring and management platform, the company said, even as administrators were applying a hotfix for two vulnerabilities disclosed just a day earlier. The latest flaw, tracked as...
> Berlin investigates new data leak after hackers publish stolen login credentials
Another trove of data from Berlin's government has appeared online, authorities said. Germany's information security agency separately warned about the Rhysida cybercrime group.
> Your Cloud Security Checklist Doesn't Work the Way You Think It Does
If managing security across multiple cloud providers wasn't hard enough, each one fails in a different way. For the 2026 Cloud Security Index, Intruder analyzed misconfiguration data from 3,000 organizations across AWS, Azure, and Google Cloud and found that risk profiles across providers have almos...
> Modified ScreenConnect Clients Used in Worm-Like Campaign
The attacks rely on backdoored ScreenConnect instances to transfer and execute payloads to newly connected clients. The post Modified ScreenConnect Clients Used in Worm-Like Campaign appeared first on SecurityWeek.
> VMware Workstation et Fusion : deux failles permettent de s’évader d’une VM vers l’hôte
Broadcom a corrigé deux failles dans VMware Workstation et Fusion 25H2 et 26H1, dont la CVE-2026-59346 notée 9.3, qui permet d'exécuter du code sur l'hôte. Le post VMware Workstation et Fusion : deux failles permettent de s’évader d’une VM vers l’hôte a été publié sur IT-Connect.
> Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. According to Huntress, three unrelated incidents have been found to use diverse initial access me...
> Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released
A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed reports of exploitation in t...
> Flirty OnlyFans promoters on X may be using AI to appear human
Personalized replies and voice notes make it increasingly difficult to tell whether you’re talking to a human, chatbot, or AI agent.
> Automobile Camouflage to Hide from Flock Cameras
Not sure it’s practical, but it’s certainly striking.
> Welsh environment regulator's FoI blunder exposes diversity data of 2,000 staff
NRW says it has found no evidence data was misused after spreadsheet published in error five years ago
> North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters
Sekoia and Kudelski Security have observed that North Korea's Lazarus umbrella is split into six distinct clusters, focused on espionage, financial theft and sanctions evasion
> Ubuntu MiniUPnPd Important Integer Underflow Denial Of Service Vuln 8731-1
MiniUPnPd could be made to crash or expose sensitive information if it received specially crafted network traffic.
> Ubuntu 24.04 LTS Minetest Important Sandbox Bypass CVE-2026-41196
Minetest could be made to crash or run programs if it received specially crafted network traffic from an authenticated user.
> Project Zenith : Microsoft dévoile un Windows 11 spécial pour le code et l’IA
Microsoft a dévoilé Project Zenith, un Windows 11 clé en main où tout est prêt pour les développeurs. Mais attention au prérequis : 64 Go de mémoire unifiée. Le post Project Zenith : Microsoft dévoile un Windows 11 spécial pour le code et l’IA a été publié sur IT-Connect.
> Brave affirme charger les pages 20 % plus vite que Chrome, Edge et Firefox
Brave a publié des benchmarks face à Chrome, Edge et Firefox sur ordinateur : 44 % de CPU en moins, pages chargées 20 % plus vite, mais attention au LCP. Le post Brave affirme charger les pages 20 % plus vite que Chrome, Edge et Firefox a été publié sur IT-Connect.
> ChatGPT can now connect to your personal apps to mimic writing style
OpenAI appears to be testing a new "Writing Style" feature for ChatGPT that can learn how you write by looking at examples from your connected apps. [...]
> Exchange Online va bloquer les e-mails des serveurs Exchange 2016 et 2019 non mis Ă  jour
Dès mi-septembre 2026, Exchange Online va limiter puis bloquer les e-mails des serveurs Exchange 2016 et 2019 sans le patch d'octobre 2025. Voici quoi faire. Le post Exchange Online va bloquer les e-mails des serveurs Exchange 2016 et 2019 non mis à jour a été publié sur IT-Connect.