[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> Beware the SparroWock: The backdoor that bites, the commands that catch
ESET researchers document SparroWocky, the new flagship backdoor of the FamousSparrow APT group
> Spain reports first data breach involving autonomous AI agent
Spain’s data protection authority (AEPD) has reported its first data breach blamed on an AI agent acting on its own, after the system reportedly logged into a company’s network, found a way to alter personal records, and pulled invoice data. “Before drawing any conclusions, it should be noted that t...
> 16 governance tools for securing your AI fleet
Every DevOps team member knows that dealing with an AI is like being a circus lion tamer. The boss and the audience are happy when the lions sit on the pedestal and roar on cue, but there’s always the danger that they’ll go rogue and bring the whole show to a quick and disastr...
> AI Agent Carries Out Multi-Stage Data Theft Attack
Spanish data protection agency AEPD reveals the country’s first AI-powered data breach
> Microsoft shares workaround for Windows domain login issues
Microsoft shared a temporary fix on Wednesday for a known issue that prevents Windows 11 users from logging in with valid domain credentials after installing the September 2026 security updates. [...]
> BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS
The Internet Systems Consortium (ISC) has released BIND 9.20.29 and 9.21.26 to fix fourteen security flaws it disclosed on 16 September in BIND 9, its open-source DNS server software. One of them affects any BIND server that answers DNS-over-HTTPS (DoH). A sender with no credentials can crash the s...
> Fake AI trading agent steals crypto wallet passwords
Attackers built a website for a fake AI crypto trading agent and used it to install Needle Stealer, malware that replaces a victim’s browser wallet with a copy that sends the wallet password to the attacker. HP caught the campaign between April and June 2026. The Needle campaign targets people who d...
> CISA Releases Guidance on Deploying Cyber Decoys
Complementing Zero Trust models, decoys enable organizations to detect, observe, and block malicious activity in their environments. The post CISA Releases Guidance on Deploying Cyber Decoys appeared first on SecurityWeek.
> AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals
New research from Irregular shows AI agents can retrain and redeploy their own underlying models during routine maintenance tasks. The post AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals appeared first on SecurityWeek.
> Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records
A security breach at Gyazo, Helpfeel's image-sharing service, exposed about 23.62 million user records, including email addresses and password hashes, the Kyoto-based company said in a notice published Wednesday. It also exposed about 490 million image metadata records, mostly for images from Janua...
> Chosen Brick, Iran’s Surveillance Malware
UK, US, and Dutch agencies expose Chosen Brick, Iranian malware used to track and harass dissidents, journalists, and activists via Telegram. The UK, the US, and the Netherlands published a joint advisory warning about a Windows malware family, dubbed Chosen Brick, that Iran’s intelligence services...
> Cisco warns of max severity ISE zero-day exploited in attacks
Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. [...]
> KB5124008 : Microsoft confirme le bug de relation d’approbation et pointe Machine Identity Isolation
Microsoft confirme que la KB5124008 peut casser la relation d'approbation des PC Windows 11 avec l'AD. En cause : Machine Identity Isolation. Voici la solution. Le post KB5124008 : Microsoft confirme le bug de relation d’approbation et pointe Machine Identity Isolation a été publié sur IT-Connect.
> Ubuntu 26.04 Valkey Important TLS Denial of Service CVE-2026-56684
Several security issues were fixed in Valkey.
> Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication. "This vulnerabilit...
> Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day
Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests. The post Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day appeared first on SecurityWeek.
> Riverbed NPM 360 uses AI to predict and prevent network disruptions
Riverbed has announced new Riverbed intelligent network observability solutions that combine 360-degree network visibility with agentic AI to help network operations teams accelerate troubleshooting, identify root causes, predict emerging issues and increasingly prevent disruptions before they impac...
> Tuskira Vector brings autonomous red teaming to attack surface validation
Tuskira has announced Vector, its autonomous red teaming agentic capability, which identifies an organization’s exploitable attack surface by simulating what an attacker can do from outside it. Tuskira validates every external finding against the organization’s deployed compensating controls, the in...
> ESET PSA plugin Service Release 2.6 has been released
ESET PSA plugin Service Release 2.6 is now available after logging into the ESET PSA plugin portal.
> Ni spyware ni faille : comment la police allemande lit les messages WhatsApp, Signal et Telegram ?
En Allemagne, police et douanes lient un appareil au compte WhatsApp, Signal ou Telegram de leurs cibles pour lire leurs messages. Une méthode contestée. Le post Ni spyware ni faille : comment la police allemande lit les messages WhatsApp, Signal et Telegram ? a été publié sur IT-Connect.