[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (12 articles)

|

// AI-powered summary generated at 08:00

> Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'fundi...
> US, Britain to coordinate on scam center takedowns
The U.S. Department of Justice and the U.K.'s National Crime Agency and Crown Prosecutor signed a memorandum to cooperate on cases involving Southeast Asian scam operations.
> Critical Citrix NetScaler auth bypass now leveraged in attacks
Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian. [...]
> PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution
PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logical decoding was introduc...
> Deux suspects interpellés après le piratage du fisc
Deux suspects arrêtés après les attaques de ZeroBytes contre le fisc, tandis que l’enquête cyber se poursuit.
> New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug strings left in the bin...
> UK account-hack losses surge as new reporting system exposes hidden cases
In its first annual assessment, published Friday, the City of London Police said victims reported losing ÂŁ6.3 million ($8.5 million) to account hacks in the year ending March 31, up from ÂŁ1.2 million ($1.6 million) a year earlier.
> Microsoft says some users can’t open the Teams desktop client
Microsoft is working to resolve a known issue that causes delays or blocks some users from opening the Microsoft Teams desktop client on Windows systems. [...]
> Hacking the Boeing 737: inside the Bus Driver attack | Kaspersky official blog
Researchers have found a way to hack Boeing 737 systems with a device that costs less than US$100. Here’s how the Bus Driver attack works, and how realistic a threat it actually is.
> 39 New Methods That Compromise Passkey Authentication
Passkeys eliminate many password-based attacks, but researchers have documented 39 methods for compromising authentication built around them. Token explains how attackers can abuse authentication prompts, synced credentials, enrollment, recovery, and other trust boundaries without breaking FIDO2 cry...
> FBI investigates breach of 153 million driving license records at IDscan.net
Drivers in North America received a nasty shock this week when it was revealed that digital scans of 153 million drivers’ licenses were for sale on the dark web. Among the victims were US Defense Secretary Pete Hegseth – and investigative reporter Brian Krebs, who has dug deep...
> PostgreSQL Hit by 12-Year-Old Vulnerability Allowing Server Takeover
PostGREShell (CVE-2026-6471) is a 12-year-old PostgreSQL flaw that lets low-privileged attackers execute code and take over servers. Cyera researchers found a severe PostgreSQL vulnerability, dubbed PostGREShell and tracked as CVE-2026-6471 (CVSS score of 7.2). Present in releases dating back to 201...
> Russian data centers face new security requirements amid Ukraine's drone threats
Russia's data centers are concentrated in areas increasingly exposed to Ukrainian drone attacks. The Kremlin wants them to stiffen their physical defenses.
> Bidding war for defunct Spirit Airlines’ employee data will not die
The destiny of Spirit Airline’s data is still undecided, months after the company sought bankruptcy protection. AI data company Micro1 has now offered $12.5 million to acquire a trove of the company’s emails, Teams chats, operations and employee productivity data, according...
> Sangoma Switchvox Vulnerabilities Exploited in the Wild
Tracked as CVE-2026-9586, the unauthenticated SQL injection flaw can be exploited remotely for arbitrary code execution. The post Sangoma Switchvox Vulnerabilities Exploited in the Wild appeared first on SecurityWeek.
> Synology : APM 2.0 s’ouvre à de nouvelles plateformes dont Proxmox et Nutanix
Synology dévoile ActiveProtect Manager 2.0 : sauvegarde d'Amazon EC2, Azure VM, Proxmox VE, Nutanix AHV et Google Workspace, et restauration cloud à cloud. Le post Synology : APM 2.0 s’ouvre à de nouvelles plateformes dont Proxmox et Nutanix a été publié sur IT-Connect.
> New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges
An anonymous security researcher who uses the "Nightmare Eclipse" handle released a CrowdStrike Falcon zero-day exploit named "FalconFlank" that lets attackers escalate privileges on up-to-date Windows systems. [...]
> US military disabled ad tracking on troops’ devices following reports of targeted attacks
A senator's letter confirms the U.S. military moved to prevent the tracking after foreign adversaries used location data to target troops.
> OpenAI a publié une version bridée de GPT-6 Astra, ce modèle redoutable en cyber
OpenAI dévoile GPT-6 Astra : 100 % sur ExploitBench, deux zero-day découvertes en test, mais la version publique est volontairement bridée et c'est tant mieux. Le post OpenAI a publié une version bridée de GPT-6 Astra, ce modèle redoutable en cyber a été publié sur IT-Connect.
> G7 urges organizations to prepare for quantum cyber threats
In a joint advisory released Thursday, the G7 Cyber Security Working Group and the U.S. Cybersecurity and Infrastructure Security Agency, CISA, said organizations should begin moving to post-quantum cryptography now.