[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (12 articles)

|

// AI-powered summary generated at 08:00

> Incident response guide for AWS CloudTrail investigations – Part 2
In Part 1 of this guide, we examined two common incident scenarios: cross-account Amazon Simple Storage Service (Amazon S3) data deletion with ransomware implications, and cryptocurrency mining deployed through AWS CloudFormation using exposed AWS Management Console credentials. We also introduced k...
> Introducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak models
Use production traffic and security signals to prioritize findings, prepare edge mitigations when safe, and propose code patches. By combining WAF data with OpenAI Daybreak models, Vulnerability Discovery and Remediation helps teams identify and patch the most critical threats first.
> Pegasus and NoviSpy Used Against Serbian Protesters
Serbian activists were targeted with zero-click Pegasus and NoviSpy spyware, exposing a major surveillance campaign ahead of elections. A member of Serbia’s student protest movement had their iPhone infected with NSO Group‘s Pegasus spyware without ever clicking a link or opening a file. The Citizen...
> Coder's registry infrastructure compromised to push malicious modules
Attackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code. [...]
> Cisco Fixed Critical RCE in Nexus 9000 Series Switches
Cisco patched a critical Nexus 9000 vulnerability, CVE-2026-20212, allowing unauthenticated remote root code execution. Cisco has released patches for a critical flaw, tracked as tracked as CVE-2026-20212 (CVSS score of 9.8) in 10 Silicon One-based Nexus 9000 switches. The vulnerability could let an...
> Large group of Serbian opposition, activist figures targeted with spyware
At least 14 Serbians have been targeted with advanced spyware since December, with victims including a member of Parliament, a local opposition politician and student protesters, according to digital forensic researchers.
> The G7 tells industry to hurry up and prep for post-quantum encryption
The nations warn that governments and industry can no longer treat quantum codebreaking as a distant or theoretical possibility. The post The G7 tells industry to hurry up and prep for post-quantum encryption appeared first on CyberScoop.
> Ubuntu 26.04 LTS rabbitmq-c Important Security Updates and Vulnerabilities
Several security issues were fixed in rabbitmq-c.
> Court Rules Against Citizen Journalists in DMCA Takedown Case—EFF Will Appeal
A federal court in Massachusetts has ruled that copyright holders can issue online takedown notices based on a subjective belief of copyright infringement, even when that belief is unreasonable and self-serving. The case was brought by our client, Channel 781 News, after takedown notices temporarily...
> Abliteration.ai is making a business out of removing AI guardrails
Abliteration.AI is making powerful AI models without guardrails easier to access, arguing that giving defenders the same tools as bad actors could ultimately improve cybersecurity.
> Attackers Actively Exploiting Critical Vulnerability in Super Forms Plugin
On July 9th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Super Forms, a WordPress plugin with an estimated 13,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoor...
> HPE patches critical ArubaOS-CX remote code execution flaw
Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution. [...]
> Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC
A shared security 'Nightmare'
> ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories
The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone might open the door? That idea runs through this edition. Attackers use real tools, fake login pages, old account links, and software guides th...
> The story behind the intelligence
From engaging with cybercriminals to surviving a live Flamin’ Hot Cheetos taste test, Hazel reflects on the latest Beers with Talos with Azim, where they cover the full spectrum of what it takes to gather threat intel.
> Chainalysis Supports HyperEVM with Automatic Token Support
Chainalysis is excited to announce support for HyperEVM, the Ethereum-compatible smart contract environment on the Hyperliquid Layer 1. It enables
 The post Chainalysis Supports HyperEVM with Automatic Token Support appeared first on Chainalysis.
> Debian Chromium Critical Remote Code Execution Denial of Service Advisory
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the stable distribution (trixie), these problems have been fixed in version 152.0.7977.75-1~deb13u1.
> UODO - autorité polonaise
L'Autorité polonaise de protection des données (UODO) organise une conférence d'experts consacrée aux défis juridiques posés par l'intelligence artificielle.Cette troisiÚme rencontre du cycle des "Conférences d'experts ouvertes" se tiendra le 11 septembre 2026 au siÚge de l'autorité à Varsovie. Elle...
> IMY - autorité suédoise
L'Autorité suédoise de protection de la vie privée (IMY) a annoncé qu'elle accompagnera deux projets d'intelligence artificielle dans le cadre de son "bac à sable de l'innovation" afin de garantir leur conformité en matiÚre de protection des données.Le premier projet, mené par la municipalité de Lun...
> StreamRat Android malware spreads through Meta and TikTok ads
Social media ads for a free streaming service exposed roughly 570,000 people to StreamRat, a banking Trojan that can take control of infected phones.