[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (12 articles)

|

// AI-powered summary generated at 08:00

> Ubuntu FFmpeg Major Vulnerabilities in Code Execution and DoS USN-8716-1
FFmpeg could be made to crash or run programs as your login if it opened a specially crafted file.
> Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal
Hacker group published roughly 550GB of data after MAG reportedly refused to pay a ransom demand; the group says it gained access via exposed admin keys. The post Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal appeared first on SecurityWeek.
> BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts. "Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empow...
> Pegasus Zero-Click Exploit Infects Serbian Student Activist's iPhone
Pegasus infected a Serbian student activist's iPhone through an iMessage zero-click exploit
> Microsoft: KB5120998 mouse reset bug affects only non-English PCs
Microsoft says a known issue that reverts mouse settings after installing the KB5120998 August 2026 preview update affects only non-English Windows 11 systems. [...]
> Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents
New models, trained using NVIDIA Nemotron 3 Ultra, aim to catch rogue agent behavior before it executes, without the latency of large-model review. The post Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents appeared first on SecurityWeek.
> OpenAI confirms ChatGPT is down ahead of 'Astra' model launch
ChatGPT and Codex are experiencing a major outage, with users reporting errors across nearly every major ChatGPT feature. [...]
> Anthropic confirms Claude is down, multiple models affected
Claude is experiencing an outage, with users encountering elevated errors when sending requests to multiple Anthropic AI models. [...]
> Drowning in CVEs and thirsty for answers? Try CTEM
Boards want to know if they're less exposed than last quarter. Patching metrics aren't the solution
> Critical Elementor Pro flaw exploited to take over WordPress sites
A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server. [...]
> Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
Thomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. West Publishing said it di...
> Kerberoasting dans Active Directory : fonctionnement et stratégies de défense
Le Kerberoasting figure parmi les techniques post-compromission les plus efficaces contre les environnements Active Directory. Explication.
> Ubuntu 26.04 SPICE vdagent Important Denial of Service Issues USN-8723-1
Several security issues were fixed in SPICE vdagent.
> Ubuntu 26.04 libssh2 Important Remote Exec DoS Issues USN-8722-1
Several security issues were fixed in libssh2.
> CVE-2026-62916 Microsoft Entra ID Elevation of Privilege Vulnerability
Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
> Ubuntu Openssh Security Advisory USN-8721-1 Critical Remote Access Threats
Several security issues were fixed in OpenSSH.
> CVE-2026-65818 Power Automate Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.
> CVE-2026-69857 Azure Cosmos DB Spoofing Vulnerability
Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network.
> Outsider Phishing Kit Survives Takedown With 700 New Pages
Outsider phishing kit generated 700 new pages after a Google-led disruption
> CVE-2026-83711 Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability
Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.