[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (12 articles)

|

// AI-powered summary generated at 08:00

> CVE-2026-70352 Azure AI Language Elevation of Privilege Vulnerability
Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.
> CVE-2026-70178 Microsoft Fabric Elevation of Privilege Vulnerability
Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
> Outsider Phishing Kit Survives Takedown With 700 New Pages
Outsider phishing kit generated 700 new pages after a Google-led disruption
> CVE-2026-62906 Microsoft Discovery Studio Information Disclosure Vulnerability
Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network.
> Thomson Reuters reveals breach that exposed U.S. and Canadian court records
Thomson Reuters has disclosed a data breach affecting C-Track, a court case management platform operated by its subsidiaries, exposing court records and sensitive personal information across courts in at least 12 US states, the US Virgin Islands, and Canada. The company published the disclosure publ...
> Your Employee’s Password Appeared in an Infostealer Log. Now What?
Infostealers can expose far more than passwords, including authenticated sessions that may let attackers bypass MFA. Flare explains how defenders can prioritize compromised identities, determine whether stolen access is still usable, and respond before it leads to account takeover. [...]
> Ils sont lĂ Ă Ă Ă Ă  : les arnaques aux colis reviennent
Arnaques aux colis, images IA et faux messages : les indices concrets pour repérer un piège avant de cliquer.
> Google’s Gemini 3.8 Flash takes on bigger AI models at a lower cost
Google has introduced Gemini 3.8 Flash, available to developers today, and a gated sibling, Gemini 3.8 Flash Cyber, reserved for vetted security teams. “Our 3rd Flash release in just 6 wks,” Google CEO Sundar Pichai said on X, adding that it makes sizable gains over 3.7 Flash in software engineering...
> Ubuntu 26.04 LTS GnuPG Important Message Integrity Bypass CVE-2026-57062
GnuPG could allow encrypted messages to be forged under certain circumstances.
> 412,000 The Town 2025 Ticket Buyers’ Data Hits the Dark Web
412,000 The Town 2025 festival buyer records are being sold for $10,000, with Brazil’s data openly marketed for bank fraud, loans and SIM registration. A seller on a Russian-language data-trading forum listed what they’re calling a Ticketmaster database on September 2, claiming over 412,000 Latin Am...
> Take-Two resserre son enquĂŞte sur les fuites de GTA VI
CYBERLEEK menace GTA VI et publie un manifeste visant les pratiques commerciales des grands éditeurs de jeux vidéo.
> FBI Seizes $560K in Crypto From Hamas Fundraising Network
Summary The U.S. Justice Department has seized $560,000 in cryptocurrency from Hamas-linked fundraising campaigns and shut down elements of the… The post FBI Seizes $560K in Crypto From Hamas Fundraising Network appeared first on Chainalysis.
> “The Skills And Resilience To Do One Of The Hardest Jobs In Policing” — Why This DFIR Recruitment Language Gets The Evidence Wrong
Does recruiting for “resilience” risk putting responsibility in the wrong place? Paul Gullon-Scott looks at what the evidence says about digital forensic well-being, workload and organisational support, and why the language we use matters.
> CREST Onboards First Cohort for AI-Enabled Pentesting Accreditation
CREST’s new AI-enabled penetration testing accreditation welcomes its first 10 providers
> USN-8720-1: GnuPG vulnerability
It was discovered that GnuPG incorrectly validated authentication tag lengths when parsing CMS messages encrypted with AES-GCM. An attacker could possibly use this issue to bypass message integrity checks.
> Cybercrooks trawl Fishbrain to net password hashes
Armed with password hashes and salts, attackers could already be kraken those creds
> USN-8723-1: SPICE vdagent vulnerabilities
It was discovered that SPICE vdagent had an integer overflow in the buffer size calculation used when writing to the daemon socket. A malicious or compromised SPICE host could possibly use this issue to cause SPICE vdagent to crash, resulting in a denial of service. (CVE-2026-57965) It was discover...
> USN-8722-1: libssh2 vulnerabilities
It was discovered that libssh2 incorrectly handled certain SFTP server responses. A remote attacker controlling an SSH server could use this issue to cause libssh2 to crash or possibly execute arbitrary code. (CVE-2026-66032) It was discovered that libssh2 incorrectly handled AES-GCM cipher negotia...
> HiddenLayer Raises $100 Million for AI Runtime Security
The Austin-based company will invest in agentic runtime security capabilities to secure AI coding agents. The post HiddenLayer Raises $100 Million for AI Runtime Security appeared first on SecurityWeek.
> USN-8719-1: APR-util vulnerabilities
It was discovered that APR-util incorrectly performed password hash comparisons in a way that was not constant-time. An attacker could possibly use this issue to obtain sensitive information. (CVE-2025-49506) It was discovered that APR-util incorrectly handled recursive XML element quoting. An atta...