[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (36 articles)

|

// AI-powered summary generated at 12:01

> Cybercrooks trawl Fishbrain to net password hashes
Armed with password hashes and salts, attackers could already be kraken those creds
> USN-8723-1: SPICE vdagent vulnerabilities
It was discovered that SPICE vdagent had an integer overflow in the buffer size calculation used when writing to the daemon socket. A malicious or compromised SPICE host could possibly use this issue to cause SPICE vdagent to crash, resulting in a denial of service. (CVE-2026-57965) It was discover...
> USN-8722-1: libssh2 vulnerabilities
It was discovered that libssh2 incorrectly handled certain SFTP server responses. A remote attacker controlling an SSH server could use this issue to cause libssh2 to crash or possibly execute arbitrary code. (CVE-2026-66032) It was discovered that libssh2 incorrectly handled AES-GCM cipher negotia...
> HiddenLayer Raises $100 Million for AI Runtime Security
The Austin-based company will invest in agentic runtime security capabilities to secure AI coding agents. The post HiddenLayer Raises $100 Million for AI Runtime Security appeared first on SecurityWeek.
> USN-8719-1: APR-util vulnerabilities
It was discovered that APR-util incorrectly performed password hash comparisons in a way that was not constant-time. An attacker could possibly use this issue to obtain sensitive information. (CVE-2025-49506) It was discovered that APR-util incorrectly handled recursive XML element quoting. An atta...
> USN-8721-1: OpenSSH vulnerabilities
It was discovered that OpenSSH's ssh-agent incorrectly handled interactions between agent locking and the [email protected] extension. A remote attacker with access to a forwarded agent connection could possibly use this issue to perform operations that should only be available locally, such...
> Microsoft says KB5120998 Windows update resets desktop settings
Microsoft has confirmed that desktop settings are lost or reset on some Windows devices after installing the KB5120998 August 2026 preview update. [...]
> USN-8718-1: SSSD vulnerability
It was discovered that SSSD did not properly validate authentication token lengths when processing PAM responder requests. A local attacker could possibly use this issue to cause SSSD to crash, resulting in a denial of service.
> US and Canadian court data exposed in Thomson Reuters breach
Sealed court information and sensitive personal data were exposed in a breach of a Thomson Reuters records platform affecting courts in at least 12 U.S. states, the U.S. Virgin Islands and Canada.
> US and Canadian Court Records Breached Following Thomson Reuters Incident
Thomson Reuters has disclosed a cyber incident affecting its C-Track court management software, potentially exposing court records in Canada and the US
> AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million
The startup’s firewall evaluates AI skills, plugins and MCP servers for malicious instructions, excessive permissions and software supply chain risks. The post AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million appeared first on SecurityWeek.
> US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries
An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campaign spanning 46 countries. Around 45% of observed activity was associated with the United States, making it the campaign...
> Decade-old PostgreSQL flaw turns backup account into a backdoor
A critical vulnerability in PostgreSQL had remained hidden for more than a decade, potentially turning a routine backup account into a path to full database and server compromise. The issue, dubbed PostGREShell by Cyera Research, exists in the database’s replication functio...
> Belkasoft Named A Major Player In The IDC MarketScape: Worldwide Digital Forensics Platforms 2026 Vendor Assessment
Belkasoft has been named a Major Player in the IDC MarketScape: Worldwide Digital Forensics Platforms 2026 Vendor Assessment – a milestone that reflects the maturity of Belkasoft X and the company’s continued innovation in AI-powered digital forensics.
> Researching Employment Scams
Researchers built a fake company to study fake employee scams.
> Counterfeit installers turn routine software downloads into enterprise breaches
Microsoft has warned that attackers are breaching enterprise systems via counterfeit download sites impersonating software including Microsoft Edge, Kaspersky and Razer, delivering trojanized installers for persistent access. “Once executed, the malicious installers deploy...
> ESET PROTECT Hub version 2.9.0 has been released
ESET PROTECT Hub version 2.9.0 has been released.
> USN-8716-1: FFmpeg vulnerabilities
It was discovered that FFmpeg incorrectly handled certain crafted media files in the VobSub subtitle demuxer. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-64830) It was discovered that FFmpeg incorrectly handled certain crafted DTS audi...
> Plex warns users to patch security vulnerabilities immediately
Plex urged users this week to update their desktop clients and media servers immediately to patch multiple security vulnerabilities. [...]
> USN-8717-1: Apache Tika vulnerability
It was discovered that Apache Tika's ISA-Tab parser incorrectly handled file path resolution. An attacker who could place files in a directory that Tika subsequently parses could use this issue to read arbitrary files accessible to the Tika process and have their contents emitted into the extracte...