[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (36 articles)

|

// AI-powered summary generated at 12:01

> Zero trust has a big AI agent problem ahead
Despite singing the praises of zero trust for many years, many CISOs have struggled to implement the framework in full. And now comes what could be the final nail: agentic AI.  Can zero trust coexist with autonomous agents in typical enterprise environments? Technically, ye...
> 2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators
2,000 leaked files expose Bauman University’s hidden Department No. 4, which trained GRU-linked hackers and propagandists linked to APT28 and Sandworm. Leaked Documents Expose Bauman University’s Hidden Department That Trained Hackers, Propagandists, and Malware Developers for the GRU More than 2,00...
> CRA Reporting – What you need to know
While the full implementation of the Cyber Resilience Act (CRA) won’t take effect until December 2027, another critical milestone is already approaching much sooner. Starting from 11 September 2026, all manufacturers selling products with digital elements in countries of the European Union will be r...
> Your AI agent’s system prompt is not a security control
An AI agent told in its system prompt to show a user only what that user is cleared to see will hand over more the moment someone talks it into doing so. Gee Rittenhouse, who oversees Security Hub, GuardDuty, and Inspector at AWS, and Eric Johnson, a fellow at the SANS Institute, put the fix one lay...
> Seemplicity Response Options accelerates vulnerability mitigation
Seemplicity announced Response Options for vulnerability management and exposure management workflows. This new capability gives security teams multiple, actionable paths to closing a vulnerability finding based on context. The problem Response Options addresses is straightforward: the complete fix...
> Windows 11 : quel outil de récupération pour quel scénario de panne ? Voici l’avis de Microsoft
Quick Machine Recovery, Point-in-time restore, Cloud rebuild, etc. Quel outil utiliser en fonction de telle ou telle panne Windows ? Voici l'avis de Microsoft. Le post Windows 11 : quel outil de récupération pour quel scénario de panne ? Voici l’avis de Microsoft a été publié sur IT-Connect.
> Terminated employee cost company hundreds of thousands of dollars because nobody revoked access
They had more access than the average Joe, and IT didn't track what needed to be cut off
> To keep the AI hacking genie bottled up, try one-way networks
Sandboxes, permissions, and VMs aren't enough to keep frontier models at bay. "Data diodes" might do the job
> Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a privilege escalation flaw impacting Crowdstrike Falcon. "FalconFlank is a 0day privilege escalation that abuses the office malicious macros...
> Oracle Linux 9 Nodejs Security Advisory ELSA-2026-61383 Critical CVEs
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
> Oracle Linux 9 nodejs Important Security Patch ELSA-2026-61386-0
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
> Your threat feed is someone else’s database: What ingesting malware intel at scale takes
The advice is to consume shared threat intelligence. Join the ISAC. Wire the community feeds into your pipeline. This looks like a fine advice and I agree to it. What nobody mentions you is the operating manual, because the access was never the hard part. A threat feed is someone else’s database. So...
> Oracle Linux 9 iperf3 Important JSON Value Check Fix ELSA-2026-61389-0
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
> Oracle Linux 9 gimp Important Fixes for Vulnerabilities ELSA-2026-61587-0
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
> Microsoft 365 : le Hero Link va remplacer vos liens de partage SharePoint et OneDrive
Microsoft va déployer les Hero Link sur SharePoint et OneDrive : un seul lien de partage par fichier, modifiable après envoi. Ce que vous devez savoir. Le post Microsoft 365 : le Hero Link va remplacer vos liens de partage SharePoint et OneDrive a été publié sur IT-Connect.
> Oracle Linux 9 wget Moderate Buffer Overflow Fix ELSA-2026-62143-0
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
> CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers' crosshairs. The vulnerabilities are as follows - CVE-2026-83548 (CVSS score: 10.0) - A server-side reques...
> When AI quietly breaks things, who pays?
David Halbreich, an insurance recovery partner at Reed Smith, breaks down how AI companies should handle coverage gaps that come up as the industry grows. He covers straddle claims that fall between tail and go-forward D&O policies after a merger, how governance disclosures in applications can t...
> 153 millions de permis de conduire en vente sur le dark web : IDScan dans le viseur
Un service du dark web vend les scans de plus de 153 millions de permis de conduire américains et canadiens : le FBI enquête sur le prestataire IDScan. Le post 153 millions de permis de conduire en vente sur le dark web : IDScan dans le viseur a été publié sur IT-Connect.
> Pentest et IA : le dilemme de la souveraineté face à l’industrialisation des attaques
Construire son agent d'audit : avantages, risques et cadres (MITRE ATLAS, OWASP) pour garder maîtrise et traçabilité. Quand l'IA rencontre le pentest. Le post Pentest et IA : le dilemme de la souveraineté face à l’industrialisation des attaques a été publié sur IT-Connect.