[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (85 articles)

|

// AI-powered summary generated at 16:01

> Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another
Forescout Research - Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware. The exploit targets CVE-2021-31886, a s...
> Manchester Airports Group - 8,728,451 breached accounts
In August 2026, Manchester Airports Group (MAG) disclosed a data breach impacting their services. The incident was later claimed by the FulcrumSec hacking group, who subsequently published email addresses and phone numbers relating to 8.7M customers of Manchester, Stansted and East Midlands airports...
> Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials
Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in question is CVE-2026-9586 (CVSS score: 9.3), a critical unauthenticated SQL injection vulnerability in Sangoma...
> Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads
The U.S. Department of Justice (DoJ) on Tuesday announced the takedown of a long-standing peer-to-peer (P2P) botnet known as Sality as part of a coordinated law enforcement operation. The effort was undertaken on August 31, 2026, by authorities from the U.S., Bulgaria, Hungary, and Romania, in coll...
> SonicWall warns of actively exploited SMA1000 zero-day flaws
SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. [...]
> Visa enhances A2A Protect to stop fraud before money leaves the account
Visa announced an enhanced version of A2A Protect, delivering real-time risk insights that help banks stop account-to-account fraud before money leaves customer accounts. The expanded solution introduces a new unified fraud score—Visa’s integration of Featurespace technology—giving financial institu...
> Edge Case launches Guardian, an AI platform for tracking risk across autonomous systems
Edge Case launched Guardian, an AI-driven platform that connects safety analysis, engineering data, and operational signals to give teams a continuous understanding of how system risk evolves. At launch, Guardian will support some of the world’s most advanced autonomous platforms, with six customer...
> DSA : l’Europe place ChatGPT, Reddit et Roblox sous surveillance renforcée
La Commission européenne désigne ChatGPT comme grand moteur de recherche, Reddit et Roblox comme grandes plateformes. Quatre mois pour être conforme au DSA. Le post DSA : l’Europe place ChatGPT, Reddit et Roblox sous surveillance renforcée a été publié sur IT-Connect.
> DuckDB stays open source while the team behind it goes to work for Amazon
Hannes MĂĽhleisen and Mark Raasveldt started as AWS employees. The two built DuckDB, an analytical database that runs inside your process instead of on a server somebody has to administer. If you ship anything on top of DuckDB, your license does not change. Amazon did not buy the project. DuckDB, Duc...
> F5 speeds up virtual patching to counter AI-driven threats
F5 announced innovations to block frontier AI-driven threats in the data path and enable faster virtual patching, giving security leaders time to make intelligent risk-based decisions rather than reactive operational compromises. With new features such as anomaly detection and agentic threat intelli...
> curl 8.22.0
Welcome to this new release. Get it as always from https://curl.se. If you rather want a security-patched older release branch, stay tuned for the follow-up Rock-solid curl announcement within a few days. Release presentation At 10:00 CEST (08:00 UTC) Daniel makes a live-streamed release presentatio...
> Vali Cyber ZeroLock 5 brings MFA to the hypervisor command line
Vali Cyber released ZeroLock 5, a major release focused on closing the two most dangerous gaps in hypervisor security: insider threats and stolen credentials on ESX and Linux hosts. The hypervisor is now the target Over the past two years, ransomware operators and nation-state actors alike have shif...
> National Life Group CISO expects more vulnerabilities in six months than in thirty years
In this Help Net Security interview, Becky Palmer is VP and CISO at National Life Group, answers five questions about defending against AI-driven attacks. The discussion covers why patch cycles built for human speed cannot keep up, and which compensating controls buy time when an immediate fix is no...
> Exchange Server : près de 22 000 serveurs exposés sont vulnérables à la CVE-2026-62911
Exchange exposé sur Internet: tout savoir sur la CVE-2026-62911, les risques, les chiffres Shadowserver et les correctifs à appliquer rapidement. Le post Exchange Server : près de 22 000 serveurs exposés sont vulnérables à la CVE-2026-62911 a été publié sur IT-Connect.
> Scareware ads keep running on Google’s transparency tool, even after they’re reported
A team of NYU and Radboud University researchers spent a year building a tool to find deceptive software ads inside Google’s public ad archive. It works. It also exposed something more uncomfortable: reporting a bad ad to Google doesn’t mean the ad, or the domain behind it, stops running. The tool i...
> Oracle Linux 8 mingw-sqlite Important Update for CVE-2026-11822
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
> Oracle glib2 Moderate Buffer Overflow Fix ELSA-2026-61766-0 CVE-2026-15588
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
> SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks
The vulnerabilities CVE-2026-83549 and CVE-2026-83548 can be chained for unauthenticated remote code execution. The post SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks appeared first on SecurityWeek.
> Oracle Linux 9 Gzip Moderate Buffer Overflow Vuln ELSA-2026-61623-0
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
> Oracle Linux 10 ELSA-2026-38489 Important Xwayland CVE Fix
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: