[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (85 articles)

|

// AI-powered summary generated at 16:01

> Multiples vulnérabilités dans les produits HPE Aruba Networking (02 septembre 2026)
De multiples vulnérabilités ont été découvertes dans les produits HPE Aruba Networking. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
> Multiples vulnérabilités dans les produits Elastic (02 septembre 2026)
De multiples vulnérabilités ont été découvertes dans les produits Elastic. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et une atteinte à la confidentialité des données.
> Multiples vulnérabilités dans SonicWall Secure Mobile Access (02 septembre 2026)
Le 01 septembre 2026, SonicWall a publié un avis de sécurité concernant deux vulnérabilités affectant les Secure Mobile Access (SMA) 1000. La vulnérabilité critique CVE-2026-83548 permet une falsification de requêtes côté serveur (SSRF) de la part d'un attaquant non authentifié. La vulnérabilité...
> Hangte
Le fabricant de composants optoélectroniques Hangte a publié une alerte de cybersécurité indiquant que ses systèmes d'information ont été attaqués. L'entreprise a mis en place des mécanismes de défense et évalue que l'impact sur ses opérations n'est pas majeur.
> Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes
23-year-old botnet down
> What happens when AI models take aim at ICS exploits
LLMs have shown great improvement in vulnerability research and exploit development capabilities over the past six months. But it’s one thing to find vulnerabilities in well documented open-source projects and an entirely different skillset to decrypt file systems and reverse-...
> Counterfeit installers to system compromise: Tracking a deceptive software download campaign
An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft Defender Experts shares observed attack techniques, Defender XDR detections, indicators of compromise, and practical mitigations to help...
> FBI Probes Service Selling 153M+ Drivers Licenses
A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning i...
> Weekly Update 519: Breaches & Data Integrity
Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSiteIt does feel like I've bitten off too much and am now chewing like crazy this week. The 3D printing talk with Elle in Oslo, the "normal" NDC infosec tal...
> FBI raises alarm over deceptive phishing campaign targeting prominent people
The ongoing social engineering threat, which dates back to late 2025, tricks victims into granting threat actors long-term access to their accounts. The post FBI raises alarm over deceptive phishing campaign targeting prominent people appeared first on CyberScoop.
> Another Artifactory CVE under attack by AI agents or humans
Unauthenticated intruders can mint admin tokens, and exposed servers are already being hit
> Hackers abuse Faronics Deploy admin tool to install ScreenConnect
Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software. [...]
> Meta's $17 Billion Settlement is a Bad Deal for Teens and All Social Media Users
Meta’s settlement with 52 state attorneys general is a bad deal for all internet users, and especially for teens. That’s what we said the day the settlement was announced. In this post, we go through the Settlement’s provisions in detail and explain why that is so, including how: The Settlement emb...
> X says attackers are targeting user accounts after the launch of X Money
X is investigating a wave of unsolicited password reset emails that it believes may be tied to the rollout of its new payments service.
> Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks
The model provider gave METR the credits for free. An actual customer would not have been so lucky
> China's 'Fire Ant' campaign used compromised Cisco routers as platform for more attacks
A hacking operation dubbed Fire Ant "didn’t just compromise systems," according to researchers. "It compromised the trust layer those systems depend on."
> Palo Alto Networks Acquires AI Agent Platform Console
The cybersecurity giant announced the acquisition alongside quarterly results showing a 34% increase in revenue and strong growth in next-generation security ARR. The post Palo Alto Networks Acquires AI Agent Platform Console appeared first on SecurityWeek.
> Tina Peters, through attorney, backs off formal role in Shasta County elections
Peters still left the door open to working with Shasta County on elections and doubled down on her statements that electronic voting machines should be discontinued. The post Tina Peters, through attorney, backs off formal role in Shasta County elections appeared first on CyberScoop.
> Debian Keystone Important Auth Bypass and Info Disclosure DSA-6480-1
Multiple vulnerabilities were discovered in Keystone, the OpenStack identity service, which may result in authorisation bypass or information disclosure. For the stable distribution (trixie), these problems have been fixed in version 2:27.0.0-3+deb13u5.
> Firefox helps iPhone users bypass ads on web sites while making money showing its own ads
Baked-in Firefox ad blocking on iOS begins rolling out slowly today, and is off by default