[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (1 articles)

|

// AI-powered summary generated at 04:00

> AEPD - autorité espagnole
L'autoritĂ© espagnole a infligĂ© une sanction de 675 000 € Ă  un fournisseur d'Ă©nergie pour de graves manquements Ă  la sĂ©curitĂ©, notamment pour avoir autorisĂ© l'utilisation d'un compte partagĂ© par 120 employĂ©s d'un sous-traitant et pour une mauvaise configuration des droits d'accĂšs ayant exposĂ© les don...
> AKI - autorité estonienne
L'autorité estonienne de protection des données (Andmekaitse Inspektsioon, AKI) annonce l'organisation d'un séminaire en ligne destiné au secteur de l'éducation sur l'utilisation des applications et de l'intelligence artificielle.Ce séminaire en ligne, prévu pour le 17 septembre de 15h00 à 16h00, s'...
> Victory: Court, Using a New Test, Rules Embedding Links is Legal
Courts have for two decades found that linking and embedding someone else’s web content, be it a photo, music, or an article, doesn’t violate copyright law–the entity that controls the server that hosts a copyrighted work, not the user or website that merely directs others to it, is directly liable...
> USN-8775-1: SQLite vulnerability
It was discovered that SQLite was vulnerable to a buffer overflow in the sqlar extension. If a user were tricked into opening a specially crafted SQLar archive, an attacker could cause a denial of service.
> First Agentic AI Data Breach Reported to Spanish Regulator
Spanish regulators say an AI agent chained together a successful login, vulnerability discovery, and access to personal data in a potential milestone for autonomous cyberattacks. The post First Agentic AI Data Breach Reported to Spanish Regulator appeared first on SecurityWeek.
> USN-8774-1: libheif vulnerabilities
Ali Firas discovered that libheif incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-62291) Dmitrijs Trizna discovered that libheif incorrectly handled certain image sequences. An attacker could possibly us...
> EFF Welcomes Alexander Macgillivray to its Board of Directors
The Electronic Frontier Foundation (EFF) is honored to announce today that Alexander "amac" Macgillivray — a former White House official who also served in top legal capacities at Twitter and Google — has joined EFF’s Board of Directors.  Macgillivray served in the Biden Administration as Deputy Ass...
> 👼 Flock Searches for the LOLs | EFFector 38.16
Mass surveillance isn't a joke. But police are treating it like one when using automated license plate reader (ALPR) networks. In our latest EFFector newsletter, we're covering a new EFF report on how officers across the country are routinely logging completely nonsensical "reasons" for their Flock...
> Big Tech’s AI safety rift signals disruption and disparity for enterprises
A growing divide among leading AI companies over how to secure increasingly powerful models is beginning to translate into challenges for enterprise IT, with implications for how organizations access, deploy, and govern AI systems. The latest flashpoint came after Meta CEO...
> How the Meta Settlement Silences Youth Activism
Since its integration into our digital world, social media has played a pivotal role in youth organizing and social mobilization. Yet, people’s access to these platforms is increasingly coming under threat from courts and legislatures under the guise of protecting young people online—presenting a si...
> Oracle’s September patches put Fusion Middleware back in the hot seat
Oracle’s September 2026 Critical Security Patch Update has arrived with 673 new security patches spanning 17 Oracle product families, with Oracle E-Business Suite accounting for the largest share at 159 patches, followed by Fusion Middleware with 153. Of these, 19 E-Business S...
> Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote at...
> International Meteor Organization says cyberattack dealt ‘critical blow’ to website
A website used around the world for reporting meteors faces weeks of downtime as the organization moves away from systems that were hacked recently.
> AI agent authorization risks remain a gap in new NIST-CISA token security guidance
AI agents’ actions are out of scope for new guidance from US authorities on securing identity and access tokens, but there is still plenty enterprises can do to protect their systems from rogue humans and AI agents alike. “Protecting Tokens and Assertions from Forgery, Thef...
> Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to...
> PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
Attackers are exploiting a critical flaw in a third-party WooCommerce plugin to upload PHP webshells
> Steganos Data Safe Evolves – New Shortcuts for Decryption
Passware Kit now supports password recovery and decryption for Steganos Data Safe v.15 and later, including newer .SHEADER vaults and additional protection options such as 2FA, Emergency Passwords, and USB-stored keys.
> Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks
The agencies issued a joint statement saying the “joint security boardings” came in response to “indications that the networks of both vessels were compromised.” The post Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks appeared first on CyberScoop.
> Google says some Pixel phone owners were hacked in zero-day attacks
The Pixel phone maker said there are indications that a bug in the phone's modem "may be under limited, targeted exploitation."
> USN-8736-2: Perl vulnerabilities
USN-8736-1 fixed vulnerabilities in Perl. This update provides the corresponding fix for Perl on Ubuntu 24.04 LTS. Original advisory details: It was discovered that Perl incorrectly handled certain large inputs during regular expression matching. An attacker could possibly use this issue to trigge...