[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (132 articles)

|

// AI-powered summary generated at 20:00

> Vulnérabilité dans Kaspersky Endpoint Security Windows (01 septembre 2026)
Une vulnérabilité a été découverte dans Kaspersky Endpoint Security Windows. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.
> Vulnérabilité dans Mozilla Firefox pour iOS (01 septembre 2026)
Une vulnérabilité a été découverte dans Mozilla Firefox pour iOS. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.
> [webapps] EasyAppointments 1.5.1 - Blind SQL Injection
EasyAppointments 1.5.1 - Blind SQL Injection
> Multiples vulnérabilités dans SPIP (01 septembre 2026)
De multiples vulnérabilités ont été découvertes dans SPIP. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et un problème de sécurité non spécifié par l'éditeur.
> [webapps] miniOrange 5.4.3 - Unauthenticated Auth Bypass
miniOrange 5.4.3 - Unauthenticated Auth Bypass
> [webapps] Grav CMS 2.0.7 - RCE
Grav CMS 2.0.7 - RCE
> Ungentlemanly behavior: Insights into a ransomware operation
Analysis of 15 intrusions revealed tradecraft used by GOLD SHERWOOD affiliates
> [webapps] Bludit CMS - Stored XSS
Bludit CMS - Stored XSS
> [webapps] Payload CMS 3.72.0 - Blind SQL Injection
Payload CMS 3.72.0 - Blind SQL Injection
> Vulnerability & Patch Roundup — August 2026
If you operate a website, you’re already aware that a single unpatched vulnerability can render your site inaccessible, compromise your reputation, or necessitate extensive remediation following an attack. Most security breaches we observe originate from automated attacks that exploit known software...
> EFF to Governor Newsom: Veto California’s AB 1709
The California legislature passed Assembly Bill 1709 (A.B. 1709) today, which functions as a sweeping ban on social media use for young people under the age of 16. This well-intentioned, but deeply flawed piece of legislation, cuts young people off from essential information and experiences, particu...
> Ne devenez pas le relais involontaire d’une intox
Avant de partager un contenu politique spectaculaire, quelques vérifications simples peuvent révéler une possible intox.
> Healthcare cyberattacks hit pacemakers and millions of patient records
McKesson admits breach as ShinyHunters demands $55.2M
> McKesson copes with fallout from data theft extortion attack
The major healthcare sector vendor did not identify the attackers, but ShinyHunters, a prolific group increasingly targeting the sector, claimed responsibility. The post McKesson copes with fallout from data theft extortion attack appeared first on CyberScoop.
> USN-8705-2: OpenZFS vulnerability
USN-8705-1 fixed vulnerabilities in OpenZFS. This update provides the corresponding fix for OpenZFS on Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. Original advisory details: It was discovered that OpenZFS incorrectly handled authorization checks for certain ioctl operations on Linux. A local attacker c...
> Cronos blockchain restarts after $74 million Tectonic exploit
The Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending platform allowed an attacker to borrow $74 million. [...]
> Five plead guilty in latest federal ATM jackpotting case
Federal law enforcement continued to warn about ATM jackpotting gangs as it announced guilty pleas from five Venezuelan nationals.
> Windows bug incorrectly tells users that Microsoft Defender Antivirus is turned off
Microsoft on Friday reported that a glitch is causing Windows to tell users that Microsoft Defender Antivirus is turned off when it is in fact fully functional, a bug that the vendor says it is working to fix. Consultants say that this advisory raises a major concern in tha...
> The Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary, (Mon, Aug 31st)
One of my internet-exposed inference honeypots was discovered, relabeled with sought-after model names, and incorporated into infrastructure apparently used to provide "free" LLM backends. It then received a real coding-agent session &#;x26;#;xe2;&#;x26;#;x80;&#;x26;#;x94; history, files...
> EFF to Courts: Don’t Rewrite Copyright Over AI Hype
The history of technology is rife with copyright panics.  In the 1980s, major rightsholders ran to Congress and the courts, claiming that videotape recorders (VTR) were “to the American film producer and the American public as the Boston strangler is to the woman home alone.” Then, the Supreme Court...