[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (132 articles)

|

// AI-powered summary generated at 20:00

> InfoSec News Nuggets – 08/31/2026
Hasbro Data Breach Exposed Employee Personal Information Notification letters filed with the Massachusetts Attorney General reveal that a cyberattack disclosed by the toy and game giant in late March also compromised employee personal data, including names, postal and email addresses, phone numbers,...
> Ubuntu 26.04 bzip2 Denial of Service Memory Management Issue USN-8685-1
bzip2 could be made to crash if it processed a specially crafted archive.
> ATM Flaws Reveal Key Weaknesses in the Software Supply Chain
A security researcher discovered nine vulnerabilities impacting ATM encryption and authentication software. But the problems extend far beyond your local cash machine.
> The AI Kill Switch Act is repeating the Clipper Chip’s mistakes
Mandating ‘kill switches’ for AI agents would threaten the security of America’s critical infrastructure and undercut U.S. AI leadership. Congress must reject the AI Kill Switch Act. The post The AI Kill Switch Act is repeating the Clipper Chip’s mistakes appeared first on CyberScoop.
> Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams
Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers. The post Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams appeared first on Unit 42.
> Trusted Chrome, Edge extensions weaponized in supply chain campaign
Attackers have turned previously legitimate browser extensions into malware after acquiring them from legitimate publishers, potentially allowing malicious updates to reach users who had installed the software when it was still safe, researchers at Socket have found. The ca...
> Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails
Russian state hackers are trying to interfere with AI-assisted malware analysis in Ukraine by deliberately setting off AI safety mechanisms, ESET has found. The technique, named GuardBreaker by ESET, appeared in a malicious VBS script tied to UAC-0099, a Russia-aligned group previously observed cond...
> Nigerians extradited to US for sextortion, deaths of two teens
Two Nigerian men extradited to the U.S. on Thursday have been charged with involvement in sextortion schemes that resulted in the deaths of two minor victims in Mississippi and North Carolina. [...]
> Infostealers Are Hijacking Claude Sessions and Draining Subscriptions
Infostealers can steal active Claude sessions, bypass 2FA and drain paid usage. Anthropic is revoking access and refunding unauthorized charges. Anthropic confirmed that several infostealer malware can hijack an active Claude login session and let attackers burn through your usage without ever touch...
> Judge Says Pentagon’s Measures Against Anthropic Were ‘Illegal and Baseless’
The ruling is part of Anthropic's legal battle against the Pentagon after the government labeled the company as a supply chain risk earlier this year. The post Judge Says Pentagon’s Measures Against Anthropic Were ‘Illegal and Baseless’ appeared first on SecurityWeek.
> China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, and manage high-value...
> This month in security with Tony Anscombe – August 2026 edition
Details about the Hugging Face hack, critical infrastructure under attack, a spoofed in-flight Wi-Fi network, and more of this month's cybersecurity news
> Berlin Won’t Pay Extortion Group Claiming Data Theft
The Rhysida ransomware group has claimed the exfiltration of over 5TB of data, including personal information and credentials. The post Berlin Won’t Pay Extortion Group Claiming Data Theft appeared first on SecurityWeek.
> Applications VPN : 85 % de celles téléchargées aux États-Unis embarquent des traqueurs
Proton a analysé plus de 7 000 applications VPN mobiles : 85 % de celles téléchargées aux États-Unis contiennent des traqueurs et 64 accèdent à votre position. Le post Applications VPN : 85 % de celles téléchargées aux États-Unis embarquent des traqueurs a été publié sur IT-Connect.
> Microsoft asks users to ignore 'Antivirus is turned off' errors
Microsoft asked customers this week to ignore incorrect alerts that Defender Antivirus has been turned off after installing the latest Defender updates. [...]
> Is your cloud security strategy ready for AI’s looming threat?
Cloud architectures designed to withstand human attackers are facing a new threat: AI agents that rewrite the rules on the pace and scope of attacks. The recent OpenAI incident involving Hugging Face offers an early example of what an autonomous AI attack can look like, wit...
> Gitea sort enfin son extension officielle pour VS Code
Gitea a publié la première version stable de son extension pour VS Code : suivi des Actions et revue des pull requests sans quitter l'éditeur de code. Le post Gitea sort enfin son extension officielle pour VS Code a été publié sur IT-Connect.
> Debian autorise officiellement l’IA générative, mais le contributeur reste responsable
Les développeurs Debian ont voté : l'IA générative n'est ni interdite ni recommandée, mais celui qui soumet une contribution en assume toute la responsabilité. Le post Debian autorise officiellement l’IA générative, mais le contributeur reste responsable a été publié sur IT-Connect.
> Debian developers rejected an LLM ban and left disclosure voluntary
A maintainer reading a merge request can’t tell whether a person or a model wrote the diff, and nobody has to say. Debian developers voted on that through August 28, and Kurt Roeckx, the project secretary, announced the result: the winning option encourages contributors to disclose AI assistance and...
> PaperCut NG/MF : deux failles exploitées et un premier correctif contourné
PaperCut NG et MF sont visés par 2 failles déjà exploitées : CVE-2026-81578 et CVE-2026-82078. Le premier correctif a été contourné, un second est disponible. Le post PaperCut NG/MF : deux failles exploitées et un premier correctif contourné a été publié sur IT-Connect.