Multiple vulnerabilities were discovered in roundcube, a skinnable AJAX based webmail solution for IMAP servers, which could result in cross-site scripting, SSRF bypass, information disclosure, privilege escalation, denial of service or remote code execution. For the stable distribution (trixie), th...
Several vulnerabilities were discovered in starlette, a lightweight ASGI framework/toolkit, which could result in bypass of authorization checks or denial of service. For the stable distribution (trixie), these problems have been fixed in version 0.46.1-3+deb13u3.
Cyberattaque scolaire : plusieurs académies affrontent pannes, affectations retardées et rentrée sous tension.
Extortion group FulcrumSec claims they stole 86GB of Manchester Airports Group data after finding API credentials exposed in client-side JavaScript. Manchester Airports Group (MAG) disclosed a data breach on August 27 affecting customers of Manchester, London Stansted, and East Midlands airports. Tw...
FulcrumSec claims it stole 86 GB of data from Manchester Airports Group. BleepingComputer validated one traveller's record, while samples revealed detailed customer, booking, and travel information beyond what MAG initially disclosed. [...]
Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage. [...]
Alaxione visé par une fuite revendiquée de 6,8 millions de patients et plus de 10,1 millions de rendez-vous. La quatrième fuite en un an ?
Multiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal cryptocurrency, sensitive data, and browser history, as well as inject ClickFix lures. [...]
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor     FTP Banners: The New Dead Drop Resolver Deliv...
PaperCut servers are under active attack, while 47% of tracked installations still run unpatched versions vulnerable to remote code execution. PaperCut, the print management software running in schools, hospitals, and offices worldwide, confirmed on August 27 that a pre-authentication remote code ex...
Un pirate informatique cible sept nouveaux SDIS fin août, après une série de fuites touchant déjà les secours français en juillet.
Un pirate revendique 149 millions de lignes volées à Zéro Logement Vacant après une compromission de Metabase.
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Hack One Robot, Reach the Next: Unitree G1 Security F...
Polling finds two-thirds don't trust this government, or any future one, with access to their encrypted chats
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Unpatched Zimbra servers are falling to CVE-2026-73570 attacks At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation sh...
Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows Terminal or PowerShell.
"While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique...
YARA-X&#;x26;#;39;s 1.20.0 release brings 14 improvements and 13 bugfixes.
Découvrez le Geekom A7 2026 Edition : Ryzen 5, 16 Go DDR5, 500 Go NVMe, USB4, Wi‑Fi 6E, Windows 11 Pro. Découvrez ce mini PC et ses performances.
Le post Test Geekom A7 2026 Edition : un mini-PC compact avec AMD Ryzen 5 et 16 Go de DDR5 a été publié sur IT-Connect.
Le système de paie des mosquées et madrasahs à Singapour, géré par le Conseil religieux islamique de Singapour (MUIS), a été victime d'une cyberattaque par rançongiciel. Le système SmartHRMS, fourni par le fournisseur de logiciels Avelogic, a été compromis, potentiellement affectant les détails du p...
Le 30 août 2026, Compucase a détecté un incident de cybersécurité affectant une partie limitée de son réseau informatique. Cette entreprise taïwanaise, spécialisée dans la conception et la fabrication de composants pour ordinateurs, a immédiatement réagi en isolant les systèmes touchés et en engagea...