[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (18 articles)

|

// AI-powered summary generated at 08:01

> Chromium: CVE-2026-78891 Buffer overflow in WebRTC
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
> CVE-2026-72984 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
> AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?
AI is accelerating vulnerability discovery, putting pressure on systems built to enrich, prioritize, and remediate flaws at a slower pace. Action1 explains why defenders increasingly need to correlate multiple intelligence sources and turn vulnerability data into faster remediation. [...]
> CVE-2026-70341 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
> CVE-2026-66798 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
> ATF Confirms Cyber Incident After Ransomware Group Claims Attack
The Bureau of Alcohol, Tobacco, Firearms and Explosives has described it as a ‘major incident’ and it’s conducting an investigation with the DOJ. The post ATF Confirms Cyber Incident After Ransomware Group Claims Attack appeared first on SecurityWeek.
> CVE-2026-66324 Microsoft Edge (Chromium-based) Spoofing Vulnerability
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
> CVE-2026-66323 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
> U.S. CISA adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabil...
> CVE-2026-62904 Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
> CVE-2026-58616 Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network.
> Windows Autopilot : Microsoft inscrit l’appartenance de vos PC directement dans l’UEFI
Nouveauté Windows Autopilot : Device association lie un PC Windows 11 à votre tenant via un marqueur UEFI attesté par le TPM, avant l'inscription dans Intune. Le post Windows Autopilot : Microsoft inscrit l’appartenance de vos PC directement dans l’UEFI a été publié sur IT-Connect.
> CVE-2026-70331 Microsoft Edge for iOS Spoofing Vulnerability
Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.
> Protect your WhatsApp account with new passkey and 2FA upgrades
WhatsApp has introduced three security upgrades. Here’s what to turn on to better protect your account.
> Windows 11 KB5120998 : la barre des tâches redevient déplaçable, mais attention aux bugs
La mise à jour KB5120998 rend enfin la barre des tâches Windows 11 déplaçable, mais des utilisateurs signalent de premiers bugs. L'essentiel à savoir. Le post Windows 11 KB5120998 : la barre des tâches redevient déplaçable, mais attention aux bugs a été publié sur IT-Connect.
> Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign
A large-scale phishing campaign used fake voicemail SVG attachments to bypass email defenses, targeting 5527 organizations with over 26,000 malicious messages
> BotBase for Operators: A clearer path to joining Cloudflare's directory of bots and agents
Bot operators now have a home in the Cloudflare dashboard to manage submissions. This update adds submission status tracking, submission editing, and a behavior model so operators can accurately declare how their bots use content.
> Over 8,300 Gitea servers vulnerable to code execution attacks
Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver. [...]
> OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems
CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents. The post OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems appeared first on SecurityWeek.
> How to choose remote work tools that don’t create security debt
The remote work tools you pick on day one become the infrastructure you're stuck with. Here's how to build a stack you won't need to rebuild.