[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (18 articles)

|

// AI-powered summary generated at 08:01

> USN-8684-1: Perl vulnerabilities
It was discovered that Perl incorrectly handled certain arguments to Socket and pack/unpack functions. An attacker could possibly use this issue to read sensitive information from memory. (CVE-2026-12087, CVE-2026-57432) It was discovered that Perl incorrectly handled regular expressions with a lar...
> Carhartt data breach exposes information of 12.9 million accounts
The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwned. [...]
> Debian Cockpit Significant Code Execution Service Denial DSA-6474-1
Two security vulnerabilities were discovered in Cockpit, a web console for Linux servers, which could result in the execution of arbitrary code or denial of service. For the stable distribution (trixie), these problems have been fixed in version 337-1+deb13u2.
> Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two unn...
> Nuisance-call blocker fined £190k for being a nuisance caller
Elderly Aids made 758,000 unwanted calls a year selling gear to stop unwanted calls
> Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools
Individuals and organizations in Cambodia have emerged as the target of a new campaign that delivers an open-source remote access trojan (RAT) called Spark RAT. "The samples employ diverse lure themes, suggesting an effort to appeal to a broad range of potential victims. These include government no...
> CISA Warns of Six Exploited Flaws in Microsoft, Linux, Red Hat and Citrix Products
CISA added six new bugs to its Known Exploited Vulnerabilities catalog on August 26, showing signs of active exploitation in the wild
> New Instagram and Facebook rules set a default two-hour limit for teens
Meta will pay up to $17 billion and introduce new protections for US teens to settle a landmark child safety case.
> Cyberattack Causes Global Disruption at Boston Scientific
The cybersecurity incident has disrupted Boston Scientific’s ability to process and ship customer orders. The post Cyberattack Causes Global Disruption at Boston Scientific appeared first on SecurityWeek.
> LSN-0121-1: Kernel Live Patch Security Notice
In the Linux kernel, the following vulnerability has been resolved: ksmbd: ipc: fix use-after-free in ipc_msg_send_request ipc_msg_send_request() waits for a generic netlink reply using an ipc_msg_table_entry on the stack. In the Linux kernel, the following vulnerability has been resolved: ksmbd: f...
> JavaScript obfuscation: From party trick to phishing kit
Learn the basics of what obfuscation is, why a researcher would try to reverse it, and several ways to approach the problem.
> The Future of AI-Driven Security Depends on Complete Data
For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. The post The Future of AI-Driven Security Depends on Complete Data appeared first on SecurityWeek.
> Boston Scientific Reveals Global Disruption After Cyber Incident
MedTech giant Boston Scientific has revealed IT outages following a cyber incident
> Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452)
CISA added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a previously patched Citrix NetScaler ADC and Gateway flaw, tracked as CVE-2026-8452, that is being exploited in the wild. The agency published the alert on August 26 and gave federal agencies until Au...
> A polymorphic phishing page (that occasionally breaks itself), (Thu, Aug 27th)
As I've mentioned before in some of my diaries, from time to time, I like to go over phishing messages that get caught in my various spam traps or sent to us here at the Internet Storm Center.
> LLM-Based Social Engineering Scams
OpenAI disrupted a social engineering group from Cambodia that used ChatGPT. Its scope is impressive: The network simultaneously conducted multiple types of scams, often blending elements from different schemes. For instance, operators used dating personas to build trust before introducing fraudulen...
> US Navy tells sailors and their families: scrub your social media, enemies are watching
The US Navy has told its entire workforce of 340,000 active-duty personnel, 58,000 reservists, and 210,000 civilian employees to clean up their social media profiles, because adversaries might be using them to determine who they are, where they live, and when they may not be at home. Read more in...
> Debian Trixie libdbi-perl Important Code Execution and DoS DSA-6473-1
Several vulnerabilities were discovered in libdbi-perl, a Perl framework that provides a common interface to access various backend databases in a uniform manner, which could result in denial of service, path traversal, bypass of file-backed filters or the execution of arbitrary code.
> GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework, GoCaracal, during a June 2026 intrusion at an unnamed communications organization in Venezuela. GoCaracal provides operators with remote shell access and payload...
> Debian trixie bubblewrap Critical Symlink Traverse Issue DSA-6472-1
A symlink traversal vulnerability was discovered in bubblewrap, a low-level unprivileged sandboxing tool used by Flatpak and other projects, which could result in sandbox escape by malicious/compromised Flatpak apps. For the stable distribution (trixie), this problem has been fixed in