[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (1 articles)

|

// AI-powered summary generated at 04:00

> USN-8514-2: OpenSSH vulnerability
USN-8514-1 fixed a vulnerability in OpenSSH. This update provides the corresponding fix for Ubuntu 14.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. Original advisory details: It was discovered that OpenSSH incorrectly handled file permissions when downloading files as root using the legacy scp...
> AI helps scammers build convincing antivirus renewal pages
A fake Avast renewal page shows how AI is helping scammers create more convincing traps with polished designs and fluent copy.
> Enterprises Warned of Attacks Exploiting WSO2 Vulnerability
The vulnerability, tracked as CVE-2026-5430, can be exploited to gain access to valuable enterprise data. The post Enterprises Warned of Attacks Exploiting WSO2 Vulnerability appeared first on SecurityWeek.
> AI made software development unrecognizable. Is cybersecurity next?
The rapid emergence of AI has radically changed a host of professions, with software engineering and development perhaps the most transformed of all pursuits. The usual “solitary ritual” of a developer writing code for hours is giving way to collaboration with an army of chatb...
> NCSC and Allies Warn of Iranian Spyware Campaign
The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents
> Texas Utility CenterPoint Energy Confirms Data Breach After Hacker Claims 7.49M Records Stolen
CenterPoint Energy confirmed a customer data breach after a hacker claimed to leak 7.49M records, including personal and billing information. CenterPoint Energy admitted on Monday that an intruder stole personal information belonging to some of its customers. The Houston-based utility, which supplie...
> Oracle Patches 800+ Vulnerabilities in September 2026 Security Update
The security updates resolve over 800 vulnerabilities across 17 product families, including over 100 critical-severity flaws. The post Oracle Patches 800+ Vulnerabilities in September 2026 Security Update appeared first on SecurityWeek.
> Forensic Windows – Partie – 12 : analyse du SRUM
Apprenez à exploiter le SRUM (base SRUDB.dat) de Windows : acquisition et analyse avec SrumECmd, applications exécutées, utilisateurs et activité réseau. Le post Forensic Windows – Partie – 12 : analyse du SRUM a été publié sur IT-Connect.
> NIST and CISA finalize playbook to stop token theft and forgery
NIST and CISA have finalized guidelines to help federal agencies and cloud service providers (CSPs) protect identity and access tokens from forgery, theft, and misuse. The guidance, Protecting Tokens and Assertions from Forgery, Theft, and Misuse (NIST IR 8587), explains how agencies and cloud provi...
> HBO Max : le compte Reddit officiel piraté pour diffuser des malwares via des pubs ClickFix
Le compte Reddit vérifié de HBO Max a été piraté pour diffuser 108 publicités ClickFix en 48 heures, avec des infostealers macOS et Windows à la clé. Le post HBO Max : le compte Reddit officiel piraté pour diffuser des malwares via des pubs ClickFix a été publié sur IT-Connect.
> Test BLUETTI Balco 260 : le kit solaire de balcon avec batterie
Test complet du BLUETTI Balco 260 : station solaire de balcon avec batterie 2,5 kWh, 4 MPPT et prise de secours. Mon avis et le rôle du S Meter. Le post Test BLUETTI Balco 260 : le kit solaire de balcon avec batterie a été publié sur IT-Connect.
> Debian DSA-6496-2 nginx Update Fixes Module Build Regression
The update for nginx released as DSA 6496-1 caused a regression in the nginx-dev package: the backported fix for CVE-2026-42533 declared two private header files, which are not shipped in nginx-dev, as dependencies of the module build, so third-party nginx modules could no longer be built against ng...
> Google fixes actively exploited Android zero-day on Pixel devices
Google has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks. [...]
> Ubuntu 26.04 LTS WebOb Important Redirect Control Issue USN-8759-1
Several security issues were fixed in WebOb.
> iOS 27 et macOS Golden Gate 27 : Apple corrige plus de 200 failles, dont 20 dans le noyau d’iOS
Apple a publié iOS 27 et macOS Golden Gate 27 avec plus de 200 correctifs de sécurité, dont une faille CoreMedia exploitable via une simple image. Le post iOS 27 et macOS Golden Gate 27 : Apple corrige plus de 200 failles, dont 20 dans le noyau d’iOS a été publié sur IT-Connect.
> What happens when AI agent governance is missing at scale
In this interview with Help Net Security, Gourab Basu, Global Head of Engineering at meshIQ, discusses governance in AI agent systems. He argues that instructions written into a prompt are not enough to control what an agent does, since agents can change their own path as they work. Real control mea...
> Mythos has made 2026 patching hell. It might make 2027 a breeze
Gartner sees huge amounts of technical debt paid down, and better scanning that could make software safer sooner
> Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. "This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote...
> Nintendo Switch : une faille permet d’exécuter du code via le code QR affiché à l’écran
Une faille de sécurité dans la Nintendo Switch : CVE-2026-82079. Un attaquant à proximité qui scanne le code QR affiché par la console peut exécuter du code. Le post Nintendo Switch : une faille permet d’exécuter du code via le code QR affiché à l’écran a été publié sur IT-Connect.
> DeepZero: Open-source hunting for vulnerable Windows drivers
DeepZero is an open-source engine that automates the search for exploitable Windows kernel drivers. You point it at a folder of binaries and it parses them, pulls them apart, scans them, throws most of them away, and asks a language model whether what survives can be attacked. Pipelines are written...