[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (98 articles)

|

// AI-powered summary generated at 16:01

> Ubuntu 26.04 OpenJDK 17 Security Issues - USN-8676-1 - Multiple Threats
Ubuntu addressed multiple vulnerabilities in OpenJDK 17 across various LTS versions, enabling potential denial of service and data security risks, necessitating package updates for user protection.
> VMs won't contain cyber-capable agents
As part of Patch the Planet, we received preview access to GPT 5.6-Cyber with a simple task: evaluate its cyber capabilities. Recent events inspired me to give it a challenge to work through: escape the VM I’d normally use for sandboxing. The target was a QEMU/KVM VM on my Linux dev machine (Debian...
> The MFA Identity Trap: When Authentication Creates a False Sense of Security
Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. The post The MFA Identity Trap: When Authentication Creates a False Sense of Security appeared first on SecurityWeek.
> Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)
Attackers have begun exploiting CVE-2026-60004, a critical code injection vulnerability in the Gitea Git platform, CISA confirmed on Tuesday by adding the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. The KEV entry does not contain or point to details about the attacks, but acc...
> InfoSec News Nuggets – 08/26/2026
Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution Microsoft disclosed a maximum-severity flaw in its Entra ID identity service, tracked as CVE-2026-69836 with a CVSS score of 10.0, tracing back to unsafe deserialization of untrusted data that could let an attacker exe...
> RightCrowd Pass unifies mobile, physical, and biometric credentials
RightCrowd announced RightCrowd Pass, a credentialing solution that issues and manages mobile, physical and biometric access credentials from a single platform. Many large enterprises and universities rely on badge programs-built years ago. As organizations add mobile and biometric credentials, what...
> Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests
Aikido Security has published research that recreates the Australian gym-booking incident in a synthetic environment, finding that Claude Opus 4.6, running on the OpenClaw agent harness, exploited a client-side-only booking restriction in 9 of 10 runs. The original incident was first reported by AB...
> Bogus recruiters go after high-value corporate credentials on mobile
Scammers posing as HR staff at well-known companies are running interview scheduling scams that end with a stolen corporate password, according to Zimperium. Attackers are using a technique called browser-in-the-browser, or BitB, which CTM360 documented in earlier research on recruitment phishing. T...
> Choose your fighter: Balancing competing requirements to select models for your AI SOC
Selecting a model for your security operations center (SOC) and digital forensics and incident response (DFIR) tasks is important, but selecting the best one is more involved than you might think. Here's how to choose.
> Chrome 152 Patches Over 300 Vulnerabilities
Most of the flaws were discovered by Google using AI, but researchers are still discovering high-value Chrome vulnerabilities. The post Chrome 152 Patches Over 300 Vulnerabilities appeared first on SecurityWeek.
> OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation
OpenAI on Tuesday said it banned a cluster of Russian ChatGPT accounts that used VPNs to bypass access restrictions and run an influence operation, which relied on its artificial intelligence (AI) tool to generate social media posts and comments that were shared on Substack, Telegram, X, Facebook an...
> Important Update for CVE-2026-11940 in Oracle Linux 8 ELSA-2026-58971
Oracle Linux 8 updates include Python 3.12.14 packages to address CVE-2026-11940, with various RPMs uploaded for x86_64 and aarch64 architectures.
> Oracle Linux 8 gstreamer1-plugins-good Critical Heap Overflow ELSA-2026-59179
Oracle Linux 8 has released updates for gstreamer1-plugins-good addressing multiple CVEs, including heap buffer overflows and use-after-free vulnerabilities, enhancing system security.
> Linux Foundation Introduces TRACE Standard for AI Runtime Evidence
This new open standard offers hardware-attested runtime and compliance evidence for AI agents
> Oracle Linux 8 Python-Pyasn1 Important DoS Security Fix CVE-2026-59886
Oracle released updated RPMs for Oracle Linux 8 addressing a denial of service vulnerability in the python3-pyasn1 package with CVE-2026-59886. Updates are available for x86_64 and aarch64.
> Oracle Linux 7 389-ds-base Significant Security Patch ELSA-2026-36205
Oracle Linux 7 has received security updates for 389-ds-base packages addressing CVE-2026-11610 and CVE-2026-11774, improving system security and functionality.
> DDoS Attack Hits Norwegian Government Services
A coordinated DDoS campaign has caused disruption among Norwegian government services
> Oracle 7 xorg-x11-server Important Security Updates for CVE-2026-55999
Oracle Linux 7 has received security updates for multiple X11 server components, addressing several CVEs, including CVE-2026-55999, with respective RPMS and source packages now available.
> U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Gitea flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE-2026-60004 (CVSS sco...
> 88 ID Verification Breaches Show the Cost of Collecting Identity Data
88 ID-verification breaches exposed billions of records, highlighting the growing risks of collecting sensitive identity and biometric data. A new report from Mysterium VPN compiles 88 documented incidents since 2011 where data collected specifically to verify someone’s identity or age got breached,...