[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (98 articles)

|

// AI-powered summary generated at 16:01

> USN-8679-1: Vim vulnerability
It was discovered that Vim incorrectly handled certain tags files. An attacker could possibly use this issue to execute arbitrary code.
> Nonprofits say Microsoft locked them out of years of data.
A new report alleges Microsoft locked nonprofits out of years of data. Here's what you need to know and what you can do about it.
> Debian OpenSSL Denial of Service DSA-6465-1 CVE-2026-14456 CVE-2026-14457
Debian issued an advisory for OpenSSL, highlighting multiple vulnerabilities that could cause denial of service, and recommends upgrading to version 3.5.7-1~deb13u2 to address these issues.
> Insurance benefits platform Paylogix says hackers stole financial and health data
The benefits management firm Paylogix told regulators that hackers stole sensitive information on tens of thousands of people from its systems.
> Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice
Joshua Culver, aka “Maverick Young,” is accused of imitating the head of the NSA’s Tailored Access Operations unit during a time it wasn’t called that. The post Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice appeared first on CyberScoop.
> What is Proton’s mission? Let us tell you.
Proton released a new video featuring CEO Andy Yen and the team explaining why the company exists, and why privacy has to be the default.
> U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an "unprecedented, whole-of-government, economic campaign" against the nation and its enablers. "We are launching an economic onslaught against Iran's financial connections around the...
> USN-8678-2: OpenSSL, OpenSSL 1.0 vulnerabilities
USN-8678-1 fixed vulnerabilities in OpenSSL. This update provides the corresponding fix for OpenSSL and OpenSSL 1.0 on Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. In addition, this update also fixes the following issues that were not previously addressed in those releases: It was dis...
> Wordfence Argus Finds Complex 6 Step Critical RCE in Avada Theme with 1 Million Sales
A year ago we wrote that we'd put AI to work across the whole company, turning everyone on the team into a capable AI operator so our defenders could stay ahead of the threat actors attacking the sites we protect. In April we showed where it was heading: in the space of a few months, AI-assisted rep...
> Norway ’s Digital Government Infrastructure Hit by a new DDoS Attack
Norway ’s shared government infrastructure suffered a third DDoS attack, disrupting digital services but showing no signs of data compromise. Norway ‘s shared digital government infrastructure has been hit by another distributed denial-of-service (DDoS) attack that disrupted services used by citizen...
> USN-8678-1: OpenSSL vulnerabilities
It was discovered that OpenSSL incorrectly handled the QUIC server incoming channel queue. A remote attacker could possibly use this issue to cause OpenSSL to use excessive resources, leading to a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-14456) It was discovered that...
> Water sector passes, government sector fails attempts to spot and halt simulated CISA attack
Agency red-teamers got initial access to both organizations they tested, but one quickly isolated and shut down the attempts from going further. The post Water sector passes, government sector fails attempts to spot and halt simulated CISA attack appeared first on CyberScoop.
> When the Algorithm Fires You: Uber Faces €825M Fine
Uber faces an €825M GDPR fine for automatically suspending drivers without human review, highlighting the risks of AI decisions affecting workers. The Dutch Data Protection Authority handed Uber its largest privacy fine yet, and this one isn’t about data transfers or cookie consent. The regulator im...
> Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable
Two CVSS 9.8 miniOrange SAML WordPress plugin auth bypasses were exploited while paid editions never appeared in any vulnerability database. Manual patch required. Two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On WordPress plugin, both rated CVSS 9.8, are...
> USN-8670-2: curl vulnerability
USN-8670-1 fixed a vulnerability in curl. This update provides the corresponding update for Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. Original advisory details: Joshua Rogers discovered that curl incorrectly handled reusing connections when client certificate settings changed. Th...
> Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation
TRACE was developed by AMD, Intel, Microsoft, OPAQUE, and TII and contributed to the Linux Foundation. The post Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation appeared first on SecurityWeek.
> You could've applied all 1,449 Oracle patches and still been hit by this attack
Attackers now ready to exploit how things work, rather than just break them, says Oracle support expert
> The patch window is collapsing: Why security needs a new control plane
Organizations need protection that operates in the gap between discovery and remediation. The post The patch window is collapsing: Why security needs a new control plane appeared first on Microsoft Security Blog.
> Massive DDoS attack disrupts Norway’s government digital services
A large distributed denial-of-service (DDoS) attack has disrupted Norway's shared government digital infrastructure since Monday, affecting services used by the public sector. [...]
> That fake Grand Theft Auto VI demo is actually just malware
Grand Theft Auto fans, eager for news about one of the most anticipated video games of all time, appear especially vulnerable to this new cyberattack.