[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (98 articles)

|

// AI-powered summary generated at 16:01

> Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators. The vulnerabilities, as disclosed by Patchstack, are li...
> Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff
AI infrastructure, including advanced semiconductors mostly made in Taiwan, has become a key point of competition between the U.S. and China. The post Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff appeared first on SecurityWeek.
> How Equifax is using AI to elevate its cybersecurity
For nearly a decade, Equifax has been dealing with the aftermath of one of the worst cybersecurity breaches in US history, racking up $1.4 billion on cleanup costs. Among the mistakes that led to the breach were a mismanaged patching process, an expired public-key certifica...
> TikTok phishing: How to spot fake login and verification pages
Scammers use fake TikTok login pages, warnings, and verification offers to trick you into handing over your account details.
> CISA Warns of Exploited Oracle WebLogic Vulnerability
The vulnerability is tracked as CVE-2026-21962 and it has been widely exploited by threat actors against WebLogic servers. The post CISA Warns of Exploited Oracle WebLogic Vulnerability appeared first on SecurityWeek.
> Fake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown
WeedHack Minecraft Malware Survives C2 Takedown: Fake Client Sites Still Active, SEO Poisoning Puts Malicious Downloads at the Top of Google McAfee Labs published a follow-up report on the WeedHack Malware-as-a-Service campaign this week, documenting ten active malicious sites and multiple file-host...
> A Note on Pentesting Passkeys
Some months ago, I performed a web application penetration test on an application that used passkey for authentication. As part of the assessment, I also tested the passkey implementation and noticed some unusual behavior. During the debugging process, I created two short JavaScript helper functions...
> NIS 2 : pourquoi la connexion à Windows reste l’angle mort de vos accès
NIS 2 oblige-t-il le MFA pour la connexion Windows ? Découvrez les exigences et une approche non invasive via Specops Secure Access pour ajouter du MFA à l'AD. Le post NIS 2 : pourquoi la connexion à Windows reste l’angle mort de vos accès a été publié sur IT-Connect.
> Impression et export PDF cassés sur Windows : les mises à jour .NET d’août 2026 en cause
Microsoft confirme que les mises à jour .NET Framework d'août 2026 cassent l'impression et l'export PDF des applications WPF. Une solution temporaire existe. Le post Impression et export PDF cassés sur Windows : les mises à jour .NET d’août 2026 en cause a été publié sur IT-Connect.
> Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2...
> AI supply chain risk is showing up in developer workflows first
In this Help Net Security interview, Dr. Jaushin Lee, CEO of Zentera Systems, discusses where AI supply chain risk shows up. He says most incidents still hit developer workflows and open-source package repositories, while poisoned model weights and compromised MCP servers stay mostly in research dem...
> Windows : la signature de code passe au post-quantique, vos applis sont-elles prĂŞtes ?
Microsoft renforce la signature de code de Windows : nouvelle autorité en octobre 2026, RSA-3072 et SHA-384 fin 2026, puis post-quantique par défaut en 2027. Le post Windows : la signature de code passe au post-quantique, vos applis sont-elles prêtes ? a été publié sur IT-Connect.
> TruffleHog AWS Analyze reduces remediation time on leaked AWS credentials
Truffle Security announced TruffleHog AWS Analyze, a new addition to TruffleHog Enterprise. TruffleHog AWS Analyze enriches found AWS credentials to highlight permissions and access levels, so a security team can assess the risk and prioritize its response. TruffleHog Enterprise already finds and ve...
> HOL Guard: Open-source antivirus for AI agents
HOL Guard is a free, open-source tool that sits between an AI assistant and the computer it runs on. When the assistant tries something risky, the tool pauses it and asks you first. It installs in about a minute, runs on your own machine, and a typical check takes under 50 milliseconds. Your files a...
> Metal Gear Online 3 : rejoindre un salon Steam suffisait à faire exécuter du code sur votre PC
Le CERT/CC a révélé la CVE-2026-19874, une faille de Metal Gear Online 3 qui permettait à l'hôte d'un lobby Steam d'exécuter du code sur le PC des joueurs. Le post Metal Gear Online 3 : rejoindre un salon Steam suffisait à faire exécuter du code sur votre PC a été publié sur IT-Connect.
> The cybercrime supply chain has five stages, each with a price
In this Help Net Security video, Chris Nyhuis, CEO at Vigilant, explains why the picture of a lone ransomware attacker is about 15 years out of date. He walks through the cybercrime supply chain and the five businesses inside it: harvesters who run infostealer malware, brokers who verify and resell...
> Debian Erlang Multiple Issues Denial of Service 2026-6464-1
Debian advises users to upgrade erlang packages due to multiple vulnerabilities that could lead to denial of service, information disclosure, and code execution, affecting various components.
> New TCG guidance gives buyers a way to test PQC-ready TPM claims
The Trusted Computing Group has published requirements that spell out what a Trusted Platform Module has to do before anyone calls it quantum-safe. A TPM is the chip that holds a machine’s keys and records measurements of its firmware, so the platform can later prove it has not been altered. Buyers...
> Cybersecurity jobs available right now: August 25, 2026
Specialist Compliance Security AT&T | USA | On-site – View job details As a Specialist Compliance Security, you will serve as AT&T’s liaison for law enforcement, first responders, and emergency personnel nationwide. Respond 24×7 to emergency requests, process subpoenas, warrants, and court o...
> ISC Stormcast For Tuesday, August 25th, 2026 https://isc.sans.edu/podcastdetail/10066, (Tue, Aug 25th)