[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (122 articles)

|

// AI-powered summary generated at 20:01

> Multiples vulnérabilités dans Cisco IOS XE (25 août 2026)
De multiples vulnérabilités ont été découvertes dans Cisco IOS XE. Elles permettent à un attaquant de provoquer un contournement de la politique de sécurité et un problÚme de sécurité non spécifié par l'éditeur.
> Multiples vulnérabilités dans Keycloak (25 août 2026)
De multiples vulnérabilités ont été découvertes dans Keycloak. Elles permettent à un attaquant de provoquer un contournement de la politique de sécurité et un problÚme de sécurité non spécifié par l'éditeur. Le CERT-FR a connaissance d'une preuve de concept publique pour la vulnérabilité...
> US sanctions Iranian cyber actors as UK discloses power plant attack
The U.S. sanctioned several Iranian nationals for cyberattacks on critical infrastructure just days after reports emerged of a cyber intrusion on a small power plant in the United Kingdom.
> SCOTUS tosses one of two injunctions against Trump USPS mail-in ballot rules
The 6-3 decision dismisses one lawsuit brought by states, saying they have no standing to sue because the disputed sections “neither requires nor forbids anything of anyone outside the executive branch.” The post SCOTUS tosses one of two injunctions against Trump USPS mail-in ballot rules appeared f...
> Third-Party Script Security: How Tags, Pixels, and Embeds Can Put Websites at Risk
Third-party scripts are common on websites. They help with analytics, ads, live chat, social media, video, payments, and many other features. While not all are risky, every external tag, pixel, widget, or embed adds to your website’s vulnerability. These tools can read page content, collect visitor...
> You don't want this Sleepwalker backdoor on your Windows machine
Its own command language, 23 instructions - signs point to 'well-resourced operation rather than an opportunistic one'
> Unpatched Calix flaw lets hackers bypass NAT to expose internal devices
An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated attackers to create port-forwarding rules that can expose local network devices to the public internet. [...]
> Browser fingerprint tool shows how easy you are to track using the latest sneaky tricks
Glassbox dev admits he had some help from Claude to build locally running tool
> New Zealand to pursue social media ban for children under 16
The legislation would mandate that high-risk social media platforms such as Instagram, TikTok, Snapchat and Facebook take “reasonable steps” to ensure users are over age 16 by using tools like facial age estimation, digital ID services, formal IDs and existing account information for verification.
> Ubuntu 24.04 curl Important Info Exposure Vuln USN-8670-1 CVE-2026-8932
A curl vulnerability in Ubuntu 24.04 LTS could lead to exposure of sensitive information due to improper handling of connection reuse with changed client certificate settings.
> Ubuntu 24.04 LTS FFmpeg Denial of Service Critical Code Execution Risks
Ubuntu issued a security notice regarding FFmpeg vulnerabilities affecting several releases. Users are advised to update their systems to fix potential denial of service and information disclosure issues.
> Alabama launches investigation into OpenAI’s hack of Hugging Face
Weeks after OpenAI disclosed that one of its cybersecurity models had gone rogue and hacked AI dataset company Hugging Face, Alabama’s Attorney General announced an investigation into the incident.
> Ubuntu 26.04 AsyncHttpClient Important Information Exposure CVE-2026-55688
Ubuntu has released a security notice regarding the AsyncHttpClient vulnerability that could expose sensitive information, affecting several LTS releases. Users are advised to update their systems.
> Hackers target WordPress sites in miniOrange auth bypass attacks
Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. [...]
> Treasury sanctions alleged Iranian hackers as part of ‘economic D-Day’
It’s a follow-up to an indictment the Justice Department unsealed last week against people affiliated with the Mabna Institute. The post Treasury sanctions alleged Iranian hackers as part of ‘economic D-Day’ appeared first on CyberScoop.
> Bipartisan Senate bill aims to prepare energy sector for Q-Day
Under the bill, FERC would consider cyber threats from quantum computers and post-quantum cryptography in its reliability standards for the energy sector.  The post Bipartisan Senate bill aims to prepare energy sector for Q-Day appeared first on CyberScoop.
> The Cloudflare Blog – Brought to you by EmDash
We migrated the Cloudflare Blog to EmDash to prove our stack at massive scale. Here is how we stress-tested performance, safely routed production traffic, and redesigned the frontend experience.
> Indian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderly
A Jersey City resident is facing charges for his alleged role as a money mule for overseas cyberscammers who stole millions from elderly New Yorkers.
> Instinct’s powerful AI assistant is raising privacy and security concerns
Early testers are raving about what Instinct can do, but some say the AI assistant’s sweeping access, broad terms and ability to act on users’ behalf come with uncomfortable trade-offs.
> TikTok reaches $400M settlement with US over COPPA violations
The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children's Online Privacy Protection Act (COPPA). [...]