> TODAY'S SUMMARY (122 articles)
Today's cybersecurity landscape highlights several critical threats and trends. The Canadian regulator is investigating IDScan for potential data privacy violations, while the ransomware PAYLOAD has demonstrated a new tactic, paralyzing an organization without file encryption. Volexity reported a China-aligned threat group exploiting vulnerabilities in Chrome and Microsoft software. The hacking group ShinyHunters claims to have breached the FBI, raising significant counterintelligence concerns. Additionally, ClosedQuorum malware is leveraging AI for attack decisions, indicating a trend towards more sophisticated, autonomous threats. CISA has urged federal agencies to patch a critical Zyxel flaw actively exploited by attackers. Meanwhile, the rise of AI in cybercrime continues, with deepfakes and AI-driven bots posing increasing risks to organizations.
|
// AI-powered summary generated at 20:01
Rentrée 2026 : faux paiements, fournitures, aides, licences et stages deviennent des vecteurs privilégiés d’arnaques cyber.
Plus: Apple sends out an “unprecedented” number of spyware warnings, Ukraine hits a Russian ecommerce giant with cyber and drone attacks, and more.
Une chemise vendue 10 € sur Vinted devait être une formalité. En quelques appels, une famille voit pourtant ses comptes basculer dans une mécanique d’escroquerie redoutable. Une adolescente crée un compte Vinted pour vendre une chemise à 10 €. Un message attribué à « Julie », probablement sous une i...
Un pirate revendique la copie de 7,3 millions de profils Chess.com, dont quatre millions de mails.
Malware is abusing car infotainment updates to install proxy software, turning Android head units into nodes for the BADBOX network. Kaspersky researchers found something in June 2026 that made them stop and look twice: an Android app with no interface at all, installed like any ordinary app but mak...
LockBit 5.0 menace de publier fin août des documents attribués à Actua concernant plus de 100 000 personnes.
Corée du Sud : une agence de certification piratée aurait exposé les coordonnées de responsables présidentiels.
The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware.
The post Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight appeared first on SecurityWeek.
Ransomware en France : le nombre de cyberattaques de 2025 déjà dépassé en août 2026.
A critical flaw (CVSS 9.4) in NASA/JPL’s AIT-GUI let anyone send unauthenticated commands to spacecraft instruments. Cycode researchers found that AIT-GUI, the browser-based operator console in NASA/JPL open-source AMMOS Instrument Toolkit, shipped with no authentication, no session checks, and no C...
In mid-2026, hundreds of thousands of user records allegedly sourced from Golf Canada began circulating via Telegram. The data included 569k unique email addresses along with names, usernames, dates of birth, genders and approximate geographic locations (city, province and postcode). Golf Canada did...
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the Zimbra Collaboration Suite (ZCS) flaw CVE-2026-73570 to its Known Exploit...
Le prestataire informatique BMS Engineering, qui héberge des données de santé sensibles pour de nombreux cabinets médicaux au Luxembourg, a été victime d'une cyberattaque majeure. L'incident, détecté le 22 août 2026, a provoqué la paralysie des services digitaux et la perte ou corruption de données...
Quarantining leaked credentials is not good enough
Cloudflare's new Bot Preference Sync automatically aligns your robots.txt file with your AI bot policies for Search, Agent, and Training. Easily manage which bots access your content without maintaining static files.
Attackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security controls
The post Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain appeared first on Unit 42.
Ubuntu released an update addressing security vulnerabilities in the Linux kernel for version 22.04 LTS, requiring users to reboot and possibly recompile third-party kernel modules.
Ubuntu 22.04 LTS received updates addressing multiple Linux kernel vulnerabilities, including issues in network drivers and file systems that could allow system compromise by attackers.
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Open vSwitch;
- SCTP protocol;
(CVE-2026-53224, CVE-2026-53246, CVE-2026-64531)
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi
implementation in the Linux kernel did not properly handle aggregated
frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A
physically proximate attacker could use this issue to inject packets.
(CVE-2025-27558...