[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (3 articles)

|

// AI-powered summary generated at 08:00

> Multiples vulnérabilités dans Oracle Virtualization (16 septembre 2026)
De multiples vulnérabilités ont été découvertes dans Oracle Virtualization. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.
> Oracle Linux 8 Kernel Important Security Update ELSA-2026-66000-0
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
> Oracle Linux 8 ELSA-2026-67145-0 Gstreamer1-Plugins-Base Moderate Patch
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
> AWS STS simplifies session token size limits and adds session token size monitoring
AWS Security Token Service (AWS STS) has simplified session token size limits, giving you more room for your session policies and session tags. STS has replaced the packed policy size and the overall session token size limits with a single token size limit of 4,096 bytes. STS now reports session tok...
> Oracle git-lfs Important Security Update ELSA-2026-67161-0
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
> Oracle Linux 8 libkcapi Moderate Memory Corruption DoS Fix ELSA-2026-67266
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
> The vulnpocalypse rains iBugs down on Apple with record-setting number of patches
September Patch Tuesday part 2?
> Oracle 8 perl-YAML-Syck Important Memory Safety Fix ELSA-2026-67269-0
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
> Acronis warns of actively exploited flaw in its cPanel backup plugin
Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]
> U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), t...
> Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]
> Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?
Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.
> Norway announces investigations into telecom Telenor’s work with Myanmar junta
Oslo-based Telenor potentially enabled crimes against humanity and violated sanctions in its dealings with the military regime that took over Myanmar in 2021, Norwegian authorities said.
> Critical Cisco Secure Email Gateway zero-day gives attackers root access
Cisco released emergency patches for a critical vulnerability in its Secure Email Gateway appliance that could allow attackers to take over the device by simply sending malicious crafted emails to users. The flaw was already being exploited in the wild when the fixes were rele...
> Boost Engagement with Free Passkeys by Wordfence
Wordfence 9 introduces passkeys, and passkeys provide a huge friction reduction because your user no longer has to remember their password or retrieve it from a password manager and copy/paste. The post Boost Engagement with Free Passkeys by Wordfence appeared first on Wordfence.
> AKI - autorité estonienne
L'autorité estonienne de protection des données (Andmekaitse Inspektsioon - AKI) annonce la tenue d'une conférence sur l'articulation entre l'accès à l'information publique, l'utilisation des données ouvertes et la protection des données personnelles.Le 21 octobre 2026, en collaboration avec le Mini...
> AZOP - autorité croate
L'autorité croate de protection des données (AZOP) a clarifié l’étendue du droit d’accès d’un patient à l’identité du personnel hospitalier ayant consulté son dossier médical via le système d’information hospitalier.Saisie d'une question sur la communication des journaux d'accès aux dossiers médicau...
> Debian cjose Critical Denial of Service and Code Execution DSA-6499-1
Two vulnerabilities were discovered in cjose, a C library implementing the JOSE standard, which could result in denial of service, execution of arbitrary code or plain text recovery in specific setups. For the stable distribution (trixie), these problems have been fixed in version 0.6.2.3-1+deb13u1.
> UODO - autorité polonaise
La Cour administrative suprême de Pologne a confirmé la position de l'autorité de protection des données (UODO) selon laquelle les garanties prévues par le droit bancaire polonais en matière de traitement des données après l'extinction d'une obligation financière s'appliquent non seulement aux conso...
> AP - autorité néerlandaise
L'Autorité des données personnelles (AP) des Pays-Bas a publié des modèles pratiques destinés aux petites et moyennes entreprises pour faciliter leur mise en conformité avec les règles de protection des données.L'autorité a mis à disposition un modèle de registre des activités de traitement et un mo...