> TODAY'S SUMMARY (3 articles)
Today's cyber news highlights significant threats and trends impacting the cybersecurity landscape. CrowdSec reported a breach where an attacker accessed and copied 170 private GitHub repositories using an ex-employee's account, emphasizing risks related to insider threats and account management. Additionally, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild and a continued focus on securing open-source software. Meanwhile, Flock is facing a decline in contracts for its license plate readers, leading to voluntary severance offerings for employees, showcasing the impact of public sentiment on technology adoption.
|
// AI-powered summary generated at 08:00
De multiples vulnérabilités ont été découvertes dans Oracle Virtualization. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
AWS Security Token Service (AWS STS) has simplified session token size limits, giving you more room for your session policies and session tags. STS has replaced the packed policy size and the overall session token size limits with a single token size limit of 4,096 bytes. STS now reports session tok...
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
September Patch Tuesday part 2?
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA)Â added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), t...
Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]
Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers.
The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.
Oslo-based Telenor potentially enabled crimes against humanity and violated sanctions in its dealings with the military regime that took over Myanmar in 2021, Norwegian authorities said.
Cisco released emergency patches for a critical vulnerability in its Secure Email Gateway appliance that could allow attackers to take over the device by simply sending malicious crafted emails to users. The flaw was already being exploited in the wild when the fixes were rele...
Wordfence 9 introduces passkeys, and passkeys provide a huge friction reduction because your user no longer has to remember their password or retrieve it from a password manager and copy/paste.
The post Boost Engagement with Free Passkeys by Wordfence appeared first on Wordfence.
L'autorité estonienne de protection des données (Andmekaitse Inspektsioon - AKI) annonce la tenue d'une conférence sur l'articulation entre l'accès à l'information publique, l'utilisation des données ouvertes et la protection des données personnelles.Le 21 octobre 2026, en collaboration avec le Mini...
L'autorité croate de protection des données (AZOP) a clarifié l’étendue du droit d’accès d’un patient à l’identité du personnel hospitalier ayant consulté son dossier médical via le système d’information hospitalier.Saisie d'une question sur la communication des journaux d'accès aux dossiers médicau...
Two vulnerabilities were discovered in cjose, a C library implementing the JOSE standard, which could result in denial of service, execution of arbitrary code or plain text recovery in specific setups. For the stable distribution (trixie), these problems have been fixed in version 0.6.2.3-1+deb13u1.
La Cour administrative suprême de Pologne a confirmé la position de l'autorité de protection des données (UODO) selon laquelle les garanties prévues par le droit bancaire polonais en matière de traitement des données après l'extinction d'une obligation financière s'appliquent non seulement aux conso...
L'Autorité des données personnelles (AP) des Pays-Bas a publié des modèles pratiques destinés aux petites et moyennes entreprises pour faciliter leur mise en conformité avec les règles de protection des données.L'autorité a mis à disposition un modèle de registre des activités de traitement et un mo...