[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (122 articles)

|

// AI-powered summary generated at 20:01

> Debian SPIP Critical Remote Code Execution Vuln DSA-6456-1
A vulnerability in SPIP could allow unauthenticated remote code execution; it has been fixed in version 4.4.21+dfsg-0+deb13u1 for the stable distribution.
> Your Shredded Visa Card May Still Work at the Checkout
UMass Amherst researchers showed expired Visa contactless cards can make real purchases by exploiting an unsigned expiry field in Visa’s EMV kernel. Researchers at the University of Massachusetts Amherst demonstrated at USENIX Security 2026 in Baltimore that expired Visa contactless credit cards can...
> New SynkLoader malware pushed in Microsoft Teams phishing campaign
A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen. [...]
> AI Is Learning to Write Genetic Code
This sort of research is both exciting and terrifying: The two models in question were told to generate complete genomes for a viable bacteriophage—a type of virus able to infect and replicate itself inside bacteria, destroying them from the inside. Using an existing bacteriophage as an example—ΦX17...
> Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it
Ukrainian hacktivists exploiting the bugs, but TrueConf's reach stretches well beyond home turf
> Former NSA Director Paul Nakasone Launches National Security Advisory Firm
The newly-formed Nakasone Group will counsel government leaders, corporations, prominent families, and other private clients confronting cybersecurity, geopolitical, and personal security risks. The post Former NSA Director Paul Nakasone Launches National Security Advisory Firm appeared first on Sec...
> AZOP - autorité croate
L'Agence pour la protection des données personnelles croate (AZOP) a émis un avis sur l'équilibre entre la transparence des réunions d'un conseil d'établissement scolaire et la protection des données lors de la nomination d'un directeur.Saisie d'une demande concernant la présence du public lors d'un...
> AZOP - autorité croate
L'Agence pour la protection des données personnelles (AZOP) a émis un avis de principe sur les modalités de communication de la documentation d'un processus de recrutement à un candidat non retenu.Saisie de la demande d'une candidate au poste de directeur d'école souhaitant obtenir copie de la docum...
> U.S. Bank says breach claims related to fourth-party incident
The bank said there is no evidence that its own systems, networks or data repositories were compromised.
> Datatilsynet - autorité danoise
L'autorité danoise de protection des données réitère sa position ferme selon laquelle les difficultés organisationnelles internes, telles que le manque de ressources ou un arriéré de dossiers, ne constituent pas une justification valable pour le non-respect des délais de réponse aux demandes de droi...
> Escape Data ZATAZ 2.0 transforme l’enquête en jeu
Escape Data ZATAZ 2.0 mêle escape game, OSINT, observation et réflexes cyber dans une enquête numérique estivale.
> EFF and Civil Society Groups Call on Nottinghamshire Police to Halt Live Face Recognition
This week, EFF, along with Big Brother Watch, Defend Digital Me, Liberty, Open Rights Group, Race Equality First, Statewatch, and Stopwatch, wrote to Nottinghamshire Police Force in the UK raising concern about the proposed roll-out of live facial recognition technology (LFR), and called for its imm...
> Pokémon Center touché par la cyberattaque d’un prestataire
Cyberattaque : des données de clients Pokémon Center exposées et certaines précommandes annulées en Europe.
> Hundreds of leaked AWS keys give full control over corporate accounts
More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid. [...]
> Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no...
> 100,000 WordPress Sites Affected by Privilege Escalation Vulnerability in Pods WordPress Plugin
On August 10th, 2026, we received a submission for an Unauthenticated Privilege Escalation vulnerability in Pods, a WordPress plugin with more than 100,000 active installations. This vulnerability allows unauthenticated attackers to escalate their privileges to administrator and perform various admi...
> Citrix NetScaler (CVE-2026-19490) : cette faille critique permet de contourner l’authentification
Citrix a corrigé deux vulnérabilités dans NetScaler ADC et Gateway. La CVE-2026-19490 ouvre la porte à un contournement de l'authentification à distance. Le post Citrix NetScaler (CVE-2026-19490) : cette faille critique permet de contourner l’authentification a été publié sur IT-Connect.
> Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage downloader to enable ad fra...
> Target visé par une nouvelle revendication de fuite
Un pirate renvendique le vol de codes sources à un géant de la grande distribution, sur fond d’une précédente fuite interne.
> Des bases de joueurs européens de casino diffusées sur un forum pirate
Un vendeur propose des bases de joueurs de casino européens contenant coordonnées, téléphones et données de dépôt.