> TODAY'S SUMMARY (122 articles)
Today's cybersecurity landscape highlights several critical threats and trends. The Canadian regulator is investigating IDScan for potential data privacy violations, while the ransomware PAYLOAD has demonstrated a new tactic, paralyzing an organization without file encryption. Volexity reported a China-aligned threat group exploiting vulnerabilities in Chrome and Microsoft software. The hacking group ShinyHunters claims to have breached the FBI, raising significant counterintelligence concerns. Additionally, ClosedQuorum malware is leveraging AI for attack decisions, indicating a trend towards more sophisticated, autonomous threats. CISA has urged federal agencies to patch a critical Zyxel flaw actively exploited by attackers. Meanwhile, the rise of AI in cybercrime continues, with deepfakes and AI-driven bots posing increasing risks to organizations.
|
// AI-powered summary generated at 20:01
A vulnerability in SPIP could allow unauthenticated remote code execution; it has been fixed in version 4.4.21+dfsg-0+deb13u1 for the stable distribution.
UMass Amherst researchers showed expired Visa contactless cards can make real purchases by exploiting an unsigned expiry field in Visa’s EMV kernel. Researchers at the University of Massachusetts Amherst demonstrated at USENIX Security 2026 in Baltimore that expired Visa contactless credit cards can...
A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen. [...]
This sort of research is both exciting and terrifying:
The two models in question were told to generate complete genomes for a viable bacteriophage—a type of virus able to infect and replicate itself inside bacteria, destroying them from the inside.
Using an existing bacteriophage as an example—ΦX17...
Ukrainian hacktivists exploiting the bugs, but TrueConf's reach stretches well beyond home turf
The newly-formed Nakasone Group will counsel government leaders, corporations, prominent families, and other private clients confronting cybersecurity, geopolitical, and personal security risks.
The post Former NSA Director Paul Nakasone Launches National Security Advisory Firm appeared first on Sec...
L'Agence pour la protection des données personnelles croate (AZOP) a émis un avis sur l'équilibre entre la transparence des réunions d'un conseil d'établissement scolaire et la protection des données lors de la nomination d'un directeur.Saisie d'une demande concernant la présence du public lors d'un...
L'Agence pour la protection des données personnelles (AZOP) a émis un avis de principe sur les modalités de communication de la documentation d'un processus de recrutement à un candidat non retenu.Saisie de la demande d'une candidate au poste de directeur d'école souhaitant obtenir copie de la docum...
The bank said there is no evidence that its own systems, networks or data repositories were compromised.
L'autorité danoise de protection des données réitère sa position ferme selon laquelle les difficultés organisationnelles internes, telles que le manque de ressources ou un arriéré de dossiers, ne constituent pas une justification valable pour le non-respect des délais de réponse aux demandes de droi...
Escape Data ZATAZ 2.0 mêle escape game, OSINT, observation et réflexes cyber dans une enquête numérique estivale.
This week, EFF, along with Big Brother Watch, Defend Digital Me, Liberty, Open Rights Group, Race Equality First, Statewatch, and Stopwatch, wrote to Nottinghamshire Police Force in the UK raising concern about the proposed roll-out of live facial recognition technology (LFR), and called for its imm...
Cyberattaque : des données de clients Pokémon Center exposées et certaines précommandes annulées en Europe.
More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid. [...]
Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no...
On August 10th, 2026, we received a submission for an Unauthenticated Privilege Escalation vulnerability in Pods, a WordPress plugin with more than 100,000 active installations. This vulnerability allows unauthenticated attackers to escalate their privileges to administrator and perform various admi...
Citrix a corrigé deux vulnérabilités dans NetScaler ADC et Gateway. La CVE-2026-19490 ouvre la porte à un contournement de l'authentification à distance.
Le post Citrix NetScaler (CVE-2026-19490) : cette faille critique permet de contourner l’authentification a été publié sur IT-Connect.
Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun.
Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage downloader to enable ad fra...
Un pirate renvendique le vol de codes sources à un géant de la grande distribution, sur fond d’une précédente fuite interne.
Un vendeur propose des bases de joueurs de casino européens contenant coordonnées, téléphones et données de dépôt.