[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (122 articles)

|

// AI-powered summary generated at 20:01

> Checker max cible les portefeuilles Solana en masse
Checker max analyse Solana par lots de 1 000 adresses, une capacité sensible pour le triage de portefeuilles proposé sur un forum de pirates.
> In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug
Other noteworthy stories that might have slipped under the radar: Threema DDoS attack, Evooo1Bot Linux botnet, Crypto4A secures top-tier NIST certification. The post In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug appeared first on SecurityWeek.
> Keycloak : cette faille critique permet de pirater un compte via la fonction de mot de passe oublié
La faille CVE-2026-18963 permet de réinitialiser le mot de passe de n'importe quel compte Keycloak sans authentification. Un patch est disponible. Le post Keycloak : cette faille critique permet de pirater un compte via la fonction de mot de passe oublié a été publié sur IT-Connect.
> Lawmakers seek watchdog review of federal hacking of Americans
Sen. Ron Wyden and Rep. Greg Casar want a GAO probe on the government’s use of spyware and other sophisticated hacking tools and authorities. The post Lawmakers seek watchdog review of federal hacking of Americans appeared first on CyberScoop.
> Oracle Linux 10 Java-21-OpenJDK Moderate Threat Advisory ELSA-2026-55787
Oracle has released multiple updated RPM packages for Oracle Linux 10, addressing several CVEs and including various versions of Java 21 OpenJDK with enhancements and fixes.
> Oracle Linux 10 java-25-openjdk Medium Update For ELSA-2026-55798
Oracle Linux has released updated Java packages for version 10 to address several CVEs, including CVE-2026-60589 and others, with a detailed list of RPMs provided.
> Canada’s Hospital for Sick Children attacked by cybercriminals again as employee data stolen
The Hospital for Sick Children — which was hit in a ransomware incident in 2022 that disabled some of its systems — released a statement on Thursday warning of a data theft incident they believe is tied to a third-party software application.
> Oracle Linux 10 ansible-core Important Remote Access Fix ELSA-2026-57148
Oracle Linux 10 updates include versions of ansible-core and ansible-test that address CVE-2026-11332, which involved potential arbitrary git configuration injection during role installation.
> Oracle Linux 10 Kernel Important Bug Fixes Advisory ELSA-2026-57251
Oracle Linux has released several kernel updates addressing multiple CVEs, including security enhancements and fixes for various stability and performance issues in its 10th version.
> Hackers poison popular Rust crates to steal developers' credentials
Malicious updates turned routine builds into a delivery system for infostealer malware
> Oracle Linux 10 kbd Moderate Threat Fix ELSA-2026-57597
Oracle Linux released updates for version 10, addressing CVE-2026-72693 with enhancements to the openvt process matching. New RPMs are available for x86_64 and aarch64 architectures.
> Microsoft blames Windows gaming issues on RGB lighting devices
Microsoft says ongoing issues causing games to crash or fail to launch after installing the August 2026 Windows updates may be caused by peripherals with RGB lighting. [...]
> DYSPHOR1A, nouveau groupe de ransomware maître chanteur
DYSPHOR1A émerge comme un nouveau groupe ransomware maître chanteur, avec ventes, fuites et retraits payants de données.
> Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini
Researchers say the new ‘Cryptographic Context Injection’ technique conceals malicious instructions until they are decrypted inside a trusted execution environment. The post Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini appeared first on SecurityWeek.
> Malware in car infotainment systems: how infection occurs | Kaspersky official blog
Kaspersky experts have discovered a trojan that infects car head units and makes them part of a botnet. Here’s how the infection works.
> New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets
Researchers say iAuthFlow V2 can register an attacker-controlled passkey, enabling persistent access even after passwords are changed and active sessions revoked. The post New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets appeared first on SecurityWeek.
> Endstate : sauvegarder et restaurer ses applications Windows (et leurs configs) sur un nouveau PC
Découvrez Endstate, un outil open source qui sauvegarde les applications et les réglages d'un PC Windows dans un fichier, puis les restaure sur un nouveau PC. Le post Endstate : sauvegarder et restaurer ses applications Windows (et leurs configs) sur un nouveau PC a été publié sur IT-Connect.
> Business email compromise: How to protect your organization from CEO fraud
Business email compromise attacks don't rely on links or malware. Learn how they work and the controls that stop them.
> Zombie Card: An expired Visa credit card can be used for purchases
Scientific research showed that the expiration date on some Visa credit cards can be manipulated in so-called Zombie Card attacks.
> Is Online Privacy Possible? How Digital Identities Can Help
Using the same email, phone number, payment method, and other identifiers makes it easier for data brokers and attackers to profile your activity. Anonyome Labs explains how separate digital personas can reduce correlation and limit the impact of breaches, spam, and identity theft. [...]