[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (1 articles)

|

// AI-powered summary generated at 08:00

> Lycées de la région des Hauts-de-France
Une attaque de rançongiciel impliquant l'enseigne Qilin a touché prÚs de 80% des lycées publics de la région des Hauts-de-France, mais les cours continuent malgré la suspension temporaire de l'accÚs à Internet. Les équipes techniques travaillent à contenir l'attaque et à sécuriser les infrastructure...
> Kelly Legal
Les hackers du groupe INC Ransom ont revendiqué avoir volé plus de 400 gigaoctets d'informations de Kelly Legal, dont des fichiers RH, aprÚs un incident de piratage en octobre. Les hackers ont publié une fuite sur leur site darknet le 13 novembre, décrivant l'entreprise et ses revenus estimés. Kelly...
> Ubuntu 18.04: Vim Important Denial of Service USN-7815-1 CVE-2025-24014
Vim could be made to crash if it received specially crafted input.
> Stoss Landscape Urbanism
An unauthorized third party gained access to Stoss Landscape Urbanism's network on September 14, 2025, and took certain files, potentially exposing personal information. A cyberattack was claimed by Akira on November 19.
> Ubuntu 24.04: LibHTP Important DoS Issues CVE-2025-53537 USN-7814-1
Several security issues were fixed in LibHTP.
> Slackware 15.0: python3 Critical Security Update SSA:2025-282-01
New python3 packages are available for Slackware 15.0 and -current to fix security issues.
> When AI Remembers Too Much – Persistent Behaviors in Agents’ Memory
Indirect prompt injection can poison long-term AI agent memory, allowing injected instructions to persist and potentially exfiltrate conversation history. The post When AI Remembers Too Much – Persistent Behaviors in Agents’ Memory appeared first on Unit 42.
> Discord data breach affects at least 70,000 users
The platform said in a press release that hackers breached a third-party vendor that Discord uses for age-related appeals.
> It's trivially easy to poison LLMs into spitting out gibberish, says Anthropic
Just 250 malicious training documents can poison a 13B parameter model - that's 0.00016% of a whole dataset Poisoning AI models might be way easier than previously thought if an Anthropic study is anything to go on. 

> PERA Remains a Serious Threat to Efforts Against Bad Patents
As all things old are new again, a bill that would make obtaining bad patents easier and harder to challenge is being considered in the Senate Judiciary Committee. The Patent Eligibility Restoration Act (PERA) would reverse over a decade of progress in fighting patent trolls and making the patent sy...
> Fake VPN and streaming app drops malware that drains your bank account
Mobdro Pro IP TV + VPN hides Klopatra, a new Android Trojan that lets attackers steal banking credentials.
> Introducing Sucuri Academy: Your New Destination for Website Security Education
Learn. Secure. Lead. We’re excited to introduce the beta launch of Sucuri Academy—a cutting-edge learning platform designed to empower website owners, developers, and digital professionals with the skills to defend against cyber threats. Whether you’re just starting out or looking to master advanced...
> Why don’t we sit around this computer console and have a sing-along?
Martin muses on why computers are less fun than campfires, why their dangers seem less real, and why he’s embarking on a lengthy research project to study this.
> Italian businessman’s phone reportedly targeted with Paragon spyware
The alleged targeting of prominent Italian businessman Francesco Gaetano Caltagirone now widens the Paragon spyware scandal in Italy to victims beyond journalists and activists.
> Apple Took Down These ICE-Tracking Apps. The Developers Aren't Giving Up
“We are going to do everything in our power to fight this,” says ICEBlock developer Joshua Aaron after Apple removed his app from the App Store.
> From HealthKick to GOVERSHELL: The Evolution of UTA0388's Espionage Malware
A China-aligned threat actor codenamed UTA0388 has been attributed to a series of spear-phishing campaigns targeting North America, Asia, and Europe that are designed to deliver a Go-based implant known as GOVERSHELL. "The initially observed campaigns were tailored to the targets, and the messages p...
> ‘Dozens’ of organizations had data stolen in Oracle-linked hacks
The mass-hacks targeting Oracle E-Business customers is the latest hacking campaign by Clop, an extortion group known for abusing security flaws in enterprise products to steal large amounts of sensitive data.
> Chromium: CVE-2025-11460 Use after free in Storage
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/202[SS9.1]5) for more information.
> Chromium: CVE-2025-11458 Heap buffer overflow in Sync
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/202[SS9.1]5) for more information.
> Securing agentic AI: Your guide to the Microsoft Ignite sessions catalog
​Security is a core focus at Microsoft Ignite 2025, reflected in dedicated sessions and hands-on experiences designed for security professionals and leaders. Take a look at the session catalog. The post Securing agentic AI: Your guide to the Microsoft Ignite sessions catalog appeared first on Micro...