> TODAY'S SUMMARY (122 articles)
Today's cybersecurity landscape highlights several critical threats and trends. The Canadian regulator is investigating IDScan for potential data privacy violations, while the ransomware PAYLOAD has demonstrated a new tactic, paralyzing an organization without file encryption. Volexity reported a China-aligned threat group exploiting vulnerabilities in Chrome and Microsoft software. The hacking group ShinyHunters claims to have breached the FBI, raising significant counterintelligence concerns. Additionally, ClosedQuorum malware is leveraging AI for attack decisions, indicating a trend towards more sophisticated, autonomous threats. CISA has urged federal agencies to patch a critical Zyxel flaw actively exploited by attackers. Meanwhile, the rise of AI in cybercrime continues, with deepfakes and AI-driven bots posing increasing risks to organizations.
|
// AI-powered summary generated at 20:01
Un membre d’un forum pirate russe recrute des francophones pour un VPN, malgré un historique lié au spam et aux RAT.
Microsoft a corrigé la CVE-2026-69836, une faille critique dans Entra ID déjà exploitée dans la nature. La bonne nouvelle : vous n'avez rien à faire.
Le post Entra ID : une faille critique a été exploitée, mais vous n’avez rien à patcher a été publié sur IT-Connect.
The statement came a day after a hacking group calling itself Black Spark claimed it had spent more than a month inside Microolap’s network and gained access to its internal systems, including EtherSensor, the company's network traffic analysis platform.
Every other web platform feature I've ever written about, I've been able to test in some easy way. Open DevTools, type the name of the thing, see if it's there. Device Bound Session Credentials doesn't work like that: there is no way
Microsoft has started rolling out a Classic Outlook theme for users of Outlook on the web and the New Outlook for Windows. [...]
The private equity giant confirms a breach, weeks after Google researchers said hackers were targeting financial companies.
Learn the psychological mechanics behind social engineering attacks and what resistance looks like in practice.
Un forum pirate propose deux millions de données françaises, sans preuve publique sur leur origine.
Senator Ron Wyden sent a letter to the U.S. federal watchdog requesting a comprehensive review of how the FBI, DEA, ICE's HSI, and the Secret Service use hacking tools and spyware against Americans.
U.S. indicts Iranian cyber espionage operations, Medusa ransomware breaches 500 organizations, and attackers exploit a critical Windows protocol flaw.
C.Hunters propose des appels ciblés sur un forum pirate, avec un intérêt explicite pour la France.
Cybersecurity researchers have linked a malicious backdoor in compromised Rust packages to previous North Korean supply chain attacks
Cisco patched nine critical flaws, including six rated CVSS 10.0, found during internal testing. None are known to be exploited. Cisco released another batch of security fixes for its Crosswork platforms and Secure Workload software, part of what it’s calling an ongoing internal security review, and...
The type confusion bug can lead to V8 sandbox escape and control-flow hijacking of the host process.
The post Critical Isolated-vm Vulnerability Leads to RCE on Host appeared first on SecurityWeek.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communications platform. [...]
Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE Researchers at Endor Labs disclosed a critical vulnerability in isolated-vm, a popular open-source sandbox with nearly a million weekly npm downloads used to run untrusted JavaScript inside an isolated V8 engine instance. A...
Microsoft has patched a critical remote code execution vulnerability (CVE-2026-69836) in Entra ID, reportedly exploited in the wild. Entra ID is Microsoft’s cloud identity service, formerly Azure Active Directory, that verifies logins and controls access to Microsoft 365, Azure, and connected third-...
Un nouvel acteur du rançongiciel, SovCali, apparaît et affirme détenir des données de Lucid Motors, première cible publiquement revendiquée.
An Agent Tesla v4 malware campaign used novel emoji-based code obfuscation to evade detection, KnowBe4 has revealed
Healthcare technology provider CareCloud confirmed that 3.75 million people were affected by a March data breach.