[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> HomeRefill - 187,457 breached accounts
In April 2020, now defunct Brazilian e-commerce platform HomeRefill suffered a data breach that was later redistributed as part of a larger corpus of data. The data included 187k unique email addresses along with names, phone numbers, dates of birth and salted password hashes.
> ZDI-25-932: MLflow Weak Password Requirements Authentication Bypass Vulnerability
This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2025-11200.
> ZDI-25-931: MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of MLflow Tracking Server. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2025-11201.
> Latest Pilot Jobs - 118,864 breached accounts
In August 2022, the Latest Pilot Jobs website suffered a data breach that later appeared on a popular hacking forum before being redistributed as part of a larger corpus of data. The data included 119k unique email addresses along with names, usernames and unsalted MD5 password hashes.
> ZDI-25-930: win-cli-mcp-server resolveCommandPath Command Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of win-cli-mcp-server. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2025-11202.
> ZDI-25-929: LiteLLM Information health API_KEY Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of LiteLLM. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 3.5. The following CVEs are assigned: CVE-2025-11203.
> Ville de Fumel
La ville de Fumel a été victime d'une cyberattaque avec demande de rançon, ce qui a bloqué certains services à la population. Les agents de la ville ont trouvé un message d'erreur en anglais demandant le paiement d'une rançon pour débloquer la situation. Le maire a indiqué que la ville avait pris un...
> Administration nationale de l'éducation publique
Un incidente de ciberseguridad a affecté la plateforme GURI, qui restera hors service pendant les prochaines heures. L'incident est actuellement en cours d'investigation. Les détails de l'incident seront communiqués dès que possible.
> Chromium: CVE-2025-11215 Off by one error in V8
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/202 5) for more information.
> Affärsverken
Le kraftvärmeverk Mältan en Suède a été victime d'une cyberattaque, mais selon la police, il n'y a pas de danger pour le public et la production n'est pas affectée. Une équipe d'intervention interne a été mise en place pour enquêter sur l'incident. Les autorités suédoises sont en train d'enquêter su...
> Commune de Saint-Claude
La commune de Saint-Claude a été victime d'une cyber-attaque, paralysant les services communaux depuis vendredi en fin d'après-midi. Le maire Lucy Weck-Mirre a mis en place une cellule de crise pour gérer la situation. Les détails de l'attaque et les mesures prises pour y remédier n'ont pas été préc...
> Chromium: CVE-2025-11216 Inappropriate implementation in Storage
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/202 5) for more information.
> Chromium: CVE-2025-11209 Inappropriate implementation in Omnibox
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/202 5) for more information.
> Family group chats: Your (very last) line of cyber defense
Amy gives an homage to parents in family group chats everywhere who want their children to stay safe in this wild world.
> Chromium: CVE-2025-11213 Inappropriate implementation in Omnibox
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/202 5) for more information.
> Chromium: CVE-2025-11210 Side-channel information leakage in Tab
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/202 5) for more information.
> Subpoena tracking platform blames outage on AWS social engineering attack
Software maker Kodex said its domain registrar fell for a fraudulent legal order A software platform used by law enforcement agencies and major tech companies to manage subpoenas and data requests went dark this week after attackers socially engineered AWS into freezing its domain.…
> Chromium: CVE-2025-11219 Use after free in V8
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/202 5) for more information.
> Chromium: CVE-2025-11212 Inappropriate implementation in Media
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/202 5) for more information.
> Tips to Protect Your Posts About Reproductive Health From Being Removed
This is the ninth installment in a blog series documenting EFF’s findings from the Stop Censoring Abortion campaign. You can read additional posts here.   Meta has been getting content moderation wrong for years, like most platforms that host user-generated content. Sometimes it’s a result of del...