Healthcare technology provider CareCloud confirmed that 3.75 million people were affected by a March data breach.
Attackers are impersonating popular AI brands like Perplexity, Claude, ChatGPT, and Copilot to spread information stealers, backdoors, malicious browser extensions, and other malware, according to Sophos. Overview of MDR cases with AI involvement (Source: Sophos) Sophos X-Ops reviewed 12 months of m...
Artificial Intelligence (AI) has become one of this decade's defining technologies. From healthcare and finance to manufacturing and education, organizations increasingly rely on AI to automate repetitive tasks, uncover patterns hidden within large datasets, and support faster decision-making. Cyber...
Google tracks three Russia-linked espionage clusters using phishing and legitimate authentication tools to target researchers, diplomats and defense staff. Google’s Threat Intelligence Group tracked three separate suspected Russia-linked cyber espionage clusters. All three focus on the same thing: a...
Microsoft has patched a maximum-severity vulnerability in the Entra ID identity and access management (IAM) platform that has been exploited in attacks. [...]
Threat actors are abusing FTP banners to hide commands that deliver two previously undocumented remote access trojans named E4del and PINHOLE. [...]
Discover what’s new on Forensic Focus – explore UK police well-being funding, BitLocker decryption, protecting investigators working on child safeguarding cases, and more.
Trois bases liées à la maternité et la puériculture sont revendiquées en 2026, dont Made in Bébé, Allobébé et Babyvista.
Toronto's Hospital for Sick Children (SickKids) says a cybersecurity incident exposed the personal information of some current and former employees and job applicants, stemming from a flaw in third-party software. Clinical systems and patient records were not affected. (264) [...]
Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review.
Four of the security vulnerabilities affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, regardl...
GitLab flaw CVE-2026-19478 is now under active exploitation, allowing unauthenticated attackers to modify or delete public projects. WatchTowr researchers warn of active exploitation of critical GitLab flaw CVE-2026-19478 (CVSS score of 9.4). This week, GitLab pushed out an emergency patch to addres...
OpenAI is adding a new safety capability that allows enterprises to detect misuse of its AI systems across multiple interactions without retaining prompts or responses, enabling risk monitoring while preserving its Zero Data Retention (ZDR) commitments.
“OpenAI does not ret...
The AI Security Institute has a new report of AI systems engaging in “unsanctioned behavior”—what I have been calling “genie behavior—while being tested on their cybersecurity capabilities.
The incident stemmed from a single evaluation where agents were given a task of solving a cyber security chall...
Malicious versions of three Rust packages, including the widely used arrayref, were published to the crates.io registry on August 20, carrying a backdoor that executed automatically when affected projects were compiled.
Security researchers at Wiz said the attack also share...
Graft, outil open source signé Nanonets, transforme votre dépôt en graphe Markdown lisible par Claude Code, Cursor ou Codex. De quoi brûler moins de tokens.
Le post Graft, l’outil open source qui cartographie votre code pour les agents IA a été publié sur IT-Connect.
Hackers pushed a poisoned arrayref version that added a dependency to fetch a malicious payload from a remote server.
The post Rust Supply Chain Attack Linked to North Korean Hackers appeared first on SecurityWeek.
Deux jours après le correctif publié par GitLab, la faille critique CVE-2026-19478 fait l'objet de tentatives d'exploitation par les pirates.
Le post GitLab : la faille critique CVE-2026-19478 est déjà exploitée, deux jours après le correctif a été publié sur IT-Connect.
Microsoft enquête sur les plantages de jeux provoqués par la mise à jour KB5121003 de Windows 11. Le studio Embark pointe le pilote tiers inpoutx64.sys.
Le post Windows 11 : la mise à jour KB5121003 fait planter des jeux, Microsoft cherche une solution a été publié sur IT-Connect.
CERT Polska confirmed active exploitation of CVE-2026-73570, a critical unauthenticated RCE in Zimbra Collaboration Suite patched on July 20. CERT Polska, Poland’s national computer emergency response team, confirmed this week that threat actors are actively exploiting a critical vulnerability in Zi...
Proton déploie les catégories dans Proton Mail : six onglets pour trier vos e-mails entrants, avec un classement basé sur les métadonnées et non sur le contenu.
Le post Proton Mail trie enfin vos e-mails automatiquement, et sans lire leur contenu a été publié sur IT-Connect.