[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> ZDI-25-907: Autodesk Revit RFA File Parsing Type Confusion Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk Revit. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The followi...
> ZDI-25-906: SolarWinds Web Help Desk AjaxProxy Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Web Help Desk. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2025-26399.
> Forlì
Le systèmes informatiques du Comune di Forlì ont été victimes d'une attaque non autorisée, mais aucune preuve de fuite de données personnelles n'a été trouvée pour le moment. Les procédures de sécurité ont été activées et des vérifications techniques sont en cours. Certains systèmes et services numé...
> ZDI-25-905: Gen Digital CCleaner Link Following Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Gen Digital CCleaner. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. Some interaction on the part of an administrator i...
> Okuma Europe GmbH
Okuma Europe GmbH, une filiale d'Okuma Corporation, a subi une attaque de ransomware, ce qui a entraîné une infection de son serveur et un risque possible d'exfiltration de données personnelles et d'informations confidentielles. L'entreprise travaille actuellement avec des experts externes pour enqu...
> Thermofin
La société Thermofin a été victime d'une attaque cybernétique massive, entraînant des fuites de données, y compris des informations sur les employés. L'entreprise est actuellement seulement accessible de manière limitée via une hotline. Les filiales en Chine et en Pologne sont également touchées.
> EFF Statement on TikTok Ownership Deal
One of the reasons we opposed the TikTok "ban" is that the First Amendment is supposed to protect us from government using its power to manipulate speech. But as predicted, the TikTok "ban" has only resulted in turning over the platform to the allies of a president who seems to have no respect for t...
> Herker Industries Inc.
L'attaque n'a pas été revendiquée, mais l'enseigne Qilin divulgue des données présentées comme issues des systèmes de Herker.
> Turf Valley Resort
L'attaque n'a pas été revendiquée, mais l'enseigne Qilin divulgue des données présentées comme issues des systèmes du Turf Valley Resort.
> Operation Rewrite: Chinese-Speaking Threat Actors Deploy BadIIS in a Wide Scale SEO Poisoning Campaign
SEO poisoning campaign "Operation Rewrite” uses a malicious IIS module called BadIIS to redirect users to unwanted websites. The post Operation Rewrite: Chinese-Speaking Threat Actors Deploy BadIIS in a Wide Scale SEO Poisoning Campaign appeared first on Unit 42.
> Lumena Financial Strategies
Lumena Financial Strategies suffered a data breach after a threat actor accessed their computer systems using ransomware. The breach occurred on September 23, 2025, and potentially exposed client information including names, dates of birth, home addresses, social security numbers, banking informatio...
> Insightin Health
InsightinHealth, Inc. suffered a data breach after an unauthorized actor gained access to their network by exploiting a previously unknown vulnerability in a third-party application. The breach occurred between September 17, 2025, and September 23, 2025, and may have impacted certain files stored on...
> How to accelerate security finding reviews using automated business context validation in AWS Security Hub CSPM
October 1, 2025: This post was updated to reflect the new name of Security Hub, which is AWS Security Hub CSPM (Cloud Security Posture Management). Security teams must efficiently validate and document exceptions to AWS Security Hub (Cloud Security Posture Management, previously known as Security Hu...
> Debian: linux Critical Privilege Escalation Vulnerabilities DSA-6009-1
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
> Debian: linux Critical Escalation Denial of Service DSA-6008-1
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
> Going Viral vs. Going Dark: Why Extremism Trends and Abortion Content Gets Censored
This is the fourth installment in a blog series documenting EFF's findings from the Stop Censoring Abortion campaign. You can read additional posts here.  One of the goals of our Stop Censoring Abortion campaign was to put names, stories, and numbers to the experiences we’d been hearing about: peopl...
> LinkedIn will soon use your data to train AI. Here’s what you can do to opt out.
LinkedIn will share your public data with Microsoft to train AI. Find what this means for your privacy and how to opt out.
> Organizations Must Update Defenses to Scattered Spider Tactics, Experts Urge
Experts at a Gartner event highlighted areas of focus in identity, processes and third-party risk management to tackle the novel tactics employed by Scattered Spider
> [Communiqué] Odile Duthil est élue présidente du Clusif
Le conseil d’administration du 19 septembre 2025 a élu Odile Duthil à la présidence du Clusif. Loïc Guézo,  Anne Doré, Michel Dubois ont été réélus au bureau. « Je remercie Benoît Fuzeau pour son engagement et tout le travail réalisé. Sous sa présidence, le Clusif a acquis une nouvelle dimension nat...
> Major Cyber Threat Detection Vendors Pull Out of MITRE Evaluations Test
MITRE said it understands why Microsoft, SentinelOne and Palo Alto pulled out of its 2025 of ATT&CK Evaluations test – and promises to do better next year