[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (16 articles)

|

// AI-powered summary generated at 20:00

> [webapps] Casdoor 2.55.0 - Cross-Site Request Forgery (CSRF)
Casdoor 2.55.0 - Cross-Site Request Forgery (CSRF)
> [webapps] dotCMS 25.07.02-1 - Authenticated Blind SQL Injection
dotCMS 25.07.02-1 - Authenticated Blind SQL Injection
> Oxford County
Oxford County a été victime d'une cyberattaque, l'administration du comté a publié une déclaration à ce sujet. La cyberattaque a eu lieu le 16 septembre 2025. Les détails de l'attaque ne sont pas encore connus.
> [webapps] ELEX WooCommerce WordPress Plugin 1.4.3 - SQL Injection
ELEX WooCommerce WordPress Plugin 1.4.3 - SQL Injection
> [webapps] XWiki Platform 15.10.10 - Metasploit Module for Remote Code Execution (RCE)
XWiki Platform 15.10.10 - Metasploit Module for Remote Code Execution (RCE)
> Chester County Library System
Le système de bibliothèque du comté de Chester en Pennsylvanie a subi une panne de plusieurs jours en raison d'une attaque de ransomware, affectant les 18 succursales et perturbant les services publics. Les services de téléphone et d'internet ont été rétablis le 25 septembre, mais des problèmes d'e-...
> [webapps] Concrete CMS 9.4.3 - Stored XSS
Concrete CMS 9.4.3 - Stored XSS
> [local] Mbed TLS 3.6.4 - Use-After-Free
Mbed TLS 3.6.4 - Use-After-Free
> Form Energy
Form Energy a subi une faille de sécurité qui a exposé des informations personnelles sensibles de ses employés actuels et anciens, y compris des noms, adresses, dates de naissance et numéros de sécurité sociale. L'entreprise a détecté l'attaque le 16 septembre 2025 et a commencé à notifier les perso...
> [remote] HTTP/2 2.0 - Denial Of Service (DOS)
HTTP/2 2.0 - Denial Of Service (DOS)
> [remote] HTMLDOC 1.9.13 - Stack Buffer Overflow
HTMLDOC 1.9.13 - Stack Buffer Overflow
> Fine Line Woodworking
Cette victime n'a pas été revendiquée par Akira, mais un affidé de l'enseigne divulgue des données qu'il lui attribue.
> The Risks of Code Assistant LLMs: Harmful Content, Misuse and Deception
We examine security weaknesses in LLM code assistants. Issues like indirect prompt injection and model misuse are prevalent across platforms. The post The Risks of Code Assistant LLMs: Harmful Content, Misuse and Deception appeared first on Unit 42.
> Our Stop Censoring Abortion Campaign Uncovers a Social Media Censorship Crisis
This is the first installment in a blog series documenting EFF's findings from the Stop Censoring Abortion campaign. You can read additional posts here.  We’ve been hearing that social media platforms are censoring abortion-related content, even when no law requires them to do so. Now, we’ve got the...
> Supporting Rowhammer research to protect the DRAM ecosystem
Posted by Daniel MoghimiRowhammer is a complex class of vulnerabilities across the industry. It is a hardware vulnerability in DRAM where repeatedly accessing a row of memory can cause bit flips in adjacent rows, leading to data corruption. This can be exploited by attackers to gain unauthorized acc...
> HybridPetya Mimics NotPetya, Adds UEFI Compromise
HybridPetya ransomware mimics Petya/NotPetya, with an added UEFI bootkit and Secure Boot bypass
> SEO Poisoning Targets Chinese Users with Fake Software Sites
SEO poisoning attack has been observed targeting Chinese Windows users via lookalike domains, installing Hiddengh0st and Winos
> 15th September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 15th September, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Panama’s Ministry of Economy and Finance (MEF) was hit by a ransomware attack that resulted in the theft of more than 1.5TB of data, including email...
> AI-Forged Military IDs Used in North Korean Phishing Attack
Genians observed the Kimsuky group impersonate a defense institution in a spear-phishing attack, leveraging ChatGPT to create fake military ID cards
> CISA at Risk After OIG Accuses it of Wasting Federal Funds
US Department of Homeland Security OIG claims CISA mismanaged a key cyber retention incentive program