[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (14 articles)

|

// AI-powered summary generated at 16:00

> AWS Kiro: Arbitrary Code Execution via Indirect Prompt Injection
On the day AWS Kiro was released, I couldn’t resist putting it through some of my Month of AI Bugs security tests for coding agents. AWS Kiro was vulnerable to arbitrary command execution via indirect prompt injection. This means that a remote attacker, who controls data that Kiro processes, could h...
> ZipLine Campaign: A Sophisticated Phishing Attack Targeting US Companies
Key findings: Introduction Check Point Research (CPR) has been closely monitoring the activity of a highly persistent and sophisticated threat actor who leverages social engineering tactics to gain the trust of targeted U.S.-based organizations. While analyzing the phishing lures used by the actors,...
> US: Maryland Confirms Cyber Incident Affecting State Transport Systems
All previously scheduled mobility trips across Maryland for this week will be honored, said the state’s transportation administration
> CIISec: Most Security Professionals Want Stricter Regulations
A new CIISec poll finds the majority of industry professionals would prefer more rigorous cybersecurity laws
> CVE-2025-55230 Windows MBT Transport Driver Elevation of Privilege Vulnerability
Corrected Download and Article links in the Security Updates table. This is an informational change only.
> Tech Manufacturer Data I/O Hit by Ransomware
Data I/O has revealed operational disruption following a ransomware breach that forced it to take some systems offline
> CVE-2025-55229 Windows Certificate Spoofing Vulnerability
Corrected Download and Article links in the Security Updates table. This is an informational change only.
> CVE-2025-55231 Windows Storage-based Management Service Remote Code Execution Vulnerability
Corrected Download and Article links in the Security Updates table. This is an informational change only.
> Into the World of Passkeys: Practical Thoughts and Real-Life Use Cases
In a previous blog post, we explored the technical side of passkeys (also known as discoverable credentials or resident keys), what they are, how they work, and why they’re a strong alternative to passwords. Today, we’ll show how passkeys are used in the real world - by everyday users and security p...
> Les derniers articles scientifiques co-écrits par des agents issus des labos de l’ANSSI
Les derniers articles scientifiques co-écrits par des agents issus des labos de l’ANSSI anssiadm mar 26/08/2025 - 07:00 Découvrez les parutions scientifiques les plus récentes auxquelles ont pris part différents agents de l’ANSSI issus des laboratoires de la division...
> ZDI-25-872: TeamViewer Link Following Denial-of-Service Vulnerability
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of TeamViewer. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1....
> ZDI-25-871: (Pwn2Own) QNAP QHora-322 miro_webserver_lib_RunExecBash Command Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of QNAP QHora-322 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 7.1. The...
> Vulnérabilité dans Citrix NetScaler ADC et NetScaler Gateway (26 août 2025)
Le 26 août 2025, Citrix a publié un bulletin de sécurité (cf. section Documentation) concernant, entre autres, la vulnérabilité CVE-2025-7775. Celle-ci permet une exécution de code arbitraire à distance et affecte toutes les versions de Citrix NetScaler ADC et NetScaler Gateway, dans certaines...
> [remote] GeoVision ASManager Windows Application 6.1.2.0 - Remote Code Execution (RCE)
GeoVision ASManager Windows Application 6.1.2.0 - Remote Code Execution (RCE)
> [local] GeoVision ASManager Windows Application 6.1.2.0 - Credentials Disclosure
GeoVision ASManager Windows Application 6.1.2.0 - Credentials Disclosure
> CVE-2025-52882: WebSocket authentication bypass in Claude Code extensions
A critical vulnerability in older versions of the Claude Code for Visual Studio Code (VS Code) and other IDE extensions allowed malicious websites to connect to unauthenticated local WebSocket servers, potentially enabling remote command execution
> [webapps] StoryChief Wordpress Plugin 1.0.42 - Arbitrary File Upload
StoryChief Wordpress Plugin 1.0.42 - Arbitrary File Upload
> [remote] Ivanti Endpoint Manager Mobile 12.5.0.0 - Authentication Bypass
Ivanti Endpoint Manager Mobile 12.5.0.0 - Authentication Bypass
> Lotte Card
Lotte Card a signalé une cyberattaque après avoir détecté des signes de violation dans ses serveurs internes à la fin du mois dernier. L'entreprise a découvert du code malveillant sur l'un de ses serveurs et a ensuite effectué un examen approfondi de ses systèmes. Aucune fuite de données sensibles d...
> [webapps] Lingdang CRM 8.6.4.7 - SQL Injection
Lingdang CRM 8.6.4.7 - SQL Injection