[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (2 articles)

|

// AI-powered summary generated at 04:00

> CVE-2025-53767 Azure OpenAI Elevation of Privilege Vulnerability
Information published.
> CVE-2025-53774 Microsoft 365 Copilot BizChat Information Disclosure Vulnerability
Information published.
> AIxCC finals: Tale of the tape
While the AIxCC winner has not yet been announced, differences in the finalists’ approaches show that there are multiple viable paths forward to using AI for vulnerability detection.
> CVE-2025-53787 Microsoft 365 Copilot BizChat Information Disclosure Vulnerability
Information published.
> Hans-Böckler-Stiftung
La Hans-Böckler-Stiftung a été victime d'une attaque ciblée et travaille avec des experts externes pour élucider l'affaire, les paiements de bourses ne sont pas affectés. La fondation a isolé et arrêté tous les systèmes informatiques après la découverte de l'attaque. Les experts en forensique inform...
> Nigeria Customs Service (NCS)
Une cyberattaque a paralysé la plateforme informatique des douanes nigérianes, provoquant de fortes perturbations dans le dédouanement des cargaisons et entraînant des pertes pour les agents à cause des frais de surestaries. Les autorités affirment avoir rétabli et renforcé le système, tout en discu...
> HTTP/1.1 Must Die: What This Means for AppSec Leadership
At Black Hat USA and DEFCON 2025, PortSwigger's Director of Research, James Kettle, issued a stark warning: request smuggling isn't dying out, it's evolving and thriving. Despite years of defensive ef
> Monterey Mushrooms, LLC
An unauthorized actor accessed files on Monterey Mushrooms' computer servers between August 2, 2025, and August 7, 2025, potentially exposing the name, Social Security number, and driver's license number or passport number of a Maine resident. The attack has been claimed by Payoutkings on September...
> Carus
Carus, LLC experienced a network disruption on or around August 7, 2025, which may have allowed an unauthorized third party to access a limited amount of personal information. The attack was claimed by Akira on September 4.
> HTTP/1.1 Must Die: What This Means for In-House Pentesters
At Black Hat USA and DEFCON 2025, PortSwigger's Director of Research, James Kettle, issued a stark warning: request smuggling isn't dying out, it's evolving and thriving. Despite years of defensive ef
> Mondi Resort
La groupe de ransomware Lynx a lancé une attaque contre le Mondi Resort am Grundlsee, entraînant la cryptage de serveurs et une demande de rançon, avec une possible fuite de données. Le groupe Lynx est responsable de centaines d'attaques cybernétiques à travers le monde depuis mi-2024. Les cibles in...
> OB-GYN Associates
OB-GYN Associates experienced a data security incident where an unauthorized third-party accessed their network environment, potentially exposing personal information of patients. The incident occurred on or about August 7, 2025, and was detected on the same date. An investigation was completed on S...
> HTTP/1.1 Must Die: What This Means for Bug Bounty Hunters
At Black Hat USA and DEFCON 2025, PortSwigger's Director of Research, James Kettle, issued a stark warning: request smuggling isn't dying out, it's evolving and thriving. Despite years of defensive ef
> Bank3
Bank3 suffered a data breach between July 25, 2025, and August 7, 2025, resulting in unauthorized access to sensitive information. The breach affected various types of data, including names, Social Security numbers, driver's licenses, financial account information, and payment card information. A cy...
> Passco Companies, LLC
Passco Companies, LLC suffered a data breach on August 7, 2025, where limited information was taken from its environment. The affected information includes name and Social Security number of certain individuals. Passco is providing access to credit monitoring services for 12 months to affected indiv...
> HTTP/1.1 Must Die: What This Means for Contract Pentesters and MSSPs
At Black Hat USA and DEFCON 2025, PortSwigger's Director of Research, James Kettle, issued a stark warning: request smuggling isn't dying out, it's evolving and thriving. Despite years of defensive ef
> The Desync Delusion: Are You Really Protected Against HTTP Request Smuggling?
The Hidden Threat That's Slipping Past Your Security HTTP request smuggling remains one of the most dangerous yet frequently overlooked web vulnerabilities today. Despite being a widely known issue si
> #BHUSA: Security Researchers Uncover Critical Flaws in Axis CCTV Software
Claroty researchers have uncovered four vulnerabilities in a proprietary protocol used by surveillance equipment manufacturer Axis Communications
> #BHUSA: Researchers Expose Infrastructure Behind Cybercrime Network VexTrio
According to Infoblox’s new report, the VexTrio cybercrime-enabling network originates from Italy and Eastern Europe
> L’Usine digitale
Le bijoutier Pandora victime d’une fuite de données personnelles La société danoise a averti ses clients d’une cyberattaque survenue via la plateforme d’un tiers. Elle explique que les noms, dates de naissance et adresses e-mail sont les seules catégories de données personnelles dérobées et qu’aucu...