[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (3 articles)

|

// AI-powered summary generated at 08:00

> Debian cjose Critical Denial of Service and Code Execution DSA-6499-1
Two vulnerabilities were discovered in cjose, a C library implementing the JOSE standard, which could result in denial of service, execution of arbitrary code or plain text recovery in specific setups. For the stable distribution (trixie), these problems have been fixed in version 0.6.2.3-1+deb13u1.
> What’s next for CISA’s CDM program that gives cybersecurity tools to federal agencies
Three feds spoke about future plans for the Continuous Diagnostics and Mitigation program, and lessons they’ve learned. The post What’s next for CISA’s CDM program that gives cybersecurity tools to federal agencies appeared first on CyberScoop.
> Low-quality casino sites conceal highly dangerous threat actors
Security firm Infoblox shines light on malicious infrastructure lurking beneath illegal gambling sites
> “We Think the Security Control Is Working” Is No Longer Good Enough
Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. The post “We Think the Security Control Is Working” Is No Longer Good Enough appeared first on SecurityWeek.
> Architecting resilient authentication with Amazon Cognito multi-Region replication
Your consumer identity and access management (CIAM) system is the foundation of your customer experience. It’s how users sign in, access services, and engage with your applications. As your business scales across geographies, ensuring authentication is always available becomes a core architectural r...
> KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersona...
> California: Tell the Governor to Stand Up for Net Neutrality, Affordability, and Public Safety
The federal government has inserted a provision into a funding deal with the state of California that would make the state abandon its gold standard net neutrality law, broadband affordability laws, and public safety protections. Doing so would be a huge step back for California, and would actually...
> Iranian spies hit Windows machines with Chosen Brick data-stealing malware
'Enemies of the regime' on notice
> US military confirms it launched space weapons into Earth’s orbit
This is the first public acknowledgment that the U.S. military put a space weapon in Earth's orbit.
> Ubuntu 26.04 LTS Kitty Important Arbitrary Code Execution Vuln 8763-1
Several security issues were fixed in kitty.
> Ubuntu 26.04 SRT Important Security Issues CVE-2026-55868 CVE-2026-55869
Several security issues were fixed in SRT.
> CenterPoint Energy confirms customer data stolen in cyberattack
CenterPoint Energy disclosed a breach compromising some customers' personal information after an attacker leaked data allegedly stolen from the utility company. [...]
> Ubuntu python-sql Critical SQL Injection Risk USN-8765-1 CVE-2024-9774
python-sql could allow an attacker to perform SQL injection attacks.
> Ubuntu Snapcast Important Remote Code Exec Risk USN-8767-1 CVE-2023-36177
Snapcast could be made to expose sensitive information or run programs if it received specially crafted network traffic.
> Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's intelligence service uses to spy on dissidents, journalists, and activists around the world. The malware is controlled via the Telegram messaging app and can cop...
> Ubuntu 24.04 Shibboleth Important SQL Injection Risk USN-8768-1
Shibboleth could be made to expose sensitive information over the network.
> Iranian cyber spies used fake MRI scan results to hack ‘enemy of regime’
According to the United Kingdom’s National Cyber Security Centre (NCSC), Iran has used this and similar cyber activity to “support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists.”
> USN-8770-1: SimpleSAMLphp vulnerabilities
It was discovered that SimpleSAMLphp incorrectly validated cryptographic signatures in XML messages. An authenticated attacker could possibly use this issue to impersonate users or gain elevated privileges. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2019-3465) It was disco...
> Cisco email security boxes can be rooted by... an email
Attackers already exploiting the critical flaw, and Cisco warns they may be able to cover their tracks once they're in
> $1 Million Sandbox Challenge Uncovers Linux Kernel Flaws
AI-assisted researchers flooded Vercel with reports, forcing the company to automate vulnerability triage. The post $1 Million Sandbox Challenge Uncovers Linux Kernel Flaws appeared first on SecurityWeek.