[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> Digital minimalism: How to reduce screen time and protect your privacy
Practical digital minimalism tips to reduce screen time on iPhone and Android, plus a guide for kids and how to protect data from Big Tech.
> Ransomware crook poses as recovery firm to steal payments from fellow extortionists
Because apparently even ransomware gangs can't trust the people they do business with
> Microsoft 365 : environ 171 000 associations auraient perdu leurs données OneDrive
Après l'arrêt d'une offre Microsoft 365 gratuite pour les associations, des milliers d'espaces OneDrive ont été effacés des tenants Microsoft. À qui la faute ? Le post Microsoft 365 : environ 171 000 associations auraient perdu leurs données OneDrive a été publié sur IT-Connect.
> How MSPs can catch phishing attacks email filters miss
AI is making phishing attacks more personalized, convincing, and difficult for traditional email filters to detect. Kaseya explains how MSPs can monitor identity, email, and endpoint activity to detect and contain attacks that make it past the inbox. [...]
> CVE-2026-69855 Microsoft Copilot in Azure Information Disclosure Vulnerability
Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.
> CVE-2026-69543 Azure Virtual Machines Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.
> Critical Arbitrary File Upload Vulnerability Patched in Elementor Pro WordPress Plugin
On July 24th, 2026, we received a submission for an Unauthenticated Arbitrary File Upload vulnerability in Elementor Pro, a WordPress plugin with an estimated 6,000,000 active installations. This vulnerability makes it possible for unauthenticated attackers to upload arbitrary files, including execu...
> CVE-2026-69558 Microsoft Partner Center Information Disclosure Vulnerability
Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.
> CVE-2026-69555 Azure Arc Elevation of Privilege Vulnerability
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
> USN-8654-1: Netty vulnerabilities
It was discovered that Netty did not properly handle malformed HTTP/2 control frames. An attacker could use this to cause a denial of service via resource exhaustion. This issue only affects Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2025-55163) It was discover...
> CVE-2026-69400 Azure Logic Apps Elevation of Privilege Vulnerability
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
> CVE-2026-69502 Azure SQL Database Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
> Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE
Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow attackers to escape the confines of the isolated environment. The vulnerability ("GHSA-864f-rcv7-6rh4"), which has yet...
> CVE-2026-69419 Azure Data Manager for Energy Remote Code Execution Vulnerability
Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network.
> CVE-2026-68782 Azure SQL Database Elevation of Privilege Vulnerability
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
> Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability. According to the cloud computing and virtualization technology company, the issues affect customer-managed NetScale...
> CVE-2026-66800 Azure Data Factory Information Disclosure Vulnerability
Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.
> CVE-2026-66309 Azure SQL Database Elevation of Privilege Vulnerability
Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
> The push to designate AI as the next critical infrastructure sector
The designation would unlock a range of federal services, tools and resources for an industry that policymakers view as increasingly tied to national and economic security. The post The push to designate AI as the next critical infrastructure sector appeared first on CyberScoop.
> CVE-2026-65816 Azure Arc Elevation of Privilege Vulnerability
Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.