[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> CVE-2026-69836 Microsoft Entra ID Remote Code Execution Vulnerability
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
> CVE-2026-69851 Microsoft Entra ID Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
> Critical Arbitrary File Upload Vulnerability Patched in Elementor Pro WordPress Plugin
On July 24th, 2026, we received a submission for an Unauthenticated Arbitrary File Upload vulnerability in Elementor Pro, a WordPress plugin with an estimated 6,000,000 active installations. This vulnerability makes it possible for unauthenticated attackers to upload arbitrary files, including execu...
> CVE-2026-69519 Azure Stack HCI Information Disclosure Vulnerability
Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.
> CVE-2026-68789 Azure SQL Database Elevation of Privilege Vulnerability
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
> USN-8654-1: Netty vulnerabilities
It was discovered that Netty did not properly handle malformed HTTP/2 control frames. An attacker could use this to cause a denial of service via resource exhaustion. This issue only affects Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2025-55163) It was discover...
> CVE-2026-65801 Microsoft Exchange Online Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
> CVE-2026-62834 Azure Data Factory Elevation of Privilege Vulnerability
Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.
> Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE
Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow attackers to escape the confines of the isolated environment. The vulnerability ("GHSA-864f-rcv7-6rh4"), which has yet...
> Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability. According to the cloud computing and virtualization technology company, the issues affect customer-managed NetScale...
> The push to designate AI as the next critical infrastructure sector
The designation would unlock a range of federal services, tools and resources for an industry that policymakers view as increasingly tied to national and economic security. The post The push to designate AI as the next critical infrastructure sector appeared first on CyberScoop.
> Ubuntu PostgreSQL Critical Buffer Overflow SQL Injection Vuln 8653-1
Ubuntu released a security update addressing multiple vulnerabilities in PostgreSQL across various versions, allowing potential arbitrary code execution and sensitive information disclosure by authenticated users.
> Twitch wants your content for Amazon AI training. Here’s how to opt out
Twitch added an option to opt out of training Amazon AI with your content—two years after it confirmed that training had begun.
> France : SFR confirme une nouvelle fuite de données visant ses abonnés fibre
SFR confirme un incident détecté le 2 juillet sur un outil de gestion des raccordements fibre. Un pirate revendique 2,1 millions de lignes de données. Le post France : SFR confirme une nouvelle fuite de données visant ses abonnés fibre a été publié sur IT-Connect.
> Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska). The vulnerability in question is CVE-2026-73570 (CVSS score: 8.9), which refers to a case of command injection tha...
> Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia
Operation CameraSwarm targeted Dahua cameras across multiple countries, focusing on Russian and CIS telecom netblocks. The post Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia appeared first on SecurityWeek.
> Club One Casino revendiqué par 3AM puis PEAR
Hack Twins : Un nouveau casino apparaît chez deux groupes de pirates informatiques différents.
> Using Microsoft Graph and Powershell - Risk Detection Commands, (Thu, Aug 20th)
Building on the last diary on Using MS Graph and Powershell, let&#;x26;#;39;s look at "Risky" logins.
> BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive
Research by: Jiří Vinopal (@vinopaljiri) Abstract What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation driver could be instructed to execute arbitrary file and registry operations from Ring 0 – without exploits,...
> AI data giant Alation confirms cyberattack
The data search and AI giant confirmed unauthorized access to its systems during an incident on Tuesday, and said it was investigating the breach.